Information access security control method and system

By deploying an environmental collection network in a secure physical space, real-time monitoring and multi-dimensional evaluation of the user environment, and dynamically adjusting access control, the problem that traditional security measures are difficult to prevent information leakage in complex environments is solved, and accurate security judgment and dynamic protection of the user environment are achieved.

CN120263523BActive Publication Date: 2025-10-17BEIJING XIN INTERNET TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510611132.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-13
Publication Date
2025-10-17
Estimated Expiration
2045-05-13

AI Technical Summary

Technical Problem

Existing information security access measures are difficult to effectively prevent information leakage in unauthorized environments in complex and changing physical environments. Traditional digital authentication and access control cannot accurately determine whether the user is in a safe environment. Attackers can bypass authentication and access sensitive data through location spoofing technology.

Method used

By deploying a secure environment collection network in a secure physical space, obtaining environmental baseline feature data, encrypting this data with user identity information, and monitoring the user environment in real time, multi-dimensional risk assessment and dynamic access control are performed, including spectrum analysis, wireless network card scanning, and electromagnetic signal reception. Combined with radio frequency fingerprint features, network matching, and behavior monitoring, access rights can be dynamically adjusted.

Benefits of technology

It achieves accurate security judgment of the user's current environment, effectively identifies potential unauthorized access risks, dynamically adjusts access control, reduces the possibility of information leakage, prevents location deception and internal threats, and enhances information access security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120263523B_ABST
    Figure CN120263523B_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of energy efficiency management, and particularly relates to an information access security control method and system. The method comprises the following steps: performing security physical space authorization on a target access environment, and deploying a security environment acquisition network; performing access environment benchmark monitoring by using the security environment acquisition network to obtain environment benchmark characteristic data; a user generates real-time access environment monitoring data by performing real-time access environment monitoring through a user terminal device; performing multi-dimensional access risk assessment on the real-time access environment monitoring data by using the environment benchmark characteristic data, and performing dynamic information security access execution to obtain access control execution data; and monitoring the operation behavior of the user based on the access control execution data to realize information access security control. The present application can effectively prevent information access in an unauthorized physical environment, and significantly improves the ability to resist location fraud, illegal intrusion and potential internal threats.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of information security technology, and in particular to an information access security control method and system. BACKGROUND

[0002] Existing information security access measures mainly focus on user identity authentication, access permission control, and network firewall technology, etc. Although these technologies play a certain role in preventing network attacks, data theft, and malicious tampering, etc., they are insufficient in considering the physical environment safety factor. Users often access sensitive information in various complex and variable physical environments, which makes the traditional security protection means relying on single digital authentication and access control have obvious limitations, and it is difficult to effectively prevent information leakage risks in unauthorized physical environments. Therefore, the traditional access control technology lacks real-time monitoring and analysis capability of the user's physical environment, and cannot accurately determine whether the user is in a safe access environment. Attackers can bypass identity verification and location-based access restrictions by location spoofing technology (such as fake GPS signals) or stealing devices in unauthorized areas, directly accessing sensitive data, and thus illegally obtaining protected information. SUMMARY

[0003] Based on this, the present application provides an information access security control method and system to solve at least one of the above technical problems.

[0004] To achieve the above purpose, an information access security control method comprises the following steps:

[0005] Step S1: authorizing a target access environment to a safe physical space; deploying a safe environment collection network in the safe physical space; monitoring the access environment benchmark using the safe environment collection network to obtain environment benchmark feature data; wherein the safe environment collection network comprises a spectrum analyzer, a wireless network card, and an electromagnetic signal receiving unit;

[0006] Step S2: obtaining user identity information; securely encrypting the environment benchmark feature data using the user identity information to obtain safe environment benchmark data; a user initiates an information access request through a user terminal device to obtain an access trigger signal; monitoring the real-time access environment using the user terminal device based on the access trigger signal to generate real-time access environment monitoring data;

[0007] Step S3: performing multi-dimensional access risk assessment on the real-time access environment monitoring data using the safe environment benchmark data to obtain multi-dimensional access risk assessment data;

[0008] Step S4: Perform dynamic information security access execution based on the multi-dimensional access risk assessment data to obtain access control execution data; monitor the user's operation behavior in real time based on the access control execution data to achieve information access security control.

[0009] By deploying a dedicated secure environment acquisition network within a pre-authorized secure physical space, the present invention is able to comprehensively and meticulously capture the unique physical and electromagnetic characteristics of the secure environment, generating reliable environmental baseline characteristic data. Encrypting this baseline data using user identity information not only ensures its security but also ties it to the specific secure environment, providing a reliable reference standard for subsequent risk assessments. When a user attempts to initiate an information access request, their terminal device instantly collects real-time access environment monitoring data for their current environment. This proactive, real-time monitoring method can capture instantaneous changes in the user's current environment, providing dynamic environmental information for subsequent security decisions. It also comprehensively considers other factors that affect access security, such as subtle trends in environmental characteristics and the frequency and intensity of abnormal energy fluctuations. This multi-dimensional analysis makes it possible to more accurately determine whether the user's current environment remains secure, thereby effectively identifying potential unauthorized access risks, such as deceptive attempts by attackers to simulate a secure environment. The system implements dynamic information security access control, flexibly adjusting based on real-time environmental security conditions. When assessments indicate a low security risk, users can access information normally. However, when environmental anomalies or increased risk are detected, the system can immediately implement appropriate security measures, such as restricting user access rights, requiring secondary authentication, or even terminating the current access session. This dynamic adjustment mechanism effectively adapts to complex and changing security environments, preventing sensitive operations from occurring in potentially risky environments and minimizing the potential for information leaks. Even after the environment is assessed as secure and user access is permitted, the system continues to monitor and analyze user activity. By detecting whether user operations conform to normal behavior patterns, such as unusual data access frequency or unusual file operations, potential insider threats or maliciously controlled user terminals can be promptly identified. Upon detecting anomalous behavior, the system can immediately issue an alert or implement further security measures, such as logging operations, restricting specific operations, or even locking the user account, creating an additional layer of defense and further enhancing information access security. Therefore, the information access security control method of the present invention can effectively identify and prevent information access in unauthorized physical environments through active environmental benchmark establishment, real-time environmental monitoring, multi-dimensional risk assessment, and dynamic access control and behavior monitoring, and significantly improve the ability to resist location deception, illegal intrusion and potential internal threats.

[0010] Preferably, the step S1 of using a secure environment collection network to perform access environment benchmark monitoring includes:

[0011] Use a spectrum analyzer to continuously collect RF signals for 10 minutes at a sampling rate of 2MS / s. Transmit the collected raw RF signals to the edge computing node through a high-speed data interface to obtain the original RF sampling signals.

[0012] Perform RF fingerprint feature analysis on the original RF sampling signal to obtain a RF fingerprint feature vector. The RF fingerprint feature analysis includes signal harmonic distortion calculation, zero-level crossing count, and carrier frequency offset estimation.

[0013] Using a wireless network card to scan surrounding Bluetooth and Wi-Fi devices every 2 seconds, recording MAC addresses, signal strengths, and device names for 5 minutes, to obtain an original baseline environment network list; wherein the wireless network card supports 2.4GHz and 5GHz frequency bands and has concurrent scanning capabilities;

[0014] The original baseline environment network list is filtered by a preset trusted network threshold to obtain the baseline environment trusted network data;

[0015] Marking a trusted device group in a secure physical space; broadcasting a low-power Bluetooth beacon to the trusted device group, and then generating trusted device electromagnetic signal strength data based on the electromagnetic signal strength received by the electromagnetic signal receiving unit;

[0016] Calculate the average value of the electromagnetic signal strength data of the trusted device and associate the anchor point signals with the trusted device group to obtain the trusted anchor point signal feature data;

[0017] The radio frequency fingerprint feature vector, the baseline environment trusted network data and the trusted anchor point signal feature data are integrated into the environment baseline feature to generate the environment baseline feature data.

[0018] The application continuously collects radio frequency signals at a high sampling rate by using a spectrum analyzer, extracts frequency points and their amplitudes in the radio frequency signal set through fast Fourier transform, and forms a radio frequency fingerprint feature vector with high resolution, which enables the system to perceive subtle changes in radio frequency activities in the environment, effectively distinguish different physical spaces, and preliminarily identify potential malicious signals. The wireless network card periodically scans the surrounding Bluetooth and Wi-Fi devices, records key network information, and constructs an original baseline environment network list. Further filtering is performed through a preset trusted network threshold to eliminate temporary or unstable network interference, obtain more stable and reliable baseline environment trusted network data, and remain vigilant about unknown or suspicious network connections. Through the collection and average value calculation of the signal strength of the secure physical space device, reliable distance and location references are provided for subsequent real-time environment monitoring, effectively improving the judgment accuracy of whether the user is in the preset safe area, and helping to discover behaviors that attempt to cheat by simulating trusted device signals. Integrating the radio frequency fingerprint feature vector, baseline environment trusted network data, and trusted anchor point signal feature data can more comprehensively and robustly describe the unique environment fingerprint of the secure physical space.

[0019] Preferably, the security encryption of the environment baseline feature data by the user identity information in step S2 comprises:

[0020] Hashing the user identity information to generate a user identity hash value;

[0021] Generating a 256-bit random number using a random number generator, and performing XOR operation on the user identity hash value and the random number to obtain a mixed key seed;

[0022] Performing key derivation processing according to the mixed key seed to generate a user-specific encryption key;

[0023] Symmetrically encrypting the environment baseline feature data by the user-specific encryption key to generate encrypted secure environment baseline data;

[0024] Associating the user identity information with the encrypted secure environment baseline data, and then performing secure storage to obtain secure environment baseline data.

