Intelligent data permission authentication method and device

By acquiring user login information and performing three-layer authentication, including user roles, tags, and behavior scores, and using intelligent AI algorithms to filter data access permissions, the problem of weak data confidentiality is solved, and data access security and intelligence are achieved.

CN114254282BActive Publication Date: 2025-12-05武汉达梦数据技术有限公司
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202111584958.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-22
Publication Date
2025-12-05
Estimated Expiration
2041-12-22

AI Technical Summary

Technical Problem

Existing technologies lack strong data confidentiality, making it difficult to effectively conduct secure data access.

Method used

By obtaining user login information, determining user roles, tags, and behavior scoring information, and performing three-layer authentication to filter data access permissions, including user role authentication, data permission authentication, and sensitive data authentication, the data is filtered using machine intelligence AI algorithms.

Benefits of technology

It enables intelligent data access and secure access permissions, ensuring data confidentiality and preventing unauthorized access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114254282B_ABST
    Figure CN114254282B_ABST
Patent Text Reader

Abstract

The application relates to an intelligent data permission authentication method and device, which comprises the following steps: obtaining user login information; determining user role information, user label information and user behavior score information according to the user login information, wherein the user behavior score information is determined by scoring user behavior data; sequentially performing data access permission three authentication according to the user role information, the user label information and the user behavior score information, and screening out user authentication passed data; and sequentially screening the user authentication passed data according to data permission authentication and sensitive data authentication, and determining accessible data of the user. The application guarantees data security and confidentiality, realizes the intellectualization of data access and the security of access permission.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data security technology, and in particular to an intelligent data access authentication method and apparatus. Background Technology

[0002] With the rapid development of internet technology, people are becoming increasingly stringent in their data access methods and data confidentiality. Often, it's necessary to determine a user's access methods and data permissions based on their personal information. At a deeper level, this information can be used to determine which data a user can view, delete, update, and whether they have granted others access to their own data. As people's security awareness increases, data confidentiality is also a major concern. Therefore, how to achieve effective and secure data access is a pressing issue that needs to be addressed. Summary of the Invention

[0003] In view of this, it is necessary to provide an intelligent data access authentication method to solve the problem of weak data confidentiality in existing technologies.

[0004] This invention provides an intelligent data access authentication method, comprising:

[0005] Obtain user login information;

[0006] Based on the user login information, user role information, user tag information, and user behavior rating information are determined, wherein the user behavior rating information is determined by rating user behavior data;

[0007] Based on the user role information, the user tag information, and the user behavior score information, data access permission three-way authentication is performed in sequence, and user authentication passed data is filtered out;

[0008] The user authentication process involves sequentially performing data permission authentication and sensitive data authentication, filtering the data to determine the user's accessible data.

[0009] Furthermore, the determination of the user role information includes:

[0010] Based on the user login information, determine the user's role and identify the corresponding user role information.

[0011] Furthermore, the determination of the user tag information includes:

[0012] Based on the user login information, determine the user's business relationships and logical relationships;

[0013] The business relationship and the logical relationship are combined into a temporary large tag, and the temporary large tag constitutes the user tag information.

[0014] Furthermore, the determination of the user behavior scoring information includes:

[0015] Based on the user login information, determine the user's recent behavior data;

[0016] The recent behavioral data is intelligently analyzed to determine the corresponding level score, and the level score constitutes the user behavior score information.

[0017] Furthermore, the process of sequentially performing three-factor authentication of data access based on the user role information, the user tag information, and the user behavior rating information, and filtering out user authentication-passed data includes:

[0018] User role authentication is performed based on the user role information.

[0019] If the user role authentication is successful, then data tag authentication is performed based on the user tag information;

[0020] If the data tag authentication is successful, then user behavior authentication is performed based on the user behavior scoring information.

[0021] If user behavior authentication is successful, the corresponding successful access data will be considered user authentication successful data.

[0022] Furthermore, the step of sequentially performing three-factor authentication of data access based on the user role information, the user tag information, and the user behavior rating information, and filtering out user-authenticated data, also includes:

[0023] When user role authentication, data tag authentication, or user behavior authentication fails, the accessed data is considered unauthorized data.

[0024] Furthermore, the sequential data access authentication includes:

[0025] The user authentication data is used as the data source;

[0026] By analyzing the row data accessed by the user, the user's permission to access the corresponding column data can be determined.

[0027] Determine the user's access field permissions based on the permissions of the column data the user accesses;

[0028] Based on the access field permissions, the user authentication passed data is filtered to determine the first authentication passed data.

