An enterprise-level data encryption and access control method and system

Through fine-grained access control and quantum encryption algorithms, access keys associated with resources are dynamically generated, which solves the problem of inflexible key management in the prior art, and realizes the refined and security of enterprise-level data encryption and access control.

CN118410505BActive Publication Date: 2025-08-22GUANGDONG WOMENS VOCATIONAL & TECH COLLEGE
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202410504088.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-04-25
Publication Date
2025-08-22
Estimated Expiration
2044-04-25

AI Technical Summary

Technical Problem

The existing enterprise-level data encryption and access control methods are difficult to perform refined permission control based on the specific needs and work responsibilities of individual users. Key management is not flexible enough and fails to effectively respond to the needs of quantum secure communication.

Method used

The enterprise server platform is built using a fine-grained access control mechanism, combining quantum encryption algorithms and symmetric encryption algorithms, dynamically generate access keys associated with resources, transmit keys through quantum communication channels, and record and monitor access behavior in real time to achieve strict key management.

Benefits of technology

It realizes refined management of data access rights, ensures flexibility and security of key use, reduces operational costs, and improves data security and communication stability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118410505B_ABST
    Figure CN118410505B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of enterprise data, and in particular to an enterprise-level data encryption and access control method and system, comprising constructing an enterprise server platform, encrypting enterprise data and generating keys according to an encryption algorithm; upon receiving an access request instruction, verifying the identity information of the user who issued the access request instruction; when the user's identity information meets the enterprise identity conditions, verifying the user's role information in the enterprise and parsing the resource corresponding to the access request instruction; when the user's role information meets the conditions for accessing the resource, matching the access key corresponding to the resource based on the user's role information in the enterprise and the resource; based on the access key corresponding to the resource, transmitting the access key to the user end according to a preset quantum state through an encryption algorithm. Based on the specific needs and job responsibilities of each user, refined management of data access rights is achieved. By adopting a quantum encryption algorithm, strict management can be achieved in the generation, distribution, storage and destruction of keys.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of enterprise data technology, and in particular to an enterprise-level data encryption and access control method and system. Background Art

[0002] The goal of enterprise-level data encryption and access control is to ensure the security of data during storage and transmission, while allowing legitimate users to access the data they need at the appropriate time and place. By implementing these measures, enterprises can reduce the risk of data breaches and insider threats, protecting their assets and customer information.

[0003] Existing access control systems typically only manage permissions at the role level, making it difficult to implement refined permission control tailored to individual users' specific needs and job responsibilities. This results in inflexible key management and the inability to dynamically generate and distribute keys based on user roles and permissions, potentially leading to overuse or inappropriate authorization of keys. Furthermore, most existing enterprise data encryption and access control methods fail to account for the requirements of quantum secure communication, making it difficult to rigorously manage and control the key generation, distribution, storage, and destruction processes.

[0004] Therefore, the prior art has defects and needs to be improved. Summary of the Invention

[0005] In order to solve one or several problems in the prior art, the main purpose of this application is to provide an enterprise-level data encryption and access control method and system.

[0006] To achieve the above-mentioned purpose, the present application proposes an enterprise-level data encryption and access control method, which includes:

[0007] Build an enterprise server platform based on a fine-grained access control mechanism, encrypt enterprise data and generate keys based on encryption algorithms;

[0008] When receiving an access request instruction, verifying the identity information of the user who issued the access request instruction;

[0009] When the user's identity information meets the enterprise identity conditions, verify the user's role information in the enterprise and resolve the resources corresponding to the access request instruction;

[0010] When the user's role information meets the conditions for accessing the resource, the access key corresponding to the resource is matched based on the user's role information in the enterprise and the resource;

[0011] Based on the access key corresponding to the resource, the access key is transmitted to the user end according to the preset quantum state through the encryption algorithm.

[0012] Furthermore, the encryption algorithm includes a quantum encryption algorithm, and the access key is transmitted to the user terminal according to a preset quantum state by using the encryption algorithm, including:

[0013] Generating a random quantum state of the access key using the quantum encryption algorithm;

[0014] Setting a quantum communication channel, and sending the random quantum state to a user terminal through the quantum communication channel;

[0015] When the user terminal receives the random quantum state, it receives the measurement basis vector of the quantum state of the enterprise server platform and the user terminal;

[0016] When the measurement basis vectors of the quantum states received from the enterprise server platform and the user terminal are the same basis vectors, the key transmission is completed based on the same basis vectors.

[0017] Furthermore, the encryption algorithm further includes a symmetric encryption algorithm. When the encryption algorithm encrypts enterprise data, the method includes:

[0018] generating an encryption key by using the quantum key algorithm;

[0019] The encryption key is sent to the symmetric encryption algorithm, and the enterprise data is encrypted by the symmetric encryption algorithm using the encryption key.

[0020] Furthermore, the encryption key is sent to the symmetric encryption algorithm, and after the encryption of the enterprise data is completed, the key is managed. The method includes:

[0021] The encrypted key is sent to the enterprise server platform, and the key is stored, backed up or destroyed by the enterprise server platform.

[0022] Furthermore, when the measurement basis vectors of the quantum states received from the enterprise server platform and the user terminal are different basis vectors, the method includes:

[0023] Re-receiving the measurement basis vectors of the quantum states of the enterprise server platform and the user terminal within a preset time and number of times;

[0024] If the measurement basis vectors of the quantum states received from the enterprise server platform and the user end are still different, analyzing whether the user's access to this resource meets the conditions for privacy resources;

[0025] When the user's access to this resource meets the privacy resource conditions, an instruction to destroy the encryption key is sent to the enterprise server platform, and the key of this resource is destroyed by the enterprise server platform, and the key transmission is ended.

