A database binding system and method

By using identity information and timer mechanisms in the database binding system, temporary transfer of access rights is achieved, the risk of data leakage in the prior art is solved, and data security and flexibility of access rights are ensured.

CN114491497BActive Publication Date: 2025-06-27GUANGZHOU CHENCHUANG TECH DEV CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210104523.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-01-28
Publication Date
2025-06-27
Estimated Expiration
2042-01-28

AI Technical Summary

Technical Problem

Existing database binding solutions cannot achieve temporary transfer of access rights while ensuring data security, resulting in the risk of data leakage.

Method used

The user's identity information is obtained through the node device, and the server temporarily grants access permissions, and uses a timer and intermittent verification information sending mechanism to determine whether the user continues to access the database, thereby extending or terminating access permissions.

Benefits of technology

It realizes temporary transfer of access permissions without leaking database data, ensuring data security and flexibility in access permissions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114491497B_ABST
    Figure CN114491497B_ABST
Patent Text Reader

Abstract

The present invention discloses a database binding system and method. The method includes: a node device obtains identity information to complete user identity recognition; the server obtains information of the node device through the node ID and temporarily grants access permission to the node device; a timer is constructed with a preset time value as the timing period, and the timer resets after reaching the preset time value; the server sends verification information to the node device, and the verification information includes an access instruction and a timing instruction. The node device identifies whether the user is accessing the database by extracting background data. If the user is accessing the database, the node device respectively extracts the access instruction and the timing instruction in the verification information; the node device respectively sends the access instruction and the timing instruction to the server and the timer. Compared with the traditional method, the present invention can realize the temporary transfer of access permission on the premise of ensuring that the internal data of the database is not leaked.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of database binding, and particularly relates to a database binding system and method. Background Art

[0002] A database, as the name implies, is a warehouse for storing data, also known as a data management system. It has a large storage space and stores millions, tens of millions, or even hundreds of millions of data internally. However, these data are not stored randomly but follow certain rules, that is, the data are stored together in a certain way to enable multiple users to share and minimize redundancy as much as possible. In short, a database can be regarded as an electronic filing cabinet - a place for storing electronic files.

[0003] Databases play a very important part in network and communication technologies. However, many databases are of a certain degree of privacy, that is, non-public databases. There are certain restrictions on accessing non-public databases through communication devices. In order to achieve the unique identification of device objects and the management of device objects, it has become one of the key technologies for various applications. Existing IP-based binding schemes or binding mechanisms in authentication and authorization mechanisms are used to bind the identity identification, location identification, static or dynamic information of terminals, so as to determine whether to grant access rights to nodes to achieve normal access to the database.

[0004] Through the above binding scheme, the identity identification of nodes can be achieved, thus completing the access to non-public databases. However, this binding scheme can only be applied when the user is always present. If the user leaves the scene but still retains the access rights of the node, then the node can be accessed by other people, which may lead to data leakage; and through real-time identity identification or intermittent identity verification in the background, such as intermittently extracting the facial images of the user through a camera and verifying, to determine whether the user matches the identity ID, then the same identity ID can only be used by the person who registers the identity ID, and the temporary transfer of access rights cannot be achieved. Summary of the Invention

[0005] The purpose of the present invention is to provide a database binding system and method to solve how to achieve the temporary transfer of access rights on the premise of ensuring that the internal data of the database is not leaked.

[0006] The purpose of the present invention can be achieved through the following technical solutions:

[0007] A database binding method includes the following steps:

[0008] The node device obtains the identity information to complete the user's identity recognition. The identity information includes the user's identity ID, facial image, and node ID.

[0009] The server obtains the information of the node device through the node ID and temporarily grants the node device access rights. The access rights allow the node device to access the data files inside the database.

[0010] A timer is built with a preset time value as the timing period. The timer resets to zero after reaching the preset time value.

[0011] The server sends verification information to the node device. The verification information includes an access instruction and a timing instruction. The node device identifies whether the user is accessing the database by extracting background data. If the user is accessing the database, the node device extracts the access instruction and the timing instruction from the verification information respectively.

[0012] The node device sends the access instruction and the timing instruction to the server and the timer respectively. After receiving the access instruction, the server extends the access rights of the node device until the end of the next timing period. After receiving the timing instruction, the timer starts the next timing period after completing the current timing period.

