Government affair data access control method and device, equipment and storage medium

By receiving government data access requests, determining the access control level based on data attributes and visitor identity, and encrypting the government data, solving the security and privacy challenges of government data and realizing the secure access control of government data.

CN120068103APending Publication Date: 2025-05-30NAT COMP NETWORK & INFORMATION SECURITY MANAGEMENT CENT
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510091627.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-21
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

On the premise of ensuring the security and privacy of government data, how to achieve effective access control of government data and solve the security and privacy challenges brought about by the opening of government data.

Method used

By receiving the government data access request of the target object, determining its importance based on the attribute information of the target government data, combining the identity information of the target object and the time of the access request, determining the access control level, and encrypting the government data to generate ciphertext data to respond.

Benefits of technology

On the basis of ensuring the security and privacy of government data, customized access control is realized for different government data and visitors to ensure the security of data during transmission, thereby achieving efficient and secure sharing of government data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120068103A_ABST
    Figure CN120068103A_ABST
Patent Text Reader

Abstract

The invention provides an access control method and device for government affair data, equipment and a storage medium. The method comprises the following steps: receiving a government affair data access request sent by a target object for target government affair data; based on the attribute information of the target government affair data, determining an importance degree value corresponding to the target government affair data; the attribute information comprises sensitivity, influence degree, aging value and data integration difficulty; determining an access control level based on the identity information of the target object, the receiving time of the government affair data access request and the importance degree value corresponding to the target government affair data; performing encryption processing on the target government affair data based on the access control level; sending a government affair data access response to the target object; the government affair data access response comprises ciphertext government affair data, and the ciphertext government affair data is used for decrypting the target object to obtain target government affair data. By adopting the technical scheme provided by the invention, the access control of the government affair data is realized on the premise of ensuring the security and privacy of the government affair data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data security technology, and in particular, to a method, apparatus, device, and storage medium for access control of government affairs data. Background Art

[0002] Government affairs data refers to the data generated during the process of carrying out government affairs activities. The government affairs open platform can make government affairs data public to the public, which is of great significance for improving service quality, promoting economic innovation and development, and strengthening governance.

[0003] Although the opening of government affairs data brings many benefits, it also faces challenges in the security and privacy of government affairs data. Therefore, on the premise of ensuring the security and privacy of government affairs data, how to achieve access control of government affairs data is an urgent problem for those skilled in the art. Summary of the Invention

[0004] This application provides a method, apparatus, device, and storage medium for access control of government affairs data, which realizes access control of government affairs data on the premise of ensuring the security and privacy of government affairs data.

[0005] This application provides a method for access control of government affairs data, including: Receiving a government affairs data access request for target government affairs data sent by a target object; Based on the attribute information of the target government affairs data, determining the importance value corresponding to the target government affairs data; wherein, the attribute information includes sensitivity, impact degree, time limit value, and data integration difficulty; Based on the identity information of the target object, the receiving time of the government affairs data access request, and the importance value corresponding to the target government affairs data, determining the access control level corresponding to the target government affairs data; Encrypting the target government affairs data based on the access control level to obtain encrypted ciphertext government affairs data; Sending a government affairs data access response to the target object; wherein, the government affairs data access response includes the ciphertext government affairs data, and the ciphertext government affairs data is used for the target object to perform decryption processing to obtain the target government affairs data.

[0006] According to the method for access control of government affairs data provided by this application, the determining the importance value corresponding to the target government affairs data based on the attribute information of the target government affairs data includes: Inputting the attribute information of the target government affairs data into a pre-constructed importance prediction model to obtain the access control level corresponding to the target government affairs data; Among them, the importance prediction model is trained based on the attribute information of multiple government affair data samples and the corresponding access control level labels.

[0007] According to an access control method for government affair data provided by the present application, determining the access control level corresponding to the target government affair data based on the identity information of the target object, the reception time of the government affair data access request, and the importance value corresponding to the target government affair data includes: Determining a first weight corresponding to the identity information of the target object, a second weight corresponding to the reception time of the government affair data access request, and a third weight corresponding to the importance value corresponding to the target government affair data; Based on the first weight, the second weight, and the third weight, performing weighted summation on the identity information of the target object, the reception time of the government affair data access request, and the importance value corresponding to the target government affair data to obtain the access control level corresponding to the target government affair data.

