A building data information security access control method, device, equipment and medium
By building a stealth communication and access gateway in the IPv6 network, authentication and access management are performed, and abnormal traffic is monitored, thus solving the security threats in the transmission and access of building inspection data and achieving secure and reliable data access.
Patent Information
- Application Number
- CN202410338390.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-03-22
- Publication Date
- 2026-03-03
- Estimated Expiration
- 2044-03-22
AI Technical Summary
Building inspection data is vulnerable to attacks such as unauthorized access, identity impersonation, sniffing, and eavesdropping during transmission and access, which compromises the security of information systems.
The system employs a stealth communication gateway and a stealth access gateway based on an IPv6 network. It acquires user access information, screens identity parameters, generates security certificates, verifies access permissions, uses a dynamic DNS module to determine the target address, establishes a secure connection, monitors abnormal traffic transmission, performs anomaly analysis, and optimizes access paths.
It improves the security of building data information, ensures that the access process cannot be scanned, sniffed, or content restored, protects user identity and access permissions, and enhances secure access in the IPv6 mobile network environment.
Smart Images

Figure CN118250048B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of information security, and in particular to a method, apparatus, equipment and medium for secure access control of building data information. Background Technology
[0002] In today's rapidly developing modern society and economy, information technology, as a product of the times, has brought numerous benefits to various industries. In the construction industry, informatization helps save costs and improve the efficiency of engineering construction. The application of CAD (Computer-Aided Design) brought about the first revolution in the construction industry. Compared to this first revolution, BIM (Building Information Modeling) not only changes production tools but also production methods and work mindsets. The national standard "Unified Standard for the Application of Building Information Modeling" divides the entire life cycle of a building into five stages: planning and design, surveying and design, construction and supervision, operation and maintenance, demolition or renovation, and reinforcement. With the development of the social economy and the continuous updating and development of building technology, appropriate reinforcement of existing buildings has become a common need. Building inspection and assessment are important technical foundations for building reinforcement, renovation, and operation and maintenance.
[0003] Currently, building inspection and assessment first requires acquiring building inspection data. This data is then uploaded to a server for information transmission and access. However, this transmission and access of building inspection data also faces serious security challenges, such as unauthorized access, identity impersonation, sniffing and eavesdropping attacks, as well as intrusions by worm viruses and malware. These attacks can damage information systems or lead to the theft, alteration, and misuse of sensitive data, severely threatening information system security and compromising the security of building data. Summary of the Invention
[0004] To address at least one of the aforementioned technical problems, this application provides a method, apparatus, device, and medium for secure access control of building data information.
[0005] Firstly, this application provides a method for secure access control of building data information, employing the following technical solution:
[0006] A stealth communication gateway and a stealth access gateway are constructed based on an IPv6 network. The stealth access gateway is a gateway set between the user equipment and the building data information access device, and the stealth communication gateway is a gateway set between the building data information access device and the building data information storage device.
[0007] When a request to access building data information is detected, user access information is obtained;
[0008] The user access information is screened for access parameters to obtain an access parameter data set;
[0009] Determine whether the identity parameter data in the access parameter data group conforms to the preset identity standard data. If it does, generate security certificate data based on the identity parameter data and the preset identity standard data, and add the security certificate data to the access parameter data group to obtain the first-level access data group.
[0010] A verification address is generated based on the security certificate data in the first-level access data group, and a connection is established between the verification address and the stealth access gateway.
[0011] The access data parameters in the first-level access data group are analyzed to obtain building access data;
[0012] The target address is determined based on the building access data and the dynamic DNS module in the IPv6 network, and a connection is established between the target address and the stealth communication gateway to access the building data information corresponding to the building access data in the building data information storage device. The target address is the data storage address corresponding to the building access data.
[0013] In one possible implementation, the analysis of access data parameter data in the primary access data group to obtain building access data includes:
[0014] Determine the user access permissions corresponding to the user access information based on the access data parameters.
[0015] The user access permissions are matched with different access permissions in the preset permission framework to determine whether the user access permissions have direct access rights. If they do, a permission tag matching the user access permissions is determined based on the preset permission framework, and the permission tag is added to the access data parameters to obtain building access data.
[0016] In one possible implementation, determining whether the user access permission includes direct access rights further includes:
[0017] If the user access permission does not have direct access rights, then the permission acquisition node of the user access permission is determined according to the preset permission framework, and node verification information is generated according to the permission acquisition node;
[0018] The node verification information is sent to the permission device corresponding to the permission-obtaining node, and the verification return information returned by the permission device is received.
[0019] Determine whether the verification status in the verification return information returned within a preset time has changed according to a preset time. If it has, update the first-level access data group based on the verification return information and the set access time limit to obtain the second-level access data group.
[0020] Building access data is determined based on the secondary access data group.
[0021] In one possible implementation, the step of determining the target address based on the building access data and the dynamic DNS module in the IPv6 network, and establishing a connection between the target address and the stealth communication gateway, further includes:
[0022] Monitor whether the user device corresponding to the user access information establishes a connection with the building information storage device corresponding to the building access data through the IPv6 network. If a connection is established, obtain the traffic transmission information between the user device and the building information storage device in real time.
[0023] The traffic transmission information is organized according to the transmission time nodes to obtain the transmission fluctuation diagram of data transmission between the user equipment and the building information storage device;
[0024] The transmission fluctuation diagram is fitted to the preset traffic transmission diagram according to the transmission time nodes to determine whether there are any abnormalities in the traffic transmission data corresponding to different transmission time nodes. If there are, historical traffic transmission data is obtained, and data transmission anomaly analysis is performed on the user equipment and building information storage device based on the historical traffic transmission data to obtain the abnormal access degree of the user equipment. The historical traffic transmission data is the traffic transmission data when different models of user equipment communicate with different building information storage devices.
[0025] The abnormal access level is compared with the access level in the abnormal access standard to obtain the user access rules, and the access data parameters in the first-level access data group are adjusted based on the user access rules.
[0026] In one possible implementation, the step of performing data transmission anomaly analysis on the user equipment and building information storage device based on the historical traffic transmission data to obtain the degree of abnormal access of the user equipment includes:
[0027] Based on the historical traffic transmission data, determine the highest and lowest traffic transmission rates of different types of user equipment during each data communication with different building information storage devices, and use the highest and lowest traffic transmission rates as the transmission numerators and the time used for each data communication process as the transmission denominator.
[0028] The change in transmission rate for each data communication process can be obtained by calculating the ratio of the transmission numerator to the transmission denominator.
[0029] Arrange the transmission rate change values in time sequence to obtain the transmission sequence of historical traffic transmission data;
[0030] All segmentation points in the transmission sequence are obtained by considering the changes in transmission rates between different types of user equipment and different building information storage devices, and the value of each transmission rate.
