A knowledge management information security system operation method, system, device and storage medium

By implementing identity authentication and dynamic permission adjustments, enabling special permission channels for monitoring access, and distributing and backing up knowledge resources, the problems of low permission security and low access efficiency in knowledge management systems are solved, thereby improving both security and efficiency.

CN117294464BActive Publication Date: 2026-07-21ELECTRIC POWER RES INST CHINA SOUTHERN POWER GRID CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
ELECTRIC POWER RES INST CHINA SOUTHERN POWER GRID CO LTD
Filing Date
2023-08-08
Publication Date
2026-07-21

AI Technical Summary

Technical Problem

Existing knowledge management information security systems suffer from low security due to open permissions and low access efficiency.

Method used

By obtaining authentication information, user identity and permissions are authenticated, permissions are dynamically adjusted, special permission channels are opened for monitoring, distributed storage and backup of knowledge resources are adopted, accessed content is monitored, and access is blocked when anomalies are detected.

Benefits of technology

It effectively prevents unauthorized access, improves system flexibility and efficiency, ensures the security of knowledge resources, and prevents data loss.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117294464B_ABST
    Figure CN117294464B_ABST
Patent Text Reader

Abstract

The application discloses a kind of knowledge management information security system operation method, system, equipment and storage medium include: obtaining authentication information, the identity and authority of user are authenticated;According to the role and task demand of knowledge management, dynamically adjust the authority;When executing special access outside authority, open special authority channel, and monitor access operation in special authority channel;Knowledge resources and process data are stored in distribution, and backup;When accessing, monitor access content, and shield access when finding exception.It can protect the security of knowledge resources.Can meet the needs of different users and different tasks, improve the flexibility and user experience of system.Can effectively manage and optimize the use of resources, improve the efficiency of system.Knowledge resources and process data are stored in distribution, and backup, which can improve the stability and reliability of system, prevent data loss.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information security technology, specifically to a method, system, device, and storage medium for operating a knowledge management information security system. Background Technology

[0002] In the information age, knowledge management has become a crucial element in internal information processing and decision-making within organizations. Knowledge Management Systems (KMS) are widely used within organizations to collect, store, retrieve, and share knowledge. However, as the value of knowledge becomes increasingly apparent, the issue of knowledge security has also attracted widespread attention.

[0003] Traditional knowledge management systems typically rely on centralized servers and databases for knowledge storage and management. However, this centralized architecture presents several problems. First, centralized servers and databases are vulnerable to attacks, potentially leading to the loss or leakage of significant amounts of knowledge. Second, a centralized architecture can restrict knowledge access and sharing, impacting the efficiency of knowledge utilization. Summary of the Invention

[0004] The purpose of this section is to outline some aspects of embodiments of the present invention and to briefly describe some preferred embodiments. Simplifications or omissions may be made in this section, as well as in the abstract and title of this application, to avoid obscuring the purpose of these documents; however, such simplifications or omissions should not be construed as limiting the scope of the invention.

[0005] In view of the above-mentioned problems, the present invention is proposed.

[0006] Therefore, the technical problem solved by this invention is: the existing knowledge management information security system operation method has low security due to open permissions, and how to optimize the problem of low access efficiency caused by comprehensive monitoring.

[0007] To address the aforementioned technical problems, this invention provides the following technical solution: a method for operating a knowledge management information security system, comprising: acquiring authentication information and authenticating the user's identity and permissions; granting partial permissions based on the authentication results and dynamically adjusting permissions according to the roles and task requirements of knowledge management; opening special permission channels when performing special access outside of authorized permissions, and monitoring access operations within these special permission channels; if the access volume of special access exceeds the access volume within the time limit, or the access efficiency of special channels is lower than the requirement, opening multiple special permission channels, and setting one channel with low resource access efficiency as a slow channel among these channels, performing comprehensive monitoring of the slow channel, and setting one channel with high resource access efficiency as a fast channel, performing real-time monitoring of the fast channel while performing delayed analysis of low-risk components; distributing and backing up knowledge resources and process data; monitoring access content during access and blocking access when anomalies are detected.

