Ecological Monitoring Station Data Security Access Authorization Method
Through the combination of file analysis module, distribution storage module, security analysis module, user analysis module and intelligent review module, the problems of user security and permission management in data review of ecological monitoring stations are solved, intelligent authorized review is realized, and the security and rigor of data access are improved.
Patent Information
- Application Number
- CN202410830743.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-06-25
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2044-06-25
AI Technical Summary
In the prior art, the user's security situation and user situation are not analyzed when reviewing data of the ecological monitoring station, resulting in the data access permission management being not strict enough and poses security risks.
The file analysis module, distribution storage module, security analysis module, user analysis module and intelligent review module are adopted to determine the reference authorization level and access permissions by analyzing the file status, user ID and user situation of the data file, and realize intelligent authorization review.
It realizes intelligent authorization review based on user security analysis and user situation, and improves the security of data access on ecological monitoring stations and the rigor of permission management.
Smart Images

Figure CN118940307B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of data management technology, and specifically relates to a method for secure access authorization of data in ecological monitoring stations. Background Art
[0002] Ecological monitoring stations are facilities or sites used to collect, record, and analyze data related to ecosystems. The data collected includes meteorological data, water quality data, soil data, vegetation data, animal population data, etc. These data are crucial for understanding the structure, function, and dynamic changes of ecosystems.
[0003] When accessing the data in an ecological monitoring station, a user can gain access after entering the correct account number and corresponding password. However, this method does not analyze the security situation of the user or the user's situation based on historical data, nor does it grant access to corresponding data based on the user's corresponding permissions.
[0004] Therefore, we propose a method for secure access authorization of data in ecological monitoring stations. Summary of the Invention
[0005] The purpose of the present invention is to propose a method for secure access authorization of data in ecological monitoring stations to solve the problems raised in the above background art.
[0006] To achieve the above purpose, the present invention adopts the following technical solutions:
[0007] A method for secure access authorization of data in ecological monitoring stations, the method comprising the following steps:
[0008] Step S100, the storage module sends the file data of different data files in the ecological monitoring station to the file analysis module. The file analysis module analyzes the file situation of the data files in the ecological monitoring station and sends the obtained access authorization level of the data files in the ecological monitoring station to the distributed storage module;
[0009] Step S200, the distributed storage module distributes and stores the data files in the ecological monitoring station according to the access authorization level, and sends the access permission level of the data files in the ecological monitoring station and the corresponding storage partition to the intelligent access module;
[0010] Step S300, when accessing the data files of ecological monitoring, the data acquisition module acquires the user ID of the access user corresponding to the data files in the ecological monitoring station and sends it to the storage module. The storage module sends the corresponding user information to the user analysis module according to the user ID;
[0011] Step S400: The security analysis module analyzes the security situation of the access user corresponding to the ecological monitoring station. If the analysis generates a normal user signal, it allows the access user to access the data files in the ecological monitoring station; if the analysis generates an abnormal user signal, it does not allow the access user to access the data files in the ecological monitoring station.
[0012] Step S500: The user analysis module analyzes the user situation of the access user corresponding to the ecological monitoring station, and sends the obtained access permission level of the access user corresponding to the ecological monitoring station to the intelligent access module.
[0013] Step S600: The intelligent access module authorizes the access to the data files accessed by the access user corresponding to the ecological monitoring station.
[0014] Preferably, the file data is the file level, the number of times the file has been attacked, and the file security coefficient of the data files in the ecological monitoring station.
[0015] The user information is specifically the registration time, user level, abnormal access duration of the access user, and the number of abnormal behaviors.
[0016] Preferably, the analysis process of the file analysis module in step S200 is as follows:
[0017] Mark the data files in the ecological monitoring station as i, where i is the file number of the data file.
[0018] Obtain the file level of the data files in the ecological monitoring station, and obtain the file importance value WZi of the data files in the ecological monitoring station based on the file level.