[0026] Furthermore, the enterprise server platform is constructed based on a fine-grained access control mechanism, including:

[0027] Receiving role structure data of the enterprise, and dividing administrators and ordinary users according to the role structure data;

[0028] Set corresponding permissions for each role according to the preset permission data, and input unique identity information for each role;

[0029] Set access rights for different roles to different resources based on preset access policies;

[0030] When access behavior is detected, the access time, access type and access results of the resource are recorded in real time.

[0031] Furthermore, after destroying the key of the resource through the enterprise server platform and ending the key transmission, the process further includes analyzing the cause of the basis vector mismatch, and the method includes:

[0032] Analyze whether the actual protocols of the enterprise server platform and the user end are the same;

[0033] When the actual protocols of the enterprise server platform and the user end are the same, it is determined that there is a signal interference factor in the quantum state key;

[0034] When the actual protocols of the enterprise server platform and the user end are different, it is determined that the quantum state key has a monitored or intercepted key.

[0035] The present application also provides an enterprise-level data encryption and access control system, including:

[0036] Building modules for building enterprise server platforms based on fine-grained access control mechanisms, encrypting enterprise data and generating keys based on encryption algorithms;

[0037] A verification module, configured to verify the identity information of the user who issued the access request instruction when receiving the access request instruction;

[0038] A parsing module, configured to verify the user's role information in the enterprise and parse the resources corresponding to the access request instruction when the user's identity information meets the enterprise identity conditions;

[0039] The matching module is used to match the access key corresponding to the resource based on the user's role information in the enterprise and the resource when the user's role information meets the conditions for accessing the resource;

[0040] The transmission module is used to transmit the access key corresponding to the resource to the user end according to the preset quantum state through the encryption algorithm.

[0041] The present application also provides a computer device, comprising a memory and a processor, wherein the memory stores a computer program, and the processor implements the steps of any of the above methods when executing the computer program.

[0042] The present application also provides a computer-readable storage medium having a computer program stored thereon, and when the computer program is executed by a processor, the steps of any of the above-mentioned methods are implemented.

[0043] The enterprise-level data encryption and access control method and system of the embodiment of the present application, by introducing a fine-grained access control mechanism, can achieve refined management of data access rights based on the specific needs and job responsibilities of each user. Compared with the existing technology, this method can not only assign corresponding permissions to different roles, but also generate keys associated with specific resources for each user, ensuring that the use of keys is more flexible and accurate. By dynamically generating keys associated with resources, the problem of inflexible key management is effectively solved. This means that the system will only generate the corresponding key when the user needs to access a specific resource, thereby avoiding excessive use and inappropriate authorization of the key. This on-demand key generation strategy not only improves the security of key management, but also reduces operating costs. In addition, by adopting quantum encryption algorithms, strict management and control can be achieved in the process of key generation, distribution, storage and destruction. The security of key transmission is ensured. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] Figure 1 A flowchart of an enterprise-level data encryption and access control method according to an embodiment of the present application is provided;

[0045] Figure 2 A flowchart of an enterprise-level data encryption and access control method according to an embodiment of the present application is provided;

[0046] Figure 3 This is a schematic block diagram of the structure of an enterprise-level data encryption and access control system according to an embodiment of the present application;

[0047] Figure 4 This is a schematic block diagram of the structure of a computer device according to an embodiment of the present application.

[0048] The realization of the objectives, functional features and advantages of this application will be further explained in conjunction with embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION

[0049] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.

[0050] Reference Figure 1 In an embodiment of the present application, an enterprise-level data encryption and access control method is provided, the method comprising:

[0051] S1. Build an enterprise server platform based on a fine-grained access control mechanism, encrypt enterprise data and generate keys based on encryption algorithms;

[0052] S2. When receiving an access request instruction, verify the identity information of the user who issued the access request instruction;

[0053] S3. When the user's identity information meets the enterprise identity conditions, verify the user's role information in the enterprise and resolve the resources corresponding to the access request instruction;

[0054] S4. When the user's role information meets the conditions for accessing the resource, the access key corresponding to the resource is matched based on the user's role information in the enterprise and the resource;

[0055] S5. Based on the access key corresponding to the resource, when the user's access rights meet the access conditions, the access key is transmitted to the user end according to the preset quantum state through the encryption algorithm.

[0056] As described in step S1 above, fine-grained access control mechanisms allow administrators to assign specific permissions to each user, role, and resource within the enterprise server platform. This mechanism, typically based on rules or policies, precisely controls user access levels to data. By implementing fine-grained access control, enterprises can reduce the risk of internal data breaches and ensure that only authorized users can access sensitive data, thereby improving data security. Encryption algorithms are used to convert data into a format that can only be decrypted by users holding the correct key. Key generation can be performed using either symmetric or asymmetric algorithms to ensure key security.

[0057] As described in steps S2-S3 above, the authentication process involves confirming the user's identity, which can be achieved through a username, password, biometric data, or other credentials. Authentication prevents unauthorized users from accessing system resources, ensuring that only authorized users can perform operations. Role verification is the process of determining a user's responsibilities and permissions within the organization. Based on the user's role and assigned permissions, role verification allows enterprises to ensure that users can only access data and resources relevant to their responsibilities, thereby enhancing data security.

