Shared storage method and device for multi-source data
By building a dynamic access control model in a multi-user collaboration environment, adjusting user permissions in real time and monitoring abnormal access behavior, the problems of inflexible permission adjustment and insufficient abnormal access monitoring in the existing technology are solved, and higher data security and privacy protection capabilities are achieved.
Patent Information
- Application Number
- CN202510247953.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-04
- Publication Date
- 2025-06-20
AI Technical Summary
In a multi-user collaboration environment, existing data access control methods are difficult to adjust in real time according to changes in user behavior, data sensitivity or collaboration relationships, resulting in excessive permissions or limited access problems, and it is difficult to effectively monitor and respond to abnormal access behaviors, affecting the overall security of the system.
By building a dynamic access control model, verify based on the user's access history and permission rules, an access token is generated, and the user's data access scope and operation permissions are determined based on the access token. At the same time, access control model parameters are adjusted to adapt to the security and privacy requirements of multi-source data, including calculating the duration of access permissions and monitoring user access behavior to identify abnormal access patterns.
It realizes real-time adjustment of access permissions according to changes in user behavior and collaboration relationships, avoids the problems of excessive openness or restriction of permissions, and can promptly identify and respond to abnormal access behaviors, reduce the risk of data leakage, and improve the system's privacy protection capabilities and overall performance.
Smart Images

Figure CN120180468A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data storage and access control, and particularly to a shared storage method and device for multi-source data. Background Art
[0002] In a multi-source data shared storage environment, efficient data sharing and secure management are one of the key challenges. Existing data access control methods mainly rely on static permission management mechanisms, such as role-based access control and attribute-based access control. These methods usually set access permissions during system initialization and remain unchanged throughout the data life cycle, lacking flexibility and being difficult to adapt to the dynamically changing security requirements in the multi-user collaboration process. In practical applications, different users may have different data access requirements, and static access control mechanisms cannot be adjusted in real time according to changes in user behavior, data sensitivity, or collaboration relationships, easily leading to problems such as over-open permissions or restricted access. In addition, existing methods have insufficient capabilities for monitoring and responding to abnormal access behaviors, making it difficult to detect and prevent potential data leakage risks in a timely manner, affecting the overall security of the system.
[0003] In addition, in a multi-user environment, the balance between privacy protection and data sharing is also an important issue. Traditional security policies usually rely on encrypted storage, access control lists (ACLs), or predefined permission rules. However, these methods are difficult to meet the requirements of dynamic collaboration while ensuring data security. For example, when the collaboration requirements of users change, how to ensure that necessary data access permissions are reasonably adjusted while avoiding excessive exposure of sensitive data is a problem that existing technologies have difficulty effectively solving. In addition, some enhanced security solutions, such as blockchain-based access control or fully homomorphic encryption, although they can improve data security, often bring high computational and storage overheads, affecting the real-time performance of data sharing and system performance. Summary of the Invention
[0004] The purpose of the present invention is to provide a shared storage method and device for multi-source data, and to regulate a dynamic access control permission adjustment mechanism to solve the problems of insufficient data security and privacy protection in a multi-user collaboration environment.
[0005] To achieve the above purpose, the present invention provides the following technical solution: A shared storage method for multi-source data, the method comprising:
[0006] S1. Construct a dynamic access control model based on the access history and permission rules of users in a multi-user collaboration environment;
[0007] S2. Verify user requests through the dynamic access control model and generate access tokens;
[0008] S3. Determine the user's data access scope and operation permissions based on the access token;
[0009] S4. Adjust the access control model parameters to meet the security and privacy requirements of multi-source data, including determining the basic frequency of access permission adjustment by the system and the user's access frequency, and calculating the duration of access permissions. The specific formula is: A = B / E;
[0010] Where, A represents the duration of access permissions, B represents the basic frequency of access permission adjustment by the system, and E represents the user's access frequency.
[0011] Preferably, the said S1 includes recording the user's access history, determining their initial permission level, determining the user's access growth rate, and calculating the change trend of access permissions. The specific formula is:
[0012]
[0013] Where, P(t) represents the access permission level at time t, t represents time, P max represents the maximum access permission, e represents the base of the natural logarithm, r represents the permission growth rate, and t0 represents the time point when the user reaches the stable permission.
[0014] Preferably, the said S2 includes determining the current number of the user's access requests Q d and the number of available access tokens Q s , if Q d > Q s , add a verification step.
