A security access control method and device for commodity sales
By using the data query touch display screen to verify identity and keyword acquisition based on security access control for product sales, based on security level analysis and implementing corresponding data security control measures, the problems of insufficient permissions and data leakage in the existing technology are solved, and the security protection and access behavior specifications of commodity sales data are realized.
Patent Information
- Application Number
- CN202510410262.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-02
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2045-04-02
AI Technical Summary
In the security access control of commodity sales, the division of roles and permissions may not be fine enough, resulting in excessive or insufficient permissions, internal personnel may abuse their permissions and lead to data leakage, and the security after commercial data leakage is difficult to guarantee.
Enter the account information through the data query touch display screen for identity verification, obtain the access requirements keywords, and analyze the security level to which the access requirements belong based on the security level mapping method, and implement corresponding data security control measures, such as mask display control, designated authorized personnel at the same time display control and reject display control.
It effectively prevents the leakage of sensitive and confidential information, ensures the security of commodity sales data, regulates access behavior, reduces the risk of data leakage, and discovers potential security risks through post-audit and monitoring.
Smart Images

Figure CN119918033B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of secure access control, and particularly to a secure access control method and device for commodity sales. Background Art
[0002] Secure access control for commodity sales is of great significance for protecting enterprise resources, maintaining customer data privacy, and complying with laws and regulations.
[0003] Sensitive information such as customer data, transaction records, and business secrets involved in the sales process needs to be protected to prevent unauthorized access and data leakage.
[0004] Many industries have strict legal and regulatory requirements, such as GDPR (General Data Protection Regulation), etc., which require enterprises to protect customer data securely. Employees within the enterprise may abuse their power due to personal interests or other reasons. Access control can limit employees' access to sensitive information and reduce the risk of internal leakage. Ensure that only authorized personnel can access critical business systems to prevent malicious operations from causing system paralysis or data loss. By implementing effective access control measures, enterprises can enhance customers' trust in their ability to protect personal information.
[0005] Role-based access control is the most commonly used access control method at present. It controls users' access to resources by defining roles and permissions. Attribute-based access control is becoming increasingly popular. It dynamically determines access permissions through attributes (such as user attributes, resource attributes, and environmental attributes). To improve security, many enterprises have started to adopt multi-factor authentication, requiring users to provide multiple authentication factors when accessing the system.
[0006] The division of roles and permissions in the above access control may not be fine enough, resulting in over-permission (users can access resources they do not need) or under-permission (users cannot access resources they need).
[0007] Even with access control, authorized internal personnel may still abuse their permissions. Especially in the case of lax supervision, data may be leaked in batches when internal personnel are authorized, causing huge losses to the enterprise. At the same time, the security of business data after leakage cannot be guaranteed. Summary of the Invention
[0008] To solve the above technical problems, the present invention provides a secure access control method and device for commodity sales. The following technical solutions are adopted:
[0009] A secure access control method for commodity sales includes the following steps:
[0010] Step 1, the access personnel enter the account information on the data query touch display screen to verify the access account identity;
[0011] Step 2: Guide the account that has passed the account identity verification through keywords to obtain access requirement keywords;
[0012] Step 3: Based on the access requirement keywords, use a security level mapping method to analyze the security level of the access behavior to which the access requirement belongs. The security levels of access behaviors include public level, internal level, sensitive level, confidential level, and top-secret level;
[0013] Step 4: Execute data security control measures based on the security level of the access behavior. The data security control measures include masked display control, simultaneous presence display control by designated authorized personnel, and refusal display control;
[0014] When it is determined that the security level of the access behavior of the access requirement belongs to the public level, directly call the corresponding commodity sales data in the commodity sales data server and display it without executing data security control measures;
[0015] When it is determined that the security level of the access behavior of the access requirement belongs to the internal level and the sensitive level, call the corresponding commodity sales data in the commodity sales data server and display it after executing masked display control;
[0016] When it is determined that the security level of the access behavior of the access requirement belongs to the confidential level, call the corresponding commodity sales data in the commodity sales data server and display it after simultaneously executing masked display control and simultaneous presence display control by designated authorized personnel;
[0017] When it is determined that the security level of the access behavior of the access requirement belongs to the top-secret level, execute refusal display control.
