Classification hierarchical labeling method, device and data access control system

By implementing data-level classification and grading annotation, the technical problems in existing technologies have been solved, and automatic data-level annotation has been achieved. This has resolved the issues of coarse data grading and lack of fine granularity.

CN115309840BActive Publication Date: 2026-05-08BEIJING CONGYUN TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BEIJING CONGYUN TECH CO LTD
Filing Date
2022-08-29
Publication Date
2026-05-08

AI Technical Summary

Technical Problem

Existing technologies have coarse data classification, failing to achieve fine-grained data-level granularity, and access control can only reach the business server IP level and database account level, failing to reach the actual user level of the business server.

Method used

By receiving data structure information from the zero-trust database gateway, attribute-level and/or data-level classification and grading annotations are performed, classification and grading attribute columns are added, and corresponding classification and grading attribute values ​​are filled into the classification and grading attribute columns corresponding to the annotated data, thereby achieving data-level annotation.

Benefits of technology

Automatic data-level annotation has been achieved, solving the technical problems in existing technologies and data classification methods. Through automatic data-level annotation, the technical problems of data classification methods have been solved, and the problems of coarse and lack of fine granularity in data classification have been resolved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115309840B_ABST
    Figure CN115309840B_ABST
Patent Text Reader

Abstract

The application relates to a classification and grading marking method and device and a data access control system, and relates to the technical field of data security. The classification and grading marking method is used for performing attribute level and / or data level classification and grading marking according to a data structure table and a data table in target database scanning information sent by a zero-trust database gateway, and the classification and grading marking result is sent to the zero-trust database gateway, so that the zero-trust database gateway performs data level marking. Therefore, automatic marking of the data level is realized through the classification and grading marking device, and the technical problems of coarse data grading and missing granularity in the prior art are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data security technology, specifically to a classification and grading labeling method, device, and data access control system. Background Technology

[0002] Technological advancements have driven continuous progress in network technology. Before accessing data, users use Single Packet Authorization (SPA) technology to gain access to the application server. After successful authorization, during the user's access to the application server, the zero-trust platform comprehensively assesses the user's identity credibility and risk through terminal security awareness, access behavior collection and analysis capabilities, and the security status of the target application server. This allows for dynamic permission granting or demotion, providing more refined and rapid automated risk response capabilities for application scenarios.

[0003] To enhance information security, information service providers typically classify and grade data according to national, industry, and other data classification and grading standards. This allows them to provide users with appropriate minimum access permissions, reducing incidents of unauthorized access, leaks, and violations of citizens' privacy. Data anonymization is a commonly used data security technique in this field. However, regarding database visitor identification, existing dynamic database anonymization products primarily anonymize query data generated by the connection based on the application server's IP address and database account. This only achieves application server-level permission identification and control, failing to reach the user level at the business layer. Furthermore, existing data classification and grading products typically classify and grade databases, tables, and table attributes, only at the column level, not the data level, making it difficult to meet the needs of high-security application scenarios.

[0004] Therefore, existing technologies suffer from the technical problem of coarse data grading and lack of fine granularity. Summary of the Invention

[0005] In view of this, the purpose of the present invention is to provide a classification and grading labeling method, device and data access control system to overcome the current problems of coarse data grading and lack of fine granularity.

[0006] To achieve the above objectives, the present invention adopts the following technical solution:

[0007] On the one hand, a classification and grading labeling method includes:

[0008] Receive target database scanning information sent by a zero-trust database gateway, wherein the target database scanning information includes the target database's data structure table and data table;

[0009] The data structure table and data table are categorized and labeled at the attribute level and / or data level, and the categorization and labeling results are sent to the zero-trust database gateway. The zero-trust data gateway adds categorization and labeling attribute columns corresponding to the labeled data to the data structure table and / or data table according to the categorization and labeling results, and fills the corresponding categorization and labeling attribute columns with corresponding categorization and labeling attribute values ​​to complete the data-level labeling.

