Data security access method and system applied to enterprise big data platform
By obtaining visitor information on the enterprise big data platform, determining the visitor type, and determining access permissions based on authentication rules, the problem of data security risks is solved, and the secure use of data and precise control of access permissions is achieved.
Patent Information
- Application Number
- CN202510319923.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-18
- Publication Date
- 2025-05-16
AI Technical Summary
Enterprise big data platforms have risks in data security, and internal service interfaces are exposed to the outside world. Anyone can consume data at will, and there is a lack of protection measures and security for sensitive data.
Provide a data secure access method applied to enterprise big data platforms, by obtaining visitor information, determining the visitor type, and determining the user's access rights based on authentication rules to obtain access data within the access rights scope. This method includes default authentication rules and additional authentication rules, automatically identify visitors, recommend popular data, and filter irrelevant data.
It realizes a safer use of data, automatically eliminates access by illegal users, filters irrelevant data, protects the security of business data, improves the efficiency of users to obtain attention data, reduces manual configuration workload, and ensures the consistency and accuracy of authentication rules.
Smart Images

Figure CN120012161A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data security technology, and in particular to a data security access method and system applied to an enterprise big data platform. Background Art
[0002] The construction of enterprise big data platforms has reached a certain scale, with more and more data and a wider range of uses. On the one hand, relevant departments within the enterprise use data maps to promote related work, and business personnel prefer to see the data they are concerned about; on the other hand, external customers can also use data through externally exposed data retrieval services. However, there are great risks in data security. On the one hand, the relevant internal service interfaces are directly exposed to the outside world, and anyone who knows how to use the service can consume any data in each data warehouse at will; on the other hand, there is a lack of protection measures for sensitive data in the data warehouse, and lack of security.
[0003] In a Chinese patent document with publication number CN118965409A, a big data-based information security management and monitoring system is disclosed, which relates to the field of information security technology, including a server, a security monitoring module and a security management module; the security monitoring module monitors the new status of each type of data and calculates the data addition rate, and the system can dynamically identify the growth trend of sensitive data; the TF-IDF algorithm is used to identify keywords in the data, and the sensitivity of each data segment is quantified based on this, and a segment sensitivity value is generated and sent to the security management module; the security management module can effectively identify potential internal security threats through a comprehensive analysis of user access behavior types, device confidence coefficients and data sensitivity. When the risk of user behavior increases, access rights will be gradually restricted and eventually completely locked.
[0004] The need to establish a data security system for big data platforms and ensure the security and compliance of data usage is becoming increasingly important. Therefore, a method for implementing data access security on big data platforms is needed to solve the above problems. Summary of the invention
[0005] In view of the defects in the prior art, the purpose of the present invention is to provide a data security access method applied to an enterprise big data platform.
[0006] A data security access method for an enterprise big data platform provided by the present invention includes:
[0007] Step S1: Obtain visitor information from the big data platform and determine the visitor type based on the visitor information;
[0008] Step S2: Based on the authentication rules, the user's access rights are determined according to the visitor type, and access data within the scope of the access rights is obtained.
[0009] Preferably, the visitor types include people, roles and social organizations;
[0010] The character includes entities that directly or indirectly contain human dimensions;
[0011] The role includes sub-dimensions of persona;
[0012] The social organization includes entities that directly or indirectly include the social organization;
[0013] The access data includes subject domain and subject;
[0014] The subject domain includes: accessible columns in the logical large wide table; the subject includes: accessible rows in the logical large wide table.
[0015] Preferably, the visitor type identification method includes: when a visitor accesses data, the visitor must enter the usrId as the only identity verification for accessing the data; and the visitor type is determined by the visitor's usrId.
[0016] Preferably, if the visitor has access rights to the relevant data, the big data platform will give priority to returning popular data when returning relevant data, and automatically filter out irrelevant data;
[0017] The hot data includes: data corresponding to dimensions whose relevance to visitor types reaches a preset value among different dimensions of relevant data;
[0018] The irrelevant data includes: data corresponding to dimensions whose relevance to visitor types does not reach a preset value among different dimensions of the relevant data.
