Database access control method and system for enhancing data privacy protection

By dynamically generating fine-grained access permission rules and real-time verification of user requests in a multi-tenant database environment, combining logging and dynamic encryption policies, the security and privacy issues of data access control in a multi-tenant database environment are solved, and fine-grained access control and data security protection for different user roles are realized.

CN120068153AInactive Publication Date: 2025-05-30WEIHAI VOCATIONAL COLLEGE
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510227690.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-28
Publication Date
2025-05-30
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

In a multi-tenant database environment, how to effectively regulate fine-grained access rights to ensure the security and privacy of data access, while solving the problems of query logging and auditing, dynamic encryption and key management, data desensitization and personalized privacy preference configuration.

Method used

By dynamically generating fine-grained access permission rules, real-time verification and regulation of user data access requests, recording and auditing of each data access behavior, dynamically adjusting data desensitization degree and encryption key management strategy, and adjusting according to user personalized privacy preference configuration and access behavior patterns.

Benefits of technology

It realizes fine-grained access rights control for different user roles, ensures the security and privacy of data access, can promptly discover and trace unauthorized data access behavior, dynamically adjust encryption policies to ensure data security, and adapt to the privacy preferences of different users.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120068153A_ABST
    Figure CN120068153A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of database security access control privacy protection, and discloses a database access control method and system for enhancing data privacy protection. According to the database access control method and system for enhancing data privacy protection, query log records and audit are regulated and controlled, and data access behaviors can be completely and accurately recorded; when unauthorized data access occurs, information such as an access source and operation content can be quickly traced according to the records, illegal access behaviors can be found and processed in time, the effect of deterring potential attackers is achieved, compliance and safety of data access are guaranteed, dynamic encryption and key management strategies are regulated and controlled, and the security of data access is improved. And the encryption mode and the key management method can be flexibly adjusted according to the sensitivity of the data and the change of storage and transmission scenes. In the storage and transmission process, high-strength safety protection is provided for sensitive data all the time, and the data are prevented from being stolen or cracked under the conditions that a storage medium is lost or a transmission link is eavesdropped or the like.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of database security access control and privacy protection, and particularly to a database access control method and system for enhancing data privacy protection. Background Art

[0002] A database access control method for enhancing data privacy protection aims to prevent possible privacy leakage during database operations by introducing multi-level security mechanisms. This method finely adjusts various security policies to ensure that data access by different user roles in a multi-tenant environment is both effective and privacy-preserving. Specifically, the first issue is about how to regulate fine-grained access permissions: by setting specific permissions for each user role, the minimum required access permissions can be provided for each user on the shared platform, thus preventing unnecessary leakage of sensitive information. Secondly, the method also needs to address the problem of query logging and auditing, that is, how to accurately and securely record each data access situation in order to promptly detect and trace unauthorized access behaviors. Thirdly, considering the confidentiality during data storage and transmission, it requires a reasonable dynamic encryption and key management strategy to ensure the secure circulation of information without affecting performance. Fourthly, in order to avoid the disclosure of sensitive information in an unauthorized environment, it is also necessary to optimize the data masking technology and determine the appropriate masking degree and scope according to actual needs. Finally, the issue of personalized privacy preferences also needs to be taken into account - users should be allowed to adjust the privacy protection intensity based on their own needs, which will help to coordinate the contradiction between user-specific needs and the general security policies formulated by the organization. The above five points together constitute the key elements of the core challenges of this method and determine the quality of its implementation effect. Summary of the Invention

[0003] To solve the problems raised in the above background art, this application provides a database access control method and system for enhancing data privacy protection.

[0004] This application provides a database access control method and system for enhancing data privacy protection, adopting the following technical solutions:

[0005] A database access control method for enhancing data privacy protection includes:

[0006] S101. Dynamically generate fine-grained access permission rules according to the personalized privacy preference configurations of each user role in a multi-tenant environment;

[0007] S102. Real-time verify and regulate the data access requests initiated by users by applying the fine-grained access permission rules;

[0008] S103. Record and audit each verification process and result to form a detailed security log for monitoring and tracing unauthorized data access behavior;

[0009] S104. Dynamically adjust the data masking degree and scope, as well as the encryption key management strategy, based on the log information and user role definition to ensure data security.