[0015] Preferably, the said S3 includes setting the reference access behavior rate and the user's current access behavior frequency, and calculating the user's current permission change speed. The specific formula is:
[0016] Where, V represents the user's current permission change speed, V0 represents the initial permission adjustment speed, h represents the user's current access behavior frequency, h0 represents the reference access behavior rate, and α represents the set permission change index.
[0017] Preferably, the said S1 further includes collecting the user access history data in a multi-user collaboration environment, including access frequency, access duration, and access data type, establishing a user behavior pattern by using a rule matching method based on the access history data and permission rules, generating a dynamic access control policy according to the user behavior pattern and security policy, and storing it in the access control database.
[0018] Preferably, S2 also includes receiving an access request from a user, the access request including user identity information, target data identifier and operation type, parsing the access request, and calling a dynamic access control model to verify the user identity and authority. If the verification passes, an access token is generated; if the verification fails, the access request is rejected.
[0019] Preferably, the S3 also includes parsing the access token, extracting user permission information, including access data scope, executable operations, and access time limit, matching the permission information in the access token with the access control rules of the target data, and calculating the final executable permissions. If the user permissions meet the access control rules, the corresponding access operations are allowed to be executed and the access results are returned. If the user permissions do not meet the access control rules, access is denied and a prompt message of insufficient permissions is returned.
[0020] Preferably, S4 includes monitoring user access behavior, including access frequency, abnormal access detection, and recording relevant logs, performing data analysis on the monitored access behavior, evaluating the applicability and security of the current access control model, and if an abnormal access pattern is detected, adjusting access rights to limit the access scope of high-risk users; if the access pattern is consistent with normal behavior, optimizing the access control strategy based on the user's long-term behavior, improving the convenience of data access, updating the access control database, and regularly training and optimizing the access control model.
[0021] Preferably, the abnormal access detection in S4 adopts rule matching, machine learning or log-based intrusion detection technology.
[0022] A shared storage device for multi-source data, the device comprising:
[0023] Dynamic access control module, used to build a dynamic access control model based on the user's access history and permission rules in a multi-user collaborative environment;
[0024] User authentication module, used to authenticate user requests and generate access tokens through a dynamic access control model;
[0025] The permission management module is used to determine the user's data access scope and operation permissions based on the access token;
[0026] The model adjustment module is used to adjust the parameters of the dynamic access control model to adapt to the security and privacy requirements of multi-source data.
[0027] It can be seen from the above technical solution that the present invention has the following beneficial effects:
[0028] The shared storage method and device for multi-source data constructs a dynamic access control model based on the access history and permission rules of users in a multi-user collaboration environment, verifies user requests through the dynamic access control model and generates access tokens, determines the data access scope and operation permissions of users according to the access tokens, adjusts the access control model parameters to meet the security and privacy requirements of multi-source data, can adjust access permissions in real time based on changes in user behavior, data sensitivity, and collaboration relationships, avoid problems of over-open permissions or restricted access, thereby meeting the personalized data access needs in a multi-user collaboration environment, can analyze user access patterns in real time, identify abnormal behaviors in a timely manner, and automatically adjust permissions or trigger security alerts, thereby reducing the risk of data leakage, minimizing the exposure of sensitive data while ensuring collaboration efficiency, enhancing the privacy protection ability of the system, reducing the consumption of computing and storage resources, thereby improving the real-time performance of data access and the overall performance of the system, ensuring that data access policies are more precise, avoiding problems of over-authorization or insufficient permissions, ensuring data access compliance, and supporting retrospective analysis, meeting industry data security standards and compliance requirements, and regulating the dynamic adjustment mechanism of access control permissions to solve the problem of insufficient data security and privacy protection in a multi-user collaboration environment. BRIEF DESCRIPTION OF THE DRAWINGS
[0029] Figure 1 It is a flowchart of the method of the present invention;
[0030] Figure 2 It is a connection diagram of the modules of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0031] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0032] As Figure 1 shown, the present invention provides a technical solution: a shared storage method for multi-source data, the method includes:
[0033] S1. Construct a dynamic access control model based on the access history and permission rules of users in a multi-user collaboration environment;
[0034] S2. Verify user requests through the dynamic access control model and generate access tokens;
[0035] S3. Determine the data access scope and operation permissions of users according to the access tokens;
[0036] S4. Adjust the access control model parameters to meet the security and privacy requirements of multi-source data, including determining the basic frequency of access right adjustment by the system and the access frequency of users, and calculating the duration of access rights. The specific formula is: A = B / E;
[0037] Where, A represents the duration of access rights, B represents the basic frequency of access right adjustment by the system, and E represents the access frequency of users.
