A method and related equipment for secure data access

By configuring hardware units for visitors to record location changes in real time and generating dynamic login passwords based on monitoring data, the problem of unauthorized data access after password theft is solved, achieving dual authentication and secure access.

CN119728293BActive Publication Date: 2025-10-28HUNAN DELTA STRATEGY INFORMATION TECH SERVICES CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510202280.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-24
Publication Date
2025-10-28
Estimated Expiration
2045-02-24

AI Technical Summary

Technical Problem

In existing technologies, once passwords are stolen, corporate data faces a high risk of unauthorized access, especially since 3D printing technology has a significant impact on facial recognition, increasing the likelihood of successful verification.

Method used

By configuring hardware units for visitors, real-time location change data is recorded, encrypted data is generated, and dual authentication is performed in conjunction with enterprise monitoring data, including verification of movement trajectory and step count, to generate a dynamic login password. The backend parses and judges the consistency of the password to verify login.

Benefits of technology

Two-factor authentication is implemented, which reduces the chance of data being accessed illegally and improves the security of data access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119728293B_ABST
    Figure CN119728293B_ABST
Patent Text Reader

Abstract

This invention discloses a data security access method and related equipment, relating to the field of data security technology. The method includes defining a natural person with assigned data access rights as an access user; configuring encryption logic for a hardware unit carried by the access user; the encryption logic includes: acquiring the access user's location change data within the enterprise; generating encrypted data one based on the location change data and preset data encryption rules; if an access login request initiated by the access user when logging into a pre-connected data server is received, performing preset location analysis based on the encrypted data one to obtain the access user's movement trajectory data one within the enterprise and time data one during location changes; combining the movement trajectory data one, time data one, and encrypted data one to obtain a dynamic login password one and sending it; and executing a decryption process when the dynamic login password one entered by the access user is received. This application effectively reduces the probability of unauthorized data access.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data security technology, and in particular to a data security access method and related equipment. Background Technology

[0002] As businesses continue to grow, meeting the need for data security compliance within an organization becomes increasingly urgent and important. Establishing appropriate identity authentication and access control mechanisms can effectively eliminate the risk of unauthorized access to a core, sensitive data within an organization.

[0003] Taking the manufacturing industry as an example, in order to prevent the leakage of companies' proprietary processes and product solutions, in addition to restricting data interaction with external networks, data access mechanisms are also established. For example, authorized personnel are required to log in using a combination of password and facial recognition before data access can be granted. However, these mechanisms have the following drawbacks:

[0004] With the advancement of technology, the probability of unauthorized access and verification has greatly increased when passwords are stolen. A typical example is the impact of 3D printing technology on facial recognition. Therefore, this application proposes a new technical solution. Summary of the Invention

[0005] To reduce the likelihood of unauthorized access to data, this application provides a data security access method and related equipment.

[0006] Firstly, this application provides a data security access method, which adopts the following technical solution:

[0007] A data security access method, comprising:

[0008] Define the natural person who is assigned data access rights as the visitor;

[0009] Configure encryption logic for the hardware units carried by visitors;

[0010] The encryption logic includes:

[0011] Obtain visitor location change data within the enterprise;

[0012] Encrypted data is generated based on location change data and preset data encryption rules;

[0013] If an access login request initiated by a visitor when logging into the pre-connected data server is received, a preset location analysis is performed based on the encrypted data to obtain the visitor's movement trajectory data within the enterprise and the time data when the location changes.

[0014] Combine the movement trajectory data 1, time data 1, and encrypted data 1 to obtain the dynamic login password and send them together;

[0015] When the system receives the dynamic login password input by the visitor, the decryption process is executed.

[0016] The decryption process includes:

[0017] Parse the dynamic login password (first), and obtain the second set of movement trajectory data and the second set of time data;

[0018] Based on the movement trajectory data 2 and time data 2, obtain the monitoring data of the corresponding location from the pre-connected enterprise monitoring system;

[0019] Based on the monitoring data, perform a preset location change analysis, and generate encrypted data II according to the analysis results and data encryption rules.

