Security protection method and system for educational resource information data
By analyzing user behavior and using record data in the education platform and dynamically adjusting user permissions, the problem of poor adaptability of RBAC model in a dynamic environment is solved, and more fine-grained permission management and higher data security are achieved.
Patent Information
- Application Number
- CN202510452589.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-11
- Publication Date
- 2025-05-09
- Estimated Expiration
- 2045-04-11
AI Technical Summary
The existing role-based access control (RBAC) model is poorly adaptable in dynamic environments and cannot respond quickly to changes in user permissions, which increases the complexity of permission management and leads to poor data protection effects.
By obtaining RBAC model data, course arrangement data and user account usage record data in the education platform, using user behavior analysis to obtain behavior stability coefficients, dynamically adjust the user's actual permission table, and control permissions based on the permission coefficients in the educational resource authority table.
Real-time monitoring of user behavior and dynamic permission management are realized, ensuring that users only obtain permissions within the actual scope required, prevent excessive authorization or abuse of permissions, and improve the security of educational resource information data.
Smart Images

Figure CN119961961A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data protection, and in particular to a method and system for protecting educational resource information data. Background Art
[0002] In the field of education, the popularity of online courses, electronic textbooks and learning management systems has made it easier to obtain and share educational resources. However, this has been accompanied by a sharp increase in the amount of access and downloads of educational resource information and an increase in the complexity of information. How to effectively manage and protect access control of these educational resource information has become an important issue that needs to be urgently addressed in the current process of educational informatization.
[0003] Currently, the mainstream access control method in education platforms is the RBAC (Role-Based Access Control) model. However, this model has poor adaptability in dynamic environments and cannot respond quickly to changes in user permissions, which increases the complexity of permission management and leads to poor data protection effects. Summary of the invention
[0004] The present invention provides a method and system for protecting the security of educational resource information data to solve the existing problems.
[0005] A security protection method and system for educational resource information data of the present invention adopts the following technical solutions: An embodiment of the present invention provides a method for protecting the security of educational resource information data, the method comprising the following steps: Obtaining RBAC model data for access control in the education platform, as well as course schedule data and user account usage record data in the database, wherein the RBAC model data includes a number of users, roles, and permissions, each user corresponds to an account, and the usage record data includes the account login time, IP address, and device serial number; Use the user's account usage record data to analyze the user's behavior and obtain the user's behavior stability coefficient; Analyze the matters in which users participate based on course schedule data and generate the actual permission table for the user's corresponding role; Analyze the usage environment of the user's corresponding account based on the account login situation, and dynamically adjust the actual permission table based on the behavior stability coefficient to obtain the education resource authority table of the user's corresponding role; The user's various permissions are controlled according to the size of the permission coefficient in the education resource authority table.
[0006] The specific method of analyzing the user's behavior by using the user's account usage record data to obtain the user's behavior stability coefficient includes: For any user's account, obtain the address sequence and device sequence of the account based on all usage record data of the account; Performing login behavior analysis on the login time of the user's corresponding account, obtaining a login interval curve of the account and spectrum data of the login interval curve; Perform change analysis and correlation analysis on address sequences and device sequences, and calculate the user's usage habit factor by combining the spectrum data of the login interval curve; Analyze the changes in the usage habit factor of the user's corresponding account during this login, and calculate the behavior stability coefficient of the account during this login.
[0007] The specific method for obtaining the address sequence and device sequence is as follows: Obtain the IP address corresponding to the user's account at each login, and obtain the sequence formed by the corresponding IP addresses at all logins in chronological order, which is recorded as the initial IP address sequence; Taking the same IP address as one IP address, obtaining several IP addresses included in the initial IP address sequence; Obtain the frequency of each IP address in the initial IP address sequence, sort all types of IP addresses in descending order of frequency, and assign each IP address a sequence number, called the address frequency number. Each IP address corresponds to an address frequency number. Replace each IP address in the initial IP address sequence with the corresponding address frequency number to obtain a sequence consisting of address frequency numbers, which is recorded as the address sequence; And so on, get the initial device serial number sequence and device serial number.
[0008] The specific method for obtaining the usage habit factor is: Analyze the spectrum data of the login interval curve of the user's corresponding account and calculate the usage time factor of the user's corresponding account; According to the correlation between the address sequence and the device sequence and their corresponding distribution, the usage habit factor of the user's corresponding account is calculated.
