Data Access Control Optimization Method Based on Graph Neural Network
By building graph models and using graph neural networks and adaptive decision-making algorithms to update access control policies in real time, the problems of slow response speed and insufficient adaptability in the rapidly changing environment are solved, and efficient and secure data access control is achieved.
Patent Information
- Application Number
- CN202411140910.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-20
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2044-08-20
AI Technical Summary
Traditional data access control systems are difficult to adapt to rapidly changing environments and complex user relationships, and are slow to respond and error-prone to them, and cannot effectively capture dynamics and complexity.
The graph neural network is used to build a graph model, process the complex relationship between nodes through the graph neural network, update the access control strategy in real time, and use adaptive decision algorithms to monitor and adjust access permissions.
It realizes dynamic adaptation to complex user relationships, improves response speed and security, reduces manual intervention, and is suitable for large-scale enterprises and cloud environments.
Smart Images

Figure CN119004509B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of graph neural networks, and particularly to an optimization method for data access control based on graph neural networks. Background Art
[0002] In today's information age, data access control has become a key technology for maintaining information security. Traditional data access control systems mainly rely on static rules to manage users' access rights to data, and these rules fixedly define which users can access specific resources under what conditions. For example, a common access control model is role-based access control (RBAC), where access rights are predefined according to users' roles and associated with specific resources. Although this method is very effective in many application scenarios, it usually cannot flexibly cope with rapidly changing environments and complex user relationships.
[0003] The prior art faces the following several core difficulties when dealing with dynamic and complex data environments:
[0004] 1. Limitations of static rules: Traditional access control systems usually rely on predefined static rules and are difficult to adapt to rapidly changing requirements and environments. When new user roles or resource requirements emerge, these static rules need to be updated manually, which is not only time-consuming but also error-prone.
[0005] 2. Difficulty in modeling complex relationships: In modern enterprises and social networks, the relationship network among users is much more complex than what traditional models can express. For example, the relationships among users may be multi-dimensional and change dynamically over time. Traditional models often cannot effectively capture this dynamicity and complexity.
[0006] 3. Slow response speed: Due to relying on static rules and manual updates, traditional systems often do not respond quickly enough to new security threats or change requests, which may lead to security vulnerabilities.
[0007] Therefore, how to provide a data access control method that can dynamically adapt to environmental changes, effectively manage complex user relationships, and improve the response speed is an urgent problem to be solved by those skilled in the art. The optimization method for data access control based on graph neural networks provides a new technical approach to solve these problems by using graph neural networks to model complex user relationships and real-time update access control policies to adapt to rapidly changing data access requirements and environments. Summary of the Invention
[0008] An object of the present invention is to propose a method for optimizing data access control based on a graph neural network. The present invention makes full use of graph neural network technology, an adaptive decision-making algorithm, and modern data processing methods, and details a method for optimizing data access control based on a graph neural network.
[0009] A method for optimizing data access control based on a graph neural network according to an embodiment of the present invention includes the following steps:
[0010] S1. Construct a graph model, which includes a plurality of nodes and edges, where each node represents a data access entity, and the data access entity is a user, a role, or a resource; each edge represents the relationship between entities;
[0011] S2. Process the graph model through a graph neural network to analyze and learn the complex relationships between nodes, including direct and indirect dependencies;
[0012] S3. Based on the analysis results of the graph neural network, evaluate the changes in the node feature vectors, identify the changes in user behavior patterns and access requirements, and dynamically adjust the data access control policy;
[0013] S4. Real-time monitor the status and user behavior, and use the adaptive decision-making algorithm to analyze the environmental changes.
[0014] Optionally, the S1 specifically includes:
[0015] S11. Collect metadata related to data access, including users U, roles R, resources S, and their attribute information;
[0016] S12. Define node types, including user nodes U i , role nodes R j and resource nodes S k , where i, j, and k respectively represent identifiers of different entities;
[0017] S13. Define edge types, representing the access permissions and relationships between different entities, including the association between users and roles (U-R), the access permissions of roles to resources (R-S), and the permissions of users to directly access resources (U-S);
[0018] S14. Use the definition matrix E of the edge ij , where E is the definition matrix, and i and j represent the entity nodes in the graph:
[0019] E ij = 1 indicates that there is a direct relationship between entity i and entity j;
[0020] E ij = 0 indicates that there is no direct relationship between entity i and entity j;
[0021] S15. Utilize the attribute matrix X, where X represents the attribute vector of node i, which contains the key characteristics and behavioral data of the entity and is used to capture and express the characteristic information of the node.
[0022] Optionally, the S2 specifically includes:
[0023] S21. Apply the graph neural network algorithm to process the initialized graph model. The graph neural network algorithm updates the representation of the nodes based on the characteristics of the nodes and the relationships of the edges.
