A security protection method and system for educational resource information data

By analyzing user behavior and usage record data in the education platform and dynamically adjusting user permissions, the problem of poor adaptability of RBAC model in a dynamic environment is solved, and efficient security protection of educational resource information data is achieved.

CN119961961BActive Publication Date: 2025-07-01CHINA UNIV OF MINING & TECH +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510452589.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-11
Publication Date
2025-07-01
Estimated Expiration
2045-04-11

AI Technical Summary

Technical Problem

The existing role-based access control (RBAC) model is poorly adaptable in dynamic environments and cannot respond quickly to changes in user permissions, which increases the complexity of permission management and leads to poor data protection effects.

Method used

By obtaining RBAC model data of the education platform, course arrangement data and user account usage record data, using user behavior analysis to obtain behavior stability coefficients, dynamically adjust the user's actual permission table, and control permissions based on the permission coefficients in the educational resource authority table.

Benefits of technology

It realizes fine-grained management of user permissions, ensures that users only obtain permissions within the scope they actually need, prevents excessive authorization or abuse of permissions, and improves the security of educational resource information data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119961961B_ABST
    Figure CN119961961B_ABST
Patent Text Reader

Abstract

The present invention relates to the technical field of data protection, and specifically relates to a security protection method and system for educational resource information data, including: performing behavior analysis on a user by using the usage record data of the user's account to obtain the user's behavior stability coefficient, analyzing the matters participated by the user based on the course arrangement data to generate an actual permission table for the corresponding role of the user, analyzing the usage environment of the user's corresponding account based on the login situation of the account, and dynamically adjusting the actual permission table in combination with the behavior stability coefficient to obtain an educational resource authority table for the corresponding role of the user, and controlling each permission of the user according to the magnitude of the permission coefficient in the educational resource authority table. The present invention effectively optimizes the dynamic permission adjustment mechanism of the RBAC model and greatly improves the security of educational resource information data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data protection, and in particular to a method and system for protecting educational resource information data. Background Art

[0002] In the field of education, the popularity of online courses, electronic textbooks and learning management systems has made it easier to obtain and share educational resources. However, this has been accompanied by a sharp increase in the amount of access and downloads of educational resource information and an increase in the complexity of information. How to effectively manage and protect access control of these educational resource information has become an important issue that needs to be urgently addressed in the current process of educational informatization.

[0003] Currently, the mainstream access control method in education platforms is the RBAC (Role-Based Access Control) model. However, this model has poor adaptability in dynamic environments and cannot respond quickly to changes in user permissions, which increases the complexity of permission management and leads to poor data protection effects. Summary of the invention

[0004] The present invention provides a method and system for protecting the security of educational resource information data to solve the existing problems.

[0005] A security protection method and system for educational resource information data of the present invention adopts the following technical solutions:

[0006] An embodiment of the present invention provides a method for protecting the security of educational resource information data, the method comprising the following steps:

[0007] Obtaining RBAC model data for access control in the education platform, as well as course schedule data and user account usage record data in the database, wherein the RBAC model data includes a number of users, roles, and permissions, each user corresponds to an account, and the usage record data includes the account login time, IP address, and device serial number;

[0008] Use the user's account usage record data to analyze the user's behavior and obtain the user's behavior stability coefficient;

[0009] Analyze the matters in which users participate based on course schedule data and generate the actual permission table for the user's corresponding role;

[0010] Analyze the usage environment of the user's corresponding account based on the account login situation, and dynamically adjust the actual permission table based on the behavior stability coefficient to obtain the education resource authority table of the user's corresponding role;

[0011] The user's various permissions are controlled according to the size of the permission coefficient in the education resource authority table.

[0012] Performing behavior analysis on a user by using the usage record data of the user's account to obtain the user's behavior stability coefficient, the specific method includes:

[0013] For any user's account, according to all the usage record data of the account, obtain the address sequence and device sequence of the account;

[0014] Perform login behavior analysis on the login time of the user's corresponding account to obtain the login interval curve of the account and the spectrum data of the login interval curve;

[0015] Perform change analysis and correlation analysis on the address sequence and device sequence, and combine with the spectrum data of the login interval curve to calculate the usage habit factor of the user;

[0016] Analyze the change situation of the usage habit factor when the user's corresponding account logs in this time, and calculate the behavior stability coefficient of the account when logging in this time.

