A basic information platform security control method, system, device and medium
By obtaining user IDs and data IDs and dynamically adjusting access rights based on business lines and levels, the problem of poor flexibility in access control on basic information platforms is solved, efficient permission management and risk assessment are achieved, and data security is ensured.
Patent Information
- Application Number
- CN202311312973.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-10-11
- Publication Date
- 2025-09-19
- Estimated Expiration
- 2043-10-11
AI Technical Summary
The existing access control methods of basic information platforms have poor flexibility, making it difficult to effectively manage access rights to data in different business categories, and lack dynamic assessment and risk control of user access behavior.
By obtaining user identification and data identification, determining the target business category and security level, dynamically adjusting access rights based on the user's business line and level, and conducting risk assessment through organizational structure tree and historical access records, dual permission control and risk management are achieved.
It improves the flexibility and security of access control, reduces the need for individual settings of user role permissions, improves the efficiency of permission management, and prevents abnormal access through risk assessment to ensure data security.
Smart Images

Figure CN117454415B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of security control, and in particular to a method, system, device and medium for security control of a basic information platform. Background Art
[0002] Today's society has entered the era of big data, with more and more data being shared, open, and cross-used. In response to problems such as lack of protection of key basic information, serious leakage of sensitive data, and confusion in information access rights, there is an urgent need to ensure data security in the context of big data by strengthening cyberspace security, protecting key information infrastructure, and strengthening data encryption.
[0003] The primary goal of building a basic information platform is to serve society and provide various information services. Therefore, it must remain open to the public. At the same time, to enhance security, user access and data manipulation must be controlled. Traditional approaches rely on role-based access control, requiring administrators to define roles and assign appropriate access permissions. However, the management flexibility for individual business data categories is limited, and this situation requires further improvement. Summary of the Invention
[0004] In order to solve the problem of poor flexibility of existing access control, this application provides a basic information platform security control method, system, device and medium, which adopts the following technical solutions:
[0005] In a first aspect, the present application provides a method for controlling the security of a basic information platform, comprising the following steps:
[0006] When a user accesses data, obtain the user ID and the data ID of the required data;
[0007] Determining the target business category and target security level of the required data according to the data identifier;
[0008] Determining, based on the user identifier, the user's access rights to the target business category data and the user's access rights to the target security level data;
[0009] When the user has access rights to the target business category data and the user has access rights to the target security level data, the user is allowed to access the required data.
[0010] By adopting the above technical solution, the present application obtains the user identification and data identification when the user accesses the data, determines the target business category and target security level of the data based on the data identification, and then determines the user's access rights to the target business category data and the user's access rights to the target security level data based on the user identification, thereby allowing the user to access the required data when the user meets the access rights. Security control is performed through dual access rights, thereby improving the security protection of basic information, and determining the access rights for different target business category data based on the user identification, without the need for separate settings, which facilitates access security control.
[0011] Optionally, determining the user's access rights to the target business category data and the user's access rights to the target security level data according to the user identifier comprises the following steps:
[0012] Determine the user business line and user level corresponding to the user identifier;
[0013] When the user business line has access rights to the target business category data, determining that the user has access rights to the target business category data;
[0014] When the user level is greater than or equal to the user required level corresponding to the target security level data, it is determined that the user has access rights to the target security level data.
[0015] By adopting the above technical solution, this application determines the user business line and user ID corresponding to the user identifier, and when the user business line has access rights to the target business category of the required data, determines that the user has access rights to the target business category of the required data, and then when the user level is greater than or equal to the user required level corresponding to the target security level data, determines that the user has access rights to the target security level data, thereby confirming the user's access rights.
[0016] Optionally, when the user level is greater than or equal to the user required level corresponding to the target security level data, before determining that the user has access rights to the target security level data, the method includes the following steps:
[0017] Obtaining a set of users allowed to access the target security level data;
[0018] Obtaining the organizational level set corresponding to the set of users allowed to access and the organizational level corresponding to the user in a preset organizational structure tree;
[0019] When the organizational level is greater than or equal to the lowest level in the organizational level set, it is determined that the user level is greater than or equal to the user required level corresponding to the target security level data.
