Data security guarantee method and device based on industrial internet identification analysis system

By receiving data access requests, matching security policy rules and dynamic threshold calculations in the industrial Internet identification resolution system, the difficulties of large manufacturing enterprises in data access control and security policy updates are solved, and flexible security policy adjustments and data security guarantees are achieved.

CN120151048APending Publication Date: 2025-06-13FOSHAN LIANKEFA INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510331944.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-20
Publication Date
2025-06-13

AI Technical Summary

Technical Problem

When large manufacturing enterprises meet the needs of refined data access control, traceable audit of operational behaviors and dynamic update of security policies, it is difficult for them to design a data security guarantee method for industrial Internet identification resolution system to achieve strict internal enterprise security strategy control for accessing and resolving system data from different departments and employees.

Method used

By receiving data access requests, pre-configured security policy rule matching is performed, and access request scores are calculated based on the matching successful rules. Combining the context information of the system's security status and load status, access thresholds are calculated dynamically, scores are compared with thresholds, and decisions are generated to allow or deny access.

Benefits of technology

It realizes access control based on dynamic thresholds, and can flexibly adjust the strictness of security policies based on system context information, ensure data security and compliance, and quickly adjust and deploy when policy adjustments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120151048A_ABST
    Figure CN120151048A_ABST
Patent Text Reader

Abstract

The invention provides a data security guarantee method and device based on an industrial internet identification analysis system, and is applied to the technical field of industrial internet, and the method comprises the steps: receiving a data access request, and obtaining a user identity and a data attribute requested to be accessed; performing multi-dimensional security check on the access request through a pre-configured security policy rule; real-time information such as a system safety state and a load state is collected; dynamically calculating an access threshold through the acquired context information; the calculated access request score is compared to the calculated dynamic access threshold. Access is allowed only when the access request score reaches or exceeds a dynamic access threshold. Therefore, the scheme has the advantages that the security policy is effectively integrated into an industrial internet identifier analysis system, the data security and compliance are guaranteed, and quick adjustment and deployment can be realized during policy adjustment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of industrial Internet, and in particular to a data security guarantee method and device based on the industrial Internet identification and resolution system. Background Art

[0002] In order to achieve comprehensive security protection for the industrial Internet identification and resolution system, enterprises have formulated strict internal security policies. This policy not only requires authentication and authorization for all behaviors accessing the data of the resolution system, but also carefully divides the data access rights of different departments and employees. For example, the production department can only access data related to its production line, the R & D department can access product design and process data, while the finance department can only access data related to cost accounting. In addition, the enterprise's security policy also emphasizes the traceability of operation behaviors. Any access and modification to the data of the resolution system must be recorded for security auditing and risk tracing. At the same time, in order to cope with increasingly complex network security threats, the enterprise's security policy requires that security measures can be updated and upgraded regularly to adapt to new security challenges. Therefore, in practical applications, it is necessary to design a data security guarantee method that can effectively integrate these fine-grained security policies into the industrial Internet identification and resolution system, ensuring that different departments can meet business needs while strictly complying with the enterprise's internal security regulations when accessing data, and preventing security incidents such as data leakage and unauthorized access.

[0003] When large manufacturing enterprises need to meet the enterprise's internal security policy that requires both refined data access control, traceable auditing of operation behaviors, and dynamic update of security policies, designing a data security guarantee method for the industrial Internet identification and resolution system to implement strict control of the enterprise's internal security policy over the behaviors of different departments and employees accessing the data of the resolution system, and being able to quickly adjust and deploy when the policy is adjusted, to ensure data security and compliance has become an urgent technical problem to be solved. Summary of the Invention

[0004] In view of the deficiencies of the above-mentioned prior art, the data security guarantee method and device based on the industrial Internet identification and resolution system provided by this application are applied in the technical field of industrial Internet, and have the advantages of effectively integrating security policies into the industrial Internet identification and resolution system, ensuring data security and compliance, and being able to quickly adjust and deploy when the policy is adjusted.

[0005] In a first aspect, a data security guarantee method based on the industrial Internet identification and resolution system, the steps of the method include: S1: Receive a data access request, where the data access request is used to request access to the data of the industrial Internet identification and resolution system; S2: Perform rule matching on the data access request according to pre-configured security policy rules, and calculate the access request score of the data access request based on the weight values of the allowed access rules that match successfully; S3: Obtain the context information of the system security status and the system load status, and calculate the dynamic access threshold according to the obtained context information; S4: Compare the access request score with the dynamic access threshold. When the access request score is greater than or equal to the dynamic access threshold, generate a decision to allow access; otherwise, generate a decision to deny access.

[0006] A data security guarantee method based on the industrial Internet identification resolution system provided by this application. By receiving a data access request and obtaining the user identity and the data attributes requested to be accessed, it provides basic information for subsequent policy matching and scoring; performs multi-dimensional security checks on the access request through pre-configured security policy rules. The weight values assign different importance to different rules, and the access request score is obtained by accumulating the weight values, realizing a preliminary security assessment based on the policy; by collecting real-time information such as the system security status and the load status, such as the security threat level and the system load situation. These information reflect the current security risks and operating conditions of the system, providing a basis for dynamically adjusting the access threshold; calculating the dynamic access threshold through the obtained context information. The higher the system security risk or the higher the load, the higher the dynamic access threshold, thereby increasing the strictness of access control; comparing the calculated access request score with the calculated dynamic access threshold. Only when the access request score reaches or exceeds the dynamic access threshold is access allowed. The method proposed in this application realizes access control based on a dynamic threshold, can flexibly adjust the strictness of the security policy according to the system context information, and takes into account the availability and performance of the system while ensuring security. Therefore, this solution has the advantages of effectively integrating the security policy into the industrial Internet identification resolution system, ensuring data security and compliance, and being able to be quickly adjusted and deployed when the policy is adjusted.

[0007] Further, step S2 includes: S21: Classify the pre-configured security policy rules to obtain at least one rule classification, and each rule classification contains at least one security policy rule; S22: For the data access request, determine the rule classification that matches the data access request; S23: In the determined rule classification, match the data access request with the security policy rules included in this rule classification to obtain the allowed access rules that match successfully; S24: For each allowed access rule that matches successfully, obtain the pre-configured weight value, and accumulate to obtain the access request score of the data access request.

[0008] A data security guarantee method based on the industrial Internet identification and resolution system provided by this application classifies pre-configured security policy rules to form multiple rule classifications. Each classification contains relevant security policy rules, organizing a large number of security policy rules for easy management and search. For the received data access request, instead of matching all rules, it first determines which rule classification or classifications the request should match, which is equivalent to narrowing the scope of rule matching and improving the matching efficiency. Inside the determined rule classification, the data access request is then matched with the security policy rules under this classification to obtain the finally successfully matched rules. On the basis of ensuring the matching of security policy rules, the matching efficiency is improved, especially when the number of security policy rules is huge, this efficiency improvement is more obvious. At the same time, the rule classification also makes the management and maintenance of security policy rules more convenient, which is conducive to quickly responding to the needs of policy adjustment.

[0009] Further, step S21 includes: S211: Obtain all pre-configured security policy rules; S212: Traverse all security policy rules. For each security policy rule, analyze the applicable department information, and classify this security policy rule into the corresponding first-level rule classification according to the department information; if there is no first-level rule classification for the corresponding department, create a new first-level rule classification for the corresponding department; S213: For each first-level rule classification, traverse the security policy rules under this first-level rule classification, analyze the applicable data security level information, and classify this security policy rule into the corresponding second-level rule classification according to the data security level information; if there is no second-level rule classification for the corresponding data security level, create a new second-level rule classification for the corresponding data security level under the current first-level rule classification; S214: Output the security policy rules after multi-level classification, where each second-level rule classification contains at least one security policy rule, and each second-level rule classification belongs to a first-level rule classification, and each first-level rule classification corresponds to a department.