[0009] The specific method for obtaining the behavior stability coefficient of the account during this login is: Obtain the login time, IP address and device serial number corresponding to the user's corresponding account at the time of this login, obtain the login time sequence, initial IP address sequence and initial device serial number sequence corresponding to the login time, IP address and device serial number at the time of this login, and record them as the new login time sequence, the new initial IP address sequence and the new initial device serial number sequence respectively; Combine the new login time sequence, the new initial IP address sequence, the new initial device serial number sequence, and use the method for obtaining the usage habit factor to calculate the usage habit factor of the account at the time of this login; According to the difference in usage habit factors before and after this login, the user's behavior stability coefficient during this login is obtained.
[0010] The specific method of analyzing the matters in which the user participates based on the course arrangement data and generating the actual permission table of the user's corresponding role includes: Get all the courses in the course schedule data, and subdivide the role permissions based on the course schedule, so that each permission corresponds to a permission value for each course, and get the initial permission table for the user's corresponding role; In the initial permission table, when the user has the permission of the corresponding role, the permission value corresponding to the permission is 1, and when the user does not have the permission of the corresponding role, the permission value of the corresponding permission is 0; The permission values in the initial permission table are adjusted according to the user's course participation, and the permission values of the courses that the user has not participated in are set to 0 to obtain the actual permission table of the user's corresponding role.
[0011] The method of analyzing the usage environment of the user's corresponding account based on the account login situation and dynamically adjusting the actual authority table in combination with the behavior stability coefficient to obtain the education resource authority table of the user's corresponding role includes: Analyze the usage environment conditions of the user's corresponding account based on the account login situation, and calculate the environment permission parameters of the account at the time of this login; Analyze the usage of educational resource information data by the user's corresponding role in the database relative to other users with the same role using different permissions, and calculate the permission sensitivity of each permission of the role; The different permissions in the actual permission table are adjusted in combination with the behavior stability coefficient and permission sensitivity to obtain the educational resource authority table of the user's corresponding role at the time of this login.
[0012] The specific method for obtaining the environment permission parameters is: Obtain the frequency of the device currently logged in by the user account appearing in the database and the number of other accounts that have logged in on the login device; Based on the frequency of the device appearing in the database and the number of other accounts that have logged in to the device, calculate the environment permission parameters of the user's corresponding account at the time of this login.
[0013] The specific method for obtaining the permission sensitivity of each permission is as follows: Constructing a binary array, wherein the elements of the binary array are the behavior stability coefficient and the environment authority parameter, and using the binary array as a login vector corresponding to the user account; According to the Euclidean distance between login vectors, the DBSCAN clustering algorithm is used to cluster the login vectors of all user accounts each time they log in within a preset time range to obtain several clusters. The cluster corresponding to the most common role is obtained, and the users of other roles in the cluster are removed to obtain the role cluster. For any role cluster, the permission sensitivity of each permission is obtained according to the usage of educational resource information data by all users in the role cluster.
[0014] A security protection system for educational resource information data includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of a security protection method for educational resource information data are implemented.
[0015] The beneficial effects of the technical solution of the present invention are: by analyzing the data such as user login time, IP address, device serial number, etc., abnormal behavior or uncommon operation mode can be identified; by analyzing the user's usage record data, generating a behavior stability coefficient, and monitoring the abnormal fluctuation of user behavior, it is possible to accurately find whether the user behavior deviates from the normal behavior pattern; in addition, based on the analysis of the user's actual participation in the course arrangement data, an actual permission table corresponding to the user role can be generated. This table is no longer static, but dynamically adjusted according to the user's actual behavior. This adjustment mechanism can ensure that the user only obtains permissions within the scope of his actual needs, thereby preventing excessive authorization or abuse of permissions. Through multi-level analysis of user behavior, equipment and environment, potential abnormal activities and security vulnerabilities can be identified in time, avoiding the leakage or abuse of education platform data. At the same time, based on the dynamic permission adjustment mechanism, the security risks caused by improper role permission setting can be greatly reduced, and the security of education resource information data is greatly improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0017] Figure 1 A flowchart of the steps of a method for protecting the security of educational resource information data of the present invention; Figure 2It is a schematic diagram of the RBAC model; Figure 3 A schematic diagram of steps for obtaining an address sequence or a device sequence; Figure 4 Express intent for initial permissions; Figure 5 Indicates intent for actual permissions. DETAILED DESCRIPTION
[0018] In order to further explain the technical means and effects adopted by the present invention to achieve the predetermined invention purpose, the following is a detailed description of the security protection method and system for educational resource information data proposed by the present invention, its specific implementation method, structure, characteristics and effects, in combination with the accompanying drawings and preferred embodiments. In the following description, different "one embodiment" or "another embodiment" does not necessarily refer to the same embodiment. In addition, specific features, structures or characteristics in one or more embodiments may be combined in any suitable form.