[0020] By adopting the above technical solution, the present application obtains a preset set of users allowed to access the target security level data, and then obtains the organizational hierarchy set corresponding to the set of users allowed to access and the organizational hierarchy of the user according to the preset organizational structure tree, and then, when the organizational hierarchy is greater than or equal to the lowest level of the organizational hierarchy set, determines that the user level is greater than or equal to the required level of the user corresponding to the target security level data, so that security managers do not need to set role access rights for too many users. By presetting the organizational structure tree and the set of users allowed to access, and then performing organizational hierarchy comparison, they can quickly determine the levels of other users and improve the efficiency of permission management.
[0021] Optionally, the process of obtaining the set of users allowed to access the target security level data includes the following steps:
[0022] Monitor and obtain the access permission user change instruction of the target security level data;
[0023] Determine the users to be added or deleted according to the change instruction;
[0024] Performing an update operation on the set of users allowed to access according to the change instruction;
[0025] Notify users and departments related to the change order;
[0026] The change instruction and the update operation are recorded.
[0027] By adopting the above technical solution, the present application updates the required level of accessible users of the target security level data by obtaining the allowed access user change instruction and updating the allowed access user set according to the change instruction.
[0028] Optionally, before allowing the user to access the required data, the following steps are included:
[0029] Obtaining the user's historical access records, and predicting the user's normal access behavior based on the historical access records;
[0030] When the current access behavior of the user does not match the normal access behavior, performing a risk assessment on the current access behavior of the user to obtain a risk assessment result;
[0031] Take corresponding control measures based on the risk assessment results.
[0032] By adopting the above technical solution, this application predicts the user's normal access behavior through the user's historical access records. When the user's current access behavior does not match the normal access behavior, the user's current access behavior is evaluated for risk, and a risk assessment result is obtained. Corresponding control measures are taken according to the risk assessment result, thereby avoiding the loss of important data caused by abnormal access.
[0033] Optionally, when the current access behavior of the user does not match the normal access behavior, the process of performing risk assessment on the current access behavior of the user includes the following steps:
[0034] Obtaining a target security level for data currently accessed by the user;
[0035] When the target security level of the currently accessed data is higher than a preset target security level threshold, and the frequency of the user's current access to data is higher than a preset frequency threshold, it is determined that the user's current access behavior has a risk.
[0036] By adopting the above technical solution, the present application obtains the target security level of the currently accessed data. When the target security level is higher than the preset target security level threshold and the frequency of the user's current access to the data is higher than the preset frequency threshold, it is determined that the user's current access behavior is risky, and corresponding control measures are taken.
[0037] Optionally, the control measures include prompting the user to confirm the legitimacy of the operation, requiring the user to provide additional identity authentication information, limiting the number of times the user accesses, or denying the user access.
[0038] In a second aspect, the present application provides a basic information platform security control system, comprising:
[0039] The identification acquisition module is used to obtain the user identification and the data identification of the required data when the user accesses the data;
[0040] a target business category and target security level determination module, configured to determine the target business category and target security level of the required data according to the data identifier;
[0041] an access authority determination module, configured to determine, based on the user identifier, the user's access authority to the target business category data and the user's access authority to the target security level data;
[0042] The access control module is configured to allow the user to access the required data when the user has access rights to the target business category data and the user has access rights to the target security level data.
[0043] In a third aspect, the present application provides a computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the above-mentioned basic information platform security control method when executing the computer program.
[0044] In a fourth aspect, the present application provides a computer-readable storage medium on which a computer program is stored, and when the computer program is executed by a processor, the steps of the above-mentioned basic information platform security control method are implemented.