[0024] S22. Dynamically update the node feature representation through the multi-layer structure of the graph neural network, enabling real-time adaptation to changes in the user behavior pattern and operating environment:
[0025]
[0026] Among them, represents the feature vector of node i at the k-th layer. In data access control, node i is the user, and the feature vector contains the identity information of the user of the node, the permission definition of the role, and the access rules of the resource. represents the feature vector of node i at the (k + 1)-th layer. Through the multi-layer message passing mechanism of the graph neural network, the feature vector of each node is updated according to the information of its neighbors at each layer, so as to obtain a new feature vector at the (k + 1)-th layer. N(i) represents the set of neighbor nodes of node i. In the graph model, there is an access relationship between users, roles, and resources. W (k) represents the weight matrix at the k-th layer. For modeling relationships at different levels, the weight matrix can capture different levels of dependency relationships between users, roles, and resources. b (k) represents the bias vector at the k-th layer, which is also a trainable parameter in the graph neural network and is added to the aggregated information for linear transformation to help the model better fit the complex access control relationship. represents the aggregation function, which is used to summarize the feature vectors of node i and all its neighbor nodes i. In data access control, the aggregation function combines the feature information of users, roles, and resources to generate a comprehensive representation; σ represents the non-linear activation function.
[0027] S23. Repeatedly execute the message passing and state update processes in step S22 until the predetermined network layer number L is reached, so that the feature vector of each node fully captures and fuses the information from its neighbors.
[0028] S24. Evaluate the effectiveness of the learned node representation, and identify direct and indirect dependency relationships through the new feature vectors between nodes.
[0029] S25. Apply the identified dependency relationships to the adjustment of the dynamic access control policy.
[0030] Optionally, S3 specifically includes:
[0031] S31. Analyze the node feature vectors generated by the graph neural network, and by identifying indicators affected by behavior patterns, access frequencies, and other environmental factors, guide the adjustment of the access control policy;
[0032] S32. Set a threshold θ to evaluate whether the change in the node behavior pattern exceeds the normal range, and monitor the change in the node behavior pattern by calculating ΔH i :
[0033]
[0034] Wherein, represents the feature vector of node i at the current moment. In data access control, node i is a user, and the current feature vector reflects the latest state of the node, including quantities such as the current behavior of the user, the permission status of the role, and the access records of resources, represents the feature vector of node i at the previous moment. These feature vectors store the state information of the node at the previous time point, including the previous behavior of the user, the permission status of the role, and the access records of resources;
[0035] S33. According to the comparison result of ΔH i calculated in step S32 and θ, adjust the access control policy of node i;
[0036] S34. For the nodes that need to be adjusted, update the access control rules, including adding, reducing, and modifying access permissions;
[0037] Optionally, S32 specifically includes:
[0038] S321. Define the change metric of the node feature vector, and use the Euclidean distance to quantify the change in the node feature vector between two moments:
[0039]
[0040] Wherein, ΔH i represents the change metric of the feature vector of node i, measuring the feature change of node i between two time points. The larger this value is, the more significant the state change of the node is, represents the eigenvalue of the feature vector of node i at the current time point in dimension k. This eigenvalue includes the identity information of the user, the permission definition of the role, and the access rules of resources, It represents the eigenvalue of the feature vector of node i at the previous time point in dimension k, which represents the characteristics of the node in the previous state, including previous behaviors, permission status of roles, and access records of resources, etc. n represents the dimension of the feature vector, that is, the number of dimensions of the node feature vector, and these dimensions include user attributes, behavior data, role permissions, resource attributes, etc.;
[0041] S322. By dynamically adjusting the threshold θ(t), it can timely respond to the changes in **user behavior patterns and operating environments**:
[0042]
[0043] Among them, θ(t) represents the security sensitivity threshold at the current moment, which is used to judge whether it is necessary to adjust the data access control policy to respond to the changes in user behavior patterns and operating environments. α determines the sensitivity to state changes, is the average value of the changes in the feature vectors of all nodes in the previous time window. By monitoring to identify potential abnormal activities or changes in behavior patterns in, and realize real-time adjustment of security policies. θ(t - 1) is the security sensitivity threshold at the previous time point;
[0044] S323. For each node, compare the feature vector change ΔH i with the dynamic threshold θ(t);
[0045] S324. Record all nodes that exceed the threshold and mark them as objects that need to be reviewed or have their access permissions adjusted.
[0046] Optionally, the S4 specifically includes:
[0047] S41. Real-time monitor data access activities and environmental changes, and the captured data includes user behaviors, access requests, and resource status;
[0048] S42. Use an adaptive decision-making algorithm to analyze the monitored data;
[0049] S43. According to the algorithm analysis results, dynamically adjust the graph model, including adding or deleting nodes and edges, and modifying node attributes, to reflect new relationships and access rules between entities;
[0050] S44. Update the access control policy, and formulate new access permissions according to the adjusted graph model and environmental changes;
[0051] S45. Apply the updated access control policy to data access control, and provide real-time feedback on environmental changes and user requirements.
