A rights control system and a rights control method

By using spatiotemporal data mining and intelligent analysis in the access control system, network access permissions can be adjusted in real time, solving the problems of high cost and low compatibility of zero-trust networks and achieving improvements in security and scalability.

CN119814366BActive Publication Date: 2025-11-04CHINA TELECOM CLOUD TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411776814.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-05
Publication Date
2025-11-04
Estimated Expiration
2044-12-05

AI Technical Summary

Technical Problem

Zero-trust networks are costly to implement, have low compatibility, and suffer from compatibility issues when multiple security protocols and routing technologies work together.

Method used

An access control system is adopted, including a data analysis server, a control management server, an identity authentication server, and a network resource server. Through spatiotemporal data mining and intelligent analysis, network access permissions are adjusted in real time. Combined with identity authentication and network resource management, precise access control is achieved.

Benefits of technology

It effectively reduces the implementation cost of zero-trust networks, improves network security and scalability, enhances the ability to monitor and protect against potential threats, and ensures the accuracy of the authentication process and the rational use of network resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119814366B_ABST
    Figure CN119814366B_ABST
Patent Text Reader

Abstract

The application provides a permission control system and method, relates to the technical field of communication, and comprises a data analysis server, which is used for analyzing space-time data, processing network events and network threats, monitoring abnormal activities in the network, generating monitoring results, and sending the monitoring results to a control management server. The control management server is used for adjusting network access permissions in real time according to the monitoring results. An identity authentication server is used for performing identity authentication on user terminals according to the network access permissions, and providing the network resource server with the identity of the user terminal that passes the identity authentication. The network resource server is used for providing network resources to the user terminal that passes the identity authentication according to the identity of the user terminal that passes the identity authentication provided by the identity authentication server. The problems of high implementation cost and low compatibility of the zero-trust network in the prior art are solved, and the technical effect of realizing permission control under the condition of low implementation cost is realized.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of communication, in particular to a permission control system and a permission control method. BACKGROUND

[0002] Zero Trust Network is a new network security architecture that abandons the traditional border-based security strategy, that is, the practice of defaulting to trust internal networks and users, and requires strict verification and authorization for each access request.

[0003] The present application inventors found that the above-mentioned technology at least has the following technical problems in the process of implementing the technical scheme of the embodiments of the present application:

[0004] Zero Trust Network requires enterprises to not only determine whether to trust a user, host or application that requests to access specific enterprise resources based on traditional identity verification methods, but also to make decisions based on a series of more complex conditions. In order to achieve this goal, micro-segmentation technology is needed to define network boundaries at a more granular level and develop corresponding access control rules. In addition, the Zero Trust Network model also relies on multiple security protocols and routing technologies to work together. Micro-segmentation technology increases the complexity of network architecture and the difficulty of developing security policies, resulting in higher implementation costs, and compatibility issues exist when multiple security protocols and routing technologies work together. SUMMARY

[0005] The present application provides a permission control system and method to solve the problem of high implementation cost and low compatibility of Zero Trust Network.

[0006] In a first aspect, the present application provides a permission control system, comprising: a data analysis server, a control management server, an identity authentication server, and a network resource server.

[0007] The data analysis server is configured to analyze spatiotemporal data, process network events and network threats, and monitor abnormal activities in the network, generate monitoring results, and send the monitoring results to the control management server. The spatiotemporal data refers to data related to network traffic and user behavior.

[0008] The control management server is configured to adjust network access permissions in real time according to the monitoring results.

[0009] The identity authentication server is configured to perform identity authentication on user terminals according to the network access permissions, and provide the network resource server with the identity of the user terminals that pass the identity authentication.

[0010] The network resource server is configured to provide network resources including application programs and network data to the user terminal that passes the identity authentication according to the identity of the user terminal that passes the identity authentication provided by the identity authentication server.

[0011] In some embodiments, the data analysis server comprises a spatio-temporal data mining module configured to:

[0012] analyze the spatio-temporal data to establish a behavior benchmark model and a security behavior baseline, wherein the behavior benchmark model is configured to represent common geographic locations, network environments, terminal devices, operation times, commonly used applications and usage habits of the user, and the security behavior baseline refers to the commonality of behaviors of users with the same attributes;

[0013] determine normal behavior patterns and abnormal behavior patterns based on the behavior benchmark model and the security behavior baseline;

[0014] analyze the spatio-temporal data to determine spatio-temporal correlation patterns, wherein the spatio-temporal correlation patterns are configured to represent the correlation of behaviors at different times and spaces;

[0015] generate a behavior analysis result based on the normal behavior patterns, the abnormal behavior patterns and the spatio-temporal correlation patterns.

[0016] In some embodiments, the data analysis server further comprises a user behavior analysis module configured to:

[0017] analyze user behavior patterns based on the behavior analysis result, wherein the user behavior patterns are configured to monitor abnormal activities, trends and correlations in the network;

[0018] identify the identity and behavior characteristics of the user, predict the behavior of the user, determine potential abnormal behaviors and attack behaviors, and generate the monitoring result based on the user behavior patterns.

[0019] In some embodiments, the control management server comprises a network control management module configured to:

[0020] formulate a permission control strategy based on the monitoring result;

[0021] adjust the network access permission based on the permission control strategy.

[0022] In some embodiments, the control management server further comprises a network attack detection and prevention module configured to:

[0023] monitor the spatio-temporal data;

[0024] analyze the spatio-temporal data to determine whether there is abnormal behavior or attack behavior;

[0025] when the abnormal behavior or the attack behavior exists, performing network resource micro-segregation according to the abnormal behavior or the attack behavior.