[0019] Among them, the file level includes the first file level, the second file level, and the third file level. The file importance value corresponding to the first file level is X3, the file importance value corresponding to the second file level is X2, and the file importance value corresponding to the first file level is X1, where 1 < X1 < X2 < X3.
[0020] Then obtain the number of times the data files in the ecological monitoring station have been attacked, and mark the number of times the file has been attacked as GCi.
[0021] Finally, obtain the file security coefficient WXi of the data files in the ecological monitoring station; among them, the file security coefficient is determined by the number of file access users and the number of file access times, and the file security coefficient = the number of file access users * weight coefficient 1 + the number of file access times * weight coefficient 2.
[0022] Calculate the file control value WGi of the data files in the ecological monitoring station through the formula. The specific formula is as follows:
[0023] WGi = (WZi + GCi) / WXi;
[0024] If the file control value is less than the first file control threshold, the access authorization level of the data file is the third access authorization level;
[0025] If the file control value is greater than or equal to the first file control threshold and less than the second file control threshold, the access authorization level of the data file is the second access authorization level;
[0026] If the file control value is greater than or equal to the second file control threshold, the access authorization level of the data file is the first access authorization level.
[0027] Preferably, the first file control threshold is less than the second file control threshold;
[0028] The access authorization levels of the access authorization levels are, from high to low: the first access authorization level, the second access authorization level, and the third access authorization level.
[0029] Preferably, in step S300, the working process of the distributed storage module is specifically as follows:
[0030] Obtain the storage space of the data file corresponding to the ecological monitoring station, divide the storage space into several storage partitions, the storage partitions include a first storage partition, a second storage partition, and a third storage partition, and the storage security of the first storage partition is higher than that of the second storage partition, and the storage security of the second storage partition is higher than that of the third storage partition;
[0031] Obtain the access authorization level of the data file in the ecological monitoring station, and store the data file in the corresponding storage partition according to the access authorization level.
[0032] Preferably, the mapping relationship between the access authorization level and the storage partition is:
[0033] If the data file is at the first access authorization level, store the data file in the first storage partition;
[0034] If the data file is at the second access authorization level, store the data file in the second storage partition;
[0035] If the data file is at the third access authorization level, store the data file in the third storage partition.
[0036] Preferably, in step S400, the analysis process of the security analysis module is specifically as follows:
[0037] The ecological monitoring station is configured with a virtual operation space, and the virtual operation space is provided with a test folder, and a fixed number of test files are stored in the test folder;
[0038] Clone the accessing user to enable the accessing user to perform access operations on the virtual running space;
[0039] After the access operation of the accessing user, obtain the real-time sector information of all test files in the test folder, and compare the real-time sector information with the initial sector information;
[0040] If the real-time sector information does not match the initial sector information, mark the corresponding test file as a tampered file. If the real-time sector information matches the initial sector information, do not perform any operation;
[0041] Count the number of tampered files and compare it with the total number of test files to obtain the tampering rate of the test files;
[0042] When the tampering rate exceeds the preset tampering rate, generate a user anomaly signal;
[0043] When the tampering rate exceeds the preset tampering rate, generate a user security signal.
[0044] Preferably, the analysis process of the user analysis module is as follows:
[0045] Obtain the registration time of the accessing user corresponding to the ecological monitoring station, and subtract the registration time from the current time of the server to obtain the registration duration ZTu of the accessing user corresponding to the ecological monitoring station, where u is the number of the accessing user;
[0046] Then obtain the user level of the accessing user corresponding to the ecological monitoring station, and obtain the user security value YAu of the accessing user corresponding to the ecological monitoring station according to the user level; among them, the user level includes the first user level, the second user level and the third user level. The user security value of the first user level is Y3, and the user security value of the second user level is Y3. The user security value of the second user level is Y1, where 1 < Y1 < Y2 < Y3;
[0047] Finally, obtain the user abnormal access duration YTu and the number of user abnormal behaviors YCu of the accessing user corresponding to the ecological monitoring station;
[0048] Calculate the user permission value YQu of the accessing user corresponding to the ecological monitoring station through the formula YQu = (ZTu + YAu) / (YTu + YCu); the user permission value is used to reflect the access permission of the accessing user, and the user permission value is proportional to the access permission;
[0049] If the user permission value is less than the first user permission threshold, the access permission level of the accessing user corresponding to the ecological monitoring station is the third access permission level;
[0050] If the user permission value is greater than or equal to the first user permission threshold and less than the second user permission threshold, the access permission level of the accessing user corresponding to the ecological monitoring station is the second access permission level;
[0051] If the user permission value is greater than or equal to the second user permission threshold, the access permission level of the access user corresponding to the ecological monitoring station is the first access permission level.