[0010] In another aspect, a data access control system includes: a business server, a zero-trust database gateway, a zero-trust controller, and a classification and grading labeling device; the classification and grading labeling device is used to execute the classification and grading labeling method described above.

[0011] The business server is used to access the target database through the zero-trust database gateway;

[0012] The zero-trust controller is used to configure the user's classification and hierarchical permissions according to the configuration operation; and after the user successfully logs in, it sends the classification and hierarchical permissions of the successfully logged-in user to the zero-trust gateway and the zero-trust database gateway, so that the successfully logged-in user can access the business server with the classification and hierarchical permissions.

[0013] The zero-trust database gateway is used to receive query requests sent by the business server, the query requests carrying user identity information for adding query conditions; parse the query requests, remove the query conditions, and obtain the real user identity information; query information in the target database based on the real user identity information, and send the query results to the business server.

[0014] Optionally, the zero-trust data gateway is further configured to: convert the classification and grading attribute values ​​into integers based on preset rules.

[0015] Optionally, the zero-trust database gateway is specifically used to receive query results, de-identify the query results according to the classification and hierarchical permissions corresponding to the user identity information, and send the de-identified results to the business server.

[0016] Optionally, the zero-trust database gateway is specifically used to complete the permission screening conditions in the query request according to the classification and hierarchical permissions corresponding to the real user identity information, query information in the target database according to the completed query request, receive the query results, and send the query results to the business server.

[0017] Optionally, the zero-trust controller is further configured to: reduce the user's classification and hierarchical permission level when an abnormal situation occurs; and send the reduced classification and hierarchical permission level to the zero-trust gateway and the zero-trust database gateway.

[0018] Optionally, the abnormal situations include: the business server being attacked, the user terminal being attacked, and abnormal user access behavior.

[0019] Optionally, the zero-trust controller is further configured to: determine whether the abnormal situation has ended, restore the user's classification and hierarchical permission level when the abnormal situation ends, and send the restored classification and hierarchical permission level to the zero-trust gateway and the zero-trust database gateway.

[0020] On another front, a classification and grading labeling device includes: a processor and a memory, wherein the processor is connected to the memory.

[0021] The processor is used to call and execute the program stored in the memory;

[0022] The memory is used to store the program, which is at least used to execute the classification and grading labeling method described above.

[0023] The technical solution provided by this invention has at least the following beneficial effects:

[0024] The technical solution provided by this invention utilizes a classification and grading annotation device to perform attribute-level and / or data-level classification and grading annotation based on the data structure tables and data tables in the target database scan information sent by a zero-trust database gateway. The classification and grading annotation results are then sent to the zero-trust database gateway for data-level annotation. Therefore, by achieving automatic data-level annotation through the classification and grading annotation device, the technical problems of coarse data grading and lack of fine granularity in existing technologies are solved. Attached Figure Description

[0025] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0026] Figure 1 This is a flowchart illustrating a classification and grading labeling method provided in an embodiment of the present invention;

[0027] Figure 2 This is a schematic diagram of the structure of a classification and grading labeling device provided in an embodiment of the present invention;

[0028] Figure 3 This is a schematic diagram of the structure of a data access control system provided in an embodiment of the present invention. Detailed Implementation

[0029] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be described in detail below. Obviously, the described embodiments are merely some embodiments of this invention, and not all embodiments. Based on the embodiments of this invention, all other implementation methods obtained by those skilled in the art without creative effort are within the scope of protection of this invention.

[0030] From the perspective of database visitor identification, existing dynamic database anonymization products primarily anonymize query data generated by the connection based on the application server IP address and database account. This only achieves application server-level permission identification and control, failing to reach the user level at the business layer. From the perspective of database data annotation, existing data classification and grading products typically classify and grade databases, tables, and table attributes, only at the column level, not the data level, making it difficult to meet the needs of some high-security application scenarios.

[0031] Therefore, existing technologies suffer from the technical problem of coarse data grading and lack of fine granularity.