[0017] The specific method for obtaining the address sequence and device sequence is:

[0018] Obtain the IP address corresponding to the user's account each time it logs in, and obtain the sequence formed by the corresponding IP addresses at all logins according to the time sequence, which is recorded as the initial IP address sequence;

[0019] Regard the same IP address as one kind of IP address, and obtain several kinds of IP addresses included in the initial IP address sequence;

[0020] Obtain the frequency of occurrence of each kind of IP address in the initial IP address sequence, sort all kinds of IP addresses in descending order of the frequency of occurrence, and assign a serial number to each IP address, which is called the address frequency number, and each kind of IP address corresponds to an address frequency number;

[0021] Replace each IP address in the initial IP address sequence with the corresponding address frequency number to obtain a sequence composed of address frequency numbers, which is recorded as the address sequence;

[0022] And so on, obtain the initial device serial number sequence and the device sequence.

[0023] The specific method for obtaining the usage habit factor is:

[0024] Analyze the spectrum data of the login interval curve of the user's corresponding account, and calculate the usage time factor of the user's corresponding account;

[0025] According to the correlation between the address sequence and the device sequence and their respective corresponding distribution situations, calculate the usage habit factor of the user's corresponding account.

[0026] The specific method for obtaining the behavior stability coefficient of the account during this login is as follows:

[0027] Obtain the login time, IP address, and device serial number corresponding to the user's account during this login, and obtain a login time sequence, an initial IP address sequence, and an initial device serial number sequence corresponding to the login time, IP address, and device serial number during this login, which are respectively denoted as the new login time sequence, the new initial IP address sequence, and the new initial device serial number sequence;

[0028] Combine the new login time sequence, the new initial IP address sequence, and the new initial device serial number sequence, and use the method for obtaining the usage habit factor to calculate the usage habit factor of the account during this login;

[0029] Based on the difference in the usage habit factors before and after this login, obtain the behavior stability coefficient of the user during this login.

[0030] The specific method for analyzing the matters participated by the user based on the course arrangement data and generating the actual permission table for the user's corresponding role includes:

[0031] Obtain all the courses in the course arrangement data, and subdivide the permissions of the role in combination with the course arrangement, so that there is a permission value corresponding to each permission and each course, and obtain the initial permission table for the user's corresponding role;

[0032] In the initial permission table, when the permission of the user's corresponding role is possessed by the user, the permission value corresponding to the permission is 1, and when the user's corresponding role does not possess the permission, the permission value corresponding to the permission is 0;

[0033] Adjust the permission values in the initial permission table according to the user's course participation situation, and set the permission values under the courses not participated to 0 to obtain the actual permission table for the user's corresponding role.

[0034] The specific method for analyzing the usage environment of the user's corresponding account based on the login situation of the account and dynamically adjusting the actual permission table in combination with the behavior stability coefficient to obtain the educational resource authority table for the user's corresponding role includes:

[0035] Analyze the usage environment conditions of the user's corresponding account based on the login situation of the account, and calculate the environmental permission parameter of the account during this login;

[0036] Analyze the usage situation of the user's corresponding role in the database using different permissions for educational resource information data compared with other users with the same role, and calculate the permission sensitivity of each permission of the role;

[0037] Adjust different permissions in the actual permission table by combining the behavior stability coefficient and the permission sensitivity to obtain the educational resource authority table for the corresponding role of the user during this login.

[0038] The specific method for obtaining the environmental permission parameter is as follows:

[0039] Obtain the frequency of the device currently logged in by the user account in the database and the number of other accounts logged in on the logged-in device.

[0040] According to the frequency of the device in the database and the number of other accounts logged in on the device, calculate the environmental permission parameter of the user's corresponding account during this login.

[0041] The specific method for obtaining the permission sensitivity of each permission is as follows:

[0042] Construct a binary array, where the elements in the binary array are the behavior stability coefficient and the environmental permission parameter respectively, and use the binary array as the login vector of the corresponding user account.

[0043] According to the Euclidean distance between the login vectors, and use the DBSCAN clustering algorithm to cluster the login vectors of all user accounts each time they log in within a preset time range, obtain several clustering clusters, obtain the clustering cluster corresponding to the most of each role and remove the users of other roles in the clustering cluster to obtain the role cluster.

[0044] For any role cluster, obtain the permission sensitivity of each permission according to the usage of educational resource information data by all users in the role cluster.

[0045] A security protection system for educational resource information data, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the steps of the security protection method for educational resource information data described above.

[0046] The beneficial effects of the technical solution of the present invention are as follows: By analyzing data such as the user login time, IP address, and device serial number, abnormal behaviors or uncommon operation patterns can be identified. By analyzing the user's usage record data, a behavior stability coefficient is generated to monitor abnormal fluctuations in the user's behavior, and it can accurately detect whether there is a deviation between the user's behavior and the normal behavior pattern. In addition, by analyzing the user's actual participation items based on the course arrangement data, an actual permission table corresponding to the user's role can be generated. This table is no longer static but dynamically adjusted according to the user's actual behavior. This adjustment mechanism can ensure that the user only obtains permissions within the scope of their actual needs, thereby preventing over-authorization or permission abuse. Through multi-level analysis of the user's behavior, devices, and environment, potential abnormal activities and security vulnerabilities can be identified in a timely manner, avoiding the leakage or abuse of educational platform data. At the same time, based on the dynamic permission adjustment mechanism, the security risks caused by improper role permission settings can be greatly reduced, and the security of educational resource information data is significantly improved. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0048] Figure 1 It is a step flow chart of a security protection method for educational resource information data of the present invention;