[0026] In some embodiments, the data analysis server further comprises a data collection module, configured to:

[0027] collecting user behavior data through a sensing device, wherein the user behavior data comprises geographic location, spatial movement information, surrounding information and temperature information, and collecting network traffic data, wherein the network traffic data comprises traffic data, threat intelligence, device status information and operation logs;

[0028] obtaining raw data according to the user behavior data and the network traffic data.

[0029] In some embodiments, the data analysis server further comprises a data preprocessing module, configured to:

[0030] scanning the raw data to remove redundant information, irrelevant information and obvious errors in the raw data, to obtain preliminary cleaning data;

[0031] identifying noise and outliers in the preliminary cleaning data, and removing the noise and the outliers to obtain purified data;

[0032] unifying conversion of the purified data according to a preset standard format to obtain standard format data, wherein the preset standard format comprises data type, encoding format and date format;

[0033] cleaning invalid records and obvious errors in the standard format data to obtain valid data;

[0034] performing normalization and standardization processing on the valid data according to a preset standard to obtain the spatio-temporal data, wherein the preset standard refers to rules or parameters used to guide data conversion;

[0035] integrating the spatio-temporal data to construct a spatio-temporal data set.

[0036] In a second aspect, the application provides a permission control method applied to a permission control system, comprising the following steps:

[0037] The data analysis server analyzes the spatio-temporal data, processes network events and network threats, and monitors abnormal activities in the network to generate the monitoring result and send it to the control management server, wherein the spatio-temporal data refers to data related to network traffic and user behavior.

[0038] The control management server adjusts the network access permission in real time according to the monitoring result;

[0039] The identity authentication server performs identity authentication on the user terminal according to the network access permission, and provides an identity of the user terminal passing the identity authentication to the network resource server;

[0040] The network resource server provides network resources to the user terminal passing the identity authentication according to the identity of the user terminal passing the identity authentication provided by the identity authentication server, the network resources including application programs and network data.

[0041] In some embodiments, the data analysis server analyzes the spatio-temporal data, processes network events and network threats, and monitors abnormal activities in the network, generates a monitoring result, and sends the monitoring result to the control management server, including the following steps:

[0042] The spatio-temporal data is analyzed to establish a behavior benchmark model and a security behavior baseline, the behavior benchmark model being used to represent common geographic locations, network environments, terminal devices, operation times, commonly used applications, and usage habits of users, and the security behavior baseline being a commonality of behaviors of users with the same attributes;

[0043] Normal behavior patterns and abnormal behavior patterns are determined through the behavior benchmark model and the security behavior baseline;

[0044] The spatio-temporal data is analyzed to determine spatio-temporal correlation patterns, the spatio-temporal correlation patterns being used to represent behavior correlation at different times and spaces;

[0045] Behavior analysis results are generated according to the normal behavior patterns, the abnormal behavior patterns, and the spatio-temporal correlation patterns.

[0046] In some embodiments, after the behavior analysis results are generated according to the normal behavior patterns, the abnormal behavior patterns, and the spatio-temporal correlation patterns, the following steps are further included:

[0047] User behavior patterns are analyzed according to the behavior analysis results, the user behavior patterns being used to monitor abnormal activities, trends, and correlations in the network;

[0048] The identities and behavior characteristics of the users are identified, behaviors of the users are predicted, potential abnormal behaviors and attack behaviors are determined, and the monitoring result is generated through the user behavior patterns.

[0049] Compared with the prior art, the present application has the following advantages:

[0050] The data analysis server comprehensively reflects the security situation of the network, and timely sends to the control management server to support the permission control, the control management server responds to the monitoring result sent by the data analysis server, adjusts the network access permission in real time, effectively prevents potential security threats, enhances the overall security of the network, the identity authentication server carries out identity authentication on the user terminal according to the network access permission set by the control management server, ensures the accuracy and security of the authentication process, and the network resource server provides network resources for the user terminal whose identity authentication is passed according to the user identifier transmitted by the user authentication server, and ensures the rational use of network resources. The problems of high implementation cost and low compatibility of the zero trust network in the prior art are solved, and the technical effect of realizing permission control under the condition of low implementation cost is realized. BRIEF DESCRIPTION OF DRAWINGS

[0051] Figure 1 is a structural schematic diagram of a permission control system provided by at least one embodiment of the present application;

[0052] Figure 2 is an architecture diagram of a permission control system provided by at least one embodiment of the present application;

[0053] Figure 3 is a structural schematic diagram of a data analysis server provided by at least one embodiment of the present application;

[0054] Figure 4 is a structural schematic diagram of a control management server provided by at least one embodiment of the present application;

[0055] Figure 5 is a structural schematic diagram of a data analysis server provided by at least one embodiment of the present application;

[0056] Figure 6 is a method flowchart of permission control provided by at least one embodiment of the present application;

[0057] Figure 7 is a method flowchart of generating a monitoring result provided by at least one embodiment of the present application. DETAILED DESCRIPTION

[0058] In order to make the above-mentioned purposes, features and advantages of the present application more obvious and easy to understand, the present application will be further described in detail below in combination with the drawings and specific embodiments.

[0059] Before the embodiments of the present application are described in detail, the background art related to the present application is briefly introduced.