[0052] Optionally, the S42 specifically includes:
[0053] S421. By calculating the security score E(S) regularly or in real time, potential security threats can be dynamically monitored and managed:
[0054]
[0055] Among them, S represents the overall state at the current moment, including the attribute information of all nodes and edges, user behavior, and resource status. N represents the total number of different risk factors considered when evaluating the security state. w i represents the relative importance of the i-th risk factor to the overall risk assessment. The larger the weight value, the more significant the impact of this risk factor in the overall security assessment. h i (S) represents the degree of influence of quantifying a specific risk factor in the current state. This evaluation function outputs a value indicating the magnitude of the influence of this risk factor;
[0056] S422. Design a dynamic update mechanism. The dynamic update mechanism adjusts the risk assessment model according to the real-time data X ch ange , in response to newly emerging threats or changing environmental conditions:
[0057] w i (t) = w i (t - 1)·(1 - α) + α·Δx i
[0058] Among them, α controls the adaptation speed to new information, balancing sensitivity and stability. Δx i specifically quantifies the monitored risk changes for adjusting the state assessment. w i (t) represents the degree of influence of each risk factor on the current state. w i (t - 1) reflects the importance of this risk factor in the security assessment at the previous moment. w i dynamically reflects the impact of risk factors on security, thereby reflecting the changes in the state in real time;
[0059] S423. Use the updated weight w i (t) and the state information to recalculate the security score E(S);
[0060] S424. When E(S) indicates a high-risk state, trigger the warning mechanism and initiate an immediate adjustment of the access control policy, including temporarily restricting or revoking certain access permissions, monitoring and auditing measures, and other appropriate security response measures;
[0061] S425. For each policy adjustment, record the reasons for the adjustment and the implementation effects.
[0062] Optionally, the S43 specifically includes:
[0063] S431. Identify the parts of the graph model that need to be updated;
[0064] S432. By dynamically updating the edge weights A' in the graph model ij , the optimization of data access control is achieved:
[0065] A' ij = A ij ·(1 - β)+β·(A ij +η·ΔE ij )
[0066] where A ij represents the initial state during the construction of the graph model, β represents the degree of response to newly emerging threats or changing environmental conditions, η is the environmental adjustment coefficient, which quantifies the impact of environmental changes on the edge weights, and ΔE ij captures the impact of environmental factors on the edges and adjusts the structure of the graph model by quantifying this impact;
[0067] S433. By updating the node attributes X' i , the latest user behavior patterns and changes in the operating environment can be dynamically reflected:
[0068]
[0069] where X' i represents the attribute state of node i after the update of the graph model, X i represents the attribute information of node i in the initial state of the graph model, including user identity information, role permission definitions, resource access rules, etc., which form the basis of the initial data access control policy, γ represents the sensitivity to newly detected environmental changes, and ΔX i represents the change vector used to capture the dynamic adjustment requirements of node attributes, δ represents the influence of neighbor nodes on node i through the relationships between nodes, including permission propagation and behavioral similarity, N(i) represents the relationships and dependencies between neighbor nodes, and the access control relationships between users and resources and users and roles affect the node attributes, and λ ij represents the permission associations between users and roles and the access relationships between users and resources;
[0070] S434. For newly added or disappeared nodes and edges, perform addition or deletion operations;
[0071] S435. Considering the cross-model impact, that is, the update of nodes and edges may affect other associated nodes and edges, use the cascade update algorithm for necessary secondary adjustments;
[0072] S436. Re-import the updated graph model G' into the graph neural network for retraining or refinement learning.
[0073] The beneficial effects of the present invention are as follows:
[0074] The present invention makes full use of graph neural network technology, adaptive decision-making algorithms, and modern data processing methods, and details a method for optimizing data access control based on graph neural networks. The main advantages of this method include:
[0075] 1. High security: By deeply analyzing the complex relationships among users, roles, and resources, this method can accurately implement access control decisions, significantly enhancing the security of data access. The introduction of graph neural networks enables the system to capture direct and indirect dependencies, conduct real-time assessment and response to potential security risks, thereby effectively preventing unauthorized access and data leakage.
[0076] 2. Dynamic adaptability: The method of the present invention can flexibly respond to changes in the environment and requirements by real-time updating the graph model and access control policies. This dynamic adjustment mechanism enables the data access control system to not only reflect static permission settings but also adapt to real-time changes in user behavior and security environment, enhancing the adaptability and response speed of the system.
[0077] 3. Improved efficiency: Traditional access control systems often require manual rule updates, with slow response speeds and high error rates. This method automates this process, real-time processing data and relationship changes through machine learning algorithms, thereby reducing manual intervention and improving the overall efficiency and accuracy of the system.
[0078] 4. Scalability and flexibility: Since the graph neural network-based method is naturally suitable for processing complex and large-scale relational data, the present invention can be easily extended to larger user and resource networks, applicable to large-scale enterprises and cloud environments. In addition, through parameterized model settings, this method allows administrators to adjust security policies and rules according to specific requirements.