[0049] Figure 2 It is a schematic diagram of the RBAC model;

[0050] Figure 3 It is a schematic diagram of the acquisition steps of the address sequence or device sequence;

[0051] Figure 4 It is a schematic diagram of the initial permission table;

[0052] Figure 5 It is a schematic diagram of the actual permission table. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0053] To further elaborate on the technical means and effects adopted by the present invention to achieve the predetermined invention purpose, the following specifically describes, with reference to the accompanying drawings and preferred embodiments, a security protection method and system for educational resource information data according to the present invention, including its specific implementation manners, structures, features, and effects. In the following description, different "one embodiment" or "another embodiment" do not necessarily refer to the same embodiment. In addition, the specific features, structures, or characteristics in one or more embodiments can be combined in any suitable form.

[0054] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the technical field to which the present invention belongs.

[0055] The following specifically describes the specific solutions of a security protection method and system for educational resource information data provided by the present invention with reference to the accompanying drawings.

[0056] Please refer to Figure 1 , which shows a flowchart of the steps of a security protection method for educational resource information data provided by an embodiment of the present invention. The method includes the following steps:

[0057] Step S001: Obtain the RBAC model data for access control in the educational platform, as well as the course schedule data and the usage record data of user accounts in the database.

[0058] It should be noted that the RBAC model consists of three aspects: users, roles, and permissions, forming an access permission triple. As Figure 2 shown in the schematic diagram of the RBAC model, since the RBAC model often defines permissions according to roles, but lacks the fine-grained control of permissions, it may cause some users to obtain unnecessary permissions in some cases. For example: a teacher only needs to view educational resources such as test papers for specific courses, but due to the mechanism of the RBAC model, the teacher has access permissions to all educational resources of all courses. Therefore, if the teacher's account is stolen, there may be risks such as leakage or malicious modification of educational resources.

[0059] Specifically, in order to implement the security protection method for educational resource information data proposed in this embodiment, first, it is necessary to collect the RBAC model data for access control on the educational platform. The specific process is as follows:

[0060] Step S101: Obtain the roles of each user and the permissions owned by each role in the educational platform.

[0061] In the database of the educational platform, all user accounts, roles, permissions, educational resource information, etc. of the platform are stored. The database based on the RBAC model usually includes a role module and a permission module.

[0062] As an embodiment, the role module and the permission module may specifically include:

[0063] Role module: students, teachers, educational administrators, administrators.

[0064] Permission module: The permissions of students include: accessing course materials (course videos, test questions, test answers, etc.), submitting assignments, participating in discussions and interactions, and viewing personal learning progress and grades.

[0065] The permissions of teachers include: creating and managing courses, publishing learning materials, grading assignments, viewing students' grades and progress, and conducting online discussions and answering questions.

[0066] The permissions of educational administrators include: managing student information and teacher information, handling course arrangements and scheduling, and generating and publishing various reports (transcripts, attendance records, etc.).

[0067] The permissions of administrators include: globally setting up and managing the platform, user management (adding, modifying, and deleting users), permission management, and monitoring the platform.

[0068] Step S102: Obtain the usage record data of each user's account and the course arrangement data.

[0069] Each user corresponds to an account. Obtain the usage record data of the user's corresponding account and the course arrangement data in the education platform database. The usage record data includes the login time, IP address, and device serial number of the account when the user logs in.

[0070] The course arrangement data is a course schedule, which includes course information, teacher information, and student information.

[0071] So far, the RBAC model data, the course arrangement data, and the usage record data of the user's account are obtained through the above method.

[0072] Step S002: Use the usage record data of the user's account to analyze the user's behavior and obtain the user's behavior stability coefficient.

[0073] It should be noted that different users have certain uniqueness in their usage habits and the matters they participate in. Therefore, by analyzing the habits and matters of users' behaviors, the permissions of users in different aspects can be adjusted in a timely manner to improve the security of educational resource information data with a more fine-grained permission management method.

[0074] It should be noted that the frequent change of the device and IP address logged in by the user's account, as well as the abnormal and frequent operations of the user on multiple educational resource information, these behaviors all indicate that there are abnormal behaviors in the user's account.

[0075] Specifically, in step S201, for any user's account, based on all usage record data of the account, an address sequence and a device sequence of the account are obtained.