[0058] As described in step S4 above, access keys are associated with specific resources and used to control access to them. Based on the user's role and resources, the system matches the corresponding access key only when the resource requested by the user matches the specific resource with the role information. By matching access keys, enterprises can achieve fine-grained access control over data and resources, preventing abuse of permissions and data leaks.

[0059] As described in step S5 above, quantum state transmission involves the use of quantum cryptography algorithms, such as quantum key distribution (QKD), to securely transmit access keys. Quantum cryptography algorithms provide a highly secure method for key transmission that prevents the key from being intercepted or tampered with during transmission, thereby ensuring the security of the key and the integrity of the data.

[0060] It's worth noting that access keys are associated with specific resources, meaning access permissions are determined based on the user's role and assigned resources. Encryption algorithms themselves are typically role-independent, protecting data from unauthorized access and understanding. However, key management and distribution vary depending on the role. The steps involved are: The enterprise's resources and corresponding permissions need to be defined. For example, a table in a database might be marked as accessible only to specific roles (such as administrators). Next, permissions are assigned to each role. For example, the administrator role might be granted full access to all resources, while the user role only has limited read access. Keys are generated when a user needs to access a resource. This generates a key associated with the resource (i.e., encryption only encrypts resources within the role's permissions. When decrypted with the correct key, the role can only decrypt the encrypted resources, leaving unencrypted resources unavailable). A key is generated for each user. Key generation and management involves the use of quantum cryptography algorithms, such as quantum key distribution (QKD), to ensure secure key transmission. When a user requests access to a resource, the system determines whether access is granted based on the user's role and assigned permissions. The system checks whether the user's role authorizes access to the resource and whether the user possesses the correct key. If the user's request is authorized, the system encrypts the data using the correct key. The encrypted data can only be decrypted by the user or system holding the corresponding key. Using quantum cryptography algorithms, key transmission follows quantum key distribution protocols to ensure the security of the key during transmission. All access activities should be logged and monitored for easy auditing and monitoring. Associating access keys with specific resources means that each resource can be assigned one or more keys, which are associated with specific access rights. The mapping of roles to permissions ensures that only users with the appropriate permissions can access specific resources. Key generation and management ensure the security and correctness of keys. Access control decisions ensure that only authorized users can access resources. Data encryption and decryption ensure the security of data during transmission and storage. Key transmission uses quantum cryptography algorithms to ensure secure key transmission. Access logging and monitoring ensure the auditing and monitoring of access activities.

[0061] Specifically, by introducing a fine-grained access control mechanism, refined management of data access rights can be achieved based on the specific needs and job responsibilities of each user. Compared with existing technologies, this method can not only assign corresponding permissions to different roles, but also generate keys associated with specific resources for each user, ensuring that the use of keys is more flexible and accurate. By dynamically generating keys associated with resources, the problem of inflexible key management is effectively solved. This means that the system will only generate the corresponding key when the user needs to access a specific resource, thus avoiding excessive use and inappropriate authorization of the key. This on-demand key generation strategy not only improves the security of key management, but also reduces operating costs. In addition, by adopting quantum encryption algorithms, strict management and control can be achieved in the process of key generation, distribution, storage and destruction. The security of key transmission is ensured.

[0062] In one possible embodiment, consider a company that owns a central server containing sensitive customer data. To protect this data, a security company decided to implement enterprise-level data encryption and access control. The security company first built an enterprise server platform based on a fine-grained access control mechanism. Within this platform, two roles were defined: administrator and user. The administrator role was granted full access to all resources, while the user role had limited read permissions. When an employee of the security company needed to access data on the server, the system verified their role within the company based on their identity information (such as employee number and name). For example, if a user attempted to access sensitive data, the system would check whether they had the appropriate read permissions. Next, the system matched the user's role with the resource they needed. For example, if a user needed to read data for a specific customer, the system would generate a key associated with that resource and send it to the user. When the user decrypted the data using the correct key, they would only be able to access the encrypted portion of the resource, while resources not covered by their permissions would be blocked. This ensured that only authorized users could access sensitive data, thereby improving data security. Furthermore, security companies are using quantum encryption algorithms to transmit access keys. Using the Quantum Key Distribution (QKD) protocol, they are able to ensure the security of key transmission, preventing it from being intercepted or leaked.

[0063] In one embodiment, resource-specific access keys are matched based on the user's role information within the enterprise and the resources they access. This involves defining the resources within the enterprise and their corresponding access permissions. For example, a table in a database might be marked as accessible only to specific roles (such as administrators). Appropriate permissions are assigned to each role. For example, an administrator role might be granted full access to all resources, while a user role might only have limited read permissions. Identity information for internal enterprise users, such as employee number, name, and department, is determined. User identities are associated with corresponding roles to ensure that users can correctly identify their roles when accessing the system. A user's resource access request is received, including the requested resource and user identity information. Based on the user's role information and the requested resource, the corresponding permissions are searched in the system's access control list (ACL) or access control matrix. The system verifies whether the user's role has permission to access the resource. If the user's request is authorized, the system generates an access key associated with the requested resource. This key is used for subsequent encryption and decryption. The generated access key is transmitted to the user via a secure communication channel. If a quantum encryption algorithm is used, the access key is transmitted via the quantum communication channel. After receiving the access key, the user can use it to decrypt the resource to access it.