[0079] Therefore, the present invention provides a solid technical support for replacing traditional static and manual data access control methods with intelligent operations, featuring high security, high adaptability, and high efficiency, and is suitable for use in rapidly changing modern data environments. Brief Description of the Drawings
[0080] The drawings are used to provide a further understanding of the present invention and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation to the present invention. In the drawings:
[0081] Figure 1This is the overall flowchart of the data access control optimization method based on graph neural networks proposed by the present invention, showing the overall workflow of the data access control system, including steps of initializing the graph model, processing the graph model through graph neural networks, adjusting the data access control policy based on the output of the graph neural networks, and updating the graph model using an adaptive decision algorithm;
[0082] Figure 2 This is the flowchart of the analysis and processing of graph neural networks, which details how graph neural networks analyze and understand the complex relationships between entities, including the update of node feature vectors and the calculation process of edge weights;
[0083] Figure 3 This is the workflow of the adaptive decision algorithm, showing how the adaptive decision algorithm updates the graph model and access control policy in real time to ensure data access security and system adaptability. Detailed implementation manners
[0084] Now, the present invention will be further described in detail with reference to the accompanying drawings. These drawings are all simplified schematic diagrams, only illustrating the basic structure of the present invention in a schematic way, so they only show the components related to the present invention.
[0085] Refer to Figure 1 , the data access control optimization method based on graph neural networks includes the following steps:
[0086] S1. Construct a graph model, which includes multiple nodes and edges, where each node represents a data access entity, and the data access entity is a user, a role, or a resource; each edge represents the relationship between entities;
[0087] In this embodiment, S1 specifically includes:
[0088] S11. Collect metadata related to data access, including users U, roles R, resources S, and their attribute information;
[0089] S12. Define node types, including user nodes U i , role nodes R j and resource nodes S k , where i, j, and k respectively represent identifiers of different entities;
[0090] S13. Define edge types, representing access permissions and relationships between different entities, including the association between users and roles (U-R), the access permissions of roles to resources (R-S), and the permissions of users to directly access resources (U-S);
[0091] S14. Use the edge definition matrix E ij , where E is the definition matrix, and i and j represent entity nodes in the graph:
[0092] E ij = 1 indicates that there is a direct relationship between entity i and entity j;
[0093] E ij = 0 indicates that there is no direct relationship between entity i and entity j;
[0094] S15. Utilize the attribute matrix X, where X represents the attribute vector of node i, and this vector contains the key characteristics and behavioral data of the entity, and is used to capture and express the characteristic information of the node.
[0095] S2. Process the graph model through a graph neural network to analyze and learn the complex relationships between nodes, including direct and indirect dependencies;
[0096] In this embodiment, S2 specifically includes:
[0097] S21. Apply the graph neural network algorithm to process the initialized graph model, and the graph neural network algorithm updates the representation of the nodes based on the characteristics of the nodes and the relationships of the edges;
[0098] S22. Dynamically update the node feature representation through the multi-layer structure of the graph neural network, so as to be able to adapt to the changes of the user behavior pattern and the operation environment in real time:
[0099]
[0100] Among them, represents the feature vector of node i at the k-th layer. In data access control, node i is a user, and the feature vector contains the identity information of the user of the node, the permission definition of the role, and the access rules of the resource. represents the feature vector of node i at the k + 1-th layer. Through the multi-layer message passing mechanism of the graph neural network, the feature vector of each node is updated according to the information of its neighbors at each layer, so as to obtain a new feature vector at the k + 1-th layer. N(i) represents the set of neighbor nodes of node i. In the graph model, there is an access relationship between users, roles, and resources. W (k) represents the weight matrix at the k-th layer. For modeling relationships at different levels, the weight matrix can capture different levels of dependencies between users, roles, and resources. b (k) represents the bias vector at the k-th layer, which is also a trainable parameter in the graph neural network. It is added to the aggregated information for linear transformation to help the model better fit the complex access control relationship. represents the aggregation function, which is used to summarize the feature vectors of node i and all its neighbor nodes i. In data access control, the aggregation function combines the feature information of users, roles, and resources to generate a comprehensive representation; σ represents the non-linear activation function;
[0101] S23. Repeat the message passing and status update process in step S22 until the predetermined network layer number L is reached, so that the feature vectors of each node can fully capture and integrate the information from its neighbors;
[0102] S24. Evaluate the effectiveness of the learned node representations, and identify direct and indirect dependencies through the new feature vectors between nodes;
[0103] S25. Apply the identified dependencies to the adjustment of the dynamic access control policy.