[0029] Furthermore, the sensitive data authentication includes:

[0030] The first authentication pass data will be used as the data source;

[0031] Based on the set sensitive keywords, the first certified data is intelligently compared with massive amounts of data to filter out data that has no sensitive keywords, and the second certified data is then determined.

[0032] Furthermore, following the sensitive data authentication, data operation authentication is also included, which includes:

[0033] Use the second authentication pass data as the data source;

[0034] Based on the background configuration authentication service and the intelligent AI operation permission judgment algorithm, the second authentication passed data is classified according to the user login information to determine the user's corresponding read-only permission data and operable data.

[0035] The present invention also provides an intelligent data access authentication device, including a processor and a memory, wherein a computer program is stored in the memory, and when the computer program is executed by the processor, the intelligent data access authentication method described above is implemented.

[0036] Compared with existing technologies, the beneficial effects of this invention include: First, it effectively acquires user login information; second, it employs a three-tiered data source judgment system for user information, utilizing multiple authentication methods based on user role information, user tag information, and user behavior rating information to filter the data; finally, based on data hierarchy, it filters data through data permission authentication and sensitive data authentication to determine the user's accessible data. In summary, this invention addresses both user information and data information levels, performing data permission authentication after user information permission authentication, thus ensuring data security and confidentiality, and achieving intelligent data access and secure access permissions. Attached Figure Description

[0037] Figure 1 A flowchart illustrating an embodiment of the intelligent data access authentication method provided by the present invention;

[0038] Figure 2 Provided by the present invention Figure 1 A flowchart illustrating an embodiment of step S3;

[0039] Figure 3 Provided by the present invention Figure 1 Flowchart of an embodiment of step S4 Figure 1 ;

[0040] Figure 4 Provided by the present invention Figure 1 Flowchart of an embodiment of step S4 Figure 2 ;

[0041] Figure 5Provided by the present invention Figure 1 Flowchart of an embodiment of step S4 Figure 3 . Detailed Implementation

[0042] Preferred embodiments of the present invention will now be described in detail with reference to the accompanying drawings, which form part of this application and are used together with the embodiments of the present invention to illustrate the principles of the present invention, but are not intended to limit the scope of the present invention.

[0043] This invention provides an intelligent data access authentication method, combined with Figure 1 Let's take a look. Figure 1 A flowchart illustrating an embodiment of the intelligent data access authentication method provided by the present invention includes steps S1 to S4, wherein:

[0044] In step S1, user login information is obtained;

[0045] In step S2, user role information, user tag information, and user behavior rating information are determined based on the user login information, wherein the user behavior rating information is determined by rating user behavior data;

[0046] In step S3, data access permission three-factor authentication is performed sequentially based on the user role information, the user tag information, and the user behavior score information to filter out user authentication passed data;

[0047] In step S4, the user authentication data is filtered according to data permission authentication and sensitive data authentication in sequence to determine the user's accessible data.

[0048] In this embodiment of the invention, firstly, user login information is effectively obtained; then, for user information, there is a three-layer data source judgment, which performs multiple authentications from user role information, user tag information, and user behavior rating information to filter the data; finally, based on the data hierarchy, data is filtered from data permission authentication and sensitive data authentication to determine the user's accessible data.

[0049] Preferably, the determination of the user role information includes:

[0050] Based on the user login information, determine the user's role and identify the corresponding user role information.

[0051] As a specific embodiment, this embodiment of the invention determines the corresponding user role information based on the user login information and feeds back the user attributes.

[0052] Preferably, the determination of the user tag information includes:

[0053] Based on the user login information, determine the user's business relationships and logical relationships;

[0054] The business relationship and the logical relationship are combined into a temporary large tag, and the temporary large tag constitutes the user tag information.

[0055] As a specific embodiment, this embodiment of the invention utilizes business relationships and logical relationships to construct temporary large tags for users, thereby forming user tag information.

[0056] Preferably, the determination of the user behavior rating information includes:

[0057] Based on the user login information, determine the user's recent behavior data;

[0058] The recent behavioral data is intelligently analyzed to determine the corresponding level score, and the level score constitutes the user behavior score information.

[0059] As a specific embodiment, this invention rates users to ensure that data is made available to safe and reliable users.

[0060] Preferably, combined with Figure 2 Let's take a look. Figure 2 Provided by the present invention Figure 1 A flowchart illustrating an embodiment of step S3, wherein step S3 includes steps S31 to S34, wherein:

[0061] In step S31, user role authentication is performed based on the user role information;

[0062] In step S32, if the user role authentication is successful, data tag authentication is performed based on the user tag information;

[0063] In step S33, if the data tag authentication is successful, then user behavior authentication is performed based on the user behavior scoring information;

[0064] In step S34, if the user behavior authentication is successful, the corresponding successful access data is the user authentication successful data.

