An asset access control method and device, electronic equipment and storage medium

CN115860476BActive Publication Date: 2026-08-21BEIJING TOPSEC NETWORK SECURITY TECH +2
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202211574644.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-08
Publication Date
2026-08-21
Estimated Expiration
2042-12-08

AI Technical Summary

Technical Problem

[0003]然而,现有技术存在很多弊端,如对资产进行访问控制过程中的安全性较低,并且管理员的身份容易被冒用,对资产访问控制的时间长,效率低下,容易发生信息泄露等

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115860476B_ABST
    Figure CN115860476B_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide an asset access control method and device, electronic equipment and a storage medium, wherein the method comprises: obtaining a pre-configured asset list and user level information; dividing the trust level of an access terminal according to the user level information to obtain the trust level of the access terminal; and performing permission matching on the asset list according to the trust level, so that the access terminal accesses non-core assets in the asset list. By implementing the embodiments of the present application, the security in the asset access control process can be improved, the efficiency of asset access control can be improved, the permission of access control can be effectively prevented from being misused, and information leakage can be prevented.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and more specifically, to an asset access control method, apparatus, electronic device, and computer storage medium. Background Technology

[0002] As IT systems in enterprises and institutions become increasingly complex, network scale and the number of devices are also increasing dramatically. In these organizations, operations and maintenance (O&M) personnel often hold the highest privileges on IT systems, and their various actions can pose significant risks. Therefore, asset access control during O&M becomes crucial. Typically, O&M personnel need to log into the O&M audit system and perform relevant O&M operations only after being granted asset O&M permissions by the administrator, thus controlling access to assets.

[0003] However, existing technologies have many drawbacks, such as low security in the process of access control of assets, easy impersonation of administrators, long and inefficient access control of assets, and easy information leakage. Summary of the Invention

[0004] The purpose of this application is to provide an asset access control method, device, electronic device, and storage medium, which can improve the security and efficiency of asset access control, effectively prevent the misuse of access control permissions, and prevent information leakage.

[0005] In a first aspect, embodiments of this application provide an asset access control method, the method comprising:

[0006] Retrieve a pre-configured list of assets and user level information;

[0007] The trust level of the access terminal is obtained by classifying the access terminal according to the user level information.

[0008] Based on the trust level, the asset list is matched for permissions, so that the accessing terminal can access non-core assets in the asset list.

[0009] In the above implementation process, user trust levels are divided, and permissions are matched to the asset list according to the trust levels. This can accurately match users with the non-core assets they want to access, reduce the risks for users in the asset access control process, improve the security of asset access control, improve the efficiency of asset access control, effectively prevent the misuse of access control permissions, and prevent information leakage.

[0010] Furthermore, the step of pre-configuring the user level information includes:

[0011] Obtain information on the criteria for classifying user trust levels;

[0012] The evaluation cycle for obtaining user trust levels;

[0013] Risk weight values ​​are obtained based on the type and level of operation and maintenance rules.

[0014] The user level information is obtained based on the user trust level classification criteria, the assessment period, and the risk weight value.

[0015] In the above implementation process, user level information is differentiated in multiple ways based on classification criteria, assessment cycle, and risk weight values. This makes it easier for users to match the asset list they want to access from multiple dimensions, improves the user classification concept, and makes user level information more reasonable.

[0016] Further, the step of classifying the trust level of the access terminal based on the user level information to obtain the trust level of the access terminal includes:

[0017] The number of risky operations performed by the access terminal during the assessment period is obtained;

[0018] The user's risk assessment value is obtained based on the number of risky operations and the risk weight value.

[0019] The access terminal is classified into trust levels based on the user risk assessment value and the user trust level classification criteria to obtain the trust level of the access terminal.

[0020] In the above implementation process, the trust level of the access terminal is divided according to the user level information to avoid risky operations during the access process, improve security, and at the same time ensure the accuracy of the trust level division.

[0021] Further, the step of performing permission matching on the asset list based on the trust level to enable the access terminal to access non-core assets in the asset list includes:

[0022] Iterate through the asset list to obtain the operational assets;

[0023] Determine whether the operation and maintenance assets are non-core assets;

[0024] If so, the asset list is matched with permissions according to the trust level so that the access terminal can access the non-core assets.