[0010] Preferably, the dynamically adjusting the data masking degree and scope, as well as the encryption key management strategy based on the log information and user role definition to ensure data security further includes:

[0011] Based on the access behavior patterns of different user roles, analyze the access frequency P in the log information in real time;

[0012] Calculate the data sensitivity coefficient S = log(Σ(T[i] * W[i])), where T[i] is the timestamp difference (time weight) of the i-th access, W[i] is the permission level weight of the i-th access, and S represents data sensitivity;

[0013] If S > H, increase the data masking degree and reduce the plaintext exposure range; if S ≤ H, maintain the current data masking degree. The formula is IF(S > H, masking intensity++, masking intensity unchanged), where H is the predetermined high-sensitivity threshold and S is the data sensitivity;

[0014] Dynamically generate the encryption key K and immediately replace it after detecting any unauthorized access.

[0015] Preferably, the dynamically adjusting the data masking degree and scope, as well as the encryption key management strategy based on the log information and user role definition to ensure data security further includes:

[0016] Based on the personalized privacy preference configuration Pp of each user, set different security levels Gj in the system to classify and manage data;

[0017] For the same user who frequently calls a certain security level n(i) within the same period, record the number of times C(i);

[0018] Calculate the request frequency coefficient F(n(i)) = E / √C(i) of this level. When F(n(i)) exceeds the set security threshold T, execute a higher-level verification mechanism (here E is the standard value of the expected call times);

[0019] Formula expression: IF(F(n(i)) > T, introduce the two-factor authentication verification process). If the frequency exceeds the limit, trigger additional verification means to ensure that it is difficult to obtain the right to access critical data in the case of unauthorized access.

[0020] Preferably, dynamically adjusting the data desensitization degree and scope as well as the encryption key management strategy based on log information and user role definition to ensure data security further includes:

[0021] According to the queried log records and the user's historical activities, identify the proportion A(t) of abnormal operations occurring within a specific time period t0;

[0022] Establish a correlation matrix M for all abnormal activities and calculate the risk score RS[M(i,j)] = SUM(A(t) * B * P), where M(i,j) represents the degree of correlation between users or multiple operations of a single user, and A(t) represents the proportion of abnormal activities occurring in different time periods;

[0023] Set a risk assessment function, that is, if RS exceeds the critical point K, then implement enhanced protection or temporary block for the relevant resources. For example, IF(RS>K), trigger an alarm and report the abnormal situation to the administrator;

[0024] Update and optimize each level of security rules in a timely manner according to the above conditions, so as to improve the accuracy of identifying potential threats and the response speed.

[0025] Preferably, dynamically adjusting the data desensitization degree and scope as well as the encryption key management strategy based on log information and user role definition to ensure data security further includes:

[0026] Collect logs from multiple sources (internal and external audit systems, firewall logs, etc.), extract useful fields to form a summary view U;

[0027] Sort the information flow in the summary view and determine whether there is a known attack pattern PM or a new type of suspicious action NM;

[0028] Suppose X% of the log entries match a certain pattern, and the same warning occurs more than twice continuously. The formula is expressed as: IF(PM >= X OR COUNT(DISTINCT NM) > Y), trigger an emergency security meeting to discuss countermeasures;

[0029] Revise and strengthen the existing key management system and access control list according to the meeting results.

[0030] Preferably, dynamically adjusting the data desensitization degree and scope as well as the encryption key management strategy based on log information and user role definition to ensure data security further includes:

[0031] Combined with personalized privacy preference configuration and actual business requirements, design a dynamic adjustment mechanism DAM suitable for multi-tenant environments;

[0032] Use sliding window technology to track the changes in user behavior over the past Z working days and count the daily activity deviation from the mean D(d) = AVG((X[d]u)), where u is the basic standard daily average activity and X[] stores the actual observation value of each day;

[0033] When a level of activity that is consistently higher than the baseline is observed for N consecutive days (i.e., ∑_(i=0)^(N1)(XiD)>O), these accounts will be considered to be of special importance and should be given special protection;

[0034] Based on this judgment logic, the fine-grained permission settings and corresponding desensitization parameters of relevant users are automatically adjusted to meet higher security compliance requirements.