[0025] The application can effectively hide the original identity information of the user, prevent the direct exposure of sensitive information, introduce a random number generator to generate a high-strength 256-bit random number, and perform XOR operation on the user identity hash value, so that the generated mixed key seed has higher randomness and security. Using the user-specific key encryption ensures that only the user with the corresponding identity can decrypt and use the reference data after authentication, effectively preventing unauthorized access and leakage. The association of the user's original identity information with the encrypted security environment reference data enables the system to quickly retrieve the corresponding security environment reference data according to the user's identity. At the same time, since the reference data itself has been highly encrypted, even if the storage medium is illegally accessed, the original environment reference information cannot be directly obtained.

[0026] Preferably, the real-time security environment monitoring of the user terminal device based on the access trigger signal in step S2 comprises:

[0027] According to the access trigger signal, the user identity is verified to obtain user identity verification data;

[0028] When the user identity verification data is true, the access trigger signal is responded to, and the current system state of the user terminal device is judged. When the network connection state of the user terminal device is greater than the preset transmission bandwidth threshold and the battery power is greater than 20%, an environment detection preparation ready signal is obtained. Otherwise, an environment detection insufficient signal is generated, and a prompt information is sent to the user;

[0029] According to the environment detection preparation ready signal, the detection task processing is performed to obtain environment detection task configuration data;

[0030] Based on the environment detection task configuration data, the user terminal device is controlled to perform real-time access environment monitoring to generate real-time access environment monitoring data. The real-time access environment monitoring includes radio frequency monitoring and network environment monitoring, and the real-time access environment monitoring data includes real-time radio frequency collection metadata and real-time network environment data.

[0031] The application further responds to the access trigger signal and performs real-time system state evaluation on the user terminal device after identity verification. By judging whether the network connection state of the terminal device meets the preset transmission bandwidth threshold and whether the battery power is sufficient (more than 20%), it can ensure that the subsequent environmental detection process has sufficient resource support, avoiding the situation that the detection data is incomplete or the detection is interrupted due to unstable network or insufficient power. When the terminal device meets the preparation conditions for environmental detection, the system generates an environmental detection preparation ready signal and processes the detection task accordingly. The system can intelligently configure specific parameters and strategies of environmental detection, such as frequency range, sampling duration, network scanning interval, etc., according to the current access request and device state. The system controls the user terminal device to perform real-time access environment monitoring based on environmental detection task configuration data, which can directly obtain the latest information of the environment where the user is currently located, and can obtain environmental feature information from different dimensions, so as to more accurately judge whether the environment where the user is currently located is safe and reliable.

[0032] Preferably, the real-time access environment monitoring data comprises:

[0033] Based on the environmental detection task configuration data, the user terminal device continuously collects radio frequency signals in the access physical environment using the built-in or external radio frequency acquisition module to obtain raw radio frequency sampling data stream;

[0034] The raw radio frequency sampling data stream is preprocessed, and then time stamping is performed to generate radio frequency time domain sampling data;

[0035] The radio frequency time domain sampling data is subjected to fast Fourier transform to obtain real-time radio frequency spectrum data;

[0036] The real-time power spectral density is calculated according to the real-time radio frequency spectrum data;

[0037] The average power value of each sub-band is extracted according to the real-time power spectral density to obtain real-time frequency band power distribution vector data;

[0038] The real-time frequency band power distribution vector data is used to estimate the noise floor and detect significant peaks to generate a real-time significant radio frequency peak feature list;

[0039] The real-time significant radio frequency peak feature list is arranged in frequency order, and radio frequency acquisition metadata is integrated according to the real-time frequency band power distribution vector data to obtain real-time radio frequency acquisition metadata.

[0040] The present invention continuously collects radio frequency signals in the physical environment that the user is currently accessing through a built-in or external radio frequency acquisition module in the user terminal device, and can capture the dynamic changes of the environmental radio frequency signals. The original radio frequency sampling data stream is subjected to necessary data preprocessing, such as filtering, gain calibration, etc., to improve the signal quality, and an accurate timestamp is marked for each sampling point. The introduction of the timestamp enables subsequent analysis to track the temporal characteristics of signal changes. Fast Fourier transform is performed on the radio frequency time domain sampling data, which is conducive to identifying specific radio frequency signal characteristics. The power spectrum density can more accurately reflect the energy intensity of the signal at each frequency. Extracting the average power value of each sub-band in the real-time power spectrum density can more accurately describe the radio frequency energy distribution characteristics in the environment. Noise floor estimation and significant peak detection based on real-time frequency band power distribution vector data can more accurately identify significant radio frequency signal peaks that exceed the noise floor. These peaks often correspond to active radio equipment or potential interference sources in the environment.

[0041] Preferably, the network environment monitoring includes:

[0042] Based on the environment detection task configuration data, the Bluetooth and Wi-Fi API interfaces in the user terminal device are called to perform active scanning for 15 seconds to obtain real-time environment network list data;

[0043] Analyze Bluetooth beacons based on real-time environmental network list data, extract MAC addresses and signal strengths, and record signals greater than -75dBm as valid signals to obtain real-time Bluetooth anchor point data.

[0044] Based on the environment detection task configuration data, the NFC module in the user terminal device is controlled to read the surrounding NFC tags at a frequency of 13.56MHz to obtain the NFC status data of the access device. The NFC status data of the access device includes whether NFC is turned on, whether it is in the polling state, and the device ID of the most recent NFC interaction.

[0045] The real-time environment network list data, real-time Bluetooth anchor point data and access device NFC status data are combined into a network environment to obtain real-time network environment data.

[0046] The application configures data according to an environmental detection task, calls an application programming interface (API) of Bluetooth and Wi-Fi in a user terminal device, performs active scanning for 15 seconds, obtains information of detectable Bluetooth and Wi-Fi devices around, and thus constructs real-time environmental network list data, and the active scanning can timely discover changes of network devices around. The real-time environmental network list data is subjected to Bluetooth beacon analysis, and MAC addresses and signal strengths of Bluetooth devices are extracted. By setting a signal strength threshold (greater than -75 dBm), far distance devices with weak signals are filtered out, and only close distance effective signals with strong signals are reserved, and these close distance Bluetooth devices belong to fixed or trusted devices around the user. Based on the environmental detection task configuration data, a near field communication (NFC) module in the user terminal device is controlled to read NFC tags around at a working frequency of 13.56 MHz, whether specific devices or environmental tags around the user exist and need to be interacted with can be perceived, and this is helpful to judge whether the user is in an expected working or safe area.

[0047] Preferably, step S3 comprises the following steps:

[0048] Step S31: common MAC address identification is performed on the reference environment trusted network data in the security environment reference data and the real-time environment network list data in the real-time network environment data, and then network environment matching degree scoring is performed to obtain network environment matching degree;

[0049] Step S32: single trusted anchor coverage calculation is performed on the real-time Bluetooth anchor data in the real-time network environment data by using the trusted anchor signal feature data in the security environment reference data, and then spatial position trustworthiness evaluation is performed to generate spatial position matching degree;

[0050] Step S33: abnormal interaction behavior analysis is performed according to the access device NFC state data to obtain NFC abnormal behavior data;

[0051] Step S34: NFC security risk assessment is performed on the NFC abnormal behavior data to generate NFC risk assessment data;

[0052] Step S35: intrusion risk detection is performed on the real-time radio frequency collection metadata by using the radio frequency fingerprint feature vector in the security environment reference data to generate intrusion risk assessment data;

[0053] Step S36: multi-dimensional access risk assessment is performed according to the network environment matching degree, the spatial position matching degree, the NFC risk assessment data and the intrusion risk assessment data to obtain multi-dimensional access risk assessment data.

[0054] The application can quantify the similarity between the current network environment and the preset security environment by identifying the MAC addresses commonly existing in the security environment benchmark data and the real-time network environment data. Higher matching degree means that the network composition of the current environment is closer to the security environment, reducing the potential risk of unauthorized network access. By analyzing whether the real-time Bluetooth signal covers the expected trusted anchor point and the degree of coverage, it can more accurately determine whether the user is in the preset safe physical space, effectively preventing the user from accessing in unauthorized areas. For NFC interaction behavior, the system will analyze the abnormal interaction behavior of the access device NFC state data, which helps to identify potential NFC spoofing attacks or security risks caused by user misoperation. The system also uses the pre-stored radio frequency fingerprint feature vector to detect the real-time collected radio frequency metadata for intrusion risk detection, which can detect whether there is abnormal radio frequency signal activity, such as unknown radio equipment or malicious interference signals, so as to assess whether there is a potential physical intrusion or radio frequency attack risk in the current environment.

[0055] Preferably, the intrusion risk detection of the real-time radio frequency collection metadata by the radio frequency fingerprint feature vector in the security environment benchmark data comprises:

[0056] According to the frequency spectrum difference comparison between the real-time frequency band power distribution vector data in the real-time radio frequency collection metadata and the radio frequency fingerprint feature vector, a frequency spectrum difference measure value is generated;

[0057] The frequency spectrum difference measure value is subjected to time sequence stability analysis to obtain a frequency band fluctuation stability coefficient;

[0058] Based on the frequency band fluctuation stability coefficient, the real-time significant radio frequency peak value feature list in the real-time radio frequency collection metadata is subjected to abnormal high-power frequency point detection to obtain abnormal frequency point detection data;

[0059] The abnormal frequency point detection data is subjected to known interference source matching by a preset interference signal feature library, and when it cannot be identified as a known interference source, a potential intrusion signal is determined;

[0060] The potential intrusion signal is subjected to abnormal peak value correlation analysis, and then intrusion type identification is performed to generate intrusion type risk assessment data.