[0008] According to an access control method for government affair data provided by the present application, determining the access control level corresponding to the target government affair data based on the identity information of the target object, the reception time of the government affair data access request, and the importance value corresponding to the target government affair data includes: Obtaining a fuzzy evaluation model established in advance based on the method of fuzzy mathematics theory; Inputting the identity information of the target object, the reception time of the government affair data access request, and the importance value corresponding to the target government affair data into the fuzzy evaluation model, and outputting the respective fuzzy values corresponding to the identity information of the target object, the reception time of the government affair data access request, and the importance value corresponding to the target government affair data through the fuzzy evaluation model; Based on the respective fuzzy values corresponding to the identity information of the target object, the reception time of the government affair data access request, and the importance value corresponding to the target government affair data, determining the access control level corresponding to the target government affair data.

[0009] According to an access control method for government affair data provided by the present application, encrypting the target government affair data based on the access control level to obtain the encrypted ciphertext government affair data includes: In the case where the access control level is the first-level access control level, performing differential privacy processing on the target government affair data to obtain the government affair data after privacy processing; Using a homomorphic encryption algorithm to encrypt the government affair data after privacy processing to obtain the ciphertext government affair data.

[0010] A method for access control of government affairs data provided by this application, encrypting the target government affairs data based on the access control level to obtain encrypted ciphertext government affairs data, includes: When the access control level is the secondary access control level, using a homomorphic encryption algorithm to encrypt the target government affairs data to obtain the ciphertext government affairs data; Among them, the access control level of the secondary access control level is lower than that of the primary access control level.

[0011] This application also provides an access control device for government affairs data, including: A receiving unit, configured to receive a government affairs data access request for target government affairs data sent by a target object; A determining unit, configured to determine an importance value corresponding to the target government affairs data based on the attribute information of the target government affairs data; where the attribute information includes sensitivity, impact degree, timeliness value, and data integration difficulty; The determining unit is further configured to determine an access control level corresponding to the target government affairs data based on the identity information of the target object, the receiving time of the government affairs data access request, and the importance value corresponding to the target government affairs data; An encrypting unit, configured to encrypt the target government affairs data based on the access control level to obtain encrypted ciphertext government affairs data; A sending unit, configured to send a government affairs data access response to the target object; where the government affairs data access response includes the ciphertext government affairs data, and the ciphertext government affairs data is used by the target object for decryption processing to obtain the target government affairs data.

[0012] This application also provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, it implements the method for access control of government affairs data as described in any one of the above.

[0013] This application also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the method for access control of government affairs data as described in any one of the above.

[0014] This application also provides a computer program product, including a computer program. When the computer program is executed by a processor, it implements the method for access control of government affairs data as described in any one of the above.

[0015] The access control method, device, equipment and storage medium for government affairs data provided by this application can, after receiving a government affairs data access request for target government affairs data sent by a target object, determine the importance value corresponding to the target government affairs data based on the attribute information of the target government affairs data; where the attribute information includes sensitivity, impact degree, timeliness value, and data integration difficulty; and determine the access control level corresponding to the target government affairs data based on the identity information of the target object, the reception time of the government affairs data access request, and the importance value corresponding to the target government affairs data; so as to perform encryption processing on the target government affairs data based on the access control level to obtain the encrypted ciphertext government affairs data; and then send a government affairs data access response to the target object; where the government affairs data access response includes the ciphertext government affairs data, and the ciphertext government affairs data is used for the target object to perform decryption processing to obtain the target government affairs data. In this way, based on the attribute information of the target government affairs data, the importance value corresponding to the target government affairs data is determined, and in combination with the identity information of the target object, the reception time of the government affairs data access request, and the importance value corresponding to the target government affairs data, the access control level corresponding to the target government affairs data is jointly determined, and then the encrypted ciphertext government affairs data is sent to the target object based on the access control level, realizing the access control of government affairs data while ensuring the security and privacy of government affairs data. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] In order to more clearly illustrate the technical solutions in this application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of this application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0017] Figure 1 It is a schematic flowchart of a method for accessing and controlling government affairs data provided by an embodiment of this application.

[0018] Figure 2 It is a schematic structural diagram of an access control device for government affairs data provided by an embodiment of this application.

[0019] Figure 3 It is a schematic physical structure diagram of an electronic device provided by an embodiment of this application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0020] To make the objectives, technical solutions, and advantages of this application clearer, the following will clearly and completely describe the technical solutions in this application with reference to the drawings in this application. Obviously, the described embodiments are some, but not all, of the embodiments of this application. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the scope of protection of this application.