[0104] S3. Based on the analysis results of the graph neural network, evaluate the changes in the node feature vectors, identify the changes in user behavior patterns and access requirements, and dynamically adjust the data access control policy;
[0105] In this embodiment, S3 specifically includes:
[0106] S31. Analyze the node feature vectors generated by the graph neural network. By identifying the metrics affected by behavior patterns, access frequencies, and other environmental factors, it will guide the adjustment of the access control policy;
[0107] S32. Set a threshold θ to evaluate whether the change in the node behavior pattern exceeds the normal range by calculating ΔH i to monitor the change in the node behavior pattern:
[0108]
[0109] where, represents the feature vector of node i at the current moment. In data access control, node i is the user, and the current feature vector reflects the latest state of the node, including quantities such as the current behavior of the user, the permission status of the role, and the access records of resources, represents the feature vector of node i at the previous moment. These feature vectors store the state information of the node at the previous time point, including the previous behavior of the user, the permission status of the role, and the access records of resources, etc.;
[0110] S33. According to the comparison result of ΔH i calculated in step S32 and θ, adjust the access control policy of node i;
[0111] S34. For the nodes that need to be adjusted, update the access control rules, including adding, reducing, and modifying access permissions;
[0112] In this embodiment, S32 specifically includes:
[0113] S32. Set a threshold θ to evaluate whether the change in the node behavior pattern exceeds the normal range by calculating ΔH i to monitor the change in the node behavior pattern:
[0114]
[0115] Among them, represents the feature vector of node i at the current moment. In data access control, node i is the user, and the current feature vector reflects the latest state of the node, including the current behavior of the user, the permission status of the role, and the access records of resources, etc. represents the feature vector of node i at the previous moment. These feature vectors store the state information of the node at the previous time point, including the previous behavior of the user, the permission status of the role, and the access records of resources, etc.
[0116] S321. Define the change metric of the node feature vector, and use the Euclidean distance to quantify the change of the node feature vector between two moments:
[0117]
[0118] Among them, ΔH i represents the change metric of the feature vector of node i, which measures the feature change of node i between two time points. The larger this value is, the more significant the state change of the node is. represents the eigenvalue of the feature vector of node i at the current time point in dimension k. This eigenvalue includes the identity information of the user, the permission definition of the role, and the access rules of resources. represents the eigenvalue of the feature vector of node i at the previous time point in dimension k. It represents the features of the node in the previous state, including previous behaviors, the permission status of the role, and the access records of resources, etc. n represents the dimension of the feature vector, that is, the number of dimensions of the node feature vector. These dimensions include user attributes, behavior data, role permissions, resource attributes, etc.
[0119] S322. By dynamically adjusting the threshold θ(t), it is possible to respond in a timely manner to **changes in user behavior patterns and operating environments:
[0120]
[0121] Among them, θ(t) represents the security sensitivity threshold at the current moment, which is used to judge whether it is necessary to adjust the data access control policy to respond to changes in user behavior patterns and operating environments. α determines the sensitivity to state changes. is the average value of the feature vector changes of all nodes in the previous time window. By monitoring to identify potential abnormal activities or behavior pattern changes in, and to achieve real-time adjustment of the security policy. θ(t - 1) is the security sensitivity threshold at the previous time point.
[0122] S323. For each node, compare the change in the feature vector ΔH i with the dynamic threshold θ(t);
[0123] S324. Record all nodes that exceed the threshold and mark them as objects that need to be reviewed or have their access rights adjusted.
[0124] S4. Monitor the status and user behavior in real time, and use an adaptive decision-making algorithm to analyze environmental changes.
[0125] In this embodiment, S4 specifically includes:
[0126] S41. Monitor data access activities and environmental changes in real time. The data captured includes user behavior, access requests, and resource status;
[0127] S42. Use an adaptive decision-making algorithm to analyze the monitored data;
[0128] S43. According to the results of the algorithm analysis, modify the graph model dynamically, including adding or deleting nodes and edges, and modifying node attributes, to reflect new relationships and access rules between entities;
[0129] S44. Update the access control policy, and formulate new access rights according to the adjusted graph model and environmental changes;
[0130] S45. Apply the updated access control policy to data access control, and provide real-time feedback on environmental changes and user requirements.
[0131] S42. Use an adaptive decision-making algorithm to analyze the monitored data;
[0132] In this embodiment, S42 specifically includes:
[0133] S421. By calculating the security score E(S) regularly or in real time, potential security threats can be monitored and managed dynamically:
[0134]
[0135] where S represents the overall state at the current moment, including the attribute information of all nodes and edges, user behavior, and resource status, N represents the total number of different risk factors considered when evaluating the security state, w i represents the relative importance of the i-th risk factor to the overall risk assessment. The larger the weight value, the more significant the impact of this risk factor on the overall security assessment, h i (S) represents the degree of influence of a specific risk factor in the current state. This evaluation function outputs a value indicating the magnitude of the influence of this risk factor;
[0136] S422. Design a dynamic update mechanism that adjusts the risk assessment model according to real-time data X ch ange , in response to newly emerging threats or changing environmental conditions:
[0137] w i (t) = w i (t - 1)·(1 - α)+α·Δx i
[0138] where α controls the adaptation speed to new information, balancing sensitivity and stability, and Δx i specifically quantifies the monitored risk changes for adjusting the assessment of the state, and w i (t) represents the impact of each risk factor on the current state, and w i (t - 1) reflects the importance of this risk factor in the previous security assessment, i dynamically reflects the impact of risk factors on security, thus reflecting the change of the state in real time;
[0139] S423. Recalculate the security score E(S) using the updated weight w i (t) and the state information;
[0140] S424. When E(S) indicates a high-risk state, trigger the warning mechanism and initiate an immediate adjustment of the access control policy, including temporarily restricting or revoking certain access permissions, monitoring and auditing measures, and other appropriate security response measures;
[0141] S425. For each policy adjustment, record the reason for the adjustment and the implemented effect.