[0019] Unless defined otherwise, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention belongs.
[0020] The following is a detailed description of a method and system for protecting the security of educational resource information data provided by the present invention in conjunction with the accompanying drawings.
[0021] See also Figure 1 , which shows a flowchart of a method for protecting the security of educational resource information data provided by an embodiment of the present invention, the method comprising the following steps: Step S001: Obtain RBAC model data used for access control in the education platform, as well as course schedule data and user account usage record data in the database.
[0022] It should be noted that the RBAC model consists of three aspects: users, roles, and permissions, which constitute the access rights triplet. Figure 2 The following is a schematic diagram of the RBAC model. Since the RBAC model often defines permissions based on roles, but lacks fine-grained permission control, some users may obtain unnecessary permissions in some cases. For example, a teacher only needs to view educational resources such as test papers for a specific course, but the RBAC model mechanism allows teachers to have access to educational resources for all courses. Therefore, if the teacher's account is stolen, there may be risks such as leakage or malicious changes of educational resources.
[0023] Specifically, in order to implement a security protection method for educational resource information data proposed in this embodiment, it is first necessary to collect RBAC model data for access control on the education platform. The specific process is as follows: Step S101: Obtain the roles of each user in the education platform and the permissions possessed by each role.
[0024] The database of the education platform stores all user accounts, roles, permissions, education resource information and other data on the platform. The database based on the RBAC model usually includes a role module and a permission module.
[0025] As an embodiment, the role module and the authority module may specifically include: Role module: students, teachers, academic staff, administrators.
[0026] Permission module: Student permissions include: accessing course materials (course videos, test questions, test answers, etc.), submitting assignments, participating in discussions and interactions, and viewing personal learning progress and grades.
[0027] Teacher permissions include: creating and managing courses, publishing learning materials, marking assignments, viewing student grades and progress, conducting online discussions, and answering questions.
[0028] The rights of academic affairs staff include: managing student and teacher information, handling course arrangements and scheduling, and generating and publishing various reports (transcripts, attendance records, etc.).
[0029] Administrator permissions include: global settings and management platform, user management (adding, modifying, and deleting users), permission management, and monitoring platform.
[0030] Step S102: Obtain usage record data of each user's account and course schedule data.
[0031] Each user corresponds to an account, and the usage record data and course schedule data of the user's corresponding account in the education platform database are obtained. The usage record data includes the user account login time, IP address and device serial number when the user logs in.
[0032] The course schedule data is a course schedule, which includes course information, teacher information, and student information.
[0033] So far, the RBAC model data, course schedule data and user account usage record data are obtained through the above method.
[0034] Step S002: Analyze the user's behavior using the user's account usage record data to obtain the user's behavior stability coefficient.
[0035] It should be noted that different users have certain uniqueness in their usage habits and the matters they participate in. Therefore, by analyzing users' behavioral habits and the matters they participate in, we can timely adjust users' permissions in different aspects, so as to utilize more fine-grained permission management methods to improve the security of educational resource information data.
[0036] It should be noted that the frequent changes in the device and IP address used to log in to the user's account, as well as the user's abnormal and frequent operations on multiple educational resource information, all indicate that the user account has abnormal behavior.
[0037] Specifically, in step S201, for any user's account, the address sequence and device sequence of the account are obtained according to all usage record data of the account.
[0038] As an embodiment, the method for obtaining the address sequence and the device sequence includes the following steps: First, obtain the IP address corresponding to the user's account at each login, and obtain the sequence formed by the corresponding IP addresses at all logins in chronological order, which is recorded as the initial IP address sequence.
[0039] Then, the same IP address is taken as a type of IP address to obtain several types of IP addresses included in the initial IP address sequence.
[0040] Secondly, obtain the frequency of occurrence of each IP address in the initial IP address sequence, sort all types of IP addresses in descending order of frequency of occurrence, and assign each IP address a serial number, called the address frequency number. Each IP address corresponds to an address frequency number.
[0041] It should be noted that during the sorting process, some IP addresses may have the same frequency. In this case, the IP addresses are sorted in the order of their appearance time. Figure 3 The figure shows a schematic diagram of the steps for obtaining an address sequence or a device sequence, wherein the letters A, B, and C may represent IP addresses or device serial numbers, and A:24 indicates that the frequency of "A" is 24. Then, according to the above sorting rules, the sequence number assigned to A is 1, B is 2, and C is 3. The corresponding address sequence or device sequence is finally obtained by replacement.