[0010] A data security guarantee method based on the industrial Internet identification and resolution system provided by this application obtains all security policy rules as the basic data for classification, and conducts first-level classification according to department information to ensure that the security policy rules of different departments are effectively isolated and managed; then, under the first-level classification of each department, secondary classification is carried out according to the data security level, realizing a more refined rule organization. This secondary classification method organizes the security policy rules according to departments and data security levels, constructs a clear rule structure, facilitates subsequent rapid rule search and matching, and finally outputs the classification results, ultimately forming a multi-level classification security policy rule system. Each secondary rule classification contains at least one rule and belongs to the first-level rule classification of a department. This solution realizes the structured and refined management of security policy rules, improves the efficiency of rule matching, and lays a foundation for the subsequent application of security policy rules.

[0011] Further, step S24 includes: S241: Obtain the set R_matched of allowed access rules with successful matches, where the R_matched contains n allowed access rules with successful matches, expressed as R_matched = {Rule_1, Rule_2, ..., Rule_n}; S242: Initialize the access request score Score of the data access request to 0; S243: For each rule Rule_j in the set R_matched of allowed access rules with successful matches, where the value range of j is from 1 to n, obtain the pre-configured weight value W_j, where the W_j represents the weight value of the rule Rule_j; S244: Calculate the access request score Score of the data access request using the cumulative weight scoring model, and the calculation formula is as follows: Score = ∑_{j=1}^{n} W_j; where ∑ represents the summation operation, j represents the index of the allowed access rule with a successful match, n represents the total number of allowed access rules with successful matches, and W_j represents the pre-configured weight value of the jth allowed access rule with a successful match Rule_j.

[0012] A data security guarantee method based on the industrial Internet identification and resolution system provided by this application provides a specific process for calculating the access request score, obtains the set of rules with successful matches, initializes the score, and obtains the weight value of each rule with a successful match. Using the cumulative model, the weight values of all rules with successful matches are summed up to obtain the final access request score. By adopting this technical means, this solution makes the calculation process of the access request score clearer and more operable. It provides a quantitative basis for subsequent access decisions and makes the access control process more accurate and effective.

[0013] Further, step S3 includes: S31: Collect multiple types of context information characterizing the system security state and the system load state, where the context information includes security threat level information, system load information, and user behavior anomaly information; S32: For each type of context information, determine a threshold adjustment parameter corresponding to this type of context information. Among them, different types of context information correspond to different threshold adjustment parameters, and the threshold adjustment parameter is used to characterize the influence degree of this type of context information on the dynamic access threshold; S33: Based on each type of context information and the corresponding threshold adjustment parameter, calculate a threshold adjustment value corresponding to each type of context information; S34: Aggregate the threshold adjustment values corresponding to all types of context information to obtain the final dynamic access threshold.

[0014] Further, step S33 includes: S331: For the three types of context information of security threat level information, system load information, and user behavior anomaly information, respectively perform the following operations: Obtain a quantization value C_i of each type of context information, where i = 1, 2, 3, respectively representing security threat level information, system load information, and user behavior anomaly information; Obtain a threshold adjustment parameter P_i, a threshold trigger value T_i, and an adjustment slope scaling factor S_i corresponding to each type of context information i; S332: Calculate a threshold adjustment value Adj_i corresponding to each type of context information i according to the following piecewise linear function: When C_i ≤ T_i, Adj_i = 0; When C_i>T_i, Adj_i = S_i * P_i * (C_i - T_i); Among them, P_i is the threshold adjustment parameter of the i-th type of context information, which is used to adjust the influence degree of the i-th type of context information on the threshold adjustment value, and P_i>0; T_i is the threshold trigger value of the i-th type of context information, indicating that when C_i exceeds T_i, this type of context information begins to have an impact on the threshold adjustment value; S_i is the adjustment slope scaling factor of the i-th type of context information, which is used to adjust the rate at which the threshold adjustment value increases with (C_i - T_i) when C_i>T_i, and S_i>0.

[0015] Further, step S34 includes: S341: Obtain the threshold adjustment value Adj_1 corresponding to the security threat level information, the threshold adjustment value Adj_2 corresponding to the system load information, and the threshold adjustment value Adj_3 corresponding to the user behavior anomaly information according to the threshold adjustment value Adj_i corresponding to each type of context information; S342: Obtain the baseline impact factor B_1 of the security threat level information, the baseline impact factor B_2 of the system load information, and the baseline impact factor B_3 of the user behavior anomaly information; S343: Obtain the adjustment rate factor R_1 of the security threat level information, the adjustment rate factor R_2 of the system load information, and the adjustment rate factor R_3 of the user behavior anomaly information; S344: Obtain the base access threshold B_T; Calculate the final dynamic access threshold D_T according to the following formula: D_T = B_T * (B_1 + R_1 * Adj_1) * (B_2 + R_2 * Adj_2) * (B_3 + R_3 * Adj_3); Wherein, Adj_1, Adj_2, and Adj_3 are the threshold adjustment values calculated according to Adj_i, and the range is non - negative real numbers; B_1, B_2, and B_3 are the baseline impact factors, with the unit of dimensionless, and the range is [1, +∞), respectively representing the baseline impact intensities of the security threat level information, the system load information, and the user behavior anomaly information; R_1, R_2, and R_3 are the adjustment rate factors, with the unit of dimensionless, and the range is [0, +∞), respectively controlling the rate of the adjustment values of the security threat level information, the system load information, and the user behavior anomaly information affecting the threshold; B_T is the base access threshold, and the range is non - negative real numbers.

[0016] Further, the step S5 includes: S51: When the access request score is less than the dynamic access threshold, initiate the secondary identity authentication process; S52: If the secondary identity authentication process passes, generate a decision to allow access; S53: If the secondary identity authentication process fails, generate a decision to deny access.

[0017] Further, the step S51 includes: S511: When the access request score is less than the dynamic access threshold, select a secondary authentication method according to a preset authentication policy, where the secondary authentication method includes at least one of dynamic verification code authentication and biometric authentication; S512: Activate the selected secondary authentication method and wait for the user to complete the authentication; S513: Receive the authentication feedback completed by the user.

[0018] In a second aspect, a data security protection device based on the industrial Internet identification resolution system is applied to the steps of the method described in any one of the above. The device includes: A request receiving module, configured to receive a data access request for requesting access to the data of the industrial Internet identification resolution system, where the data access request includes user identity information and attribute information of the accessed identifier; A score calculation module, configured to perform rule matching on the data access request according to a pre-configured security policy rule, and calculate an access request score of the data access request based on the weight value of the allowed access rule that matches successfully; A threshold calculation module, configured to obtain context information, where the context information characterizes the system security state and the system load state, and calculate a dynamic access threshold according to the obtained context information; A decision generation module, configured to compare the access request score with the dynamic access threshold, generate an access decision according to the comparison result, and generate a decision to allow access when the access request score is greater than or equal to the dynamic access threshold; otherwise, generate a decision to deny access.