[0008] As a preferred embodiment of the knowledge management information security system operation method described in this invention, the authentication result includes distinguishing internal employees and external users based on identity information, and unlocking the matched permissions based on user level and employee level.

[0009] The system retrieves the access records of authenticated users. If more than 50% of the authenticated user's historical access records require further permission grants and there are no abnormal access records, then the permissions in the historical records are directly granted, and the access process is audited after the access ends. If less than 50% of the authenticated user's historical access records require further permission grants, there are abnormal access records, and the user has not applied for permission grants, then access is granted after a single permission request. The permission grant review includes allowing users to submit permission grant requests if they frequently need to use access outside their permissions. If the permission grant review is approved, access can be granted without a single permission request. During the permission grant review, the number of accesses outside the permissions is limited.

[0010] As a preferred embodiment of the knowledge management information security system operation method described in this invention, the limitation is expressed as follows:

[0011]

[0012] Where T represents the total number of accesses in the previous access cycle; I represents the importance of the accessed resource to information security, ranging from 0 to 1; R represents the level of trust assessed during permission granting review, ranging from 0 to 1; and the next cycle is updated each time the limit for accesses outside the permitted number of times is exhausted.

[0013] As a preferred embodiment of the knowledge management information security system operation method described in this invention, the dynamic adjustment includes: dynamically adjusting the permissions of users and employees based on their behavior and needs; continuously monitoring and analyzing user behavior; predicting potential user needs; granting permissions to relevant resources if a user is working on a specific project and submitting an application; revoking additional permissions if the predicted user needs are met or the behavior pattern changes; and granting permissions to relevant resources to internal employees who are assigned new projects and need access to resources they do not have permission to access, and revoking permissions after the project is completed.

[0014] As a preferred embodiment of the knowledge management information security system operation method described in this invention, the special access includes: if a user accesses the resource after a single permission request, a special channel is used for the access process; the access operation is monitored during the access process through the special channel; and a time limit is set for the special access. The time limit is set according to the amount of resource content: t = (a + 1 / b) * t0; where t is the time limit, a is the text length of the resource content, b is the resource difficulty rating, and t0 represents the time step; if the access volume of the special access is greater than the access volume within the time limit, or the access efficiency of the special channel is lower than the requirement, a special permission channel is added until the access volume of the special access is no greater than the access volume within the time limit and the access efficiency of the special channel is no lower than the requirement, at which point the number of channels is stopped being increased. When there are multiple special access channels, one channel with low resource access efficiency is designated as a slow channel, and comprehensive monitoring is performed on the slow channel. Another channel with high resource access efficiency is designated as a fast channel, and while real-time monitoring is performed on the fast channel, low-risk resource access is analyzed with a delay. When setting up slow and fast channels, within a time limit, each special channel is randomly set to slow channel sequentially, and the time for each channel to be set to slow channel is the same. When the original fast channel is set to slow channel, a special channel is randomly selected as the fast channel. The delay analysis also includes identifying resources with zero recorded anomalies based on historical security records as low-risk resources. While performing real-time monitoring on the fast channel, access to low-risk resources is not monitored but records are retained. Upon completion of access, a review is performed to analyze whether any anomalies were found.

[0015] As a preferred embodiment of the knowledge management information security system operation method described in this invention, the anomaly recording further includes: recording an anomaly if an anomaly occurs during the access process, resulting in access being blocked; recording an anomaly if malicious frequent downloads and malicious batch exports are identified, and restricting malicious download and malicious batch export behaviors; reducing the recording of an anomaly if the user submits the cause of the anomaly and the revision is approved; inserting resource tags into the anomaly when recording an anomaly, and statistically analyzing the anomalies in accessing resources when conducting permission opening audits and evaluating low-risk resources.