[0064] In another embodiment, when the resource accessed by the role information is beyond the access scope, the access rights of the role information are verified. When the user's access rights meet the access conditions, the access key corresponding to the resource is matched with the resource beyond the access scope. The access key is then transmitted to the user end in a preset quantum state using the encryption algorithm. The management end can set a single access right for the preset role information, allowing the user of the role information to access the resource beyond the access scope.

[0065] Reference Figure 2 In one embodiment, the encryption algorithm includes a quantum encryption algorithm, and transmitting the access key to the user terminal according to a preset quantum state using the encryption algorithm includes:

[0066] S51, generating a random quantum state of the access key using the quantum encryption algorithm;

[0067] S52, setting a quantum communication channel, and sending the random quantum state to a user terminal through the quantum communication channel;

[0068] S53. When the user terminal receives the random quantum state, it receives a measurement basis vector of the quantum state of the enterprise server platform and the user terminal;

[0069] S54. When the measurement basis vectors of the quantum states received from the enterprise server platform and the user terminal are the same, the key transmission is completed based on the same basis vector.

[0070] As described in the steps above, quantum cryptography algorithms, such as quantum key distribution (QKD), leverage the principles of quantum mechanics, specifically the superposition and entanglement properties of qubits, to generate random quantum states. These quantum states carry the key information used for encryption. The randomness of quantum states and the uncertainty inherent in quantum mechanics ensure the unpredictability and security of the key, thereby improving the quality of the key. A quantum communication channel is a special communication channel capable of transmitting quantum states, such as photons. It must meet specific conditions for quantum state transmission, such as low noise, low loss, and a short transmission distance. The use of a quantum communication channel ensures the integrity of the quantum state during transmission, preventing any form of eavesdropping or interference, thereby protecting the key. In the QKD protocol, measurement basis vectors are two orthogonal directions used to measure the quantum state. The client and server must choose the same measurement basis vectors to ensure key consistency. By receiving and comparing the measurement basis vectors, both parties can verify the security of the key, as any attempt to eavesdrop or interfere with the quantum state will destroy its integrity and thus be detected. In the QKD protocol, if both parties choose the same measurement basis vector, they can confirm that part of the shared key is secure. This shared key can then be used with traditional encryption algorithms to encrypt the actual data. By using the same basis vectors to transmit the key, both parties can ensure the secure generation and transmission of the key, providing a high level of security for data encryption.

[0071] It's worth noting that in fine-grained access control, the system defines fine-grained access control policies based on employee roles, responsibilities, and specific needs. For example, employees in the Finance department can only access finance-related data, while employees in the R&D department can access both R&D and finance-related data. The system automatically detects changes in employee responsibilities and updates their access permissions in real time. For example, when an employee transfers from Finance to R&D, the system automatically adjusts their access permissions. In quantum state transmission technology, the system uses a quantum random number generator to generate random numbers, enhancing the randomness and security of cryptographic keys. The system also uses a quantum random number generator to generate access keys, ensuring their randomness and unpredictability. Fine-grained access control and quantum state transmission technology enhance the security of data access control and prevent the leakage of sensitive information. The system can dynamically adjust access permissions based on employees' specific needs and job responsibilities, improving work efficiency. Quantum state transmission technology improves the security of key transmission and reduces the risk of key leakage.

[0072] In one embodiment, the encryption algorithm further includes a symmetric encryption algorithm. When the encryption algorithm is used to encrypt enterprise data, the method includes:

[0073] generating an encryption key by using the quantum key algorithm;

[0074] The encryption key is sent to the symmetric encryption algorithm, and the enterprise data is encrypted by the symmetric encryption algorithm using the encryption key.

[0075] As mentioned above, quantum key algorithms, such as quantum key distribution (QKD), leverage the principles of quantum mechanics, specifically the superposition and entanglement properties of qubits, to generate random quantum keys. These keys carry the key information used for encryption. The randomness of quantum keys and the uncertainty of quantum mechanics ensure their unpredictability and security, thereby improving their quality. In symmetric encryption algorithms, the same key is used for encryption and decryption. The encryption key generated by the quantum key algorithm is sent to a symmetric encryption algorithm, which then uses the same key to encrypt data. By sending the quantum key to a symmetric encryption algorithm, the system leverages the high security of the quantum key to enhance the strength of the symmetric encryption algorithm, providing a higher level of data protection. Symmetric encryption algorithms, such as AES, use a single key to encrypt and decrypt data. Combining quantum keys with symmetric encryption algorithms transforms the data during the encryption process, ensuring that only users with the correct key can decrypt the data. By combining quantum keys with symmetric encryption algorithms, the system can provide a highly secure encryption solution that prevents unauthorized access and data leakage.

[0076] In one embodiment, the sending of the encryption key to the symmetric encryption algorithm, after the encryption of the enterprise data is completed, includes managing the key, and the method includes:

[0077] The encrypted key is sent to the enterprise server platform, and the key is stored, backed up or destroyed by the enterprise server platform.