[0035] A database access control system for enhancing data privacy protection, the system is executed by the database access control method for enhancing data privacy protection, and the system comprises:

[0036] The generation module is responsible for generating keys for data encryption and decryption. Strong and random keys are essential to ensure the security of encrypted data. For example, when using the AES encryption algorithm, the generation module will generate encryption keys of appropriate length (such as 128 bits, 192 bits, or 256 bits) according to specific key generation rules. These keys are used to encrypt the storage and transmission of sensitive data in the database to ensure that the data is protected even if it is illegally obtained.

[0037] Verification and control module: The verification module will strictly verify the identity information entered by the user, such as user name, password, digital certificate, etc., and compare it with the user identity data stored in the database to ensure that the user is who he claims to be, prevent illegal users from impersonating legitimate users to access the database, and avoid data leakage risks;

[0038] The monitoring module records all user operations in the database in real time, including login time, query content, data modification records, etc. By recording these behaviors in detail, it provides basic data for subsequent analysis and auditing;

[0039] The dynamic data adjustment module can analyze users' access patterns and needs in real time. If it is found that the frequency of access to specific data by a certain user or user group has increased significantly, the module can automatically adjust the data storage method or access permissions to improve access efficiency. For example, in an e-commerce database, the number of accesses to data related to popular products may increase significantly when a shopping festival is approaching. The dynamic data adjustment module can cache this data to a more accessible location, or add temporary higher-level access permissions to relevant users to ensure a quick response to query requests.

[0040] In summary, the present application includes at least one of the following beneficial technical effects:

[0041] 1. The database access control method and system for enhancing data privacy protection can accurately restrict the access of different user roles to data in a multi-tenant environment by regulating fine-grained access permissions, avoid privacy leakage caused by excessive permissions, ensure the effective protection of the data privacy of each tenant, and enable different user roles to only access the data they are authorized to, enhancing the security and privacy of data in a multi-tenant environment.

[0042] 2. The database access control method and system for enhancing data privacy protection regulate query log records and audits, and can completely and accurately record data access behaviors. When unauthorized data access occurs, it can quickly trace information such as the access source and operation content based on these records, which helps to promptly discover and handle illegal access behaviors, plays a role in deterring potential attackers, and ensures the compliance and security of data access.

[0043] 3. The database access control method and system for enhancing data privacy protection regulate dynamic encryption and key management strategies, and can flexibly adjust the encryption method and key management method according to the sensitivity of data and changes in storage and transmission scenarios. During storage and transmission, it always provides high-intensity security protection for sensitive data, prevents data from being stolen or cracked in cases such as the loss of storage media or the eavesdropping of transmission links, and ensures the security of sensitive data throughout its life cycle.

[0044] 4. The database access control method and system for enhancing data privacy protection reasonably regulate the degree and scope of data masking, and can appropriately process sensitive information in an unauthorized environment according to different scenarios and risk levels. It not only ensures that the risk of sensitive information exposure is minimized without affecting the usability of data, prevents sensitive information from being maliciously used, but also meets the data usage requirements of different business scenarios.

[0045] 5. The database access control method and system for enhancing data privacy protection regulate personalized privacy preference configurations, and can take into account general security policies while meeting the specific privacy needs of users. It resolves the conflict between the two, improves users' satisfaction with data privacy protection, and at the same time ensures the effectiveness of the overall security policy, making the system both meet users' personalized requirements and maintain the overall security protection level. Brief Description of the Drawings

[0046] Figure 1 It is a flowchart of a database access control method for enhancing data privacy protection according to the present invention.

[0047] Figure 2 It is a flowchart of a database access control system for enhancing data privacy protection according to the present invention. Detailed Implementation Modes

[0048] The following details the implementation modes of the present application, and examples of the implementation modes are shown in the accompanying drawings.

[0049] In the description of this specification, the description with reference to the terms "certain implementation modes", "one implementation mode", "some implementation modes", "schematic implementation modes", "examples", "specific examples", or "some examples" means that the specific features, structures, materials, or characteristics described in connection with the implementation mode or example are included in at least one implementation mode or example of the present application. In this specification, the schematic expressions of the above terms do not necessarily refer to the same implementation mode or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in a suitable manner in any one or more implementation modes or examples.