[0142] S43. According to the algorithm analysis results, dynamically adjust the graph model by adding or deleting nodes and edges, and modifying node attributes to reflect new relationships and access rules between entities;
[0143] In this embodiment, S43 specifically includes:
[0144] S431. Identify the part of the graph model that needs to be updated;
[0145] S432. Optimize the data access control by dynamically updating the edge weight A' ij in the graph model:
[0146] A' ij = A ij ·(1 - β)+B·(A ij +η·ΔE ij )
[0147] where A ijrepresents the initial state during the construction of the graph model. β represents the degree of response to newly emerging threats or changing environmental conditions. η is the environmental adjustment coefficient, which quantifies the impact of environmental changes on the weights of the edges. ΔE ij captures the impact of environmental factors on the edges and adjusts the structure of the graph model by quantifying this impact;
[0148] S433. By updating the node attribute X′ i it can dynamically reflect the latest user behavior patterns and changes in the operating environment:
[0149]
[0150] where X′ i represents the attribute state of node i after the update of the graph model. X i represents the attribute information of node i in the initial state of the graph model, including user identity information, role permission definitions, resource access rules, etc., which form the basis of the initial data access control policy. γ represents the sensitivity to newly detected environmental changes. ΔX i represents the change vector used to capture the dynamic adjustment requirements of the node attributes. δ Neighboring nodes affect node i through the relationships between nodes, including permission propagation and behavioral similarity. N(i) The relationships and dependencies between neighboring nodes, the access control relationships between users and resources, and users and roles affect the node attributes. λ ij represents the permission association between users and roles and the access relationship between users and resources;
[0151] S434. For newly added or disappeared nodes and edges, perform addition or deletion operations;
[0152] S435. Consider cross-model impacts, that is, the update of nodes and edges may affect other associated nodes and edges, and use a cascade update algorithm for necessary secondary adjustments;
[0153] S436. Re-import the updated graph model G' into the graph neural network for retraining or refined learning.
[0154] In 2023, a large multinational technology company located in Silicon Valley, USA, faced huge challenges in data management and access control. The company has more than 10,000 employees, distributed in different offices and R & D centers around the world. The company's internal network covers a wide range of data and resources, including various sensitive information such as financial data, customer information, and R & D materials. With the expansion of the company's scale and the rapid change of business needs, the traditional data access control system has shown deficiencies.
[0155] Scenario description:
[0156] In March 2023, the company launched a new R & D project involving AI technology. The project team consists of engineers from the United States, China, and Germany. This project requires team members to share R & D materials, experimental data, and market analysis reports in real time. Since team members are distributed globally and the members and roles of each team often change as the project progresses, this requires an access control method that can flexibly respond to such demand changes.
[0157] Method application:
[0158] Using the data access control optimization method based on graph neural network provided by the present invention, a graph model including users, roles, and resources is first constructed. For example, the project manager has the highest access rights to all files in Silicon Valley, while ordinary team members in China and Germany are granted access rights to specific R & D data according to their responsibilities.
[0159] By deploying the graph neural network algorithm, the system can process and analyze complex relationship graphs. The system monitors the changes of team members and data access behaviors in real time, automatically updates the graph model, and dynamically adjusts the access rights of users according to real-time data. When new members join or old members leave the project, the system will automatically adjust the permissions to ensure that everyone can access appropriate resources.
[0160] Table 1 Comparison of data for handling permission adjustment requests (2022 vs 2023)
[0161]
[0162] Table 2 Statistics of data security incidents (2022 vs 2023)
[0163]
[0164] Referring to the above tables, in the evaluation in June 2023, compared with the same period in 2022, the efficiency of the company's data access control system in handling permission adjustment requests increased by 60%. The average processing time per request decreased from 30 minutes to 12 minutes. The number of manually processed requests decreased from an average of 500 times per month to 250 times, and the proportion of automatic processing by the system increased to 75%. The error rate decreased from 5% to 0.5%. In addition, since the implementation of this method, data-related security incidents have decreased by 80%, and data leakage incidents have almost been eliminated.
