Multi-level data security grading authentication and user access authority dynamic matching method

By using multi-level data security hierarchical authentication dynamically matches user access rights in data access control, problems such as insufficient flexibility and accuracy and large resource consumption in the existing technology are solved, and dynamic management and refined control of data access rights are realized, security risks are reduced and defense capabilities are enhanced for internal attacks.

CN120217428APending Publication Date: 2025-06-27SHANGHAI AOTENG COMPUTER TECHNOLOGY CO LTD

Patent Information

Application Number
CN202510275661.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-10
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

The existing technology has problems such as insufficient flexibility and accuracy, large resource consumption, insufficient internal attack defense, lack of space-time features, and multi-factor authentication complexity in data access control, which is difficult to meet the data security needs in modern complex environments.

Method used

The dynamic matching method of multi-level data security hierarchical authentication and user access rights is adopted, and the refined matching of user roles' data access rights and security risk levels through technical means such as preset sensitive data risk levels, hierarchical authentication, multi-factor authentication, behavioral pattern monitoring and dynamic permission adjustment can be achieved.

Benefits of technology

It realizes dynamic management and refined control of data access rights, reduces security risks, improves the flexibility and accuracy of access control, reduces resource consumption, and enhances the defense capabilities of internal attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120217428A_ABST
    Figure CN120217428A_ABST
Patent Text Reader

Abstract

The invention relates to a multi-level data security grading authentication and user access permission dynamic matching method, and belongs to the technical field of data management. The method comprises the following steps: presetting a sensitive data risk level, and performing hierarchical authentication on accessible data in a system according to the sensitive data risk level to obtain a security risk level based on access data; defining user roles according to an organization structure and business requirements of a system use object, allocating an initial data access permission to each user role, and dynamically adjusting the data access permission of the user roles by monitoring a behavior mode and a data access history of the user roles; the user roles are matched with the identification vectors of the security risk levels through the built-in permission vectors when accessing the system data, and corresponding data access permissions are distributed to the corresponding user roles after matching succeeds. And fine management of data security and dynamic optimization of user access authority are realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of data management, and particularly relates to a multi-level data security classification and authentication method and a dynamic matching method for user access rights. Background Art

[0002] In the current technical field of data management, the management of data security and user access rights is of crucial importance. Traditional data security management methods often adopt static permission allocation methods, that is, preset the data access permissions according to the user's role or position. However, this method has many limitations, such as the permission allocation is not fine enough, and it is impossible to dynamically adjust the permissions according to the user's behavior, which easily leads to security problems such as data leakage or abuse.

[0003] With the development of information technology, the sensitivity and importance of data are increasing continuously. Multi-level security models (such as the BLP model, the ABAC model, etc.) are widely used to ensure the confidentiality and integrity of data. Although traditional access control models (such as RBAC) are simple and easy to manage, in complex environments such as cloud computing and mobile edge computing, their flexibility and fine-grainedness are insufficient. In modern application scenarios, users may access data at different times and locations, so a mechanism that can dynamically adjust access permissions is needed to adapt to the changing environment. For example, in the cloud computing environment, the behavior and trustworthiness of users need to be evaluated in real time to dynamically adjust their access permissions. Existing access control policies often ignore the risk of internal attacks, which may lead to serious security hazards in practical applications.

[0004] Problems Existing at the Current Stage

[0005] Lack of flexibility and accuracy: Existing access control policies usually have the problem of coarse-grainedness and are difficult to meet the needs of fine-grained authorization. For example, the traditional RBAC model cannot dynamically adjust permissions according to the specific attributes and context of users.

[0006] Resource consumption and overhead: Although some advanced access control methods (such as attribute-based encryption and fine-grained authorization) improve security, they will increase the computational and storage overhead of the system, especially difficult to apply on resource-limited mobile devices.

[0007] Insufficient defense against internal attacks: Existing methods do not fully consider the risk of internal attacks, resulting in being vulnerable to threats from internal personnel in practical applications.

[0008] Lack of spatio-temporal characteristics: Existing multi-level security models usually ignore time and space factors, making it difficult for them to meet the needs of users accessing data at different times and locations.

[0009] Multi - factor authentication complexity: Although multi - factor authentication (MFA) improves security, it also increases the complexity of the authentication process and the burden on the user experience.