[0050] Next, refer to the attached Figure 1 , and describe each step of a database access control method for enhancing data privacy protection of the present invention. This method aims to solve the data privacy protection problem in a multi-tenant environment, especially the challenges faced in aspects such as different user roles, logging and auditing, dynamic encryption and key management, data desensitization degree, and regulation of personalized privacy preferences.

[0051] First, according to the personalized privacy preference configuration of each user role in the multi-tenant environment, the system dynamically generates fine-grained access permission rules, which is achieved through a predefined privacy preference module. Each user role can customize the specific content that needs to be protected in data access, such as personal identity information, financial information, medical records, etc. These personalized privacy preferences are mapped to a series of specific access control policies to ensure that only users with corresponding permissions can view specific types of data. Specifically, in the system initialization stage, the administrator or user can set personalized security levels and access control conditions according to their roles (such as ordinary users, auditors, administrators). Then, these preferences will be converted into a set of detailed rules and stored in a permission rule table. For example, in a multi-tenant enterprise information system, the finance department may need to strictly restrict anyone except specific personnel from viewing financial reports.

[0052] Subsequently, by applying the described fine-grained access permission rules, the system will conduct real-time verification and regulation on the data access requests initiated by users. Whenever a user attempts to obtain a certain piece of information, the system will first extract the authentication token of the current user, decode the role identifier and other permission information carried therein, and match and verify it with the previously defined rule set. If the match fails during this process, the access request will be immediately blocked and an error message will be returned to the user; otherwise, the request will continue to be processed and access rights will be granted or data display with some sensitive fields masked. In this embodiment, a company HR staff member attempts to view the specific salary records of other employees after logging in. However, since his role does not have full access rights to read this data, he can only obtain a partially blurred presentation result, such as only the salary level instead of the specific amount.

[0053] In addition, after each access request undergoes the verification and authorization process, all involved operations and results will be recorded in a complete and detailed manner to form a detailed security log for future analysis, review, and tracing of unauthorized behaviors. The log contains important elements such as date-time stamps, initiator UIDs, the names and types of the objects being operated on, etc. With such a log system, not only can potential internal abuse risks be effectively curbed, but also reliable investigation materials can be provided for external regulatory agencies. For example, in a large cloud service provider, assuming abnormal traffic activities are detected, the suspected intrusion IP address can be found by referring to the logs for the corresponding period, further narrowing down the suspicious scope until the real source of the violation is located and necessary blocking actions are taken.

[0054] Furthermore, to ensure that sensitive data is under strict protection from the very beginning, it is also necessary to rely on efficient and reliable dynamic encryption / decryption processing measures for the data itself, that is, based on the log information and user role characteristics mentioned above, regularly evaluate the validity period of the current key and replace the key in a timely manner to prevent the risk of being cracked due to long-term immutability and resulting in a security breach threat. At the same time, based on the access control list, determine the highly confidential items that are about to be accessed, and thus decide to activate a high-strength cryptographic algorithm to encrypt and package them to ensure invisibility and confidentiality during the transmission process. For example, a hospital stores patients' medical records using a high-level public-private key scheme to ensure that even if the files are accidentally leaked, no valuable medical conclusions can be understood by the outside world.

[0055] Finally, another equally important technology is about how to accurately adapt to different scenario requirements and appropriately adjust the authenticity of the content presented in the unlicensed environment, that is, the formulation of data desensitization strategies. This link relies on the accumulated user access habit statistical data mentioned above and logical rule reasoning to jointly calculate what level of disguise means should be applied to achieve the goal of both normally exerting the statistical significance of data and helping to hide core details. For example, for marketing team members, they often only need to understand the general trend rather than the exact case numbers. So, some simple mathematical transformations can be done on the original values at the report summary level or replaced with fictional codes for sharing without worrying about revealing customer identity characteristics and thus causing compliance problems.