[0038] The present invention is based on a dynamic access control model. Through the analysis of user access history and permission rules, a permission management mechanism suitable for the multi-source data sharing environment is constructed. First, the system collects user access behavior data, such as access time, access type, operation mode, etc., and combines with preset permission policies, and uses rule matching or machine learning methods to dynamically adjust the access control model. When a user accesses data, the system verifies the user's identity according to this model, matches its permission scope, and generates a corresponding access token to ensure that the access request conforms to the security policy. Subsequently, the access token is parsed to determine the user's data access scope and operation permissions. At the same time, the system will dynamically adjust the validity time of the permissions according to the access frequency and security policy, so as to achieve a balance among data security, privacy protection, and access efficiency. By adopting this method, the system can adjust access rights in real time, improve the flexibility of permission management, and ensure the security and controllability of data sharing. The present invention improves the security and management efficiency of data sharing storage through a dynamic access control model. First, this method can adaptively adjust permissions according to the user's historical access behavior and permission rules, avoid over-authorization or permission lag, and improve the accuracy of data access. Secondly, the access token mechanism ensures the traceability of access rights, so that each access request is strictly verified, thereby reducing the risk of unauthorized access. In addition, this method calculates the duration of access rights, combines the access frequency and permission adjustment strategy, enables the system to flexibly adapt to the access needs of different users, improves resource utilization, and reduces the management burden. Finally, this solution can not only enhance data security and privacy protection, but also optimize the resource allocation of the storage system, and improve the convenience and efficiency of data sharing.
[0039] S1 includes recording the user's access history, determining its initial permission level, determining the user's access growth rate, and calculating the change trend of access rights. The specific formula is:
[0040] Where, P(t) represents the access permission level at time t, t represents time, P max represents the maximum access permission, e represents the base of the natural logarithm, r represents the permission growth rate, and t0 represents the time point when the user reaches the stable permission.
[0041] This method realizes the precise control and adjustment of access rights through the dynamic monitoring and mathematical modeling of user access behaviors. First, based on the user's access history, the system determines their initial permission level and calculates the access growth rate r in combination with the access behavior. It can accurately predict the change trend of the access permission P(t), enabling it to gradually grow from the initial permission to the maximum access permission P max , and reach a stable state at t0. This way can ensure the dynamic adaptability of access rights, enabling the system to adjust permissions according to the user behavior pattern and avoiding excessive opening or restriction of permissions. In addition, this model allows for flexible adjustment of the growth rate r and the stable time t_0 based on different user characteristics (such as access frequency, data sensitivity), thus implementing a more targeted permission management strategy. This method improves the system's refined management ability of access rights by introducing the mathematical modeling of access rights. First, this method conducts permission prediction and dynamic adjustment based on the user access history, enabling the access permission to grow naturally with the user usage situation and enhancing the intelligence level of the system. Secondly, using the logistic growth model P(t) to control the change trend of access rights can effectively prevent the permission from increasing too fast or too slow, ensuring the rationality and security of access control. In addition, this method provides a flexible parameter adjustment mechanism, which can optimize r and t0 according to business requirements to make it applicable to different application scenarios, such as cloud storage, enterprise-level data management, and medical data access, improving the adaptability and security of the system.
[0042] S2 includes determining the current number of access requests Q of the user d and the number of available access tokens Q s . If Q d >Q s , add a verification step. This method dynamically adjusts the access control mechanism by monitoring the number of access requests Q of the user d and the number of available access tokens Q of the system s to optimize resource allocation and ensure data security. First, after receiving the user's access request, the system calculates the current number of access requests Q d and synchronously queries the number of available access tokens Q of the system s . When Q d ≤Q s , the system generates an access token and authorizes the user to access according to the normal process; but when Q d >Q sWhen this occurs, the system triggers additional verification steps, such as two-factor authentication, manual review, or access priority assessment, to ensure that high-priority requests can obtain access permissions first while preventing abnormal access behaviors. This mechanism can effectively balance access requirements and system capacity, improving the stability and security of data access. This method is based on the dynamic matching of the number of user requests and available resources, enhancing the accuracy and security of data access management. First, this method can adjust the access control policy according to the system load to avoid system crashes or access delays caused by request overload. Second, by adding verification steps, it can preferentially authorize trusted users when access tokens are in short supply, thus improving the utilization efficiency of system resources. In addition, this method enhances access security, preventing malicious attacks or abnormal access behaviors and improving the overall reliability of the system. At the same time, this mechanism can adapt to different application scenarios, such as cloud storage, enterprise database management, and financial data access, ensuring the stability and compliance of data sharing.