[0018] By adopting the above technical solution, the data query touch display screen is used for company internal personnel to query commodity sales-related data in an authorized state. The access personnel first need to enter their account passwords. Of course, biometric authentication such as face and fingerprint can also be added. Guide the account that has passed the account identity verification through keywords to obtain access requirement keywords, which simplifies the operation process of the access personnel, makes the access process more convenient, and can also standardize the acquisition of the target data intention of the access personnel, providing a basis for determining the security level of the target data in the subsequent stage. By classifying the access requirements into different security levels and executing corresponding data security control measures for different levels of access, it effectively prevents the leakage of sensitive and confidential information and ensures the security of commodity sales data;
[0019] Execute data security control measures based on the security level of the access behavior. The data security control measures include masked display control, simultaneous presence display control by designated authorized personnel, and refusal display control;
[0020] For internal, sensitive and confidential access requirements, measures such as masked display control and display control with designated authorized personnel on site are adopted to effectively prevent data leakage caused by improper behavior of internal personnel. Masked display control can avoid related data leakage caused by displaying target data, and display control with designated authorized personnel on site can effectively avoid the risk of leakage of high-security data by taking photos or other means without the authorization of designated authorized personnel.
[0021] Denial of display control can effectively prevent the leakage of top-secret data.
[0022] By clearly dividing the security levels of access behaviors, access personnel can have a clearer understanding of their access behaviors, which helps to regulate access behaviors. For example, all access behaviors of access personnel can be scored for behavioral risks, and a scoring result threshold can be set. If the behavioral risk score of a certain access personnel exceeds the scoring result threshold, a warning is required, and the management personnel need to pay attention to whether the intentions of the access personnel are good.
[0023] Access behaviors at different security levels are recorded to facilitate post-audit and monitoring, helping to discover potential security risks.
[0024] Optionally, mask display control is to display only the target data corresponding to the access requirement keyword in the displayed data page, and mask other data on the data page.
[0025] By adopting the above technical solution, mask display control can adopt visual means such as blur processing to achieve masking of other information. For example, in a commodity sales contract, if the target data of the accessing personnel is the sales amount, then other sensitive information of the displayed sales contract, such as the contact information of the contracting parties, the payment account and other sensitive information, needs to be masked.
[0026] Optionally, when the designated authorized personnel are on-site at the same time, the display control is to first prompt the designated authorized personnel's information, then set the designated authorized personnel's arrival time limit, within the designated authorized personnel's arrival time limit, the designated authorized personnel enters the account number and password, and performs biometric information authentication, if the authentication is completed, the target data corresponding to the access requirement keyword is retrieved, and the biometric information of the designated authorized personnel and the person accessing the account is continuously verified while the target data is displayed, and if the biometric information is lost, the target data is stopped from being displayed.
[0027] Optionally, the biometric information authentication is facial authentication, and the method for continuously verifying the biometric information of the designated authorized personnel and the personnel accessing the account is: calling the camera to continuously capture the facial images of the designated authorized personnel and the personnel accessing the account, and analyzing whether the facial images continue to correspond to the designated authorized personnel and the personnel accessing the account; if the facial images corresponding to the designated authorized personnel and the personnel accessing the account continue to exist, the target data is continuously displayed.
[0028] By adopting the above technical solution, the designated authorized personnel need to continuously stay in front of the data query touch display screen after account authentication. In this way, sales data with a higher security level is displayed under the continuous attention of the designated authorized personnel, preventing access personnel from using means such as taking pictures to record relevant data and reducing the risk of leakage of sales data with a higher security level.