[0020] Determine if encrypted data one and encrypted data two are consistent. If they are, then the login verification is successful.

[0021] Optionally, the encryption logic further includes:

[0022] The visitor's step count 1 is obtained and sent to the pre-connected base station; wherein the base station is preset in a location area within the enterprise that is not covered by the monitoring system and the base station is data connected to the hardware unit;

[0023] Based on step one and the data encryption rules, encrypted data three is generated;

[0024] If an access login request is received from the data platform, the encrypted data three and encrypted data one will be combined to obtain the combined password one and sent together.

[0025] The decryption process also includes:

[0026] Establish a data connection with the base station;

[0027] Get the visitor's step count from the base station (step count 2);

[0028] Based on step two and the data encryption rules, encrypted data four is generated. Encrypted data four is combined with encrypted data two to obtain combined password two.

[0029] Check if the first combination password and the second combination password are the same. If they are the same, the login verification is successful.

[0030] Optionally, step two of obtaining the visitor from the base station includes:

[0031] Based on the monitoring data and the pre-uploaded layout map of each base station, determine the ID of the base station closest to the location area entered by the visitor, and obtain the visitor's step number 2 from the corresponding base station according to the ID.

[0032] Optionally, the decryption process further includes:

[0033] Obtain the power level of the hardware unit;

[0034] If the battery level is lower than the preset threshold, a charging prompt will be output and the charging process will be executed.

[0035] Secondly, this application provides a data security access system, which adopts the following technical solution:

[0036] A data security access system includes: a cloud backend, a base station located in an area not covered by the enterprise's monitoring system, and a hardware unit carried by the user. The base station is communicatively connected to the cloud backend. The cloud backend is used to load and execute a computer program of the data security access method as described in any one of claims 1-4. The hardware unit is configured with encryption logic and is connected to a communication module. The communication module includes an RFID tag and a radio frequency reader / writer. The RFID tag is built into the hardware unit, and the radio frequency reader / writer is deployed in an area not covered by the enterprise's monitoring system and wirelessly connected to the base station.

[0037] Optionally, the hardware unit includes a housing and a control motherboard, a positioning module, a step counting module, a battery module, and a charging module integrated within the housing. The control motherboard is connected to the positioning module, the step counting module, the battery module, and the charging module. The positioning module is used to acquire data on the visitor's location changes within the enterprise. The step counting module is used to acquire the visitor's step count. The battery module is used to supply power to the control motherboard, and the charging module is used to charge the battery module.

[0038] Thirdly, this application provides a computer device, which adopts the following technical solution:

[0039] A computer device includes a memory and a processor, the memory storing a computer program that can be loaded by the processor and executed to implement the data secure access method as described in any of the preceding claims.

[0040] Fourthly, this application provides a computer-readable storage medium, which adopts the following technical solution:

[0041] A computer-readable storage medium having a computer program stored thereon, the computer program being executed by a processor to implement the data secure access method as described in any of the preceding claims.

[0042] In summary, this application includes the following beneficial technical effects: By utilizing a hardware unit to record the visitor's movement within the enterprise in real time, corresponding encrypted data 1 is generated and awaits retrieval. When the visitor connects the hardware unit to the server to log in, the encrypted data 1 is analyzed, and the visitor's movement trajectory and time within the enterprise are added to generate a dynamic login password 1. When the visitor logs in, they enter the aforementioned dynamic login password 1. The backend parses the dynamic login password 1 and retrieves the monitoring data corresponding to the visitor's trajectory. By viewing the actual situation reflected in the monitoring, not only can the visitor's face be recognized and verified, but the actual location changes of the visitor can also be reflected from the monitoring data, corresponding to the generation of a set of encrypted data. By comparing the encrypted data generated by the hardware unit carried by the visitor (the visitor's location change) with the encrypted data reflected by the monitoring data (the visitor's location change), it is determined whether the access is secure, thus achieving dual authentication and reducing the probability of unauthorized data access. Attached Figure Description

[0043] Figure 1 This is a flowchart of the method described in this application.

[0044] Figure 2 This is a schematic diagram of the system architecture of this application. Detailed Implementation

[0045] The following is combined with Figure 1-2 This application is described in further detail.