[0043] S3 includes setting a baseline access behavior rate and the current access behavior frequency of the user, and calculating the current permission change speed of the user. The specific formula is:
[0044] Among them, V represents the current permission change speed of the user, V0 represents the initial permission adjustment speed, h represents the current access behavior frequency of the user, h0 represents the baseline access behavior rate, and α represents the set permission change index.
[0045] This method uses the ratio between the user access behavior frequency h and the baseline access rate h0 to calculate the access permission change speed V, thereby dynamically adjusting the user's permission upgrade or downgrade rate. The system first sets the baseline access behavior rate h0 to measure the normal access mode; when the actual access frequency h of the user changes, the system adjusts according to the exponential adjustment formula Calculate the new permission change speed V. Among them, the exponential parameter α controls the sensitivity of permission adjustment. When h > h0, the permission adjustment speed increases, allowing for faster acquisition of higher-level access permissions; when h < h0, the permission adjustment speed decreases to prevent permission abuse. This dynamic adjustment method can adapt to changes in user behavior, optimize the access control policy, and improve system security and resource utilization. This method improves the accuracy and intelligence level of permission management through a mathematical model based on the frequency of user access behavior. First, user permissions can be automatically adjusted according to their access frequency without manual intervention, improving the automation level of the system. Second, this method can flexibly adapt to different types of user access patterns, ensuring that active users with frequent access can obtain higher-level permissions faster, while users with low-frequency access maintain lower permissions, thus optimizing resource allocation. In addition, the exponential adjustment parameter α enables the system to achieve a balance between security and flexibility, preventing permission abuse while also enhancing the user experience. This method can be widely applied to scenarios that require dynamic access control, such as cloud storage, enterprise data management, and financial trading systems, to improve the stability and security of access management.
[0046] S1 also includes collecting user access historical data in a multi-user collaboration environment, including access frequency, access duration, and access data type. Based on the access historical data and permission rules, a rule matching method is used to establish user behavior patterns. According to the user behavior patterns and security policies, dynamic access control policies are generated and stored in the access control database. This method constructs a dynamic access control mechanism by collecting and analyzing access behavior data in a multi-user collaboration environment to ensure the security and accuracy of data access. First, the system collects user access historical data, including key parameters such as access frequency, access duration, and access data type, to obtain user behavior characteristics. Subsequently, the system combines the preset permission rules and uses a rule matching method to identify the access patterns of different users and formulates security policies based on these behavior patterns. For example, if a user frequently accesses a certain type of data and this behavior conforms to the normal working mode, the permissions can be appropriately relaxed; if abnormal access behavior is detected, such as a large-scale access to sensitive data in a short period of time, additional verification or access permission restrictions are triggered. After generating the dynamic access control policies, the system stores them in the access control database to support subsequent permission management and optimization adjustments, realizing adaptive access control based on historical behavior. This method realizes more refined dynamic access control by combining access historical data with permission rules. First, this method can adaptively adjust access permissions according to different user behavior patterns, improving the security of data sharing. Second, establishing user behavior patterns based on access historical data makes permission management more accurate, reducing the risks of misjudgment and over-authorization. In addition, using the rule matching method improves the ability to detect abnormal behavior and can effectively prevent malicious attacks or abnormal access. Storing the dynamic access control policies in the access control database enables the system to continuously optimize permission management and improve the maintainability and scalability of access control. This method is applicable to various data storage systems, such as cloud storage, enterprise-level database management, medical and financial data access management, etc., enhancing access security and compliance.