[0019] Preferably, in step S2, the authentication rules include: default authentication rules and additional authentication rules;
[0020] The default authentication rules include: the big data platform describes the dependency relationships between entities through metadata, and automatically forms default data access authentication rules through these relationships;
[0021] The additional authentication rules include: authentication rules added by visitors in addition to the default authentication rules.
[0022] Preferably, the default authentication rules include: if the authentication subject is a role, the authentication object is the subject domain; if the authentication subject is a social organization, the object is the subject domain and / or the subject; if the authentication subject is a person, the object is the subject domain and / or the subject.
[0023] Preferably, when the authentication subject is a role and the authentication object is a subject domain:
[0024] If the role is the main business object of the current business process and the role is located at the first layer on the dimensional path of the business process dimensional topology diagram, then the role is allowed to access the atomic subject domain of the business process, and other subsequent roles on the dimensional path are not allowed to access the atomic subject domain.
[0025] Preferably, when the authentication subject is a social organization and the object is a subject domain or subject:
[0026] If a social organization is the main business object of the current business process and is located at the first layer on the dimensional path of the business process dimensional topology diagram, then the social organization is allowed to access the atomic subject domain of the business process, and other subsequent social organizations on the dimensional path are not allowed to access the atomic subject domain of the business process;
[0027] Social organizations are allowed to access the atomic subject domain of their own business processes.
[0028] Preferably, when the subject of authentication is a person and the object is a subject domain or subject:
[0029] All subject domains that the role of the heir is allowed to access;
[0030] All subject domains that the social organization to which the heir belongs allows access;
[0031] People allows access to the People subject domain.
[0032] According to the present invention, a data security access system applied to an enterprise big data platform includes:
[0033] Module M1: Obtain visitor information from the big data platform and determine visitor type based on the visitor information;
[0034] Module M2: Based on the authentication rules, the user's access rights are determined according to the visitor type, and access data within the scope of the access rights is obtained.
[0035] Compared with the prior art, the present invention has the following beneficial effects:
[0036] 1. The solution disclosed in the present invention can make data be used more safely. The big data platform automatically excludes access by illegal users, and the big data platform automatically filters out data that is irrelevant to the platform application personnel, and allows the platform application personnel to pay more attention to their own business data, so as to obtain better protection effects.
[0037] 2. The present invention recommends popular data to visitors with access rights, filters irrelevant data, and finally obtains the data that the user is concerned about, so that the user can obtain the information that the user is concerned about more quickly, thereby improving work efficiency.
[0038] 3. The present invention utilizes the default authentication rules in combination with the additional authentication rules, which not only realizes automatic authentication, but also allows flexible addition of additional access controls, reduces the workload of manual configuration, and also ensures the consistency and accuracy of the authentication rules.
[0039] 4. The present invention can refine access rights according to the business process dimension topology diagrams at different levels, which provides the management with more accurate data access control capabilities and helps to achieve refined management of business operations.
[0040] 5. Through precise control of access behavior, the present invention enables enterprises to better comply with internal policies and external regulations, ensure the security and legality of data use, and help meet increasingly stringent data protection requirements. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] Other features, objects and advantages of the present invention will become more apparent from the detailed description of non-limiting embodiments made with reference to the following drawings:
[0042] Figure 1 The present invention is a flowchart of a method for securely accessing data on an enterprise big data platform. DETAILED DESCRIPTION
[0043] The present invention is described in detail below in conjunction with specific embodiments. The following embodiments will help those skilled in the art to further understand the present invention, but are not intended to limit the present invention in any form. It should be noted that, for those of ordinary skill in the art, several changes and improvements can also be made without departing from the concept of the present invention. These all belong to the protection scope of the present invention.
[0044] The present invention discloses a data security access method applied to an enterprise big data platform. For data visitors of various roles, whether they are internal platform visitors, they can obtain data through a data map (including search box search and advanced search); or external users can obtain data through an API gateway, and through a data service layer (including authentication service), the method automatically identifies visitors, rejects illegal visitors, recommends popular data, filters irrelevant data, and finally obtains the data that they are concerned about, and ensures that the data is used more safely.
[0045] Specifically, the method includes:
[0046] Step S1: Obtain visitor information from the big data platform and determine the visitor type based on the visitor information;
[0047] Step S2: Based on the authentication rules, the user's access rights are determined according to the visitor type, and access information under the access rights is obtained.