[0019] Beneficial effects: The data security guarantee method and device based on the industrial Internet identification and resolution system proposed in this application receive data access requests, obtain user identities and the data attributes requested for access, providing basic information for subsequent policy matching and scoring; perform multi-dimensional security checks on access requests through pre-configured security policy rules. Different weights are assigned to different rules to indicate different levels of importance, and the weights are accumulated to obtain the access request score, realizing a preliminary security assessment based on policies; collect real-time information such as the system security status and load status, such as the security threat level and system load conditions. These information reflect the current security risks and operating conditions of the system, providing a basis for dynamically adjusting the access threshold; dynamically calculate the access threshold based on the obtained context information. The higher the system security risk or load, the higher the dynamic access threshold, thereby increasing the strictness of access control; compare the calculated access request score with the calculated dynamic access threshold. Access is only allowed when the access request score reaches or exceeds the dynamic access threshold. The method proposed in this application realizes access control based on dynamic thresholds, can flexibly adjust the strictness of security policies according to system context information, and takes into account the usability and performance of the system while ensuring security. Therefore, this solution has the advantages of effectively integrating security policies into the industrial Internet identification and resolution system, ensuring data security and compliance, and being able to be quickly adjusted and deployed when policies are adjusted. Description of the Drawings

[0020] Figure 1 It is a flowchart of a data security guarantee method based on the industrial Internet identification and resolution system proposed in this application.

[0021] Figure 2 It is a structural diagram of a data security guarantee device based on the industrial Internet identification and resolution system proposed in this application.

[0022] Label description: 201, Request receiving module; 202, Scoring calculation module; 203, Threshold calculation module; 204, Decision generation module. Detailed Implementation Modes

[0023] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. The components of the embodiments of the present application usually described and marked in the accompanying drawings here can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present application provided in the accompanying drawings is not intended to limit the scope of the present application to be protected, but only represents the selected embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without creative efforts belong to the scope of protection of the present application.

[0024] It should be noted that similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of the present application, terms such as "first" and "second" are only used for distinguishing descriptions and cannot be construed as indicating or implying relative importance.

[0025] When large manufacturing enterprises need to meet internal security policies that require both refined data access control, traceable auditing of operation behaviors, and dynamic updates of security policies, the prior art cannot propose an effective solution. Therefore, to solve this problem, the present application provides a data security guarantee method and device based on the industrial Internet identification and resolution system, specifically: Please refer to Figure 1 , in a first aspect, the present application proposes a data security guarantee method for the industrial Internet identification and resolution system. The steps of this method include: S1: Receive a data access request, which is used to request access to the data of the industrial Internet identification and resolution system; S2: Perform rule matching on the data access request according to pre-configured security policy rules, and calculate an access request score for the data access request based on the weight values of the allowed access rules that match successfully; S3: Obtain context information of the system security state and the system load state, and calculate a dynamic access threshold according to the obtained context information; S5: Compare the access request score with the dynamic access threshold. When the access request score is greater than or equal to the dynamic access threshold, generate a decision to allow access; otherwise, generate a decision to deny access.

[0026] Among them, in step S1, the data access request is initiated by a user and is used to request access to specific data in the industrial Internet identification and resolution system. The data access request contains the user's identity information, such as the user name, user role, etc., and the attribute information of the data that the user attempts to access, such as the data identifier, data type, etc.

[0027] In step S2, the pre-configured security policy rules are formulated according to the internal security policies of the enterprise and are used to define the access permissions that different users have for different data under different circumstances. The rule matching process is to compare the user information and data attribute information in the data access request with the pre-configured security policy rules to determine which rules are applicable to the current data access request. Each allowed access rule is pre-configured with a weight value, and the weight value represents the importance of the rule in the access decision. By accumulating the weight values of the allowed access rules that match successfully, a comprehensive access request score can be obtained, and this score reflects the security risk level of the access request.

[0028] In step S3, the context information is a real-time reflection of the current security state and load state of the system. For example, whether the system is under a network attack, whether the CPU utilization rate is too high, etc. This information can help the system dynamically adjust the access control policy.

[0029] The purpose of calculating the dynamic access threshold is to dynamically adjust the strictness of access control according to the current security risk and load situation of the system. For example, when the system detects an increase in security threats, the dynamic access threshold can be increased to more strictly control data access.

[0030] In step S4, comparing the access request score with the dynamic access threshold is a key step in the final access decision. If the access request score is higher than or equal to the dynamic access threshold, the access request is considered safe and access is allowed; otherwise, if the access request score is lower than the dynamic access threshold, the access request is considered to have a high security risk and access is denied. Thus, by dynamically adjusting the access threshold, it is possible to adaptively adjust the access control policy according to changes in the system environment, taking into account both the data security and the usability and performance of the system.

[0031] Specifically, in step S1, the data access request can be understood as an operation by a user on the client side to initiate an access to data from the industrial Internet identification resolution system server through an application or an interface. The reception of the data access request is the initial link in the access control process, preparing the necessary information for subsequent policy matching and security assessment.

[0032] In step S2, the security policy rules can be pre-configured as a combination of a series of conditions and weight values. For example, a rule can be "if the user belongs to the production department and the data type accessed is production data, then the weight value is 5". The rule matching engine analyzes the data access request and matches it according to the preset rules to find all the rules that meet the conditions. Then, the weight values of the successfully matched rules are added together to obtain the access request score. The higher the access request score, the safer the access request is considered at the security policy level.

[0033] In step S3, the acquisition of context information can be achieved through various channels. For example, the security threat level information can be obtained from an intrusion detection system or a security information and event management system; the system load information can be obtained from a system monitoring tool or an operating system interface; the user behavior anomaly information can be detected through a user behavior analysis system. These context information are quantified into computable values for subsequent calculation of the dynamic access threshold.

[0034] The calculation of the dynamic access threshold can adopt various algorithms. As a preferred implementation, different threshold adjustment parameters and calculation formulas can be set according to different types of context information. For example, higher threshold adjustment parameters can be set for security threat level information, indicating that security threats have a greater impact on the dynamic access threshold. By aggregating the threshold adjustment values corresponding to various context information, the final dynamic access threshold can be obtained.

[0035] In step S4, the generation of the access decision is determined based on the comparison result between the access request score and the dynamic access threshold. When the access request score is greater than or equal to the dynamic access threshold, the system generates a decision to allow access and returns the requested data to the user; when the access request score is less than the dynamic access threshold, the system generates a decision to deny access and returns a prompt message for denying access to the user.

[0036] Thus, through steps S1 to S4, a data security guarantee method for the industrial Internet identification resolution system based on dynamic thresholds is realized, which can effectively solve the problem of inflexible access control.

[0037] Furthermore, step S2 includes: S21: Classify the pre-configured security policy rules to obtain at least one rule classification, and each rule classification contains at least one security policy rule; S22: For the data access request, determine the rule classification that matches the data access request; S23: In the determined rule classification, match the data access request with the security policy rules included in the rule classification to obtain the allowed access rules that match successfully; S24: For each allowed access rule that matches successfully, obtain the pre-configured weight value and accumulate it to obtain the access request score of the data access request.

[0038] Among them, in step S21, the classification operation of the security policy rules is performed. Specifically, all the pre-set security policy rules are first obtained. Subsequently, a traversal operation is performed on all the security policy rules. For each security policy rule, the applicable department information is parsed, and according to the department information, the security policy rule is classified into the corresponding first-level rule classification.

[0039] If the first-level rule classification corresponding to the department does not exist, a new first-level rule classification corresponding to the department is created. For each first-level rule classification, a traversal operation is performed on the security policy rules under the first-level rule classification, the applicable data security level information is parsed, and according to the data security level information, the security policy rules are classified into the corresponding second-level rule classifications.

[0040] If the secondary rule classification corresponding to the data security level does not exist, a new secondary rule classification corresponding to the data security level is created under the current primary rule classification. Thereby, the security policy rules after multi-level classification are output, where each secondary rule classification contains at least one security policy rule, and each secondary rule classification belongs to a primary rule classification, and each primary rule classification corresponds to a department.

[0041] In step S22, for the received data access request, the operation of determining the rule classification that matches the data access request is performed. As a preferred implementation manner, the request access department information of the data access request and the data security level information of the requested access data are extracted, and compared with the department information and data security level information of the pre-established rule classification. When the request access department information and data security level information of the data access request are consistent with the department information and data security level information of the rule classification, this rule classification is determined as the rule classification that matches the data access request.