[0031] The transmission sequence is segmented based on all the split points. The similarity of the change value sequences corresponding to each two adjacent transmission sequences is obtained. Based on the similarity, it is determined whether each two adjacent transmission sequences need to be merged, and two or more transmission data segments are obtained.
[0032] Based on the data security situation of each change value corresponding to each transmission data segment within a preset time, an anomaly analysis is performed on each change value corresponding to each transmission data segment to obtain the degree of anomaly of different change values corresponding to different transmission data segments during each data communication between different models of user equipment and different building information storage devices.
[0033] Based on the degree of anomaly, the degree of abnormal access to the data segment corresponding to the user equipment, the building information storage device, and the transmission time node where traffic transmission data anomalies occur is obtained.
[0034] In one possible implementation, the anomaly analysis of each changed value corresponding to each transmitted data segment based on the data security situation occurring within a preset future time period for each changed value corresponding to each transmitted data segment, to obtain the degree of anomaly of different changed values corresponding to different transmitted data segments during each data communication between different models of user equipment and different building information storage devices, includes:
[0035] Each data segment's corresponding change value within a preset future timeframe is obtained to assess its data security status.
[0036] Determine whether each change value corresponding to each transmitted data segment has the data security situation. If it does, input the data security situation into the traffic transmission anomaly model for identification, and obtain the degree of anomaly of different change values corresponding to different transmitted data segments during each data communication between different types of user equipment and different building information storage devices.
[0037] In one possible implementation, the comparison of the abnormal access level with the access level in the abnormal access criteria further includes:
[0038] Determine whether the abnormal access level is within a preset abnormal level. If so, determine the access path corresponding to the abnormal access level and perform access optimization processing on the access path.
[0039] Secondly, this application provides a building data information security access control device, which adopts the following technical solution:
[0040] A building data information security access control device, comprising:
[0041] A gateway construction module is used to build a stealth communication gateway and a stealth access gateway based on an IPv6 network. The stealth access gateway is a gateway set between a user equipment and a building data information access device, and the stealth communication gateway is a gateway set between a building data information access device and a building data information storage device.
[0042] The information acquisition module is used to acquire user access information when a request for accessing building data information is detected.
[0043] The parameter screening module is used to screen the user access information for access parameters to obtain an access parameter data set.
[0044] The identity determination module is used to determine whether the identity parameter data in the access parameter data group conforms to the preset identity standard data. If it does, it generates security certificate data based on the identity parameter data and the preset identity standard data, and adds the security certificate data to the access parameter data group to obtain the first-level access data group.
[0045] The first connection module is used to generate a verification address based on the security certificate data in the first-level access data group, and establish a connection between the verification address and the stealth access gateway.
[0046] The parameter analysis module is used to analyze the access data parameter data in the first-level access data group to obtain building access data;
[0047] The second connection module is used to determine the target address based on the building access data and the dynamic DNS module in the IPv6 network, and establish a connection between the target address and the stealth communication gateway to access the building data information corresponding to the building access data in the building data information storage device. The target address is the data storage address corresponding to the building access data.
[0048] In one possible implementation, when the parameter analysis module analyzes the access data parameter data in the first-level access data group to obtain building access data, it is specifically used for:
[0049] Determine the user access permissions corresponding to the user access information based on the access data parameters.
[0050] The user access permissions are matched with different access permissions in the preset permission framework to determine whether the user access permissions have direct access rights. If they do, a permission tag matching the user access permissions is determined based on the preset permission framework, and the permission tag is added to the access data parameters to obtain building access data.
[0051] In another possible implementation, the apparatus further includes: a verification generation module, a verification interaction module, a verification update module, and a data determination module, wherein,
[0052] The verification generation module is used to determine the permission acquisition node of the user's access permission according to the preset permission framework when the user's access permission does not have direct access rights, and generate node verification information according to the permission acquisition node.
[0053] The verification interaction module is used to send the node verification information to the permission device corresponding to the permission node, and receive the verification return information returned by the permission device.
[0054] The verification update module is used to determine whether the verification status in the verification return information returned within a preset time has changed in a preset manner. If it has changed, the first-level access data group is updated based on the verification return information and the set access time limit to obtain the second-level access data group.
[0055] The data determination module is used to determine building access data based on the secondary access data group.
[0056] In another possible implementation, the device further includes: a traffic acquisition module, an information processing module, an anomaly analysis module, and a parameter adjustment module, wherein,
[0057] The traffic acquisition module is used to monitor whether the user device corresponding to the user access information establishes a connection with the building information storage device corresponding to the building access data through the IPv6 network. If a connection is established, the traffic transmission information between the user device and the building information storage device is acquired in real time.
[0058] The information processing module is used to process the traffic transmission information according to the transmission time nodes to obtain a transmission fluctuation diagram of data transmission between the user equipment and the building information storage device.
[0059] The anomaly analysis module is used to fit the transmission fluctuation diagram with the preset traffic transmission diagram according to the transmission time nodes, determine whether there are anomalies in the traffic transmission data corresponding to different transmission time nodes, and if so, obtain historical traffic transmission data, and perform data transmission anomaly analysis on the user equipment and building information storage device based on the historical traffic transmission data to obtain the abnormal access level of the user equipment. The historical traffic transmission data is the traffic transmission data when different models of user equipment communicate with different building information storage devices.
[0060] The parameter adjustment module is used to compare the abnormal access level with the access level in the abnormal access standard to obtain user access rules, and adjust the access data parameter data in the first-level access data group based on the user access rules.
[0061] In another possible implementation, when the anomaly analysis module performs data transmission anomaly analysis on the user equipment and the building information storage device based on the historical traffic transmission data to obtain the abnormal access level of the user equipment, it is specifically used for:
[0062] Based on the historical traffic transmission data, determine the highest and lowest traffic transmission rates of different types of user equipment during each data communication with different building information storage devices, and use the highest and lowest traffic transmission rates as the transmission numerators and the time used for each data communication process as the transmission denominator.
[0063] The change in transmission rate for each data communication process can be obtained by calculating the ratio of the transmission numerator to the transmission denominator.
[0064] Arrange the transmission rate change values in time sequence to obtain the transmission sequence of historical traffic transmission data;
[0065] All segmentation points in the transmission sequence are obtained by considering the changes in transmission rates between different types of user equipment and different building information storage devices, and the value of each transmission rate.
[0066] The transmission sequence is segmented based on all the split points. The similarity of the change value sequences corresponding to each two adjacent transmission sequences is obtained. Based on the similarity, it is determined whether each two adjacent transmission sequences need to be merged, and two or more transmission data segments are obtained.