[0016] As a preferred embodiment of the knowledge management information security system operation method described in this invention, the access blocking includes: blocking access if frequent downloading behavior, attempts to access unauthorized resources, or a large number of queries within a short period of time occur; not blocking access if frequent downloading behavior and a large number of queries within a short period of time are requested before access; if frequent downloading behavior and a large number of queries within a short period of time cause an anomaly, submitting the cause of the anomaly and reducing the anomaly record is equivalent to requesting access before access and not blocking access during access; all knowledge resources and process data are backed up using distributed storage; after access blocking ends, the consistency between the backup and platform resources is checked; if they are inconsistent, a tampering warning is issued, and the tampered content is repaired; the accessing user is traced based on the warning information and added to a blacklist.

[0017] A knowledge management information security system operating system employing the method described in this invention is characterized by: an authentication unit that acquires authentication information and authenticates the user's identity and permissions; an access authorization unit that grants partial permissions based on the authentication results and dynamically adjusts permissions according to the roles and task requirements of knowledge management; opening special permission channels when performing special access outside of authorized permissions and monitoring access operations within these special permission channels; opening multiple special permission channels when the access volume of special access exceeds the access volume within the time limit or the access efficiency of special channels is lower than the requirement, setting one channel with low resource access efficiency as a slow channel among these special permission channels and performing comprehensive monitoring of the slow channel, and setting one channel with high resource access efficiency as a fast channel and performing real-time monitoring of the fast channel while performing delayed analysis of low-risk parts; and a backup and shielding control unit that uses distributed storage for knowledge resources and process data and performs backups; monitoring access content during access and shielding access when anomalies are detected.

[0018] A computer device includes: a memory and a processor; the memory stores a computer program, characterized in that: when the processor executes the computer program, it implements the steps of the method described in any one of the present invention.

[0019] A computer-readable storage medium having a computer program stored thereon, characterized in that: when the computer program is executed by a processor, it implements the steps of the method described in any one of the present invention.

[0020] The beneficial effects of this invention are as follows: The knowledge management information security system operation method provided by this invention authenticates users' identities and permissions by acquiring authentication information, which can effectively prevent unauthorized access and operation, thereby protecting the security of knowledge resources. Granting partial permissions based on authentication results and dynamically adjusting permissions according to the roles and task requirements of knowledge management can meet the needs of different users and tasks, improving system flexibility and user experience. Opening special permission channels for special access outside of authorized permissions and monitoring access operations within these channels can effectively manage and optimize resource utilization, improving system efficiency. Distributed storage and backup of knowledge resources and process data can improve system stability and reliability, preventing data loss. Attached Figure Description

[0021] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. Wherein:

[0022] Figure 1 A flowchart illustrating the operation method of a knowledge management information security system, as provided in the first embodiment of the present invention;

[0023] Figure 2 This is a comparison chart of resource output efficiency in a knowledge management information security system operation method provided in the second embodiment of the present invention. Detailed Implementation

[0024] To make the above-mentioned objects, features, and advantages of the present invention more apparent and understandable, specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of them. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the protection scope of the present invention.

[0025] Many specific details are set forth in the following description in order to provide a full understanding of the invention. However, the invention may also be practiced in other ways different from those described herein, and those skilled in the art can make similar extensions without departing from the spirit of the invention. Therefore, the invention is not limited to the specific embodiments disclosed below.

[0026] Secondly, the term "one embodiment" or "embodiment" as used herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The phrase "in one embodiment" appearing in different places in this specification does not necessarily refer to the same embodiment, nor is it a single or selective embodiment that is mutually exclusive with other embodiments.

[0027] This invention is described in detail with reference to the schematic diagrams. When detailing the embodiments of this invention, for ease of explanation, the cross-sectional views illustrating the device structure may be partially enlarged, not adhering to the usual scale. Furthermore, the schematic diagrams are merely examples and should not be construed as limiting the scope of protection of this invention. In actual fabrication, the three-dimensional spatial dimensions of length, width, and depth should be included.

[0028] Furthermore, in the description of this invention, it should be noted that the terms "upper," "lower," "inner," and "outer," etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. These terms are used solely for the convenience of describing the invention and for simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on the invention. In addition, the terms "first," "second," or "third" are used for descriptive purposes only and should not be construed as indicating or implying relative importance.