[0078] As mentioned above, after encryption, keys must be securely stored and managed. The enterprise server platform, as a core component of the system, provides key storage and management capabilities. Keys are sent to the enterprise server platform to ensure key security and facilitate unified key management. Centralized key management improves key security and prevents unauthorized access or disclosure. The enterprise server platform provides key storage. Keys can be stored in a hardware security module (HSM), an encrypted database, or a dedicated key management system. When storing keys, the system implements strict access control and encryption measures to ensure key security. Key storage ensures the security of keys when not in use, preventing unauthorized access or disclosure. To prevent key loss or damage, the enterprise server platform backs up keys. Backup can be achieved through various methods, such as cold storage, off-site backup, or the use of encrypted backup media. Key backup ensures key recovery in the event of loss or damage, ensuring system operation and data security. When keys are no longer needed, the enterprise server platform destroys them. The destruction process ensures that the key cannot be recovered. This can include physical destruction, data erasure, or using encryption algorithms to convert the key into an unrecognizable form. Key destruction prevents key misuse, especially in the event of employee departure or key leakage. Prompt destruction of keys can reduce the risk of data breaches.

[0079] In one embodiment, when the measurement basis vectors of the quantum states received from the enterprise server platform and the user terminal are different, the method includes:

[0080] Re-receiving the measurement basis vectors of the quantum states of the enterprise server platform and the user terminal within a preset time and number of times;

[0081] If the measurement basis vectors of the quantum states received from the enterprise server platform and the user end are still different, analyzing whether the user's access to this resource meets the conditions for privacy resources;

[0082] When the user's access to this resource meets the privacy resource conditions, an instruction to destroy the encryption key is sent to the enterprise server platform, and the key of this resource is destroyed by the enterprise server platform, and the key transmission is ended.

[0083] As mentioned above, during the quantum key distribution (QKD) process, if the quantum state measurement basis vectors initially received by the enterprise server platform differ from those received by the user, the system will retry receiving them within a preset time and number of times. This ensures that errors or interference during communication are corrected, allowing both parties to retry generating a shared key. This mechanism improves QKD reliability and communication stability, reducing the risk of key transmission failures due to one-time errors. If, after multiple attempts to receive the quantum state measurement basis vectors, a match is still not found, the system analyzes whether the user meets the privacy requirements for accessing the resource. This may involve checking the user's role, permissions, access history, and other factors. This analysis ensures that even if communication issues arise during the QKD process, the system can determine whether to allow resource access based on other user information, thereby maintaining data security to a certain extent. If the system determines that the user's access to the resource meets the privacy requirements, it will send a command to the enterprise server platform to destroy the encryption key. This typically occurs when an uncorrectable error occurs during the QKD process. To prevent unauthorized access, the system instructs the server to destroy the key. Destroying encryption keys prevents unauthorized users from accessing resources using compromised keys, thereby protecting data security. Upon receiving an instruction to destroy an encryption key, the enterprise server platform executes the key destruction operation. The destruction process ensures that the key cannot be recovered, including physical destruction, data erasure, or the use of encryption algorithms to convert the key into an unrecognizable form. Key destruction prevents key misuse, especially in the event of a key leak. Prompt destruction can reduce the risk of data leakage.

[0084] In one embodiment, building an enterprise server platform based on a fine-grained access control mechanism includes:

[0085] Receiving role structure data of the enterprise, and dividing administrators and ordinary users according to the role structure data;

[0086] Set corresponding permissions for each role according to the preset permission data, and input unique identity information for each role;

[0087] Set access rights for different roles to different resources based on preset access policies;

[0088] When access behavior is detected, the access time, access type and access results of the resource are recorded in real time.

[0089] As described above, the system receives role schema data provided by the enterprise and, based on this data, defines different roles within the system, such as administrators and regular users. These roles reflect the enterprise's organizational structure and responsibilities. Role division helps clarify user responsibilities and permissions within the organization, providing a foundation for subsequent access control. Pre-set permission data defines the operations each role can perform, such as read, write, and modify. The system assigns corresponding permissions to each role based on this permission data. This permission setting ensures that only authorized users can perform specific operations, helping to prevent unauthorized access and data leakage. Each role is assigned unique identity information, such as a username or digital ID. This identity information is used to identify and authenticate users during access control. This unique identity helps distinguish between different users and provide personalized access control for each user. Access policies define which roles can access which resources. The system assigns access rights to different resources to different roles based on pre-set access policies. This role-based access control (RBAC) mechanism allows enterprises to exercise fine-grained control over data and resources, improving the flexibility and accuracy of data protection. The auditing and monitoring components in the system record user access to resources in real time, including access time, access type (e.g., read, write), and access result (e.g., success or failure). Recording and monitoring access behavior helps enterprises understand data usage, promptly identify abnormal behavior and potential security threats, and ensure data security and compliance.

[0090] In one embodiment, after destroying the key of the resource by the enterprise server platform and ending the key transmission, the method further includes analyzing the cause of the basis vector mismatch, and the method includes:

[0091] Analyze whether the actual protocols of the enterprise server platform and the user end are the same;

[0092] When the actual protocols of the enterprise server platform and the user end are the same, it is determined that there is a signal interference factor in the quantum state key;

[0093] When the actual protocols of the enterprise server platform and the user end are different, it is determined that the quantum state key has a monitored or intercepted key.

[0094] As mentioned above, the system compares the protocols used by the enterprise server platform and the client to ensure consistency. This involves comparing parameters such as protocol version, encryption method, and key exchange method. Ensuring that both parties use the same protocol can reduce communication errors caused by protocol mismatches and improve the stability and reliability of the QKD process. If the protocols are consistent, the system analyzes whether there are external signal interferences, such as nonlinear effects in optical fibers and environmental noise, which can cause basis vector mismatches. Identifying signal interference factors facilitates mitigation or elimination, ensuring the smooth progress of the QKD process. If the protocols are inconsistent, the system checks for unauthorized eavesdropping or key interception, which may involve attempts to eavesdrop or tamper with quantum states. Detecting and identifying such interception allows for timely implementation of security measures, such as terminating communication and regenerating keys, to ensure data security and key confidentiality.