[0056] In summary, the above-mentioned enhanced database access mechanism covers multiple aspects of innovative design, not only effectively enhancing the privacy protection ability in modern information systems, but also flexibly taking into account business continuity and operability management, truly reflecting the value orientation of people-oriented in the development of information technology. In actual application scenarios, it can help enterprises and organizations calmly cope with complex and changing data security risks, while meeting the growing information security guarantee needs, enabling users to enjoy convenient and fast application experiences on a more reassuring and reliable service platform.

[0057] In one embodiment, a database access control system for enhancing data privacy protection is also disclosed. This system is executed by the above-mentioned method for enhancing data privacy protection in a database access control, as Figure 2 shown, the system includes:

[0058] A generation module, responsible for generating keys for data encryption and decryption. Powerful and random keys are crucial for ensuring the security of encrypted data. For example, when using the AES encryption algorithm, the generation module will generate encryption keys of appropriate lengths (such as 128 bits, 192 bits, or 256 bits) according to specific key generation rules. These keys are used for encrypting and storing sensitive data in the database and encrypting the transmission, ensuring that the data cannot be illegally obtained even if it is intercepted;

[0059] A verification and regulation module. The verification module will strictly verify the user input identity information, such as user name, password, digital certificate, etc., and compare it with the user identity data stored in the database to ensure that the user is the identity they claim to be, preventing illegal users from impersonating legitimate users to access the database and avoiding the risk of data leakage;

[0060] A monitoring module, which records all the operation behaviors of users in the database in real time, including login time, query content, records of modified data, etc. By recording these behaviors in detail, it provides basic data for subsequent analysis and auditing;

[0061] The dynamic data adjustment module can analyze users' access patterns and needs in real time. If it is found that the frequency of access to specific data by a certain user or user group has increased significantly, the module can automatically adjust the data storage method or access permissions to improve access efficiency. For example, in an e-commerce database, the number of accesses to data related to popular products may increase significantly when a shopping festival is approaching. The dynamic data adjustment module can cache this data to a more accessible location, or add temporary higher-level access permissions to relevant users to ensure a quick response to query requests.

[0062] Although the embodiments of the present application have been shown and described above, it can be understood that the above embodiments are exemplary and cannot be understood as limitations on the present application. Ordinary technicians in this field can change, modify, replace and modify the above embodiments within the scope of the present application.

Claims

1. A database access control method for enhancing data privacy protection, characterized in that: include: S101, dynamically generate fine-grained access rights rules based on the personalized privacy preference configuration of each user role in a multi-tenant environment; S102, performing real-time verification and regulation on the data access request initiated by the user by applying the fine-grained access permission rule; S103. Record and audit each verification process and results to form a detailed security log to monitor and trace unauthorized data access behavior; S104. Based on the log information and user role definition, dynamically adjust the degree and scope of data desensitization and encryption key management strategy to ensure data security.

2. A database access control method for enhancing data privacy protection according to claim 1, characterized in that: The dynamically adjusting the degree and scope of data desensitization and encryption key management strategy based on log information and user role definition to ensure data security further includes: Based on the access behavior patterns of different user roles, the access frequency P in the log information is analyzed in real time; Calculate the data sensitivity coefficient S = log(Σ(T[i]*W[i])), where T[i] is the timestamp difference of the i-th access (time weight), W[i] is the permission level weight of the i-th access, and S represents the data sensitivity; If S>H, the data desensitization level is increased to reduce the exposure range of plain text; if S≤H, the current data desensitization level is maintained, and the formula is IF(S>H, desensitization strength++, desensitization strength remains unchanged), where H is the predetermined high sensitivity threshold and S is the data sensitivity; The encryption key K is dynamically generated and replaced immediately upon detection of any unauthorized access.

3. A database access control method for enhancing data privacy protection according to claim 1, characterized in that: Dynamically adjust the degree and scope of data desensitization and encryption key management strategies based on log information and user role definitions to ensure data security further includes: Based on each user's personalized privacy preference configuration Pp, different security levels Gj are set in the system to manage data in a hierarchical and classified manner; For the same user who frequently calls a certain security level n(i) in the same period, record the number C(i); Calculate the request frequency coefficient of this level F(n(i)) = E / √C(i), and execute a higher-order verification mechanism when F(n(i)) exceeds the set safety threshold T (here E is the standard value of the expected number of calls); Formula expression: IF(F(n(i))>T, introduce a secondary verification code verification process), if the frequency exceeds the limit, additional verification measures are triggered to ensure that it is difficult to obtain access to key data without authorization.