[0042] In step S23, in the rule classification determined in step S22, the data access request is matched with the security policy rules included in this rule classification to obtain the allowed access rules that match successfully. Specifically, for the determined rule classification, all the security policy rules under this rule classification are traversed, and the user identity information and the attribute information of the accessed identifier included in the data access request are compared with the preset conditions in the security policy rules. When the data access request meets the preset conditions in the security policy rules, this security policy rule is determined as the allowed access rule that matches successfully.

[0043] In step S24, for each allowed access rule that matches successfully obtained in step S23, the pre-configured weight value is obtained, and the accumulation operation is performed, thereby obtaining the access request score of the data access request. For example, if the data access request successfully matches three allowed access rules, and the weight values of these three rules are 10, 20, and 30 respectively, then the finally calculated access request score is 10 + 20 + 30 = 60.

[0044] In some specific implementation manners, for the data access request of the industrial Internet identification resolution system, a security guarantee method is used to achieve refined control and security management of data access. First, the pre-configured security policy rules are classified according to the department and data security level. For example, rule classifications such as "Production Department - Confidential Data" and "R & D Department - Internal Data" can be created, and each classification contains multiple specific security policy rules. When a data access request from a user is received, the system first analyzes the department and data security level to which the target access data of this request belongs, thereby quickly determining the rule classification that needs to be matched.

[0045] For example, if a user requests access to data under the classification of "Production Department - Confidential Data", the system will only search for applicable security policy rules under this classification, rather than searching through all the rules. In the determined rule classification, the system will perform a detailed match between the data access request and each security policy rule under this classification. The weight values of the successfully matched rules are accumulated to calculate the access request score. For example, under the classification of "Production Department - Confidential Data", if the user request satisfies two rules, namely "IP Address Whitelist" and "Access Time Period Limit", and the weight values of these two rules are 20 and 30 respectively, then the access request score for this data access request is 50. Through rule classification and rule matching within the classification, the matching scope of the security policy rules is effectively narrowed, the matching efficiency is improved, and at the same time, the management and maintenance of the security policy rules become more convenient.

[0046] Further, step S21 includes: S211: Obtain all pre-configured security policy rules; S212: Traverse all security policy rules. For each security policy rule, parse the applicable department information, and divide this security policy rule into the corresponding first-level rule classification according to the department information; if there is no first-level rule classification corresponding to the department, create a new first-level rule classification corresponding to the department; S213: For each first-level rule classification, traverse the security policy rules under this first-level rule classification, parse the applicable data security level information, and divide this security policy rule into the corresponding second-level rule classification according to the data security level information; if there is no second-level rule classification corresponding to the data security level, create a new second-level rule classification corresponding to the data security level under the current first-level rule classification; S214: Output the security policy rules after multi-level classification, where each second-level rule classification contains at least one security policy rule, and each second-level rule classification belongs to a first-level rule classification, and each first-level rule classification corresponds to a department.

[0047] Among them, in step S211, all pre-configured security policy rules are obtained as the data basis for subsequent classification operations.

[0048] In step S212, the traversal operation is performed for all security policy rules. For each security policy rule, the applicable department information is parsed. The department information can include, for example, "Production Department", "R & D Department", or "Finance Department", etc. According to the parsed department information, the security policy rules are classified into the corresponding first-level rule categories. The first-level rule categories are distinguished by departments and are used to manage and organize security policy rules related to specific departments. If there is no first-level rule category corresponding to the department information, a new first-level rule category for the corresponding department is created to ensure that each department has its corresponding rule category.

[0049] In step S213, for each first-level rule category, the traversal operation is performed among the security policy rules under this first-level rule category. For each security policy rule, the applicable data security level information is parsed. The data security level information can include, for example, "Top Secret", "Confidential", or "Public", etc. According to the data security level information, the security policy rules are classified into the corresponding second-level rule categories. The second-level rule categories are distinguished by data security levels under each first-level rule category and are used to manage and organize security policy rules more precisely. If there is no second-level rule category corresponding to the data security level, a new second-level rule category for the corresponding data security level is created under the current first-level rule category to ensure that each data security level has its corresponding rule category.

[0050] In step S214, the security policy rules after multi-level classification are output. The output result is a multi-level classified security policy rule system, where each second-level rule category contains at least one security policy rule, and each second-level rule category belongs to a first-level rule category, and each first-level rule category corresponds to a department. Thus, the security policy rules are structurally classified according to departments and data security levels.

[0051] In some specific embodiments, it is assumed that an enterprise has pre-configured several security policy rules, including: Rule 1: The applicable department is "Production Department", the data security level is "Confidential", and the weight value is 8; Rule 2: The applicable department is "Production Department", the data security level is "Public", and the weight value is 3; Rule 3: The applicable department is "R & D Department", the data security level is "Top Secret", and the weight value is 10; Rule 4: The applicable department is "R & D Department", the data security level is "Confidential", and the weight value is 7.

[0052] Execute step S211 to obtain the above 4 security policy rules.

[0053] Execute step S212 to traverse Rules 1 to 4. First, process Rule 1. After parsing, the applicable department is found to be the "Production Department". It is checked and found that there is no first-level rule classification for the "Production Department". Therefore, a first-level rule classification for the "Production Department" is created, and Rule 1 is classified into the first-level rule classification of the "Production Department". Then, process Rule 2. After parsing, the applicable department is found to be the "Production Department". It is checked and found that there already exists a first-level rule classification for the "Production Department". Therefore, Rule 2 is classified into the first-level rule classification of the "Production Department". Next, process Rules 3 and 4. Similarly, a first-level rule classification for the "R & D Department" is created, and Rules 3 and 4 are classified into the first-level rule classification of the "R & D Department".

[0054] Execute step S213. For the first-level rule classification of the "Production Department", traverse Rules 1 and 2. First, process Rule 1. After parsing, the data security level is found to be "Confidential". It is checked and found that there is no second-level rule classification of "Confidential" under the first-level rule classification of the "Production Department". Therefore, a second-level rule classification of "Confidential" is created, and Rule 1 is classified into the second-level rule classification of "Confidential" under the first-level rule classification of the "Production Department". Then, process Rule 2. After parsing, the data security level is found to be "Public". It is checked and found that there is no second-level rule classification of "Public" under the first-level rule classification of the "Production Department". Therefore, a second-level rule classification of "Public" is created, and Rule 2 is classified into the second-level rule classification of "Public" under the first-level rule classification of the "Production Department". For the first-level rule classification of the "R & D Department", similarly, second-level rule classifications of "Top Secret" and "Confidential" are created, and Rule 3 is classified into the second-level rule classification of "Top Secret" under the first-level rule classification of the "R & D Department", and Rule 4 is classified into the second-level rule classification of "Confidential" under the first-level rule classification of the "R & D Department".

[0055] Execute step S214 to output the security policy rules after multi-level classification. The output result is as follows: First-level rule classification of the "Production Department": Second-level rule classification of "Confidential": Rule 1; Second-level rule classification of "Public": Rule 2; First-level rule classification of the "R & D Department": Second-level rule classification of "Top Secret": Rule 3; Second-level rule classification of "Confidential": Rule 4.

[0056] Through the above embodiments, the security policy rules are effectively classified according to the department and the data security level, constructing a rule system with a clear structure and easy to manage, providing support for subsequent rapid rule matching, and improving the application efficiency of the security policy rules.