[0047] S2 also includes receiving an access request from a user. The access request includes user identity information, a target data identifier, and an operation type. It parses the access request and invokes a dynamic access control model to verify the user's identity and permissions. If the verification passes, it generates an access token; if the verification fails, it rejects the access request. This method strictly verifies the user's access request through a dynamic access control model to ensure the security and compliance of data access. When a user submits an access request, the system first parses the request and extracts the user identity information, target data identifier, and operation type. Then, the system invokes the dynamic access control model to authenticate the user's identity and verify whether the user has the permission to access the data according to the preset permission rules. If the verification passes, the system generates an access token, which contains the target data allowed to be accessed, the authorized operation type, and the access validity period, and returns it to the user. If the verification fails, the system rejects the access request and records a failure log for security auditing or abnormal behavior analysis. This method ensures that only authorized users can access specific data through a dual safeguard mechanism of identity verification and permission control, thus effectively preventing unauthorized access and potential data leakage risks. This method realizes efficient and secure access management through a dynamic access control model. First, this method ensures that all access requests are authenticated and permission-checked, which helps prevent unauthorized access behaviors and improve the security of the system. Second, the access token mechanism supports fine-grained permission management and can divide permissions according to different operation types (such as read, write, modify, delete), thereby enhancing the data protection ability. In addition, this method also supports the logging function and can automatically store relevant information when the permission verification fails, facilitating system administrators for security auditing and abnormal analysis. This mechanism is applicable to various multi-user collaboration environments, such as cloud storage, enterprise-level databases, financial and medical data management, etc., improving the security and controllability of data sharing.
[0048] S3 also includes parsing the access token, extracting user permission information, including the scope of access data, executable operations, and access time limit. According to the permission information in the access token, it is matched with the access control rules of the target data, and the final executable permission is calculated. If the user permission meets the access control rules, the corresponding access operation is allowed to be executed, and the access result is returned. If the user permission does not meet the access control rules, the access is denied, and a prompt message of insufficient permission is returned. This method achieves precise control of user access rights by parsing the access token to ensure that the access request meets the security policy. After receiving the user access request, the system first parses the access token and extracts user permission information from it, including the scope of accessible data, the allowed operation type (such as read, write, modify, delete) and the access time limit. Subsequently, the system matches the extracted permission information with the access control rules of the target data and calculates the user's final executable permission. If the matching result shows that the user permission meets the access control rules, the system allows the user to perform the corresponding access operation and returns the access result; if the user permission does not meet the rules, the system denies the access request and returns a prompt message of insufficient permission. This method ensures strict management of access rights, prevents unauthorized access, and improves data security. This method improves the security of the system and the refined management of access control through access token parsing and permission matching mechanism. First, this method ensures that all access requests must be verified by access tokens to prevent unauthorized access. Secondly, the access token contains access time information, which enables the system to automatically control the validity period of permissions and reduce the security risks brought by long-term open permissions. In addition, this method ensures that users can only access data that complies with security policies through access control rule matching, thereby improving the compliance of data access. When the system rejects unauthorized access, it provides a clear prompt for insufficient permissions to improve the user experience, and supports logging functions to facilitate security audits and abnormal behavior analysis. This method is suitable for scenarios such as cloud storage, enterprise data management, financial and medical data access control, and improves the security and management efficiency of data sharing.
[0049] S4 includes monitoring user access behaviors, including access frequency and abnormal access detection, recording relevant logs, performing data analysis on the monitored access behaviors, evaluating the applicability and security of the current access control model. If abnormal access patterns are detected, access permissions are adjusted to limit the access scope of high-risk users. If the access pattern conforms to normal behavior, the access control policy is optimized based on the user's long-term behavior to improve the convenience of data access, the access control database is updated, and the access control model is trained and optimized regularly. This method realizes the dynamic adjustment of the access control policy by continuously monitoring user access behaviors to enhance data security and access efficiency. First, the system monitors the user's access frequency, access request patterns, and abnormal behaviors (such as accessing sensitive data in a large amount within a short time, requests from abnormal IP addresses, etc.) and records detailed logs. Subsequently, the system analyzes the collected data to evaluate the applicability and security of the current access control model. If abnormal access patterns (such as frequent invalid access requests, permission boundary crossing attempts, etc.) are detected, the system automatically adjusts the access permissions to limit the access scope of high-risk users to prevent potential security threats. On the contrary, if the user access pattern has long conformed to normal behavior, the system optimizes the access control policy according to the historical behavior data to appropriately improve the access convenience of users. For example, the system can reduce the authentication frequency of specific users or expand the data scope they can access. In addition, the system regularly updates the access control database and trains and optimizes the access control model to ensure that it can adapt to the changing user behavior patterns and security requirements. This method improves the security and intelligent management ability of data access through real-time monitoring and dynamic adjustment of access permissions. First, based on the analysis of user access behaviors, the system can quickly identify abnormal access patterns and take protective measures to reduce the risks of data leakage and malicious attacks. Second, by optimizing the access control policy for normal users, this method can improve the convenience of data access while ensuring security, reduce unnecessary authentication steps, and enhance the user experience. In addition, regularly training and optimizing the access control model enables the system to adapt to changes in user behaviors and maintain long-term security and stability. This method can be widely applied to fields such as cloud storage, enterprise data management, finance, and healthcare to ensure the security, compliance, and efficiency of data sharing.