[0076] As an embodiment, the steps included in the method for obtaining the address sequence and the device sequence are as follows:

[0077] First, obtain the IP address corresponding to the user's account at each login, and obtain the sequence formed by the corresponding IP addresses at all logins according to the time sequence, which is denoted as the initial IP address sequence.

[0078] Then, regard the same IP address as one kind of IP address, and obtain several kinds of IP addresses included in the initial IP address sequence.

[0079] Secondly, obtain the frequency of occurrence of each kind of IP address in the initial IP address sequence, sort all kinds of IP addresses in descending order of the frequency of occurrence, and assign a serial number to each IP address, which is called the address frequency number, and each kind of IP address corresponds to an address frequency number.

[0080] It should be noted that in the sorting process, there may be some IP addresses with the same frequency. At this time, sort them in the order of the time sequence of the occurrence of the IP addresses. As Figure 3 shown in the schematic diagram of the steps for obtaining the address sequence or the device sequence, where the letters A, B, and C can represent the IP address or the device serial number, A: 24 means that the frequency of "A" is 24. Then, according to the above sorting rules, the serial number assigned to A is 1, B is 2, and C is 3. Through substitution, the corresponding address sequence or device sequence is finally obtained.

[0081] Finally, replace each IP address in the initial IP address sequence with the corresponding address frequency number to obtain a sequence composed of address frequency numbers, which is denoted as the address sequence; and so on, obtain the initial device serial number sequence and the device sequence.

[0082] It should be noted that the address sequence and the device sequence obtained by the above method can effectively quantify and reflect the usage behavior of the user account, which is convenient for subsequent behavior analysis of the usage behavior of the user account and helps to establish a user behavior model.

[0083] In step S202, perform a login behavior analysis on the login time of the user's corresponding account, and obtain the login interval curve of the account and the spectrum data of the login interval curve.

[0084] As an embodiment, for any user's account, the method for obtaining the spectrum data of the login interval curve specifically includes:

[0085] First, sort the login times of the user accounts in chronological order to obtain a login time sequence, calculate the forward difference sequence of the login time sequence, and obtain a login interval sequence;

[0086] Then, construct a two-dimensional rectangular coordinate system, map the login interval sequence into the two-dimensional rectangular coordinate system, where the horizontal axis of the two-dimensional rectangular coordinate system is the ordinal number of the elements in the login interval sequence, and the vertical axis is the numerical value of the elements in the login interval sequence, and use the least squares method to perform curve fitting on the data points in the two-dimensional rectangular coordinate system to obtain a login interval curve;

[0087] Finally, use the Fast Fourier Transform (FFT) to process the login interval curve to obtain the spectral data of the login interval curve.

[0088] It should be noted that both the least squares method and the Fast Fourier Transform are existing algorithms, and will not be specifically described in this embodiment.

[0089] Step S203: Perform change analysis and correlation analysis on the address sequence and the device sequence, and combine the spectral data of the login interval curve to calculate the usage habit factor of the user.

[0090] As an embodiment, the steps for obtaining the usage habit factor include:

[0091] First, analyze the spectral data of the login interval curve of the user's corresponding account, and calculate the usage time factor of the user's corresponding account.

[0092] As an embodiment, the specific calculation method of the usage time factor is:

[0093] ; where, represents the usage time factor of the user's corresponding account; represents the th frequency value in the spectral data of the login interval curve; represents the amplitude corresponding to the th frequency value in the spectral data of the login interval curve; represents the number of frequency values with non-zero amplitudes in the spectral data of the login interval curve.

[0094] It should be noted that the usage time factor reflects the regular characteristics of the user account in terms of usage time intervals, reveals the regularity and change characteristics of the user account login behavior. When the number of frequency values with non-zero amplitudes in the spectral data of the login interval curve of the user's corresponding account is smaller and the amplitudes are larger, the regular characteristics of the user's account in terms of login time are stronger.

[0095] Then, according to the correlation between the address sequence and the device sequence and their respective corresponding distribution situations, calculate the usage habit factor of the user's corresponding account.

[0096] As an embodiment, the calculation method of the usage habit factor is:

[0097] ; where represents the usage habit factor; represents the dispersion degree of the address sequence, that is, the variance of the element values in the address sequence; represents the dispersion degree of the device sequence; represents the Pearson correlation coefficient between the address sequence and the device sequence; represents the number of types of IP addresses included in the initial IP address sequence; represents the number of types of device serial numbers included in the initial device serial number sequence; represents the usage time factor of the user account; represents the exponential function with the natural constant as the base.

[0098] Among them, the dispersion degrees corresponding to the address sequence and the device sequence are the variances of the element values in the device sequence.