[0052] Preferably, the first user permission threshold is less than the second user permission threshold, the permission of the first access permission level is greater than the permission of the second access permission level, and the permission of the second access permission level is greater than the permission of the third access permission level.
[0053] Preferably, in step S600, the access authorization process of the intelligent access module is specifically as follows:
[0054] Obtain the access permission level of the access user, and obtain the storage partitions that the access user can unlock according to the access permission level;
[0055] If the access permission level of the access user is the first access permission level, unlock the access permissions of all data files in all storage partitions;
[0056] If the access permission level of the access user is the second access permission level, unlock the access permissions of the data files in the second storage partition and the third storage partition;
[0057] If the access permission level of the access user is the third access permission level, only unlock the access permissions of the data files in the third storage partition.
[0058] Compared with the prior art, the beneficial effects of the present invention are:
[0059] The present invention first uses the file analysis module to analyze the file situation of the data files in the ecological monitoring station, and obtains the access authorization levels of the data files in the ecological monitoring station. The distributed storage module distributes and stores the data files in the ecological monitoring station according to the access authorization levels. When accessing the data files of the ecological monitoring, on the one hand, the security analysis module analyzes the security situation of the access user corresponding to the ecological monitoring station. If the analysis generates a normal user signal, it allows the access user to access the data files in the ecological monitoring station. On the other hand, the user analysis module also analyzes the user situation of the access user corresponding to the ecological monitoring station, and obtains the access permission level of the access user corresponding to the ecological monitoring station. Finally, the intelligent access module combines the access authorization level and the access permission level to realize the access authorization of the data files in the ecological monitoring station. The present invention realizes the intelligent authorized access of users to the data in the ecological monitoring station based on the user security analysis and the user analysis results. Description of the Drawings
[0060] For the convenience of those skilled in the art to understand, the present invention will be further described below with reference to the accompanying drawings.
[0061] Figure 1 is the flowchart of the operation of the present invention;
[0062] Figure 2 is the overall system block diagram of the present invention;
[0063] Figure 3 is the structural schematic diagram of the computer device in the present invention. Specific embodiments
[0064] The technical solution of the present invention will be clearly and completely described below in conjunction with the embodiments. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0065] In one embodiment, please refer to Figure 1 - Figure 2 As shown, the technical solution provided by the present invention is: an ecological monitoring station data security access authorization method, including the following steps:
[0066] Step S100, the storage module sends the file data of different data files in the ecological monitoring station to the file analysis module, and the file analysis module analyzes the file situation of the data files in the ecological monitoring station, and sends the obtained access authorization level of the data files in the ecological monitoring station to the distributed storage module;
[0067] Step S200, the distributed storage module distributes and stores the data files in the ecological monitoring station according to the access authorization level, and sends the access permission level of the data files in the ecological monitoring station and the corresponding storage partition to the intelligent access module;
[0068] Step S300, when accessing the data files of ecological monitoring, the data acquisition module acquires the user ID of the access user corresponding to the data files in the ecological monitoring station and sends it to the storage module, and the storage module sends the corresponding user information to the user analysis module according to the user ID;
[0069] Step S400, the security analysis module analyzes the security situation of the access user corresponding to the ecological monitoring station. If the analysis generates a normal user signal, it allows the access user to access the data files in the ecological monitoring station. If the analysis generates an abnormal user signal, it does not allow the access user to access the data files in the ecological monitoring station;
[0070] Step S500, the user analysis module analyzes the user situation of the access user corresponding to the ecological monitoring station, and sends the obtained access permission level of the access user corresponding to the ecological monitoring station to the intelligent access module;
[0071] Step S600, the intelligent access module authorizes the access to the data files accessed by the corresponding access users of the ecological monitoring station.