[0021] In the embodiments of the present application, "at least one" means one or more, and "a plurality" means two or more. "And / or" describes the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone. Here, A and B can be singular or plural. In the written description of the present application, the character " / " generally represents an "or" relationship between the associated objects before and after.

[0022] The technical solution provided by the embodiments of the present application can be applied to the access control scenario of government affairs data. The government affairs open platform can disclose government affairs data to the public, which is of great significance for improving service quality, promoting economic innovation and development, and strengthening governance. However, it also faces challenges in the security and privacy of government affairs data. Therefore, effective access control of government affairs data is crucial.

[0023] In order to achieve access control of government affairs data while ensuring the security and privacy of government affairs data, the present application proposes an access control method for government affairs data. After receiving a government affairs data access request for target government affairs data sent by a target object, it can determine the importance value corresponding to the target government affairs data based on the attribute information of the target government affairs data. Among them, the attribute information includes sensitivity, influence degree, time limit value, and data integration difficulty. And based on the identity information of the target object, the reception time of the government affairs data access request, and the importance value corresponding to the target government affairs data, it determines the access control level corresponding to the target government affairs data. Then, it encrypts the target government affairs data based on the access control level to obtain the encrypted ciphertext government affairs data. Finally, it sends a government affairs data access response to the target object. The government affairs data access response includes the ciphertext government affairs data, which is used by the target object for decryption processing to obtain the target government affairs data. In this way, based on the attribute information of the target government affairs data, the importance value corresponding to the target government affairs data is determined, and in combination with the identity information of the target object, the reception time of the government affairs data access request, and the importance value corresponding to the target government affairs data, the access control level corresponding to the target government affairs data is jointly determined. Then, based on the access control level, the encrypted ciphertext government affairs data is sent to the target object, realizing the access control of government affairs data while ensuring the security and privacy of government affairs data.

[0024] It can be understood that the execution subject of this method can be an electronic device such as a storage device for government affairs data, a specially set access control device for government affairs data, a computer, or a server. It can also be an access control device for government affairs data set in the electronic device. The access control device for government affairs data can be implemented through software, hardware, or a combination of both, and can be specifically set according to actual needs.

[0025] Next, the access control method for government affairs data provided by this application will be described in detail through the following specific embodiments. It can be understood that the following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments.

[0026] Figure 1 It is a schematic flowchart of an access control method for government affairs data provided by an embodiment of this application. For example, please refer to Figure 1 As shown, the access control method for government affairs data may include: S101. Receive a government affairs data access request sent by a target object for target government affairs data.

[0027] For example, the government affairs data access request may include the identity information of the target object, or may not include the identity information of the target object, which can be specifically set according to actual needs.

[0028] For example, when receiving a government affairs data access request sent by a target object for target government affairs data, it can be based on a Web service method, such as a HyperText Transfer Protocol (HTTP) request or a HyperText Transfer Protocol Secure (HTTPS) request, to receive the government affairs data access request sent by the target object for target government affairs data; it can also be based on a message queue method, etc., to receive the government affairs data access request sent by the target object for target government affairs data, which can be specifically set according to actual needs.

[0029] S102. Determine the importance value corresponding to the target government affairs data based on the attribute information of the target government affairs data; where the attribute information includes sensitivity, impact degree, timeliness value, and data integration difficulty.

[0030] Among them, sensitivity usually involves personal privacy, unit privacy, and business secrets, etc. Once leaked or illegally used, it may bring serious consequences. Therefore, the higher the sensitivity of the government affairs data, the higher the corresponding importance value.

[0031] The impact degree may include impacts on individuals, units, or industries, etc. If government affairs data is leaked or misused, the wider its impact range, the greater the impact degree, and the greater the harm. Therefore, the higher the impact degree of the government affairs data, the higher the corresponding importance value.

[0032] The timeliness value of government affairs data directly affects the accuracy and efficiency of unit decision-making and public services. The stronger the timeliness of the government affairs data, the higher the corresponding importance value.

[0033] Under normal circumstances, the sources of government affairs data are extensive and complex, so the integration of government affairs data is difficult and may require complex processing and analysis to obtain valuable information. Therefore, the higher the integration difficulty of government affairs data, the higher the corresponding importance value.

[0034] For example, in the embodiments of the present application, the attribute information may include, in addition to sensitivity, impact degree, timeliness value, and data integration difficulty, the data value of the target government affairs data, etc. The higher the data value of the government affairs data, the higher the corresponding importance value, which can be specifically set according to actual needs.