[0029] Unless otherwise explicitly specified and limited, the terms "installation," "connection," and "joining" in this invention should be interpreted broadly. For example, they can refer to fixed connections, detachable connections, or integral connections; similarly, they can refer to mechanical connections, electrical connections, or direct connections, or indirect connections through an intermediate medium, or internal connections between two components. Those skilled in the art can understand the specific meaning of the above terms in this invention based on the specific circumstances.

[0030] Example 1

[0031] Reference Figure 1 As an embodiment of the present invention, a method for operating a knowledge management information security system is provided, comprising:

[0032] S1: Obtain authentication information and authenticate the user's identity and permissions.

[0033] Furthermore, personal identity is authenticated by inputting information. The authentication results include distinguishing between internal employees and external users based on identity information, and unlocking the matched permissions based on user level and employee level.

[0034] Next, the access records of the authenticated user are retrieved. If the number of times further permission needs to be granted in the authenticated user's historical access records exceeds 50%, and there are no abnormal records in the user's access records, then the permissions in the historical records are directly granted, and the access process is audited after the access ends. If the number of times further permission needs to be granted in the authenticated user's historical access records does not exceed 50%, there are abnormal records in the user's access records, and the user has not applied for permission, then access is granted after a single permission application. Permission granting review includes allowing users who need to frequently use access outside their permissions to submit permission granting applications. If the permission granting review is approved, access can be granted without a single permission application. During the permission granting review, the number of accesses outside the permissions is limited. The limit is expressed as follows:

[0035] ,

[0036] Where T represents the total number of accesses in the previous access cycle; I represents the importance of the accessed resource to information security, ranging from 0 to 1; R represents the level of trust assessed during permission granting review, ranging from 0 to 1; and the next cycle is updated each time the limit for accesses outside the permitted number of times is exhausted.

[0037] It's worth noting that if access permissions are granted more than 50% of the time, it indicates that the user frequently needs to grant these permissions. In this case, if there are no abnormal records, it means the user's actions when granting these permissions were appropriate. Therefore, the application can be approved, and access can be granted directly.

[0038] S2: Grant partial permissions based on the authentication results, and dynamically adjust permissions according to the roles and task requirements of knowledge management.

[0039] Furthermore, dynamic adjustments include: dynamically adjusting user and employee permissions based on user and employee behavior and needs; continuously monitoring and analyzing user behavior to predict potential user needs; granting permissions to relevant resources if a user is working on a specific project and submits a request; revoking additional permissions if user needs are predicted to be met or behavioral patterns change; and granting permissions to relevant resources to internal employees who are assigned new projects and require access to resources they do not have permission to access, revoking permissions after the project is completed.

[0040] It's important to understand that different users and employees have different needs and authority, so their required permissions will also differ. Permissions should be adjusted promptly based on changes in their needs, and if the changes are temporary, permissions should be revoked immediately after completion to ensure security.

[0041] S3: When performing special access outside of the execution permissions, open a special permission channel and monitor the access operation in the special permission channel; if the access volume of special access exceeds the access volume within the time limit, or the access efficiency of the special channel is lower than the demand, open multiple special permission channels, and set one channel with low resource access efficiency as the slow channel among the multiple special permission channels, and perform comprehensive and strict monitoring on the slow channel; set one channel with high resource access efficiency as the fast channel, and perform real-time monitoring on the fast channel while performing delayed analysis on the low-risk part.

[0042] Furthermore, special access includes using a special channel for access if a user requests access through a single permission request. During access through this special channel, the access operation is monitored, and a time limit is set for the special access. The time limit is set based on the amount of resource content: t = (a + 1 / b) * t0; where t is the time limit, a is the text length of the resource content, b is the difficulty rating of accessing the resource, and t0 represents the time step.

[0043] If the access volume of special access exceeds the access volume within the time limit, or the access efficiency of special channels is lower than the demand, add a special permission channel until the access volume of special access is no greater than the access volume within the time limit and the access efficiency of special channels is no lower than the demand, then stop adding channels. When there are multiple special permission channels, set one channel with low resource access efficiency as a slow channel and perform comprehensive and strict monitoring on the slow channel; set one channel with high resource access efficiency as a fast channel and perform real-time monitoring on the fast channel while performing delayed analysis on low-risk resource access.