[0072] As Figure 2 shown, the above method involves a server, which is connected to a storage module, a file analysis module, a distributed storage module, a data acquisition module, a security analysis module, a user analysis module, and an intelligent access module;
[0073] In this embodiment, the storage module is used to record the file data of different data files in the ecological monitoring station. The storage module is data-connected to the file analysis module, and the storage module sends the file data of different data files in the ecological monitoring station to the file analysis module;
[0074] Specifically, the file data is the file level, the number of times the file has been attacked, and the file security factor of the data file in the ecological monitoring station;
[0075] The file analysis module is used to analyze the file situation of the data files in the ecological monitoring station. The analysis process is as follows:
[0076] Mark the data files in the ecological monitoring station as i, where i is the file number of the data file;
[0077] Obtain the file level of the data files in the ecological monitoring station, and obtain the file importance value WZi of the data files in the ecological monitoring station based on the file level;
[0078] Among them, the file level includes the first file level, the second file level, and the third file level. The file importance value corresponding to the first file level is X3, the file importance value corresponding to the second file level is X2, and the file importance value corresponding to the first file level is X1, where 1 < X1 < X2 < X3;
[0079] Then obtain the number of times the data files in the ecological monitoring station have been attacked, and mark the number of times the file has been attacked as GCi;
[0080] Finally, obtain the file security factor WXi of the data files in the ecological monitoring station; among them, the file security factor is determined by the number of file accesses and the number of file access times of the data file. File security factor = number of file accesses * weight coefficient 1 + number of file access times * weight coefficient 2;
[0081] Calculate the file control value WGi of the data files in the ecological monitoring station through the formula. The formula is as follows:
[0082] WGi = (WZi + GCi) / WXi;
[0083] If the file control value is less than the first file control threshold, the access authorization level of the data file is the third access authorization level;
[0084] If the file control value is greater than or equal to the first file control threshold and less than the second file control threshold, the access authorization level of the data file is the second access authorization level;
[0085] If the file control value is greater than or equal to the second file control threshold, the access authorization level of the data file is the first access authorization level; wherein, the first file control threshold is less than the second file control threshold, and the access authorization levels of the access authorization levels are, from high to low, the first access authorization level, the second access authorization level, and the third access authorization level;
[0086] The file analysis module feeds back the access authorization level of the data file in the ecological monitoring station to the server, and the server sends the access authorization level of the data file in the ecological monitoring station to the distributed storage module;
[0087] The distributed storage module is used to distribute and store the data files in the ecological monitoring station according to the access authorization level. The specific working process is as follows:
[0088] Obtain the storage space corresponding to the data file of the ecological monitoring station, divide the storage space into several storage partitions, including the first storage partition, the second storage partition, and the third storage partition. The storage security of the first storage partition is higher than that of the second storage partition, and the storage security of the second storage partition is higher than that of the third storage partition;
[0089] Obtain the access authorization level of the data file in the ecological monitoring station, and store the data file in the corresponding storage partition according to the access authorization level. Specifically:
[0090] If the data file is at the first access authorization level, store the data file in the first storage partition;
[0091] If the data file is at the second access authorization level, store the data file in the second storage partition;
[0092] If the data file is at the third access authorization level, store the data file in the third storage partition;
[0093] The distributed storage module feeds back the access permission level of the data file in the ecological monitoring station and the corresponding storage partition to the server, and the server sends the access permission level of the data file in the ecological monitoring station and the corresponding storage partition to the intelligent access module.