[0029] Optionally, the designated authorized personnel information is generated by a random number generation method. All designated authorized personnel are numbered, and the numbers of the designated authorized personnel are randomly generated by the random number generation method. The designated authorized personnel information corresponding to the number is called for authentication prompt, and at the same time, a permission cooperation prompt is sent to the handheld intelligent terminal of the designated authorized personnel based on the network.
[0030] By adopting the above technical solution, the designated authorized personnel are generated by a random number generation method. For example, the designated authorized personnel are 10 middle-level managers of an enterprise. Each time the designated authorized personnel are required to cooperate, a number of a middle-level manager is generated by the random number generation method, and a permission cooperation prompt is sent to the handheld intelligent terminal of the designated authorized personnel corresponding to the number. In this way, the risk that access personnel collude with the designated authorized personnel by illegal means in advance to obtain high-security-level sales data can be reduced.
[0031] Optionally, the refusal to display control is not to display the target data, record the current access information, and send a security access warning message to the administrator.
[0032] By adopting the above technical solution, the refusal to display control usually targets sales data at the top-secret level. For example, the target data of the access personnel is the contact information of all customers, etc. This type of data involves the foundation of the enterprise and cannot be displayed on the data query touch display screen. It must be retrieved only at the highest decision-making meeting of the enterprise. For such access, the current access information needs to be recorded, and a security access warning message is sent to the administrator to remind the staff to pay attention to the behavior of the access personnel.
[0033] Optionally, in step 1, the verification of the access account identity includes the verification of the account password and the verification of the biometric information.
[0034] Optionally, step 2 includes the following specific steps:
[0035] Step 21, display the keyword guidance of the data category. The access personnel select the keyword of the target commodity sales data category according to the keyword guidance of the commodity sales data category.
[0036] Step 22, display the keyword guidance of the data range. The access personnel select the target data range according to the keyword guidance of the data range. The target data range includes all data, partial data, and specific data.
[0037] Part of the data is the target data selected according to the data time span, and the specific data is a specific single specified data.
[0038] By adopting the above technical solution, the target commodity sales data category keywords usually refer to sales contracts, sales records, commodity inventory data, sales price data, etc. For example, when displaying the data category keyword guide, it is simultaneously displayed: sales contract, sales record, commodity inventory, sales price, etc. The display data range keyword guide can be that the access personnel see on the screen:
[0039] Please select the data range you need to query:
[0040] All data: Click here to view the commodity sales data of all categories.
[0041] Part of the data: Select the time span;
[0042] This week's data: Click here to view this week's commodity sales data.
[0043] This month's data: Click here to view this month's commodity sales data.
[0044] Custom time range: Please enter the start date and end date.
[0045] Specific data: Enter the query condition;
[0046] Commodity number: Please enter the commodity number and click query.
[0047] Sales order number: Please enter the sales order number and click query.
[0048] A certain access personnel selects a sales contract, then selects specific data in the display data range keyword guide, and enters the specific sales order number to query the corresponding sales order.
[0049] Optionally, step 3 includes the following specific steps:
[0050] Step 31, create a keyword library containing all commodity sales data categories, and each keyword in the keyword library corresponds to a basic access behavior security level;
[0051] Step 32, adjust the basic access behavior security level based on the target data range to obtain the access behavior security level;
[0052] If the basic access behavior security level is the public level, no fine-tuning is performed;
[0053] When the basic access behavior security level is internal and sensitive, if the target data range is specific data, no fine-tuning is performed. If the target data range is partial data, the public level is raised by one level. If the target data range is all data, the public level is raised by two levels.
[0054] By adopting the above technical solution, each keyword in the keyword library corresponds to a basic access behavior security level. For example, the basic access behavior security level of a sales contract corresponds to the sensitive level. If the target data range is selected as a custom time range and the input date range includes all sales contracts, then the public level is raised by two levels to become the top secret level, because retrieving all sales contracts at the same time belongs to the company's top secret and the control measure of refusing to display should be adopted.