[0046] This application discloses a method for secure data access.

[0047] Reference Figure 1 Data security access methods include:

[0048] S1. Define the natural person who is assigned data access rights as the visitor;

[0049] S2. Configure encryption logic for the hardware unit carried by the visitor;

[0050] In this embodiment, the hardware unit can be a miniaturized structure, making it easy for users to carry. It is also equipped with a data interface (such as a USB interface). Data connection is achieved by plugging the data interface of the hardware unit into the interface of the server carrying the data content to be accessed. Other hardware structures inside the hardware unit will be described in detail later.

[0051] Regarding the encryption logic, it includes:

[0052] 1) Obtain data on visitor location changes within the enterprise;

[0053] In this embodiment, the hardware unit includes a housing and a control motherboard, a positioning module, and a battery module integrated within the housing. The control motherboard is connected to the positioning module and the battery module. The positioning module is used to acquire location change data of the visitor within the enterprise, and the battery module is used to power the control motherboard. The positioning module can use WIFI positioning technology. For example, a WIFI router is set up inside the enterprise. When the hardware unit carried by the visitor connects to the enterprise's WIFI, the router determines the location based on the signal strength to acquire location change data of the visitor's movement within the enterprise. The location change data includes the locations where the visitor has stayed within the enterprise and the time of the location change. Therefore, it is also necessary to record the timestamp of each location change. For example, when the visitor moves from the office to the meeting room, the time when the visitor leaves the office and the time when the visitor arrives at the meeting room are recorded.

[0054] 2) Generate encrypted data one based on location change data and preset data encryption rules;

[0055] In this embodiment, the data encryption rules are exemplified as follows: Each location area within the enterprise is assigned a unique binary code, forming a location code table stored in the database. For example, the office code is 01, the meeting room code is 10, the rest area code is 11, etc. Time is converted into binary code, and the codes corresponding to the location areas visited by the visitor are combined according to the timestamp. For example, if the visitor enters the office at 8:00, enters the meeting room at 8:30, and enters the rest area at 9:10, the generated binary sequence number (encrypted data one) is "011011".

[0056] 3) If an access login request is received from a visitor when logging into the pre-connected data server, a preset location analysis is performed based on the encrypted data to obtain the visitor's movement trajectory data within the enterprise and the time data when the location changes.

[0057] Understandably, when a visitor inserts the hardware unit into the server's data interface and logs into the server they wish to access, the server sends an access login request to the hardware unit. It then reads encrypted data one and performs location analysis on it. Based on the binary encoding table for each location area within the enterprise, it deciphers encrypted data one (binary sequence) to obtain the visitor's location within the enterprise. Then, it converts the location according to a location conversion table stored in the database beforehand. In this embodiment, the location conversion table is: Office #2, Meeting Room #3, Rest Area #4.

[0058] Location analysis example: If the encrypted data is "011110", then according to the location encoding table stored in the database, the visitor's movement trajectory data is: office - rest area - meeting room. Then, according to the location conversion table, the movement trajectory data is "#2#4#3". By calling the monitoring data of the above three locations, the time corresponding to entering and leaving the above locations can be obtained. For example, if the visitor enters the office at 8:00, enters the rest area at 8:30, and enters the meeting room at 9:00, the time data is "8:00 8:30 9:00".

[0059] 4) Combine the movement trajectory data 1, time data 1, and encrypted data 1 to obtain the dynamic login password and send them together.

[0060] In this embodiment, for example: if the first behavioral trajectory data is "#2#4#3", the first time data is "8:008:309:00", and the first encrypted data is "011011", the first dynamic login password obtained by combining them is "#2#4#38:008:309:00011011". The first dynamic login password can be sent by displaying it on the screen pre-installed on the hardware unit, allowing the visitor to view the password on the screen, or by storing the visitor's mobile phone number corresponding to the hardware unit in the database and sending it directly to the visitor's mobile phone. The visitor uses the first dynamic login password to log in and verify during data access.