[0013] As a further solution of the present invention: The process of the server sending the verification information is intermittent, and its sending frequency corresponds to the timing period. The verification information is sent to the node device at the start moment of each timing period.

[0014] As a further solution of the present invention: The timing period includes a verification period and a buffer period. The verification period and the buffer period are carried out alternately, and the first timing period is the verification period.

[0015] As a further solution of the present invention: At the start moment of the verification period, the server sends the verification information to the node device. After the timer receives the timing instruction, the current verification period is terminated, the timer is reset to zero and enters the buffer period. After the buffer period ends, it automatically resets to zero and enters the verification period.

[0016] As a further solution of the present invention: If the timer has not received the timing instruction after the verification period ends, the timer is stopped and no longer enters the next timing period.

[0017] As a further solution of the present invention: In the process of the node device identifying whether the user is accessing the database by extracting background data, it specifically includes the following steps:

[0018] Judge whether the node device is running the corresponding viewing software.

[0019] Determine whether the access software is accessing the data file in the database;

[0020] During the entire recognition process, determine whether the data file accessed by the access software is always the same data file.

[0021] As a further solution of the present invention: during the process of the node device identifying whether the user is accessing the database by extracting background data, if during the entire recognition process, the data file accessed by the access software is always the same data file, then the node device background determines whether the same content of the same data file is always accessed during the entire recognition process. If during the entire recognition process, the same content of the same data file is always accessed, then it is determined that the user is not accessing the database.

[0022] A database binding system, comprising:

[0023] A database for storing data;

[0024] A node device for extracting the identity information of the user;

[0025] An identity recognition module, which completes the identity recognition of the user through the identity information extracted by the node device, so as to determine whether it has the right to access the database;

[0026] A timing module, with a preset time value as the timing period, and the timer resets after reaching the preset time value;

[0027] A server, which sends verification information to the node device and decides whether to grant the node device the permission to access the database according to whether the node device is accessing the database.

[0028] Advantages of the present invention: When the present invention is initially started, user identity recognition is completed through facial recognition or other methods. After the identity recognition is completed, the node device is granted temporary access rights by the server. This access right has a certain timeliness and can only last until the end of the next timing cycle. At the beginning stage of each timing cycle, verification information is sent through the server, and the background data of the node device is used to determine whether the node device has been accessing the database, so as to judge whether to extend the access right of the node device. It should be noted that when the user completes identity recognition and leaves midway, and the node device still retains the access right, no new operations will occur on the node device within a certain period of time (in the present invention, it is default that other people cannot take over the node device immediately without the user noticing when the user just leaves). Then, within this intermittent time period, the node device will be determined not to be accessing the database. At this time, the node device will not decompose the verification information, and the access right of the node device will not be extended, and it will lose the access right to the database at the end of this timing cycle, thus avoiding data leakage. After the user identity recognition is completed, the access right can be transferred to others (during the transfer process, it is default that the transferee can immediately take over the node device and start viewing the data files inside the database). During the transfer process, it is continuous. During this process, the node device is determined to be accessing the database all the time. At this time, by decomposing the verification information, the access right of the node device can be extended while starting the next timing cycle until the user stops accessing the database. The combination of the two can realize the temporary transfer of the access right on the premise of ensuring that the internal data of the database is not leaked. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] The present invention will be further described below with reference to the accompanying drawings.

[0030] Figure 1 is a schematic flowchart of a database binding method provided in a preferred embodiment of the present invention;

[0031] Figure 2 is a schematic flowchart of determining whether a node device is accessing the database provided in another preferred embodiment of the present invention;

[0032] Figure 3 is a schematic flowchart of sending and decomposing verification information provided in another preferred embodiment of the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0033] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0034] Data can come from many sources, such as travel records, consumption records, web pages browsed, messages sent, and so on. In addition to text-type data, images, music, and sounds are also data.

[0035] A database is a computer software system that stores and manages data according to a data structure. The concept of a database actually includes two meanings:

[0036] (1) A database is an entity, which is a "warehouse" that can reasonably store data. Users store the transaction data to be managed in this "warehouse", and the two concepts of "data" and "warehouse" are combined to form a database.

[0037] (2) A database is a new method and technology for data management. It can organize data more appropriately, maintain data more conveniently, control data more strictly, and utilize data more effectively.