[0025] In the above implementation process, non-core assets are extracted from the asset list, which makes it easier for the access terminal to access non-core assets more accurately, reduces the possibility of errors in the access control process, improves the access efficiency of the access terminal, and effectively shortens the access control time.

[0026] Further, the step of performing permission matching on the asset list based on the trust level to enable the access terminal to access the non-core assets includes:

[0027] Determine whether the access terminal is a trusted user based on the trust level;

[0028] If so, grant access permissions to the access terminal based on the non-core assets, so that the access terminal with the granted access permissions can access the non-core assets;

[0029] If not, grant temporary authorization to the accessing client to temporarily access the non-core assets.

[0030] In the above implementation process, judging whether the access terminal is trustworthy based on the trust level can further improve the rigor of the access terminal audit, prevent the access terminal from being misused, and prevent information leakage.

[0031] Furthermore, the step of temporarily authorizing the access terminal includes:

[0032] Determine whether the accessing client is a high-risk user;

[0033] If so, temporarily authorize the access terminal based on the trust level and the risk assessment value;

[0034] If not, the access terminal is determined to be a high-risk user, and access to the non-core assets is denied.

[0035] In the above implementation process, it is further determined whether the access terminal is a risky user or a high-risk user, and different access control processing is carried out on them respectively. Corresponding feedback can be given to access terminals with different trust levels, which is more flexible, can meet the needs of more access terminals, and is conducive to expanding the coverage of access terminals.

[0036] Secondly, embodiments of this application also provide an asset access control device, the device comprising:

[0037] The acquisition module retrieves a pre-configured list of assets and user level information.

[0038] The segmentation module classifies the access terminal based on the user level information to obtain the trust level of the access terminal.

[0039] The authorization module performs permission matching on the asset list based on the trust level, so that the access terminal can access non-core assets in the asset list.

[0040] In the above implementation process, user trust levels are divided, and permissions are matched to the asset list according to the trust levels. This can accurately match users with the non-core assets they want to access, reduce the risks for users in the asset access control process, improve the security of asset access control, improve the efficiency of asset access control, effectively prevent the misuse of access control permissions, and prevent information leakage.

[0041] Furthermore, the device also includes a configuration module for:

[0042] Obtain information on the criteria for classifying user trust levels;

[0043] The evaluation cycle for obtaining user trust levels;

[0044] Risk weight values ​​are obtained based on the type and level of operation and maintenance rules.

[0045] The user level information is obtained based on the user trust level classification criteria, the assessment period, and the risk weight value.

[0046] In the above implementation process, user level information is differentiated in multiple ways based on classification criteria, assessment cycle, and risk weight values. This makes it easier for users to match the asset list they want to access from multiple dimensions, improves the user classification concept, and makes user level information more reasonable.

[0047] Thirdly, an electronic device provided in this application includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the method as described in any of the first aspects.

[0048] Fourthly, embodiments of this application provide a computer-readable storage medium storing instructions that, when executed on a computer, cause the computer to perform the method described in any of the first aspects.

[0049] Fifthly, embodiments of this application provide a computer program product that, when run on a computer, causes the computer to perform the method described in any of the first aspects.

[0050] Other features and advantages of this disclosure will be set forth in the following description, or some features and advantages may be inferred from the description or determined without doubt, or may be learned by practicing the techniques described above.

[0051] It can be implemented in accordance with the contents of the specification. The preferred embodiments of this application are described in detail below with reference to the accompanying drawings. Attached Figure Description

[0052] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation on the range. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0053] Figure 1 A flowchart illustrating the asset access control method provided in this application embodiment;

[0054] Figure 2 A schematic diagram illustrating the structural composition of the asset access control device provided in this application embodiment;

[0055] Figure 3 This is a schematic diagram of the structural composition of the electronic device provided in the embodiments of this application. Detailed Implementation

[0056] The technical solutions in the embodiments of this application will now be described with reference to the accompanying drawings.

[0057] It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures. Furthermore, in the description of this application, terms such as "first," "second," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.