[0050] In S4, anomaly access detection adopts rule matching, machine learning, or log-based intrusion detection technology. This method realizes anomaly access detection through various technical means to improve the security and detection accuracy of the system. During the S4 access behavior monitoring process, the system uses rule matching, machine learning, and log-based intrusion detection technology to identify abnormal access patterns. Rule matching technology is based on predefined access rules, such as access frequency thresholds, blacklists of suspicious IP addresses, unauthorized access attempts, etc., to compare access behaviors in real time and quickly detect obvious violations. Machine learning technology uses historical access data to train anomaly detection models, such as methods based on support vector machines (SVM), random forests, neural networks, etc., to automatically identify complex abnormal patterns, such as progressive privilege escalation attacks or covert data theft behaviors. In addition, the system also combines log-based intrusion detection technology (such as IDS, intrusion detection system) to deeply analyze access logs and identify potential intrusion attempts, such as multiple failed logins within a short period of time, abnormal data download volumes, etc. Through the synergistic effect of these detection means, the system can effectively discover abnormal access and take corresponding security measures, such as triggering additional authentication, restricting the permissions of suspicious users, or sending security alerts to administrators. This method improves the security and intelligence level of access control through a multi-level anomaly access detection mechanism. First, rule matching technology can quickly respond to known security threats, such as access frequency overlimit or unauthorized access attempts, to ensure basic security protection. Second, machine learning technology enables the system to autonomously learn user access behaviors, detect unknown abnormal patterns, and enhance the defense ability against new types of attacks. In addition, log-based intrusion detection provides the ability to analyze historical data, can retrospectively analyze potential security risks, and support long-term security optimization. By comprehensively using these technologies, the system can improve the flexibility of access management, reduce the possibility of false positives and false blocks of users while ensuring data security. This method is applicable to scenarios with high security requirements such as cloud computing, enterprise data storage, medical care, and finance to ensure the compliance and security of data access.
[0051] As Figure 2 shown, a shared storage device for multi-source data is also provided. The device includes:
[0052] A dynamic access control module for constructing a dynamic access control model based on the access history and permission rules of users in a multi-user collaboration environment;
[0053] A user verification module for verifying user requests through the dynamic access control model and generating access tokens;
[0054] A permission management module for determining the data access scope and operation permissions of users according to the access tokens;
[0055] A model adjustment module for adjusting the parameters of the dynamic access control model to meet the security and privacy requirements of multi-source data.
[0056] This device realizes dynamic access control and permission management of multi-source data through the collaborative work of multiple functional modules. The dynamic access control module is responsible for collecting the user's access history data, including access frequency, data type, operation mode, etc., and combining with the preset permission rules to construct an access control model that can adapt to changes. After receiving a user access request, the user authentication module calls the dynamic access control model to authenticate the user's identity and verify their access permissions according to the permission rules. If the verification is successful, an access token is generated and attached to the user request. The permission management module parses the access token to obtain the allowed operation types (such as read, write, modify, delete) and the accessible data range of the user, and decides whether to allow access according to the access control policy. The model adjustment module is responsible for monitoring the user's access behavior and the system's security requirements, and dynamically optimizing the parameters of the access control model, such as adjusting the permission update frequency, adding abnormal access detection, etc., to ensure that the system can not only meet the privacy protection requirements but also provide efficient data access services. Through the dynamic access control model, this device improves the security and flexibility of data sharing. First, the device can automatically adjust permissions according to the user's access behavior, avoiding over-authorization or permission lag and improving the accuracy of data access. Second, the access token mechanism enhances the traceability of access management, ensuring that each access can be verified and audited. In addition, the model adjustment module provides an intelligent security policy optimization function, enabling the system to adapt to different application scenarios, such as cloud storage, enterprise data management, medical, finance, etc., ensuring the security and compliance of data sharing, while improving the user experience and access efficiency.