[0099] It should be noted that the usage habit factor reflects the distribution characteristics of the user account in multiple aspects (i.e., usage time, IP address, and used device) during the usage process, so as to describe the regularity degree of the user account usage. When the IP addresses logged in and the used devices during the usage process of the user account change little, then the regularity shown by the user account's behavior habits during normal usage is stronger. Similarly, when the login time of the user account is more regular, then the regularity shown by the user account's behavior habits during the usage process is also stronger.

[0100] Step S204, analyze the change situation of the usage habit factor of the user's corresponding account during this login, and calculate the behavior stability coefficient of the account during this login.

[0101] As an embodiment, the steps for obtaining the behavior stability coefficient of the account during this login include:

[0102] First, obtain the login time, IP address, and device serial number corresponding to the user's corresponding account during this login, and obtain the login time sequence, initial IP address sequence, and initial device serial number sequence corresponding to the login time, IP address, and device serial number during this login respectively, and record them as the new login time sequence, new initial IP address sequence, and new initial device serial number sequence respectively.

[0103] Then, combine the new login time series, the new initial IP address series, and the new initial device serial number series, and use the method for obtaining the usage habit factor to calculate the usage habit factor of the account during this login.

[0104] Finally, based on the difference in the usage habit factors before and after this login, obtain the behavior stability coefficient of the user during this login.

[0105] As an embodiment, the calculation method of the behavior stability coefficient is:

[0106] ; where represents the behavior stability coefficient of the user during this login; represents the usage habit factor during this login; represents the usage habit factor before this login; represents obtaining the absolute value.

[0107] It should be noted that is the usage habit factor calculated by using the login time series, the initial IP address series, and the initial device serial number series corresponding to the login time, IP address, and device serial number that do not include this login.

[0108] It should be noted that the behavior stability coefficient reflects the probability of abnormal behavior of the user when using the account. The smaller the behavior stability coefficient, the higher the probability of abnormal behavior of the user, and the more necessary it is to control or restrict the user's permissions to avoid the leakage of educational resource information data.

[0109] So far, the behavior stability coefficient of the user corresponding to the account under this login is obtained through the above method.

[0110] Step S003: Analyze the matters participated by the user based on the course arrangement data, and generate an actual permission table for the user's corresponding role.

[0111] It should be noted that the permissions of roles in the RBAC model are usually global and static within the system, which may lead to the operation of educational resource information data within the global scope of the system when the user account is stolen, posing a great threat to the data security of educational resource information. Therefore, according to the matters participated by the user, that is, the course arrangement, the permissions of the user's corresponding role can be subdivided to generate a permission table for the participated matters, so as to facilitate more detailed regulation of the user's corresponding permissions in the future, and to facilitate fine-grained management of the user's permissions according to the behavior of the user account in the future, avoiding problems such as leakage and tampering of educational resource information, thereby improving the security of educational resource information.

[0112] Specifically, first, all courses in the course schedule data are obtained, and the permissions of the role are subdivided in combination with the course schedule, so that there is a permission value corresponding to each permission and each course, and an initial permission table for the user's corresponding role is obtained. In the initial permission table, when the permission of the user's corresponding role is possessed by the user, the permission value corresponding to the permission is 1, and when the user's corresponding role does not have the permission, the permission value of the corresponding permission is 0.

[0113] It should be noted that, as Figure 4 shown in the schematic diagram of the initial permission table, Figure 4 the user in it is "Teacher Zhang", whose corresponding role is teacher, and at least has the permissions to release learning materials and correct homework. In the RBAC model, the permissions of this user are possessed in all courses. In the schematic diagram, when the permission value is 1, it means that the role of this user has the corresponding permission under the corresponding course, and when the permission value is 0, it means that the permission is not possessed.

[0114] Then, according to the user's course participation situation, the permission values in the initial permission table are adjusted, and the permission values under the courses not participated are set to 0, and an actual permission table for the user's corresponding role is obtained.

[0115] It should be noted that in the actual teaching process, if a user does not participate in the teaching task of a certain course, the permission value of this user under this course should be 0. Therefore, by combining the course schedule table, the permission values corresponding to the courses not participated by the user in the user's initial permission table are adjusted to obtain the corresponding actual permission table. For example: if the user "Teacher Zhang" does not participate in the teaching task of English, then as Figure 5 shown in the schematic diagram of the actual permission table.

[0116] By combining the course schedule table to refine and adjust the permissions corresponding to the user's role, the fine-grainedness of user permission management in the RBAC model is initially improved. By avoiding the situation that a teacher can access the educational resource information of all courses, the risk of leakage of educational resource information data is reduced, and the security protection ability of educational resource information is improved.

[0117] So far, the actual permission table is obtained through the above method.

[0118] Step S004: Analyze the usage environment of the user's corresponding account based on the login situation of the account, and dynamically adjust the actual permission table in combination with the behavior stability coefficient to obtain an educational resource authority table for the user's corresponding role.