[0035] In this way, based on the attribute information of the target government affairs data, the importance value corresponding to the target government affairs data can be determined more accurately and more pertinently, so that the access control level corresponding to the target government affairs data can be jointly determined in combination with the importance value corresponding to the target government affairs data subsequently, that is, execute the following S103.

[0036] S103. Determine the access control level corresponding to the target government affairs data based on the identity information of the target object, the reception time of the government affairs data access request, and the importance value corresponding to the target government affairs data.

[0037] Among them, the reception time of the government affairs data access request can be understood as the government affairs data access time of the target object.

[0038] For example, when determining the access control level corresponding to the target government affairs data in combination with the identity information of the target object, the identity information of the target object can also be verified, and when it is determined that the target object is a legitimate user, then determine the access control level corresponding to the target government affairs data in combination with the identity information of the target object, which can be specifically set according to actual needs.

[0039] For example, the access control level can be represented by a numerical value. For example, the higher the numerical value, the higher the corresponding access control level; it can also be represented by a first-level access control level and a second-level access control level, which can be specifically set according to actual needs. Among them, the access control level of the first-level access control level is higher than that of the second-level access control level.

[0040] For example, when obtaining the identity information of the target object, if the government affairs data access request includes the identity information of the target object, the identity information of the target object can also be directly obtained based on the government affairs data access request; if the government affairs data access request does not include the identity information of the target object, the identity information of the target object can be obtained based on the network address of the government affairs data access request, which can be specifically set according to actual needs.

[0041] When determining the access control level corresponding to the target government data based on the target object's identity information, the time of receiving the government data access request and the importance value corresponding to the target government data, if the target object is determined based on the target object's identity information to be an object that frequently accesses the target government data, the government data access time belongs to the time period when the target object frequently accesses the target government data, and the lower the importance value corresponding to the target government data, the more secure the government data access is, and the corresponding access control level is lower; on the contrary, if the target object is determined based on the target object's identity information to be an object that accesses the target government data for the first time, the government data access time belongs to an abnormal access time period, and the higher the importance value corresponding to the target government data, the more abnormal the government data access is, and the corresponding access control level is higher.

[0042] After determining the access control level corresponding to the target government data, the target government data can be encrypted in a targeted manner based on the access control level, that is, the following S104 is executed.

[0043] S104. Encrypt the target government data based on the access control level to obtain encrypted ciphertext government data.

[0044] Generally speaking, the higher the access control level, the higher the corresponding encryption level; the lower the access control level, the lower the corresponding encryption level. In this way, encrypting the target government data based on the access control level can effectively ensure the security of the target government data during transmission, thereby realizing efficient and secure sharing of government data.

[0045] S105. Send a government data access response to the target object; wherein the government data access response includes ciphertext government data, and the ciphertext government data is used for decryption processing by the target object to obtain the target government data.

[0046] After the target object receives the government data access response, it can decrypt the ciphertext government data based on the decryption algorithm corresponding to the encryption algorithm used during the encryption process, thereby obtaining the target government data in plain text.

[0047] It can be seen that in the embodiments of the present application, after receiving a government data access request for target government data sent by a target object, the importance value corresponding to the target government data can be determined based on the attribute information of the target government data; where the attribute information includes sensitivity, impact degree, timeliness value, and data integration difficulty; and based on the identity information of the target object, the reception time of the government data access request, and the importance value corresponding to the target government data, the access control level corresponding to the target government data is determined; so as to perform encryption processing on the target government data based on the access control level to obtain the encrypted ciphertext government data; and then send a government data access response to the target object; where the government data access response includes the ciphertext government data, and the ciphertext government data is used for the target object to perform decryption processing to obtain the target government data. In this way, based on the attribute information of the target government data, the importance value corresponding to the target government data is determined, and combined with the identity information of the target object, the reception time of the government data access request, and the importance value corresponding to the target government data, the access control level corresponding to the target government data is jointly determined, and then the encrypted ciphertext government data is sent to the target object based on the access control level, realizing the access control of government data while ensuring the security and privacy of government data.

[0048] Based on the above Figure 1 In the embodiment shown, in S102 above, when determining the importance value corresponding to the target government data based on the attribute information of the target government data, the following at least two possible implementation manners may be included: In one possible implementation manner, the attribute information of the target government data can be input into a pre-constructed importance prediction model to obtain the access control level corresponding to the target government data.

[0049] Among them, the importance prediction model is trained based on the attribute information of multiple government data samples and their corresponding access control level labels.

[0050] Exemplarily, in the embodiments of the present application, the importance prediction model can be a feedforward neural network (FNN), convolutional neural network (CNN), recurrent neural network (RNN), etc. based on deep learning, and can be specifically set according to actual needs.