[0032] Data masking is currently mainly used in scenarios such as application servers and databases, and database access by developers / operations personnel. Data masking is further divided into two main techniques: static masking and dynamic masking. Static masking is primarily used in scenarios such as database copying and transferring data from production to development databases. Dynamic masking is mainly used in real-time data protection scenarios, such as between application servers and databases.

[0033] From the perspective of database data annotation, existing data classification and grading products typically classify and grade data at the database, table, and table attributes levels. However, in some high-security application scenarios, different data rows within the same table may have different access permissions. Therefore, traditional solutions only classify and grade database data at the column level, failing to achieve the data level.

[0034] Meanwhile, existing data security products typically implement static data authorization for visitors based on permission policy mapping configuration, but cannot dynamically update the authorization policy based on dynamic factors such as the visitor's current security environment, whether they have been attacked, and whether they are still trustworthy.

[0035] Based on this, embodiments of the present invention provide a classification and grading labeling method, system, and data access control system.

[0036] First, in the embodiments of this application, the data classification and grading technology and the dynamic data desensitization technology of the database are briefly introduced.

[0037] Existing database classification and grading products mainly obtain the attribute names of databases, tables, and columns through database table scanning and structure scanning, and use these to establish database ledgers. The classification and grading labeling of data is mainly completed outside the business database.

[0038] Dynamic data masking technology for databases: Architecturally, current data access control primarily achieves this through dynamic data masking. CNC dynamic masking technology mainly employs a database proxy model, where the masking component / service runs independently, and the business server accesses the real database through the masking component. During the SQL (Structured Query Language) request phase, the database masking component initializes masking strategy rules based on whether the SQL query is a query and the accessed database table. According to these rules, the data returned by the SQL query is parsed, and then the corresponding dynamic masking algorithm is applied based on the column attribute types to perform masking. The data masking strategy rules are defined at the granularity of the application server IP, account, etc., from which the SQL query originated.

[0039] Therefore, in existing technical solutions, implementation through third-party components is currently the mainstream approach, satisfying general data anonymization scenarios but unsuitable for specific high-security scenarios. It suffers from the following drawbacks: data annotation granularity is limited to the column level, not the data level; access control granularity is limited to the business server IP and database account levels, not the actual user level on the business server.

[0040] Figure 1 This is a flowchart illustrating a classification and grading labeling method provided in an embodiment of the present invention. (See attached diagram.) Figure 1 The classification and grading labeling method provided in this embodiment of the invention may include the following steps:

[0041] Step S11: Receive the target database scan information sent by the zero-trust database gateway. The target database scan information includes the data structure table and data table of the target database.

[0042] In this application, the executing entity can be a classification and grading labeling device, wherein the database to be accessed can be defined as the target database.

[0043] Specifically, a zero-trust database gateway can be deployed in a bypass configuration within the user server area. It establishes connections with specified target databases by configuring database access information; these target databases can be one or more databases. Administrator access to the database is required during the connection establishment process. After the connection is established, the zero-trust data gateway performs table structure and data scanning operations, sending the scanned target database's data structure tables and data tables to the classification and labeling device.

[0044] For example, the scanned data structure table is shown in Table 1, and the data table is shown in Table 2:

[0045] Table 1 Data Structure Table

[0046] Attribute Name type Remark Name Varchar(32) User Name Age int(2) age Phone Varchar(32) telephone number Email Varchar(64) Email address

[0047] Table 2 Data Table

[0048]

[0049]

[0050] Step S12: Perform attribute-level and / or data-level classification and grading annotations on the data structure table and data table, and send the classification and grading annotation results to the zero-trust database gateway. This allows the zero-trust data gateway to add classification and grading attribute columns corresponding to the annotated data to the data structure table and / or data table based on the classification and grading annotation results, and to fill the corresponding classification and grading attribute columns with the corresponding classification and grading attribute values, thus completing the data-level annotation.