[0119] It should be noted that during the actual use of the user account, the role permissions of the user should be dynamically adjusted according to the usage environment of the account to improve the dynamic response ability of the RBAC model and avoid security risks to the educational resource information data through role permissions when there are abnormalities in the account usage environment.

[0120] Specifically, the permission value in the actual permission table is weighted and adjusted by using the behavior stability coefficient and the usage environment conditions of the user account to obtain the permission coefficient, and the permission table of the user at the time of this login is obtained, which is recorded as the educational resource authority table.

[0121] Step S401: Analyze the usage environment conditions of the user's corresponding account based on the login situation of the account, and calculate the environmental permission parameter of the account at the time of this login.

[0122] First, obtain the frequency of the device currently logged in by the user account in the database and the number of other accounts logged in on the logged-in device.

[0123] Then, calculate the environmental permission parameter of the user's corresponding account at the time of this login according to the frequency of the device in the database and the number of other accounts logged in on the device.

[0124] As an embodiment, the specific calculation method of the environmental permission parameter is:

[0125] ; where represents the environmental permission parameter of the user account at the time of this login; represents the frequency of the device currently logged in by the user account in the database; represents the average frequency of all devices in the database; represents the number of accounts logged in on the device currently logged in by the user account; represents the average number of accounts logged in on each device; represents a preset hyperparameter.

[0126] It should be noted that the hyperparameter is preset to be 0.1 according to experience and can be adjusted according to the actual situation. This embodiment does not make specific limitations.

[0127] It should be noted that in the environmental permission parameter reflects the relative frequency of the device currently logged in by the user account in the database, reflects the relative number of accounts that have been logged in on the current device where the user account logs in; the environmental permission parameter reflects the risk degree of educational resource information leakage on the device where the user account logs in. When the relative frequency is larger and the relative number is smaller, the environmental permission parameter is larger, indicating that the user accounts logged in multiple times on the device are fewer, that is, the possibility that the device belongs to a personal device is higher, then the risk degree of educational resource information leakage is smaller, and thus the login environment of the user account is relatively secure.

[0128] Step S402: Analyze the usage of educational resource information data by the user's corresponding role in the database with different permissions relative to other users with the same role, and calculate the permission sensitivity of each permission of the role.

[0129] As an embodiment, the method for obtaining the permission sensitivity includes:

[0130] First, construct a binary array, where the elements in the binary array are the behavior stability coefficient and the environmental permission parameter respectively, and use the binary array as the login vector of the corresponding user account.

[0131] Then, according to the Euclidean distance between the login vectors, and use the DBSCAN clustering algorithm to cluster the login vectors of all user accounts each time they log in within a preset time range, obtain several clustering clusters, and obtain the clustering cluster corresponding to the most of each role and remove the users of other roles in the clustering cluster to obtain the role cluster.

[0132] It should be noted that according to experience, the preset time range is one month, which can be adjusted according to the actual situation, and this embodiment does not make specific limitations.

[0133] For example: among several clustering clusters, there is a clustering cluster with the largest number of users with the role of "teacher", then the clustering cluster obtained by removing the users corresponding to the roles other than the "teacher" role in this clustering cluster is the role cluster corresponding to the "teacher" role; in addition, when there are multiple roles with the largest number in a clustering cluster, there is no conflict, and this clustering cluster can be reused to obtain the role cluster corresponding to each role.

[0134] It should be noted that since the login vector of an account may be different each time it logs in, duplicate statistics should be avoided when counting the number of roles in the clustering cluster.

[0135] Finally, for any role cluster, obtain the permission sensitivity of each permission according to the usage of educational resource information data by all users in the role cluster.

[0136] 1). For any permission, count the total number of times all users view, upload, modify, and download educational resource information data using the permission 。

[0137] 2). Calculate the permission sensitivity of each permission of the user's corresponding role according to the environmental permission parameters and the usage of educational resource information data by users in the role cluster.

[0138] As an embodiment, the calculation expression of the permission sensitivity is:

[0139] ; where represents the permission sensitivity of the th permission of the user's corresponding role in the actual permission table during this login; represents the environmental permission parameters of the user account during this login; represents the total number of times all users in the role cluster of the user's corresponding role view, upload, modify, and download educational resource information data using the th permission; represents the number of permissions of the user's corresponding role.

[0140] It should be noted that the permission sensitivity reflects the degree of security threat that the corresponding permission will pose to educational resource information when the user account logs in this time.

[0141] Step S403: Adjust different permissions in the actual permission table by combining the behavior stability coefficient and the permission sensitivity to obtain the educational resource authority table of the user's corresponding role during this login.

[0142] As an embodiment, the method for obtaining the educational resource authority table includes:

[0143] First, adjust the permission values of different permissions in the actual permission table by using the behavior stability coefficient and the permission sensitivity to obtain the permission coefficient.