[0051] In another possible implementation, weights corresponding to the attribute information of the target government affairs data, namely sensitivity, impact degree, timeliness value, and data integration difficulty, can be set in advance, and based on the respective corresponding weights, the sensitivity, impact degree, timeliness value, and data integration difficulty are weighted and fused to obtain the importance value corresponding to the target government affairs data, which can be specifically set according to actual needs.

[0052] After determining the importance value corresponding to the target government affairs data in a targeted manner based on the attribute information of the target government affairs data, the access control level corresponding to the target government affairs data can be jointly determined based on the identity information of the target object and the reception time of the government affairs data access request, combined with the importance value corresponding to the target government affairs data, that is, execute the above S103.

[0053] Exemplarily, in the above S103, when determining the access control level corresponding to the target government affairs data based on the identity information of the target object, the reception time of the government affairs data access request, and the importance value corresponding to the target government affairs data, at least two of the following possible implementation methods may be included: In one possible implementation, the first weight corresponding to the identity information of the target object, the second weight corresponding to the reception time of the government affairs data access request, and the third weight corresponding to the importance value corresponding to the target government affairs data can be determined first; and based on the first weight, the second weight, and the third weight, the identity information of the target object, the reception time of the government affairs data access request, and the importance value corresponding to the target government affairs data are weighted and summed to obtain the access control level corresponding to the target government affairs data.

[0054] Generally, considering that the importance of the importance value corresponding to the target government affairs data is higher than the importance of the identity information of the target object, and the importance of the identity information of the target object is higher than the importance of the reception time of the government affairs data access request, therefore, the third weight is greater than the first weight, and the first weight is greater than the second weight.

[0055] In this way, based on the first weight, the second weight, and the third weight, the identity information of the target object, the reception time of the government affairs data access request, and the importance value corresponding to the target government affairs data are weighted and summed to jointly determine the access control level corresponding to the target government affairs data, so that the encrypted ciphertext government affairs data can be sent to the target object based on the access control level later, realizing the access control of government affairs data while ensuring the security and privacy of government affairs data.

[0056] In another possible implementation, a fuzzy evaluation model established in advance based on the fuzzy mathematics theory can be obtained. The identity information of the target object, the receiving time of the government affairs data access request, and the importance value corresponding to the target government affairs data are all input into the fuzzy evaluation model. The fuzzy evaluation model outputs the fuzzy values corresponding to the identity information of the target object, the receiving time of the government affairs data access request, and the importance value corresponding to the target government affairs data respectively. And through methods such as fuzzy reasoning and fuzzy calculation, a comprehensive evaluation is performed on the fuzzy values corresponding to the identity information of the target object, the receiving time of the government affairs data access request, and the importance value corresponding to the target government affairs data respectively, so as to obtain the access control level corresponding to the target government affairs data.

[0057] It should be noted that when determining the access control level corresponding to the target government affairs data based on the identity information of the target object, the receiving time of the government affairs data access request, and the importance value corresponding to the target government affairs data, the embodiments of the present application only take the above two possible implementation manners as examples for illustration, and other manners can also be adopted. For example, the access control level corresponding to the target government affairs data can be determined based on a comparative evaluation method or a grade integration method, etc., and can be specifically set according to actual needs. Here, the embodiments of the present application do not make further limitations.

[0058] After jointly determining the access control level corresponding to the target government affairs data in combination with the identity information of the target object, the receiving time of the government affairs data access request, and the importance value corresponding to the target government affairs data, the target government affairs data can be encrypted based on the access control level, that is, the above S104 is executed.

[0059] Exemplarily, in the above S104, when encrypting the target government affairs data based on the access control level, the following at least two possible scenarios may be included: In a possible scenario, the access control level is a first-level access control level.

[0060] When the access control level is a first-level access control level, it indicates that the access control level of the target government affairs data is relatively high. Then, differential privacy processing can be performed on the target government affairs data first to obtain the government affairs data after privacy processing; and then, a homomorphic encryption algorithm is used to encrypt the government affairs data after privacy processing to obtain the ciphertext government affairs data.

[0061] Exemplarily, in the embodiments of the present application, when performing differential privacy processing on the target government affairs data, reference can be made to the following formula 1.

[0062] Formula 1 Among them, D represents the target government affairs data, represents the government affairs data after differential privacy processing, A function representing the target government affairs data, representing the sensitivity of the function, representing the privacy budget.