[0045] In summary, this application includes at least one of the following beneficial technical effects:
[0046] 1. When a user accesses data, this application obtains a user identifier and a data identifier, determines the target business category and target security level of the data based on the data identifier, and then determines the user's access rights to the target business category data and the target security level data based on the user identifier. This allows the user to access the required data if the user meets the access rights. This dual access right control improves the security protection of basic information. In addition, access rights for different target business category data are determined based on the user identifier, eliminating the need for separate settings, facilitating access security control.
[0047] 2. This application obtains a preset set of users allowed to access the target security level data, then obtains the organizational hierarchy set corresponding to the set of users allowed to access and the organizational hierarchy of the user from a preset organizational structure tree. Then, when the organizational hierarchy is greater than or equal to the lowest level of the organizational hierarchy set, the application determines that the user level is greater than or equal to the required level of the user corresponding to the target security level data. This eliminates the need for security managers to set too many user role access permissions. By presetting the organizational structure tree and the set of users allowed to access, and then performing organizational hierarchy comparison, the levels of other users can be quickly determined, thereby improving the efficiency of permission management.
[0048] 3. This application predicts the user's normal access behavior through the user's historical access records. When the user's current access behavior does not match the normal access behavior, a risk assessment is performed on the user's current access behavior to obtain a risk assessment result. Corresponding control measures are taken according to the risk assessment result to avoid the loss of important data caused by abnormal access. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] Figure 1 This is an exemplary flow chart of a basic information platform security control method of the present application;
[0050] Figure 2 is an exemplary flow chart of the present application for determining a user's access rights to target security level data;
[0051] Figure 3 This is an exemplary flow chart of the application's risk assessment of the user's current access behavior;
[0052] Figure 4 This is a module diagram of a basic information platform security control system according to an embodiment of the present application;
[0053] Figure 5 It is a diagram of the internal structure of the computer according to the embodiment of the present application. DETAILED DESCRIPTION
[0054] The terms used in the following examples of the present application are only for the purpose of describing specific embodiments and are not intended to limit the present application. As used in the specification and appended claims of this application, the singular expressions "a," "an," "said," "above," "the," and "this" are intended to include plural expressions as well, unless the context clearly indicates otherwise. It should also be understood that the term "and / or" used in this application refers to any or all possible combinations comprising one or more of the listed items.
[0055] In the following, the terms "first" and "second" are used for descriptive purposes only and should not be understood to imply or suggest relative importance or implicitly indicate the number of the technical features indicated. Therefore, the features defined as "first" and "second" may explicitly or implicitly include one or more of the features. In the description of the embodiments of this application, unless otherwise specified, "plurality" means two or more.
[0056] In order to improve the security of basic information platform data, it is necessary to control user access behavior and data operations. The traditional method is mainly based on role-based access control, which has poor management flexibility for data of various target business categories.
[0057] The present application provides a basic information platform security control method, system, device and medium. When a user accesses data, the user identification and data identification are obtained, and the target business category and target security level of the data are determined according to the data identification. Then, the user's access rights to the target business category data and the user's access rights to the target security level data are determined according to the user identification. Thus, the user is allowed to access the required data when the user meets the access rights. Thus, the access rights for different target business category data are determined according to the user identification without the need for separate settings, and different access rights are also set for data with different target security levels, thereby facilitating access security control.
[0058] The embodiments of the present application are described in further detail below with reference to the accompanying drawings.
[0059] The embodiments of the present application provide a method performed by an electronic device, which can be either a server or a terminal device. The server can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing cloud computing services. In this embodiment, the terminal device is a server, but is not limited to this. It can also be a smart tablet, computer, etc. The terminal device and the server can be directly or indirectly connected via wired or wireless communication, which is not limited in this embodiment of the present application.
[0060] The method of this application is applied to the national land and space basic information platform, which is deployed on the government cloud platform. The government cloud platform is specifically operated and maintained by local information service centers at all levels.