[0094] As a further embodiment of the present invention, when accessing the data file of ecological monitoring, it is necessary to analyze the security situation and user situation of the user;
[0095] Specifically, the data acquisition module is used to collect the user ID of the access user corresponding to the data file in the ecological monitoring station, and send the user ID to the server, and the server sends the user ID to the storage module;
[0096] The storage module is also used to store the user information corresponding to different user IDs, and the storage module is used to send the corresponding user information to the user analysis module according to the user ID. The user information is specifically the registration time, user level, user abnormal access duration, and user abnormal behavior times of the access user;
[0097] The security analysis module is used to analyze the security situation of the access user corresponding to the ecological monitoring station. The analysis process is as follows:
[0098] The ecological monitoring station is configured with a virtual operation space. The virtual operation space is provided with a test folder, and a fixed number of test files are stored in the test folder; among them, the test files do not have a protection function and are only used to test the security of the access user;
[0099] Using digital twin technology to clone the access user, so that the access user performs access operations on the virtual operation space, and the access operations include uploading, downloading, moving, viewing, etc.;
[0100] After the access operation of the access user, obtain the real-time sector information of all test files in the test folder, and compare the real-time sector information with the initial sector information;
[0101] If the real-time sector information does not match the initial sector information, the corresponding test file is marked as a tampered file. If the real-time sector information matches the initial sector information, no operation is performed;
[0102] Count the number of tampered files and compare with the total number of test files to obtain the tampering rate of the test files;
[0103] When the tampering rate exceeds the preset tampering rate, a user abnormal signal is generated;
[0104] When the tampering rate exceeds the preset tampering rate, a user security signal is generated;
[0105] The security analysis module feeds back the user abnormal signal or the user security signal to the server. If the server receives the user security signal, it allows the access user to access the data file in the ecological monitoring station. If the server receives the user abnormal signal, it does not allow the access user to access the data file in the ecological monitoring station;
[0106] The user analysis module is used to analyze the user situation of the access user corresponding to the ecological monitoring station. The analysis process is as follows:
[0107] Obtain the registration time of the access user corresponding to the ecological monitoring station, and subtract the registration time from the current time of the server to obtain the registration duration ZTu of the access user corresponding to the ecological monitoring station, where u is the number of the access user;
[0108] Then obtain the user level of the access user corresponding to the ecological monitoring station, and obtain the user security value YAu of the access user corresponding to the ecological monitoring station according to the user level; among them, the user level includes the first user level, the second user level and the third user level, the user security value of the first user level is Y3, the user security value of the second user level is Y3, the user security value of the second user level is Y1, and 1 < Y1 < Y2 < Y3;
[0109] Finally, obtain the abnormal access duration YTu and the number of abnormal behavior times YCu of the access user corresponding to the ecological monitoring station;
[0110] Calculate the user permission value YQu of the access user corresponding to the ecological monitoring station through the formula YQu = (ZTu + YAu) / (YTu + YCu); the user permission value is used to reflect the access permission of the access user, and the user permission value is directly proportional to the access permission;
[0111] If the user permission value is less than the first user permission threshold, the access permission level of the access user corresponding to the ecological monitoring station is the third access permission level;
[0112] If the user permission value is greater than or equal to the first user permission threshold and less than the second user permission threshold, the access permission level of the access user corresponding to the ecological monitoring station is the second access permission level;
[0113] If the user permission value is greater than or equal to the second user permission threshold, the access permission level of the access user corresponding to the ecological monitoring station is the first access permission level; among them, the first user permission threshold is less than the second user permission threshold, the permission of the first access permission level is greater than the permission of the second access permission level, and the permission of the second access permission level is greater than the permission of the third access permission level;
[0114] The user analysis module feeds back the access permission level of the access user corresponding to the ecological monitoring station to the server, and the server sends the access permission level of the access user corresponding to the ecological monitoring station to the intelligent access module;
[0115] The intelligent access module is used to perform access authorization on the data files accessed by the access user corresponding to the ecological monitoring station. The specific process of access authorization is as follows:
[0116] Obtain the access permission level of the access user, and obtain the storage partition that the access user can unlock according to the access permission level;
[0117] If the access privilege level of the accessing user is the first access privilege level, the access rights to all data files in all storage partitions are unlocked;
[0118] If the access privilege level of the accessing user is the second access privilege level, the access rights to the data files in the second storage partition and the third storage partition are unlocked;
[0119] If the access privilege level of the accessing user is the third access privilege level, only the access rights to the data files in the third storage partition are unlocked;
[0120] In this application, if there are corresponding calculation formulas, the above calculation formulas are all dimensionless and take their numerical values for calculation. For coefficients such as weight coefficients and proportionality coefficients existing in the formulas, the magnitudes set are for obtaining a result value by quantifying each parameter. Regarding the magnitudes of the weight coefficients and proportionality coefficients, as long as the proportional relationship between the parameters and the result value is not affected.