[0063] Exemplarily, when using the homomorphic encryption algorithm to encrypt the government affairs data after privacy processing, reference can be made to the following formula 2.

[0064] Formula 2 where, represents the encrypted government affairs data obtained by using the homomorphic encryption algorithm to encrypt the government affairs data after privacy processing, n represents a large prime number, g represents a generator, and r represents a random number.

[0065] In another possible scenario, the access control level is the first-level access control level, and the access control level of the second-level access control level is lower than that of the first-level access control level.

[0066] In the case where the access control level is the second-level access control level, it indicates that the access control level of the target government affairs data is relatively low, and then the homomorphic encryption algorithm can be used to encrypt the target government affairs data to obtain the encrypted government affairs data.

[0067] After only using the homomorphic encryption algorithm to encrypt the target government affairs data to obtain the encrypted government affairs data, the encrypted government affairs data can be sent to the target object; correspondingly, the target object can use the homomorphic decryption algorithm to decrypt the encrypted government affairs data to obtain the plaintext target government affairs data. Among them, the homomorphic decryption algorithm can be seen in the following formula 3.

[0068] where, represents the plaintext target government affairs data, represents the encrypted government affairs data obtained by using the homomorphic encryption algorithm to encrypt the target government affairs data, represents the decryption parameter, represents the normalization parameter.

[0069] In this way, after jointly determining the access control level corresponding to the target government affairs data by combining the identity information of the target object, the reception time of the government affairs data access request, and the importance value corresponding to the target government affairs data, the target government affairs data can be encrypted based on the access control level to obtain the encrypted encrypted government affairs data; and a government affairs data access response is sent to the target object; among them, the government affairs data access response includes the encrypted government affairs data, so that the target object can decrypt the encrypted government affairs data to obtain the target government affairs data, and the access control of the government affairs data is realized on the premise of ensuring the security and privacy of the government affairs data.

[0070] The access control device for government affairs data provided by this application will be described below. The access control device for government affairs data described below can be correspondingly referred to the access control method for government affairs data described above.

[0071] Figure 2 The following is a schematic structural diagram of an access control device for government affairs data provided by an embodiment of this application. By way of example, please refer to Figure 2 As shown, the access control device 20 for government affairs data may include: A receiving unit 201, configured to receive a government affairs data access request for target government affairs data sent by a target object; A determining unit 202, configured to determine an importance level value corresponding to the target government affairs data based on the attribute information of the target government affairs data; wherein, the attribute information includes sensitivity, impact degree, time limit value, and data integration difficulty; The determining unit 202 is further configured to determine an access control level corresponding to the target government affairs data based on the identity information of the target object, the receiving time of the government affairs data access request, and the importance level value corresponding to the target government affairs data; An encrypting unit 203, configured to perform encryption processing on the target government affairs data based on the access control level to obtain encrypted ciphertext government affairs data; A sending unit 204, configured to send a government affairs data access response to the target object; wherein, the government affairs data access response includes the ciphertext government affairs data, and the ciphertext government affairs data is used by the target object for decryption processing to obtain the target government affairs data.

[0072] By way of example, in an embodiment of this application, the determining unit 202 is configured to determine an importance level value corresponding to the target government affairs data based on the attribute information of the target government affairs data, including: Inputting the attribute information of the target government affairs data into a pre-constructed importance prediction model to obtain an access control level corresponding to the target government affairs data; Wherein, the importance prediction model is trained based on the attribute information of multiple government affairs data samples and their corresponding access control level labels.

[0073] By way of example, in an embodiment of this application, the determining unit 202 is configured to determine an access control level corresponding to the target government affairs data based on the identity information of the target object, the receiving time of the government affairs data access request, and the importance level value corresponding to the target government affairs data, including: Determining a first weight corresponding to the identity information of the target object, a second weight corresponding to the receiving time of the government affairs data access request, and a third weight corresponding to the importance level value corresponding to the target government affairs data; Based on the first weight, the second weight, and the third weight, perform a weighted sum on the identity information of the target object, the reception time of the government affairs data access request, and the importance value corresponding to the target government affairs data, to obtain the access control level corresponding to the target government affairs data.