[0144] As an embodiment, the calculation method of the permission coefficient is:

[0145] ; where represents the permission coefficient of the th permission of the user's corresponding role during this login; represents the behavior stability coefficient of the user during this login; represents the permission sensitivity of the th permission of the user's corresponding role in the actual permission table during this login; represents the permission value of the th permission of the user's corresponding role in the actual permission table; represents the linear normalization function.

[0146] It should be noted that the permission coefficient reflects the probability that there is no data security risk for the corresponding permission and is used to control the corresponding permission.

[0147] Then, update the permission values corresponding to each permission in the actual permission table to the corresponding permission coefficients to obtain the educational resource authority table of the corresponding role of the user at the time of this login.

[0148] So far, the educational resource authority table of the corresponding role of the user at the time of this login is obtained through the above method.

[0149] Step S005: Control each permission of the user according to the size of the permission coefficient in the educational resource authority table.

[0150] It should be noted that when the behavior pattern of the user account changes during use and is different from the previous usage habits, it is very likely that the user's account has been stolen. Therefore, the stolen account may threaten the security of the educational resource information data. Therefore, when a theft occurs, the user's permissions should be controlled in a timely manner.

[0151] Specifically, preset a permission coefficient threshold. When the permission coefficient is less than or equal to the permission coefficient threshold, close the permissions under the course corresponding to the permission coefficient.

[0152] It should be noted that according to experience, the preset permission coefficient is 0.8, which can be adjusted according to the actual situation, and no specific limitation is made in this embodiment.

[0153] In addition, after the user's permissions are restricted, the user can apply for permission restoration through identity verification methods such as fingerprint verification and SMS verification or through the method of appealing for account permissions.

[0154] Through the above steps, the control of each permission of the user when accessing educational resource information data is completed.

[0155] An embodiment of the present invention provides a security protection system for educational resource information data, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the steps of a security protection method for educational resource information data in steps S001 to S005.

[0156] In this embodiment, by analyzing data such as the user login time, IP address, device serial number, etc., abnormal behaviors or uncommon operation patterns can be identified. By analyzing the user's usage record data, a behavior stability coefficient is generated to monitor abnormal fluctuations in the user's behavior, and it can accurately detect whether there are deviations between the user's behavior and the normal behavior pattern. In addition, based on the analysis of the user's actual participation items according to the course arrangement data, an actual permission table corresponding to the user's role can be generated. This table is no longer static but dynamically adjusted according to the user's actual behavior. This adjustment mechanism can ensure that the user only obtains permissions within the scope of their actual needs, thereby preventing over-authorization or permission abuse. Through multi-level analysis of the user's behavior, devices, and environment, potential abnormal activities and security vulnerabilities can be identified in a timely manner, avoiding the leakage or abuse of educational platform data. At the same time, based on the dynamic permission adjustment mechanism, the security risks caused by improper role permission settings can be greatly reduced, and the security of educational resource information data is greatly improved.

[0157] It should be noted that the model used in this embodiment is only used to represent the negative correlation relationship and restrict the result of the model output to be within the interval. Specifically in implementation, it can be replaced with other models with the same purpose. This embodiment only takes the model as an example for description and does not make specific limitations on it, where refers to the input of this model.

[0158] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the principle of the present invention shall be included in the protection scope of the present invention.

Claims

1. A method for protecting the security of educational resource information data, characterized in that: The method comprises the following steps: Obtaining RBAC model data for access control in the education platform, as well as course schedule data and user account usage record data in the database, wherein the RBAC model data includes a number of users, roles, and permissions, each user corresponds to an account, and the usage record data includes the account login time, IP address, and device serial number; Use the user's account usage record data to analyze the user's behavior and obtain the user's behavior stability coefficient; Analyze the matters in which users participate based on course schedule data and generate the actual permission table for the user's corresponding role; Analyze the usage environment of the user's corresponding account based on the account login situation, and dynamically adjust the actual permission table based on the behavior stability coefficient to obtain the education resource authority table of the user's corresponding role; Control the user's permissions based on the size of the permission coefficient in the database corresponding to the education resource authority table; The specific method of analyzing the user's behavior by using the user's account usage record data to obtain the user's behavior stability coefficient includes: For any user's account, obtain the address sequence and device sequence of the account based on all usage record data of the account; Performing login behavior analysis on the login time of the user's corresponding account, obtaining a login interval curve of the account and spectrum data of the login interval curve; Perform change analysis and correlation analysis on address sequences and device sequences, and calculate the user's usage habit factor by combining the spectrum data of the login interval curve; Analyze the changes in the usage habit factor of the user's corresponding account during this login, and calculate the behavior stability coefficient of the account during this login.