[0067] Based on the data security situation of each change value corresponding to each transmission data segment within a preset time, an anomaly analysis is performed on each change value corresponding to each transmission data segment to obtain the degree of anomaly of different change values corresponding to different transmission data segments during each data communication between different models of user equipment and different building information storage devices.
[0068] Based on the degree of anomaly, the degree of abnormal access to the transmission data segment corresponding to the user equipment, the building information storage device, and the transmission time node where traffic transmission data anomalies occur is obtained.
[0069] In another possible implementation, the anomaly analysis module performs anomaly analysis on each changed value corresponding to each transmitted data segment based on the data security situation occurring within a preset future timeframe, to obtain the degree of anomaly of different changed values corresponding to different transmitted data segments during data communication between different user equipment models and different building information storage devices. Specifically, this is used to:
[0070] Each data segment's corresponding change value within a preset future timeframe is obtained to assess its data security status.
[0071] Determine whether each change value corresponding to each transmitted data segment has the data security situation. If it does, input the data security situation into the traffic transmission anomaly model for identification, and obtain the degree of anomaly of different change values corresponding to different transmitted data segments during each data communication between different types of user equipment and different building information storage devices.
[0072] In another possible implementation, the apparatus further includes a path optimization module, wherein,
[0073] The path optimization module is used to determine whether the abnormal access level is a preset abnormal level. If so, it determines the access path corresponding to the abnormal access level and performs access optimization processing on the access path.
[0074] Thirdly, this application provides an electronic device that adopts the following technical solution:
[0075] At least one processor;
[0076] Memory;
[0077] At least one application, wherein the at least one application is stored in memory and configured to be executed by at least one processor, the at least one application being configured to: execute a building data information security access control method as described in any of the first aspects.
[0078] Fourthly, this application provides a computer-readable storage medium, which adopts the following technical solution:
[0079] A computer-readable storage medium having a computer program stored thereon, which, when executed in a computer, causes the computer to perform the building data information security access control method as described in any of the first aspects.
[0080] In summary, this application includes at least one of the following beneficial technical effects:
[0081] When a user accesses building data information via a network connected to their user device, a stealth communication gateway and a stealth access gateway are constructed based on the IPv6 network. Upon detecting a building data access request, the system acquires user access information and performs access parameter screening to obtain an access parameter data group. It then determines whether the identity parameter data in the access parameter data group conforms to preset identity standards. If it does, a security certificate is generated based on the identity parameter data and the preset identity standards, and added to the access parameter data group to obtain a primary access data group. Finally, a verification address is generated based on the security certificate data in the primary access data group, and this verification address is established with the stealth access gateway. The system connects to the building information storage device and analyzes the access data parameters in the primary access data group to obtain building access data. Then, based on this data and the dynamic DNS module in the IPv6 network, it determines the target address and establishes a connection between the target address and the stealth communication gateway. The target address is the data storage address corresponding to the building access data. This verifies the user's identity and access permissions before the user device connects to the building information storage device, determining if the user meets the access requirements. If so, it establishes data connectivity between the user device and the building information storage device using IPv6 stealth secure communication technology. IPv6 stealth secure communication technology can be used for secure access to protected applications in IPv6 mobile network environments. A gateway supporting IPv6 stealth service publishing is deployed at the site where the protected application resides and published to the mobile network environment. Authorized user devices can verify their identity through certificates and directly access the protected application through IPv6 stealth secure communication technology and the intermediate IPv6 network. The entire communication process is unscannable, unsniffable, and its content cannot be recovered, thus improving the security of building data information. Attached Figure Description
[0082] Figure 1 This is a flowchart illustrating a method for secure access control of building data information provided in an embodiment of this application.
[0083] Figure 2 This is a schematic diagram of a building data information security access control device provided in an embodiment of this application.
[0084] Figure 3 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0085] The following is in conjunction with the appendix Figure 1-3 This application will be described in further detail.
[0086] This specific embodiment is merely an explanation of this application and is not intended to limit it. After reading this specification, those skilled in the art can make modifications to this embodiment without contributing any inventive step, but such modifications are protected by patent law as long as they are within the scope of this application.
[0087] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0088] Furthermore, the term "and / or" in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. Additionally, the character " / " in this article, unless otherwise specified, generally indicates that the preceding and following related objects have an "or" relationship.
[0089] The embodiments of this application will now be described in further detail with reference to the accompanying drawings.
[0090] This application provides a method for secure access control of building data information, executed by an electronic device. This electronic device can be a server or a terminal device. The server can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing cloud computing services. The terminal device can be a smartphone, tablet, laptop, desktop computer, etc., but is not limited to these. The terminal device and the server can be directly or indirectly connected via wired or wireless communication. This application does not impose any limitations on this. Figure 1 As shown, the method includes:
[0091] Step S10: Construct a stealth communication gateway and a stealth access gateway based on the IPv6 network.
[0092] The stealth access gateway is a gateway set between the user equipment and the building data information access device, and the stealth communication gateway is a gateway set between the building data information access device and the building data information storage device.
[0093] In this embodiment of the application, the stealth communication gateway and the building data information access device are in a default connection state, while the stealth communication gateway and the user equipment are in a verified connection state, meaning that a connection can only be established with the stealth communication gateway after verification is completed. Similarly, the stealth access gateway and the building data information storage device are in a default connection state, while the stealth access gateway and the building data information access device are in a verified connection state, meaning that a connection can only be established with the stealth access gateway after verification is completed.
[0094] Specifically, when electronic devices construct stealth communication gateways and stealth access gateways via an IPv6 network, the first step is to define supported communication protocols, security requirements, and performance metrics. After definition, a protocol capable of hiding the sending and receiving of data is selected, such as TOR (Onion Router) or I2P (Stealth Network). This protocol is then integrated with the IPv6 network protocol to generate a stealth protocol. Next, a network architecture capable of handling IPv6 packets is defined, including the interaction flow between clients, servers, and the gateway. Considering the needs of stealth communication and access, the selected stealth protocol is integrated into the network. The electronic device then processes packets from clients and routes them to the correct destination. Code is written using programming languages (such as Python or C++) to process IPv6 packets and route them using the selected stealth protocol, thus constructing and generating the stealth communication gateway. This includes implementing operations such as packet decoding, encryption, decryption, and encoding. Finally, the electronic device processes packets from the server and routes them to the correct client. Similarly, code capable of processing IPv6 packets is written and routed using the selected stealth protocol to build a stealth access gateway. When the building information storage device connects to the stealth access gateway and the user equipment connects to the stealth communication gateway, the two devices transmit data through the IPv6 stealth network.
[0095] Step S11: When a request to access building data information is detected, obtain the user access information.
[0096] Specifically, user access information includes user identity information, user request information, user permission information, user access data information, user device information, etc. Among them, user permission information is used to indicate the user's access permissions to the application, that is, whether the user has the right to directly obtain the information provided by the corresponding building information storage device after connecting to the gateway.