[0051] It's worth noting that administrators can manually classify and label data on the classification and grading labeling device, or they can configure the device to automatically classify and label data. This allows for attribute-level and / or data-level classification and grading of data structure tables and data tables. When performing classification and grading labeling, categories and grades can be labeled separately.

[0052] For example, annotation methods can be divided into attribute-level annotation and data-level annotation. When annotating an attribute of a data structure table, all data of that attribute are simultaneously assigned the classification and grading value of that annotation. When annotating a specific attribute of a single data record in a data table, the annotation value of that specific attribute will override the standard value at the column level.

[0053] For example, Table 3 is a labeled data table provided in an embodiment of this application.

[0054] Table 3 shows the labeled data.

[0055] Name Age [G1_5] Phone [G2_10] Email Zhang San 20[G1_6] 13888888888 zhangsan@a.com Li Si 25 18077776666[G2_12] lisi@a.com Wang Er 30 13688885555 wanger@a.com

[0056] Refer to Table 3, where 【】 represents attribute-level annotation and [] represents data-level annotation; if no data-level annotation is performed, the value of the attribute-level annotation will be used; data that does not need protection can also be left unannotated, such as the Email field.

[0057] In the annotations, G represents a category, with G1 and G2 representing different data categories. The number after "-" indicates the level. G1-5 represents category 1, level 5. Users can also set annotation standards according to their needs.

[0058] After the classification and grading annotation device completes the annotation, it sends the annotation results to the zero-trust database gateway. Upon receiving the data classification and grading annotation results, the zero-trust database gateway adds a classification and grading attribute column for the data to the corresponding table and fills the corresponding classification and grading attribute value into the column, thus completing the data-level annotation. For example, refer to Table 4, which is a data table annotated by the zero-trust database gateway according to an embodiment of the present invention.

[0059] Table 4

[0060] Name Age Phone Email Age_L Phone_L Zhang San 20 13888888888 zhangsan@a.com 16(G1_6) (110)G2_10 Li Si 25 18077776666 lisi@a.com 15(G1_5) (112)G2_12 Wang Er 30 13688885555 wanger@a.com 15(G1_5) (110)G2_10

[0061] Adding the suffix "_L" to the original attribute column name indicates that it is a category / level attribute column corresponding to that attribute column. Refer to Table 4, where Age_L is the category / level label column added to the Age attribute column, and Phone_L is the category / level label column added to the Phone attribute column. Furthermore, to facilitate level calculation, the category / level values ​​are uniformly converted to integer levels according to certain rules.

[0062] In some embodiments, the zero-trust data gateway is further configured to: convert classification and grading attribute values ​​into integers based on preset rules.

[0063] For example, to avoid ranking conflicts, there are relatively large differences between different categories, and the category to which a value belongs can be intuitively distinguished based on the magnitude of the value. For example, G1=10, G2=100, G3=1000, etc. For example, G1-6 can be converted to 10+6=16, and G2-10 can be converted to 1000+10=1010.

[0064] It is understood that, using the technical solution provided by this invention, the classification and grading annotation device performs attribute-level and / or data-level classification and grading annotation based on the data structure tables and data tables in the target database scan information sent by the zero-trust database gateway, and sends the classification and grading annotation results to the zero-trust database gateway so that the zero-trust database gateway can perform data-level annotation. Therefore, by achieving automatic data-level annotation through the classification and grading annotation device, the technical problems of coarse data grading and lack of fine granularity in the prior art are solved.

[0065] Based on a general inventive concept, embodiments of the present invention also provide a classification and grading labeling device.

[0066] Figure 2 This is a schematic diagram of a classification and grading labeling device provided in an embodiment of the present invention, used to implement the above-described method embodiments. Figure 2As shown, the classification and grading labeling device of this embodiment includes a processor 21 and a memory 22, with the processor 21 connected to the memory 22. The processor 21 is used to call and execute the program stored in the memory 22; the memory 22 is used to store the program, which is at least used to execute the classification and grading labeling device method in the above embodiments.