[0061] The application can quantize the deviation degree of the overall radio frequency spectrum of the current environment from the safe environment benchmark spectrum by comparing the real-time frequency band power distribution vector data with the pre-established radio frequency fingerprint feature vector, and preliminarily judge whether there is abnormal radio frequency activity. By analyzing the change trend of the spectrum difference over time, it can be judged whether the radio frequency characteristics of the current environment are stable. Severe fluctuations reveal that the environment has undergone unexpected changes or there is an interference source. By identifying the frequency points exceeding the normal power range, the strong signal interference source or potential illegal emission equipment existing in the environment can be quickly located. The preset interference signal feature library is used to match the detected abnormal frequency points. If it can be identified as a known, non-threatening interference source (such as normal Bluetooth or Wi-Fi signal), the risk is excluded. For abnormal frequency points that cannot be identified as known interference sources, they are determined as potential intrusion signals and need to be analyzed more deeply. By analyzing the frequency, bandwidth, power, modulation mode and other characteristics of the abnormal signal, and comparing them with known various intrusion signal types (such as malicious interference, illegal monitoring equipment, etc.), the nature and level of potential threats can be more accurately judged.

[0062] Preferably, step S4 comprises the following steps:

[0063] Step S41: calculating the threat probability distribution according to the multi-dimensional access risk assessment data to generate the current access risk level of the user;

[0064] Step S42: based on the current access risk level of the user and the multi-dimensional access risk assessment data, searching the corresponding access control strategy from the pre-defined risk level-access control mapping table to obtain an initial access control strategy;

[0065] Step S43: extracting specific permission items according to the initial access control strategy to obtain a dynamic permission item list;

[0066] Step S44: associating the dynamic permission item list with the access request and updating the user access session state;

[0067] Step S45: performing information security access on the user based on the user access session state to obtain access control execution data;

[0068] Step S46: monitoring the user's operation behavior in real time during the information access process based on the access control execution data, and when the user has irregular operation behavior, the operation is immediately blocked, the corresponding dynamic permission item is deleted, and the user access session state is reinitialized to realize information access security control.

[0069] The present application can clearly reflect the security state of the current environment based on threat probability distribution calculation of multi-dimensional access risk assessment data. According to the calculated current access risk level of the user and the detailed multi-dimensional access risk assessment data, the user of different risk levels is ensured to have initial access permissions matching the risk level, and the risk-based preliminary permission allocation is realized. According to the initial access control strategy, the operation currently allowed to be performed by the user is accurately determined, and the minimization and fine management of the permissions are realized. During the information access process, the system will perform specific security access control based on the access session state of the user, such as allowing reading of specific files, prohibiting modification of sensitive data, etc. This dynamic permission-based access control can effectively limit the operation range of the user and reduce the security risks caused by illegal or unauthorized operations. During the information access process, the operation behavior of the user is monitored in real time, and once it is detected that the user has violated the operation behavior, the system will immediately block the operation and delete the corresponding dynamic permission item, and reinitialize the access session state of the user. This real-time violation behavior monitoring and disposal mechanism can timely discover and prevent potential security threats, and even after the user passes the preliminary risk assessment and obtains access permissions, it can continuously ensure the security of the information system, forming a dynamic security barrier. Through this active monitoring and response, the system can effectively prevent security risks caused by internal threats and user misoperations, and ensure the safety and controllability of the information access process.

[0070] Preferably, the present application also provides an information access security control system for executing the information access security control method as described above, which comprises:

[0071] An environment reference collection module is configured to authorize a safe physical space in a target access environment, to deploy a safe environment collection network in the safe physical space, to monitor the environment reference by using the safe environment collection network, and to obtain environment reference feature data. The safe environment collection network comprises a spectrum analyzer, a wireless network card, and an electromagnetic signal receiving unit.

[0072] An access environment monitoring module is configured to obtain user identity information, to securely encrypt the environment reference feature data by using the user identity information, to obtain safe environment reference data, to obtain an access trigger signal by initiating an information access request by using a user terminal device, and to generate real-time access environment monitoring data by using the user terminal device based on the access trigger signal.

[0073] A multi-dimensional risk assessment module is configured to perform multi-dimensional access risk assessment on the real-time access environment monitoring data by using the safe environment reference data, and to obtain multi-dimensional access risk assessment data.

[0074] The dynamic access control module is used for performing dynamic information security access according to the multi-dimensional access risk assessment data, and access control execution data is obtained; and the operation behavior of the user is monitored in real time based on the access control execution data, so as to realize information access security control. BRIEF DESCRIPTION OF DRAWINGS

[0075] Figure 1 A step flow diagram of the information access security control method of the present application is shown in the figure.

[0076] Figure 2 A detailed implementation step flow diagram of step S3 in the figure. Figure 1

[0077] The implementation, functional features and advantages of the present application will be further described with reference to the embodiments and the accompanying drawings. DETAILED DESCRIPTION

[0078] The technical method of the present application will be described clearly and completely below with reference to the accompanying drawings. Obviously, the described embodiments are part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor fall within the protection scope of the present application.

[0079] In addition, the accompanying drawings are only schematic diagrams of the present application, and are not necessarily drawn to scale. The same reference signs in the drawings represent the same or similar parts, and thus repeated descriptions thereof will be omitted. Some block diagrams shown in the drawings are functional entities, and do not necessarily correspond to physically or logically independent entities. The functional entities can be implemented in the form of software, or in one or more hardware modules or integrated circuits, or in different network and / or processor methods and / or microcontroller methods.

[0080] It should be understood that although the terms "first", "second" and the like can be used herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another. For example, without departing from the scope of the exemplary embodiments, a first element can be referred to as a second element, and similarly a second element can be referred to as a first element. The term "and / or" as used herein includes any and all combinations of one or more of the associated listed items.

[0081] To achieve the above-mentioned purpose, please refer to Figures 1 to 2 The present application provides an information access security control method, comprising the following steps:

[0082] ​Step S1: a security physical space authorization is performed on a target access environment to obtain a security physical space; a security environment collection network is deployed in the security physical space; the security environment collection network is used to perform access environment benchmark monitoring to obtain environment benchmark characteristic data; the security environment collection network comprises a spectrum analyzer, a wireless network card and an electromagnetic signal receiving unit;

[0083] Step S2: user identity information is obtained; the environment benchmark characteristic data is securely encrypted by using the user identity information to obtain security environment benchmark data; an information access request is initiated by a user through a user terminal device to obtain an access trigger signal; real-time access environment monitoring is performed by using the user terminal device based on the access trigger signal to generate real-time access environment monitoring data;

[0084] Step S3: multi-dimensional access risk assessment data is obtained by performing multi-dimensional access risk assessment on the real-time access environment monitoring data by using the security environment benchmark data;

[0085] Step S4: access control execution data is obtained by performing dynamic information security access according to the multi-dimensional access risk assessment data; the operation behavior of the user is monitored in real time based on the access control execution data to realize information access security control.

[0086] In the embodiment of the application, the information access security control method comprises the following steps:

[0087] Step S1: a security physical space authorization is performed on a target access environment to obtain a security physical space; a security environment collection network is deployed in the security physical space; the security environment collection network is used to perform access environment benchmark monitoring to obtain environment benchmark characteristic data; the security environment collection network comprises a spectrum analyzer, a wireless network card and an electromagnetic signal receiving unit;

[0088] In the embodiment of the present application, for a specific area that needs to implement information access security control, such as a server room, a confidential file storage room or a confidential meeting room, a user draws the physical boundary of the area according to the organization's security policy and physical security standard. The physical boundary can be clearly defined by means such as physical fences, access control systems, and monitoring camera coverage. Then, the administrator creates a security physical space object corresponding to the physical area in the security management system, and assigns a unique identifier to the security physical space. For the security physical space, for example, a security environment acquisition network is deployed inside the electronic file reading room. The network includes a spectrum analyzer with a fixed sampling rate of 2MS / s, which continuously collects indoor radio frequency signals for 600 seconds to generate an original radio frequency sampling signal file. The original radio frequency sampling signal is subjected to fast Fourier transform to extract the top 20 frequency points with the largest amplitude and their corresponding amplitude values, forming a radio frequency fingerprint feature vector, which is stored in the form of a list, with each element containing the exact frequency value and amplitude value. At the same time, a computer equipped with an Intel AX200 wireless network card is used to scan the surrounding Bluetooth and Wi-Fi devices at a fixed interval of 2 seconds for 300 seconds, recording the MAC addresses, received signal strength indicators (RSSI) and broadcast device names of all detected devices, forming an original baseline environment network list. The original list is filtered by a pre-set trusted network MAC address list, retaining only the records of devices whose MAC addresses match the trusted list, to obtain baseline environment trusted network data. Three fixed trusted device groups are pre-set in the reading room, each containing three low-power Bluetooth beacons with the same broadcast frequency and power, broadcasting unique device identifiers. A handheld spectrum analyzer is used with a directional antenna to receive the Bluetooth signals broadcast by each trusted device group at five pre-set anchor point locations in the reading room, recording the signal strength (RSSI value) of each beacon at each anchor point location. The signal strength received by each trusted device group at all anchor point locations is averaged, and the average value is associated with the corresponding trusted device group identifier and anchor point location to generate trusted anchor point signal feature data, which is stored as a table. Finally, the radio frequency fingerprint feature vector, baseline environment trusted network data and trusted anchor point signal feature data are integrated into an environment baseline feature data file.