[0121] In one embodiment, Figure 3 An entity structure diagram of a computer device is illustrated, such as Figure 3As shown in the figure, the computer device may include: a processor, a communications interface, a memory, and a communication bus. Among them, the processor, the communication interface, and the memory complete communication with each other through the communication bus. The processor may call the logical instructions in the memory to execute the method for authorizing access to the data security of the ecological monitoring station. The method includes: the storage module sends the file data of different data files in the ecological monitoring station to the file analysis module, and the file analysis module analyzes the file conditions of the data files in the ecological monitoring station, and sends the obtained access authorization level of the data files in the ecological monitoring station to the distributed storage module; the distributed storage module distributes and stores the data files in the ecological monitoring station according to the access authorization level, and sends the access permission level of the data files in the ecological monitoring station and the corresponding storage partition to the intelligent access module; when accessing the data files of the ecological monitoring, the data acquisition module acquires the user ID of the access user corresponding to the data files in the ecological monitoring station and sends it to the storage module, and the storage module sends the corresponding user information to the user analysis module according to the user ID; the security analysis module analyzes the security situation of the access user corresponding to the ecological monitoring station. If the analysis generates a normal user signal, it allows the access user to access the data files in the ecological monitoring station. If the analysis generates an abnormal user signal, it does not allow the access user to access the data files in the ecological monitoring station; the user analysis module analyzes the user situation of the access user corresponding to the ecological monitoring station, and sends the obtained access permission level of the access user corresponding to the ecological monitoring station to the intelligent access module; the intelligent access module authorizes access to the data files accessed by the access user corresponding to the ecological monitoring station.
[0122] In addition, when the logical instructions in the above-mentioned memory can be implemented in the form of software functional units and sold or used as an independent product, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs that can store program codes.
[0123] On the other hand, the present application also provides a computer program product. The computer program product includes a computer program stored on a computer-readable storage medium. The computer program includes program instructions. When the program instructions are executed by a computer, the computer can execute the ecological monitoring station data security access authorization method provided by the above-mentioned various methods. The method includes: the storage module sends the file data of different data files in the ecological monitoring station to the file analysis module, and the file analysis module analyzes the file situation of the data files in the ecological monitoring station, and sends the access authorization level of the data files in the ecological monitoring station obtained by the analysis to the distributed storage module; the distributed storage module distributes and stores the data files in the ecological monitoring station according to the access authorization level, and sends the access permission level of the data files in the ecological monitoring station and the corresponding storage partition to the intelligent access module; when accessing the data files of the ecological monitoring, the data acquisition module acquires the user ID of the access user corresponding to the data files in the ecological monitoring station and sends it to the storage module, and the storage module sends the corresponding user information to the user analysis module according to the user ID; the security analysis module analyzes the security situation of the access user corresponding to the ecological monitoring station. If a user normal signal is generated by the analysis, the access user is allowed to access the data files in the ecological monitoring station. If a user abnormal signal is generated by the analysis, the access user is not allowed to access the data files in the ecological monitoring station; the user analysis module analyzes the user situation of the access user corresponding to the ecological monitoring station, and sends the access permission level of the access user corresponding to the ecological monitoring station obtained by the analysis to the intelligent access module; the intelligent access module performs access authorization on the data files accessed by the access user corresponding to the ecological monitoring station.