[0055] A security access control device for commodity sales, used to implement a security access control method for commodity sales. The security access control device includes a data query touch display screen, a camera, a memory, an analysis chip module, a handheld intelligent terminal, and a commodity sales data server. The data query touch display screen is communicatively connected to the commodity sales data server through the Internet. The camera is installed on the outer shell of the data query touch display screen and is used to capture the facial feature images of the people in front. The memory communicates and interacts with the camera and the data query touch display screen respectively to input keyword data and facial feature data. The analysis chip module includes a visual analysis chip and a data analysis chip. The visual analysis chip and the data analysis chip are respectively communicatively connected to the memory. The visual analysis chip realizes biometric information authentication based on the facial feature data. The data analysis chip analyzes the access behavior security level to which the access requirement belongs based on the access requirement keyword, and executes data security control measures based on the access behavior security level. The memory is wirelessly communicatively connected to the handheld intelligent terminal, and the data analysis chip controls the memory to wirelessly interact with the handheld intelligent terminal for security access warning information.
[0056] In summary, the present invention includes at least one of the following beneficial technical effects:
[0057] The present invention can provide a security access control method and device for commodity sales. By guiding the account verified by the account identity through keywords to obtain the access requirement keyword, the operation process of the access personnel is simplified, making the access process more convenient. It can also standardize the target data intention of the access personnel and provide a basis for determining the security level of the target data subsequently. By classifying the access requirements into different security levels and performing corresponding data security control measures on different levels of access, it effectively prevents the leakage of sensitive and confidential information and ensures the security of commodity sales data;
[0058] For internal, sensitive and confidential access requirements, measures such as masked display control and display control with designated authorized personnel on site are adopted to effectively prevent data leakage caused by improper behavior of internal personnel. Masked display control can avoid related data leakage caused by displaying target data, and display control with designated authorized personnel on site can effectively avoid the risk of leakage of high-security data by taking photos or other means without the authorization of designated authorized personnel.
[0059] By clearly dividing the security levels of access behaviors, access personnel can have a clearer understanding of their access behaviors, which helps to regulate access behaviors. For example, all access behaviors of access personnel can be scored for behavioral risks, and a scoring result threshold can be set. If the behavioral risk score of a certain access personnel exceeds the scoring result threshold, a warning is required, and the management personnel need to pay attention to whether the intentions of the access personnel are good.
[0060] Access behaviors at different security levels are recorded to facilitate post-audit and monitoring, helping to discover potential security risks. BRIEF DESCRIPTION OF THE DRAWINGS
[0061] Figure 1 It is a flow chart of a method for secure access control of commodity sales according to the present invention;
[0062] Figure 2 It is a schematic diagram of the component connection principle of a security access control device for commodity sales according to the present invention.
[0063] Explanation of the accompanying drawings: 1. Data query touch screen; 2. Camera; 3. Memory; 4. Analysis chip module; 41. Visual analysis chip; 42. Data analysis chip; 5. Handheld smart terminal; 6. Commodity sales data server. DETAILED DESCRIPTION
[0064] The present invention is further described in detail below in conjunction with the accompanying drawings.
[0065] The embodiment of the invention discloses a method and device for secure access control for commodity sales.
[0066] Reference Figure 1 and Figure 2 , Embodiment 1, a security access control method for commodity sales, comprising the following steps:
[0067] Step 1: The visitor enters the account information on the data query touch screen 1 to verify the identity of the visitor account;
[0068] Step 2: Use keywords to guide the account that has passed the account identity verification to obtain the access demand keywords;
[0069] Step 3: Based on the access requirement keywords, use the security level mapping method to analyze the security level of the access behavior to which the access requirement belongs. The security levels of access behavior include public level, internal level, sensitive level, confidential level, and top-secret level;
[0070] Step 4: Execute data security control measures based on the security level of the access behavior. The data security control measures include mask display control, simultaneous presence display control of designated authorized personnel, and refusal display control;
[0071] When it is determined that the security level of the access behavior of the access requirement belongs to the public level, directly call the corresponding commodity sales data in the commodity sales data server 6 and display it without executing data security control measures;
[0072] When it is determined that the security level of the access behavior of the access requirement belongs to the internal level and the sensitive level, call the corresponding commodity sales data in the commodity sales data server 6 and display it after executing mask display control;
[0073] When it is determined that the security level of the access behavior of the access requirement belongs to the confidential level, call the corresponding commodity sales data in the commodity sales data server 6 and display it after simultaneously executing mask display control and simultaneous presence display control of designated authorized personnel;
[0074] When it is determined that the security level of the access behavior of the access requirement belongs to the top-secret level, execute refusal display control.