[0065] As a specific embodiment, the present invention authenticates users by sequentially performing user role authentication, data tag authentication, and user behavior authentication, ensuring that data is open to reliable users from multiple levels.

[0066] Preferably, step S2 further includes: when user role authentication, data tag authentication, or user behavior authentication fails, the failed access data is considered unauthorized data. As a specific embodiment, this embodiment of the invention considers any user data that fails all three authentication processes as unauthorized data, thus preventing user access and ensuring data security.

[0067] In a specific embodiment of the present invention, the three-level authentication of data access permissions is based on the user's own level of data access permission authentication. It involves three layers of data source determination regarding the user's own information, as detailed below:

[0068] The first layer: user role information. This is a more common approach. Users can access data directly by specifying the data access permissions that their role has. The system provides a backend configuration option to configure data access permissions for that role. This is the most common usage.

[0069] The second layer is user tagging information. It tags users, supporting a massive number of tags. In certain application scenarios, a user's associated information may come from multiple identities. For example, a user might be a local leader, a project manager, or a regional manager, etc. This is an uncertain situation, and there are many possible factors. Therefore, an intelligent tag management service is provided. In such uncertain situations, simply assigning a corresponding tag to the user is sufficient. This tag is essentially like issuing a temporary ID card to the user, which can be revoked at any time. During information verification, a comprehensive ID card verification matching algorithm is provided to obtain the user's permission information. Tags also have parent-child hierarchies and linear relationships. For example, if a user has parent tag permissions, the system algorithm will automatically temporarily assign the parent permission data to the child tag. This is a relatively traditional relationship. For linear relationships, an intelligent AI relationship comparison algorithm is provided. This algorithm assembles all tags with business or logical relationships into a temporary large tag, and then uses this temporary tag to view the user's access data permissions.

[0070] The third layer is led by machine intelligence AI analysis, using recent user behavior as the data source. Machine intelligence AI analysis is used to determine the user's access methods and permissions. The core of this algorithm is to provide a set of all or recent user behavior data, and the machine intelligence AI will intelligently analyze these behaviors. After the analysis, a score will be given, and the score will determine whether the person has permission to access the data. For example, in terms of credit score, people with very low credit scores will never be allowed to access highly secure data.

[0071] Preferably, the specific implementation of the ID card verification matching algorithm consists of three steps:

[0072] The first step is to generate a temporary, unique "ID number" for the user when tagging them. Then, the system will construct all the data access permissions for the ID number based on the tags, package the constructed permissions into a data object, and obtain the access address of the object.

[0073] The second step is to create an index file using key-value pairs for the access addresses of the "ID card" and the packaged data objects, and to create a search index for the "ID card". Then, the constructed access permission object is serialized and stored in a unified user permission library (this library is a free file library that can be quickly searched by address).

[0074] The third step involves quickly retrieving the temporary ID card issued to the user from the index file, then using key-value pairs to find the address of the permission object. This address is then used to quickly find the corresponding access permission in the permission database (supporting massive searches). Finally, all matching permissions are merged into a single access permission list. Our tags also exhibit parent-child hierarchies and linear relationships. For example, if a user has parent tag permissions, the system algorithm will automatically assign the parent's permissions temporarily to the child tag. This is a more traditional relationship. For linear relationships, we provide an additional intelligent AI relationship comparison algorithm. This algorithm assembles all tags with business or logical relationships into a single temporary tag, which is then used to view the user's access permissions.

[0075] Preferably, the intelligent AI relationship comparison algorithm consists of two steps:

[0076] Step 1: Obtain the association relationship of tags by connecting all the data in the system. For example, if a user is tagged with both "project manager" and "architect", the system will determine that the two tags belong to the same person through this relationship.

[0077] Step 2: Merge the two tags into one large tag, issue a temporary "ID card" and store it.

[0078] Preferably, the algorithms for intelligent analysis and scoring are divided into:

[0079] Step 1: Extract system keywords from user behaviors and sensitive behaviors provided by human intervention;

[0080] Step II involves comparing the keywords provided by both sides and assigning a score based on the degree of matching. For example, if the keywords related to a person's behavior appear in a high proportion of the proposed sensitive keywords, the system will assign a high sensitivity score to that user. This score will then be used to determine whether the person has permission to access the data. For instance, regarding credit scores, we would never allow someone with a very low credit score to access highly secure data.