[0061] S3. When the dynamic login password 1 entered by the visitor is received, the decryption process is executed;

[0062] The decryption process includes:

[0063] 1) Parse the dynamic login password to obtain the second set of movement trajectory data and the second set of time data;

[0064] It is understandable that, based on the location conversion table above, the location where the visitor stayed within the enterprise (movement trajectory data two) and the corresponding time (time data two) can be obtained.

[0065] 2) Based on the movement trajectory data 2 and time data 2, obtain the monitoring data of the corresponding location from the pre-connected enterprise monitoring system;

[0066] Understandably, the corresponding monitoring data is retrieved based on the location where the visitor stayed within the enterprise (movement trajectory data 2) and the corresponding time (time data 2).

[0067] 3) Perform a preset location change analysis based on the monitoring data, and generate encrypted data II according to the analysis results and data encryption rules;

[0068] Understandably, based on the facial recognition processing and analysis of the monitoring data, it is important to note that the database pre-stores the visitor's basic information, including face, name, gender, job responsibilities, and data access permissions. This not only allows for facial verification by calling the monitoring data but also for tracking the visitor's movement, recording the visitor's actual location within the company and the corresponding time spent there. Furthermore, according to the aforementioned data encryption rules, the actual location is converted into a binary sequence number (encrypted data two).

[0069] 4) Determine if encrypted data one and encrypted data two are consistent. If they are, then the login verification is successful.

[0070] In this embodiment, if encrypted data one is consistent with encrypted data two, then the secure access login verification is considered successful.

[0071] With the above setup, hardware units record visitors' movements within the enterprise in real time, generating encrypted data (data 1) which is then ready for retrieval. When a visitor connects the hardware unit to the server to log in, the encrypted data (data 1) is analyzed, and the visitor's movement trajectory and time within the enterprise are added to generate a dynamic login password (data 1). The visitor enters this dynamic login password (data 1) upon login. The backend parses this password and retrieves the monitoring data corresponding to the visitor's trajectory. By reviewing the monitoring data, not only can the visitor's face be recognized and verified, but the actual location changes reflected in the monitoring data are also analyzed, generating a set of encrypted data. By comparing the encrypted data generated by the visitor's portable hardware unit (reflecting location changes) with the encrypted data reflected in the monitoring data (reflecting location changes), a secure access is determined, achieving dual authentication and reducing the likelihood of unauthorized data access.

[0072] In another embodiment of this application, since the decryption method involves accessing monitoring data to view the visitor's actual location changes, and considering that there may be areas within the enterprise where monitoring cannot be installed, base stations are set up in each of these unmonitored areas for data transmission. The hardware unit can count the visitor's steps and transmit the count to the base station closest to the visitor (the specific method will be explained later). Therefore, based on the above, the following is also included: Regarding the encryption logic, it further includes:

[0073] 1) Obtain the visitor's step count 1 and send step count 1 to the pre-connected base station;

[0074] Understandably, the hardware unit also includes a step counting module integrated within the package housing. This step counting module is connected to the control motherboard. In this embodiment, the step counting module can analyze the acceleration changes caused by the swinging of the body or arms during walking, captured by an accelerometer, to calculate the number of steps taken by the visitor. To transmit the step count to the base station, the hardware unit is also connected to a communication module, which may employ radio frequency technology; details will be described in subsequent system descriptions.

[0075] 2) Generate encrypted data three based on step one and the data encryption rules;

[0076] Understandably, the data encryption rules also include converting the number of steps (decimal) into binary numbers to obtain encrypted data.

[0077] 3) If an access login request is received from the data platform, the encrypted data three and encrypted data one will be combined to obtain the combined password one and sent together;

[0078] It is understandable that when a visitor logs in, for example: encrypted data three is 10100011, encrypted data one is 011011, and the combined password one is 10100011#011011. In this embodiment, the combination of encrypted data three and encrypted data one can be separated by adding a # symbol between the two data. In other embodiments, other symbols can also be used for separation.

[0079] With the above settings, step count verification is added on top of monitoring, so that step count can be verified in areas that cannot be covered by the monitoring system.