[0057] Furthermore, step S24 includes: S241: Obtain the set of allowed access rules \(R_{matched}\) that match successfully. \(R_{matched}\) contains \(n\) allowed access rules that match successfully, denoted as \(R_{matched}=\{Rule\_1, Rule\_2, \cdots, Rule\_n\}\); S242: Initialize the access request score \(Score\) of the data access request to 0; S243: For each rule \(Rule_j\) in the set of allowed access rules \(R_{matched}\) that match successfully, where the value range of \(j\) is from 1 to \(n\), obtain the pre-configured weight value \(W_j\), and \(W_j\) represents the weight value of rule \(Rule_j\); S244: Use the cumulative weight scoring model to calculate the access request score \(Score\) of the data access request. The calculation formula is as follows: Score = ∑_{j = 1}^{n} W_j; where, ∑ represents the summation operation, \(j\) represents the index of the allowed access rule that matches successfully, \(n\) represents the total number of allowed access rules that match successfully, and \(W_j\) represents the pre-configured weight value of the \(j\)-th allowed access rule \(Rule_j\) that matches successfully.

[0058] Among them, in step S241, the set of allowed access rules \(R_{matched}\) that match successfully is obtained. This set is generated by the rule matching process in step S23 and contains all allowed access rules that match the data access request.

[0059] In step S242, the access request score \(Score\) is initialized to 0. This is to ensure that the initial value of the score calculation is determined and avoid being affected by random factors.

[0060] In step S243, for each rule \(Rule_j\) in the set \(R_{matched}\), the pre-configured weight value \(W_j\) is obtained. The weight value \(W_j\) represents the importance of the corresponding rule \(Rule_j\) in the access decision. These weight values can be preset during system configuration and stored in, for example, a database or a configuration file.

[0061] In step S244, the cumulative weight scoring model is used, and the access request score \(Score\) is calculated by adding up the weight values \(W_j\) of all allowed access rules that match successfully. Specifically, the formula Score = ∑_{j = 1}^{n} W_j means adding up the weight values of all rules in the set \(R_{matched}\), and the final Score value is the access request score of the data access request.

[0062] Specifically, for the calculation problem of access request scoring, this solution provides a clear and operable calculation method. After the security policy rules are matched, there may be multiple rules that match successfully at the same time. To comprehensively consider these successfully matched rules and give a quantitative access request score, this solution is implemented by accumulating the weight values of these successfully matched rules. The weight values can be pre-configured to reflect the importance of different security policy rules. For example, for operations with a high security level, the successfully matched rules may be configured with higher weight values. By accumulating the weight values, a comprehensive score can be obtained, which can quantitatively represent the security risk level or trustworthiness of the data access request. The higher the access request score, the higher the degree of permission obtained by the access request at the security policy rule level. On the contrary, the lower the score, the lower the degree of permission. Thus, subsequent access control decisions can be based on this quantitative score, thereby achieving more refined and accurate access control.

[0063] Further, step S3 includes: S31: Collect various types of context information characterizing the system security state and system load state, where the context information includes security threat level information, system load information, and user behavior anomaly information; S32: For each type of context information, determine the threshold adjustment parameter corresponding to this type of context information. Among them, different types of context information correspond to different threshold adjustment parameters, and the threshold adjustment parameter is used to characterize the influence degree of this type of context information on the dynamic access threshold; S33: Based on each type of context information and the corresponding threshold adjustment parameter, calculate the threshold adjustment value corresponding to each type of context information; S34: Aggregate the threshold adjustment values corresponding to all types of context information to obtain the final dynamic access threshold.

[0064] Among them, in step S31, the context information types are limited to these three types: security threat level information, system load information, and user behavior anomaly information. The collection of various types of context information realizes the comprehensive monitoring of the system security state and load state. Thus, the evaluation of the system real-time state can be achieved from multiple dimensions, providing a data basis for subsequent dynamic threshold calculation.

[0065] In step S32, configuring corresponding threshold adjustment parameters for each type of context information means that the influence degrees of different types of context information on the dynamic access threshold can be set differentially. For example, the security threat level information is given a higher threshold adjustment parameter, indicating that when the system security risk increases, the dynamic access threshold should be adjusted more significantly. This differential configuration method improves the flexibility and fineness of the dynamic threshold adjustment, and thus makes the security policy effective in adapting to different types of security risks and system load changes.

[0066] In step S33, based on the context information and the threshold adjustment parameters, the threshold adjustment value corresponding to each type of context information is calculated, thereby realizing the key to dynamic threshold adjustment. Through the preset calculation method, the collected context information is quantified and converted into a value available for threshold adjustment.

[0067] In step S34, the threshold adjustment values corresponding to all types of context information are aggregated to finally obtain the dynamic access threshold. Aggregation processing means that the influences of various context information on the access threshold are comprehensively considered, rather than relying only on a single factor. Through a reasonable aggregation algorithm, the dynamic access threshold can comprehensively reflect the current security state and load condition of the system, thereby realizing the intelligence and effectiveness of access control.

[0068] In some specific embodiments, the following examples can be used to illustrate step S3. Assume that the quantified value of the current system security threat level information is 6 (the higher the quantified value, the higher the security threat level), the quantified value of the system load information is 70% (the higher the quantified value, the higher the system load), and the quantified value of the user behavior anomaly information is 2 (the higher the quantified value, the higher the degree of user behavior anomaly). The preset threshold adjustment parameter P_1 for the security threat level information is 0.8, the threshold trigger value T_1 is 5, and the adjustment slope scaling factor S_1 is 1.2; the threshold adjustment parameter P_2 for the system load information is 0.5, the threshold trigger value T_2 is 60%, and the adjustment slope scaling factor S_2 is 1.0; the threshold adjustment parameter P_3 for the user behavior anomaly information is 0.6, the threshold trigger value T_3 is 1, and the adjustment slope scaling factor S_3 is 1.1. According to the piecewise linear function calculation in step S33, the threshold adjustment value Adj_1 corresponding to the security threat level information = 1.2 * 0.8 * (6 - 5) = 0.96; the threshold adjustment value Adj_2 corresponding to the system load information = 1.0 * 0.5 * (70% - 60%) = 0.05; the threshold adjustment value Adj_3 corresponding to the user behavior anomaly information = 1.1 * 0.6 * (2 - 1) = 0.66.

[0069] Furthermore, assume that the baseline impact factor B_1 of the security threat level information is 1.5, the baseline impact factor B_2 of the system load information is 1.2, the baseline impact factor B_3 of the user behavior anomaly information is 1.1, the basic access threshold B_T is 60 points, and the adjustment rate factors R_1 of the security threat level information, R_2 of the system load information, and R_3 of the user behavior anomaly information are all 1. Aggregate the threshold adjustment values corresponding to all types of context information according to step S34 to obtain the final dynamic access threshold. The specific aggregation formula is: D_T = 60 * (1.5 + 1 * 0.96) * (1.2 + 1 * 0.05) * (1.1 + 1 * 0.66) = 324.72. Thus, the dynamic access threshold is calculated and used for subsequent access decisions. It can be seen from the above embodiments that the dynamic access threshold can be adjusted according to the real-time security state and load state of the system, so as to achieve more flexible and intelligent data security protection.

[0070] The present application further proposes that step S33 includes: Step S331: For the three types of context information of security threat level information, system load information, and user behavior anomaly information, perform the following operations respectively: Obtain the quantization value C_i of each type of context information, where i represents security threat level, system load, and user behavior anomaly respectively; Obtain the threshold adjustment parameter P_i, the threshold trigger value T_i, and the adjustment slope scaling factor S_i corresponding to each type of context information i; Step S332: Calculate the threshold adjustment value Adj_i corresponding to each type of context information i according to the following piecewise linear function: When C_i ≤ T_i, Adj_i = 0; When C_i > T_i, Adj_i = S_i * P_i * (C_i - T_i); Wherein, P_i is the threshold adjustment parameter of the i-th type of context information, which is used to adjust the influence degree of the i-th type of context information on the threshold adjustment value, and P_i > 0; T_i is the threshold trigger value of the i-th type of context information, indicating that when C_i exceeds T_i, this type of context information begins to affect the threshold adjustment value; S_i is the adjustment slope scaling factor of the i-th type of context information, which is used to adjust the rate at which the threshold adjustment value increases with (C_i - T_i) when C_i > T_i, and S_i > 0.