[0095] In one embodiment, when the resource accessed by the role information is a resource outside the access scope, the method includes:

[0096] Obtain the time of access to the current role information, and determine whether the access time is within the preset working hours;

[0097] When the access time is not within the preset working hours, determining the importance coefficient of the accessed resource;

[0098] When the importance coefficient is not greater than a preset coefficient threshold, determining whether the current access satisfies a specific condition; if the current access satisfies the specific condition, temporarily elevating the role information, and matching the access key corresponding to the resource based on the temporarily elevated role information and the resource;

[0099] When the importance coefficient is greater than the preset coefficient threshold, the access behavior information is sent to the administrator, and the administrator's transparent review instruction is received in real time;

[0100] When a transparent audit instruction is received from the administrator, a communication and data exchange channel is established between the user terminal and the management terminal.

[0101] As described above, the user's access timestamp is recorded and compared with the preset working hours. This allows for differentiating access requests during normal and non-working hours, enabling the implementation of different access control policies. Pre-set working hours parameters, such as the start and end times of the workday, are used to determine whether the user's access time is within working hours. This ensures that access requests during non-working hours are handled appropriately, mitigating security risks. The system assigns an importance factor to each resource, reflecting its sensitivity and criticality. This factor allows the system to determine whether further review or temporary privilege escalation is required based on the resource's importance. The system determines whether specific conditions are met based on preset criteria (such as user responsibilities and project requirements). Automatic temporary privilege escalation is provided for eligible users, improving access efficiency and user experience. The system dynamically elevates user privileges based on user role information and resource requirements, allowing users to access resources beyond their normal privileges in specific circumstances while maintaining control over critical resources. Temporary access keys are generated for the elevated role information, enabling users to access the appropriate resources. This ensures that even with temporary privilege escalation, access is still subject to proper encryption and key management. The system automatically reports high-risk access requests to administrators. Access control security is enhanced by allowing administrators to intervene and review potential security risks. The system provides a transparent review process, allowing administrators to approve access requests in real time. This ensures transparency in the access control decision-making process, facilitating audit and traceability. The system establishes a secure communication and data exchange channel between users and administrators, allowing administrators to communicate directly with users to obtain additional information or provide instructions when necessary.

[0102] For example, an employee (User A) in one department needs to access data (Resource B) from another department to complete a cross-departmental project. User A attempts to access Resource B outside of working hours, but due to the urgency of the project, the access request requires immediate processing. The system detects that User A's access time is outside the preset working hours. Resource B is marked as critical business data, and its importance coefficient exceeds the preset threshold. The system sends information about User A's access behavior to the administrator. The administrator receives the access request in real time and conducts a transparent review. The administrator decides to temporarily elevate User A's permissions, allowing access to Resource B. Based on the role information and resources after the temporary privilege escalation, the system matches the access key for Resource B. User A successfully accesses Resource B using the temporary access key and completes the data analysis required for the project. User A is able to access critical resources during non-working hours, meeting the urgency of the project. Transparent review and privilege escalation by the administrator ensure that access control is properly managed even in emergency situations.

[0103] In one embodiment, when the resource accessed by the role information is a resource beyond the access scope, further comprising cross-departmental collaboration, the method includes:

[0104] Obtain all role information for cross-departmental collaboration, and set a dynamic permission matrix based on all role information for cross-departmental collaboration, wherein the dynamic permission matrix is ​​used to adjust access rights between cross-departmental role information;

[0105] Dynamically adjust the time of cross-departmental collaboration user access rights based on the progress of cross-departmental collaboration;

[0106] When receiving a cross-departmental access request instruction from role information, determining whether the role information meets the conditions for cross-departmental collaboration through the dynamic permission matrix;

[0107] When the role information meets the conditions for cross-department collaboration, determining whether the access time is within the time limit of the cross-department collaboration user access permission;

[0108] When the access time is within the time of the cross-department collaboration user access rights, the access key of the corresponding resource is matched based on the resources within the cross-department collaboration scope.

[0109] As described above, the system obtains information about all roles involved in cross-departmental collaboration. This ensures that all relevant role information is taken into account, facilitating subsequent permission setting and access control. The system dynamically sets a permissions matrix based on role information, resource requirements, and project progress. This allows the system to dynamically adjust access rights based on project needs and role changes, increasing the flexibility of permissions management. The system automatically adjusts the expiration period of user access rights based on project progress and timelines, ensuring that users access resources only when required, reducing resource waste and potential security risks. The system uses a dynamic permissions matrix to assess whether user role information and access requests meet cross-departmental collaboration requirements. Automated processing of cross-departmental access requests reduces human error and improves response time. The system checks whether the user's access time falls within the currently set access rights validity period. This ensures that users access resources during the correct time period while preventing unauthorized access. Based on the user's role information and access time, the system matches the corresponding access key to grant access to resources. This ensures that users can securely access resources within the authorized access period while protecting resources from unauthorized access.