[0075] The data query touch display screen 1 is used for company internal personnel to query commodity sales-related data in an authorized state. The access personnel first need to enter their account passwords. Of course, biometric authentication such as face and fingerprint can also be added. The access requirement keywords are obtained through keyword guidance for the account verified by the account identity, which simplifies the operation process of the access personnel, makes the access process more convenient, and can also standardize the target data intention of the access personnel, providing a basis for determining the security level of the target data in the follow-up. By classifying the access requirements into different security levels and executing corresponding data security control measures for different levels of access, the leakage of sensitive and confidential information is effectively prevented, and the security of commodity sales data is guaranteed;
[0076] Execute data security control measures based on the security level of the access behavior. The data security control measures include mask display control, simultaneous presence display control of designated authorized personnel, and refusal display control;
[0077] For internal, sensitive and confidential access requirements, measures such as masked display control and display control with designated authorized personnel on site are adopted to effectively prevent data leakage caused by improper behavior of internal personnel. Masked display control can avoid related data leakage caused by displaying target data, and display control with designated authorized personnel on site can effectively avoid the risk of leakage of high-security data by taking photos or other means without the authorization of designated authorized personnel.
[0078] Denial of display control can effectively prevent the leakage of top-secret data.
[0079] By clearly dividing the security levels of access behaviors, access personnel can have a clearer understanding of their access behaviors, which helps to regulate access behaviors. For example, all access behaviors of access personnel can be scored for behavioral risks, and a scoring result threshold can be set. If the behavioral risk score of a certain access personnel exceeds the scoring result threshold, a warning is required, and the management personnel need to pay attention to whether the intentions of the access personnel are good.
[0080] Access behaviors at different security levels are recorded to facilitate post-audit and monitoring, helping to discover potential security risks.
[0081] Access behavior risk scoring can be achieved through a comprehensive formula that takes into account multiple factors, including access frequency, access time, access security level, access results (whether successful), and historical behavior records of access personnel.
[0082] Risk score = w1×F(a)+w2×F(b)+w3×F(c)+w4×F(d)+w5×F(e);
[0083] w1, w2, w3, w4, and w5 are weight coefficients, assigned according to the importance of each factor;
[0084] F(a) is the frequency factor, which is a risk factor calculated based on the access frequency. For example, frequent access may increase the risk score.
[0085] F(b) is the time factor, which is a risk factor calculated based on the access time. Access during non-working hours may increase the risk score.
[0086] F(c) is the security level factor which is a risk factor calculated based on the security level of the access requirement. Accessing confidential or top secret information will have a higher risk score.
[0087] F(d) is the historical behavior factor, which is a risk factor calculated based on the visitor's historical behavior records. Visitors with a history of violations will have a higher risk score.
[0088] F(e) is an abnormal behavior factor, which is a risk factor calculated based on whether the current behavior of the visitor is abnormal, such as accessing irrelevant data categories or frequent failed attempts.
[0089] In Embodiment 2, the mask display control is to only display the target data corresponding to the access requirement keywords in the displayed data page, and mask the other data in the data page.
[0090] The mask display control can adopt visual means such as blurring processing, and can realize the mask processing of other information. For example, in a commodity sales contract, if the target data of the access person is the sales amount, then other sensitive information in the displayed sales contract, such as the contact information of the contract party, the collection account, etc., needs to be masked.