[0048] To solve the problem of what data closely related to the visitor has access rights by default, it is necessary to first confirm what types of visitors (subjects) exist and what data (objects) they can access. Combined with the modeling system of the big data platform, the specific settings are as follows:
[0049] Visitor types include people, roles, and social organizations.
[0050] The person can be a user, employee, developer, operation and maintenance personnel, or other entity that is directly or indirectly rolled up in the person dimension.
[0051] Roles can be sub-dimensions of all people (including physical sub-dimensions and virtual sub-dimensions). For example, employees, administrative heads, party members, users, operation and maintenance personnel, operation and maintenance A-role, data governance engineers, ETL engineers, developers, development project managers, event handlers, change reviewers, configuration item creators, etc. in the big data platform are all roles. Currently, there are records in the dim_role dimension table.
[0052] A social organization can be an entity in the dimension of a social organization (so), such as an enterprise, an organizational structure, a government agency, an operation center group, or an operation center, which is directly or indirectly involved.
[0053] Data types include subject domains and topics.
[0054] The subject domain includes: From the perspective of the logical large wide table, the subject domain determines the accessible columns in the table (derived metrics, periodic snapshot facts, dimension attributes, and portrait labels).
[0055] Topics include: From the perspective of a logical large wide table, topics determine the accessible rows in the table.
[0056] For visitor type settings, the enterprise big data platform includes a metadata management platform by default, which maintains metadata information such as people, roles, and social organizations (without the need for manual settings by humans); according to the rules in the instructions, various types of data of the subject are implemented through code.
[0057] For the identification of visitor types, when a visitor accesses data, he / she must enter the usrId as the only identity verification for accessing the data; through the visitor's usrId, the visitor's visitor type can be further determined, such as whether the visitor is a developer or a party member, etc.
[0058] Regarding the processing of the identification results, if the visitor has access rights to the relevant data, the relevant data access service returns the relevant data; if the visitor does not have access rights to the relevant data, the relevant data access service returns a "no permission" prompt message and the data is returned empty.
[0059] If the visitor has access rights to the relevant data, the big data platform will give priority to returning popular data when returning relevant data, and automatically filter out irrelevant data.
[0060] Hot data: Enterprise big data platforms involve data of various dimensions. For example, if a user wants to access the number of employees, there will be data on the number of employees in different dimensions, such as the global, group, company, department, and team. Depending on the type of the visitor, if he is just an ordinary employee, he may only pay attention to the number of employees in his team or department, which will be the hot data of the current role. If he is the person in charge of the enterprise, he will pay more attention to the hot data of the number of employees at the global, group, and company levels.
[0061] Irrelevant data: Based on the subject type, the data of irrelevant dimensions will be filtered out; for example, for the employees mentioned above, the data of global and group dimensions will be automatically filtered out.
[0062] In a specific implementation, the authentication rules provided in the present invention include the following two parts:
[0063] Default authentication rules: The big data platform has rich metadata to describe the complex dependencies between entities. Through these relationships and according to certain rules, default data access authentication rules are automatically formed to automatically identify visitors, recommend popular data, and filter irrelevant data.
[0064] Additional authentication rules: In addition to the default authentication rules, if the visitor wants to access data allowed by other businesses, he or she can obtain data access rights by adding authentication rules.
[0065] If the authentication subject is a role, the authentication object is the subject domain: If the authentication subject is a social organization, the object is the subject domain and / or subject: If the authentication subject is a person, the object is the subject domain and / or subject. Specifically:
[0066] In the default authentication rules, when the authentication subject is the role, the authentication object is the subject domain:
[0067] If the role is the main business object of the current business process and the role is located at the first layer on the dimensional path of the business process dimensional topology diagram, then the role is allowed to access the atomic subject domain of the business process, and other subsequent roles on the dimensional path are not allowed to access the atomic subject domain.
[0068] The main business object is mainly for the transaction business process of the process-type business object (such as configuration item change creation). Usually the main object is a person-related role (such as operation and maintenance personnel), and both the main and object business objects cannot be empty. The object business object is a process-type business object. The main business object has a corresponding foreign key in the corresponding transaction table. The main business object and the object business object of the business process cannot be the same.