[0060] Zero-trust network is an advanced security architecture with high application value and potential. The core idea of zero-trust network is not to trust any external or internal users or devices, but to verify all people, things and objects that try to access the system before authorization. This network model breaks the traditional boundary protection thinking and focuses on the security of resources themselves, and deploys security around the entire life cycle of resources.

[0061] Zero-trust network is mainly composed of identity and access management, terminal device environment risk assessment, attribute-based access control model, and machine learning-based identity analysis technology. These technology components cooperate with each other to achieve the verification and authorization of users and devices. However, there are some practical problems and shortcomings in the use of zero-trust network.

[0062] Firstly, zero-trust network requires enterprises to determine whether to trust users / hosts / applications requesting access to specific ranges of the enterprise based on user, user location, and other data conditions, using micro-isolation and fine-grained boundary rules. This requires the enterprise to re-plan the network architecture and security strategy, increasing the complexity and cost of implementation.

[0063] Secondly, zero-trust network requires the use of multiple security protocols and routing technologies, but there is a lack of effective integration management between these protocols and technologies. Although IAM can be used for the network, it is not used to determine how data packets are routed, which increases the complexity and management difficulty of the network.

[0064] In addition, zero-trust network currently lacks unified standards and specifications, and there are certain compatibility issues between products and services from different manufacturers. At the same time, zero-trust network requires a large amount of computing and storage resources, as well as real-time monitoring and analysis of network traffic, which may have some impact on network performance.

[0065] The following are some technical keywords related to this application:

[0066] Spatiotemporal artificial intelligence: A machine learning technology that combines time and space data to analyze and understand spatial and temporal patterns in data.

[0067] Zero-trust network: A network security model that emphasizes the principle of "don't trust, verify everything", which emphasizes identity verification and permission control in all network access.

[0068] Spatiotemporal data mining: A process of extracting valuable information and knowledge from spatiotemporal data, including pattern recognition, association rule mining, etc.

[0069] Data prediction: A process of predicting and analyzing future trends and results using existing data and models. Data prediction can help businesses and individuals make more informed decisions, improve decision-making accuracy and efficiency.

[0070] User behavior analysis: Through in-depth analysis of user behavior data, understanding user needs and behavior patterns to provide personalized services and products.

[0071] Authentication: A process of verifying and confirming the identity of a user to ensure that the user is legitimate and authorized. Authentication is an important part of network security, which can prevent unauthorized users from accessing sensitive data and resources. Common authentication methods include username and password, digital certificate, biometric identification, etc.

[0072] Access control: A mechanism for managing and controlling user or system access to network resources, data or services. Access control can ensure that only authorized users or systems can access specific resources or services, preventing unauthorized access and potential security threats. Common access control methods include role-based access control (RBAC), attribute-based access control (ABAC), etc.

[0073] Network attack detection and prevention: A process of monitoring network traffic and user behavior to detect and prevent various network attacks in a timely manner.

[0074] Edge computing: A technology that distributes computing tasks to devices closer to data sources for processing to reduce network latency and improve response speed.

[0075] The embodiments of the present application have at least the following advantages:

[0076] 1. Higher security: Zero-trust network architecture is a more secure model because it assumes that no one is trustworthy. This model can prevent the exploitation of internal and external threats and reduce the attack surface that attackers can exploit. And the present invention can further enhance the security of zero-trust networks by integrating spatiotemporal artificial intelligence. For example, by analyzing spatiotemporal data and network behavior data of users, it can more accurately identify abnormal behavior and potential attack behavior, and take appropriate protective measures in a timely manner to prevent data leakage and attacks.

[0077] 2. Better scalability and flexibility: Since zero-trust network architecture does not rely on fixed boundaries and trust models, it has better scalability and flexibility. This means it can adapt to different network environments and business needs, and can be expanded as the business grows. And the present invention can further enhance the scalability and flexibility of zero-trust networks by integrating spatiotemporal artificial intelligence. For example, through automated decision support systems, intelligent authorization and management can be performed according to user behavior patterns, enabling more flexible network management and operation.

[0078] 3. Better visibility and control: Zero-trust network architecture provides better visibility and control because all devices, users and applications must be verified and authenticated. This allows businesses to better monitor and control data flow on the network and identify and respond to any threats in a timely manner. And the present invention can further enhance the visibility and control capabilities of zero-trust networks by integrating spatiotemporal artificial intelligence. For example, by analyzing spatiotemporal data and network traffic data, a more comprehensive monitoring of network environment and user behavior can be achieved, and abnormal behavior and potential attack behavior can be discovered in a timely manner, and appropriate protective measures can be taken.

[0079] 4. Stronger automation and intelligence: By integrating spatiotemporal artificial intelligence technology, the present invention can achieve stronger automation and intelligence. For example, through automated decision support systems, intelligent authorization and management can be performed according to user behavior patterns, enabling more flexible network management and operation. At the same time, through machine learning and deep learning technologies, more accurate user behavior analysis and prediction can be achieved, improving network security and stability.

[0080] 5. Promote innovation and industrial synergy: The present invention can promote the innovation and development of related technologies and drive progress in the entire technical field. At the same time, by integrating spatiotemporal artificial intelligence technology, more extensive data collection and analysis can be achieved, promoting cooperation and synergy between different manufacturers and different industries, and driving the development and innovation of the industry.

[0081] Example 1

[0082] Reference Figure 1The embodiments of the present application provide a permission control system, comprising a data analysis server 10, a control management server 20, an identity authentication server 30 and a network resource server 40.

[0083] The data analysis server 10 is configured to analyze space-time data, process network events and network threats, and monitor abnormal activities in the network, generate monitoring results, and send the monitoring results to the control management server 20. The space-time data refers to data about network traffic and user behavior.