[0067] The specific implementation scheme of the classification and grading labeling device provided in this application can be referred to the implementation scheme of the classification and grading labeling method in any of the above embodiments, and will not be repeated here.

[0068] Based on a general inventive concept, embodiments of the present invention also provide a data access control system.

[0069] Figure 3 This is a schematic diagram of a data access control system provided in an embodiment of the present invention. (See attached diagram.) Figure 3 The system provided in this application embodiment may include the following structure:

[0070] The system includes a business server 31, a zero-trust database gateway 32, a zero-trust controller 33, and a classification and grading labeling device 34; the classification and grading labeling device is used to execute the classification and grading labeling method described in the above embodiments.

[0071] The business server is used to access the target database A through a zero-trust database gateway;

[0072] The Zero Trust Controller is used to configure user classification and hierarchical permissions based on the configuration operation; and after a user successfully logs in, it sends the classification and hierarchical permissions of the successfully logged-in user to the Zero Trust Gateway and the Zero Trust Database Gateway, so that the successfully logged-in user can access the business server with the classification and hierarchical permissions.

[0073] The zero-trust database gateway is used to receive query requests sent by business servers, which carry user identity information for adding query conditions; parse the query request, remove the query conditions, and obtain the real user identity information; query information in the target database based on the real user identity information, and send the query results to the business server.

[0074] This allows adjusting the business server access configuration to the target database. For example, the original service address of the target database is: 192.168.100.1:3306

[0075] Business server username / password: a / 123456

[0076] Administrator account / password: admin / 123456

[0077] The Zero Trust Database Gateway service address is: 192.168.100.2:3307

[0078] Business server account / password: b / 123456

[0079] Configure the database information for the zero-trust database gateway proxy as follows: 192.168.100.1:3306,admin / 123456

[0080] Modify the target database connection information of the business server:

[0081] If 192.168.100.1:3306,a / 123456 is replaced by 192.168.100.2:3307,b / 123456, then subsequent database access to the business server will be completed through a zero-trust database gateway proxy.

[0082] In this application, categorized and hierarchical permissions for authorized users can be configured on the zero-trust controller. For example, admin1 (G1_5) means that administrator admin1 has access to data at level 5 and below in category G1; admin2 (G1_10,G2_10) means that administrator admin2 has access to data at level 10 in category G1 and level 10 and below in category G2.

[0083] After administrators admin1 and admin2 log in through the Zero Trust Controller, the Zero Trust Controller sends the user's data authorization configuration to the Zero Trust Gateway and the Zero Trust Database Gateway:

[0084] admin1(G1_5,G2_0), where G2_0 is automatically added, indicating that the user does not have permission for this category;

[0085] admin2(G1_10,G2_10).

[0086] Administrators admin1 and admin2 access the business server according to the marked category and hierarchical permissions.

[0087] After receiving a query request from the business server, the zero-trust database gateway removes the query conditions, obtains the real user identity information, queries the target database based on the real user identity information, and sends the query results to the business server.

[0088] In some embodiments, the zero-trust database gateway is specifically used to receive query results, de-identify the query results according to the classification and hierarchical permissions corresponding to the user's identity information, and send the de-identified results to the business server.

[0089] Specifically, the business server sends a query request via SQL. Based on the session (session control) and other factors, the business server obtains the username that triggered the current business SQL, adds the specified query conditions, and retrieves the user information through the SQL query conditions.

[0090] For example, the original query request was:

[0091] Query the list of users (SELECT * FROM USER)

[0092] When Administrator 1 uses it, the generated SQL statement is:

[0093] SELECT*FROM USER WHERE reqUserName=`admin1`

[0094] When Administrator 2 used the service, a conditional query was performed, resulting in the following SQL statement:

[0095] SELECT*FROM USER WHERE age>=20AND reqUserName=`admin2`

[0096] Here, reqUserName is the added specified query condition. reqUserName can identify the user's identity information. The zero-trust database gateway parses the SQL statement, parses the current real application server access user name according to the specified query condition, removes the condition from the SQL statement, and then forwards it to the database.