[0091] In Embodiment 3, the simultaneous presence display control of designated permission personnel is to first prompt the information of the designated permission personnel, then set the arrival time limit of the designated permission personnel. Within the arrival time limit of the designated permission personnel, the designated permission personnel enter the account number and password, and perform biometric information authentication. If the authentication is completed, the target data corresponding to the access requirement keywords is retrieved. While the target data is being displayed, the biometric information of the designated permission personnel and the access account personnel is continuously verified. If the biometric information is lost, the display of the target data is stopped.
[0092] In Embodiment 4, the biometric information authentication is face authentication. The method of continuously verifying the biometric information of the designated permission personnel and the access account personnel is: calling the camera 2 to continuously capture the facial images of the designated permission personnel and the access account personnel, and analyzing whether the facial images continuously correspond to the designated permission personnel and the access account personnel. If there are continuously corresponding facial images of the designated permission personnel and the access account personnel, the target data is continuously displayed.
[0093] After the designated permission personnel complete the account authentication, they need to continuously stay in front of the data query touch display screen 1, so that the sales data with a higher security level is displayed under the continuous attention of the designated permission personnel, avoiding the access personnel from using means such as taking pictures to record relevant data, and reducing the risk of leakage of the sales data with a higher security level.
[0094] In Embodiment 5, the information of the designated permission personnel is generated by a random number generation method. All the designated permission personnel are numbered, and the numbers of the designated permission personnel are randomly generated by the random number generation method. The information of the designated permission personnel corresponding to the numbers is called for authentication prompt, and at the same time, a permission cooperation prompt is sent to the handheld smart terminal 5 of the designated permission personnel based on the network.
[0095] Use a random number generation method to generate designated authorized personnel. For example, the designated authorized personnel are 10 middle - level managers of an enterprise. Each time the cooperation of the designated authorized personnel is required, use the random number generation method to generate the number of a middle - level manager, and send a permission cooperation prompt to the handheld smart terminal 5 of the designated authorized personnel corresponding to the number. In this way, the risk that the visiting personnel collude with the designated authorized personnel by illegal means in advance to obtain high - security - level sales data can be reduced.
[0096] Example 6, the refusal to display control is not to display the target data, record the current access information, and send a security access warning message to the administrator.
[0097] The refusal to display control usually targets sales data at the top - secret level. For example, the target data of the visiting personnel is the contact information of all customers, etc. This type of data involves the foundation of the enterprise and cannot be displayed on the data query touch display screen 1. It can only be retrieved at the highest - level decision - making meeting of the enterprise. For such access, the current access information needs to be recorded, and a security access warning message is sent to the administrator to remind the staff to pay attention to the behavior of the visiting personnel.
[0098] Example 7, in step 1, the verification of the access account identity includes the verification of the account password and the verification of the biometric information.
[0099] Example 8, step 2 includes the following specific steps:
[0100] Step 21, display the keyword guidance for the data category. The visiting personnel select the target commodity sales data category keyword according to the keyword guidance for the commodity sales data category.
[0101] Step 22, display the keyword guidance for the data range. The visiting personnel select the target data range according to the keyword guidance for the data range. The target data range includes all data, partial data, and specific data.
[0102] The partial data is the target data selected according to the data time span, and the specific data is the specific single - item designated data.
[0103] The target commodity sales data category keyword usually refers to sales contracts, sales records, commodity inventory data, sales price data, etc. For example, in the display of the keyword guidance for the data category, display at the same time: sales contracts, sales records, commodity inventory, sales price, etc. The display of the keyword guidance for the data range can be that the visiting personnel see on the screen:
[0104] Please select the data range you need to query:
[0105] All data: Click here to view the commodity sales data of all categories.
[0106] Partial data: Select the time span;
[0107] This week's data: Click here to view this week's product sales data.
[0108] This month's data: Click here to view this month's product sales data.
[0109] Custom time range: Please enter the start date and end date.
[0110] Specific data: Enter the query conditions;
[0111] Product number: Please enter the product number and click query.
[0112] Sales order number: Please enter the sales order number and click query.