[0074] Exemplarily, in an embodiment of the present application, the determining unit 202 is configured to determine the access control level corresponding to the target government affairs data based on the identity information of the target object, the reception time of the government affairs data access request, and the importance value corresponding to the target government affairs data, including: Obtain a fuzzy evaluation model established in advance based on the method of fuzzy mathematics theory; Input the identity information of the target object, the reception time of the government affairs data access request, and the importance value corresponding to the target government affairs data into the fuzzy evaluation model, and output the fuzzy values corresponding to the identity information of the target object, the reception time of the government affairs data access request, and the importance value corresponding to the target government affairs data respectively through the fuzzy evaluation model; Based on the fuzzy values corresponding to the identity information of the target object, the reception time of the government affairs data access request, and the importance value corresponding to the target government affairs data respectively, determine the access control level corresponding to the target government affairs data.

[0075] Exemplarily, in an embodiment of the present application, the encryption unit 203 is configured to perform encryption processing on the target government affairs data based on the access control level to obtain the encrypted ciphertext government affairs data, including: In the case where the access control level is a first-level access control level, perform differential privacy processing on the target government affairs data to obtain the government affairs data after privacy processing; Use a homomorphic encryption algorithm to perform encryption processing on the government affairs data after privacy processing to obtain the ciphertext government affairs data.

[0076] Exemplarily, in an embodiment of the present application, the encryption unit 203 is configured to perform encryption processing on the target government affairs data based on the access control level to obtain the encrypted ciphertext government affairs data, including: In the case where the access control level is a second-level access control level, use a homomorphic encryption algorithm to perform encryption processing on the target government affairs data to obtain the ciphertext government affairs data; Wherein, the access control level of the second-level access control level is lower than the access control level of the first-level access control level.

[0077] The access control device 20 for government affairs data provided by the embodiments of the present application can implement the technical solutions of the access control method for government affairs data in any of the above embodiments. Its implementation principle and beneficial effects are similar to those of the access control method for government affairs data. For details, refer to the implementation principle and beneficial effects of the access control method for government affairs data, which will not be elaborated here.

[0078] Figure 3 It is a schematic physical structure diagram of an electronic device provided by an embodiment of the present application. As Figure 3 shown, the electronic device may include: a processor 310, a communication interface 320, a memory 330, and a communication bus 340. Among them, the processor 310, the communication interface 320, and the memory 330 communicate with each other through the communication bus 340. The processor 310 can call the logical instructions in the memory 330 to execute the access control method for government affairs data, which includes: receiving a government affairs data access request for target government affairs data sent by a target object; determining an importance degree value corresponding to the target government affairs data based on the attribute information of the target government affairs data, where the attribute information includes sensitivity, impact degree, time limit value, and data integration difficulty; determining an access control level corresponding to the target government affairs data based on the identity information of the target object, the reception time of the government affairs data access request, and the importance degree value corresponding to the target government affairs data; encrypting the target government affairs data based on the access control level to obtain encrypted ciphertext government affairs data; sending a government affairs data access response to the target object, where the government affairs data access response includes the ciphertext government affairs data, and the ciphertext government affairs data is used by the target object for decryption processing to obtain the target government affairs data.

[0079] In addition, when the logical instructions in the above-mentioned memory 330 are implemented in the form of software function units and sold or used as an independent product, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art or a part of this technical solution can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present application. The foregoing storage medium includes: various media such as a USB flash drive, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk, or an optical disc that can store program codes.

[0080] On the other hand, the present application also provides a computer program product, which includes a computer program that can be stored on a computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the access control method for government affairs data provided by the above-mentioned various methods. The method includes: receiving a government affairs data access request for target government affairs data sent by a target object; determining an importance degree value corresponding to the target government affairs data based on the attribute information of the target government affairs data, where the attribute information includes sensitivity, influence degree, timeliness value, and data integration difficulty; determining an access control level corresponding to the target government affairs data based on the identity information of the target object, the reception time of the government affairs data access request, and the importance degree value corresponding to the target government affairs data; performing encryption processing on the target government affairs data based on the access control level to obtain encrypted ciphertext government affairs data; sending a government affairs data access response to the target object, where the government affairs data access response includes the ciphertext government affairs data, and the ciphertext government affairs data is used for the target object to perform decryption processing to obtain the target government affairs data.

[0081] On another aspect, the present application also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it realizes the access control method for government affairs data provided by the above-mentioned various methods. The method includes: receiving a government affairs data access request for target government affairs data sent by a target object; determining an importance degree value corresponding to the target government affairs data based on the attribute information of the target government affairs data, where the attribute information includes sensitivity, influence degree, timeliness value, and data integration difficulty; determining an access control level corresponding to the target government affairs data based on the identity information of the target object, the reception time of the government affairs data access request, and the importance degree value corresponding to the target government affairs data; performing encryption processing on the target government affairs data based on the access control level to obtain encrypted ciphertext government affairs data; sending a government affairs data access response to the target object, where the government affairs data access response includes the ciphertext government affairs data, and the ciphertext government affairs data is used for the target object to perform decryption processing to obtain the target government affairs data.