[0071] Among them, the quantization values of each type of context information are obtained. The types of context information include security threat level information, system load information, and user behavior anomaly information. Each type of context information is configured with a corresponding threshold adjustment parameter, threshold trigger value, and adjustment slope scaling factor. The threshold adjustment parameter is used to adjust the influence degree of the corresponding type of context information on the adjustment value threshold. The threshold trigger value is set as the critical point to determine whether the quantization value of the context information starts to affect the adjustment value threshold. The adjustment slope scaling factor is used to control the growth rate of the threshold adjustment value with respect to the part by which the quantization value of the context information exceeds the threshold trigger value when the quantization value of the context information exceeds the threshold trigger value.

[0072] Specifically, when calculating the dynamic access threshold, first, for the security threat level information, system load information, and user behavior anomaly information, their quantization values are obtained respectively, and the quantization values are represented as C_1, C_2, and C_3 respectively. Then, for each type of context information, the threshold adjustment value is calculated according to the preset parameters. Taking the security threat level information as an example, assume its threshold adjustment parameter is P_1, the threshold trigger value is T_1, and the adjustment slope scaling factor is S_1. If the current quantization value C_1 of the security threat level is less than or equal to the threshold trigger value T_1, the threshold adjustment value Adj_1 corresponding to the security threat level information is set to 0, indicating that the security threat level has not reached the trigger condition at this time and does not have an adjustment effect on the adjustment value threshold. On the contrary, if C_1 is greater than T_1, Adj_1 is calculated according to the formula Adj_1 = S_1 * P_1 * (C_1 - T_1), and the calculation result is a positive value, indicating that the higher the security threat level, the higher the adjustment value threshold will be adjusted. The calculation methods of the threshold adjustment values Adj_2 and Adj_3 for the system load information and user behavior anomaly information are similar to that of the security threat level information, both calculated through a piecewise linear function and combined with their respective parameters. Thus, the threshold adjustment value corresponding to each type of context information can be obtained.

[0073] Furthermore, step S34 includes: S341: Obtain the threshold adjustment value Adj_1 corresponding to the security threat level information, the threshold adjustment value Adj_2 corresponding to the system load information, and the threshold adjustment value Adj_3 corresponding to the user behavior anomaly information according to the threshold adjustment value Adj_i corresponding to each type of context information; S342: Obtain the reference influence factor B_1 of the security threat level information, the reference influence factor B_2 of the system load information, and the reference influence factor B_3 of the user behavior anomaly information; S343: Obtain the adjustment rate factor R_1 of the security threat level information, the adjustment rate factor R_2 of the system load information, and the adjustment rate factor R_3 of the user behavior anomaly information; S344: Obtain the base access threshold B_T; Calculate the final dynamic access threshold D_T according to the following formula: D_T = B_T * (B_1 + R_1 * Adj_1) * (B_2 + R_2 * Adj_2) * (B_3 + R_3 * Adj_3); Where, Adj_1, Adj_2, and Adj_3 are threshold adjustment values calculated according to Adj_i, and the range is non - negative real numbers; B_1, B_2, and B_3 are baseline impact factors, dimensionless, and the range is [1, +∞), which respectively represent the baseline impact intensities of security threat level information, system load information, and user behavior anomaly information; R_1, R_2, and R_3 are adjustment rate factors, dimensionless, and the range is [0, +∞), which respectively control the rate of influence of the adjustment values of security threat level information, system load information, and user behavior anomaly information on the threshold; B_T is the base access threshold, and the range is non - negative real numbers.

[0074] Among them, in step S341, the threshold adjustment value Adj_1 corresponding to the security threat level information, the threshold adjustment value Adj_2 corresponding to the system load information, and the threshold adjustment value Adj_3 corresponding to the user behavior anomaly information are obtained through the calculation of step S33.

[0075] In step S342, the baseline impact factors B_1, B_2, and B_3 are pre - set parameters, which are used to represent the basic impact degrees of various context information on the dynamic access threshold without dynamic adjustment. These baseline impact factors can be configured according to the importance of different context information. For example, the security threat level information may be considered the most important, so a higher baseline impact factor B_1 can be set.

[0076] In step S343, the adjustment rate factors R_1, R_2, and R_3 are also pre - set parameters, which are used to control the rate of influence of the threshold adjustment value of each context information on the final dynamic access threshold. The larger the adjustment rate factor, the more significant the influence of the threshold adjustment value of the corresponding context information on the final dynamic access threshold.

[0077] In step S344, the basic access threshold B_T is the basic value for dynamic access threshold adjustment, representing the initial access threshold when no context information is considered. The final dynamic access threshold D_T is calculated through a multiplication formula. In the formula, the basic access threshold B_T is multiplied by the weighted adjustment term for each type of context information. The weighted adjustment term consists of the baseline impact factor B_i plus the product of the adjustment rate factor R_i and the threshold adjustment value Adj_i. This multiplication aggregation method can effectively integrate the impacts of multiple context information, enabling the dynamic access threshold to sensitively and comprehensively reflect the system security state and load state.

[0078] Specifically, through the dynamic access threshold calculation method provided in step S34, the system can dynamically adjust the control intensity of data access according to the real-time security state and load state. When the system detects an increase in the security threat level, an increase in system load, or abnormal user behavior, step S33 will calculate the corresponding threshold adjustment value Adj_i. These adjustment values are aggregated through the formula in step S34, ultimately resulting in an increase in the dynamic access threshold D_T. An increase in the dynamic access threshold means that an access request requires a higher access request score to obtain a decision to allow access, thereby strengthening the strictness of access control. Conversely, when the system security state is good and the load is low, the dynamic access threshold D_T will decrease, and the strictness of access control will also decrease accordingly. The baseline impact factor B_i ensures that even when the adjustment value Adj_i of the context information is zero, various context information still has a basic impact on the dynamic access threshold. The adjustment rate factor R_i provides a refined control ability for the impact degree of different context information. The use of the multiplication formula effectively synthesizes the impacts of various context information, jointly determining the final dynamic access threshold, thus achieving a sensitive response to system environment changes and comprehensive security protection.

[0079] Furthermore, step S5 includes: S51: When the access request score is less than the dynamic access threshold, initiate the secondary authentication process; S52: If the secondary authentication process passes, generate a decision to allow access; S53: If the secondary authentication process fails, generate a decision to deny access.

[0080] Among them, in step S51, when the access request score does not reach the dynamic access threshold, the system is configured not to immediately reject the access, but to start an additional verification step, that is, a secondary identity authentication process. As a preferred implementation, the secondary identity authentication process can include various authentication methods, such as dynamic verification code authentication or biometric authentication. Dynamic verification code authentication may involve the system sending a one-time verification code to the mobile device registered by the user, and the user needs to enter the correct verification code within a limited time to complete the authentication. Biometric authentication may utilize technologies such as fingerprint recognition, face recognition, or iris scanning to further verify the user's identity.

[0081] In step S52, if the user successfully passes the secondary identity authentication process, the system generates a decision to allow access, thus ensuring the access rights of legitimate users.

[0082] In step S53, if the secondary identity authentication process fails to pass the verification, indicating that the legitimacy of the access request is in doubt, the system will finally generate a decision to reject the access to ensure data security. Thus, the introduction of the secondary identity authentication process provides a more flexible and accurate mechanism for access control.