[0080] When a visitor logs in and enters the combined password into the data server they wish to access, the background process executes a decryption procedure, which includes:

[0081] 1) Establish a data connection with the base station;

[0082] 2) Obtain the visitor's step count from the base station;

[0083] In this embodiment, to ensure more stable, faster, and more accurate data transmission between the hardware unit and the base station, a base station is set up in each independent area not covered by the monitoring system. If a visitor enters an independent room not covered by the monitoring system, and there are other independent rooms nearby that are also not covered by the monitoring system, which base station's step count data will be more accurate? Specifically, the details are as follows:

[0084] Based on the monitoring data and the pre-uploaded layout map of each base station, determine the ID of the base station closest to the location area entered by the visitor, and obtain the visitor's step number 2 from the corresponding base station according to the ID.

[0085] Understandably, the base station layout map is stored in the database. It can be a map showing the location distribution of each base station within the enterprise, and each base station is bound to a unique ID. By calling the monitoring data, the location corresponding to the last screen of the visitor in the monitoring is determined. Based on the location, the base station layout map is searched to find the ID of the base station closest to that location. Based on the ID, the visitor's step count is obtained from the corresponding base station.

[0086] 3) Generate encrypted data four based on step two and the data encryption rules, and combine encrypted data four with encrypted data two to obtain combined password two;

[0087] It is understandable that the data obtained from the base station step two will be encrypted to obtain encrypted data four. The data encryption rules are the same as those mentioned above, and step two will be converted into binary numbers.

[0088] 4) Determine if the first combination password and the second combination password are the same. If they are, the login verification is successful.

[0089] The above settings not only involve analyzing monitoring data but also verifying the visitor's step count, thereby improving the security of data access.

[0090] In another embodiment of this application, the decryption process further includes:

[0091] Obtain the power level of the hardware unit;

[0092] In this embodiment, when the hardware unit is inserted into the server's data interface, the battery module of the hardware unit is tested for power.

[0093] If the battery level is lower than the preset threshold, a charging prompt will be output and the charging process will be executed.

[0094] Understandably, the hardware unit also includes a charging module connected to the control motherboard. This charging module charges the battery module. When the battery level drops below 20% of the total capacity, a charging prompt is output. This prompt can be a pop-up window indicating that the hardware unit should not be disconnected and that charging is required. The charging process involves determining the voltage and current through the interface to charge the battery module. When charging is complete, this can be indicated by displaying "Charging Complete" on a pre-set screen on the hardware unit, or by a flashing green indicator light.

[0095] This application also discloses a data security access system.

[0096] Reference Figure 2 The data security access system includes: a cloud backend, a base station located in an area not covered by the enterprise's monitoring system, and a hardware unit carried by the user. The base station is wirelessly connected to the cloud backend. The cloud backend is used to load and execute a computer program of any of the data security access methods described above. The hardware unit is configured with encryption logic and is connected to a communication module. The communication module includes an RFID tag and a radio frequency reader. The RFID tag is built into the hardware unit, and the radio frequency reader is placed at the entrance and exit of the area not covered by the enterprise's monitoring system and is wired to the base station.

[0097] With the above setup, when a visitor's personal hardware unit enters a room not covered by the monitoring system, the radio frequency reader reads the information from the RFID tag, establishes a data connection, and thus obtains the hardware unit's location data and step count data.

[0098] The hardware unit includes a housing and a control motherboard, a positioning module, a step counting module, a battery module, and a charging module integrated within the housing. The control motherboard is connected to the positioning module, the step counting module, the battery module, and the charging module. The positioning module is used to acquire data on the visitor's location changes within the enterprise. The step counting module is used to acquire the visitor's step count. The battery module is used to supply power to the control motherboard, and the charging module is used to charge the battery module.

[0099] This application also discloses a computer device, including a memory and a processor, wherein the memory stores a computer program that can be loaded and executed by the processor to implement the data security access method as described in any of the above-described embodiments.

[0100] This application also discloses a computer-readable storage medium storing a computer program thereon, which is executed by a processor to implement the data security access method as described in any of the above embodiments.