[0165] Proof of beneficial effects:
[0166] Through this graph neural network-based method, the company not only ensures the security of data but also significantly improves the operational efficiency and the system's adaptability. The internal audit report in July 2023 shows that the project team's satisfaction with the system has increased, believing that access control is more timely and accurate. The implementation of this system effectively supports the company's data security and business continuity in a rapidly changing business environment, providing solid technical support for the company's business expansion globally.
[0167] As mentioned above, it is only the preferred specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention, according to the technical solution and inventive concept of the present invention, makes equivalent replacements or changes, and all should be covered within the protection scope of the present invention.
Claims
1. A method for optimizing data access control based on graph neural network, characterized in that It includes the following steps: S1. Construct a graph model, which includes multiple nodes and edges. Each node represents a data access entity, and the data access entity is a user, a role, or a resource; each edge represents the relationship between entities; S2. Process the graph model through a graph neural network to analyze and learn the complex relationships between nodes, including direct and indirect dependencies; S3. Based on the analysis results of the graph neural network, evaluate the changes in the node feature vectors, identify the changes in user behavior patterns and access requirements, and dynamically adjust the data access control policy; S4. Real-time monitor the status and user behavior, and use an adaptive decision-making algorithm to analyze the environmental changes; The specific content of S3 includes: S31. Analyze the node feature vectors generated by the graph neural network. By identifying the indicators affected by behavior patterns, access frequencies, and other environmental factors, it will guide the adjustment of the access control policy; S32. Set a threshold value , evaluate whether the change in the node behavior pattern exceeds the normal range, and monitor the change in the node behavior pattern by calculating : ; Among them, represents the feature vector of the current time node In data access control, the node is the user. The current feature vector reflects the latest state of the node, including the current behavior of the user, the permission status of the role, and the access record of the resource. represents the feature vector of the previous time node These feature vectors store the state information of the node at the previous time point, including the previous behavior of the user, the permission status of the role, and the access record of the resource; S33. Adjust the access control policy of node based on the comparison result between and calculated in step S32; S34. For the nodes that need to be adjusted, update the access control rules, including adding, reducing, and modifying access permissions.
2. The data access control optimization method based on a graph neural network according to claim 1, wherein The specific content of S1 includes: S11. Collect metadata related to data access, including users , roles , resources and their attribute information; S12. Define node types, including user nodes , role nodes and resource nodes , where respectively represent identifiers of different entities; S13. Define the edge types, representing the access permissions and relationships between different entities, including the association between users and roles (U-R), the access permissions of roles to resources (R-S), and the permissions of users to directly access resources (U-S); S14. Use the edge definition matrix , where is the definition matrix, and j represent the entity nodes in the graph: Represents an entity There is a direct relationship with the entity There is a direct relationship between them; Represents an entity There is no direct relationship with the entity ; S15. Utilize the attribute matrix , where represents the attribute vector of node . This vector contains the key characteristics and behavioral data of the entity and is used to capture and express the characteristic information of the node.
3. The data access control optimization method based on graph neural network according to claim 1, wherein The specific content of S2 includes: S21. Apply the graph neural network algorithm to process the initialized graph model. The graph neural network algorithm updates the representation of nodes based on the characteristics of nodes and the relationships of edges; S22. Through the multi-layer structure of the graph neural network, dynamically update the node feature representation, enabling it to adapt to the changes in user behavior patterns and operating environments in real time: ; in, Indicates Layer Node The characteristic vector of, in data access control, node is a user. The feature vector contains the node’s user identity information, role permission definition, and resource access rules. Indicates Layer Node Through the multi-layer message passing mechanism of the graph neural network, the feature vector of each node is updated according to the information of its neighbors at each layer, so that The layer obtains a new feature vector, Representation Node A set of neighbor nodes. In the graph model, there is an access relationship between users, roles, and resources. Indicates The weight matrix of the layer, for modeling relationships at different levels, the weight matrix can capture the different levels of dependencies between users, roles and resources. Indicates The bias vector of the layer, which is also a trainable parameter in the graph neural network, is added to the aggregated information for linear transformation, helping the model to better fit complex access control relationships. Represents an aggregation function, used to aggregate nodes and all its neighbor nodes In data access control, the aggregation function combines the characteristic information of users, roles and resources to generate a comprehensive representation; represents a nonlinear activation function; S23. Repeat the message passing and state update processes in step S22 until the predetermined number of network layers is reached so that the feature vectors of each node can fully capture and integrate information from its neighbors; S24. Evaluate the effectiveness of the learned node representations, and identify direct and indirect dependencies through the new feature vectors between nodes; S25. Apply the identified dependencies to the adjustment of the dynamic access control policy.