[0097] Step S12: Screen the user access information for access parameters to obtain access parameter data sets.
[0098] Specifically, the access parameter data group is a combination of data related to the access application from the user access information. Different types of parameter data are arranged and combined in the form of a List collection to obtain the access parameter data group.
[0099] Step S13: Determine whether the identity parameter data in the access parameter data group conforms to the preset identity standard data. If it does, generate security certificate data based on the identity parameter data and the preset identity standard data, and add the security certificate data to the access parameter data group to obtain the first-level access data group.
[0100] In this embodiment of the application, the preset identity standard data is the accessible identity verification framework data pre-set for each building information storage device. The identity verification framework data has a hierarchical framework structure, with each layer representing different permissions and different methods of obtaining permissions. For example, Zhang San's identity permission is located at the third layer, that is, he can only access the primary data. If he wants to access the advanced data, he needs to go through the approval of the corresponding personnel with permissions at the first and second layers according to the connection relationship of the identity verification framework data before he can access the advanced data.
[0101] In addition, each layer of the default identity standard data is assigned a corresponding security certificate. This is a security certificate assigned to each mobile user who needs to access the protected application. It is used to verify the user's identity and generate security certificate data for the IPv6 5-tuple, which has cryptographic integrity that cannot be counterfeited.
[0102] Step S14: Generate a verification address based on the security certificate data in the Level 1 access data group, and establish a connection between the verification address and the stealth access gateway.
[0103] Specifically, the system retrieves security certificate data from the primary access data group. This security certificate data is used for authentication and data encryption. Then, a verification address is generated based on the security certificate data. This verification address is used to verify the user's identity and access permissions. A connection is established with the stealth access gateway using the verification address. The stealth access gateway is a proxy server that can hide the user's real IP address and access behavior, while providing functions such as data encryption and authentication. The stealth access gateway proxies the user's access behavior. The user's access requests are received and processed by the stealth access gateway, thereby realizing the verification of the user's identity and control of access permissions.
[0104] Step S15: Analyze the access data parameter data in the first-level access data group to obtain building access data.
[0105] Specifically, based on the access data parameters, the user access permissions corresponding to the user access information are determined. Then, the user access permissions are matched with different access permissions in the preset permission framework to determine whether the user access permissions have direct access rights. If they do, the permission tags that match the user access permissions are determined based on the preset permission framework, and the permission tags are added to the access data parameters to obtain the building access data.
[0106] Step S16: Determine the target address based on the building access data and the dynamic DNS module in the IPv6 network, establish a connection between the target address and the stealth communication gateway, and access the building data information corresponding to the building access data in the building data information storage device.
[0107] The target address is the data storage address corresponding to the building access data.
[0108] Based on the above embodiments, when a user accesses building data information via a user device connected to the network, a stealth communication gateway and a stealth access gateway are constructed based on the IPv6 network. When a building data information access request is detected, user access information is acquired, and access parameters are screened to obtain an access parameter data group. It is then determined whether the identity parameter data in the access parameter data group conforms to preset identity standard data. If it does, security certificate data is generated based on the identity parameter data and the preset identity standard data, and added to the access parameter data group to obtain a first-level access data group. Finally, a verification address is generated based on the security certificate data in the first-level access group, and the verification address is then compared with the stealth access... The gateway establishes a connection and then analyzes the access data parameters in the primary access data group to obtain building access data. Based on this data and the dynamic DNS module in the IPv6 network, it determines the target address and establishes a connection between the target address and the stealth communication gateway. The target address is the data storage address corresponding to the building access data. This verifies the user's identity and access permissions before the user device connects to the building information storage device, determining if the user meets the access requirements. If so, it establishes data connectivity between the user device and the building information storage device using IPv6 stealth secure communication technology. IPv6 stealth secure communication technology can be used for secure access to protected applications in IPv6 mobile network environments. A gateway supporting IPv6 stealth service publishing is deployed at the site where the protected application resides and published to the mobile network environment. Authorized user devices can verify their identity through certificates and directly access the protected application through IPv6 stealth secure communication technology and the intermediate IPv6 network. The entire communication process is unscannable, unsniffable, and its content cannot be recovered, thus improving the security of building data information.
[0109] One possible implementation of this application embodiment, in determining whether a user's access permission has direct access rights, further includes: if the user's access permission does not have direct access rights, then determining the access permission node for obtaining the user's access permission according to a preset permission framework, generating node verification information according to the access permission node, then sending the node verification information to the permission device corresponding to the access permission node, and receiving the verification return information returned by the permission device, then determining whether the verification status in the verification return information returned within a preset time has changed according to a preset time, if so, then updating the first-level access data group based on the verification return information and the set access time limit to obtain the second-level access data group, and then determining the building access data according to the second-level access data group.
[0110] Specifically, the verification return information indicates that the current user device does not have direct access rights, so permission requests need to be submitted level by level. If the corresponding level of permission administrator approves the user device's access, the permission approval tag in the node verification information will be changed. For example, Zhang San wants to access Level 1 confidential data, but at this time Zhang San only has direct access rights to Level 3 confidential data. Therefore, Zhang San needs to submit his node verification information to the Level 2 and Level 1 permission administrators, informing the higher-level permission administrators of the data he wants to access and the node that the permission administrator has approved. If the higher-level permission administrator approves Zhang San's access to Level 1 confidential data with his user device, the corresponding node approval status in the node verification information will be changed, thereby updating the permission approval tag in the node verification information.
[0111] In this application embodiment, the preset time is the approval time of the superior authority administrator. In order to prevent user permission application fraud, this application has controlled the review time. The time limit is set according to the shortest and longest approval time of the superior authority administrator, forming a preset time. This preset time is known only to electronic devices and not to other operators. When the user approval time is too long or too short, it is determined that there is a situation of permission application fraud.
[0112] One possible implementation of this application involves determining the target address based on building access data and a dynamic DNS module in the IPv6 network, and establishing a connection between the target address and a stealth communication gateway. The implementation further includes: monitoring whether the user device corresponding to the user access information establishes a connection with the building information storage device corresponding to the building access data via the IPv6 network; if a connection is established, real-time acquisition of traffic transmission information between the user device and the building information storage device. The traffic transmission information is organized according to transmission time nodes to obtain a transmission fluctuation diagram of data transmission between the user device and the building information storage device. The transmission fluctuation diagram is fitted to a preset traffic transmission diagram according to transmission time nodes to determine whether there are anomalies in the traffic transmission data corresponding to different transmission time nodes. If so, historical traffic transmission data is acquired, and a data transmission anomaly analysis is performed on the user device and the building information storage device based on the historical traffic transmission data to obtain the abnormal access level of the user device. The historical traffic transmission data consists of traffic transmission data when different models of user devices communicate with different building information storage devices. The abnormal access level is compared with the access level in the abnormal access standard to obtain user access rules, and the access data parameters in the first-level access data group are adjusted based on the user access rules.