[0082] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. A person of ordinary skill in the art can understand and implement it without creative labor.

[0083] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0084] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. A method for controlling access to government data, characterized in that: include: Receiving a government affairs data access request for target government affairs data sent by a target object; Based on the attribute information of the target government data, determining the importance value corresponding to the target government data; wherein the attribute information includes sensitivity, impact, timeliness value and data integration difficulty; Determine the access control level corresponding to the target government data based on the identity information of the target object, the reception time of the government data access request and the importance value corresponding to the target government data; Encrypting the target government data based on the access control level to obtain encrypted ciphertext government data; Sending a government data access response to the target object; wherein the government data access response includes the ciphertext government data, and the ciphertext government data is used for decryption processing by the target object to obtain the target government data.

2. The access control method for government data according to claim 1 is characterized in that: The determining, based on the attribute information of the target government data, the importance value corresponding to the target government data includes: Inputting the attribute information of the target government data into a pre-built importance prediction model to obtain the access control level corresponding to the target government data; The importance prediction model is obtained by training based on the attribute information of multiple government data samples and the corresponding access control level labels.

3. The access control method for government data according to claim 1 is characterized in that: The determining the access control level corresponding to the target government data based on the identity information of the target object, the reception time of the government data access request and the importance value corresponding to the target government data includes: Determine a first weight corresponding to the identity information of the target object, a second weight corresponding to the reception time of the government data access request, and a third weight corresponding to the importance value corresponding to the target government data; Based on the first weight, the second weight and the third weight, the identity information of the target object, the reception time of the government data access request and the importance value corresponding to the target government data are weightedly summed to obtain the access control level corresponding to the target government data.

4. The access control method for government data according to claim 1 is characterized in that: The determining the access control level corresponding to the target government data based on the identity information of the target object, the reception time of the government data access request and the importance value corresponding to the target government data includes: Obtaining a fuzzy evaluation model established in advance based on a method of fuzzy mathematical theory; The identity information of the target object, the time of receiving the government data access request, and the importance value corresponding to the target government data are input into the fuzzy evaluation model, and the fuzzy numerical values ​​corresponding to the identity information of the target object, the time of receiving the government data access request, and the importance value corresponding to the target government data are output through the fuzzy evaluation model; The access control level corresponding to the target government data is determined based on the identity information of the target object, the reception time of the government data access request, and the fuzzy numerical values ​​corresponding to the importance value of the target government data.

5. The method for controlling access to government data according to claim 1, characterized in that: The step of encrypting the target government data based on the access control level to obtain encrypted ciphertext government data includes: When the access control level is the first-level access control level, performing differential privacy processing on the target government data to obtain privacy-processed government data; The privacy-processed government data is encrypted using a homomorphic encryption algorithm to obtain the ciphertext government data.

6. The method for controlling access to government data according to claim 5, characterized in that: The step of encrypting the target government data based on the access control level to obtain encrypted ciphertext government data includes: When the access control level is the secondary access control level, encrypting the target government data using a homomorphic encryption algorithm to obtain the ciphertext government data; The access control level of the secondary access control level is lower than the access control level of the primary access control level.

7. An access control device for government data, characterized in that: include: A receiving unit, used for receiving a government affairs data access request for target government affairs data sent by a target object; A determination unit, configured to determine the importance value corresponding to the target government data based on the attribute information of the target government data; wherein the attribute information includes sensitivity, impact, timeliness value and data integration difficulty; The determining unit is further configured to determine the access control level corresponding to the target government data based on the identity information of the target object, the time of receipt of the government data access request, and the importance value corresponding to the target government data; An encryption unit, used for encrypting the target government data based on the access control level to obtain encrypted ciphertext government data; A sending unit is used to send a government data access response to the target object; wherein the government data access response includes the ciphertext government data, and the ciphertext government data is used for decryption processing by the target object to obtain the target government data.

8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and running on the processor, characterized in that: When the processor executes the computer program, the access control method for government data as described in any one of claims 1 to 6 is implemented.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the access control method for government data as described in any one of claims 1 to 6 is implemented.

10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the access control method for government data as described in any one of claims 1 to 6 is implemented.

Citation Information

Cited By

  • Medical data security encryption method

    CN122087844A