[0061] The basic information platform adopts a Docker containerized microservice architecture with front-end and back-end separation. In terms of platform security, security control is carried out through various means such as system login, permission control, security authentication, attack interception, and security audit. In terms of data security, security control is carried out through data access control, data encryption and desensitization processing, data service monitoring, and data backup. Among them, in terms of data access control, by adopting the method of this application, security control of data in the national land and space basic information platform is achieved, and at the same time, flexible management of various business category data in the national land and space basic information platform is carried out to facilitate security management operations by local information service centers at all levels.
[0062] Reference Figure 1 , Figure 1 This is an exemplary flowchart of a basic information platform security control method of the present application.
[0063] A basic information platform security control method includes the following steps:
[0064] S110 . When a user accesses data, a user identifier and a data identifier of the required data are obtained.
[0065] Among them, the user identifier is information that can represent the user's identity, such as an ID number, mobile phone number, or a registered account that the user can use based on the business, and the data identifier is information that can uniquely identify the target data that the user wants to access, which can specifically be a data number, a hash value generated based on the data title or content, etc.
[0066] Specifically, the system monitors the user's operation of accessing data, and then obtains the user ID and the data ID of the required data accessed by the user.
[0067] S120: Determine the target business category and target security level of the required data according to the data identifier.
[0068] The target business category and target security level are the business category and security level corresponding to the required data. Data can be pre-classified as different business data based on different business attributes to meet the data needs of different business departments. Therefore, the required data can be categorized by business category. Furthermore, different security levels can be set based on the importance of each piece of data.
[0069] Specifically, based on data attributes, data is divided into target business categories such as basic geographic data, land resource data, mineral resource data, geological environment and geological disaster data, natural resource property rights data, socioeconomic data, spatial planning data, spatial management data, statistical data, development and reform data, ecological and environmental data, housing and construction data, transportation data, water conservancy data, agricultural and rural data, meteorological data, and internet and Internet of Things data. Based on the data's value, legal requirements, and its sensitivity and criticality, data is divided into different target security levels, such as public basic data, professional basic data, and business management data. The business categories and security levels of the data are pre-labeled.
[0070] S130: Determine the user's access rights to the target business category data and the user's access rights to the target security level data according to the user identifier.
[0071] Step S130 includes the following steps:
[0072] S131. Determine the user business line and user level corresponding to the user identifier.
[0073] Among them, users include public users and users of relevant departments. Users of relevant departments include users of the Statistics Bureau, the Development and Reform Bureau, the Ecological Environment Bureau, the Housing and Urban-Rural Development Bureau, the Transportation Bureau, and so on. According to the user ID, you can search in the database to determine the business line corresponding to the user and the level of the user in the business line. Among them, public users belong to the lowest level of users and can only access public basic data. The level of department users is obtained in the organizational structure tree corresponding to their respective departments. Among them, the organizational structure tree can be constructed based on the organizational structure of each department of the entire land and space management. The organizational structure tree includes multiple organizational levels.
[0074] Specifically, when a user registers and logs in, their information is saved in the database. If they are a department user, the department administrator must join or approve the user and add the user's organization node to the department's organizational structure. After obtaining the user ID, the user's corresponding business line and user level can be determined. If the user is not a department user, they are classified as a public user.
[0075] S132: When the user business line has access rights to the target business category data, determine whether the user has access rights to the target business category data.
[0076] The target business category data refers to the data of the business category corresponding to the data required by the user, and each user business line has pre-set access rights to the data of each business category.
[0077] Specifically, the Water Conservancy Bureau can access water conservancy data, as well as basic geographic data, land resource data, mineral resource data, geological environment and geological disaster data, natural resource property data, socio-economic data, spatial planning data, spatial management data, and the public basic data parts of other department data, as well as the data parts that the Water Conservancy Bureau needs to use. The Transportation Bureau can access transportation data, as well as basic geographic data, land resource data, mineral resource data, geological environment and geological disaster data, natural resource property data, socio-economic data, spatial planning data, spatial management data, and the public basic data parts of other department data, as well as the data parts that the Transportation Bureau needs to use, and so on.