[0110] The enterprise-level data encryption and access control method of the present application, by introducing a fine-grained access control mechanism, can achieve refined management of data access rights based on the specific needs and job responsibilities of each user. Compared with the existing technology, this method can not only assign corresponding permissions to different roles, but also generate keys associated with specific resources for each user, ensuring that the use of keys is more flexible and accurate. By dynamically generating keys associated with resources, the problem of inflexible key management is effectively solved. This means that the system will only generate the corresponding key when the user needs to access a specific resource, thereby avoiding excessive use and inappropriate authorization of the key. This on-demand key generation strategy not only improves the security of key management, but also reduces operating costs. In addition, by adopting quantum encryption algorithms, strict management and control can be achieved in the process of key generation, distribution, storage and destruction. The security of key transmission is ensured.

[0111] Reference Figure 3 , the embodiment of the present application also provides an enterprise-level data encryption and access control system, including:

[0112] Building modules for building enterprise server platforms based on fine-grained access control mechanisms, encrypting enterprise data and generating keys based on encryption algorithms;

[0113] A verification module, configured to verify the identity information of the user who issued the access request instruction when receiving the access request instruction;

[0114] A parsing module, configured to verify the user's role information in the enterprise and parse the resources corresponding to the access request instruction when the user's identity information meets the enterprise identity conditions;

[0115] The matching module is used to match the access key corresponding to the resource based on the user's role information in the enterprise and the resource when the user's role information meets the conditions for accessing the resource;

[0116] The transmission module is used to transmit the access key corresponding to the resource to the user end according to the preset quantum state through the encryption algorithm.

[0117] As described above, it can be understood that the various components of the enterprise-level data encryption and access control system proposed in this application can realize the functions of any of the enterprise-level data encryption and access control methods described above, and the specific structure will not be repeated.

[0118] Reference Figure 4 In the embodiment of the present application, a computer device is also provided. The computer device may be a server, and its internal structure may be as follows: Figure 4As shown. The computer device includes a processor, a memory, a network interface and a database connected via a system bus. The processor of the computer design is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The database of the computer device is used to store data such as monitoring data. The network interface of the computer device is used to communicate with an external terminal via a network connection. When the computer program is executed by the processor, an enterprise-level data encryption and access control method is implemented.

[0119] The above-mentioned processor executes the above-mentioned enterprise-level data encryption and access control method, including: building an enterprise server platform according to a fine-grained access control mechanism, encrypting enterprise data and generating keys according to an encryption algorithm; when an access request instruction is received, verifying the identity information of the user who issued the access request instruction; when the user's identity information meets the enterprise identity conditions, verifying the user's role information in the enterprise, and parsing the resources corresponding to the access request instruction; when the user's role information meets the conditions for accessing the resource, matching the access key corresponding to the resource according to the user's role information and resources in the enterprise; based on the access key corresponding to the resource, transmitting the access key to the user end according to a preset quantum state through the encryption algorithm.

[0120] The aforementioned enterprise-level data encryption and access control method, by introducing a fine-grained access control mechanism, enables refined management of data access rights based on each user's specific needs and job responsibilities. Compared to existing technologies, this method not only assigns corresponding permissions to different roles, but also generates keys associated with specific resources for each user, ensuring more flexible and precise key usage. By dynamically generating keys associated with resources, the problem of inflexible key management is effectively resolved. This means that the system only generates the corresponding key when a user needs to access a specific resource, thus avoiding excessive key use and inappropriate authorization. This on-demand key generation strategy not only improves the security of key management but also reduces operating costs. In addition, by adopting quantum encryption algorithms, strict management and control can be achieved during the key generation, distribution, storage, and destruction processes, ensuring the security of key transmission.

[0121] An embodiment of the present application also provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, an enterprise-level data encryption and access control method is implemented, including the following steps: building an enterprise server platform based on a fine-grained access control mechanism, encrypting enterprise data and generating keys based on an encryption algorithm; when an access request instruction is received, verifying the identity information of the user who issued the access request instruction; when the user's identity information meets the enterprise identity conditions, verifying the user's role information in the enterprise, and parsing the resources corresponding to the access request instruction; when the user's role information meets the conditions for accessing the resource, matching the access key corresponding to the resource based on the user's role information and resources in the enterprise; based on the access key corresponding to the resource, transmitting the access key to the user end according to a preset quantum state through the encryption algorithm.

[0122] Those skilled in the art will understand that all or part of the processes in the above-mentioned embodiment methods can be implemented by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media provided in this application and used in the embodiments may include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (SSRSDRAM), enhanced SDRAM (ESDRAM), Synchronous Link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct RAM bus dynamic RAM (DRDRAM), and RAM bus dynamic RAM (RDRAM), etc.

[0123] It should be noted that, in this document, the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, apparatus, article, or method comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, apparatus, article, or method. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, apparatus, article, or method comprising the element.

[0124] The above description is only a preferred embodiment of the present application and does not limit the patent scope of the present application. Any equivalent structure or equivalent process transformation made using the contents of the present application specification and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present application.