[0044] The lag analysis also includes identifying resources with zero recorded anomalies based on historical security records as low-risk resources. During real-time monitoring in the fast channel, access to low-risk resources is not monitored but records are retained. Upon completion of access, a review is performed to analyze whether any anomalies are found.

[0045] It's important to note that access beyond authorized permissions requires granting new permissions. Granting these permissions constitutes a special access method and necessitates opening a dedicated channel. A single access channel has limitations on access efficiency; if the access volume is too high, multiple channels need to be added. Furthermore, the duration of permission activation must be limited to prevent potential security risks. If a large number of resources need to be accessed within this time limit, it's clearly insufficient, requiring the opening of multiple channels. Alternatively, if the content being accessed is highly complex, access efficiency will decrease, meaning access will slow down. Activating multiple channels allows for faster delivery of the required content.

[0046] It's important to understand that setting up a fast channel and a slow channel for access channel monitoring ensures that the average efficiency of access across multiple channels remains constant. Because the slow channel has a slower access efficiency, it allows for more comprehensive monitoring and analysis. The fast channel, on the other hand, requires rapid monitoring, so lower-risk resources are prioritized for analysis after access, thus ensuring the fast channel's efficiency.

[0047] It's also worth mentioning that when setting up slow and fast channels, within the time limit, each special channel is randomly assigned to a slow channel sequentially, and each channel is assigned to a slow channel for the same duration. When an original fast channel is assigned to a slow channel, a special channel is randomly selected as the fast channel. For example, if the time limit is 9 minutes and there are three special channels (a, b, and c), one channel is randomly selected as the slow channel (let's say channel a), and a channel is randomly selected as the fast channel (let's say channel b). Then, channel a is the slow channel for three minutes. After three minutes, the slow channel changes (let's say it changes to channel c). After another three minutes, the slow channel should switch back to channel b, but since channel b is now the fast channel, the fast channel is randomly switched back to either channel a or c, and channel b becomes the slow channel.

[0048] The exception logging also includes recording an exception if an exception occurs during the access process and leads to access being blocked; recording an exception if malicious frequent downloads and malicious batch exports are identified, and restricting malicious download and batch export behaviors; reducing the exception record if the reason submitted by the user for the exception is approved and revised; inserting resource tags into the exception when recording exceptions; and statistically analyzing resource access exceptions when conducting permission opening audits and low-risk resource assessments.

[0049] It's important to note that inserting resource tags into abnormal records allows for timely identification of potential anomalies when accessing a resource. This provides timely detection. Malicious frequent downloads and bulk exports are detrimental to information security. Furthermore, they increase the system's workload. If prior notification or timely corrections are provided and accepted, then the behavior is considered reasonable. Only reasonably frequent downloads and bulk exports will not be recorded as abnormalities or security issues.

[0050] S4: Distributed storage and backup are used for knowledge resources and process data; access is monitored during access and access is blocked when anomalies are detected.

[0051] Furthermore, access blocking includes blocking access if there are frequent downloads, attempts to access unauthorized resources, or a large number of queries in a short period of time; if frequent downloads and a large number of queries in a short period of time are requested before access, access will not be blocked; if frequent downloads and a large number of queries in a short period of time cause an exception, submitting the reason for the exception and reducing the exception records is equivalent to requesting access before access and not blocking access during access.

[0052] It's important to know that promptly blocking unauthorized access and behavior when an anomaly occurs can ensure the security of data and resources. If the user's behavior is reasonable, the blocking can be lifted after submitting an application or making a correction.

[0053] It should also be noted that all knowledge resources and process data are backed up using distributed storage. After access is blocked, the consistency between the backup and the platform resources is checked. If there is a discrepancy, a tampering warning is issued, and the tampered content is repaired. Based on the warning information, the accessing user is traced and added to the blacklist.