[0084] Specifically, the network traffic data comprises traffic data, threat intelligence, device status information and operation logs, and the user behavior data comprises geographic location information, spatial movement information, surrounding information and temperature information. The network threat refers to a time that threatens network security, and the abnormal activity in the network refers to an activity deviating from normal network behavior. The data analysis server 10 uses data mining technology and deep learning algorithms to deeply integrate, analyze and mine space-time data and network security intelligence, comprehensively understand network events and threats, monitor abnormal activities in the network, and provide support for intelligent decision-making. Exemplarily, the data mining technology refers to a frequent pattern mining algorithm including an Apriori algorithm and an FP tree algorithm, and the deep learning algorithm refers to a convolutional neural network or a recurrent neural network.

[0085] The control management server 20 is configured to adjust network access permissions in real time according to the monitoring results.

[0086] Specifically, the control management server 20 continuously monitors network security and the data analysis server 10, establishes a dynamic connection between the control management server 20 and the network resource server 40, uses space-time data and intelligent analysis results, and automatically formulates decisions to adjust network permissions and access control in real time, so as to ensure the security and stability of the network. The intelligent analysis result refers to a result obtained by analyzing space-time data, and the automatic decision-making refers to a network access permission adjustment strategy formulated according to the monitoring results. Exemplarily, the data analysis server 10 further comprises a real-time threat detection system configured to monitor abnormal activities in the network and establish real-time communication with the real-time threat detection system.

[0087] The identity authentication server 30 is configured to perform identity authentication on a user terminal according to network access permissions, and provide an identity of a user terminal passing the identity authentication to the network resource server 40.

[0088] The network resource server 40 is configured to provide network resources to the user terminal passing the identity authentication according to the identity of the user terminal passing the identity authentication provided by the identity authentication server 30. The network resources comprise application programs and network data.

[0089] Specifically, the identity authentication server 30 establishes a trusted connection with the control management server 20 for authenticating users. Application refers to software programs accessed by user terminals, including web browsers, email clients, etc., and network data refers to electronic data collected, stored, transmitted, processed and generated through the network.

[0090] For example, referring to Figure 2 , the data analysis server 10 includes a data collection layer, a data preprocessing layer, a spatio-temporal data mining layer, and a user behavior analysis layer, and the control management server 20 includes a network management and optimization layer, a data privacy protection layer, a network attack detection and prevention layer, and a control management layer.

[0091] For example, referring to Figure 2 The data collection layer collects spatio-temporal data from multiple sources, including user location, device status, network traffic data, threat intelligence, etc. The data preprocessing layer cleans, denoises, and formats the data, and integrates the collected spatio-temporal data into a comprehensive database to establish a comprehensive spatio-temporal data set. The spatio-temporal data mining layer uses data mining techniques to deeply integrate, analyze and mine spatio-temporal data and network security intelligence, comprehensively understand network events and threats, monitor abnormal activities in the network, and provide support for intelligent decision-making. The user behavior analysis layer analyzes user behavior patterns based on the results of spatio-temporal data mining to detect abnormal activities, trends and correlations to ensure the authenticity of their identity. By analyzing and predicting user behavior patterns, the identity and behavior characteristics of users can be identified, as well as potential abnormal behavior and attack behavior. According to the results of spatio-temporal data mining, the user behavior patterns can be analyzed and predicted to identify the identity and behavior characteristics of users, and to discover abnormal behavior and potential attack behavior. At the same time, through the automatic authorization and access control mechanism, the flexibility and convenience of user behavior can be enhanced, and the user experience can be improved.

[0092] The control management server 20 uses an intelligent decision support system to automatically make decisions based on the results of user behavior analysis and prediction, which can adjust network permissions and access control in real time to ensure the security and stability of the network; at the same time, by monitoring network traffic and user behavior, abnormal behavior and attack behavior can be discovered in a timely manner, and appropriate protective measures can be taken to enhance the security and stability of the network. The network management and optimization layer is used to monitor and analyze network traffic and user behavior, dynamically adjust network access permissions, implement real-time access control, and optimize network management and operation. The data privacy protection layer uses encryption and concealment technologies to protect user data security and privacy. The network attack detection and prevention layer monitors network traffic and user behavior, discovers abnormal behavior and attack behavior in a timely manner, and performs network resource micro-isolation. The control management layer continuously monitors network security and spatio-temporal data analysis system, uses spatio-temporal data and intelligent analysis results to automatically make decisions to adjust network permissions and access control in real time.

[0093] Specifically, the data privacy protection layer utilizes the distributed, decentralized, and tamper-proof characteristics of blockchain technology to build a decentralized trust mechanism, ensuring the authenticity and credibility of data. At the same time, some data can be stored on the blockchain, improving data traceability and transparency. By utilizing the distributed storage and computing advantages of cloud computing technology, large-scale data processing and analysis can be achieved, improving data processing efficiency and storage capacity. At the same time, virtualization technology can be used to achieve rapid deployment and flexible expansion. Some data processing and analysis tasks are transferred to edge devices to reduce data transmission latency and network load, improving data processing efficiency and response speed. At the same time, network bandwidth requirements and cloud computing pressure can be reduced.