[0042] Finally, each IP address in the initial IP address sequence is replaced with the corresponding address frequency number to obtain a sequence composed of address frequency numbers, which is recorded as the address sequence; and so on, the initial device serial number sequence and the device sequence are obtained.
[0043] It should be noted that the address sequence and device sequence obtained by the above method can effectively quantify and reflect the usage behavior of the user account, which is convenient for subsequent behavior analysis of the usage behavior of the user account and helps to establish a user behavior model.
[0044] Step S202, performing login behavior analysis on the login time of the user's corresponding account, and obtaining a login interval curve of the account and spectrum data of the login interval curve.
[0045] As an embodiment, for any user account, the method for acquiring spectrum data of a login interval curve specifically includes: First, sort the login time of user accounts in chronological order to obtain the login time sequence, and calculate the forward difference sequence of the login time sequence to obtain the login interval sequence; Then, a two-dimensional rectangular coordinate system is constructed, and the login interval sequence is mapped to the two-dimensional rectangular coordinate system, wherein the horizontal axis of the two-dimensional rectangular coordinate system is the ordinal number of the element in the login interval sequence, and the vertical axis is the numerical value of the element in the login interval sequence, and the least squares method is used to perform curve fitting on the data points in the two-dimensional rectangular coordinate system to obtain a login interval curve; Finally, the login interval curve is processed by Fast Fourier Transform (FFT) to obtain the spectrum data of the login interval curve.
[0046] It should be noted that the least square method and the fast Fourier transform are both existing algorithms, and are not described in detail in this embodiment.
[0047] Step S203, performing change analysis and correlation analysis on the address sequence and the device sequence, and calculating the user's usage habit factor in combination with the spectrum data of the login interval curve.
[0048] As an embodiment, the step of obtaining the usage habit factor includes: First, the spectrum data of the login interval curve of the user's corresponding account is analyzed to calculate the usage time factor of the user's corresponding account.
[0049] As an embodiment, the specific calculation method of the usage time factor is: ;in, Indicates the usage time factor of the user's corresponding account; The spectrum data representing the logging interval curve frequency values; The spectrum data representing the logging interval curve The amplitude corresponding to the frequency value; Indicates the number of frequency values with non-zero amplitude in the spectrum data of the logging interval curve.
[0050] It should be noted that the usage time factor reflects the regular characteristics of the user account in the usage time interval, and reveals the regularity and change characteristics of the user account login behavior. When the frequency values with amplitudes other than 0 in the spectrum data of the login interval curve of the user's corresponding account are fewer and the amplitudes are larger, the regular characteristics of the user's account in the login time are stronger.
[0051] Then, according to the correlation between the address sequence and the device sequence and their corresponding distribution, the usage habit factor of the user's corresponding account is calculated.
[0052] As an embodiment, the calculation method of the usage habit factor is: ;in, Indicates usage habit factor; Indicates the degree of discreteness of the address sequence, that is, the variance of the element values in the address sequence; Indicates the discreteness of the equipment sequence; Pearson correlation coefficient between address sequence and device sequence; Indicates the number of types of IP addresses included in the initial IP address sequence; Indicates the number of types containing device serial numbers in the initial device serial number sequence; Indicates the usage time factor of the user account; Represents an exponential function with a natural constant as base.
[0053] The discrete degree corresponding to the address sequence and the device sequence is the variance of the element values in the device sequence.
[0054] It should be noted that the usage habit factor reflects the distribution characteristics of the user account in multiple aspects (i.e., usage time, IP address, and device used) during use, so as to describe the regularity of the use of the user account. When the IP address and device used to log in to the user account do not change much during use, the regularity of the behavioral habits of the user account during normal use will be stronger. Similarly, the more regular the login time of the user account, the stronger the regularity of the behavioral habits of the user account during use.
[0055] Step S204, analyzing the change of the usage habit factor of the user's corresponding account during the current login, and calculating the behavior stability coefficient of the account during the current login.
[0056] As an embodiment, the steps of obtaining the behavior stability coefficient of the account during the current login include: First, obtain the login time, IP address and device serial number corresponding to the user's corresponding account at the time of this login, and obtain the login time sequence, initial IP address sequence and initial device serial number sequence corresponding to the login time, IP address and device serial number at the time of this login, and record them as the new login time sequence, new initial IP address sequence and new initial device serial number sequence respectively.
[0057] Then, the usage habit factor of the account at the time of this login is calculated by combining the new login time sequence, the new initial IP address sequence, and the new initial device serial number sequence and using the method for obtaining the usage habit factor.