[0097] For example, when Administrator 1's SQL statement reaches the zero-trust database gateway, after analysis, the real user accessing this SQL statement is admin1, based on the reqUserName attribute. After removing redundant conditions, the SQL statement is restored to: SELECT * FROM USER.

[0098] The same method was used to identify Administrator 2's SQL statement. After processing, the recovered SQL statement was:

[0099] SELECT*FROM USER WHERE age>=20.

[0100] The zero-trust database gateway intercepts the final query results of the database, obtains the user's classification and hierarchical permissions based on the current user's identity, and performs dynamic de-identification processing on the query results based on the values ​​of the classification and hierarchical attribute columns. For data values ​​that do not meet the permission requirements, different dynamic de-identification algorithms are selected according to different attribute types and business meanings to perform dynamic de-identification processing, and the processed data is repackaged and returned to the business server.

[0101] For example, for administrator 1 with permission (G1_5), the data returned by the SQL request is processed according to administrator 1's permissions. After dynamically desensitizing the specified fields and automatically removing the marked columns, the result is shown in Table 5:

[0102] Table 5

[0103] Name Age Phone Email Zhang San 0 138****8888 zhangsan@a.com Li Si 25 180****6666 lisi@a.com Wang Er 30 136****5555 wanger@a.com

[0104] Refer to Table 5. Fields in bold are those that meet the criteria, and those on italics are those that have undergone dynamic desensitization.

[0105] For administrator 2, with permissions (G1_10, G2_10), the results of dynamic data masking for data that does not meet the permission requirements are shown in Table 6:

[0106] Table 6

[0107] Name Age Phone Email Zhang San 20 13888888888 zhangsan@a.com Li Si 25 180****6666 lisi@a.com Wang Er 30 13688885555 wanger@a.com

[0108] Refer to Table 6. Fields in bold are those that meet the criteria, and those in italics are those that have undergone dynamic desensitization.

[0109] In some embodiments, the zero-trust database gateway is specifically used to complete the permission screening conditions in the query request based on the classification and hierarchical permissions corresponding to the real user identity information, query information in the target database according to the completed query request, receive the query results, and send the query results to the business server.

[0110] When highly sensitive data exists in the same table because it belongs to the same business, or when different entity objects have different security levels, and the entity data cannot be accessed if not all attributes are available, row-level access control can be implemented to ensure data security. That is, if a single attribute does not meet the permission requirements, the entire row of data will not be returned.

[0111] Specifically, the zero-trust database gateway parses the SQL, extracts the actual username of the application server accessing the database based on the specified query conditions, removes the condition from the SQL statement, and then forwards it to the database. If the query request contains empty information, such as "*", it is automatically replaced with all the actual data column names of the table.

[0112] For example, when Administrator 1's SQL statement reaches the zero-trust database gateway, after analysis, the actual user accessing the SQL statement is determined to be admin1 based on the reqUserName attribute. Based on admin1's permission G1_5 (with a calculated value of 15), redundant conditions are removed, and the permission screening conditions are completed, the SQL statement becomes:

[0113] SELECT Name,Age,Phone,Email FROM USER WHERE Age_L<=15AND Phone_L<=1000.

[0114] The same method was used to identify Administrator 2's SQL statement. Based on their permissions G1_10 (corresponding calculated value 10+10=20) and G2_12 (1012), and after removing redundant conditions and completing the permission screening conditions, the SQL statement is as follows:

[0115] SELECT Name,Age,Phone,Email FROM USER WHERE age>=20AND Age_L<=20ANDPhone_L<=1020.

[0116] The target database's mechanism will automatically filter out columns that do not meet the query conditions, and will not parse or process the returned data content in this case, but will directly return it to the business server.

[0117] For Administrator 1, with permissions (G1_5), the data returned by the SQL request is processed according to Administrator 1's permissions. After dynamically desensitizing the specified fields and automatically removing the marked columns, the result is as follows:

[0118] Table 7

[0119] Name Age Phone Email

[0120] Referring to Table 7, since the permissions are not satisfied in the specified columns, the returned data is empty.