[0094] The technical solutions in the embodiments of the present application have at least the following technical effects or advantages:

[0095] The data analysis server 10 comprehensively reflects the security posture of the network and sends it to the control management server 20 in a timely manner to provide support for permission control. The control management server 20 responds to the monitoring results sent by the data analysis server 10 to adjust the network access permissions in real time, effectively preventing potential security threats and enhancing the overall security of the network. The identity authentication server 30 performs identity authentication on the user terminal according to the network access permissions set by the control management server 20, ensuring the accuracy and security of the authentication process. The network resource server 40 provides network resources for the user terminal that passes the identity authentication according to the user identifier transmitted by the user authentication server, ensuring the rational use of network resources. The problems of high implementation cost and low compatibility of the existing zero-trust network are solved, and the technical effect of realizing permission control under low implementation cost is achieved.

[0096] Referring to Figure 3 The data analysis server 10 includes a network resource server 11, which is configured to analyze spatiotemporal data, establish a behavior benchmark model and a security behavior baseline. The behavior benchmark model is used to represent the user's common geographic location, network environment, terminal device, operation time, commonly used application, and usage habit. The security behavior baseline refers to the commonality of the behaviors of users with the same attributes.

[0097] Specifically, the behavior benchmark model and the safe behavior baseline are used to determine normal behavior patterns and abnormal behavior patterns. The behavior benchmark model is used to comprehensively and accurately represent the user's commonly used geographic location, network environment, terminal device, operation time, commonly used application, and usage habits. Specifically, the behavior benchmark model records the user's frequently visited geographic location information, such as home, company, or frequently visited public places, and the network environment used in these places, such as Wi-Fi, 4G / 5G, etc. At the same time, the user's terminal device information, such as mobile phone model, operating system version, etc., is also included in the model, so as to more comprehensively understand the user's usage environment. In addition, the model also records the user's operation time regularity in detail, such as daily active period, difference in use between weekends and weekdays, etc., as well as the user's commonly used application programs and usage habits, such as preferred browsers, social media platforms, etc. Through the integration of these information, the behavior benchmark model can support the subsequent determination of user behavior analysis data.

[0098] The safe behavior baseline refers to the common characteristics of user behavior with the same attributes further refined based on the behavior benchmark model. By finding the common behavior patterns of user groups with similar attributes (such as geographic location, network environment, organizational department, etc.), such as the network access frequency of certain users within a certain time period, the access order of commonly used applications, etc., which constitute an important part of the safe behavior baseline. By establishing the safe behavior baseline, a reference standard is provided for monitoring abnormal activities in the network, and by comparing the safe behavior baseline with the user's behavior, abnormal activities in the network can be determined. Through the behavior benchmark model and the safe behavior baseline, normal behavior patterns and abnormal behavior patterns can be determined.

[0099] Specifically, the normal behavior patterns and abnormal behavior patterns determined by the behavior benchmark model and the safe behavior baseline can clearly define the normal behavior boundaries of the user, providing support for monitoring abnormal activities in the network.

[0100] Analyzing spatio-temporal data to determine spatio-temporal correlation patterns, the spatio-temporal correlation patterns are used to represent the behavior correlation in different time and space.

[0101] Specifically, the spatio-temporal correlation patterns are used to reveal the behavior correlation in different time, different space, and different time and space. In determining the spatio-temporal correlation patterns, first, by analyzing the behavior activities of each time node, the trend and periodicity of behavior change over time are determined; then, by analyzing the behavior performance in different geographic locations, the influence of regional environment on user behavior is understood; finally, by combining time and space dimensions, the spatio-temporal correlation patterns are determined.

[0102] By determining the spatio-temporal correlation pattern, the behavior habits of the user at a specific time and place can be reflected, and the mutual influence and dependency relationship of the behavior under different spatio-temporal backgrounds can be revealed, thereby providing support for monitoring abnormal activities in the network.

[0103] According to the normal behavior pattern, the abnormal behavior pattern, and the spatio-temporal correlation pattern, a behavior analysis result is generated.

[0104] Specifically, by comparing the behavior data of the user with the normal behavior pattern, the behavior trajectory conforming to the convention is identified, and meanwhile, according to the abnormal behavior pattern, the behavior deviating from the normal trajectory or having abnormal characteristics is marked and classified, so as to timely discover abnormal activities in the network. In combination with the spatio-temporal correlation pattern, the overall trend of the user behavior can be accurately grasped, and the behavior pattern hidden in the complex spatio-temporal background can be identified.

[0105] In this embodiment, the spatio-temporal data mining technology is utilized to deeply analyze and mine the spatio-temporal data of the user, so as to obtain the behavior pattern and the spatio-temporal correlation of the user. By deeply analyzing and mining the spatio-temporal data by using the spatio-temporal data mining technology, the behavior pattern and the spatio-temporal correlation of the user can be obtained, thereby providing support for subsequent user behavior analysis and prediction. Meanwhile, by mining the pattern and rule in the spatio-temporal data, potential security threats and attack behaviors can be discovered, thereby improving the network security and stability.

[0106] With reference to Figure 3 , the data analysis server 10 further comprises a user behavior analysis module 12, which is configured to:

[0107] According to the behavior analysis result, a user behavior pattern is analyzed, and the user behavior pattern is configured to monitor abnormal activities, trends, and correlations in the network.

[0108] By the user behavior pattern, the identity and behavior characteristics of the user are identified, the behavior of the user is predicted, potential abnormal behaviors and attack behaviors are determined, and a monitoring result is generated.