[0010] Insufficient dynamic risk assessment: When existing methods dynamically assess the risk of user behavior, they may not be able to comprehensively capture all potential threat factors, resulting in inaccurate access control policies. Summary of the Invention

[0011] To solve the above problems existing in the prior art, the present invention provides a multi - level data security hierarchical authentication and dynamic matching method for user access rights;

[0012] The object of the present invention can be achieved through the following technical solutions:

[0013] A multi - level data security hierarchical authentication and dynamic matching method for user access rights, including:

[0014] Preset the risk levels of sensitive data, perform hierarchical authentication on the accessible data in the system according to the risk levels of sensitive data to obtain the security risk level based on the accessed data; define user roles according to the organizational structure and business requirements of the system users, and assign initial data access rights to each user role, and dynamically adjust the data access rights of the user roles by monitoring the behavior patterns and data access history of the user roles; when the user role accesses the system data, it matches through the built - in permission vector and the identification vector of the security risk level, and after successful matching, assign corresponding data access rights to the corresponding user role.

[0015] Specifically, the hierarchical authentication method adopts a multi - factor authentication mechanism, classifies the sources of data to be accessed, including data sets, data items, and derived data, and obtains the security risk level according to the data scale, data coverage, and sensitive risk of the data sets, data items, and derived data according to the risk levels of sensitive data.

[0016] Specifically, the initial data access rights are the default rights preset by the system according to the basic attributes, scope of responsibilities, and business requirements of the user role; the data access rights ensure that the user role can perform its duties normally while restricting access to sensitive data; during subsequent use, the system will dynamically adjust the initial rights according to the behavior patterns and data access history of the user role.

[0017] Specifically, the identification vector of the security risk level includes a color - coded risk matrix, an information security level vector, a target security level, and a security risk level determined through data matching.

[0018] Specifically, the permission vector built into the user role includes a static vector and a dynamic vector. The static vector is preset according to the basic attributes and scope of responsibilities of the user role, representing the basic permissions of the role in the system. The dynamic vector is dynamically generated based on the behavior patterns, data access history, and security risk levels of the user role, and is used to adjust and improve the permission scope set by the static vector. By combining the static vector and the dynamic vector, refined management and dynamic adjustment of the user role permissions are achieved, ensuring that while the user role performs its duties, its access permissions match the security risk level.

[0019] Specifically, the method for matching the permission vector and the identification vector is as follows:

[0020] The system generates a permission vector space based on the permission vector of the user role. The permission vector includes a static vector and a dynamic vector. Each permission vector in the permission vector space is compared with the identification vector of the preset security risk level, and the best matching relationship is determined by calculating the similarity between the two. The matching process comprehensively considers the color-coded risk matrix, the information security level vector, the target security level, and establishes a weight system to assign corresponding weights to each factor. Then, combining the similarity calculation results of the permission vector and the identification vector, the final matching level is obtained. The similarity uses the cosine similarity, and the specific calculation formula is as follows:

[0021]

[0022] Among them, T is the security risk level, A is the permission vector, B is the identification vector, R is the risk coefficient determined according to the color-coded risk matrix, T x is the target security level, T y is the information security level; w1, w2, w3 are weight coefficients, set according to the security policy.

[0023] Specifically, the method for dynamically adjusting the data access permissions of the user role is as follows: The system will monitor the behavior data of the user role in real time, including access frequency, access time, access content, and the matching degree between the behavior of the user role and the security policy. The matching degree is represented by the permission consistency difference between the actual permissions of the user and the predefined role permission template. If the matching degree is lower than the preset adaptation threshold, the dynamic adjustment mechanism is triggered, and the system re-evaluates the permission vector of the user role. According to the latest security requirements and risk levels, the data access permissions are dynamically increased or decreased. The dynamic adjustment process follows the principle of least privilege, only granting the user the minimum set of permissions required to complete their tasks.

[0024] Specifically, the behavior analysis algorithm is as follows:

[0025] Collect user behavior data, including login time, access path, and operation type information; preprocess the data to remove noise and redundant information;

[0026] Use machine learning algorithms to model user behavior and establish a baseline for normal behavior; monitor user behavior in real time and compare it with the normal behavior baseline to identify abnormal behavior;

[0027] Conduct in-depth analysis of the identified abnormal behavior through association rule mining to obtain the correlation between abnormal behavior and other security events, and combine business rules to judge the risk level of abnormal behavior to obtain an evaluated risk level;

[0028] Perform secondary authentication on the permission vector of the user role according to the evaluated risk level of user behavior.