[0078] S133: When the user level is greater than or equal to the user required level corresponding to the target security level data, determine that the user has access rights to the target security level data.
[0079] The target security level data refers to the data of the security level corresponding to the data required by the user.
[0080] S140 . When the user has access rights to target business category data and target security level data, allow the user to access required data.
[0081] Before step S133, the method includes the following steps:
[0082] Reference Figure 2 , Figure 2 This is an exemplary flow chart of the present application for determining a user's access rights to target security level data.
[0083] S210: Obtain a set of users who are allowed to access target security level data.
[0084] Among them, users in the allowed access user set can access data of the target security level corresponding to the required data.
[0085] Specifically, when security managers set permissions for users, they pre-set access authorizations for some department users, such as the authorization categories for data of specific services, including querying data or editing data, and the authorization periods for data of specific services, including one month, three months, etc. The set of allowed access users is obtained based on the corresponding settings of the target security level data.
[0086] Wherein, step S210 includes the following sub-steps;
[0087] S211. Monitor and obtain the instruction to change the user allowed to access the target security level data.
[0088] S212: Determine the users to be added or deleted according to the change instruction.
[0089] Among them, when the security manager sets the permissions for users, the system monitors and obtains the instructions for changing the user allowed to access, and then determines the users that need to be added or deleted based on the instructions.
[0090] It is understandable that when the security administrator sets an access period for the user's access rights, when the access period expires, the system will also monitor the change instruction and then change the state to inaccessible.
[0091] S213: Update the set of users allowed to access according to the change instruction.
[0092] By doing so, the set of users permitted to access is kept up to date, thereby updating the required level of users permitted to access the target security level data.
[0093] S214. Notify users and departments related to the change instruction.
[0094] S215: Record the change instructions and update operations.
[0095] Through this, affected users and departments are notified to ensure they are aware of the latest access rights information, while change instructions and update operations are recorded to ensure the security and traceability of the system and conduct regular audits.
[0096] S220: Obtain the organizational level set corresponding to the set of users allowed to access the system and the organizational level corresponding to the user in the preset organizational structure tree.
[0097] Among them, the organizational structure tree is constructed according to the organizational structure of each department of the entire land space management, including multiple levels. The corresponding organizational level set is obtained based on the set of users allowed to access, and the organizational level corresponding to the current access user is obtained, so that a comparison can be made to determine whether the user has access rights to the target security level data.
[0098] S230: When the organizational level is greater than or equal to the lowest level in the organizational level set, determine that the user level is greater than or equal to the user required level corresponding to the target security level data.
[0099] Among them, by traversing each organizational level in the organizational level set, the lowest level is determined, and then the user's organizational level is compared with the lowest level. When other users at the same organizational level as the user or at a lower level than the user have the authority to access the target security level data, it is determined that the user also has the authority to access the target security level data.
[0100] It can be understood that if the current user belongs to a water conservancy bureau user, he or she has not been set with access rights to water conservancy project data by the security management personnel in the system, but there is a second user with access rights set in the organizational structure tree of the water conservancy department, and the second user belongs to the same level as the current user in the organizational structure tree, then it means that the organizational level of the current user has access rights to the water conservancy project data, and the current user is allowed to access the water conservancy project data.
[0101] Through this, security managers do not need to set too many user role access rights. By presetting the organizational structure tree and allowing access to the user set, and then comparing the organizational levels, they can quickly determine the level of other users and improve the efficiency of permission management.
[0102] In some embodiments, before allowing the user to access the required data, the following steps are further included:
[0103] Reference Figure 3 , Figure 3 This is an exemplary flow chart of the risk assessment of the user's current access behavior in this application.
[0104] S310: Obtain the user's historical access records, and predict the user's normal access behavior based on the historical access records.