[0113] A certain access person selects a sales contract, then selects specific data in the keyword guidance for the display data range, and enters the specific sales order number to query the corresponding sales order.
[0114] Example 9, step 3 includes the following specific steps:
[0115] Step 31, create a keyword library containing all categories of product sales data, and each keyword in the keyword library corresponds to a basic access behavior security level;
[0116] Step 32, adjust the basic access behavior security level based on the target data range to obtain the access behavior security level;
[0117] If the basic access behavior security level is public, no fine-tuning is performed;
[0118] If the basic access behavior security level is internal and sensitive, when the target data range is specific data, no fine-tuning is performed. If the target data range is partial data, the public level is raised by one level. If the target data range is all data, the public level is raised by two levels.
[0119] Each keyword in the keyword library corresponds to a basic access behavior security level. For example, the basic access behavior security level of a sales contract corresponds to the sensitive level. If the target data range selects the custom time range and the entered date range includes all sales contracts, then the public level is raised by two levels to become the top secret level, because retrieving all sales contracts at the same time belongs to the company's top secret and should adopt control measures of refusing to display.
[0120] Embodiment 10, a security access control device for commodity sales, which is used to implement a security access control method for commodity sales. The security access control device includes a data query touch display screen 1, a camera 2, a memory 3, an analysis chip module 4, a handheld intelligent terminal 5, and a commodity sales data server 6. The data query touch display screen 1 is communicatively connected to the commodity sales data server 6 through the Internet. The camera 2 is installed on the housing of the data query touch display screen 1 and is used to capture the facial feature images of the people in front. The memory 3 communicates and interacts with the camera 2 and the data query touch display screen 1 respectively to input keyword data and facial feature data. The analysis chip module 4 includes a visual analysis chip 41 and a data analysis chip 42. The visual analysis chip 41 and the data analysis chip 42 are respectively communicatively connected to the memory 3. The visual analysis chip 41 implements biometric information authentication based on the facial feature data. The data analysis chip 42 analyzes the security level of the access behavior to which the access requirement belongs based on the access requirement keywords, and executes data security control measures based on the security level of the access behavior. The memory 3 is wirelessly communicatively connected to the handheld intelligent terminal 5. The data analysis chip 42 controls the memory 3 to wirelessly interact with the handheld intelligent terminal 5 for security access warning information.
[0121] The above are all the preferred embodiments of the present invention, and the protection scope of the present invention is not limited thereby. Therefore, all equivalent changes made according to the structure, shape, and principle of the present invention shall be covered within the protection scope of the present invention.
Claims
1. A security access control method for commodity sales, characterized in that: The following steps are involved: Step 1: The accessing personnel enters the account information on the data query touch screen (1) to verify the identity of the accessing account; Step 2: Use keywords to guide the account that has passed the account identity verification to obtain the access demand keywords; Step 3: Based on the access requirement keywords, the security level mapping method is used to analyze the access behavior security level to which the access requirement belongs. The access behavior security levels include public level, internal level, sensitive level, confidential level and top secret level. Step 4: Execute data security control measures based on the access behavior security level. The data security control measures include mask display control, display control with designated authorized personnel at the same time, and display rejection control. When it is determined that the security level of the access demand behavior is public, the corresponding product sales data in the product sales data server (6) is directly called and displayed without executing data security control measures; When it is determined that the security level of the access demand belongs to the internal level and the sensitive level, the corresponding commodity sales data in the commodity sales data server (6) is called and displayed after performing mask display control; When it is determined that the security level of the access request belongs to the confidential level, the corresponding commodity sales data in the commodity sales data server (6) is called and the mask display control and the designated authorized personnel are simultaneously executed for display control and then displayed; When the security level of the access request is determined to be top secret, the display rejection control is executed; The control of the simultaneous presence of designated authorized personnel is to first prompt the designated authorized personnel information, then set the designated authorized personnel's presence time limit, and within the designated authorized personnel's presence time limit, the designated authorized personnel enters the account number and password, and performs biometric information authentication. If the authentication is completed, the target data corresponding to the access requirement keyword is retrieved, and the biometric information of the designated authorized personnel and the person accessing the account is continuously verified while the target data is displayed. If the biometric information is lost, the display of the target data stops; The designated authority personnel information is generated by using a random number generation method, all designated authority personnel are numbered, and the designated authority personnel numbers are randomly generated by using the random number generation method. The designated authority personnel information corresponding to the number is called for authentication prompts, and at the same time, a permission matching prompt is sent to the handheld smart terminal (5) of the designated authority personnel based on the network.