2. A method for protecting the security of educational resource information data according to claim 1, characterized in that: The specific method for obtaining the address sequence and device sequence is: Obtain the IP address corresponding to the user's account at each login, and obtain the sequence formed by the corresponding IP addresses at all logins in chronological order, which is recorded as the initial IP address sequence; Taking the same IP address as one IP address, obtaining several IP addresses included in the initial IP address sequence; Obtain the frequency of each IP address in the initial IP address sequence, sort all types of IP addresses in descending order of frequency, and assign each IP address a sequence number, called the address frequency number. Each IP address corresponds to an address frequency number. Replace each IP address in the initial IP address sequence with the corresponding address frequency number to obtain a sequence consisting of address frequency numbers, which is recorded as the address sequence; And so on, get the initial device serial number sequence and device serial number.

3. A method for protecting the security of educational resource information data according to claim 1, characterized in that: The specific method for obtaining the usage habit factor is: Analyze the spectrum data of the login interval curve of the user's corresponding account and calculate the usage time factor of the user's corresponding account; According to the correlation between the address sequence and the device sequence and their corresponding distribution, the usage habit factor of the user's corresponding account is calculated.

4. A method for protecting the security of educational resource information data according to claim 3, characterized in that: The specific method for obtaining the behavior stability coefficient of the account during this login is: Obtain the login time, IP address and device serial number corresponding to the user's corresponding account at the time of this login, obtain the login time sequence, initial IP address sequence and initial device serial number sequence corresponding to the login time, IP address and device serial number at the time of this login, and record them as the new login time sequence, the new initial IP address sequence and the new initial device serial number sequence respectively; Combine the new login time sequence, the new initial IP address sequence, the new initial device serial number sequence, and use the method for obtaining the usage habit factor to calculate the usage habit factor of the account at the time of this login; According to the difference in usage habit factors before and after this login, the user's behavior stability coefficient during this login is obtained.

5. A method for protecting the security of educational resource information data according to claim 1, characterized in that: The specific method of analyzing the matters in which the user participates based on the course arrangement data and generating the actual permission table of the user's corresponding role includes: Get all the courses in the course schedule data, and subdivide the role permissions based on the course schedule, so that each permission corresponds to a permission value for each course, and get the initial permission table for the user's corresponding role; In the database corresponding to the initial permission table, when the user has the permission of the corresponding role, the permission value corresponding to the permission is 1, and when the user does not have the permission of the corresponding role, the permission value of the corresponding permission is 0; According to the user's course participation, the permission values ​​in the database corresponding to the initial permission table are adjusted, and the permission values ​​of the courses not participated in are set to 0 to obtain the actual permission table of the user's corresponding role.

6. A method for protecting the security of educational resource information data according to claim 1, characterized in that: The method of analyzing the usage environment of the user's corresponding account based on the account login situation and dynamically adjusting the actual authority table in combination with the behavior stability coefficient to obtain the education resource authority table of the user's corresponding role includes: Analyze the usage environment conditions of the user's corresponding account based on the account login situation, and calculate the environment permission parameters of the account at the time of this login; Analyze the usage of educational resource information data by the user's corresponding role in the database relative to other users with the same role using different permissions, and calculate the permission sensitivity of each permission of the role; The different permissions in the database corresponding to the actual permission table are adjusted in combination with the behavior stability coefficient and permission sensitivity to obtain the educational resource authority table of the user's corresponding role at the time of this login.

7. A method for protecting the security of educational resource information data according to claim 6, characterized in that: The specific method for obtaining the environment permission parameters is: Obtain the frequency of the device currently logged in by the user account appearing in the database and the number of other accounts that have logged in on the login device; Based on the frequency of the device appearing in the database and the number of other accounts that have logged in to the device, calculate the environment permission parameters of the user's corresponding account at the time of this login.

8. A method for protecting the security of educational resource information data according to claim 6, characterized in that: The specific method for obtaining the permission sensitivity of each permission is as follows: Constructing a binary array, wherein the elements of the binary array are the behavior stability coefficient and the environment authority parameter, and using the binary array as a login vector corresponding to the user account; According to the Euclidean distance between login vectors, the DBSCAN clustering algorithm is used to cluster the login vectors of all user accounts each time they log in within a preset time range to obtain several clusters. The cluster corresponding to the most common role is obtained, and the users of other roles in the cluster are removed to obtain the role cluster. For any role cluster, the permission sensitivity of each permission is obtained according to the usage of educational resource information data by all users in the role cluster.

9. A security protection system for educational resource information data, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the steps of a method for security protection of educational resource information data as described in any one of claims 1 to 8 are implemented.

Citation Information

Patent Citations

  • Security access control method and system suitable for cloud computing environment

    CN119011304A

  • Intelligent education management system based on multi-user cooperation

    CN119741171A