[0038] As Figure 1 shown, a database binding method in the present invention is shown. The described database binding method is applied to a device that can be connected to the Internet in real time. This device can be a mobile phone, a tablet computer, a computer, and other communicable devices. No specific limitation is made here. The described database binding method is described in detail as follows:

[0039] In step S100, the node device obtains identity information to complete user identity recognition. The identity information includes the user's identity ID, facial image, and node ID;

[0040] In step S200, the server obtains the information of the node device through the node ID and temporarily grants the node device access rights. The access rights can allow the node device to access the data files inside the database;

[0041] In step S300, a timer is constructed with a preset time value as the timing period. The timer resets after reaching the preset time value;

[0042] In step S400, the server sends verification information to the node device. The verification information includes an access instruction and a timing instruction. The node device identifies whether the user is accessing the database by extracting background data. If the user is accessing the database, the node device extracts the access instruction and the timing instruction in the verification information respectively;

[0043] In step S500, the node device sends an access instruction and a timing instruction to the server and the timer respectively. After receiving the access instruction, the server extends the access permission of the node device until the end of the next timing cycle. After receiving the timing instruction, the timer starts the next timing cycle after completing the current timing cycle.

[0044] The so-called server can be a Central Processing Unit (CPU), or other general-purpose servers, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), Field-Programmable Gate Arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose server can be a micro-server or the server can also be any conventional server, etc. The above server is the control center of the above terminal device, and connects various parts of the entire user terminal through various interfaces and lines.

[0045] It should be noted that, as mentioned in step S400, the process of the server sending the verification information is intermittent, and its sending frequency corresponds to the timing cycle. The verification information is sent to the node device at the start moment of each timing cycle.

[0046] As Figure 3 shown, it shows the transmission and decomposition process of the verification code in steps S400 and S500.

[0047] As Figure 2 shown, in another preferred embodiment of the present invention, in order to ensure the accuracy of the node device in the process of identifying whether the user is accessing the database by extracting background data, the following specific steps are included:

[0048] In step S401, it is judged whether the node device is running the corresponding viewing software;

[0049] In step S402, it is judged whether the viewing software is viewing the data file in the database;

[0050] In step S403, during the entire identification process, it is judged whether the data file viewed by the viewing software is always the same data file.

[0051] It can be understood that the entire recognition process is from receiving the verification information to the end of the current timing cycle. During this time period, the operating conditions of the node device are judged intermittently, and the interval time is set by the user or the server. During the recognition process, if it is judged that the node device is not accessing the database and the current timing cycle has not ended, then the next judgment is made until it is judged that the node device is accessing the database; if the timing cycle ends, and during the time period from receiving the verification information to the end of the current timing cycle, all the judgment results are that the node device is not accessing the database, then the output of this recognition process is that the node device is not accessing the database, the verification information is not decomposed, the access privilege is not extended, and the next timing cycle is not started.

[0052] In another case of this embodiment, during the process of the node device identifying whether the user is accessing the database by extracting background data, if during the entire recognition process, the data file retrieved by the retrieval software is always the same data file, then step S404 is executed.

[0053] In step S404, it is judged by the background of the node device whether the same content of the same data file is always retrieved during the entire recognition process. If during the entire recognition process, the same content of the same data file is always retrieved, then it is judged that the user is not accessing the database.

[0054] In another preferred embodiment of the present invention, the timing cycle includes a verification cycle and a buffer cycle. The verification cycle and the buffer cycle are carried out alternately, and the first timing cycle is the verification cycle.

[0055] And in this embodiment, at the start moment of the verification cycle, the server sends verification information to the node device. And after the timer receives the timing instruction, the current verification cycle is terminated, the timer is reset to zero and then enters the buffer cycle. After the buffer cycle ends, it is automatically reset to zero and enters the verification cycle.

[0056] It should be noted that in the embodiment, the timing cycle is divided into two parts: the verification cycle and the buffer cycle. The server sends verification information to the node device at the beginning stage of the verification cycle, and the node device identifies whether it is accessing the database during the verification cycle. If no judgment result of accessing the database is obtained after the verification cycle ends, then the timing ends, the timer does not enter the next timing cycle, and the access privilege of the node device is terminated; while when the node device obtains an output of accessing the database, the verification cycle ends, the timer directly enters the buffer cycle, and after the buffer cycle ends, it is automatically reset to zero and enters the verification cycle, thus repeating the above process.