[0105] Among them, the user's historical access records include user identification, access time, access pages and other information. By performing data mining on the user's historical access records, the frequent sequence of user-accessed pages can be obtained, thereby predicting the user's normal access behavior.
[0106] S320: When the user's current access behavior does not match the normal access behavior, a risk assessment is performed on the user's current access behavior to obtain a risk assessment result.
[0107] Among them, mismatches with normal access behaviors include large differences in the security level of the accessed data and the data service category, high access frequency, and large differences in the time points of access.
[0108] Specifically, when it does not match the normal access behavior, the target security level of the user's current access data is obtained, and the frequency of the user's current access data is obtained. When the target security level of the current access data is higher than the preset target security level threshold, and the frequency of the current access data is higher than the preset frequency threshold, it is determined that the current access behavior is risky, and corresponding control measures are taken.
[0109] S330. Take corresponding control measures based on the risk assessment results.
[0110] It is worth noting that the risk level can be determined based on the target security level of the user's current access data and the frequency of the user's current access to the data, and corresponding control measures can be taken according to the risk level. Control measures include prompting the user to confirm the legality of the operation, requiring the user to provide additional authentication information, limiting the number of user access times, denying user access, etc.
[0111] Through this, corresponding control measures can be taken for risky access behaviors, thereby improving the security of basic information data.
[0112] The implementation principle of a basic information platform security control method in an embodiment of the present application is as follows: when a user accesses data, the present application obtains a user identifier and a data identifier, determines the target business category and target security level of the data based on the data identifier, and then determines the user's access rights to the target business category data and the user's access rights to the target security level data based on the user identifier, thereby allowing the user to access the required data when the user meets the access rights, thereby determining the access rights for different target business category data based on the user identifier, without the need for separate settings, and facilitating access security control.
[0113] In the second aspect, the present application provides a basic information platform security control system. The following describes the basic information platform security control system of the present application in combination with the above-mentioned basic information platform security control method. Figure 4 , Figure 4 This is a module diagram of a basic information platform security control system according to an embodiment of the present application.
[0114] A basic information platform security control system, comprising:
[0115] The identification acquisition module 410 is used to obtain the user identification and the data identification of the required data when the user accesses the data;
[0116] A target business category and target security level determination module 420 is configured to determine a target business category and a target security level of the required data according to the data identifier;
[0117] an access permission determination module 430 for determining the user's access permission to the target business category data and the user's access permission to the target security level data according to the user identifier;
[0118] The access control module 440 is configured to allow the user to access the required data when the user has access rights to the target business category data and the user has access rights to the target security level data.
[0119] In one embodiment, the present application provides a computer device, which may be a server, and its internal structure diagram may be as follows: Figure 5 As shown. The computer device includes a processor, a memory and a network interface connected via a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The database of the computer device is used to store data. The network interface of the computer device is used to communicate with an external terminal via a network connection. When the computer program is executed by the processor, a basic information platform security control method is implemented.
[0120] Those skilled in the art will understand that Figure 5 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.
[0121] In one embodiment, a computer device is further provided, including a memory and a processor. The memory stores a computer program, and the processor implements the steps in the above method embodiments when executing the computer program.
[0122] Those skilled in the art will appreciate that all or part of the processes in the above-described method embodiments can be implemented by instructing the relevant hardware through a computer program. The above-described computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the above-described method embodiments. Any reference to memory, storage, database, or other media used in the embodiments provided herein may include at least one of non-volatile and volatile memory. Non-volatile memory may include read-only memory (ROM), magnetic tape, floppy disk, flash memory, or optical storage. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM).
[0123] The above are all preferred embodiments of the present application, and are not intended to limit the scope of protection of the present application. Therefore, any equivalent changes made based on the structure, shape, and principle of the present application should be included in the scope of protection of the present application.