Claims

1. An enterprise-level data encryption and access control method, characterized in that: The method comprises: Build an enterprise server platform based on a fine-grained access control mechanism, encrypt enterprise data and generate keys based on encryption algorithms; When receiving an access request instruction, verifying the identity information of the user who issued the access request instruction; When the user's identity information meets the enterprise identity conditions, verify the user's role information in the enterprise and resolve the resources corresponding to the access request instruction; When the user's role information meets the conditions for accessing the resource, the access key corresponding to the resource is matched based on the user's role information in the enterprise and the resource; Based on the access key corresponding to the resource, the access key is transmitted to the user terminal according to the preset quantum state through the encryption algorithm; When the resource accessed by the role information is a resource beyond the access scope, the method includes: Obtain the time of access to the current role information, and determine whether the access time is within the preset working hours; When the access time is not within the preset working hours, determining the importance coefficient of the accessed resource; When the importance coefficient is not greater than a preset coefficient threshold, determining whether the current access satisfies a specific condition; if the current access satisfies the specific condition, temporarily elevating the role information, and matching the access key corresponding to the resource based on the temporarily elevated role information and the resource; When the importance coefficient is greater than the preset coefficient threshold, the access behavior information is sent to the administrator, and the administrator's transparent review instruction is received in real time; When receiving a transparent audit instruction from the administrator, a communication and data exchange channel is established between the user terminal and the administrator terminal; In fine-grained access control, fine-grained access control policies are defined based on employees’ roles, responsibilities, and specific needs; The access key is associated with a specific resource and is used to control access to the resource. According to the user's role and resource, the corresponding access key will be matched only when it is verified that the resource the user requires to access is a specific resource that matches the role information. When the resource accessed by the role information is a resource beyond the access scope, the access permission of the role information is verified. When the user's access permission meets the access conditions, the access key corresponding to the resource is matched through the resource beyond the access scope, and the access key is transmitted to the user end according to the preset quantum state through the encryption algorithm. The management end can set a single access permission for the preset role information, allowing the user of the role information to access resources beyond the access scope.

2. The enterprise-level data encryption and access control method according to claim 1, characterized in that: The encryption algorithm includes a quantum encryption algorithm, and the access key is transmitted to the user terminal according to a preset quantum state by using the encryption algorithm, including: Generating a random quantum state of the access key using the quantum encryption algorithm; Setting a quantum communication channel, and sending the random quantum state to a user terminal through the quantum communication channel; When the user terminal receives the random quantum state, it receives the measurement basis vector of the quantum state of the enterprise server platform and the user terminal; When the measurement basis vectors of the quantum states received from the enterprise server platform and the user terminal are the same basis vectors, the key transmission is completed based on the same basis vectors.

3. The enterprise-level data encryption and access control method according to claim 1, characterized in that: When the resource accessed by the role information is beyond the access scope, cross-departmental collaboration is also included, and the method includes: Obtain all role information for cross-departmental collaboration, and set a dynamic permission matrix based on all role information for cross-departmental collaboration, wherein the dynamic permission matrix is ​​used to adjust access rights between cross-departmental role information; Dynamically adjust the time of cross-departmental collaboration user access rights based on the progress of cross-departmental collaboration; When receiving a cross-departmental access request instruction from role information, determining whether the role information meets the conditions for cross-departmental collaboration through the dynamic permission matrix; When the role information meets the conditions for cross-department collaboration, determining whether the access time is within the time limit of the cross-department collaboration user access permission; When the access time is within the time of the cross-department collaboration user access rights, the access key of the corresponding resource is matched based on the resources within the cross-department collaboration scope.

4. The enterprise-level data encryption and access control method according to claim 2, characterized in that: When the measurement basis vectors of the quantum states received from the enterprise server platform and the user terminal are different, the method includes: Re-receiving the measurement basis vectors of the quantum states of the enterprise server platform and the user terminal within a preset time and number of times; If the measurement basis vectors of the quantum states received from the enterprise server platform and the user end are still different, analyzing whether the user's access to this resource meets the conditions for privacy resources; When the user's access to this resource meets the privacy resource conditions, an instruction to destroy the encryption key is sent to the enterprise server platform, and the key of this resource is destroyed by the enterprise server platform, and the key transmission is ended.

5. The enterprise-level data encryption and access control method according to claim 1, characterized in that: The enterprise server platform is constructed based on a fine-grained access control mechanism, including: Receiving role structure data of the enterprise, and dividing administrators and ordinary users according to the role structure data; Set corresponding permissions for each role according to the preset permission data, and input unique identity information for each role; Set access rights for different roles to different resources based on preset access policies; When access behavior is detected, the access time, access type and access results of the resource are recorded in real time.

6. The enterprise-level data encryption and access control method according to claim 4, characterized in that: After destroying the key of the resource through the enterprise server platform and ending the key transmission, the method further includes analyzing the cause of the basis vector mismatch, and the method includes: Analyze whether the actual protocols of the enterprise server platform and the user end are the same; When the actual protocols of the enterprise server platform and the user end are the same, it is determined that there is a signal interference factor in the quantum state key; When the actual protocols of the enterprise server platform and the user end are different, it is determined that the quantum state key has a monitored or intercepted key.

7. An enterprise-level data encryption and access control system, used in the method according to any one of claims 1 to 6, characterized in that: include: Building modules for building enterprise server platforms based on fine-grained access control mechanisms, encrypting enterprise data and generating keys based on encryption algorithms; A verification module, configured to verify the identity information of the user who issued the access request instruction when receiving the access request instruction; A parsing module, configured to verify the user's role information in the enterprise and parse the resources corresponding to the access request instruction when the user's identity information meets the enterprise identity conditions; The matching module is used to match the access key corresponding to the resource based on the user's role information in the enterprise and the resource when the user's role information meets the conditions for accessing the resource; The transmission module is used to transmit the access key corresponding to the resource to the user end according to the preset quantum state through the encryption algorithm.

8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.

Citation Information

Patent Citations

  • Data security transmission method and system, client method and device as well as server-side method and device

    CN107404461A

  • Data encryption access control method and system based on LDAP

    CN113742743A

  • Enterprise document encryption protection system based on computer

    CN117201148A