[0054] It's important to understand that distributed storage backups ensure resource security, preventing a single resource error from rendering the entire backup unusable. After the blocking process ends, verifying the backup against the platform's data resources effectively detects any tampering with platform resources and data, significantly increasing security. If tampering is discovered, it indicates a significant security risk to the user, who should be immediately blacklisted. If the issue is later rectified, the user can be removed from the blacklist.

[0055] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments described above. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory, magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory, magnetic variable memory, ferroelectric memory, phase change memory, graphene memory, etc. Volatile memory can include random access memory or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory or dynamic random access memory, etc. The databases involved in the embodiments provided in this application can include at least one of relational databases and non-relational databases. Non-relational databases can include blockchain-based distributed databases, etc., and are not limited thereto.

[0056] The processors involved in the various embodiments provided in this application may be general-purpose processors, central processing units, graphics processors, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited thereto.

[0057] Example 2

[0058] Reference Figure 2 This invention provides a method for operating a knowledge management information security system. To verify the beneficial effects of the invention, scientific demonstration is conducted through economic benefit calculations and simulation experiments.

[0059] Table 1 shows the security effects of the present invention and traditional methods on the knowledge management information security system. It also shows the effect of the present invention when applying for additional open permissions compared with normal access.

[0060] Table 1. Security Effects and Access Control Effects

[0061]

[0062] It can be seen that this invention not only makes data and resources less susceptible to tampering, but also maintains the same efficiency as normal access when accessing data outside of normal permissions, greatly improving the user experience.

[0063] Figure 2 This paper compares the resource output efficiency of the present invention with that of conventional inventions when enabling access functions beyond the user's authorized permissions, compared to the resource output efficiency with normal permissions. It can be seen that the present invention has high and stable output efficiency when accessing resources beyond the user's authorized permissions, while the conventional method has low output efficiency and poor stability.

[0064] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.

Claims

1. A method for operating a knowledge management information security system, characterized in that, include: Obtain authentication information to authenticate the user's identity and permissions; Grant partial permissions based on the authentication results, and dynamically adjust permissions according to the roles and task requirements of knowledge management; When performing special access outside of authorized permissions, a special permission channel is opened, and the access operation is monitored within this special permission channel. If the access volume of special access exceeds the access volume within the time limit, or the access efficiency of the special channel is lower than the demand, multiple special permission channels are opened. Among these channels, one channel with low resource access efficiency is designated as the slow channel, and the slow channel is fully monitored. Another channel with high resource access efficiency is designated as the fast channel, and while the fast channel is monitored in real time, low-risk resource access is analyzed with a delay. Knowledge resources and process data are stored in a distributed manner and backed up. Access content is monitored during access, and access is blocked when anomalies are detected. Based on historical security records, resources with zero recorded anomalies are identified as low-risk access resources.

2. The method for operating a knowledge management information security system as described in claim 1, characterized in that: The authentication results include distinguishing between internal employees and external users based on identity information, and unlocking the matched permissions based on user level and employee level. Retrieve the access records of the authenticated user. If the number of times the authenticated user's historical access records require further permission granting exceeds 50% and there are no abnormal records in the user's access records, then grant the permissions in the historical records directly, and audit the access process after the access ends. If the number of times the authenticated user's historical access records require further permission granting does not exceed 50%, there are abnormal records in the user's access records, and the user has not applied for permission granting, then access is granted after a single permission request. The permission granting review includes allowing users to frequently access content outside their permissions by submitting a permission granting application. If the permission granting review is approved, access can be granted without a single permission granting application. During the permission granting review, the number of times access outside the permissions can be limited.

3. The method for operating a knowledge management information security system as described in claim 2, characterized in that: The restriction is expressed as follows: , Where T represents the total number of accesses in the previous access cycle; I represents the importance of the accessed resource to information security, ranging from 0 to 1; and R represents the level of trust assessed during the permission granting review, ranging from 0 to 1. Update the cycle each time the limit for accessing content outside the permitted range is reached.