Claims
1. A basic information platform security control method, characterized in that: The steps include: When a user accesses data, obtain the user ID and the data ID of the required data; Determine the target business category and target security level corresponding to the required data based on the data identifier, wherein the target business category includes basic geographic data, land resource data, mineral resource data, geological environment and geological disaster data, natural resource property rights data, socio-economic data, spatial planning data, spatial management data, statistical data, development and reform data, ecological environment data, housing and construction data, transportation data, water conservancy data, agricultural and rural data, meteorological data, Internet and Internet of Things data; the target security level is divided according to the value of the data, legal requirements, and the sensitivity and criticality of the data, including public basic data, professional basic data and business management data; Determining, based on the user identifier, the user's access rights to the target business category data and the user's access rights to the target security level data; When the user has access rights to the target business category data and the user has access rights to the target security level data, allowing the user to access the required data; Determining the user's access rights to the target business category data and the user's access rights to the target security level data according to the user identifier includes the following steps: Determine the user business line and user level corresponding to the user identifier; Obtaining a set of users allowed to access the target security level data, wherein, when setting user permissions, access authorization for some department users is pre-set, including the authorization category and authorization period for data of specific services. Based on the set of allowed access users corresponding to the target security level data, a set of allowed access users is obtained, and when the authorization period expires, the state is changed to inaccessible; Obtaining the organizational level set corresponding to the set of users allowed to access and the organizational level corresponding to the user in a preset organizational structure tree; When the organizational level is greater than or equal to the lowest level in the organizational level set, determining that the user level is greater than or equal to the user required level corresponding to the target security level data; When the user business line has access rights to the target business category data, determining that the user has access rights to the target business category data; When the user level is greater than or equal to the user required level corresponding to the target security level data, it is determined that the user has access rights to the target security level data.
2. The basic information platform security control method according to claim 1, characterized in that: The process of obtaining the set of users allowed to access the target security level data includes the following steps: Monitor and obtain the access permission user change instruction of the target security level data; Determine the users to be added or deleted according to the change instruction; Performing an update operation on the set of users allowed to access according to the change instruction; Notify users and departments related to the change order; The change instruction and the update operation are recorded.
3. The basic information platform security control method according to claim 1, characterized in that: Before allowing the user to access the required data, the following steps are included: Obtaining the user's historical access records, and predicting the user's normal access behavior based on the historical access records; When the current access behavior of the user does not match the normal access behavior, performing a risk assessment on the current access behavior of the user to obtain a risk assessment result; Take corresponding control measures based on the risk assessment results.
4. The basic information platform security control method according to claim 3, characterized in that: The process of performing risk assessment on the user's current access behavior when the user's current access behavior does not match the normal access behavior includes the following steps: Obtaining a target security level for data currently accessed by the user; When the target security level of the currently accessed data is higher than a preset target security level threshold, and the frequency of the user's current access to data is higher than a preset frequency threshold, it is determined that the user's current access behavior has a risk.
5. The basic information platform security control method according to claim 4, characterized in that: The control measures include prompting the user to confirm the legitimacy of the operation, requiring the user to provide additional identity authentication information, limiting the number of times the user accesses, and denying the user access.
6. A basic information platform security control system, characterized in that: The basic information platform security control method according to any one of claims 1 to 5 comprises: The identification acquisition module is used to obtain the user identification and the data identification of the required data when the user accesses the data; A target business category and target security level determination module, configured to determine a target business category and a target security level corresponding to the required data according to the data identifier; an access authority determination module, configured to determine, based on the user identifier, the user's access authority to the target business category data and the user's access authority to the target security level data; The access control module is configured to allow the user to access the required data when the user has access rights to the target business category data and the user has access rights to the target security level data.
7. A computer device, characterized in that: The method comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the steps of the basic information platform security control method described in any one of claims 1 to 5 are implemented.
8. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the basic information platform security control method described in any one of claims 1 to 5 are implemented.
Citation Information
Patent Citations
Method and device for data access permission control, computer equipment and storage medium
CN111191210A
Sensitive data identification method and device
CN116108409A
Data request processing method and device, equipment and storage medium
CN116226923A