[0121] For administrator 2, with permissions (G1_10, G2_10), the results of dynamic data masking for data that does not meet the permission requirements are shown in Table 8:

[0122] Table 8

[0123] Name Age Phone Email Zhang San 20 13888888888 zhangsan@a.com Wang Er 30 13688885555 wanger@a.com

[0124] Referring to Table 8, no results were returned because one of Li Si's attribute columns did not meet the permission requirements.

[0125] In some embodiments, the zero-trust controller is further configured to: reduce the user's classification and hierarchical permission level when an abnormal situation occurs; and send the reduced classification and hierarchical permission level to the zero-trust gateway and the zero-trust database gateway.

[0126] In some embodiments, abnormal situations include: the business server being attacked, the user terminal being attacked, and abnormal user access behavior.

[0127] For example, when the Zero Trust Controller detects that the application server or user terminal has been attacked, or that the user's access behavior is abnormal, it automatically reduces the user's access authorization, such as reducing the authorization of Administrator 1 from G1-5 to G1-1. The updated authorization rules are then sent to the Zero Trust Database Gateway, which takes effect immediately and automatically uses the updated permissions to control access for subsequent requests, without requiring any cooperation from the administrator or the application server.

[0128] In some embodiments, the zero-trust controller is further configured to: determine whether the abnormal situation has ended; if the abnormal situation has ended, restore the user's classification and hierarchical permission level, and send the restored classification and hierarchical permission level to the zero-trust gateway and the zero-trust database gateway.

[0129] For example, when the Zero Trust controller detects that the risk has been eliminated, it can automatically restore the authorization of Administrator 1: G1-1 becomes G1-5. After the authorization is updated to the Zero Trust gateway, the administrator can restore access to the relevant data without any cooperation from the administrator or the application server.

[0130] It is understood that in the technical solution provided in this application, the data stored in the target database remains intact, and the data obtained by the user is different depending on the user's identity when accessing the target database; when the user's identity or user permissions change, the obtained data changes accordingly, thereby achieving dynamic desensitization.

[0131] The technical solution described in this application achieves data-level classification and grading annotation by automatically adding annotation columns, solving the problem of insufficient granularity in current classification and grading systems. By adding specific query conditions, it enables the application server to transparently transmit real user information, addressing the limitation of previous database protection components that only achieved server IP and database account-level access control, thus better meeting the fine-grained user-level requirements of the current zero-trust environment. Through row-level data anonymization, it meets performance and security requirements in both high-security and high-performance scenarios, combining the database's inherent capabilities, unlike the typical approach of dynamically anonymizing data after it's returned by the database. By analyzing the classification and grading attribute columns in the database through data-level anonymization, it addresses the challenges and fine-grained issues of storing large-scale data classification and grading rules, better ensuring users' access to data with minimal privileges. This aligns with the zero-trust principle that all components, including the application server itself, are untrusted, further ensuring data security.

[0132] It is understood that the same or similar parts in the above embodiments can be referred to each other, and the contents not described in detail in some embodiments can be referred to the same or similar contents in other embodiments.

[0133] It should be noted that in the description of this invention, the terms "first," "second," etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance. Furthermore, in the description of this invention, unless otherwise stated, "a plurality of" means at least two.

[0134] Any process or method description in the flowchart or otherwise herein can be understood as representing a module, segment, or portion of code comprising one or more executable instructions for implementing a particular logical function or process, and the scope of the preferred embodiments of the invention includes additional implementations in which functions may be performed not in the order shown or discussed, including substantially simultaneously or in reverse order depending on the functions involved, as will be understood by those skilled in the art to which embodiments of the invention pertain.

[0135] It should be understood that various parts of the present invention can be implemented in hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented in software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.

[0136] Those skilled in the art will understand that all or part of the steps of the methods in the above embodiments can be implemented by a program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, the program includes one or a combination of the steps of the method embodiments.