[0101] The above are all preferred embodiments of the present application, and are not intended to limit the scope of protection of the present application. Therefore, any equivalent changes made based on the structure, shape, and principle of the present application should be included in the scope of protection of the present application.

Claims

1. A method for secure data access, characterized in that, include: Define the natural person who is assigned data access rights as the visitor; Configure encryption logic for the hardware units carried by visitors; The encryption logic includes: Obtain visitor location change data within the enterprise; Encrypted data is generated based on location change data and preset data encryption rules; If an access login request initiated by a visitor when logging into the pre-connected data server is received, a preset location analysis is performed based on the encrypted data to obtain the visitor's movement trajectory data within the enterprise and the time data when the location changes. Combine the movement trajectory data 1, time data 1, and encrypted data 1 to obtain the dynamic login password and send them together; When the system receives the dynamic login password input by the visitor, the decryption process is executed. The decryption process includes: Parse the dynamic login password (first), and obtain the second set of movement trajectory data and the second set of time data; Based on the movement trajectory data 2 and time data 2, obtain the monitoring data of the corresponding location from the pre-connected enterprise monitoring system; Based on the monitoring data, perform a preset location change analysis, and generate encrypted data II according to the analysis results and data encryption rules. Determine if encrypted data one and encrypted data two are consistent; if they are, then the login verification is successful. The encryption logic further includes: obtaining the visitor's step count 1 and sending step count 1 to the pre-connected base station; wherein the base station is preset in a location area within the enterprise that is not covered by the monitoring system and the base station is data connected to the hardware unit; Based on step one and the data encryption rules, encrypted data three is generated; If an access login request is received from the data platform, the encrypted data three and encrypted data one will be combined to obtain the combined password one and sent together. The decryption process also includes: Establish a data connection with the base station; Get the visitor's step count from the base station (step count 2); Based on step two and the data encryption rules, encrypted data four is generated. Encrypted data four is combined with encrypted data two to obtain combined password two. Determine whether the first combination password and the second combination password are the same; if so, the login verification is successful. The second step, obtaining the visitor's number from the base station, includes: Based on the monitoring data and the pre-uploaded layout map of each base station, determine the ID of the base station closest to the location area entered by the visitor, and obtain the visitor's step number 2 from the corresponding base station according to the ID.

2. The data security access method according to claim 1, characterized in that, The decryption process also includes: Obtain the power level of the hardware unit; If the battery level is lower than the preset threshold, a charging prompt will be output and the charging process will be executed.

3. A data security access system, characterized in that, include: The system comprises a cloud-based backend, a base station located in an area not covered by the enterprise's monitoring system, and a hardware unit carried by the visitor. The base station is communicatively connected to the cloud-based backend. The cloud-based backend is used to load and execute a computer program for the data security access method as described in any one of claims 1-2. The hardware unit is configured with encryption logic and is connected to a communication module. The communication module includes an RFID tag and a radio frequency reader / writer. The RFID tag is built into the hardware unit, and the radio frequency reader / writer is deployed in an area not covered by the enterprise's monitoring system and wirelessly connected to the base station.

4. The data security access system according to claim 3, characterized in that, The hardware unit includes a housing and a control motherboard, a positioning module, a step counting module, a battery module, and a charging module integrated within the housing. The control motherboard is connected to the positioning module, the step counting module, the battery module, and the charging module. The positioning module is used to acquire data on the visitor's location changes within the enterprise. The step counting module is used to acquire the visitor's step count. The battery module is used to supply power to the control motherboard, and the charging module is used to charge the battery module.

5. A computer device, characterized in that: It includes a memory and a processor, wherein the memory stores a computer program that can be loaded and executed by the processor to implement the data security access method as described in any one of claims 1-2.

6. A computer-readable storage medium, characterized in that: It stores a computer program, which is executed by a processor to implement the data security access method as described in any one of claims 1-2.

Citation Information

Patent Citations

  • Access control method, information display device using the same, and information display system

    CN103034816A

  • Server login method, terminal and server

    CN105246042A

  • Authentication system, authentication requesting device, verification device and service medium

    JP2002149611A