4. A database access control method for enhancing data privacy protection according to claim 1, characterized in that: Dynamically adjust the degree and scope of data desensitization and encryption key management strategies based on log information and user role definitions to ensure data security further includes: Based on the query log records and the user's historical activities, identify the proportion A(t) of abnormal operations in a specific time period t0; For all abnormal activities, a correlation matrix M is established and the risk score RS[M(i,j)]=SUM(A(t)*B*P) is calculated. Here, M(i,j) represents the correlation between users or multiple operations of a single user, and A(t) represents the proportion of abnormal activities occurring in different time periods. Set a risk assessment function. If RS exceeds the critical point K, then strengthen protection or temporarily block the relevant resources. If (RS>K), an alarm will be triggered and the abnormal situation will be reported to the administrator. Update and optimize security rules at all levels in a timely manner based on the above conditions, thereby improving the accuracy of identifying potential threats and the speed of response.

5. A database access control method for enhancing data privacy protection according to claim 1, characterized in that: Dynamically adjust the degree and scope of data desensitization and encryption key management strategies based on log information and user role definitions to ensure data security further includes: Collect logs from multiple sources (internal and external audit systems, firewall logs, etc.) and extract useful fields to form a summary view U; Sort the information flow in the summary view and determine whether there are known attack patterns PM or new types of suspicious actions NM; Assuming that X% of log items match a certain pattern, and the same warning occurs more than twice in a row, the formula is: IF(PM>=X OR COUNT(DISTINCT NM)>Y), triggering an emergency security meeting to discuss countermeasures; Revise and strengthen the existing key management system and access control list based on the meeting results.

6. A database access control method for enhancing data privacy protection according to claim 1, characterized in that: Dynamically adjust the degree and scope of data desensitization and encryption key management strategies based on log information and user role definitions to ensure data security further includes: Combining personalized privacy preference configuration and actual business needs, we designed a dynamic adjustment mechanism DAM that is suitable for multi-tenant environments; Use sliding window technology to track the changes in user behavior over the past Z working days and count the daily activity deviation from the mean D(d) = AVG((X[d]u)), where u is the basic standard daily average activity and X[] stores the actual observation value of each day; When a level of activity that is consistently higher than the baseline is observed for N consecutive days (i.e., ∑_(i=0)^(N1)(XiD)>O), these accounts will be considered to be of special importance and should be given special protection; Based on this judgment logic, the fine-grained permission settings and corresponding desensitization parameters of relevant users are automatically adjusted to meet higher security compliance requirements.

7. A database access control system for enhancing data privacy protection according to claim 1, characterized in that: The system is executed by a database access control method for enhancing data privacy protection according to any one of claims 1 to 6, and the system comprises: The generation module is responsible for generating keys for data encryption and decryption. Strong and random keys are essential to ensure the security of encrypted data. For example, when using the AES encryption algorithm, the generation module will generate encryption keys of appropriate length (such as 128 bits, 192 bits, or 256 bits) according to specific key generation rules. These keys are used to encrypt the storage and transmission of sensitive data in the database to ensure that the data is protected even if it is illegally obtained. Verification and control module: The verification module will strictly verify the identity information entered by the user, such as user name, password, digital certificate, etc., and compare it with the user identity data stored in the database to ensure that the user is who he claims to be, prevent illegal users from impersonating legitimate users to access the database, and avoid data leakage risks; The monitoring module records all user operations in the database in real time, including login time, query content, data modification records, etc. By recording these behaviors in detail, it provides basic data for subsequent analysis and auditing; The dynamic data adjustment module can analyze users' access patterns and needs in real time. If it is found that the frequency of access to specific data by a certain user or user group has increased significantly, the module can automatically adjust the data storage method or access permissions to improve access efficiency. For example, in an e-commerce database, the number of accesses to data related to popular products may increase significantly when a shopping festival is approaching. The dynamic data adjustment module can cache this data to a more accessible location, or add temporary higher-level access permissions to relevant users to ensure a quick response to query requests.