[0058] The specific embodiments of this application will be described in further detail below with reference to the accompanying drawings and examples. The following examples are used to illustrate this application, but are not intended to limit the scope of this application.

[0059] Example 1

[0060] Figure 1 This is a flowchart illustrating the asset access control method provided in this application embodiment, as shown below. Figure 1 As shown, the method includes:

[0061] S1, retrieve the pre-configured asset list and user level information;

[0062] S2, classify the trust level of the access terminal according to the user level information to obtain the trust level of the access terminal;

[0063] S3 performs permission matching on the asset list based on trust level, enabling the client to access non-core assets in the asset list.

[0064] In the above implementation process, user trust levels are divided, and permissions are matched to the asset list according to the trust levels. This can accurately match users with the non-core assets they want to access, reduce the risks for users in the asset access control process, improve the security of asset access control, improve the efficiency of asset access control, effectively prevent the misuse of access control permissions, and prevent information leakage.

[0065] This application defines the trust level of operation and maintenance users (access terminal in this application embodiment), dynamically divides the trust level of operation and maintenance users, and performs basic configuration, including the delineation of edge assets, setting of user trust level and setting of trust level assessment criteria, so as to realize access control of non-core assets (also known as edge assets).

[0066] In S1, the asset list is pre-set by the system (operations) administrator, which stores the assets managed during the operations and maintenance audit process (including non-core assets), and is manually added to the system by the system (operations) administrator according to business needs.

[0067] Furthermore, the step of pre-configuring user level information includes:

[0068] Obtain information on the criteria for classifying user trust levels;

[0069] The evaluation cycle for obtaining user trust levels;

[0070] Risk weight values ​​are obtained based on the type and level of operation and maintenance rules.

[0071] User level information is obtained based on the criteria for classifying user trust levels, the assessment period, and the risk weight value.

[0072] In the above implementation process, user level information is differentiated in multiple ways based on classification criteria, assessment cycle, and risk weight values. This makes it easier for users to match the asset list they want to access from multiple dimensions, improves the user classification concept, and makes user level information more reasonable.

[0073] The classification criteria include three levels: trusted users, risky users, and high-risk users. Optionally, the assessment period in this embodiment is 7 days by default, but it can be adjusted as needed.

[0074] Each trust level is divided according to a threshold. The relationship between trust level and threshold in this embodiment is shown in Table 1: (where x is the default threshold, i.e., the risk assessment value).

[0075] Table 1. Relationship between Trust Level and Threshold

[0076] Trusted users 0≤x<10 Risky users 10≤x<50 High-risk users x≥50

[0077] The corresponding risk weight value is obtained based on the type of operation and maintenance rule and its risk level. The relationship between the operation and maintenance rule type and the risk weight value is shown in Table 2.

[0078] Table 2 Relationship between Operation and Maintenance Rule Types and Risk Weight Values

[0079]

[0080]

[0081] Furthermore, S2 includes:

[0082] Get the number of risky operations performed by the accessing client during the assessment period;

[0083] The user's risk assessment value is obtained based on the number of risky operations and the risk weight value.

[0084] The trust level of the access terminal is determined by classifying the user's risk assessment value and the user trust level classification criteria.

[0085] In the above implementation process, the trust level of the access terminal is divided according to the user level information to avoid risky operations during the access process, improve security, and at the same time ensure the accuracy of the trust level division.

[0086] This application embodiment uses historical audit data of operation and maintenance users as a basis to periodically classify and evaluate users' trust levels.

[0087] In this embodiment, the initial trust level of a user is that of a high-risk user, and the trust level of all operation and maintenance users is periodically assessed according to the assessment cycle. In addition to calculating the user risk assessment value and determining the trust level for each user, it is also necessary to audit the user's historical data.

[0088] Specifically, the audit history data includes: categorized statistics on the number of risky operations performed by users in the previous assessment period, that is, the number of times user operations violated the operation and maintenance rules in that assessment period.

[0089] Calculation of user risk assessment value: Multiply the number of times different types of rules are hit by the corresponding risk weight value, and sum the weighted statistical results to obtain the user risk assessment value in the previous period.