[0058] Finally, according to the difference in usage habit factors before and after this login, the user's behavior stability coefficient during this login is obtained.
[0059] As an embodiment, the calculation method of the behavior stability coefficient is: ;in, Indicates the user's behavior stability coefficient during this login; Indicates the usage habit factor during this login; Indicates the usage habit factor before this login; Gets the absolute value.
[0060] It should be noted that The usage habit factor is calculated by utilizing the login time sequence, initial IP address sequence and initial device serial number sequence corresponding to the login time, IP address and device serial number that do not include the current login.
[0061] It should be noted that the behavior stability coefficient reflects the probability that a user will have abnormal behavior when using an account. The smaller the behavior stability coefficient, the higher the probability that the user will have abnormal behavior, and the more it is necessary to control or restrict the user's permissions to avoid leakage of educational resource information data.
[0062] At this point, the behavior stability coefficient of the user's corresponding account under this login is obtained through the above method.
[0063] Step S003: Analyze the matters in which the user participates based on the course arrangement data, and generate an actual authority table of the user's corresponding role.
[0064] It should be noted that the permissions of roles in the RBAC model are usually global and static within the system. This will result in the ability to operate on educational resource information data within the global scope of the system when a user account is stolen, which can easily pose a threat to the data security of educational resource information. Therefore, the permissions of the roles corresponding to the users can be subdivided according to the matters in which the users participate, that is, the course schedule, and a permission table for the participating matters can be generated to facilitate more detailed regulation of the corresponding permissions of the users in the future, so that the user's permissions can be managed in a fine-grained manner in a timely manner according to the behavior of the user account in the future, avoiding the leakage and tampering of educational resource information, thereby improving the security of educational resource information.
[0065] Specifically, first, all courses in the course schedule data are obtained, and the permissions of the roles are subdivided in combination with the course schedule, so that each permission corresponds to a permission value between each course, and an initial permission table of the user's corresponding role is obtained. In the initial permission table, when the permission of the user's corresponding role is possessed by the user, the permission value corresponding to the permission is 1, and when the user's corresponding role does not have the permission, the permission value of the corresponding permission is 0.
[0066] It should be noted that if Figure 4 The initial permission statement is shown. Figure 4 The user is "Mr. Zhang", whose corresponding role is teacher. The permissions he has include at least publishing learning materials and marking homework. In the RBAC model, this user has permissions in all courses. In the diagram, when the permission value is 1, it means that the user's role has the corresponding permission in the corresponding course. When the permission value is 0, it means that the user has no permission.
[0067] Then, the permission values in the initial permission table are adjusted according to the user's course participation, and the permission values of the courses that the user has not participated in are set to 0, so as to obtain the actual permission table of the user's corresponding role.
[0068] It should be noted that in the actual teaching process, if the user does not participate in the teaching task of a certain course, then the permission value under the course should be 0. Therefore, by combining the course schedule, the permission values corresponding to the courses that the user does not participate in in the user's initial permission table are adjusted to obtain the corresponding actual permission table. For example: If the user "Teacher Zhang" does not participate in the English teaching task, then Figure 5 Actual authority representations are shown.
[0069] By refining and adjusting the permissions corresponding to the user's role in combination with the course schedule, the granularity of user permission management in the RBAC model has been initially improved. By avoiding the situation where a teacher can access the educational resource information of all courses, the risk of leakage of educational resource information data is reduced and the security protection capability of educational resource information is improved.
[0070] So far, the actual permission table is obtained through the above method.
[0071] Step S004: Analyze the usage environment of the user's corresponding account based on the account login situation, and dynamically adjust the actual authority table in combination with the behavior stability coefficient to obtain the education resource authority table of the user's corresponding role.
[0072] It should be noted that in the actual use of user accounts, the user's role permissions should be dynamically adjusted according to the account usage environment to improve the dynamic response capability of the RBAC model and avoid security risks to educational resource information data through role permissions when there are abnormalities in the account usage environment.
[0073] Specifically, the authority value in the actual authority table is weightedly adjusted using the behavior stability coefficient and the usage environment conditions of the user account to obtain the authority coefficient, and the authority table of the user at the time of this login is obtained, which is recorded as the education resource authority table.
[0074] Step S401, analyzing the usage environment conditions of the user's corresponding account based on the account's login status, and calculating the environment authority parameters of the account at the time of this login.
[0075] First, the frequency with which the device currently logged in by the user account appears in the database and the number of other accounts that have logged in on the login device are obtained.