[0089] Step S2: obtaining user identity information; securely encrypting the environment baseline feature data based on the user identity information to obtain secure environment baseline data; the user initiating an information access request through a user terminal device to obtain an access trigger signal; and performing real-time access environment monitoring based on the access trigger signal using the user terminal device to generate real-time access environment monitoring data;

[0090] In the embodiment of the present application, the user identity information is obtained by using the work number provided by the user who attempts to enter the reading room to consult files. The work number is hashed by using the SHA-256 algorithm to generate a 256-bit user identity hash value. A 256-bit random number is generated by calling a cryptographically secure pseudo-random number generator, and the user identity hash value is subjected to bitwise XOR operation with the random number to obtain a 256-bit mixed key seed. The mixed key seed is processed by using the HMAC-SHA-256 key derivation function with a preset fixed salt value as an auxiliary to derive a 256-bit user-specific AES-256 encryption key. The Galois / Counter Mode (GCM) of the AES-256 algorithm is selected, and a random 128-bit random number is generated. The user-specific encryption key derived and the random number generated are used to symmetrically encrypt the aforementioned generated environment reference feature data JSON file to generate encrypted secure environment reference data, which includes ciphertext, random number, and authentication tag. The work number of the user is associated with the encrypted secure environment reference data (ciphertext, random number, and authentication tag) in the database and is securely stored to form the final secure environment reference data. When the user holding the work card swipes the card at the entrance of the reading room, the system generates an information access request to trigger an access trigger signal. After the user terminal device (for example, the user's tablet computer, which is pre-installed with a secure access control application) receives the signal, the user is first prompted to perform identity verification by fingerprint. After the user successfully completes the fingerprint verification, the user terminal device sends a verification success message to the background identity verification server, and the server compares the fingerprint features with the pre-registered template. After verification, the user identity verification data is true. The user terminal device then checks the network connection state of itself to obtain the current Wi-Fi downlink transmission rate (for example, by using an operating system API). At the same time, the current battery percentage of the device is obtained (for example, by using an operating system API). If the Wi-Fi downlink transmission rate is greater than the preset 10 Mbps and the battery percentage is greater than 20%, the user terminal device generates an environment detection ready signal. Otherwise, an environment detection insufficient signal is generated, and a prompt message "current network is unstable or battery is insufficient, please try again later" is displayed on the tablet computer screen. After receiving the environment detection ready signal, the background system sends environment detection task configuration data to the user terminal device. The data specifies the sampling frequency of the radio frequency monitoring as 2 MS / s, the duration as 5 seconds, and the scanning frequency band as the 2.4 GHz ISM frequency band in the JSON format; the network environment monitoring scans Wi-Fi and Bluetooth with a scanning interval of 2 seconds to record the MAC address, RSSI, and device name; and the NFC module is instructed to read the NFC tag at a frequency of 13.56 MHz. According to the configuration data, the user terminal device calls the built-in radio frequency acquisition module to continuously acquire the radio frequency signal of the 2.4 GHz frequency band for 5 seconds to obtain the original radio frequency sample data stream.The data stream is preprocessed by removing the direct current component and amplitude normalization, and a precise timestamp is added to each sampling point to generate radio frequency time domain sampling data. Fast Fourier transform is performed on the radio frequency time domain sampling data to obtain real-time radio frequency spectrum data, and the real-time power spectrum density is calculated. According to the preset frequency band division scheme, the average power value of each sub-frequency band is calculated to obtain the real-time frequency band power distribution vector data. Noise floor estimation and significant peak detection are performed to generate a real-time significant radio frequency peak feature list, which is arranged in frequency order. The list is integrated with real-time frequency band power distribution vector data, acquisition timestamp, sampling frequency and duration, etc. into real-time radio frequency acquisition metadata. At the same time, the user terminal device calls the API interface of Bluetooth and Wi-Fi for active scanning, lasting for 15 seconds, and records the MAC address, RSSI and device name of all devices scanned to obtain real-time environmental network list data. Analyze the Bluetooth devices in the real-time environmental network list, extract the MAC address and signal strength, and when the signal strength is greater than -75dBm and the MAC address matches the preset reading room beacon MAC address list, record it as real-time Bluetooth anchor point data. The user terminal device enables the NFC module to poll the surrounding NFC tags at a frequency of 13.56MHz, obtains whether the NFC is on, whether it is in polling state, and the device ID of the last NFC interaction, and obtains the access device NFC state data. Finally, the real-time environmental network list data, real-time Bluetooth anchor point data and access device NFC state data are combined to obtain real-time network environment data.

[0091] Step S3: Perform multi-dimensional access risk assessment on the real-time access environment monitoring data by the security environment benchmark data to obtain multi-dimensional access risk assessment data;

[0092] In the embodiment of the present application, after receiving the real-time access environment monitoring data sent by the user terminal device, the system first extracts the security environment reference data associated with the current user ID (which needs to be decrypted using the user's exclusive decryption key, but in this risk assessment stage, we directly use the unencrypted reference data for comparison to illustrate the principle). By comparing the reference environment trusted network data and the real-time environment network list data, identifying the common MAC addresses, calculating the ratio of the number of matched trusted devices to the total number of reference trusted devices, and obtaining the network environment matching degree. Using the average signal strength of the beacons recorded in the reference environment trusted anchor signal feature data at different locations, comparing the beacons and their signal strengths detected in the real-time Bluetooth anchor data, calculating the coverage rate of a single trusted anchor, and performing trilateration to estimate the current location of the user terminal device, determining whether it is located within the predetermined safe area of the reading room, generating a spatial position matching degree (for example, if it is within the safe area, the matching degree is high, otherwise it is low). Analyze the access device NFC state data, if the NFC is in an unexpected open or polling state, or interacts with an unknown NFC tag, generate NFC abnormal behavior data containing the abnormal type and the involved device ID. According to the NFC abnormal behavior data, match the pre-defined risk rules, assess the risk level of NFC interaction, and generate NFC risk assessment data (for example, high risk indicates detection of interaction with an unknown high-privilege tag). Compare the real-time frequency band power distribution vector data in the real-time radio frequency collection metadata with the reference radio frequency fingerprint feature vector, and calculate the frequency spectrum difference measure value. Analyze the time sequence stability of the measure value to obtain the frequency band fluctuation stability coefficient. Based on the coefficient, perform abnormal high-power frequency point detection on the real-time significant radio frequency peak feature list to obtain abnormal frequency point data. Match the abnormal frequency point data with the preset interference signal feature library, if it cannot be identified as a known interference source, it is determined as a potential intrusion signal. Analyze the frequency, bandwidth, and power characteristics of the potential intrusion signal, identify the intrusion type, and generate intrusion type risk assessment data containing the risk level. Finally, according to the preset weight, the network environment matching degree, the spatial position matching degree, the NFC risk assessment data, and the intrusion risk assessment data are weighted and calculated to obtain a multi-dimensional access risk score.

[0093] Step S4: performing dynamic information security access according to the multi-dimensional access risk assessment data to obtain access control execution data; monitoring the user's operation behavior in real time based on the access control execution data to realize information access security control.

[0094] In the embodiment of the present application, according to the multi-dimensional access risk assessment data (for example, “medium risk”) generated in step S3, the system searches for a predefined risk level-access control mapping table. Assuming that the initial access control policy corresponding to the medium risk level is “allowing to read non-top secret level files, prohibiting file download and copy, and limiting network communication”. According to the initial policy, the permission management system is queried to extract the user's “read” permission for non-top secret level electronic files in the reading room, but not to grant “modify”, “delete”, “copy”, “download” and other permissions, and at the same time, limit the direct connection of the terminal device with the external network, and only allow limited communication through the controlled internal server. These specific permission operations are added to the dynamic permission item list of the user. Each file reading request of the user is compared with the dynamic permission item list, and only the operation conforming to the list is allowed to be executed. The access session state of the user is updated, and the currently effective dynamic permission item is recorded. In the process of the user reading the file, the system monitors the operation behavior of the user in real time. For example, if the user attempts to click the “download” button or use the copy and paste function, the monitoring module will detect that the operation does not conform to the restriction in the dynamic permission item list, and immediately block the operation and pop up a warning message. If the user attempts to establish a network connection with an external IP address, it will also be prevented by the firewall strategy. If the monitoring system detects that the user attempts to bypass the permission control, performs frequent illegal operations, or triggers a higher level of security alarm (for example, attempts to access top secret files), the system will immediately block the current operation of the user, delete all dynamic permission items in the session, and force the user to re-authenticate and perform environment risk assessment to achieve more stringent information access security control.

[0095] Preferably, the step S1 comprises:

[0096] The radio frequency signal is continuously collected for 10 minutes by using a spectrum analyzer with a sampling rate of 2MS / s, and the collected original radio frequency signal is transmitted to the edge computing node through a high-speed data interface to obtain an original radio frequency sampling signal;

[0097] The original radio frequency sampling signal is subjected to radio frequency fingerprint feature analysis to obtain a radio frequency fingerprint feature vector; wherein the radio frequency fingerprint feature analysis includes signal harmonic distortion calculation, signal zero crossing frequency statistical calculation, and carrier frequency offset estimation;

[0098] The wireless network card is used to scan the surrounding Bluetooth and Wi-Fi devices every 2 seconds, record the MAC address, signal strength, and device name, and continuously collect for 5 minutes to obtain an original baseline environment network list;

[0099] The original baseline environment network list is subjected to trusted network filtering through a preset trusted network threshold to obtain baseline environment trusted network data;

[0100] The security physical space marks a trusted device group; the trusted device group carries out low-power Bluetooth beacon broadcasting, and then receives device electromagnetic signal strength according to the electromagnetic signal receiving unit to generate trusted device electromagnetic signal strength data;

[0101] The trusted device electromagnetic signal strength data is subjected to average value calculation, and anchor point signal correlation is carried out according to the trusted device group to obtain trusted anchor point signal feature data;

[0102] The radio frequency fingerprint feature vector, the benchmark environment trusted network data and the trusted anchor point signal feature data are subjected to environment benchmark feature integration to generate environment benchmark feature data.