2. A method for secure access control for commodity sales according to claim 1, characterized in that: Mask display control is to display only the target data corresponding to the access requirement keyword in the displayed data page, and mask other data on the data page.
3. A method for secure access control for commodity sales according to claim 2, characterized in that: Biometric information authentication is facial authentication. The method for continuously verifying the biometric information of the designated authorized person and the person accessing the account is: calling the camera (2) to continuously capture the facial images of the designated authorized person and the person accessing the account, and analyzing whether the facial images continue to correspond to the designated authorized person and the person accessing the account; if the facial images corresponding to the designated authorized person and the person accessing the account continue to exist, the target data is continuously displayed.
4. A method for secure access control for commodity sales according to claim 3, characterized in that: Deny display control means not displaying the target data, recording the current access information, and sending security access warning information to the administrator.
5. A method for secure access control for commodity sales according to claim 1, characterized in that: In step 1, account access identity verification includes account password verification and biometric information verification.
6. A method for secure access control for commodity sales according to claim 1, characterized in that: Step 2 includes the following specific steps: Step 21, displaying data category keyword guidance, and the interviewer selects the target commodity sales data category keyword according to the commodity sales data category keyword guidance; Step 22, displaying the data range keyword guide, the interviewer selects the target data range according to the data range keyword guide, and the target data range includes all data, part of data and specific data; Partial data refers to target data selected based on the data time span, and specific data refers to a specific single piece of specified data.
7. A method for secure access control for commodity sales according to claim 6, characterized in that: Step 3 includes the following specific steps: Step 31, creating a keyword library containing all commodity sales data categories, each keyword in the keyword library corresponds to a basic access behavior security level; Step 32, adjusting the basic access behavior security level based on the target data range to obtain the access behavior security level; If the basic access behavior security level is public, no fine-tuning is performed; If the basic access behavior security level is internal and sensitive, if the target data range is specific data, no fine-tuning will be performed; if the target data range is partial data, the disclosure level will be increased by one level; if the target data range is all data, the disclosure level will be increased by two levels.
8. A security access control device for commodity sales, characterized in that: A method for implementing a security access control method for commodity sales as described in any one of claims 1 to 7, wherein the security access control device comprises a data query touch screen (1), a camera (2), a memory (3), an analysis chip module (4), a handheld intelligent terminal (5) and a commodity sales data server (6), wherein the data query touch screen (1) is connected to the commodity sales data server (6) via the Internet, the camera (2) is mounted on the housing of the data query touch screen (1) and is used to capture facial feature images of a person in front, and the memory (3) communicates and interacts with the camera (2) and the data query touch screen (1) to input keyword data and facial features. The analysis chip module (4) comprises a visual analysis chip (41) and a data analysis chip (42), the visual analysis chip (41) and the data analysis chip (42) are respectively connected to the memory (3) for communication, the visual analysis chip (41) implements biometric information authentication based on facial feature data, the data analysis chip (42) analyzes the access behavior security level to which the access demand belongs based on the access demand keyword, and executes data security management and control measures based on the access behavior security level, the memory (3) is connected to the handheld smart terminal (5) for wireless communication, and the data analysis chip (42) controls the memory (3) to wirelessly exchange security access warning information with the handheld smart terminal (5).
Citation Information
Patent Citations
Data security management platform for preventing data loss
CN115733681A
Information data security management method, system, equipment and medium
CN119046957A