[0090] Trust level determination: The trust level of operation and maintenance users is determined based on the threshold of trust level classification and the risk assessment value.

[0091] Furthermore, S3 includes:

[0092] Iterate through the asset list to obtain the operational assets;

[0093] Determine whether the assets under maintenance are non-core assets;

[0094] If so, the asset list is matched with permissions based on the trust level to allow the client to access the non-core assets.

[0095] In the above implementation process, non-core assets are extracted from the asset list, which makes it easier for the access terminal to access non-core assets more accurately, reduces the possibility of errors in the access control process, improves the access efficiency of the access terminal, and effectively shortens the access control time.

[0096] Furthermore, the steps of matching permissions on the asset list based on trust levels to enable access to non-core assets include:

[0097] Determine whether the accessing client is a trusted user based on the trust level;

[0098] If so, add access permissions to the accessing client based on the non-core assets, so that the accessing client with the added access permissions can access the non-core assets;

[0099] If not, grant temporary authorization to the accessing client to allow temporary access to non-core assets.

[0100] In the above implementation process, judging whether the access terminal is trustworthy based on the trust level can further improve the rigor of the access terminal audit, prevent the access terminal from being misused, and prevent information leakage.

[0101] Furthermore, the steps for granting temporary authorization to the accessing end include:

[0102] Determine whether the user accessing the service is a high-risk user;

[0103] If so, grant temporary authorization to the accessing client based on the trust level and risk assessment value;

[0104] If not, the accessing client is determined to be a high-risk user, and access to non-core assets is denied.

[0105] In the above implementation process, it is further determined whether the access terminal is a risky user or a high-risk user, and different access control processing is carried out on them respectively. Corresponding feedback can be given to access terminals with different trust levels, which is more flexible, can meet the needs of more access terminals, and is conducive to expanding the coverage of access terminals.

[0106] When a trusted user logs in and accesses an edge asset, access is granted directly without authorization or approval. When a risky user logs in and accesses an edge asset, if there is no authorization for that edge asset, temporary authorization is required. During authorization, the system provides the user's trust level and risk assessment value as a reference to assist the administrator in making decisions. When a high-risk user logs in and accesses an edge asset, if there is no authorization for that edge asset, the system directly denies their access.

[0107] This application simplifies the approval process for trusted users' access permissions to edge assets, significantly improving the work efficiency of system (operation and maintenance) administrators and operation and maintenance users. It allows for periodic assessment and updates of user trust levels, ensuring the effectiveness and flexibility of edge asset access control.

[0108] Example 2

[0109] In order to execute the method corresponding to Embodiment 1 above and achieve the corresponding functions and technical effects, an asset access control device is provided below, such as... Figure 2 As shown, the device includes:

[0110] Module 1 is used to retrieve a pre-configured list of assets and user level information.

[0111] Module 2 is used to classify the trust level of the access terminal based on user level information, thereby obtaining the trust level of the access terminal.

[0112] Authorization module 3 uses permission matching based on trust level to enable the client to access non-core assets in the asset list.

[0113] In the above implementation process, user trust levels are divided, and permissions are matched to the asset list according to the trust levels. This can accurately match users with the non-core assets they want to access, reduce the risks for users in the asset access control process, improve the security of asset access control, improve the efficiency of asset access control, effectively prevent the misuse of access control permissions, and prevent information leakage.

[0114] Furthermore, the device also includes a configuration module for:

[0115] Obtain information on the criteria for classifying user trust levels;

[0116] The evaluation cycle for obtaining user trust levels;

[0117] Risk weight values ​​are obtained based on the type and level of operation and maintenance rules.

[0118] User level information is obtained based on the criteria for classifying user trust levels, the assessment period, and the risk weight value.

[0119] In the above implementation process, user level information is differentiated in multiple ways based on classification criteria, assessment cycle, and risk weight values. This makes it easier for users to match the asset list they want to access from multiple dimensions, improves the user classification concept, and makes user level information more reasonable.

[0120] Furthermore, module 2 is also used for:

[0121] Get the number of risky operations performed by the accessing client during the assessment period;

[0122] The user's risk assessment value is obtained based on the number of risky operations and the risk weight value.