4. The method for operating a knowledge management information security system as described in claim 3, characterized in that: The dynamic adjustment includes dynamically adjusting users' and employees' permissions based on their behavior and needs; Continuously monitor and analyze user behavior to predict potential user needs. If a user is working on a specific project and submits a request, grant permissions to the relevant resources. If the user's needs are predicted to be met or their behavior pattern changes, revoke any additional permissions. If an internal employee is assigned a new project and needs to access resources they do not have permission to access, then permission for the relevant resources should be granted, and the permission should be revoked after the project is completed.

5. The method for operating a knowledge management information security system as described in claim 4, characterized in that: The special access includes: if a user accesses the resource after a single permission request, a special channel is used for the access process, the access operation is monitored during the access process through the special channel, and a time limit is set for the special access. The time limit is set according to the amount of resource content: t = (a + 1 / b) * t0. Where t is the time limit, a is the text length of the resource content, b is the resource difficulty rating, and t0 represents the time step. If the access volume of special access exceeds the access volume within the time limit, or the access efficiency of special channels is lower than the demand, add a special permission channel until the access volume of special access is no greater than the access volume within the time limit and the access efficiency of special channels is no lower than the demand, then stop adding channels. When there are multiple special permission channels, one channel with low resource access efficiency is set as the slow channel, and the slow channel is fully monitored; one channel with high resource access efficiency is set as the fast channel, and the fast channel is monitored in real time while the low-risk resource access portion is analyzed with a lag. When setting up slow and fast channels, within the time limit, each special channel is randomly set to a slow channel in turn, and the time for each channel to be set to a slow channel is the same. When the original fast channel is set to a slow channel, a special channel is randomly selected as the fast channel. The lag analysis also includes identifying resources with zero recorded anomalies based on historical security records as low-risk resources. During real-time monitoring in the fast channel, access to low-risk resources is not monitored but records are retained. Upon completion of access, a review is performed to analyze whether any anomalies are found.

6. The method for operating a knowledge management information security system as described in claim 5, characterized in that: The abnormal log also includes recording an abnormality if an abnormality occurs during the access process and causes access to be blocked; recording an abnormality if malicious frequent downloads and malicious batch exports are identified, and restricting malicious download and malicious batch export behaviors. If a user submits an error and the reason for the error is approved and the correction is made, the error record will be reduced by one. When logging anomalies, resource tags are inserted for the anomalies. When conducting permission opening audits and evaluating low-risk resources, statistics are compiled on anomalies in accessing resources.

7. The method for operating a knowledge management information security system as described in claim 6, characterized in that: The access blocking includes blocking access if there are frequent downloads, attempts to access unauthorized resources, or a large number of queries in a short period of time; if frequent downloads and a large number of queries in a short period of time are requested before access, access will not be blocked; if frequent downloads and a large number of queries in a short period of time cause an anomaly, submitting the cause of the anomaly and reducing the anomaly record is equivalent to requesting access before access and not blocking access during access. All knowledge resources and process data are backed up using distributed storage. After access is blocked, the consistency between the backup and the platform resources is checked. If there is a discrepancy, a tampering warning is issued, and the tampered content is repaired. Based on the warning information, the accessing user is traced and added to the blacklist.

8. A knowledge management information security system operating system employing the method described in any one of claims 1-7, characterized in that: The authentication unit acquires authentication information and authenticates the user's identity and permissions. Access authorization units grant partial permissions based on authentication results, and dynamically adjust permissions according to the roles and task requirements of knowledge management; When performing special access outside of authorized permissions, a special permission channel is opened, and the access operation is monitored in the special permission channel; if the access volume of special access exceeds the access volume within the time limit, or the access efficiency of the special channel is lower than the demand, multiple special permission channels are opened, and one channel with low resource access efficiency is set as the slow channel among the multiple special permission channels. The slow channel is fully monitored, and one channel with high resource access efficiency is set as the fast channel. The fast channel is monitored in real time, while the low-risk resource access part is analyzed with a lag. The backup and shielding control unit uses distributed storage for knowledge resources and process data and performs backups; it monitors the content accessed during access and blocks access when anomalies are detected.

9. A computer device, comprising: A memory and a processor; the memory stores a computer program, characterized in that: when the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 7.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 7.