[0069] If the role is not the main business object of the current business process, but is the management role that appears for the first time on the dimension path in the dimension topology diagram of the business process (Note: In an enterprise, there is a special type of role, which is a group of people with the same management responsibilities. This is a management role. For example, the customer manager is fully responsible for the customer's operations and maintenance, and is the first person responsible for the customer), then this management role allows access to the atomic-level subject domains of all business objects, business processes, and business relationships in the paired management dimension and the lower layers of the management dimension (including the atomic subject domain associated with the current business process). The management roles that appear later in the dimension path do not have the right to access the permissions of the management role that appears for the first time (excluding the atomic subject domain associated with the current business process), that is, they have permissions to the atomic subject domain associated with the current business process).
[0070] When a role has access permissions to all subject domains contained in a subject domain, the role has access permissions to the subject domain.
[0071] In the default authentication rules, when the authentication subject is a social organization and the object is a subject domain or subject:
[0072] If a social organization is the main business object of the current business process and is located at the first layer on the dimensional path of the business process dimensional topology diagram, then the social organization is allowed to access the atomic subject domain of the business process, and other subsequent social organizations on the dimensional path are not allowed to access the atomic subject domain of the business process.
[0073] The social organization is not the main business object of the current business process. In the dimensional topology diagram of the business process, the social organization appears for the first time on the dimensional path and is a management role (management dimensions and management roles must appear in pairs, and management roles can be omitted in the dimensional topology diagram of the business process) (In an enterprise, there is a special type of role, that is, a group of people with the same management responsibilities, which is the management role. The target object managed by the management role is usually a higher-level dimension, called the management dimension. The management dimension, management role, and main business object are all dimensions that have management or responsibility for the business process. For example, the customer manager has the responsibility to pay attention to the operation of the customer's system.), then the social organization is allowed to access the atomic subject domains of all business objects, business processes, and business relationships of the social organization and its lower layers. If it is a social organization, but not a management role, then the social organization is not allowed to access the atomic subject domains of all business objects, business processes, and business relationships of the social organization and its lower layers.
[0074] When a social organization has access permissions to all subject domains included in a combined subject domain, the social organization has access permissions to the combined subject domain.
[0075] Social organizations are allowed to access the atomic subject domain of their own business processes.
[0076] When the authentication subject is a person and the object is a subject domain or subject:
[0077] All subject domains that the role of the person heir is allowed to access; all subject domains that the social organization to which the person heir belongs is allowed to access; person is allowed to access the person subject domain.
[0078] In the additional authentication rules, if you want to solve how visitors can access related data outside the default permissions, you can obtain it by adding authentication rules. The additional authentication rules are applied, reviewed, and configured in the platform in a triplet manner. The configuration information is as follows:
[0079] The configuration information for configuring the additional authentication rule "Subject is allowed to access subject domain" is shown in Table 1:
[0080] Subject primary key Subject Name Access permission flag Subject domain primary key Subject Field Name
[0081] Table 1
[0082] The configuration information for configuring the additional authentication rule "Subject is allowed to access the subject" is shown in Table 2:
[0083] Subject primary key Subject Name Access permission flag Subject primary key Theme Name
[0084] Table 2
[0085] The present invention also provides a data security access system applied to an enterprise big data platform. The data security access system applied to an enterprise big data platform can be implemented by executing the process steps of the data security access method applied to an enterprise big data platform, that is, those skilled in the art can understand the data security access method applied to an enterprise big data platform as a preferred implementation of the data security access system applied to an enterprise big data platform.
[0086] The present invention discloses a data security access method applied to an enterprise big data platform, comprising:
[0087] Module M1: Obtain visitor information from the big data platform and determine visitor type based on the visitor information;
[0088] Module M2: Based on the authentication rules, the user's access rights are determined according to the visitor type, and access data within the scope of the access rights is obtained.
[0089] Those skilled in the art know that, in addition to realizing the system and its various devices, modules, and units provided by the present invention in a purely computer-readable program code, it is entirely possible to realize the same functions in the form of logic gates, switches, application-specific integrated circuits, programmable logic controllers, and embedded microcontrollers by logically programming the method steps. Therefore, the system and its various devices, modules, and units provided by the present invention can be considered as a hardware component, and the devices, modules, and units included therein for realizing various functions can also be regarded as structures within the hardware component; the devices, modules, and units for realizing various functions can also be regarded as both software modules for realizing the method and structures within the hardware component.