[0137] Furthermore, the functional units in the various embodiments of the present invention can be integrated into a processing module, or each unit can exist physically separately, or two or more units can be integrated into a module. The integrated module can be implemented in hardware or as a software functional module. If the integrated module is implemented as a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium.

[0138] The storage media mentioned above can be read-only memory, disk, or optical disk, etc.

[0139] In the description of this specification, references to terms such as "one embodiment," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.

[0140] Although embodiments of the present invention have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting the present invention. Those skilled in the art can make changes, modifications, substitutions and variations to the above embodiments within the scope of the present invention.

Claims

1. A classification and grading labeling method, characterized in that, include: Receive target database scanning information sent by a zero-trust database gateway, wherein the target database scanning information includes the target database's data structure table and data table; The method involves classifying and labeling the data structure table and data table at the attribute level and / or data level, and sending the classification and labeling results to a zero-trust database gateway. The zero-trust database gateway then adds classification and labeling attribute columns corresponding to the labeled data to the data structure table and / or data table based on the classification and labeling results, and fills the corresponding classification and labeling attribute columns with corresponding classification and labeling attribute values, thus completing the data-level labeling. The method further includes: the zero-trust database gateway receiving a query request carrying user identity information with added query conditions; parsing the query request to remove the query conditions and obtain the real user identity information; and, based on the classification and labeling permissions corresponding to the real user identity information, supplementing the query request with permission screening conditions based on the classification and labeling attribute columns, and querying information in the target database based on the supplemented query request; furthermore, in the event of an anomaly, lowering the user's classification and labeling permission level; and restoring the user's classification and labeling permission level when the anomaly ends; wherein the classification and labeling permissions are dynamically changing permissions used by the zero-trust database gateway to supplement the permission screening conditions in the query request.

2. A data access control system, characterized in that, include: Business servers, zero-trust database gateways, zero-trust controllers, and classification and grading labeling devices; The classification and grading labeling device is used to perform the classification and grading labeling method as described in claim 1; The business server is used to access the target database through the zero-trust database gateway; The zero-trust controller is configured to configure user classification and hierarchical permissions according to the configuration operation, and to send the classification and hierarchical permissions of the successfully logged-in user to the zero-trust gateway and the zero-trust database gateway after the user successfully logs in, so that the successfully logged-in user can access the business server with the classification and hierarchical permissions. It is also configured to reduce the user's classification and hierarchical permission level when an abnormal situation occurs, and restore the user's classification and hierarchical permission level when the abnormal situation ends, and send the reduced or restored classification and hierarchical permission level to the zero-trust database gateway. The zero-trust database gateway is used to receive query requests sent by the business server, the query requests carrying user identity information for adding query conditions; parse the query requests, remove the query conditions, and obtain the real user identity information; And based on the classification and hierarchical permissions corresponding to the real user identity information, the permission screening conditions based on the classification and hierarchical attribute columns are supplemented in the query request, and the information is queried in the target database according to the supplemented query request, so as to send the query results to the business server.

3. The system according to claim 2, characterized in that, The zero-trust data gateway is further configured to: convert the classification and grading attribute values ​​into integers based on preset rules.

4. The system according to claim 2, characterized in that, The zero-trust database gateway is specifically used to receive query results, de-identify the query results according to the classification and hierarchical permissions corresponding to the user identity information, and send the de-identified results to the business server.

5. The system according to claim 2, characterized in that, The abnormal situations include: the business server being attacked, the user terminal being attacked, and abnormal user access behavior.

6. A classification and grading labeling device, characterized in that, include: A processor and a memory, wherein the processor is connected to the memory: wherein the processor is used to call and execute a program stored in the memory; The memory is used to store the program, which is at least used to execute the classification and grading labeling method according to claim 1.

Citation Information

Patent Citations

  • Security exchange method and system for internetwork data

    CN108449324A

  • Database fine-grained access control method based on zero-trust architecture

    CN113051602A