[0103] In the embodiment of the present application, the model of the spectrum analyzer is Agilent N9020B, which is configured to have a real-time sampling rate of 2MS / s or higher. The spectrum analyzer is started, and the center frequency is set to cover the common wireless communication frequency bands (such as 2.4GHz and 5GHz ISM bands) in the target secure physical space, the bandwidth is set to a range sufficient to capture the target signal, and the resolution bandwidth is set to 10kHz to balance the frequency resolution and scanning speed. The spectrum analyzer is operated in continuous scanning mode, and the sampling duration is accurately set to 600 seconds. The time-domain signal is analyzed by using the built-in fast Fourier transform (FFT) algorithm module to obtain the frequency-domain signal. The number of points of the FFT operation is determined according to the sampling rate and the sampling time to ensure that the frequency resolution meets the requirements. The amplitude spectrum of the frequency-domain signal is analyzed, and the 20 frequency points with the largest amplitudes are automatically identified by using a preset peak search algorithm. The accurate frequency values and corresponding amplitude values of the 20 frequency points are recorded. The wireless network scanning tool provided by the operating system or the third-party network analysis tool (such as Wireshark) is used, and the wireless network card is set to the promiscuous mode. The wireless network card is triggered to scan the surrounding wireless signals at a fixed interval of 2 seconds. The MAC address, received signal strength indication (RSSI) value and broadcast device name (if any) of all Bluetooth devices detected in each scanning operation are recorded. Similarly, the MAC address (BSSID), RSSI value and service set identifier (SSID) of all Wi-Fi access points (APs) scanned are recorded. This scanning process lasts for 300 seconds to form an original baseline environment network list containing multiple scanning results, and each record in the list contains a scanning timestamp, a device type (Bluetooth / Wi-Fi), a MAC address, a signal strength and a device name (if any). The system is pre-configured with a trusted network threshold, which includes a series of MAC address prefixes or complete MAC addresses of Bluetooth and Wi-Fi devices considered to be legally present in the target secure physical space. For each record in the original baseline environment network list, the MAC address is extracted and compared with the preset trusted threshold. If the MAC address matches any item in the trusted threshold, the record is determined as trusted network data. A new list is created to contain only the network device records determined as trusted, and the list is the baseline environment trusted network data. A number of fixed positions in the target secure physical space are marked as trusted device groups. At least three beacon devices supporting low-power Bluetooth broadcasting function are deployed in each trusted device group, and the beacon devices are selected from the Texas Instruments CC2640R2F model. These beacon devices are configured to periodically broadcast low-power Bluetooth signals containing unique identifiers at the same broadcast frequency and power.In the environmental benchmark monitoring phase, a portable electromagnetic signal receiving unit, such as a handheld spectrum analyzer, is used in conjunction with a directional antenna to receive low-power Bluetooth signals broadcast by each trusted device group at several pre-set positions (as anchor point positions) within the target secure physical space. The received signal strength (RSSI) values from each beacon device in each trusted device group are recorded at each anchor point position. For each trusted device group, the signal strength values received at all anchor point positions are arithmetically averaged, and each trusted device group is associated with its corresponding average electromagnetic signal strength data and anchor point positions to generate trusted anchor point signal feature data. These three parts of data are stored in a JSON file, where the radio frequency fingerprint feature vector is stored as an array, the benchmark environmental trusted network data is stored as a list, each element in the list is a dictionary containing the MAC address, RSSI, and device name, and the trusted anchor point signal feature data is stored as a dictionary with the MAC address of the beacon device as the key and the corresponding average RSSI value as the value.

[0104] Especially importantly, the radio frequency fingerprint feature analysis specifically includes:

[0105] The original radio frequency sampling signal is subjected to sampling frame segmentation to obtain radio frequency sampling frame data;

[0106] The radio frequency instantaneous amplitude, phase, and frequency are calculated from the radio frequency sampling frame data to obtain an instantaneous radio frequency feature data frame;

[0107] Signal harmonic distortion and signal intermodulation distortion analysis are performed on the radio frequency sampling frame data to obtain nonlinear signal feature data;

[0108] The number of times the signal passes through zero is calculated from the radio frequency sampling frame data to obtain a radio frequency signal zero-crossing rate, and the slopes and times of the rising and falling edges of the signal are analyzed from the radio frequency sampling frame data to obtain signal rise-fall times;

[0109] Carrier frequency offset estimation is performed on the radio frequency sampling frame data to obtain carrier frequency offset data;

[0110] The instantaneous radio frequency feature data frame, nonlinear signal feature data, radio frequency signal zero-crossing rate, signal rise-fall times, and carrier frequency offset data are subjected to cross-frame statistics to obtain a radio frequency fingerprint feature vector.

[0111] In the embodiment of the present application, for each frame of radio frequency sampling frame data, the instantaneous amplitude, phase and frequency of the radio frequency signal are calculated using Hilbert transform. The calculated instantaneous amplitude, phase and frequency are stored in a vector to form a frame of instantaneous radio frequency feature data. Fast Fourier transform (FFT) is performed on each frame of radio frequency sampling frame data to obtain the frequency spectrum of the signal. The amplitudes and phases of the harmonic components in the frequency spectrum are analyzed to calculate the harmonic distortion of the signal, such as total harmonic distortion (THD). At the same time, the amplitudes and phases of the intermodulation product components in the frequency spectrum are analyzed to calculate the intermodulation product distortion of the signal, such as third-order intermodulation intercept point (IP3). For each frame of radio frequency sampling frame data, the total number of zero-crossing events occurring in a radio frequency sampling frame is counted, and then the number is divided by the time length of the frame to obtain the zero-crossing rate of the radio frequency signal of the frame, which is in the unit of times per second. The envelope of the signal is identified in each radio frequency sampling frame. The envelope can be obtained by calculating the instantaneous amplitude of the signal. Then, local maxima and local minima are found in the envelope, which correspond to the peak and valley values of the signal. The rising edge is defined as the process in which the signal amplitude rises from the valley value to the peak value, and the falling edge is defined as the process in which the signal amplitude falls from the peak value to the valley value. The time length (the time experienced from the valley value to the peak value) and the amplitude change of each rising edge are measured, and the average slope of the rising edge (amplitude change / time length) is calculated. Similarly, the time length and the amplitude change of each falling edge are measured, and the average slope of the falling edge is calculated. For each frame of radio frequency sampling frame data, the carrier frequency offset of the signal is estimated using a frequency offset estimation algorithm, such as an FFT-based frequency offset estimation algorithm or a phase-locked loop-based frequency offset estimation algorithm. The estimated carrier frequency offset value is stored in the carrier frequency offset data. The frame-to-frame statistics of the instantaneous radio frequency feature data frame, the nonlinear signal feature data, the radio frequency signal zero-crossing rate, the signal rise-fall time and the carrier frequency offset data of all frames are performed. For example, the mean, variance, maximum value, minimum value and other statistical characteristics of the amplitudes, phases and frequencies in each frame of instantaneous radio frequency feature data frame are calculated; the mean and variance of the nonlinear signal feature data are calculated; the mean and variance of the radio frequency signal zero-crossing rate, the signal rise-fall time and the carrier frequency offset are calculated. All the calculated statistical characteristics are combined into a vector, i.e., a radio frequency fingerprint feature vector.

[0112] Preferably, the security encryption of the environment reference feature data by the user identity information in step S2 comprises:

[0113] hashing the user identity information to generate a user identity hash value;

[0114] generating a 256-bit random number by using a random number generator, and performing XOR operation on the user identity hash value and the random number to obtain a mixed key seed;

[0115] According to the mixed key seed, a key derivation process is performed to generate a user-specific encryption key;

[0116] The environment reference feature data is symmetrically encrypted by the user-specific encryption key to generate encrypted secure environment reference data;

[0117] The user identity information is associated with the encrypted secure environment reference data, and then stored securely to obtain secure environment reference data.

[0118] In the embodiment of the present application, the original identity information provided by the user for information access control is obtained, which can include user ID, employee number or other strings capable of uniquely identifying the user identity. A one-way encryption operation is performed on the original identity information by using a hash algorithm conforming to the SHA-256 standard. The specific operation is to take the original identity information as the input of the SHA-256 algorithm, generate a fixed-length hash value of 256 bits through a series of complex bit operations (including XOR, AND, shift, addition, etc.) and table lookup operations. The hash value is irreversible, that is, the original identity information cannot be deduced from the hash value, and the same output is always generated for the same input, and the output will be significantly different for slight input changes. A length-256-bit random number is generated by calling a system-built cryptographically secure pseudo-random number generator (CSPRNG), such as a hardware-based random number generator or a generator implemented by a strictly cryptographically analyzed algorithm. The random number is represented in binary form. The user identity hash value (256-bit binary form) generated in the previous step is obtained. The 256-bit user identity hash value and the generated 256-bit random number are subjected to a bitwise XOR operation. The rule of the XOR operation is: if the two input bits are the same, the output is 0; if the two input bits are different, the output is 1. After the bitwise XOR operation, a new 256-bit binary number is obtained, which is used as the mixed key seed. A fixed salt value (salt) is defined, which is a pre-set random string, used to increase the security of key derivation and prevent rainbow table attacks. The salt value and the mixed key seed are used as the input of the HMAC-SHA-256 algorithm. The HMAC-SHA-256 algorithm generates a message authentication code (MAC) by using the SHA-256 hash function and the key (here, the mixed key seed). The first 256 bits of the MAC are used as the derived user-specific encryption key. The iteration number of the key derivation function is set to one to meet the current security requirements. The final derived user-specific encryption key is a 256-bit binary string used for symmetric encryption algorithms. The derived 256-bit user-specific encryption key is used as the key of the AES-256 algorithm. The cipher block chaining (CBC) mode or the Galois / counter mode (GCM) is selected as the running mode of the AES, and a random initialization vector (IV) (for CBC mode) or a random nonce (for GCM mode) is generated. The environment reference feature data is encrypted by using the AES-256 encryption algorithm with the user-specific encryption key and the generated IV / nonce. The original identity information of the user is associated with the encrypted secure environment reference data. The association method can be to create a record in the database, which contains the user identity information as the index and the corresponding encrypted secure environment reference data (ciphertext, IV / nonce, authentication tag).Alternatively, the user's identity information can be stored as part of the file name for the encrypted data file. A storage medium or database system with data encryption function is selected for secure storage, ensuring that even if the storage medium is accessed unauthorized, the original environmental reference feature data cannot be directly obtained, because the data is stored in encrypted form, and only with the correct user-specific decryption key can be decrypted. The correspondence between user identity information and encrypted data needs to be recorded during storage, so that in the subsequent information access control process, the user's corresponding encrypted secure environmental reference data can be retrieved according to the user's identity.