[0081] Preferably, combined with Figure 3 Let's take a look. Figure 3 Provided by the present invention Figure 1 Flowchart of an embodiment of step S4 Figure 1 The data authorization authentication in step S4 includes steps S41 to S44, wherein:

[0082] In step S41, the user authentication pass data is used as the data source;

[0083] In step S42, the user's permission to access the corresponding column data is determined by the row data accessed by the user.

[0084] In step S43, the user's access field permissions are determined based on the user's permissions for accessing column data;

[0085] In step S44, the user authentication passed data is filtered according to the access field permissions to determine the first authentication passed data.

[0086] As a specific embodiment, this embodiment of the invention sets up data permission authentication to determine the data fields that the user can access.

[0087] Preferably, combined with Figure 4 Let's take a look. Figure 4 Provided by the present invention Figure 1 Flowchart of an embodiment of step S4 Figure 2 The sensitive data authentication in step S4 also includes steps S45 to S46, wherein:

[0088] In step S45, the first authentication pass data is used as the data source;

[0089] In step S46, based on the set sensitive keywords, the first authentication passed data is subjected to massive data intelligent comparison to filter out data that has no sensitive keywords, and the second authentication passed data is determined.

[0090] As a specific embodiment, this invention sets up sensitive data authentication and filters sensitive keyword data to ensure the security of the displayed data.

[0091] Preferably, combined with Figure 5 Let's take a look. Figure 5 Provided by the present invention Figure 1 Flowchart of an embodiment of step S4 Figure 3 In step S4, after the sensitive data authentication, data operation authentication is also included, specifically steps S47 to S48, wherein:

[0092] In step S47, the second authentication pass data is used as the data source;

[0093] In step S48, based on the background configuration authentication service and the intelligent AI operation permission judgment algorithm, the second authentication passed data is classified according to the user login information to determine the user's corresponding read-only permission data and operable data.

[0094] As a specific embodiment, this embodiment of the invention sets up data operation authentication to ensure that different users are granted different access permissions for operation data, such as which data has read-only permissions and which data can be updated.

[0095] In a specific embodiment of the present invention, data access authentication, sensitive data authentication, and data operation authentication are performed again based on the first step of user information access authentication. This is divided into three layers, referred to as data three-factor authentication, as follows:

[0096] The first layer: This layer also utilizes machine intelligence AI algorithms, using data filtered through three-stage personnel authentication as the data source. The backend provides a set of human relationship configuration schemes as the standard, and the system's intelligent AI data permission matching algorithm determines whether a user has permission to access certain data columns based on the row data accessed by the user. For example, in one scenario, a leader of Department A can view the data information of all employees in their company, but often this leader can only view the detailed information of all employees in their own department, but can only view the basic information of employees in other departments, such as names and phone numbers. Here, the algorithm provides better permission control in terms of fields.

[0097] The second layer: Here, machine intelligence comparison AI algorithm will be used. The core of this algorithm is to provide a complete set of sensitive data keywords by humans, and then use this algorithm to intelligently compare the data filtered out in the first layer of data authentication with massive amounts of data to filter out data that has no sensitive keywords. The filtered data is safe and accessible data.

[0098] Step 3: Data operation permissions. When a user has access to some data, but not necessarily operation permissions, the data source for operation permission authentication comes from the user's own authentication and data-level authentication. Only one authentication is required here, referred to as operation authentication: data configuration authentication. The system provides a complete backend configuration authentication service and an intelligent AI algorithm to determine operation permissions. Through the AI ​​algorithm, it can obtain which data the user has permission to access, which have read-only permissions, which can be updated, etc.

[0099] It should be noted that the machine intelligence AI algorithm is the same as the machine intelligence AI mentioned above, and the machine intelligence comparison AI algorithm is also the same as the machine intelligence AI mentioned above.

[0100] This invention also provides an intelligent data access authentication device, including a processor and a memory. The memory stores a computer program, and when the computer program is executed by the processor, it implements the intelligent data access authentication method described above.

[0101] This invention discloses an intelligent data access authentication method and device. First, user login information is effectively acquired. Then, for user information, a three-layer data source judgment is performed, using multiple authentication methods based on user role information, user tag information, and user behavior rating information to filter the data. Finally, based on the data hierarchy, data is filtered through data access authentication and sensitive data authentication to determine the user's accessible data.

[0102] The technical solution of this invention starts from two levels: user information and data information. After user information permission authentication, data permission authentication is performed again to ensure data security and confidentiality, and realize intelligent data access and secure access permissions.