[0083] Specifically, in the access control process, first calculate the access request score of the data access request and obtain the dynamic access threshold. Subsequently, the system compares the access request score with the dynamic access threshold. If the access request score is greater than or equal to the dynamic access threshold, a decision to allow access is directly generated. However, when the access request score is less than the dynamic access threshold, the system does not immediately reject the access, but starts the secondary identity authentication process. This processing method takes into account that the access request score may have a certain degree of volatility, or there may be some special circumstances in the user's access behavior. By introducing secondary identity authentication, the system can provide an additional verification opportunity for the user when the access request score is slightly lower than the threshold, avoiding misjudgment of legitimate access requests. As a remedial measure, the secondary identity authentication process improves the flexibility of user access and the user experience while ensuring the security of the system.

[0084] In some specific embodiments, assume that after a user initiates a data access request, the access request score calculated by the system is 80 points, while the current dynamic access threshold is 85 points. Since the access request score of 80 points is less than the dynamic access threshold of 85 points, the system will initiate a secondary identity authentication process. As an example, the system selects the dynamic verification code authentication method. The system sends a text message containing a verification code to the mobile phone number reserved by the user. After receiving the verification code, the user needs to enter the verification code on the system interface. If the user correctly enters the verification code within the specified time, the secondary identity authentication process passes, and the system will generate a decision to allow access, and the user can normally access the requested data. Conversely, if the user fails to correctly enter the verification code or fails to enter it within the timeout period, the secondary identity authentication process fails, and the system will generate a decision to deny access and reject the user's access request.

[0085] Further, the step S51 includes: S511: When the access request score is less than the dynamic access threshold, select a secondary identity authentication method according to a preset authentication policy, where the secondary identity authentication method includes at least one of dynamic verification code authentication and biometric authentication; S512: Initiate the selected secondary identity authentication method and wait for the user to complete the authentication; S513: Receive the authentication feedback completed by the user.

[0086] Among them, step S51 of initiating the secondary authentication process is the key step to provide flexibility. Steps S52 and S53 respectively correspond to the processing of successful and failed secondary authentication, jointly constituting a more refined and adjustable access decision-making mechanism.

[0087] Specifically, when the access request score is initially evaluated as not reaching the dynamic access threshold, the system does not immediately deny access but initiates a secondary identity authentication process. This secondary authentication can adopt more flexible and secure identity verification methods such as dynamic verification codes and biometric recognition. If the user can successfully pass the secondary identity authentication, the system will still generate a decision to allow access, thus avoiding misjudgment that may be caused by a slightly lower score and ensuring the normal access needs of legitimate users. Conversely, if the secondary identity authentication fails, a decision to deny access will be finally generated to ensure the security of the system. Thus, by adding a secondary identity authentication link, on the premise of ensuring security, the flexibility and fault tolerance of access control are improved, the possibility of legitimate requests being wrongly rejected is reduced, and the data security guarantee method is more perfect and user-friendly.

[0088] In practical applications, when the access request score of a data access request is calculated to be lower than the dynamic access threshold, the system does not immediately make a decision to deny access. As a preferred implementation, the system will initiate a secondary authentication process to further verify the legitimacy of the user's identity. The secondary authentication method can be flexibly selected. For example, dynamic verification code authentication can be used. The system sends a random verification code to the mobile phone or email bound to the user, and the user needs to correctly enter the verification code within a limited time to complete the authentication. Another example is biometric authentication, such as fingerprint recognition or face recognition. The user needs to authenticate their identity through a biometric recognition device. After the secondary authentication process is initiated, the system waits for the user to complete the authentication operation and receives the authentication result. If the user successfully passes the secondary authentication, it indicates that although the initial score is low, the user still has a high level of credibility. At this time, the system will generate a decision to allow access and allow the user to access the requested data. Conversely, if the user fails to pass the secondary authentication, it indicates that the legitimacy of the user's identity is in doubt, or there is an abnormality in the authentication process. To ensure data security, the system will finally generate a decision to deny access and reject the user's access request.

[0089] The present application further proposes a data security protection device, which is applied to the above method steps. The device includes: A request receiving module 201, configured to receive a data access request, where the data access request is used to request access to data in the industrial Internet identity resolution system, and the data access request includes user identity information and attribute information of the accessed identifier; A score calculation module 202, configured to perform rule matching on the data access request according to pre-configured security policy rules, and calculate the access request score of the data access request based on the weight value of the allowed access rules that match successfully; A threshold calculation module 203, configured to obtain context information, where the context information characterizes the system security state and the system load state, and calculate the dynamic access threshold according to the obtained context information; A decision generation module 204, configured to compare the access request score with the dynamic access threshold, generate an access decision according to the comparison result, and generate a decision to allow access when the access request score is greater than or equal to the dynamic access threshold; otherwise, generate a decision to deny access.

[0090] Among them, the request receiving module 201 is configured as an interface for the system to interact with the outside world, and is used to receive requests from users or applications to access data in the industrial Internet identity resolution system. The data access request contains necessary user identity information, such as a username or user ID, and attribute information of the data identifier that the user attempts to access, such as data type or sensitivity level. The score calculation module is connected to a security policy rule library, and multiple security policy rules are pre-stored in the rule library, and each rule is associated with a weight value.

[0091] After receiving a data access request, the scoring calculation module 202 extracts the information in the request and matches it with the rules in the rule library. The weight values of the access rules that match successfully are accumulated to calculate the access request score for this data access request.

[0092] The threshold calculation module 203 is responsible for collecting the context information during the operation of the system in real time. This information reflects the security status and load status of the system. For example, it can include the real-time security threat alert level, the CPU and memory usage of the system, and the abnormal detection results of user behavior. Then, according to the preset threshold calculation model, it calculates the dynamic access threshold. The calculation of the dynamic access threshold takes into account the current system security status and load status, enabling the access control policy to be dynamically adjusted according to environmental changes.

[0093] The decision-making generation module 204 is the core component of the device. It receives the access request score from the scoring calculation module and the dynamic access threshold from the threshold calculation module. By comparing these two values, the decision-making generation module generates the final access decision. If the access request score is greater than or equal to the dynamic access threshold, a decision to allow access is generated; otherwise, a decision to deny access is generated.

[0094] In some specific implementation manners, the request receiving module 201 can be implemented as an API interface of a Web server, supporting the reception of data access requests using the HTTP or HTTPS protocol.

[0095] The scoring calculation module 202 can be implemented using a rule engine, such as Drools or Open Policy Agent. The security policy rules are loaded into the rule engine in the form of rule files, and the rule engine is responsible for efficiently performing rule matching and scoring calculation.

[0096] The threshold calculation module 203 can integrate multiple data sources and use piecewise linear functions or machine learning models to calculate the dynamic access threshold. For example, it obtains security alert information from security devices (such as firewalls, intrusion detection systems), obtains system load data from system monitoring tools (such as Prometheus, Grafana), and obtains user abnormal behavior scores from the user behavior analysis system. And various context information is used as input parameters for the piecewise linear function or machine learning model to calculate the dynamic access threshold.

[0097] The decision-making generation module 204 can be integrated with the identity authentication system. When the access request score is lower than the dynamic access threshold, a secondary identity authentication process can be triggered. For example, it can require the user to enter a dynamic verification code or perform biometric identification to further verify the user's identity and enhance security.

[0098] The above are only embodiments of the present application and are not intended to limit the protection scope of the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the protection scope of the present application.

Claims

1. A data security assurance method based on the industrial Internet identification resolution system, characterized in that: The steps of the method include: S1: receiving a data access request, where the data access request is used to request access to data in the industrial Internet identity resolution system; S2: performing rule matching on the data access request according to pre-configured security policy rules, and calculating an access request score of the data access request based on the weight value of the successfully matched access permission rule; S3: Obtaining context information of the system security status and the system load status, and calculating a dynamic access threshold based on the obtained context information; S4: Compare the access request score with the dynamic access threshold, and when the access request score is greater than or equal to the dynamic access threshold, generate a decision to allow access; otherwise, generate a decision to deny access.