[0119] Preferably, the real-time secure environment monitoring of the user terminal device based on the access trigger signal in step S2 comprises:

[0120] User identity authentication according to the access trigger signal to obtain user identity authentication data;

[0121] When the user identity authentication data is true, respond to the access trigger signal to determine the current system state of the user terminal device, and when the network connection state of the user terminal device is greater than the preset transmission bandwidth threshold and the battery power is greater than 20%, an environmental detection preparation ready signal is obtained; otherwise, an environmental detection capability insufficient signal is generated, and a prompt information is sent to the user;

[0122] Performing detection task processing according to the environmental detection preparation ready signal to obtain environmental detection task configuration data;

[0123] Controlling the user terminal device to perform real-time access environment monitoring based on the environmental detection task configuration data to generate real-time access environment monitoring data; the real-time access environment monitoring includes radio frequency monitoring and network environment monitoring, and the real-time access environment monitoring data includes real-time radio frequency collection metadata and real-time network environment data.

[0124] In the embodiments of the present application, when a user attempts to access a protected information resource, the system will generate an access trigger signal. After the user terminal device receives the signal, it prompts the user to input identity credentials, which can include a user ID and corresponding password, biometric information (such as fingerprint or facial recognition data), or a one-time password generated by a security token. After the user inputs or provides the identity credentials on the terminal device, the terminal device sends the credentials to the identity verification server through a secure channel. After the identity verification server receives the user credentials, it first retrieves the stored user registration information, and then performs the corresponding verification operation according to the type of the received credentials. For example, for password verification, the server will compare the received password with the stored hash value; for biometric verification, the server will extract features from the received biometric data and match them with the registered template; for token verification, the server will verify whether the received one-time password is consistent with the valid password generated within the current time window. The verification result generates user identity verification data, which is a Boolean value indicating whether the user identity verification is successful or failed. When the user identity verification data is true, the system responds to the access trigger signal and initiates a check of the current system state of the user terminal device. First, the current network connection state of the user terminal device is detected, specifically by obtaining the type of the current network connection (such as Wi-Fi, cellular data) and the real-time uplink and downlink transmission rates through the API provided by the operating system. The obtained real-time downlink transmission rate is compared with the preset transmission bandwidth threshold (such as 10 Mbps). At the same time, the current battery percentage of the user terminal device is obtained through the operating system API and compared with the preset battery percentage threshold (such as 20%). Only when the downlink transmission rate of the network connection of the user terminal device is greater than or equal to the preset transmission bandwidth threshold and the battery percentage is greater than the preset battery percentage threshold, the system will generate an environment probe ready signal, indicating that the terminal device has the ability to perform the environment probe task. If either condition is not met, an environment probe insufficient signal is generated, and a prompt message is sent to the user through the display interface of the user terminal device, informing the user that the current network connection is unstable or the battery is too low, and suggesting the user to connect to a more stable network or charge before attempting access again. After receiving the environment probe ready signal, the system will generate environment probe task configuration data for guiding the user terminal device to perform real-time environment monitoring. The configuration data contains the following information: the sampling frequency of radio frequency monitoring (such as 2 MS / s), the duration of radio frequency monitoring (such as 5 seconds), the frequency range that needs to be scanned for radio frequency monitoring (such as the 2.4 GHz ISM frequency band), the type of wireless network that needs to be scanned for network environment monitoring (such as Wi-Fi and Bluetooth), the interval time for network scanning (such as scanning every 2 seconds), and the network information fields that need to be recorded (such as MAC address, signal strength, device name).The configuration data is transmitted to the user terminal device in the form of structured data, such as JSON or XML. After the user terminal device receives the environment detection task configuration data, it starts real-time access environment monitoring according to the configuration information. For radio frequency monitoring, the terminal device calls its built-in wireless communication module, and collects the radio frequency signals of the surrounding environment according to the sampling frequency and duration specified in the configuration data, and converts the collected analog signals into digital signals and stores them as real-time radio frequency sampling data. Then, the real-time radio frequency sampling data is subjected to fast Fourier transform processing to extract the frequency spectrum information, and the current timestamp and frequency spectrum data are recorded to form real-time radio frequency collection metadata. For network environment monitoring, the terminal device uses its Wi-Fi and Bluetooth modules to scan for Wi-Fi access points and Bluetooth devices around it according to the scanning interval specified in the configuration data, and records the MAC address (BSSID), signal strength (RSSI), and service set identifier (SSID) of each scanned Wi-Fi access point, as well as the MAC address, signal strength (RSSI), and device name (if available) of each scanned Bluetooth device. Each scan result is accompanied by a current timestamp, and the results of multiple scans are aggregated to form real-time network environment data.

[0125] Preferably, the real-time access environment monitoring data includes:

[0126] Based on the environment detection task configuration data, the user terminal device continuously collects radio frequency signals in the access physical environment using the built-in or external radio frequency collection module to obtain a raw radio frequency sampling data stream;

[0127] The raw radio frequency sampling data stream is preprocessed, and then time-stamped to generate radio frequency time-domain sampling data;

[0128] The radio frequency time-domain sampling data is subjected to fast Fourier transform to obtain real-time radio frequency spectrum data;

[0129] The real-time power spectral density is calculated based on the real-time radio frequency spectrum data;

[0130] The average power value of each sub-band is extracted based on the real-time power spectral density to obtain real-time frequency band power distribution vector data;

[0131] Noise floor estimation and significant peak detection are performed based on the real-time frequency band power distribution vector data to generate a real-time significant radio frequency peak feature list;

[0132] The real-time significant radio frequency peak feature list is arranged in frequency order, and the real-time frequency band power distribution vector data is used to integrate the radio frequency collection metadata to obtain real-time radio frequency collection metadata.

[0133] In the embodiment of the present application, the user terminal device starts its built-in or USB interface connected radio frequency acquisition module according to the received environmental detection task configuration data. The radio frequency acquisition module has the ability to continuously collect signals in the specified frequency range with the configured sampling frequency (for example, 2MS / s). The collection process lasts for a preset length of time (for example, 5 seconds). The radio frequency acquisition module converts the received analog radio frequency signals into discrete digital sampling points, forming a continuous raw radio frequency sampling data stream. The data stream contains complex sampling values arranged in time sequence, and each sampling value represents the amplitude and phase information of the received signal at a specific time. The raw radio frequency sampling data stream is subjected to preliminary data preprocessing. The preprocessing operation includes removing the direct current component, amplitude normalization, etc., aiming to eliminate some interference factors in the collection process and improve the accuracy of subsequent signal processing. For example, the average value of the raw sampling data is calculated, and the average value is subtracted from each sampling value to remove the direct current bias. After completing the data preprocessing, an accurate time stamp is added to each sampling point in the raw radio frequency sampling data stream. The time stamp records the specific time when each sampling point is collected, with a time accuracy of microseconds. The radio frequency sampling data after adding the time stamp is referred to as radio frequency time domain sampling data. The radio frequency time domain sampling data is divided into several equal length time domain data blocks. The length of each data block is determined according to the number of FFT operations and the expected frequency resolution. The fast Fourier transform (FFT) algorithm is applied to each time domain data block. The FFT algorithm converts the time domain signal into the frequency domain signal, and the output is complex frequency spectrum data, each complex number representing the amplitude and phase of a specific frequency component. After performing FFT operation on each time domain data block, a series of real-time radio frequency spectrum data corresponding to different time periods is obtained. For each complex frequency component in each real-time radio frequency spectrum data block, the square of its amplitude is calculated, and then divided by the equivalent noise bandwidth and the sampling time to obtain the power spectrum density (PSD) estimate value at that frequency point. The power spectrum density represents the distribution of signal energy in frequency, and the unit is usually W / Hz or dBm / Hz. By calculating the power spectrum density, the frequency spectrum data can be converted into energy distribution information, which more directly reflects the intensity of different frequency components. The calculated real-time power spectrum density data still corresponds to the time domain data block on which the FFT operation is performed, that is, each PSD data block represents the frequency energy distribution in a time segment. The entire monitoring frequency band is divided into several continuous sub-bands. For example, the 2.4GHz ISM frequency band can be divided into multiple sub-channels with equal bandwidth. For each real-time power spectrum density data block calculated in the previous step, the average power value in each sub-band is calculated. The specific operation is to perform arithmetic averaging on the power spectrum density values of all frequency points in each sub-band. A real-time frequency band power distribution vector data is generated for each time segment, and each element of the vector represents the average power value of the corresponding sub-band.The average or median of all elements in the power distribution vector is calculated as an estimate of the noise floor. Then, a significance threshold is set, which can be a fixed difference relative to the noise floor (e.g. 10 dB higher than the noise floor), or dynamically adjusted based on statistical methods. Traverse each element in the real-time frequency band power distribution vector, if the average power value of a certain sub-band exceeds the sum of the estimated noise floor and the significance threshold, it is considered that there is a significant radio frequency peak in the sub-band. Record the center frequency and peak power corresponding to the significant peak. Detect and record all significant peaks that exceed the threshold to generate a real-time significant radio frequency peak feature list, each element in the list contains peak frequency and peak power information. Arrange the real-time significant radio frequency peak feature list in order of frequency value from small to large. At the same time, the real-time frequency band power distribution vector data corresponding to this time period is also included in the integration process. The arranged real-time significant radio frequency peak feature list and the corresponding real-time frequency band power distribution vector data, together with the time stamp of this radio frequency signal collection, sampling frequency, collection duration and other information, are integrated to form real-time radio frequency collection metadata. This metadata contains the key feature information of the radio frequency environment collected at a certain time point, including the overall frequency band power distribution and the significant signal peaks and their frequencies and intensities.