[0123] The trust level of the access terminal is determined by classifying the user's risk assessment value and the user trust level classification criteria.

[0124] In the above implementation process, the trust level of the access terminal is divided according to the user level information to avoid risky operations during the access process, improve security, and at the same time ensure the accuracy of the trust level division.

[0125] Furthermore, the authorization module 3 is also used for:

[0126] Iterate through the asset list to obtain the operational assets;

[0127] Determine whether the assets under maintenance are non-core assets;

[0128] If so, the asset list is matched with permissions based on the trust level to allow the client to access the non-core assets.

[0129] In the above implementation process, non-core assets are extracted from the asset list, which makes it easier for the access terminal to access non-core assets more accurately, reduces the possibility of errors in the access control process, improves the access efficiency of the access terminal, and effectively shortens the access control time.

[0130] Furthermore, the authorization module 3 is also used for:

[0131] Determine whether the accessing client is a trusted user based on the trust level;

[0132] If so, add access permissions to the accessing client based on the non-core assets, so that the accessing client with the added access permissions can access the non-core assets;

[0133] If not, grant temporary authorization to the accessing client to allow temporary access to non-core assets.

[0134] In the above implementation process, judging whether the access terminal is trustworthy based on the trust level can further improve the rigor of the access terminal audit, prevent the access terminal from being misused, and prevent information leakage.

[0135] Furthermore, the authorization module 3 is also used for:

[0136] Determine whether the user accessing the service is a high-risk user;

[0137] If so, grant temporary authorization to the accessing client based on the trust level and risk assessment value;

[0138] If not, the accessing client is determined to be a high-risk user, and access to non-core assets is denied.

[0139] In the above implementation process, it is further determined whether the access terminal is a risky user or a high-risk user, and different access control processing is carried out on them respectively. Corresponding feedback can be given to access terminals with different trust levels, which is more flexible, can meet the needs of more access terminals, and is conducive to expanding the coverage of access terminals.

[0140] The asset access control device described above can implement the method of Embodiment 1. The options in Embodiment 1 are also applicable to this embodiment, and will not be described in detail here.

[0141] The remaining contents of this embodiment can be referred to the contents of Embodiment 1 above, and will not be repeated in this embodiment.

[0142] Example 3

[0143] This application provides an electronic device, including a memory and a processor. The memory stores a computer program, and the processor runs the computer program to cause the electronic device to perform the asset access control method of Embodiment 1.

[0144] Alternatively, the aforementioned electronic device may be a server.

[0145] Please see Figure 3 , Figure 3 This is a schematic diagram illustrating the structural composition of an electronic device provided in an embodiment of this application. The electronic device may include a processor 31, a communication interface 32, a memory 33, and at least one communication bus 34. The communication bus 34 is used to enable direct communication between these components. In this embodiment, the communication interface 32 is used for signaling or data communication with other node devices. The processor 31 may be an integrated circuit chip with signal processing capabilities.

[0146] The processor 31 described above can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), an off-the-shelf programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. It can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor can be a microprocessor, or the processor 31 can be any conventional processor.

[0147] The memory 33 may be, but is not limited to, random access memory (RAM), read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), etc. The memory 33 stores computer-readable instructions. When these computer-readable instructions are executed by the processor 31, the device can perform the aforementioned operations. Figure 1 The various steps involved in the method implementation examples.

[0148] Optionally, the electronic device may also include a storage controller and an input / output unit. The memory 33, storage controller, processor 31, peripheral interface, and input / output unit are electrically connected directly or indirectly to each other to achieve data transmission or interaction. For example, these components can be electrically connected to each other via one or more communication buses 34. The processor 31 is used to execute executable modules stored in the memory 33, such as software function modules or computer programs included in the device.

[0149] Input / output units are used to enable users to create tasks and set optional start periods or preset execution times for those tasks, facilitating user-server interaction. Input / output units can be, but are not limited to, a mouse and keyboard.

[0150] Understandable. Figure 3 The structure shown is for illustrative purposes only; the electronic device may also include components that are more advanced than those shown. Figure 3 The more or fewer components shown, or having the same Figure 3 The different configurations shown. Figure 3The components shown can be implemented using hardware, software, or a combination thereof.