[0029] The beneficial effects of the present invention are as follows:

[0030] Through the method of the present invention, dynamic management and refined control of data access permissions are achieved. First, the present invention presets the risk levels of sensitive data and conducts hierarchical authentication on the accessible data within the system, thereby obtaining the security risk level based on the accessed data. This step ensures the accuracy of data classification and risk assessment and provides a basis for subsequent permission allocation. User roles are defined according to the organizational structure and business requirements of system users, and initial data access permissions are assigned to each user role. These permissions are default permissions preset based on the basic attributes, scope of responsibilities, and business requirements of user roles, which not only ensure that user roles can perform their duties normally but also restrict access to sensitive or high-risk data. During subsequent use, the present invention dynamically adjusts the initial permissions according to the behavior patterns and data access history of user roles. This dynamic adjustment mechanism makes permission management more refined and personalized, can adjust the data access permissions of user roles in a timely manner according to actual situations, and reduces security risks.

[0031] In addition, the present invention also realizes the matching of user role permissions and data security risk levels through the matching method of permission vectors and identification vectors. The system generates a permission vector space based on the permission vectors of user roles and compares it with the identification vectors of preset security risk levels, and determines the best matching relationship by calculating the similarity. This process comprehensively considers multiple factors such as the risk matrix with color coding, the information security level vector, and the target security level, ensuring the accuracy and reliability of the matching. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] For the convenience of those skilled in the art to understand, the present invention will be further described below with reference to the accompanying drawings.

[0033] Figure 1It is a schematic flow chart of a multi-level data security classification authentication and user access right dynamic matching method of the present invention. Detailed implementation manners

[0034] To further elaborate on the technical means and effects adopted by the present invention to achieve the predetermined invention purpose, the following will, in conjunction with the accompanying drawings and preferred embodiments, detail the specific implementation manners, structures, features and their effects according to the present invention.

[0035] Please refer to Figure 1 , a multi-level data security classification authentication and user access right dynamic matching method, including:

[0036] Preset the risk levels of sensitive data, perform classification authentication on the accessible data in the system according to the risk levels of the sensitive data to obtain the security risk levels based on the accessed data; define user roles according to the organizational structure and business requirements of the system users, and assign initial data access rights to each user role, and dynamically adjust the data access rights of the user roles by monitoring the behavior patterns and data access histories of the user roles; when the user roles access the system data, they match through the built-in permission vector and the identification vector of the security risk level, and after successful matching, assign corresponding data access rights to the corresponding user roles.

[0037] Specifically, the classification authentication method adopts a multi-factor authentication mechanism, classifies the sources of the data to be accessed, including data sets, data items, and derived data, and obtains the security risk levels according to the data scale, data coverage, and sensitive risks of the data sets, data items, and derived data according to the risk levels of the sensitive data.

[0038] Specifically, the initial data access rights are the default rights preset by the system according to the basic attributes, scope of responsibilities, and business requirements of the user roles; the data access rights ensure that the user roles can perform their duties normally while restricting access to sensitive data; during subsequent use, the system will dynamically adjust the initial rights according to the behavior patterns and data access histories of the user roles.

[0039] Specifically, the identification vector of the security risk level includes a color-coded risk matrix, an information security level vector, a target security level, and a security risk level determined through data matching.

[0040] Specifically, the permission vector built into the user role includes a static vector and a dynamic vector. The static vector is preset according to the basic attributes and scope of responsibilities of the user role, representing the basic permissions of the role in the system. The dynamic vector is dynamically generated based on the behavior pattern, data access history, and security risk level of the user role, and is used to adjust and improve the permission scope set by the static vector. By combining the static vector and the dynamic vector, refined management and dynamic adjustment of the user role's permissions are achieved, ensuring that while the user role performs its duties, its access permissions match the security risk level.

[0041] Specifically, the method for matching the permission vector and the identification vector is as follows:

[0042] The system generates a permission vector space based on the permission vector of the user role. The permission vector includes a static vector and a dynamic vector. Each permission vector in the permission vector space is compared with the identification vector of the preset security risk level, and the best matching relationship is determined by calculating the similarity between the two. The matching process comprehensively considers the color-coded risk matrix, the information security level vector, and the target security level, and establishes a weight system to assign corresponding weights to each factor. Then, combining the similarity calculation results of the permission vector and the identification vector, the final matching level is obtained. The similarity uses cosine similarity, and the specific calculation formula is:

[0043]

[0044] where T is the security risk level, A is the permission vector, B is the identification vector, R is the risk coefficient determined according to the color-coded risk matrix, T x is the target security level, T y is the information security level; w1, w2, and w3 are weight coefficients, set according to the security policy.