[0113] In this embodiment of the application, a coordinate system is established, where the X-axis represents time information and the Y-axis represents flow rate information. The time information corresponding to the X-axis is distributed in units of time nodes, with each unit of time node being every minute. The flow rate of the flow rate information corresponding to the flow rate information on the Y-axis within the current time is marked, and then the corresponding flow rate marks for each subsequent minute are connected to form a flow rate curve between the user equipment and the building information storage device. This curve is the data transmission fluctuation diagram, while the preset flow transmission diagram is a curve of the flow rate range corresponding to different units of time. By fitting the transmission fluctuation diagram with the preset flow transmission diagram, it can be determined whether there is a data transmission anomaly.
[0114] Specifically, based on historical traffic transmission data, anomaly analysis is performed on user equipment and building information storage devices to obtain the degree of abnormal access by user equipment. This includes: determining the highest and lowest traffic transmission rates of different user equipment models during each data communication with different building information storage devices based on historical traffic transmission data, using the highest and lowest traffic transmission rates as the numerators and the time taken for each data communication process as the denominator. The ratio of the numerator to the denominator yields the transmission rate change value for each data communication process. These transmission rate change values are then arranged chronologically to obtain the transmission sequence of historical traffic transmission data. Based on the transmission rate change values corresponding to different user equipment models and different building information storage devices in the transmission sequence, and the value of each transmission rate, all segmentation points in the transmission sequence are obtained. The transmission sequence is then segmented based on all segmentation points, and the similarity of the change value sequences corresponding to each pair of adjacent transmission sequences is obtained. Based on the similarity, it is determined whether each pair of adjacent transmission sequences needs to be merged, resulting in two or more transmission data segments. Anomaly analysis is performed on each changed value corresponding to each transmitted data segment based on the data security situation within a preset future timeframe. This analysis yields the anomaly degree of different changed values corresponding to different transmitted data segments during data communication between different user equipment models and different building information storage devices. Based on the anomaly degree, the abnormal access degree of the transmitted data segments corresponding to the user equipment, building information storage devices, and transmission time nodes exhibiting traffic transmission anomalies is determined.
[0115] One possible implementation of this application embodiment involves performing anomaly analysis on each changed value corresponding to each transmission data segment based on the data security situation of each changed value within a preset future time, to obtain the degree of anomaly of different changed values corresponding to different transmission data segments during each data communication between different types of user equipment and different building information storage devices. This includes: obtaining the data security situation of each changed value corresponding to each transmission data segment within a preset future time, then determining whether there is a data security situation for each changed value corresponding to each transmission data segment, and if so, inputting the data security situation into the traffic transmission anomaly model for identification, thereby obtaining the degree of anomaly of different changed values corresponding to different transmission data segments during each data communication between different types of user equipment and different building information storage devices.
[0116] In this embodiment of the application, the traffic transmission anomaly model is a pre-trained neural network model.
[0117] In one possible implementation of this application, the abnormal access level is compared with the access level in the abnormal access standard. Before that, the method further includes: determining whether the abnormal access level is a preset abnormal level. If so, the access path corresponding to the abnormal access level is determined, and the access path is optimized.
[0118] Specifically, the determined access path is optimized, including optimizing nodes within the path and cleaning and integrating data to improve access efficiency and quality. Based on the optimized access path, access requests are re-proxened and forwarded to protect user identity and conceal access behavior. It is important to note that when determining the degree of abnormal access, a judgment should be made based on the actual situation, and an appropriate threshold should be selected for judgment. Simultaneously, when optimizing the access path, adjustments should be made based on actual conditions to ensure the effectiveness and practicality of the optimization. Furthermore, a suitable stealth communication gateway should be selected based on user access behavior and needs to achieve user identity protection and concealment of access behavior.
[0119] The following describes a building data information security access control device provided in an embodiment of this application. The building data information security access control device described below can be referred to in conjunction with the building data information security access control method described above. Figure 2 , Figure 2 This is a schematic diagram of the structure of a building data information security access control device 20 provided in an embodiment of this application, including:
[0120] Gateway construction module 21 is used to build stealth communication gateways and stealth access gateways based on IPv6 networks;
[0121] Information acquisition module 22 is used to acquire user access information when a building data information access request is detected;
[0122] Parameter screening module 23 is used to screen access parameters of user access information to obtain access parameter data group;
[0123] The identity determination module 24 is used to determine whether the identity parameter data in the access parameter data group conforms to the preset identity standard data. If it does, it generates security certificate data based on the identity parameter data and the preset identity standard data, and adds the security certificate data to the access parameter data group to obtain the first-level access data group.
[0124] The first connection module 25 is used to generate a verification address based on the security certificate data in the first-level access data group, and establish a connection between the verification address and the stealth access gateway.
[0125] Parameter analysis module 26 is used to analyze the access data parameter data in the first-level access data group to obtain building access data;
[0126] The second connection module 27 is used to determine the target address based on the building access data and the dynamic DNS module in the IPv6 network, and to establish a connection between the target address and the stealth communication gateway to access the building data information corresponding to the building access data in the building data information storage device.
[0127] In one possible implementation of this application embodiment, when the parameter analysis module 26 analyzes the access data parameter data in the first-level access data group to obtain building access data, it is specifically used for:
[0128] Determine user access permissions corresponding to user access information based on access data parameters;
[0129] The user's access permissions are matched with different access permissions in the preset permission framework to determine whether the user's access permissions have direct access rights. If so, the permission tag that matches the user's access permissions is determined based on the preset permission framework, and the permission tag is added to the access data parameters to obtain the building access data.
[0130] In another possible implementation of this application embodiment, the device 20 further includes: a verification generation module, a verification interaction module, a verification update module, and a data determination module, wherein,
[0131] The verification generation module is used to determine the permission acquisition node of the user's access permissions according to the preset permission framework when the user's access permissions do not have direct access rights, and to generate node verification information according to the permission acquisition node.
[0132] The verification interaction module is used to send node verification information to the authorized device corresponding to the authorized node, and to receive the verification return information returned by the authorized device.
[0133] The verification update module is used to determine whether the verification status in the verification return information returned within a preset time has changed in a preset manner. If it has, the first-level access data group is updated based on the verification return information and the set access time limit to obtain the second-level access data group.
[0134] The data determination module is used to determine building access data based on the secondary access data group.