[0103] The above description is only a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any changes or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in the present invention should be included within the scope of protection of the present invention.

Claims

1. An intelligent data authority authentication method, characterized in that, The method comprises the following steps: obtaining user login information; determining user role information, user label information and user behavior score information according to the user login information, wherein the user behavior score information is determined by scoring user behavior data; sequentially performing data access permission three authentication according to the user role information, the user label information and the user behavior score information, and screening out user authentication passed data; sequentially screening the user authentication passed data according to data permission authentication and sensitive data authentication to determine the accessible data of the user; the determination of the user label information comprises: determining the business relationship and the logical relationship of the user according to the user login information; composing a temporary large label by the business relationship and the logical relationship based on an AI relationship comparison algorithm, and the temporary large label constitutes the user label information; wherein composing a temporary large label by the business relationship and the logical relationship based on an AI relationship comparison algorithm specifically comprises: obtaining the association relationship of two labels, and determining that the two labels are for the same user according to the association relationship; merging the two labels into a temporary large label; adopting an ID verification matching algorithm to realize the verification of the user label information; wherein the specific implementation of the ID verification matching algorithm is divided into three steps: firstly, when labeling the user, the system generates a temporary and non-repetitive ID number for the user, then constructs all data access permissions of the ID number through the label, packs the constructed permissions into a data object, and obtains the access address of the data object; secondly, the index file is created in the form of key-value pair by the ID number and the access address of the packed data object, and the search index of the ID number is created, then the constructed access permission object is serialized and stored in the unified user permission library; thirdly, when the data permission of the user needs to be queried, the temporary ID issued to the user is quickly found in the index file through the index, the access address of the permission object is queried through the key-value pair, then the access permission is quickly found in the permission library through the access address, and all the satisfied access permissions are merged into one access permission. 2.The intelligent data permission authentication method of claim 1, wherein, the determination of the user role information comprises: judging the role to which the user belongs according to the user login information, and determining the corresponding user role information. 3.The intelligent data permission authentication method of claim 1, wherein, the determination of the user behavior score information comprises: determining the recent behavior data of the user according to the user login information; intelligently analyzing the recent behavior data to determine the corresponding level score, and the level score constitutes the user behavior score information. 4.The intelligent data permission authentication method of claim 1, wherein, the step of sequentially performing data access permission three authentication according to the user role information, the user label information and the user behavior score information to screen out user authentication passed data comprises: performing user role authentication according to the user role information; if the user role authentication is passed, performing data label authentication according to the user label information; if the data label authentication is passed, performing user behavior authentication according to the user behavior score information; If the user behavior authentication passes, the corresponding passed access data is user authentication passed data. 5.The intelligent data permission authentication method of claim 4, wherein, The data access permission three authentications are performed in sequence according to the user role information, the user label information and the user behavior score information, and the user authentication passed data is screened out, and the screening further includes: When the user role authentication, the data label authentication or the user behavior authentication does not pass, the access data that does not pass is no permission data. 6.The intelligent data permission authentication method of claim 4, wherein, The data permission authentication includes: The user authentication passed data is taken as data source; The permission of the user to access corresponding column data is determined through the row data accessed by the user; The access field permission of the user is determined according to the permission of the column data accessed by the user; The first authentication passed data is determined by screening the user authentication passed data according to the access field permission. 7.The intelligent data permission authentication method of claim 6, wherein, The sensitive data authentication includes: The first authentication passed data is taken as data source; The second authentication passed data is determined by screening the first authentication passed data to completely have no sensitive keywords based on the set sensitive keywords. 8.The intelligent data permission authentication method of claim 7, wherein, The data operation authentication is further included after the sensitive data authentication, and the data operation authentication includes: The second authentication passed data is taken as data source; The second authentication passed data is classified to determine the read-only permission data and the operable data corresponding to the user based on the user login information, the background configuration authentication service and the intelligent AI operation permission algorithm.

9. An intelligent data authority authentication device, characterized in that, The computer program is executed by the processor to realize the intelligent data permission authentication method according to any one of claims 1-8. The computer program is executed by the processor to realize the intelligent data permission authentication method according to any one of claims 1-8.

Citation Information

Patent Citations

  • Big data-based data security monitoring system for protecting data

    CN112115482A

  • Power grid core business system access method and system based on trusted identity authentication

    CN112257042A

  • Fine-grained data access control method and device

    CN112580091A

  • Authority control method and device, equipment, storage medium and program product

    CN113297550A