[0109] Specifically, the monitoring result provides support for timely control of the permission by providing potential abnormal behaviors and attack behaviors, thereby improving the security and stability of the network. According to the behavior analysis result, the user behavior pattern is analyzed, and the activity trajectory, interaction habit, and preference of the user on the network are comprehensively analyzed, thereby helping to build a precise user portrait. By comparing the difference between the current behavior of the user and the normal behavior pattern, abnormal activities such as abnormal login attempts and illegal data access can be timely discovered. Meanwhile, in combination with the spatio-temporal correlation pattern, the occurrence time and place of the abnormal behavior can be accurately located, thereby providing support for determining potential abnormal behaviors and attack behaviors. Exemplarily, the machine learning technology is adopted to more deeply learn and understand the user behavior, so as to establish a more refined user behavior model, thereby improving the accuracy and efficiency of the user behavior analysis and prediction.

[0110] In this embodiment, according to the results of spatio-temporal data mining, the behavior patterns of users are analyzed and predicted, the identity and behavior characteristics of users are identified, and the abnormal behavior and attack behavior that may exist are identified. According to the results of spatio-temporal data mining, the behavior patterns of users are analyzed and predicted, the identity and behavior characteristics of users are identified, and the abnormal behavior and potential attack behavior are discovered. At the same time, through the automatic authorization and access control mechanism, the flexibility and convenience of user behavior can be enhanced, and the user experience can be improved.

[0111] With reference to Figure 4 , the control management server 20 comprises a network control management module 21, which is configured to formulate a permission control policy according to the monitoring results.

[0112] The network access permission is adjusted through the permission control policy.

[0113] Specifically, according to the monitoring results, the laws of network activities, user behavior patterns and potential security risks are analyzed in depth, and the permission control policy is formulated, which not only considers the needs of different users, the security requirements of business systems and the sensitivity of network resources, but also ensures that the normal work requirements are met and the security risks are effectively prevented.

[0114] For example, according to the permission control policy, the network access permission is adjusted by configuring the access control list, setting the user permission level, limiting the access range of specific resources, etc., to realize precise control of the permission, ensure that legitimate users can smoothly access the required resources, effectively organize the intrusion of illegal users, and comprehensively improve the security and stability of the network system.

[0115] With reference to Figure 4 , the control management server 20 further comprises a network attack detection and prevention module 22, which is configured to:

[0116] Monitor spatio-temporal data.

[0117] Analyze the spatio-temporal data to determine whether there is abnormal behavior or attack behavior.

[0118] When there is abnormal behavior or attack behavior, network resource micro-isolation is performed according to the abnormal behavior or attack behavior.

[0119] Specifically, by monitoring and analyzing the spatio-temporal data, and in the case of determining the existence of abnormal behavior or attack behavior, network resource micro-isolation is performed to finely isolate the affected network resources or system parts, to minimize the impact on normal business, while ensuring that the abnormal behavior or attack behavior is effectively contained, the spread of abnormal traffic is limited, and the normal operation state of the network is quickly restored, ensuring the overall security of the system.

[0120] In this embodiment, by monitoring network traffic and user behavior, abnormal behavior and attack behavior are discovered in a timely manner, and corresponding protection measures are taken to improve network security and stability. By monitoring network traffic and user behavior, abnormal behavior and attack behavior are discovered in a timely manner, and corresponding protection measures are taken to improve network security and stability, protect the core information assets of enterprises, and reduce potential security risks and attack surfaces.

[0121] With reference to Figure 5 , the data analysis server 10 further comprises a data collection module 13, which is configured to:

[0122] Through the sensing device, user behavior data is collected, and network traffic data is obtained. The user behavior data includes geographic location, spatial movement information, surrounding information, and temperature information. The network traffic data includes traffic data, threat intelligence, device status information, and operation logs.

[0123] According to the user behavior data and the network traffic data, raw data is obtained.

[0124] Specifically, the sensing device can collect user behavior data in multiple dimensions. The geographic location information is used to track the spatial activity trajectory. The spatial movement information includes movement speed, movement direction, and stay duration, which is used to analyze the user's action pattern. The surrounding environment information includes WiFi hotspots, Bluetooth devices, and temperature information, which indicates the temperature of the user terminal device. The surrounding environment information and the temperature information are used to represent the physical environment status of the user.

[0125] The network traffic data includes traffic data, network data transmission volume, transmission speed, and transmission direction, which provides a basis for analyzing network usage and bandwidth allocation. Threat intelligence is used to capture malicious activities in the network, including virus attacks and malicious software propagation, ensuring network security. Device status information is used to reflect the working status of the user terminal device, such as CPU occupancy and memory occupancy, which helps to discover and solve device faults in a timely manner. Operation logs record all network activities of user login, logout, and data access, providing reliable basis for tracing problems and auditing security.

[0126] By integrating user behavior data and network traffic data, raw data is obtained, which provides support for subsequent analysis, adjustment of network access permissions, and execution of network resource micro-isolation.

[0127] For example, by connecting devices, sensors, and networks through Internet of Things technology, more comprehensive and real-time data collection and monitoring can be achieved, improving the efficiency and quality of network management and operation.

[0128] In this embodiment, the spatio-temporal data and network traffic data of the user are collected through various sensors and data sources, including the user's location information, device status, network traffic, etc. By collecting multi-source spatio-temporal data and network traffic data, more comprehensive and accurate data sources can be obtained to provide basic data support for subsequent data analysis and mining. At the same time, using various sensors and data sources can improve the diversity and reliability of the data, and reduce the error and uncertainty of a single data source.