4. The data access control optimization method based on graph neural network according to claim 1, characterized in that The specific content of S32 includes: S321. Define the change metric of the node feature vectors, and use the Euclidean distance to quantify the change of the node feature vectors between two moments: ; Among them, represents the change metric of the eigenvector of the node , measuring the feature change of the node between two time points. The larger this value is, the more significant the state change of the node is. represents the eigenvalue of the eigenvector of the node at the current time point in dimension . This eigenvalue includes the user's identity information, role permission definitions, and resource access rules. represents the eigenvalue of the eigenvector of the node at the previous time point in dimension . It represents the features of the node in the previous state, including previous behaviors, role permission states, and resource access records. represents the dimension of the eigenvector, that is, the number of dimensions of the node eigenvector. These dimensions include user attributes, behavior data, role permissions, and resource attributes; S322. By dynamically adjusting the threshold , it can promptly respond to changes in user behavior patterns and operating environments: ; Among them, represents the security sensitivity threshold at the current moment, and determines whether it is necessary to adjust the data access control policy to cope with changes in the user behavior pattern and the operating environment, determines the sensitivity to state changes, is the average value of the feature vector changes of all nodes in within the previous time window, and realizes real-time adjustment of the security policy by monitoring to identify potential abnormal activities or behavior pattern changes in and is the security sensitivity threshold at the previous time point; S323. For each node, compare the change in the feature vector with the dynamic threshold ; S324. Record all nodes that exceed the threshold and mark them as objects that need to be reviewed or have their access permissions adjusted.
5. The data access control optimization method based on a graph neural network according to claim 1, wherein The specific content of S4 includes: S41. Real-time monitor the data access activities and environmental changes. The captured data includes user behavior, access requests, and resource status; S42. Use an adaptive decision-making algorithm to analyze the monitored data; S43. According to the algorithm analysis results, dynamically adjust the graph model, including adding or deleting nodes and edges, and modifying node attributes, to reflect the new relationships and access rules between entities; S44. Update the access control policy, and formulate new access permissions according to the adjusted graph model and environmental changes; S45. Apply the updated access control policy to data access control, and provide real-time feedback on environmental changes and user requirements.
6. The data access control optimization method based on graph neural network according to claim 5, wherein The specific content of S42 includes: S421. By calculating the security score regularly or in real time , potential security threats can be dynamically monitored and managed: ; Among them, represents the overall state at the current moment, including the attribute information of all nodes and edges, user behavior, and resource status, represents the total number of different risk factors considered when evaluating the security state, represents the relative importance of the nth risk factor to the overall risk assessment. The larger the weight value, the more significant the impact of this risk factor in the overall security assessment. It represents the degree of impact of a specific risk factor in the current state. This evaluation function outputs a value indicating the magnitude of the impact of this risk factor; S422. Design a dynamic update mechanism that adjusts the risk assessment model according to real-time data , in response to newly emerging threats or changing environmental conditions: ; Among them, Control the adaptation speed of new information and balance sensitivity and stability, Specifically quantify the monitored risk changes for adjusting the state assessment, Represent the influence degree of each risk factor on the current state, Reflect the importance of the risk factor in the previous safety assessment, Dynamically reflect the impact of risk factors on safety, thus reflecting the changes of the state in real time; S423. Recalculate the security score using the updated weights and status information ; S424. When indicating a high-risk state, trigger the warning mechanism and initiate an immediate adjustment of the access control policy, including temporarily restricting or revoking certain access rights, monitoring and auditing measures, and other appropriate security response measures; S425. For each policy adjustment, record the reasons for the adjustment and the implementation effects.
7. A method for optimizing data access control based on a graph neural network according to claim 5, characterized in that The specific content of S43 includes: S431. Identify the parts of the graph model that need to be updated; S432. Optimize data access control by dynamically updating the edge weights in the graph model , thus achieving the optimization of data access control: ; Among them, represents the initial state during the construction of the graph model, indicates the degree of response to newly emerging threats or changing environmental conditions, is the environmental adjustment coefficient, which quantifies the impact of environmental changes on the weights of the edges, captures the impact of environmental factors on the edges and adjusts the structure of the graph model by quantifying this impact; S433. By updating node attributes , it can dynamically reflect the changes in the latest user behavior patterns and operating environments: ; Among them, represents the attribute state of the node after the graph model is updated, represents the node in the initial state of the graph model, including user identity information, role permission definition, and resource access rules, which form the basis of the initial data access control policy, represents the sensitivity to changes in newly detected environmental changes, indicates that the change vector is used to capture the dynamic adjustment requirements of node attributes, Neighboring nodes affect the node through the relationships between nodes, including permission propagation and behavioral similarity, The relationships and dependencies between neighboring nodes, as well as the access control relationships between users and resources and users and roles, affect the node attributes, represents the permission association between users and roles and the access relationship between users and resources; S434. For the newly added or disappeared nodes and edges, perform the addition or deletion operations; S435. Considering the cross-model influence, that is, the update of nodes and edges may affect other associated nodes and edges, a cascading update algorithm is used for secondary adjustment; S436. Re-import the updated graph model into the graph neural network for retraining or refined learning.
Citation Information
Patent Citations
Context sensing method and system based on weighted GraphSAGE and data access control method
CN115658979A