[0076] Then, based on the frequency of the device appearing in the database and the number of other accounts that have logged in to the device, the environment permission parameters of the user's corresponding account at the time of this login are calculated.
[0077] As an embodiment, the specific calculation method of the environmental authority parameter is: ;in, Indicates the environment permission parameters of the user account during this login; Indicates the frequency of the device currently logged in by the user account appearing in the database; Indicates the average frequency of all devices appearing in the database; Indicates the number of accounts that have logged in on the device where the user account is currently logged in; Indicates the average number of accounts logged in on each device; Represents the preset hyperparameters.
[0078] It should be noted that the hyperparameters are preset based on experience It is 0.1, and can be adjusted according to actual conditions, and is not specifically limited in this embodiment.
[0079] It should be noted that the environment permission parameters Reflects the relative frequency of the user account's current login device in the database. It reflects the relative number of accounts that have logged in to the current device logged in by the user account; the environmental authority parameter reflects the risk of educational resource information leakage when the user account logs in to the device. When the relative frequency is greater and the relative number is smaller, the environmental authority parameter is larger, indicating that the device has fewer user accounts that have logged in multiple times, that is, the possibility that the device is a personal device is higher, and the risk of educational resource information leakage is smaller, so the login environment of the user account is relatively safe.
[0080] Step S402, analyzing the usage of educational resource information data by the user's corresponding role in the database with different permissions relative to other users with the same role, and calculating the permission sensitivity of each permission of the role.
[0081] As an embodiment, a method for obtaining permission sensitivity includes: First, a binary array is constructed, the elements of which are the behavior stability coefficient and the environment authority parameter, respectively, and the binary array is used as a login vector of the corresponding user account.
[0082] Then, according to the Euclidean distance between the login vectors, the DBSCAN clustering algorithm is used to cluster the login vectors of all user accounts each time they log in within a preset time range to obtain several clusters. The cluster corresponding to the most common role is obtained, and users of other roles in the cluster are removed to obtain the role cluster.
[0083] It should be noted that the time range is preset to one month based on experience, and can be adjusted according to actual conditions, and is not specifically limited in this embodiment.
[0084] For example: among several clusters, there is a cluster that contains the most users with the role of "teacher". Then, after removing the users corresponding to roles other than the role of "teacher" in the cluster, the cluster obtained is the role cluster corresponding to the role of "teacher". In addition, when there are multiple roles in a cluster that are the most, there is no conflict, and the cluster can be reused to obtain the role cluster corresponding to each role.
[0085] It should be noted that, since the login vector of an account may be different each time it logs in, repeated counting should be avoided when counting the number of roles in the cluster.
[0086] Finally, for any role cluster, the permission sensitivity of each permission is obtained according to the usage of educational resource information data by all users in the role cluster.
[0087] 1) For any permission, count the total number of times all users view, upload, modify and download educational resource information data using the permission .
[0088] 2) Calculate the permission sensitivity of each permission of the user's corresponding role based on the environmental permission parameters and the user's usage of educational resource information data in the role cluster.
[0089] As an embodiment, the calculation expression of permission sensitivity is: ;in, Indicates the first role of the user in the actual permission table during this login. The permission sensitivity of each permission; Indicates the environment permission parameters of the user account during this login; Indicates that all users in the role cluster corresponding to the user use The total number of times educational resource information data is viewed, uploaded, modified and downloaded by each permission; Indicates the number of permissions that the user has for the corresponding role.
[0090] It should be noted that the sensitivity of permissions reflects the degree to which the corresponding permissions will pose a security threat to educational resource information when the user account logs in this time.
[0091] Step S403, adjusting different permissions in the actual permission table in combination with the behavior stability coefficient and the permission sensitivity, and obtaining the education resource authority table of the user's corresponding role at the time of this login.
[0092] As an embodiment, the method for obtaining the education resource authority table includes: Firstly, the permission values of different permissions in the actual permission table are adjusted using the behavior stability coefficient and permission sensitivity to obtain the permission coefficient.
[0093] As an embodiment, the calculation method of the authority coefficient is: ;in, Indicates the first role of the user in this login. The authority coefficient of each authority; Indicates the user's behavior stability coefficient during this login; Indicates the first role of the user in the actual permission table during this login. The permission sensitivity of each permission; Indicates the first role of the user in the actual permission table. The permission value of each permission; represents the linear normalization function.
[0094] It should be noted that the permission coefficient reflects the probability that there is no data security risk for the corresponding permission and is used to control the corresponding permission.