2. According to claim 1, a data security assurance method based on an industrial Internet identification resolution system is characterized in that: Step S2 includes: S21: Classify the pre-configured security policy rules to obtain at least one rule classification, each rule classification including at least one security policy rule; S22: for the data access request, determining a rule classification that matches the data access request; S23: In the determined rule classification, the data access request is matched with the security policy rules included in the rule classification to obtain a successfully matched access permission rule; S24: For each successfully matched access permission rule, a pre-configured weight value is obtained, and the weight value is accumulated to obtain an access request score of the data access request.

3. According to claim 2, a data security assurance method based on an industrial Internet identification resolution system is characterized in that: Step S21 includes: S211: Obtain all pre-configured security policy rules; S212: traverse all security policy rules, analyze the applicable department information for each security policy rule, and classify the security policy rule into a corresponding first-level rule category according to the department information; if there is no first-level rule category corresponding to the department, create a new first-level rule category corresponding to the department; S213: for each first-level rule classification, traverse the security policy rules under the first-level rule classification, parse the applicable data security level information, and classify the security policy rules into corresponding second-level rule classifications according to the data security level information; if there is no second-level rule classification corresponding to the data security level, create a new second-level rule classification corresponding to the data security level under the current first-level rule classification; S214: Output the security policy rules after multi-level classification, wherein each secondary rule classification contains at least one security policy rule, and each secondary rule classification belongs to a primary rule classification, and each primary rule classification corresponds to a department.

4. According to claim 3, a data security assurance method based on an industrial Internet identification resolution system is characterized in that: Step S24 includes: S241: Obtain a set of successfully matched access permission rules R_matched, where R_matched includes n successfully matched access permission rules, expressed as R_matched = {Rule_1, Rule_2, ..., Rule_n}; S242: Initialize the access request score of the data access request to 0; S243: for each rule Rule_j in the successfully matched access permission rule set R_matched, where the value of j ranges from 1 to n, obtain a pre-configured weight value W_j, where W_j represents the weight value of rule Rule_j; S244: Calculate the access request score Score of the data access request using a cumulative weighted scoring model. The calculation formula is as follows: Score=∑_{j=1}^{n} W_j, where ∑ represents a summation operation, j represents the index of the successfully matched access-allowing rule, n represents the total number of successfully matched access-allowing rules, and W_j represents the pre-configured weight value of the jth successfully matched access-allowing rule Rule_j.

5. According to claim 1, a data security assurance method based on an industrial Internet identification resolution system is characterized in that: Step S3 includes: S31: Collecting multiple types of context information representing system security status and system load status, wherein the context information includes security threat level information, system load information, and user behavior abnormality information; S32: for each type of context information, determining a threshold adjustment parameter corresponding to the context information type, wherein different context information types correspond to different threshold adjustment parameters, and the threshold adjustment parameter is used to characterize the degree of influence of the context information of the type on the dynamic access threshold; S33: Based on each type of context information and the corresponding threshold adjustment parameter, calculate a threshold adjustment value corresponding to each type of context information; S34: Aggregate the threshold adjustment values ​​corresponding to all types of context information to obtain a final dynamic access threshold.

6. According to claim 5, a data security assurance method based on an industrial Internet identification resolution system is characterized in that: Step S33 includes: S331: For the three types of context information, namely, security threat level information, system load information, and user behavior abnormality information, the following operations are performed respectively: Obtain the quantized value C_i of each context information type, where i = 1, 2, and 3, representing security threat level information, system load information, and user behavior abnormality information, respectively; Obtaining a threshold adjustment parameter P_i, a threshold trigger value T_i and an adjustment slope scaling factor S_i corresponding to each context information type i; S332: Calculate the threshold adjustment value Adj_i corresponding to each context information type i according to the following piecewise linear function: When C_i ≤ T_i, Adj_i = 0; When C_i > T_i, Adj_i = S_i * P_i * (C_i - T_i); Wherein, P_i is the threshold adjustment parameter of the i-th context information, which is used to adjust the influence of the i-th context information on the threshold adjustment value, P_i > 0; T_i is the threshold trigger value of the i-th type of context information, indicating that when C_i exceeds T_i, this type of context information begins to affect the threshold adjustment value; S_i is the adjustment slope scaling factor of the i-th context information, which is used to adjust the rate at which the threshold adjustment value increases with (C_i - T_i) when C_i > T_i, S_i > 0.

7. According to claim 6, a data security assurance method based on the industrial Internet identification resolution system is characterized in that: Step S34 includes: S341: Obtaining a threshold adjustment value Adj_1 corresponding to the security threat level information, a threshold adjustment value Adj_2 corresponding to the system load information, and a threshold adjustment value Adj_3 corresponding to the user behavior abnormality information according to the threshold adjustment value Adj_i corresponding to each type of context information; S342: Obtaining a baseline impact factor B_1 of security threat level information, a baseline impact factor B_2 of system load information, and a baseline impact factor B_3 of user behavior abnormality information; S343: Obtaining an adjustment rate factor R_1 for security threat level information, an adjustment rate factor R_2 for system load information, and an adjustment rate factor R_3 for abnormal user behavior information; S344: Obtaining a basic access threshold B_T; The final dynamic access threshold D_T is calculated according to the following formula: D_T =B_T * (B_1 + R_1 * Adj_1) * (B_2 + R_2 * Adj_2) * (B_3 + R_3 * Adj_3); Wherein, Adj_1, Adj_2, and Adj_3 are threshold adjustment values ​​calculated based on Adj_i, and their ranges are non-negative real numbers; B_1, B_2, and B_3 are the baseline impact factors, which are dimensionless and range from [1, +∞), and represent the baseline impact strength of security threat level information, system load information, and user behavior abnormality information, respectively; R_1, R_2, and R_3 are adjustment rate factors, which are dimensionless and range from [0, +∞), and respectively control the rate at which the adjustment values ​​of security threat level information, system load information, and user behavior abnormality information affect the threshold; B_T is the basic access threshold, which ranges from non-negative real numbers.

8. According to claim 1, a data security assurance method based on an industrial Internet identification resolution system is characterized in that: The step S5 comprises: S51: When the access request score is less than the dynamic access threshold, a secondary identity authentication process is initiated; S52: If the secondary identity authentication process is passed, a decision to allow access is generated; S53: If the secondary identity authentication process fails, a decision to deny access is generated.

9. The data security assurance method based on the industrial Internet identification resolution system according to claim 8 is characterized in that: The step S51 comprises: S511: When the access request score is less than the dynamic access threshold, selecting a secondary identity authentication method according to a preset authentication strategy, wherein the secondary identity authentication method includes at least one of a dynamic verification code authentication and a biometric authentication; S512: Start the selected secondary identity authentication method and wait for the user to complete the authentication; S513: Receive authentication feedback completed by the user.

10. A data security protection device based on the industrial Internet identification resolution system, characterized in that: Applied in the steps of the method according to any one of claims 1 to 9, the device comprises: A request receiving module, used to receive a data access request, wherein the data access request is used to request access to data of the industrial Internet identity resolution system, and the data access request includes user identity information and attribute information of the accessed identity; A score calculation module, used to perform rule matching on the data access request according to pre-configured security policy rules, and calculate an access request score of the data access request based on the weight value of the successfully matched access permission rule; A threshold calculation module, used to obtain context information, wherein the context information represents a system security state and a system load state, and calculate a dynamic access threshold based on the obtained context information; A decision generation module is used to compare the access request score with the dynamic access threshold, generate an access decision according to the comparison result, and generate a decision to allow access when the access request score is greater than or equal to the dynamic access threshold; otherwise, generate a decision to deny access.