[0129] With reference to Figure 5 The data analysis server 10 further comprises a data preprocessing module 14, which is configured to:

[0130] Scan the original data to remove redundant information, irrelevant information and obvious errors in the original data to obtain preliminary cleaned data.

[0131] Identify noise and outliers in the preliminary cleaned data, and remove the noise and outliers to obtain purified data.

[0132] According to the preset specification format, the purified data is uniformly converted to obtain standard format data, and the preset specification format includes data type, encoding format and date format.

[0133] Clean invalid records and obvious errors in the standard format data to obtain valid data.

[0134] According to the preset standard, the valid data is normalized and standardized to obtain spatio-temporal data, and the preset standard refers to rules or parameters used to guide data conversion.

[0135] The spatio-temporal data is integrated to construct a spatio-temporal data set.

[0136] Specifically, redundant information refers to repeated information, irrelevant information refers to information irrelevant to the analysis target, and obvious errors include misspelled words and unreasonable numerical values. Noise refers to random data fluctuations or data fluctuations that are useless for analysis results, and outliers refer to values that significantly deviate from the normal data range. By setting a reasonable threshold and filtering conditions, noise and outliers are removed to ensure the accuracy and reliability of the data.

[0137] The purified data is uniformly converted using the preset specification format, including specifying the data type of each field, which is an integer, a floating-point number or a string, to ensure that the encoding format of the data is consistent. Using a unified encoding format and a standard date data format can obtain standard format data that is uniform in format and easy to process.

[0138] By cleaning the missing key information and obviously illogical records in the standard format data, higher quality effective data can be obtained. According to the preset standard, the effective data is normalized, that is, the effective data is scaled to a specific range to eliminate the dimensional difference between different data; the standardization processing is to convert the data into the form of standard normal distribution by calculating the mean and standard deviation of the data, and generate the space-time data.

[0139] By organizing the space-time data according to the time sequence and spatial position, a space-time data set can be constructed to provide a basis for subsequent analysis.

[0140] In this embodiment, by cleaning, denoising and formatting the collected data, removing invalid and error data, standardizing and normalizing the data, accurate basis is provided for subsequent data analysis and mining. By cleaning, denoising and formatting the collected data, the accuracy and reliability of the data can be improved, which provides an accurate basis for subsequent data analysis and mining. At the same time, by standardizing and normalizing the data, the comparability and understandability of the data can be enhanced, which facilitates the fusion and analysis between different data sources.

[0141] Embodiment two

[0142] With reference to Figure 6 , the application embodiment provides a permission control method applied to a permission control system, including the following steps:

[0143] S10, the data analysis server analyzes the space-time data, processes network events and network threats, and monitors abnormal activities in the network, generates monitoring results, and sends them to the control management server. The space-time data refers to data related to network traffic and user behavior.

[0144] S20, the control management server adjusts the network access permission in real time according to the monitoring results.

[0145] S30, the identity authentication server performs identity authentication on the user terminal according to the network access permission, and provides the identity of the user terminal that passes the identity authentication to the network resource server.

[0146] S40, the network resource server provides network resources to the user terminal that passes the identity authentication according to the identity of the user terminal that passes the identity authentication provided by the identity authentication server. The network resources include application programs and network data.

[0147] With reference to Figure 7 , the data analysis server analyzes the space-time data, processes network events and network threats, and monitors abnormal activities in the network, generates monitoring results, and sends them to the control management server, including the following steps:

[0148] S11, analyze the spatio-temporal data, establish a behavior benchmark model and a security behavior baseline, the behavior benchmark model is used to represent the user's common geographic location, network environment, terminal device, operation time, common application and usage habit, and the security behavior baseline refers to the behavior commonality of the same attribute user.

[0149] S12, determine normal behavior mode and abnormal behavior mode through the behavior benchmark model and the security behavior baseline.

[0150] S13, analyze the spatio-temporal data, determine the spatio-temporal correlation mode, and the spatio-temporal correlation mode is used to represent the behavior correlation in different time and space.

[0151] S14, generate a behavior analysis result according to the normal behavior mode, the abnormal behavior mode and the spatio-temporal correlation mode.

[0152] Reference Figure 7 After the behavior analysis result is generated according to the normal behavior mode, the abnormal behavior mode and the spatio-temporal correlation mode, the following steps are further included:

[0153] S15, analyze the user behavior mode according to the behavior analysis result, and the user behavior mode is used to monitor the abnormal activity, trend and correlation in the network.

[0154] S16, identify the identity and behavior characteristics of the user, predict the behavior of the user, determine the potential abnormal behavior and attack behavior, and generate a monitoring result through the user behavior mode.

[0155] For the method embodiment, since it is basically similar to the system embodiment, the description is relatively simple, and the related parts refer to the part of the system embodiment.

[0156] Each embodiment in the specification is described in a progressive manner, and each embodiment focuses on the difference from other embodiments. The same and similar parts between the embodiments can be referred to each other.

[0157] The above describes the permission control system and method provided by the application in detail. The principle and implementation mode of the application are described by applying specific examples. The above embodiment description is only used to help understand the method and core idea of the application. Meanwhile, for those skilled in the art, according to the idea of the application, the specific implementation mode and application range can be changed. In summary, the content of the specification should not be understood as a limitation of the application.