[0135] In another possible implementation of this application embodiment, the device 20 further includes: a traffic acquisition module, an information processing module, an anomaly analysis module, and a parameter adjustment module, wherein,
[0136] The traffic acquisition module is used to monitor whether the user device corresponding to the user access information has established a connection with the building information storage device corresponding to the building access data through the IPv6 network. If a connection is established, the traffic transmission information between the user device and the building information storage device is acquired in real time.
[0137] The information processing module is used to process traffic transmission information according to transmission time nodes to obtain a transmission fluctuation diagram of data transmission between user equipment and building information storage equipment.
[0138] The anomaly analysis module is used to fit the transmission fluctuation graph with the preset traffic transmission graph according to the transmission time nodes, determine whether there are anomalies in the traffic transmission data corresponding to different transmission time nodes. If there are, historical traffic transmission data is obtained, and data transmission anomaly analysis is performed on user equipment and building information storage equipment based on the historical traffic transmission data to obtain the abnormal access level of user equipment. The historical traffic transmission data is the traffic transmission data when different models of user equipment communicate with different building information storage devices.
[0139] The parameter adjustment module is used to compare the abnormal access level with the access level in the abnormal access standard to obtain the user access rules, and adjust the access data parameters in the first-level access data group based on the user access rules.
[0140] Another possible implementation in this application embodiment is that, when the anomaly analysis module performs data transmission anomaly analysis on the user equipment and building information storage device based on historical traffic transmission data to obtain the abnormal access level of the user equipment, it is specifically used for:
[0141] Based on historical traffic transmission data, determine the highest and lowest traffic transmission rates of different types of user equipment during each data communication with different building information storage devices, and use the highest and lowest traffic transmission rates as the transmission numerators and the time taken for each data communication process as the transmission denominator.
[0142] The change in transmission rate for each data communication process can be obtained by calculating the ratio of the transmission numerator to the transmission denominator.
[0143] Arrange the transmission rate change values in time sequence to obtain the transmission sequence of historical traffic transmission data;
[0144] All segmentation points in the transmission sequence are obtained by considering the changes in transmission rates between different types of user equipment and different building information storage devices, and the value of each transmission rate.
[0145] The transmission sequence is segmented based on all the split points. The similarity of the change value sequences corresponding to each two adjacent transmission sequences is obtained. Based on the similarity, it is determined whether each two adjacent transmission sequences need to be merged, and two or more transmission data segments are obtained.
[0146] Based on the data security situation of each change value corresponding to each transmission data segment within a preset time, an anomaly analysis is performed on each change value corresponding to each transmission data segment to obtain the degree of anomaly of different change values corresponding to different transmission data segments during each data communication between different models of user equipment and different building information storage devices.
[0147] Based on the degree of anomaly, the degree of abnormal access to the transmitted data segment corresponding to the user equipment, building information storage equipment, and the transmission time node where traffic transmission data anomalies occur is obtained.
[0148] Another possible implementation in this application embodiment is that the anomaly analysis module performs anomaly analysis on each changed value corresponding to each transmitted data segment based on the data security situation occurring within a preset future time for each changed value corresponding to each transmitted data segment, and obtains the degree of anomaly of different changed values corresponding to different transmitted data segments during each data communication between different models of user equipment and different building information storage devices. Specifically, it is used for:
[0149] Each data segment's corresponding change value within a preset future timeframe is obtained to assess its data security status.
[0150] Determine whether there is a data security issue for each change value corresponding to each transmitted data segment. If so, input the data security issue into the traffic transmission anomaly model for identification, and obtain the degree of anomaly of different change values corresponding to different transmitted data segments during each data communication between different types of user equipment and different building information storage devices.
[0151] In another possible implementation of this application embodiment, the device 20 further includes: a path optimization module, wherein,
[0152] The path optimization module is used to determine whether the abnormal access level is within the preset abnormal level. If so, it determines the access path corresponding to the abnormal access level and performs access optimization processing on the access path.
[0153] The following describes an electronic device provided in an embodiment of this application. The electronic device described below can be referred to in correspondence with the building data information security access control method described above.
[0154] This application provides an electronic device, such as... Figure 3 As shown, Figure 3This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Figure 3 The illustrated electronic device 300 includes a processor 301 and a memory 303. The processor 301 and the memory 303 are connected, for example, via a bus 302. Optionally, the electronic device 300 may also include a transceiver 304. It should be noted that in practical applications, the transceiver 304 is not limited to one type, and the structure of this electronic device 300 does not constitute a limitation on the embodiments of this application.
[0155] Processor 301 may be a CPU (Central Processing Unit), a general-purpose processor, a DSP (Digital Signal Processor), an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It can implement or execute the various exemplary logic blocks, modules, and circuits described in connection with the embodiments of this application. Processor 301 may also be a combination that implements computing functions, such as including one or more microprocessor combinations, a combination of a DSP and a microprocessor, etc.
[0156] Bus 302 may include a pathway for transmitting information between the aforementioned components. Bus 302 may be a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus, etc. Bus 302 can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 3 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.
[0157] The memory 303 may be a ROM (Read Only Memory) or other type of static storage device capable of storing static information and instructions, RAM (Random Access Memory) or other type of dynamic storage device capable of storing information and instructions, or an EEPROM (Electrically Erasable Programmable Read Only Memory), CD-ROM (Compact Disc Read Only Memory) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital universal optical discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but not limited thereto.
[0158] The memory 303 is used to store application code that executes the scheme of the embodiments of this application, and its execution is controlled by the processor 301. The processor 301 is used to execute the application code stored in the memory 303 to implement the content shown in the foregoing method embodiments.
[0159] Among them, electronic devices include, but are not limited to: mobile terminals such as mobile phones, laptops, digital radio receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), and in-vehicle terminals (such as in-vehicle navigation terminals), as well as fixed terminals such as digital TVs and desktop computers. Figure 3 The electronic device shown is merely an example and should not impose any limitation on the functionality and scope of use of the embodiments of this application.
[0160] The following describes a computer-readable storage medium provided by an embodiment of this application. The computer-readable storage medium described below can be referred to in correspondence with the method described above.
[0161] This application provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps of the above-described building data information security access control method.
[0162] Since the embodiments of the computer-readable storage medium portion correspond to the embodiments of the method portion, please refer to the description of the embodiments of the method portion for the embodiments of the computer-readable storage medium portion.
[0163] It should be understood that although the steps in the flowcharts of the accompanying figures are shown sequentially as indicated by the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the accompanying figures may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the sub-steps or stages of other steps.
[0164] The above are only some embodiments of this application. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of this application, and these improvements and modifications should also be considered within the scope of protection of this application.