[0057] It can be understood that by dividing the timing cycle into a verification cycle and a buffer cycle, the verification process can be separated from the timing loop independently. As long as a timing instruction is obtained, the verification cycle automatically resets to zero and enters the buffer cycle. Compared with using the same timing cycle for looping, this is more flexible, has higher sensitivity, and is more responsive, thus avoiding processing delays.

[0058] In one case of this embodiment, if the timer still has not received a timing instruction after the verification cycle ends, the timer is stopped and the timer does not enter the next timing cycle.

[0059] A database binding system includes:

[0060] A database for storing data;

[0061] A node device for extracting the identity information of a user;

[0062] An identity recognition module that completes the identity recognition of the user through the identity information extracted by the node device, thereby determining whether the user has the right to access the database;

[0063] A timing module that uses a preset time value as the timing cycle, and the timer resets to zero after reaching the preset time value;

[0064] A server that sends verification information to the node device and determines whether to grant the node device the permission to access the database based on whether the node device is accessing the database.

[0065] The above has described a detailed description of an embodiment of the present invention, but the content described is only a preferred embodiment of the present invention and cannot be considered as used to limit the scope of implementation of the present invention. All equivalent changes and improvements made according to the scope of the present invention application should still fall within the scope covered by the patent of the present invention.

Claims

1. A database binding method, characterized in that, Including the following steps: The node device obtains the identity information to complete the user's identity recognition. The identity information includes the user's identity ID, facial image, and node ID; The server obtains the information of the node device through the node ID and temporarily grants the node device access permission. The access permission allows the node device to access the data files inside the database; A timer is built with a preset time value as the timing period. The timer resets to zero after reaching the preset time value; The server sends verification information to the node device. The verification information includes an access instruction and a timing instruction. The node device identifies whether the user is accessing the database by extracting background data. If the user is accessing the database, the node device extracts the access instruction and the timing instruction in the verification information respectively; The node device sends the access instruction and the timing instruction to the server and the timer respectively. After receiving the access instruction, the server extends the access permission of the node device until the end of the next timing period. After receiving the timing instruction, the timer starts the next timing period after completing the current timing period; 2. The database binding method according to claim 1, wherein The process of the server sending the verification information is intermittent, and its sending frequency corresponds to the timing period. The verification information is sent to the node device at the start moment of each timing period; 3. The database binding method according to claim 1, wherein The timing period includes a verification period and a buffer period. The verification period and the buffer period alternate, and the first timing period is the verification period; 4. The database binding method according to claim 3, wherein At the start moment of the verification period, the server sends verification information to the node device. After the timer receives the timing instruction, the current verification period is terminated, the timer is reset to zero and enters the buffer period. After the buffer period ends, it automatically resets to zero and enters the verification period; 5. A database binding method according to claim 1, characterized in that If the timer does not receive the timing instruction after the verification period ends, the timer is stopped and no longer enters the next timing period; 6. A database binding method according to claim 1, characterized in that In the process of the node device identifying whether the user is accessing the database by extracting background data, it specifically includes the following steps: Judge whether the node device is running the corresponding viewing software; Judge whether the viewing software is viewing the data files in the database; During the whole recognition process, judge whether the data file viewed by the viewing software is always the same data file; 7. A database binding method according to claim 6, wherein In the process of the node device identifying whether the user is accessing the database by extracting background data, if during the whole recognition process, the data file viewed by the viewing software is always the same data file, then judge through the node device background whether the same content of the same data file is always viewed during the whole recognition process. If during the whole recognition process, the same content of the same data file is always viewed, then it is determined that the user is not accessing the database; 8. A database binding system, characterized in that Including: A database for storing data; A node device for extracting the user's identity information, identifying whether the user is accessing the database after reading the verification information sent by the server, and sending an instruction to the server to extend the permission to access the database when the user is accessing the database; An identity recognition module that completes the identity recognition of a user through the identity information extracted by the node device, so as to determine whether the user has the right to access the database; A timing module that uses a preset time value as the timing period, and the timer resets after reaching the preset time value; A server that, after the identity recognition module determines that the user has the right to access the database, obtains the information of the node device through the node ID and temporarily grants the node device the permission to access the database; when the timer resets, it sends a verification message to the node device and decides whether to continue the permission of the node device to access the database according to whether the node device is accessing the database.

Citation Information

Patent Citations

  • A Face-To-Face Identity Verification System

    AU2014239871A1

  • Fingerprint identification-based question search method and apparatus

    CN107301340A