[0095] Then, the permission value corresponding to each permission in the actual permission table is updated to the corresponding permission coefficient, and the educational resource authority table of the corresponding role of the user at the time of this login is obtained.
[0096] At this point, the educational resource authority table of the user's corresponding role at the time of this login is obtained through the above method.
[0097] Step S005: Manage and control the user's various permissions according to the size of the permission coefficient in the education resource authority table.
[0098] It should be noted that when the behavior pattern of a user account changes during use and is different from previous usage habits, the user account is likely to be stolen. The stolen account may threaten the security of educational resource information data. Therefore, when theft occurs, the user's permissions should be promptly managed and controlled.
[0099] Specifically, a permission coefficient threshold is preset, and when the permission coefficient is less than or equal to the permission coefficient threshold, the permission under the course corresponding to the permission coefficient is closed.
[0100] It should be noted that the authority coefficient is preset to 0.8 based on experience, and can be adjusted according to actual conditions, and is not specifically limited in this embodiment.
[0101] In addition, when a user's permissions are restricted, the user can apply for permission restoration through identity authentication methods such as fingerprint verification, SMS verification, or account permission appeal.
[0102] Through the above steps, the user's various permissions are managed when accessing educational resource information data.
[0103] An embodiment of the present invention provides a security protection system for educational resource information data, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, steps S001 to S005 of a method for security protection of educational resource information data are implemented.
[0104] This embodiment can identify abnormal behavior or uncommon operation modes by analyzing data such as user login time, IP address, and device serial number. By analyzing the user's usage record data, generating a behavior stability coefficient, and monitoring abnormal fluctuations in user behavior, it can accurately detect whether the user behavior deviates from the normal behavior pattern. In addition, based on the analysis of the user's actual participation in matters based on the course schedule data, an actual permission table corresponding to the user role can be generated. This table is no longer static, but is dynamically adjusted according to the user's actual behavior. This adjustment mechanism can ensure that the user only obtains permissions within the scope of his or her actual needs, thereby preventing excessive authorization or abuse of permissions. Through multi-level analysis of user behavior, equipment, and environment, potential abnormal activities and security vulnerabilities can be identified in a timely manner to avoid leakage or abuse of education platform data. At the same time, based on the dynamic permission adjustment mechanism, the security risks caused by improper role permission settings can be greatly reduced, greatly improving the security of educational resource information data.
[0105] It should be noted that the The model is only used to represent negative correlation and constrain the output of the model to be in In the specific implementation, it can be replaced by other models with the same purpose. This embodiment is only based on The model is described as an example without any specific limitation. is the input to the model.
[0106] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the principles of the present invention should be included in the protection scope of the present invention.
Claims
1. A method for protecting the security of educational resource information data, characterized in that: The method comprises the following steps: Obtaining RBAC model data for access control in the education platform, as well as course schedule data and user account usage record data in the database, wherein the RBAC model data includes a number of users, roles, and permissions, each user corresponds to an account, and the usage record data includes the account login time, IP address, and device serial number; Use the user's account usage record data to analyze the user's behavior and obtain the user's behavior stability coefficient; Analyze the matters in which users participate based on course schedule data and generate the actual permission table for the user's corresponding role; Analyze the usage environment of the user's corresponding account based on the account login situation, and dynamically adjust the actual permission table based on the behavior stability coefficient to obtain the education resource authority table of the user's corresponding role; The user's various permissions are controlled according to the size of the permission coefficient in the database corresponding to the education resource authority table.
2. A method for protecting the security of educational resource information data according to claim 1, characterized in that: The specific method of analyzing the user's behavior by using the user's account usage record data to obtain the user's behavior stability coefficient includes: For any user's account, obtain the address sequence and device sequence of the account based on all usage record data of the account; Performing login behavior analysis on the login time of the user's corresponding account, obtaining a login interval curve of the account and spectrum data of the login interval curve; Perform change analysis and correlation analysis on address sequences and device sequences, and calculate the user's usage habit factor by combining the spectrum data of the login interval curve; Analyze the changes in the usage habit factor of the user's corresponding account during this login, and calculate the behavior stability coefficient of the account during this login.
3. A method for protecting the security of educational resource information data according to claim 2, characterized in that: The specific method for obtaining the address sequence and device sequence is: Obtain the IP address corresponding to the user's account at each login, and obtain the sequence formed by the corresponding IP addresses at all logins in chronological order, which is recorded as the initial IP address sequence; Taking the same IP address as one IP address, obtaining several IP addresses included in the initial IP address sequence; Obtain the frequency of each IP address in the initial IP address sequence, sort all types of IP addresses in descending order of frequency, and assign each IP address a sequence number, called the address frequency number. Each IP address corresponds to an address frequency number. Replace each IP address in the initial IP address sequence with the corresponding address frequency number to obtain a sequence consisting of address frequency numbers, which is recorded as the address sequence; And so on, get the initial device serial number sequence and device serial number.