Claims

1. An access control system, characterized in that, include: Data analysis server, control and management server, identity authentication server, network resource server; The data analysis server is used to analyze spatiotemporal data, process network events and network threats, monitor abnormal activities in the network, generate monitoring results, and send them to the control and management server. The spatiotemporal data refers to data related to network traffic and user behavior. The control and management server is used to adjust network access permissions in real time based on the monitoring results; The identity authentication server is used to authenticate the user terminal according to the network access permissions, and to provide the network resource server with the identifier of the user terminal that has passed the identity authentication. The network resource server is used to provide network resources to the authenticated user terminal based on the identifier of the authenticated user terminal provided by the identity authentication server. The network resources include applications and network data. The data analysis server includes a spatiotemporal data mining module, which is used for: Analyze the spatiotemporal data to establish a behavioral baseline model and a security behavior baseline. The behavioral baseline model is used to represent the user's common geographical location, network environment, terminal device, operation time, common applications and usage habits. The security behavior baseline refers to the commonalities in the behavior of users with the same attributes. The normal behavior pattern and the abnormal behavior pattern are determined by the behavioral baseline model and the safe behavior baseline; Analyze the spatiotemporal data to determine spatiotemporal correlation patterns, which are used to represent behavioral correlations in different times and spaces; Based on the normal behavior pattern, the abnormal behavior pattern, and the spatiotemporal correlation pattern, behavioral analysis results are generated.

2. The access control system as described in claim 1, characterized in that, The data analysis server further includes a user behavior analysis module, which is used for: Based on the behavioral analysis results, user behavior patterns are analyzed, and these user behavior patterns are used to monitor abnormal activities, trends, and correlations in the network. By analyzing the user behavior patterns, the system identifies the user's identity and behavioral characteristics, predicts the user's behavior, identifies potential abnormal and attack behaviors, and generates the monitoring results.

3. The access control system as described in claim 1 or 2, characterized in that, The control management server includes a network control management module, which is used for: Based on the monitoring results, develop access control strategies; The network access permissions are adjusted through the aforementioned access control policy.

4. The access control system as described in claim 3, characterized in that, The control and management server also includes a network attack detection and prevention module, which is used for: Monitor the spatiotemporal data; Analyze the spatiotemporal data to determine whether there are any abnormal or attack behaviors; When the aforementioned abnormal behavior or attack behavior exists, network resource differential isolation is performed based on the aforementioned abnormal behavior or attack behavior.

5. The access control system as described in claim 1 or 2, characterized in that, The data analysis server further includes a data acquisition module, which is used for: User behavior data is collected through sensing devices, and network traffic data is obtained. The user behavior data includes geographical location, spatial movement information, surrounding information and temperature information. The network traffic data includes traffic data, threat intelligence, device status information and operation logs. The raw data is obtained based on the user behavior data and the network traffic data.

6. The access control system as described in claim 5, characterized in that, The data analysis server further includes a data preprocessing module, which is used for: The original data is scanned to remove redundant information, irrelevant information, and obvious errors, resulting in preliminarily cleaned data. Identify noise and outliers in the preliminary cleaning data, remove the noise and outliers, and obtain the purified data. According to a preset standard format, the purified data is uniformly converted to obtain standard format data. The preset standard format includes data type, encoding format, and date format. Clean up invalid records and obvious errors in the standard format data to obtain valid data; According to a preset standard, the effective data is normalized and standardized to obtain the spatiotemporal data. The preset standard refers to the rules or parameters used to guide the data transformation. The spatiotemporal data are integrated to construct a spatiotemporal dataset.

7. An access control method, characterized in that, The access control system applied to any one of claims 1-6 comprises the following steps: The data analysis server analyzes the spatiotemporal data, processes network events and network threats, monitors abnormal activities in the network, generates the monitoring results, and sends them to the control and management server. The spatiotemporal data refers to data related to network traffic and user behavior. The control and management server adjusts the network access permissions in real time based on the monitoring results; The identity authentication server authenticates the user terminal based on the network access permissions and provides the network resource server with the identifier of the user terminal that has passed the identity authentication. The network resource server provides network resources to the authenticated user terminal based on the identifier of the authenticated user terminal provided by the identity authentication server. The network resources include applications and network data.

8. The method as described in claim 7, characterized in that, The data analysis server analyzes the spatiotemporal data, processes network events and threats, monitors abnormal activities in the network, generates monitoring results, and sends them to the control and management server, including the following steps: Analyze the spatiotemporal data to establish a behavioral baseline model and a security behavior baseline. The behavioral baseline model is used to represent the user's common geographical location, network environment, terminal device, operation time, common applications and usage habits. The security behavior baseline refers to the commonalities in the behavior of users with the same attributes. The normal behavior pattern and the abnormal behavior pattern are determined by the behavioral baseline model and the safe behavior baseline; Analyze the spatiotemporal data to determine spatiotemporal correlation patterns, which are used to represent behavioral correlations in different times and spaces; Based on the normal behavior pattern, the abnormal behavior pattern, and the spatiotemporal correlation pattern, behavioral analysis results are generated.

9. The method as described in claim 8, characterized in that, After generating the behavior analysis results based on the normal behavior pattern, the abnormal behavior pattern, and the spatiotemporal correlation pattern, the following steps are also included: Based on the behavioral analysis results, user behavior patterns are analyzed, and these user behavior patterns are used to monitor abnormal activities, trends, and correlations in the network. By analyzing the user behavior patterns, the system identifies the user's identity and behavioral characteristics, predicts the user's behavior, identifies potential abnormal and attack behaviors, and generates the monitoring results.

Citation Information

Patent Citations

  • Space-time process intelligent analysis mining method and system based on multi-source big data

    CN115455076A

  • GIS-based comprehensive situation awareness protection system and construction method thereof

    CN119051999A