[0090] The above describes the specific embodiments of the present invention. It should be understood that the present invention is not limited to the above specific embodiments, and those skilled in the art can make various changes or modifications within the scope of the claims, which does not affect the essence of the present invention. In the absence of conflict, the embodiments of the present application and the features in the embodiments can be combined with each other arbitrarily.
Claims
1. A data security access method applied to an enterprise big data platform, characterized in that: include: Step S1: Obtain visitor information from the big data platform and determine the visitor type based on the visitor information; Step S2: Based on the authentication rules, the user's access rights are determined according to the visitor type, and access data within the scope of the access rights is obtained.
2. The data security access method applied to the enterprise big data platform according to claim 1 is characterized in that: The types of visitors mentioned include people, roles, and social organizations; The character includes entities that directly or indirectly contain human dimensions; The role includes sub-dimensions of persona; The social organization includes entities that directly or indirectly include the social organization; The access data includes subject domain and subject; The subject domain includes: accessible columns in a logical large wide table; The topics include: accessible rows in logically large wide tables.
3. The data security access method applied to the enterprise big data platform according to claim 1 is characterized in that: The visitor type identification method includes: when a visitor accesses data, inputting a usrId as a unique identity verification for accessing the data; and judging the visitor type by the visitor's usrId.
4. The data security access method applied to the enterprise big data platform according to claim 1 is characterized in that: If the visitor has access rights to the relevant data, the big data platform will give priority to returning popular data when returning relevant data, and will automatically filter out irrelevant data; The hot data includes: data corresponding to dimensions whose relevance to visitor types reaches a preset value among different dimensions of relevant data; The irrelevant data includes: data corresponding to dimensions whose relevance to visitor types does not reach a preset value among different dimensions of the relevant data.
5. The data security access method applied to the enterprise big data platform according to claim 2 is characterized in that: In the step S2, the authentication rules include: a default authentication rule and an additional authentication rule; The default authentication rules include: the big data platform describes the dependency relationships between entities through metadata, and automatically forms default data access authentication rules through these relationships; The additional authentication rules include: authentication rules added by visitors in addition to the default authentication rules.
6. The data security access method applied to the enterprise big data platform according to claim 5 is characterized in that: The default authentication rules include: if the authentication subject is a role, the authentication object is the subject domain; if the authentication subject is a social organization, the object is the subject domain and / or the subject; if the authentication subject is a person, the object is the subject domain and / or the subject.
7. The data security access method applied to the enterprise big data platform according to claim 6 is characterized in that: When the authentication subject is a role and the authentication object is a subject domain: If the role is the main business object of the current business process and the role is located at the first layer on the dimensional path of the business process dimensional topology diagram, then the role is allowed to access the atomic subject domain of the business process, and other subsequent roles on the dimensional path are not allowed to access the atomic subject domain.
8. The data security access method applied to the enterprise big data platform according to claim 6 is characterized in that: When the authentication subject is a social organization and the object is a subject domain or subject: If a social organization is the main business object of the current business process and is located at the first layer on the dimensional path of the business process dimensional topology diagram, then the social organization is allowed to access the atomic subject domain of the business process, and other subsequent social organizations on the dimensional path are not allowed to access the atomic subject domain of the business process; Social organizations are allowed to access the atomic subject domain of their own business processes.
9. The data security access method applied to the enterprise big data platform according to claim 6 is characterized in that: When the authentication subject is a person and the object is a subject domain or subject: All subject domains that the role of the heir is allowed to access; All subject domains that the social organization to which the heir belongs allows access; People allows access to the People subject domain.
10. A data security access system applied to an enterprise big data platform, characterized in that: include: Module M1: Obtain visitor information from the big data platform and determine visitor type based on the visitor information; Module M2: Based on the authentication rules, the user's access rights are determined according to the visitor type, and access data within the scope of the access rights is obtained.
Citation Information
Patent Citations
Information security management and monitoring system based on big data
CN118965409A