[0151] In addition, this application also provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the asset access control method of Embodiment 1.

[0152] This application also provides a computer program product that, when run on a computer, causes the computer to perform the method described in the method embodiment.

[0153] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can also be implemented in other ways. The apparatus embodiments described above are merely illustrative; for example, the flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of apparatus, methods, and computer program products according to various embodiments of this application. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than those marked in the drawings. For example, two consecutive blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram and / or flowchart, and combinations of blocks in block diagrams and / or flowcharts, can be implemented using dedicated hardware-based apparatus that performs the specified function or action, or using a combination of dedicated hardware and computer instructions.

[0154] In addition, the functional modules in the various embodiments of this application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.

[0155] If the aforementioned functions are implemented as software functional modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, external hard drives, ROM, RAM, magnetic disks, or optical disks.

[0156] The above description is merely an embodiment of this application and is not intended to limit the scope of protection of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application. It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.

[0157] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of protection of the claims.

[0158] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

Claims

1. An access control method for an asset, characterized in that, The method includes: Retrieve a pre-configured list of assets and user level information; The trust level of the access terminal is obtained by classifying the access terminal according to the user level information. Based on the trust level, the asset list is matched with permissions so that the accessing terminal can access non-core assets in the asset list; The steps for pre-configuring the user level information include: Obtain information on the criteria for classifying user trust levels; The evaluation cycle for obtaining user trust levels; Risk weight values ​​are obtained based on the type and level of operation and maintenance rules. The user level information is obtained based on the user trust level classification criteria, the assessment period, and the risk weight value. The step of classifying the trust level of the access terminal based on the user level information to obtain the trust level of the access terminal includes: The number of risky operations performed by the access terminal during the assessment period is obtained; The user's risk assessment value is obtained based on the number of risky operations and the risk weight value. The access terminal is classified into trust levels based on the user risk assessment value and the user trust level classification criteria information to obtain the trust level of the access terminal. The step of performing permission matching on the asset list based on the trust level to enable the access terminal to access non-core assets in the asset list includes: Iterate through the asset list to obtain the operational assets; Determine whether the operation and maintenance assets are non-core assets; If so, perform permission matching on the asset list based on the trust level; If the access terminal is a trusted user, grant access directly; if the access terminal is a risky user, and there is no authorization for the non-core asset, grant temporary authorization to the access terminal based on the trust level and risk assessment value; if the access terminal is a high-risk user, deny its access.

2. An asset access control device, characterized in that, The device includes: The acquisition module retrieves a pre-configured list of assets and user level information. The segmentation module classifies the access terminal based on the user level information to obtain the trust level of the access terminal. The authorization module performs permission matching on the asset list based on the trust level, so that the access terminal can access non-core assets in the asset list; The device further includes a configuration module for: Obtain information on the criteria for classifying user trust levels; The evaluation cycle for obtaining user trust levels; Risk weight values ​​are obtained based on the type and level of operation and maintenance rules. The user level information is obtained based on the user trust level classification criteria, the assessment period, and the risk weight value. The number of risky operations performed by the access terminal during the assessment period is obtained; The user's risk assessment value is obtained based on the number of risky operations and the risk weight value. The access terminal is classified into trust levels based on the user risk assessment value and the user trust level classification criteria information to obtain the trust level of the access terminal. The authorization module is also used for: Iterate through the asset list to obtain the operational assets; Determine whether the operation and maintenance assets are non-core assets; If so, perform permission matching on the asset list based on the trust level; If the access terminal is a trusted user, grant access directly; if the access terminal is a risky user, and there is no authorization for the non-core asset, grant temporary authorization to the access terminal based on the trust level and risk assessment value; if the access terminal is a high-risk user, deny its access.

3. An electronic device, characterized in that, The device includes a memory and a processor, the memory being used to store a computer program, and the processor running the computer program to cause the electronic device to perform the asset access control method according to claim 1.

4. A computer-readable storage medium, characterized in that, It stores a computer program that, when executed by a processor, implements the asset access control method as described in claim 1.