[0045] Specifically, the method for dynamically adjusting the data access permissions of the user role is as follows: The system will monitor the behavior data of the user role in real time, including access frequency, access time, access content, and the matching degree between the behavior of the user role and the security policy. The matching degree is represented by the permission consistency difference between the actual permissions of the user and the predefined role permission template. If the matching degree is lower than the preset adaptation threshold, the dynamic adjustment mechanism is triggered, and the system re-evaluates the permission vector of the user role. According to the latest security requirements and risk level, the data access permissions are dynamically increased or decreased. The dynamic adjustment process follows the principle of least privilege, only granting the minimum set of permissions required for the user to complete their tasks.

[0046] Specifically, the behavior analysis algorithm is as follows:

[0047] Collect user behavior data, including login time, access path, and operation type information; preprocess the data to remove noise and redundant information;

[0048] Use machine learning algorithms to model user behavior and establish a baseline for normal behavior; monitor user behavior in real time and compare it with the normal behavior baseline to identify abnormal behavior;

[0049] Conduct in-depth analysis of the identified abnormal behavior through association rule mining to obtain the correlation between abnormal behavior and other security events, and combine business rules to judge the risk level of abnormal behavior to obtain an evaluation risk level;

[0050] Perform secondary authentication on the permission vector of the user role according to the evaluation risk level of the user behavior.

[0051] In this embodiment, user behavior data, including information such as login time, access path, and operation type, is obtained through network traffic monitoring, system log recording, etc.; after data collection is completed, the data is preprocessed to remove noise and redundant information. The preprocessing steps include: data cleaning: removing invalid or incorrect data records; data deduplication: ensuring that the behavior records of each user are unique; data normalization: unifying the data formats from different sources for subsequent analysis; extracting key features from the preprocessed data, mainly including the frequency of accessing sensitive data, the complexity of the access path, and the operation type; marking normal and abnormal behaviors based on historical data, and generating a behavior baseline by analyzing the behavior data of normal users; selecting a support vector machine model and choosing the radial basis function (RBF) kernel for training, and deploying the trained model to the production environment; using stream processing technologies (such as Apache Kafka or Spark Streaming) to receive and process user behavior data in real time, and identifying the behavior data through the SVM model; using the FP-Growth algorithm for the identified abnormal behavior to mine the correlation between abnormal behavior and other security events, specifically by integrating abnormal behavior and other security events to create a transaction dataset; each transaction should contain all events related to a certain user, such as Transaction 1: {abnormal behavior 1, high-frequency unauthorized access}; Transaction 2: {abnormal behavior 2, account lock}; using the FP-Growth algorithm in the Python mlxtend library for frequent itemset mining; setting an appropriate minimum support (0.1) according to the data scale and requirements to filter out frequent itemsets; using association rule mining to generate association rules from the frequent itemsets, evaluating the generated rules, and viewing indicators such as support, confidence, and lift to judge the strength of the association.

[0052] Based on the results of combining business rules and association rules, determine the risk level of abnormal behavior, and dynamically adjust the user's access rights according to the risk level.

[0053] The computer storage medium of the embodiments of the present invention may adopt any combination of one or more computer-readable media. The computer-readable medium may be a computer-readable signal medium or a computer-readable storage medium. The computer-readable storage medium may, for example, but not be limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (non-exhaustive list) of the computer-readable storage medium include: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this document, the computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.

[0054] The computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries the computer-readable program code. Such a propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium may also be any computer-readable medium other than the computer-readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device.

[0055] The program code contained on the computer-readable medium may be transmitted using any appropriate medium, including but not limited to wireless, wire, optical fiber cable, RF, etc., or any suitable combination of the above. The computer program code for performing the operations of the present invention may be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., by using an Internet service provider to connect through the Internet).

[0056] The above are only the preferred embodiments of the present invention, and do not impose any form of limitation on the present invention. Although the present invention has been disclosed above with the preferred embodiments, it is not intended to limit the present invention. Any person skilled in the art can make some changes or modifications to equivalent embodiments by using the above-disclosed technical content within the scope of the technical solution of the present invention. However, as long as it does not depart from the content of the technical solution of the present invention, any simple modification, equivalent change and modification made to the above embodiments based on the technical essence of the present invention still fall within the scope of the technical solution of the present invention.

Claims

1. A multi-level data security hierarchical authentication and user access rights dynamic matching method, characterized in that: include: Preset sensitive data risk levels, and perform hierarchical authentication on accessible data in the system according to the sensitive data risk levels to obtain security risk levels based on access data; User roles are defined according to the organizational structure and business requirements of the system users, and initial data access permissions are assigned to each user role. The data access permissions of the user roles are dynamically adjusted by monitoring the user roles' behavior patterns and data access histories. When the user roles access system data, the built-in permission vector is matched with the identification vector of the security risk level. After a successful match, the corresponding data access permissions are assigned to the corresponding user roles.