[0134] Preferably, the network environment monitoring comprises:

[0135] Based on the environment detection task configuration data, the API interfaces of Bluetooth and Wi-Fi in the user terminal device are called for active scanning, lasting for 15 seconds, to obtain real-time environment network list data;

[0136] According to the real-time environment network list data, Bluetooth beacon analysis is performed, and MAC addresses and signal strengths are extracted, and when the signal strength is greater than -75 dBm, it is recorded as a valid signal to obtain real-time Bluetooth anchor point data;

[0137] Based on the environment detection task configuration data, the NFC module in the user terminal device is controlled to read the surrounding NFC tags at a working frequency of 13.56 MHz to obtain access device NFC state data; wherein the access device NFC state data includes whether the NFC is turned on, whether it is in a polling state, and the device ID of the last NFC interaction;

[0138] The real-time environment network list data, the real-time Bluetooth anchor point data, and the access device NFC state data are combined to obtain real-time network environment data.

[0139] In the embodiment of the present application, after the user terminal device receives the environment detection task configuration data, the network type (Bluetooth and Wi-Fi) and the scanning duration (15 seconds) specified in the configuration are called respectively to invoke the Bluetooth and Wi-Fi scanning API interfaces provided by the operating system. For Wi-Fi scanning, the Wi-Fi module of the terminal device will actively send a detection request frame, listen to the beacon frames and detection response frames sent by the surrounding Wi-Fi access points (AP), and record the MAC address (BSSID), signal strength (RSSI), service set identifier (SSID), and encryption type and other information of each detected Wi-Fi network. For Bluetooth scanning, the Bluetooth module of the terminal device will broadcast a query message and listen to the response message sent by the surrounding Bluetooth devices, and record the MAC address, signal strength (RSSI), and device name (if broadcasted) of each scanned Bluetooth device. The entire scanning process lasts for 15 seconds, during which multiple continuous scans are performed, and all scanned Wi-Fi and Bluetooth device information is summarized to form real-time environment network list data. For the screened Bluetooth device records, the MAC address and signal strength (RSSI) value are extracted. According to the pre-set MAC address list of the Bluetooth beacon device, it is judged whether the currently scanned Bluetooth device belongs to a trusted Bluetooth beacon device. If the MAC address of the scanned Bluetooth device matches an entry in the pre-set beacon MAC address list, and its received signal strength (RSSI) is greater than the pre-set valid signal threshold (-75 dBm), the MAC address and signal strength of the Bluetooth device are recorded as a valid real-time Bluetooth anchor point data. The user terminal device enables its built-in near field communication (NFC) module according to the environment detection task configuration data. The NFC module is controlled to start polling the surrounding NFC tags at a working frequency of 13.56 MHz. Through the NFC API interface provided by the operating system, the working state of the current NFC module is obtained, including whether the NFC function has been started. If the NFC function has been started, it is further judged whether the NFC module is in an active polling mode, i.e., whether it is actively scanning the surrounding NFC tags. If the proximity of any NFC tag is detected during the polling process and data interaction occurs, the unique identifier (device ID) of the NFC tag of the last successful interaction is recorded. If the NFC function is in a closed state, or is started but not in a polling state, or no NFC interaction has occurred, the corresponding state information is recorded. Finally, the start state, polling state, and NFC device ID of the last interaction (if any) of the NFC module are combined into access device NFC state data. The three different types of data are organized into a structured data format, such as a JSON object.The JSON object can include three main key-value pairs: one key corresponds to real-time environment network list data (its value is a list containing all scanned network device information), one key corresponds to real-time Bluetooth anchor data (its value is a list containing beacon MAC addresses and signal strengths), and another key corresponds to access device NFC state data (its value is an object containing NFC state information).

[0140] As an example of the present application, referring to Figure 2 shown, the step S3 includes: Figure 1 a detailed implementation step flowchart of step S3 in the example, the step S3 includes:

[0141] Step S31: Common MAC address identification is performed on the reference environment trusted network data in the security environment reference data and the real-time environment network list data in the real-time network environment data, and then network environment matching degree scoring is performed to obtain the network environment matching degree.

[0142] In the embodiment of the present application, the reference environment trusted network data is extracted from the security environment reference data, and the data contains a MAC address list of known trusted Wi-Fi and Bluetooth devices. The real-time environment network list data is extracted from the real-time network environment data, and the data contains a MAC address list of all Wi-Fi and Bluetooth devices detected in the current environment. Each MAC address in the real-time environment network list data is traversed to check whether it exists in the reference environment trusted network data. The number of matched MAC addresses is counted. The network environment matching degree score is calculated: the number of matched MAC addresses is divided by the total number of MAC addresses in the reference environment trusted network data. The calculation result is multiplied by 100% to obtain the network environment matching degree percentage value. For example, if there are 10 trusted devices in the reference environment and 6 devices are detected in the real-time environment that match the reference environment, the network environment matching degree is (6 / 10) x 100% = 60%. The percentage value is taken as the network environment matching degree.

[0143] Step S32: Single trusted anchor coverage calculation is performed on the real-time Bluetooth anchor data in the real-time network environment data using the trusted anchor signal feature data in the security environment reference data, and then spatial position trustworthiness evaluation is performed to generate the spatial position matching degree.

[0144] In the embodiment of the present application, the trusted anchor point signal feature data is extracted from the security environment reference data, which contains the MAC address of each trusted Bluetooth anchor point device and its corresponding average RSSI value. The real-time Bluetooth anchor point data is extracted from the real-time network environment data, which contains the MAC address of the detected Bluetooth beacon device in the current environment and its RSSI value. For each trusted Bluetooth anchor point, check whether its MAC address exists in the real-time Bluetooth anchor point data. If it exists, it is considered that the anchor point is covered. Calculate the single trusted anchor point coverage rate: divide the number of covered anchor points by the total number of trusted anchor points. Then, according to the preset distance-RSSI mapping relationship model, such as the RSSI ranging formula based on the logarithmic path loss model, convert the RSSI value of each covered anchor point in the real-time Bluetooth anchor point data into the estimated distance between the user terminal device and the anchor point. According to these distance values and the known anchor point positions, the spatial position of the user terminal device is estimated using trilateration or other positioning algorithms. Compare the estimated position with the predefined security area to determine whether the user terminal device is located within the security area. If it is located within the security area, the spatial position has a high degree of confidence; otherwise, the spatial position has a low degree of confidence. Combine the single trusted anchor point coverage rate and the spatial position confidence to generate the final spatial position matching degree using the weighted average method.

[0145] Step S33: abnormal interaction behavior analysis according to the access device NFC state data, to obtain NFC abnormal behavior data;

[0146] In the embodiment of the present application, it is analyzed whether the NFC is in an unexpected state. For example, if it is specified in the security policy that the NFC function should be in the off state in a specific scenario, and it is monitored that the NFC is in the on state, it is considered that there is an abnormality. For another example, if it is monitored that the NFC is in the active polling state, but there is no expected NFC tag nearby for interaction, it is considered as abnormal behavior. Further analyze the device ID of the last NFC interaction. Compare the device ID with the ID of the trusted NFC tag pre-registered or recorded in the reference environment. If the NFC tag ID of the last interaction is not in the trusted list, or does not match the expected interaction object of the current access operation, it is considered that there is potential risk. In addition, the frequency and duration of NFC interaction can also be analyzed. For example, frequently interacting with different unknown NFC tags in a short time, or maintaining a connection with a certain unknown NFC tag for a long time, is considered as abnormal behavior. According to the above analysis, NFC abnormal behavior data is generated, which can be a Boolean value indicating whether there is abnormal behavior, or a structured data containing multiple fields, which records the detected abnormal type, occurrence time, involved NFC tag ID and other information in detail.

[0147] Step S34: NFC security risk assessment is performed on the NFC abnormal behavior data to generate NFC risk assessment data;

[0148] In the embodiment of the present application, a series of NFC security risk rules and corresponding risk levels are defined. For example, "NFC is turned on when it is supposed to be turned off according to the policy" can be considered as low risk because it is a user's misoperation. The risk level of "interaction with unknown NFC tag" depends on the nature of the unknown tag and the content of the interaction. If only public information is read, it is a medium risk. If it involves the transmission of sensitive data or triggers an unknown application, it is a high risk. "Frequent interaction with multiple unknown NFC tags in a short period of time" indicates an attempt of malicious scanning or man-in-the-middle attack, which can be rated as high risk. The evaluation process matches the NFC abnormal behavior data with the pre-defined risk rules. If an abnormal behavior that meets a certain risk rule is detected, the NFC risk assessment data is generated according to the risk level corresponding to the rule. The NFC risk assessment data can be a numerical value representing the risk level (e.g. low, medium, high), or a structured data containing risk description and risk level. For example, if data interaction with a high-risk unknown NFC tag is detected, the NFC risk assessment data is "Risk Level: High, Description: High-risk data interaction with device with ID [unknown NFC tag ID]". If no NFC abnormal behavior is detected, the NFC risk assessment data can indicate "no risk".