Claims
1. A method for secure access control of building data information, characterized in that, The application relates to a building data information access method based on an IPV6 network. The application comprises the following steps: When detecting a building data information access demand, user access information is acquired; The user access information is subjected to access parameter screening to obtain an access parameter data group; It is judged whether identity parameter data in the access parameter data group meets preset identity standard data, if yes, a security certificate data is generated based on the identity parameter data and the preset identity standard data, and the security certificate data is added to the access parameter data group to obtain a first-level access data group; An authentication address is generated according to the security certificate data in the first-level access data group, and the authentication address is connected with the stealth access gateway; The access data parameter data in the first-level access data group is analyzed to obtain building access data. The application comprises the following steps: The user access information is subjected to access parameter screening to obtain an access parameter data group; It is judged whether identity parameter data in the access parameter data group meets preset identity standard data, if yes, a security certificate data is generated based on the identity parameter data and the preset identity standard data, and the security certificate data is added to the access parameter data group to obtain a first-level access data group; An authentication address is generated according to the security certificate data in the first-level access data group, and the authentication address is connected with the stealth access gateway; The access data parameter data in the first-level access data group is analyzed to obtain building access data. The application comprises the following steps: The user access information is subjected to access parameter screening to obtain an access parameter data group; It is judged whether identity parameter data in the access parameter data group meets preset identity standard data, if yes, a security certificate data is generated based on the identity parameter data and the preset identity standard data, and the security certificate data is added to the access parameter data group to obtain a first-level access data group; An authentication address is generated according to the security certificate data in the first-level access data group, and the authentication address is connected with the stealth access gateway; 2. The method for secure access control of building data information according to claim 1, characterized in that, The access data parameter data in the first-level access data group is analyzed to obtain building access data. The application comprises the following steps: The user access information is subjected to access parameter screening to obtain an access parameter data group; It is judged whether identity parameter data in the access parameter data group meets preset identity standard data, if yes, a security certificate data is generated based on the identity parameter data and the preset identity standard data, and the security certificate data is added to the access parameter data group to obtain a first-level access data group; An authentication address is generated according to the security certificate data in the first-level access data group, and the authentication address is connected with the stealth access gateway; The access data parameter data in the first-level access data group is analyzed to obtain building access data. The application comprises the following steps: The user access information is subjected to access parameter screening to obtain an access parameter data group; It is judged whether identity parameter data in the access parameter data group meets preset identity standard data, if yes, a security certificate data is generated based on the identity parameter data and the preset identity standard data, and the security certificate data is added to the access parameter data group to obtain a first-level access data group; An authentication address is generated according to the security certificate data in the first-level access data group, and the authentication address is connected with the stealth access gateway; The access data parameter data in the first-level access data group is analyzed to obtain building access data. The application comprises the following steps: The user access information is subjected to access parameter screening to obtain an access parameter data group; It is judged whether identity parameter data in the access parameter data group meets preset identity standard data, if yes, a security certificate data is generated based on the identity parameter data and the preset identity standard data, and the security certificate data is added to the access parameter data group to obtain a first-level access data group; An authentication address is generated according to the security certificate data in the first-level access data group, and the authentication address is connected with the stealth access gateway; The access data parameter data in the first-level access data group is analyzed to obtain building access data. The application comprises the following steps: The user access information is subjected to access parameter screening to obtain an access parameter data group; It is judged whether identity parameter data in the access parameter data group meets preset identity standard data, if yes, a security certificate data is generated based on the identity parameter data and the preset identity standard data, and the security certificate data is added to the access parameter data group to obtain a first-level access data group; An authentication address is generated according to the security certificate data in the first-level access data group, and the authentication address is connected with the stealth access gateway; The access data parameter data in the first-level access data group is analyzed to obtain building access data. The application comprises the following steps: The user access information is subjected to access parameter screening to obtain an access parameter data group; It is judged whether identity parameter data in the access parameter data group meets preset identity standard data, if yes, a security certificate data is generated based on the identity parameter data and the preset identity standard data, and the security certificate data is added to the access parameter data group to obtain a first-level access data group; An authentication address is generated according to the security certificate data in the first-level access data group, and the authentication address is connected with the stealth access gateway; The access data parameter data in the first-level access data group is analyzed to obtain building access data. The application comprises the following steps: The user access information is subjected to access parameter screening to obtain an access parameter data group; It is judged whether identity parameter data in the access parameter data group meets preset identity standard data, if yes, a security certificate data is generated based on the identity parameter data and the preset identity standard data, and the security certificate data is added to the access parameter data group to obtain a first-level access data group; An authentication address is generated according to the security certificate data in the first-level access data group, and the authentication address is connected with the stealth access gateway; The access data parameter data in the first-level access data group is analyzed to obtain building access data. The application comprises the following steps: The user access information is subjected to access parameter screening to obtain an access parameter data group; It is judged whether identity parameter data in the access parameter data group meets preset identity standard data, if yes, a security certificate data is generated based on the identity parameter data and the preset identity standard data, and the security certificate data is added to the access parameter data group to obtain a first-level access data group; An authentication address is generated according to the security certificate data in the first-level access data group, and the authentication address is connected with the stealth access gateway; The access data parameter data in the first-level access data group is analyzed to obtain building access data. The application comprises the following steps: The user access information is subjected to access parameter screening to obtain an access parameter data group; It is judged whether identity parameter data in the access parameter data group meets preset identity standard data, if yes, a security certificate data is generated based on the identity parameter data and the preset identity standard data, and the security certificate data is added to the access parameter data group to obtain a first-level access data group; An authentication address is generated according to the security certificate data in the first-level access data group, and the authentication address is connected with the stealth access gateway; The access data parameter data in the first-level access data group is analyzed to obtain building access data. The application comprises the following steps: The user access information is subjected to access parameter screening to obtain an access parameter data group; It is judged whether identity parameter data in the access parameter data group meets preset identity standard data, if yes, a security certificate data is generated based on the identity parameter data and the preset identity standard data, and the security certificate data is added to the access parameter data group to obtain a first-level access data group; An authentication address is generated according to the security certificate data in the first-level access data group, and the authentication address is connected with the stealth access gateway; The access data parameter data in the first-level access data group is analyzed to obtain building access data. The application comprises the following steps: The user access information is subjected to access parameter screening to obtain an access parameter data group; It is judged whether identity parameter data in the access parameter data group meets preset identity standard data, if yes, a security certificate data is generated based on the identity parameter data and the preset identity standard data, and the security certificate data is added to the access parameter data group to obtain a first-level access data group; An authentication address is generated according to the security certificate data in the first-level access data group, and the authentication address is connected with the stealth access gateway; The access data parameter data in the first-level access data group is analyzed to obtain building access data. The application comprises the following steps: The user access information is subjected to access parameter screening to obtain an access parameter data group; It is judged whether identity parameter data in the access parameter data group meets preset identity standard data, if yes, a security certificate data is generated based on the identity parameter data and the preset identity standard data, and the security certificate data is added to the access parameter data group to obtain a first-level access data group; An authentication address is generated according to the security certificate data in the first-level access data group, and the authentication address is connected with the stealth access gateway; The access data parameter data in the first-level access data group is analyzed to obtain building access data. The application comprises the following steps: The user access information is subjected to access parameter screening to obtain an access parameter data group; It is judged whether identity parameter data in the access parameter data group meets preset identity standard data, if yes, a security certificate data is generated based on the identity parameter data and the preset identity standard data, and the security certificate monitoring whether a user equipment corresponding to the user access information is connected with a building information storage equipment corresponding to the building access data through the IPV6 network, if connected, real-time acquiring traffic transmission information between the user equipment and the building information storage equipment; arranging the traffic transmission information according to transmission time nodes to obtain a transmission fluctuation graph of data transmission between the user equipment and the building information storage equipment; fitting the transmission fluctuation graph and a preset traffic transmission graph according to the transmission time nodes to determine whether traffic transmission data corresponding to different transmission time nodes is abnormal, if so, acquiring historical traffic transmission data, and based on the historical traffic transmission data, performing data transmission anomaly analysis on the user equipment and the building information storage equipment to obtain an abnormal access degree of the user equipment, the historical traffic transmission data being traffic transmission data when different types of user equipment and different building information storage equipment perform data communication; comparing the abnormal access degree with an access degree in an abnormal access standard to obtain a user access rule, and based on the user access rule, adjusting access data parameter data in the first access data group.