[0057] Although the embodiments of the present invention have been shown and described, it will be understood by those of ordinary skill in the art that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A shared storage method for multi-source data, characterized in that: The method comprises: S1, build a dynamic access control model based on the user's access history and permission rules in a multi-user collaborative environment; S2, verify the user request through the dynamic access control model and generate an access token; S3. Determine the user's data access scope and operation permissions based on the access token; S4. Adjust the parameters of the access control model to adapt to the security and privacy requirements of multi-source data, including determining the basic frequency of the system's adjustment of access rights and the user's access frequency, and calculating the duration of access rights. The specific formula is: A = B / E; A represents the duration of access rights, B represents the basic frequency of the system's adjustment of access rights, and E represents the user's access frequency.
2. A shared storage method for multi-source data according to claim 1, characterized in that: S1 includes recording the user's access history, determining the initial permission level, determining the user's access growth rate, and calculating the change trend of the access permission. The specific formula is: Where P(t) represents the access permission level at time t, t represents time, and P max represents the maximum access permission, e represents the natural logarithm base, r represents the permission growth rate, and t0 represents the time point when the user reaches stable permission.
3. A shared storage method for multi-source data according to claim 1, characterized in that: S2 includes determining the current number of access requests Q of the user d and the number of access tokens that can be provided, Q s , if Q d >Q s , add verification steps.
4. A shared storage method for multi-source data according to claim 1, characterized in that: S3 includes setting the benchmark access behavior rating and the user's current access behavior frequency, and calculating the user's current permission change speed. The specific formula is: Among them, V represents the user's current permission change speed, V0 represents the initial permission adjustment speed, h represents the user's current access behavior frequency, h0 represents the benchmark access behavior evaluation rate, and α represents the set permission change index.
5. The shared storage method for multi-source data according to claim 1, characterized in that: The S1 also includes collecting user access history data in a multi-user collaborative environment, including access frequency, access duration, and access data type. Based on the access history data and permission rules, a rule matching method is used to establish a user behavior pattern. According to the user behavior pattern and security policy, a dynamic access control policy is generated and stored in the access control database.
6. A shared storage method for multi-source data according to claim 1, characterized in that: The S2 also includes receiving an access request from a user, the access request including user identity information, target data identifier and operation type, parsing the access request, and calling a dynamic access control model to verify the user identity and authority. If the verification passes, an access token is generated; if the verification fails, the access request is rejected.
7. A shared storage method for multi-source data according to claim 1, characterized in that: The S3 also includes parsing the access token, extracting user permission information, including the access data scope, executable operations, and access time limit, matching the permission information in the access token with the access control rules of the target data, and calculating the final executable permissions. If the user permissions meet the access control rules, the corresponding access operations are allowed to be executed and the access results are returned. If the user permissions do not meet the access control rules, access is denied and a prompt message of insufficient permissions is returned.
8. A shared storage method for multi-source data according to claim 1, characterized in that: The S4 includes monitoring user access behavior, including access frequency, abnormal access detection, and recording relevant logs, performing data analysis on the monitored access behavior, evaluating the applicability and security of the current access control model, and if an abnormal access pattern is detected, adjusting access rights to limit the access scope of high-risk users. If the access pattern is consistent with normal behavior, optimizing the access control strategy based on the user's long-term behavior, improving the convenience of data access, updating the access control database, and regularly training and optimizing the access control model.
9. A shared storage method for multi-source data according to claim 8, characterized in that: The abnormal access detection in S4 adopts rule matching, machine learning or log-based intrusion detection technology.
10. A shared storage device for multi-source data, characterized in that: The device comprises: Dynamic access control module, used to build a dynamic access control model based on the user's access history and permission rules in a multi-user collaborative environment; User authentication module, used to authenticate user requests and generate access tokens through a dynamic access control model; The permission management module is used to determine the user's data access scope and operation permissions based on the access token; The model adjustment module is used to adjust the parameters of the dynamic access control model to adapt to the security and privacy requirements of multi-source data.
Citation Information
Patent Citations
Safety access method and system based on industrial internet platform
CN118487847A
Client information dynamic management and protection method
CN118643480A
Access control method and system for data security protection
CN119109614A
Data system and dynamic access control method based on historical access records
CN119341782A
Methods and systems for enabling access control based on credential properties
US9923927B1
Cited By
Trusted data space connector layer data flow method and system
CN120567574A
Multi-scene identity authentication and data sharing system based on real-name DID
CN120979767A