2. The method according to claim 1, characterized in that The hierarchical authentication method adopts a multi-factor authentication mechanism to classify the sources of the data to be accessed, including data sets, data items, and derived data, and obtains the security risk level by setting the data scale, data coverage, and sensitive risks of the data sets, data items, and derived data according to the sensitive data risk level.

3. The method according to claim 1, characterized in that The initial data access rights are default rights preset by the system based on the basic attributes of the user role, scope of responsibilities, and business needs; the data access rights ensure that the user role can perform its duties normally while limiting access to sensitive data; in subsequent use, the system will dynamically adjust the initial rights based on the user role's behavior patterns and data access history.

4. The method according to claim 1, characterized in that The identification vector of the security risk level includes a color-coded risk matrix, an information security level vector, a target security level, and a security risk level determined by data matching.

5. The method according to claim 1, characterized in that The built-in permission vector of the user role includes a static vector and a dynamic vector. The static vector is preset according to the basic attributes and scope of responsibilities of the user role, and represents the basic permissions of the role in the system; the dynamic vector is dynamically generated according to the behavior pattern, data access history and security risk level of the user role, and is used to adjust and improve the permission scope set by the static vector; by combining the static vector and the dynamic vector, the refined management and dynamic adjustment of the user role permissions are achieved, ensuring that the user role's access rights match the security risk level while performing its duties.

6. The method according to claim 1, characterized in that The matching method between the permission vector and the identification vector is: The system will generate a permission vector space based on the permission vector of the user role, which includes static vectors and dynamic vectors; compare each permission vector in the permission vector space with the identification vector of the preset security risk level, and determine the best matching relationship by calculating the similarity between the two; the matching process will comprehensively consider the color-coded risk matrix, information security level vector, target security level, and establish a weight system to assign corresponding weights to each factor, and then combine the similarity calculation results of the permission vector and the identification vector to obtain the final matching level. The similarity adopts cosine similarity, and the specific calculation formula is: Among them, T is the security risk level, A is the authority vector, B is the identification vector, and R is the risk coefficient determined according to the color-coded risk matrix. x is the target safety level, T y is the information security level; w1, w2, w3 are weight coefficients, which are set according to the security policy.

7. The method according to claim 1, characterized in that The method for dynamically adjusting the data access rights of the user role is as follows: the system monitors the behavioral data of the user role in real time, including access frequency, access time, access content, and the degree of match between the user role's behavior and the security policy, and the degree of match is represented by the difference in permission consistency between the user's actual permissions and the predefined role permission template; if the degree of match is lower than a preset adaptation threshold, the dynamic adjustment mechanism is triggered, and the system re-evaluates the permission vector of the user role, and dynamically increases or decreases data access rights based on the latest security requirements and risk levels; the dynamic adjustment process follows the principle of least privilege, and only grants the user the minimum set of permissions required to complete his or her task.

8. The method according to claim 7, characterized in that The behavior analysis algorithm is: Collect user behavior data, including login time, access path, and operation type information; pre-process the data to remove noise and redundant information; Use machine learning algorithms to model user behavior and establish a baseline of normal behavior; Monitor user behavior in real time and compare it with the normal behavior baseline to identify abnormal behavior; Through association rule mining, the identified abnormal behaviors are deeply analyzed to obtain the correlation between abnormal behaviors and other security events, and the risk level of abnormal behaviors is determined in combination with business rules to obtain the assessed risk level; Based on the assessed risk level of the user's behavior, the permission vector of the user role is re-authenticated.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the multi-level data security hierarchical authentication and user access authority dynamic matching method as described in any one of claims 1-8 is implemented.

10. A storage medium containing computer executable instructions, characterized in that: The computer executable instructions, when executed by a computer processor, are used to execute the multi-level data security hierarchical authentication and user access authority dynamic matching method as described in any one of claims 1-8.

Citation Information

Patent Citations

  • Role-based access control situation awareness defense method and system

    CN113411295A

  • Data access method and device, electronic equipment and storage medium

    CN115344888A

  • Meteorological service system-oriented intelligent authority dynamic management method, system and terminal

    CN116502209A

Cited By

  • Computer data security protection method and system

    CN120408688A

  • Safety management method and system for data management and storage medium

    CN120896742A

  • Secret data security management system and method based on role access control

    CN121333740A

  • Role-based knowledge base authority management and data access control method and system

    CN121723500A