3. The method for secure access control of building data information according to claim 2, characterized in that, The data transmission anomaly analysis on the user equipment and the building information storage equipment based on the historical traffic transmission data to obtain the abnormal access degree of the user equipment includes: determining, according to the historical traffic transmission data, a highest traffic transmission rate and a lowest traffic transmission rate in each data communication process of different types of user equipment with different building information storage equipment, and taking the highest traffic transmission rate and the lowest traffic transmission rate as a transmission numerator and taking time used in each data communication process as a transmission denominator; obtaining a transmission rate change value of each data communication process according to a ratio of the transmission numerator to the transmission denominator; arranging the transmission rate change value in time sequence to obtain a transmission sequence of the historical traffic transmission data; obtaining all segmentation points in the transmission sequence according to change values corresponding to transmission rates of different types of user equipment in each data communication process with different building information storage equipment and numerical values of each transmission rate; segmenting the transmission sequence according to all segmentation points to acquire a similarity of change value sequences corresponding to each adjacent two segments of the transmission sequence, determining whether each adjacent two segments of the transmission sequence needs to be merged according to the similarity, and obtaining two segments and two segments and more transmission data segments; performing anomaly analysis on each change value corresponding to each transmission data segment according to a data security situation of each change value corresponding to each transmission data segment occurring within a future preset time to obtain an abnormal degree of different change values corresponding to different transmission data segments in each data communication process of different types of user equipment with different building information storage equipment; based on the abnormal degree, obtaining an abnormal access degree of a transmission data segment corresponding to the user equipment, the building information storage equipment and a transmission time node with abnormal traffic transmission data.
4. The method for secure access control of building data information according to claim 3, characterized in that, The abnormality of each change value corresponding to each transmission data segment is analyzed according to the data security situation of each change value corresponding to each transmission data segment occurring within a future preset time, and the abnormality degree of different change values corresponding to different transmission data segments in each data communication process between different user equipment of different models and different building information storage equipment is obtained, including: Respectively acquire the data security situation of each change value corresponding to each transmission data segment occurring within a future preset time; Determine whether each change value corresponding to each transmission data segment exists in the data security situation, if so, input the data security situation into the traffic transmission abnormality model for identification, and obtain the abnormality degree of different change values corresponding to different transmission data segments in each data communication process between different user equipment of different models and different building information storage equipment.
5. The method for secure access control of building data information according to claim 2, wherein, The abnormal access degree and the access degree in the abnormal access standard are compared, and the following steps are further included: Determine whether the abnormal access degree is a preset abnormal degree, if so, determine the access path corresponding to the abnormal access degree, and perform access optimization processing on the access path.
6. A building data information security access control device, characterized by, Including: The gateway construction module is used for constructing the stealth communication gateway and the stealth access gateway based on the IPV6 network; The information acquisition module is used for acquiring user access information when detecting building data information access demand; The parameter screening module is used for screening access parameters of the user access information to obtain an access parameter data group; The identity judgment module is used for judging whether the identity parameter data in the access parameter data group meets a preset identity standard data, if so, generating security certificate data based on the identity parameter data and the preset identity standard data, and adding the security certificate data to the access parameter data group to obtain a first-level access data group; The first connection module is used for generating a verification address according to the security certificate data in the first-level access data group, and establishing a connection between the verification address and the stealth access gateway; The parameter analysis module is used for analyzing the access data parameter data in the first-level access data group to obtain building access data; When the parameter analysis module analyzes the access data parameter data in the first-level access data group to obtain building access data, it is specifically used for: Determining the user access right corresponding to the user access information based on the access data parameter data; Matching the user access right with different access rights in a preset right framework to determine whether the user access right exists a direct access right, if so, determining a right label matched with the user access right based on the preset right framework, and adding the right label to the access data parameter to obtain building access data; The device further includes a verification generation module, a verification interaction module, a verification update module, and a data determination module, wherein The verification generation module is used for determining the access right acquisition node of the user access right according to the preset right framework when the user access right does not exist a direct access right, and generating node verification information according to the access right acquisition node; The verification interaction module is configured to send the node verification information to the permission device corresponding to the permission node, and receive verification return information returned by the permission device; The verification update module is configured to determine whether a verification state in the verification return information returned within a preset time changes by a preset change, and if so, update the first access data group based on the verification return information and a set access time limit to obtain a second access data group; The data determination module is configured to determine building access data according to the second access data group; The second connection module is configured to determine a target address according to the building access data and a dynamic DNS module in the IPV6 network, establish a connection between the target address and the stealth communication gateway, and access building data information corresponding to the building access data in the building data information storage device.
7. An electronic device, comprising: Comprise: At least one processor; Memory; At least one application program, wherein the at least one application program is stored in the memory and is configured to be executed by the at least one processor, and the at least one application program is configured to execute the building data information security access control method in any one of claims 1 to 5.
8. A computer-readable storage medium, characterized in that, The computer program stored in the memory can be loaded and executed by the processor to execute the building data information security access control method in any one of claims 1 to 5.
Citation Information
Patent Citations
Data security transmission method and device based on equipment identity pre-authentication
CN113612790A
Security gateway and creation method thereof, method for accessing internal service by user, electronic equipment and storage medium
CN114785575A