[0124] In another aspect, the present application also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it is used to execute the ecological monitoring station data security access authorization method provided above. The method includes: the storage module sends the file data of different data files in the ecological monitoring station to the file analysis module, and the file analysis module analyzes the file situation of the data files in the ecological monitoring station, and sends the access authorization level of the data files in the ecological monitoring station obtained by the analysis to the distributed storage module; the distributed storage module distributes and stores the data files in the ecological monitoring station according to the access authorization level, and sends the access permission level of the data files in the ecological monitoring station and the corresponding storage partition to the intelligent access module; when accessing the data files of the ecological monitoring, the data acquisition module acquires the user ID of the access user corresponding to the data files in the ecological monitoring station and sends it to the storage module, and the storage module sends the corresponding user information to the user analysis module according to the user ID; the security analysis module analyzes the security situation of the access user corresponding to the ecological monitoring station. If the user normal signal is generated by the analysis, the access user is allowed to access the data files in the ecological monitoring station. If the user abnormal signal is generated by the analysis, the access user is not allowed to access the data files in the ecological monitoring station; the user analysis module analyzes the user situation of the access user corresponding to the ecological monitoring station, and sends the access permission level of the access user corresponding to the ecological monitoring station obtained by the analysis to the intelligent access module; the intelligent access module conducts access authorization on the data files accessed by the access user corresponding to the ecological monitoring station.
[0125] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative labor.
[0126] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0127] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. A method for authorizing secure access to ecological monitoring station data, characterized in that, The method includes the following steps: In step S100, the storage module sends the file data of different data files recorded in the ecological monitoring station to the file analysis module. The file analysis module analyzes the file situation of the data files in the ecological monitoring station, and sends the obtained access authorization level of the data files in the ecological monitoring station to the distributed storage module; In step S200, the distributed storage module distributes and stores the data files in the ecological monitoring station according to the access authorization level, and sends the access permission level of the data files in the ecological monitoring station and the corresponding storage partition to the intelligent access module; In step S300, when accessing the data files of ecological monitoring, the data acquisition module acquires the user ID of the access user corresponding to the data files in the ecological monitoring station and sends it to the storage module. The storage module sends the corresponding user information to the user analysis module according to the user ID; In step S400, the security analysis module analyzes the security situation of the access user corresponding to the ecological monitoring station. If the analysis generates a user normal signal, it allows the access user to access the data files in the ecological monitoring station. If the analysis generates a user abnormal signal, it does not allow the access user to access the data files in the ecological monitoring station; In step S400, the analysis process of the security analysis module is specifically as follows: The ecological monitoring station is configured with a virtual operation space, and the virtual operation space is set with a test folder, and a fixed number of test files are stored in the test folder; Clone the access user so that the access user performs access operations on the virtual operation space; After the access operation of the access user, obtain the real-time sector information of all test files in the test folder, and compare the real-time sector information with the initial sector information; If the real-time sector information does not match the initial sector information, mark the corresponding test file as a tampered file. If the real-time sector information matches the initial sector information, no operation is performed; Count the number of tampered files and compare it with the total number of test files to obtain the tampering rate of the test files; When the tampering rate exceeds the preset tampering rate, generate a user abnormal signal; When the tampering rate exceeds the preset tampering rate, generate a user security signal; In step S500, the user analysis module analyzes the user situation of the access user corresponding to the ecological monitoring station, and sends the obtained access permission level of the access user corresponding to the ecological monitoring station to the intelligent access module; In step S600, the intelligent access module authorizes the access to the data files accessed by the access user corresponding to the ecological monitoring station.