4. A method for protecting the security of educational resource information data according to claim 2, characterized in that: The specific method for obtaining the usage habit factor is: Analyze the spectrum data of the login interval curve of the user's corresponding account and calculate the usage time factor of the user's corresponding account; According to the correlation between the address sequence and the device sequence and their corresponding distribution, the usage habit factor of the user's corresponding account is calculated.
5. A method for protecting the security of educational resource information data according to claim 4, characterized in that: The specific method for obtaining the behavior stability coefficient of the account during this login is: Obtain the login time, IP address and device serial number corresponding to the user's corresponding account at the time of this login, obtain the login time sequence, initial IP address sequence and initial device serial number sequence corresponding to the login time, IP address and device serial number at the time of this login, and record them as the new login time sequence, the new initial IP address sequence and the new initial device serial number sequence respectively; Combine the new login time sequence, the new initial IP address sequence, the new initial device serial number sequence, and use the method for obtaining the usage habit factor to calculate the usage habit factor of the account at the time of this login; According to the difference in usage habit factors before and after this login, the user's behavior stability coefficient during this login is obtained.
6. A method for protecting the security of educational resource information data according to claim 1, characterized in that: The specific method of analyzing the matters in which the user participates based on the course arrangement data and generating the actual permission table of the user's corresponding role includes: Get all the courses in the course schedule data, and subdivide the role permissions based on the course schedule, so that each permission corresponds to a permission value for each course, and get the initial permission table for the user's corresponding role; In the database corresponding to the initial permission table, when the user has the permission of the corresponding role, the permission value corresponding to the permission is 1, and when the user does not have the permission of the corresponding role, the permission value of the corresponding permission is 0; According to the user's course participation, the permission values in the database corresponding to the initial permission table are adjusted, and the permission values of the courses not participated in are set to 0 to obtain the actual permission table of the user's corresponding role.
7. A method for protecting the security of educational resource information data according to claim 1, characterized in that: The method of analyzing the usage environment of the user's corresponding account based on the account login situation and dynamically adjusting the actual authority table in combination with the behavior stability coefficient to obtain the education resource authority table of the user's corresponding role includes: Analyze the usage environment conditions of the user's corresponding account based on the account login situation, and calculate the environment permission parameters of the account at the time of this login; Analyze the usage of educational resource information data by the user's corresponding role in the database relative to other users with the same role using different permissions, and calculate the permission sensitivity of each permission of the role; The different permissions in the database corresponding to the actual permission table are adjusted in combination with the behavior stability coefficient and permission sensitivity to obtain the educational resource authority table of the user's corresponding role at the time of this login.
8. A method for protecting the security of educational resource information data according to claim 7, characterized in that: The specific method for obtaining the environment permission parameters is: Obtain the frequency of the device currently logged in by the user account appearing in the database and the number of other accounts that have logged in on the login device; Based on the frequency of the device appearing in the database and the number of other accounts that have logged in to the device, calculate the environment permission parameters of the user's corresponding account at the time of this login.
9. A method for protecting the security of educational resource information data according to claim 7, characterized in that: The specific method for obtaining the permission sensitivity of each permission is as follows: Constructing a binary array, wherein the elements of the binary array are the behavior stability coefficient and the environment authority parameter, and using the binary array as a login vector corresponding to the user account; According to the Euclidean distance between login vectors, the DBSCAN clustering algorithm is used to cluster the login vectors of all user accounts each time they log in within a preset time range to obtain several clusters. The cluster corresponding to the most common role is obtained, and the users of other roles in the cluster are removed to obtain the role cluster. For any role cluster, the permission sensitivity of each permission is obtained according to the usage of educational resource information data by all users in the role cluster.
10. A security protection system for educational resource information data, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the steps of a method for security protection of educational resource information data as described in any one of claims 1 to 9 are implemented.
Citation Information
Patent Citations
Electronic resource database malicious agent protection method and device, equipment and medium
CN115859326A
Security access control method and system suitable for cloud computing environment
CN119011304A
Data security management system based on Internet of Things
CN119377989A
Intelligent user permission conflict detection method and system
CN119622680A
Intelligent education management system based on multi-user cooperation
CN119741171A