2. The method for authorizing secure access to ecological monitoring station data according to claim 1, wherein The file data is the file level, the number of times the file has been attacked, and the file security coefficient of the data files in the ecological monitoring station; The user information is specifically the registration time, user level, abnormal access duration of the access user, and the number of abnormal behavior times.
3. The method for authorizing access to ecological monitoring station data security according to claim 2, characterized in that In step S200, the analysis process of the file analysis module is specifically as follows: Obtain the file level of the data files in the ecological monitoring station, and obtain the file importance value of the data files in the ecological monitoring station according to the file level; Then obtain the number of times the data files in the ecological monitoring station have been attacked and the file security coefficient; Calculate the file control value of the data files in the ecological monitoring station; The file control value is compared with the file control threshold to determine that the access authorization level of the data file is the third access authorization level, the second access authorization level, or the first access authorization level.
4. The method for authorizing access to the data security of the ecological monitoring station according to claim 3, characterized in that, The access authorization levels of the access authorization levels are, from high to low: the first access authorization level, the second access authorization level, and the third access authorization level.
5. The ecological monitoring station data security access authorization method according to claim 1, characterized in that The working process of the distributed storage module in step S300 is specifically as follows: Obtain the storage space of the data file corresponding to the ecological monitoring station, divide the storage space into several storage partitions, including the first storage partition, the second storage partition, and the third storage partition. The storage security of the first storage partition is higher than that of the second storage partition, and the storage security of the second storage partition is higher than that of the third storage partition; Obtain the access authorization level of the data file in the ecological monitoring station, and store the data file in the corresponding storage partition according to the access authorization level.
6. The method for authorizing secure access to ecological monitoring station data according to claim 5, characterized in that, The mapping relationship between the access authorization level and the storage partition is: If the data file is at the first access authorization level, store the data file in the first storage partition; If the data file is at the second access authorization level, store the data file in the second storage partition; If the data file is at the third access authorization level, store the data file in the third storage partition.
7. The method for authorizing access to the data security of the ecological monitoring station according to claim 1, wherein The analysis process of the user analysis module is specifically as follows: Obtain the registration time of the access user corresponding to the ecological monitoring station, and subtract the registration time from the current time of the server to obtain the registration duration of the access user corresponding to the ecological monitoring station; Then obtain the user level of the access user corresponding to the ecological monitoring station, and obtain the user security value of the access user corresponding to the ecological monitoring station according to the user level; Finally, obtain the user abnormal access duration and the number of user abnormal behaviors of the access user corresponding to the ecological monitoring station; Calculate the user permission value of the access user corresponding to the ecological monitoring station; The user permission value is compared with the user permission threshold to determine that the access permission level of the access user corresponding to the ecological monitoring station is the third access permission level, the second access permission level, or the first access permission level.
8. The method for authorizing secure access to ecological monitoring station data according to claim 7, characterized in that, The permission of the first access permission level is greater than the permission of the second access permission level, and the permission of the second access permission level is greater than the permission of the third access permission level.
9. The method for authorizing access to ecological monitoring station data security according to claim 1, characterized in that The access authorization process of the intelligent access module in step S600 is specifically as follows: Obtain the access permission level of the access user, and obtain the storage partition that the access user can unlock according to the access permission level; If the access permission level of the access user is the first access permission level, unlock the access permission of all data files in all storage partitions; If the access permission level of the access user is the second access permission level, unlock the access permission of the data files in the second storage partition and the third storage partition; If the access permission level of the access user is the third access permission level, only unlock the access permission of the data files in the third storage partition.
Citation Information
Patent Citations
Data resource security control method in thin client mode
CN103441986A
Big data security system access operation platform and data retrieval method
CN112699357A
Monitoring and management system for abnormal access state of user
CN117744072A