[0149] Step S35: Intrusion risk detection is performed on the real-time radio frequency collection metadata by the radio frequency fingerprint feature vector in the security environment benchmark data to generate intrusion risk assessment data;

[0150] In the embodiment of the present application, the radio frequency fingerprint feature vector is extracted from the security environment benchmark data. The real-time frequency band power distribution vector data is extracted from the real-time radio frequency collection metadata. The similarity between the real-time frequency band power distribution vector data and the radio frequency fingerprint feature vector is calculated, for example using cosine similarity. According to the similarity score, it is determined whether there is an intrusion risk. If the similarity is lower than a pre-set threshold, it is considered that there is an intrusion risk, and the intrusion risk level is determined according to the difference between the similarity score and the threshold, for example the greater the difference, the higher the risk level. The intrusion risk level is taken as the intrusion risk assessment data.

[0151] Step S36: Multi-dimensional access risk assessment is performed according to the network environment matching degree, the spatial location matching degree, the NFC risk assessment data and the intrusion risk assessment data to obtain multi-dimensional access risk assessment data.

[0152] In the embodiments of the present application, the evaluation results of each dimension are normalized to unify the values to the same range (for example, between 0 and 1) for unified comparison and calculation. For the network environment matching degree and the spatial position matching degree, the percentage form or the normalized value can be directly used. For the NFC risk assessment data and the intrusion risk assessment data, if the output is a risk level (for example, low, medium and high), it needs to be mapped to a numerical range (for example, low = 0.2, medium = 0.6, and high = 1.0). If the output is a risk score, it can be directly used or normalized. Next, according to the set weights, the evaluation results of each dimension are weighted and summed to obtain a comprehensive risk score. The calculation formula can be: multi-dimensional risk score = (network environment matching degree x weight 1) + (spatial position matching degree x weight 2) + (NFC risk assessment value x weight 3) + (intrusion risk assessment value x weight 4), wherein the sum of weight 1, weight 2, weight 3 and weight 4 is 1.

[0153] Preferably, the intrusion risk detection of the real-time radio frequency collection metadata by the radio frequency fingerprint feature vector in the security environment reference data comprises:

[0154] According to the spectrum difference comparison between the real-time frequency band power distribution vector data in the real-time radio frequency collection metadata and the radio frequency fingerprint feature vector, a spectrum difference measurement value is generated;

[0155] The spectrum difference measurement value is subjected to time sequence stability analysis to obtain a frequency band fluctuation stability coefficient;

[0156] Based on the frequency band fluctuation stability coefficient, an abnormal high-power frequency point detection is performed on the real-time significant radio frequency peak value feature list in the real-time radio frequency collection metadata to obtain abnormal frequency point detection data;

[0157] The abnormal frequency point detection data is matched with a known interference source through a preset interference signal feature library, and when it cannot be identified as a known interference source, a potential intrusion signal is determined;

[0158] The potential intrusion signal is subjected to abnormal peak value correlation analysis, and then intrusion type identification is performed to generate intrusion type risk assessment data.

[0159] In the embodiment of the present application, the radio frequency fingerprint feature vector is extracted from the security environment reference data, which contains the power values of each frequency band in the reference environment. The real-time frequency band power distribution vector data is extracted from the real-time radio frequency collection metadata, which contains the power values of each frequency band in the current environment. The Euclidean distance between the real-time frequency band power distribution vector data and the radio frequency fingerprint feature vector is calculated to obtain the spectral difference measure value. The larger the value, the greater the spectral difference. A plurality of real-time frequency band power distribution vector data collected within a period of time (for example, the past 1 minute) is stored in a matrix, and each row represents a frequency band power distribution vector at a time point. The standard deviation of the power value of each frequency band in the time period is calculated, and the standard deviation is divided by the average power value of the frequency band to obtain the fluctuation coefficient of the frequency band. The fluctuation coefficients of all frequency bands are averaged to obtain the frequency band fluctuation stability coefficient. The smaller the coefficient, the more stable the frequency band fluctuation. Based on the frequency band fluctuation stability coefficient, the real-time significant radio frequency peak feature list in the real-time radio frequency collection metadata is detected for abnormal high-power frequency points. Specifically, each frequency point in the real-time significant radio frequency peak feature list is traversed. If the power value of the frequency point exceeds the average power value of the frequency band in the reference environment plus a preset threshold (for example, twice the reference power value), and the fluctuation coefficient of the frequency band is less than the frequency band fluctuation stability coefficient, the frequency point is marked as an abnormal high-power frequency point, and these abnormal frequency points are stored in the abnormal frequency point detection data, which contains the frequency and power value of each abnormal frequency point. Each abnormal frequency point in the abnormal frequency point detection data is compared with a preset interference signal feature library. The interference signal feature library contains the frequency, power, modulation mode and other characteristic information of known interference sources, such as Wi-Fi signals, Bluetooth signals, Zigbee signals, etc. Frequency and power are used as matching standards. If an abnormal frequency point is very close to the frequency and power of a known interference source in the interference signal feature library (for example, the frequency difference is less than 1 MHz, and the power difference is less than 3 dB), it is considered that the abnormal frequency point is generated by the known interference source, and it is removed from the abnormal frequency point detection data. The potential intrusion signal which cannot be identified as a known interference source is analyzed for abnormal peak correlation. For example, whether there is a harmonic relationship between the frequencies of the potential intrusion signal, or whether multiple abnormal peaks appear at the same time within a short period of time. According to the results of the correlation analysis, the type of the potential intrusion signal is identified, such as narrowband interference, wideband interference, deception interference, etc. According to the identified intrusion type, the corresponding risk level is evaluated, for example, the risk level of narrowband interference is low, the risk level of wideband interference is high, and the risk level of deception interference is the highest.

[0160] Preferably, step S4 comprises the following steps:

[0161] Step S41: calculating the threat probability distribution according to the multi-dimensional access risk assessment data to generate the current access risk level of the user;

[0162] Step S42: based on the current access risk level of the user and the multi-dimensional access risk assessment data, find the corresponding access control strategy from the pre-defined risk level-access control mapping table, and obtain the initial access control strategy;

[0163] Step S43: according to the initial access control strategy, specific permission item extraction is performed to obtain a dynamic permission item list;

[0164] Step S44: associating the dynamic permission item list with the access request, and updating the user access session state;

[0165] Step S45: based on the user access session state, performing information security access to the user to obtain access control execution data;

[0166] Step S46: based on the access control execution data, real-time monitoring of user operation behavior in the information access process, when the user has irregular operation behavior, immediately block the operation, delete the corresponding dynamic permission item, and re-initialize the user access session state, to realize the information access security control.

[0167] In the embodiments of the present application, the threat probability distribution is calculated according to the multi-dimensional access risk assessment data, such as the comprehensive risk score. Specifically, the risk score is divided into different level intervals, such as low risk, medium risk, and high risk, and the threat probability corresponding to each level interval is determined according to historical data or expert experience. For example, the risk score between 0-30 is low risk, and the threat probability is 10%; the risk score between 31-60 is medium risk, and the threat probability is 50%; the risk score between 61-100 is high risk, and the threat probability is 90%. According to the level interval in which the multi-dimensional access risk assessment data falls, the current access risk level of the user is determined. Based on the current access risk level of the user and the scores of each sub-item in the multi-dimensional access risk assessment data, such as network environment matching degree, spatial position matching degree, NFC risk assessment data, and intrusion risk assessment data, the corresponding access control strategy is searched from a pre-defined risk level-access control mapping table. The mapping table defines the access control strategies corresponding to different risk levels and combinations of scores of each risk sub-item, such as allowing access, limiting access, and denying access. According to the matching result, the initial access control strategy is obtained. For example, if the initial access control strategy is "partial restriction, prohibit modification of sensitive data", it is necessary to further determine which specific data resources are considered "sensitive data", and which operations of the user are prohibited (such as "modification", "deletion", etc.). These specific permission control items will be added to the dynamic permission item list. The extraction process of the permission item needs to query the pre-configured permission management system or policy database, which stores the corresponding relationship between users, roles, resources, and operations. According to the identity information of the user and the restriction conditions specified in the initial access control strategy, the specific operations that the user is allowed to perform and the specific resources that the user can access are retrieved. For example, if the user requests to access a certain specific file resource, and the initial access control strategy allows "read-only access", the dynamic permission item list will contain the permission that allows the user to perform the "read" operation on the file, but does not contain the permission of other operations such as "modify" or "delete". The dynamic permission item list can be a data structure containing multiple permission items, each of which specifies which resources the user can perform which operations on. When the user initiates an information access request (such as opening a certain file or querying a certain database record), the system will obtain the dynamic permission item list of the user. The access request of the user is matched with the permission items in the dynamic permission item list. Only when the access request of the user is consistent with a permission item in the list (i.e. the accessed resource and the performed operation are within the scope allowed by the permission item), is the access request considered legal. After completing the permission verification, the access session state of the user needs to be updated. The user access session state records the identity information of the current user, session ID, currently valid dynamic permission item list, and session validity period, etc.After each successful authentication and dynamic permission acquisition, the user's session state is created or updated, containing the latest list of dynamic permission items. Subsequent access requests initiated by the user during the session are checked against the dynamic permissions recorded in the session state. For example, after a user successfully logs in and completes the environmental risk assessment, the system creates a new session for the user and associates the list of dynamic permission items generated based on the assessment results with the session. When the user initiates a request to access a certain information resource, the security control module intercepts the request and checks the list of dynamic permission items associated with the user's session. It determines whether the user's request operation and target resource are within the scope allowed by a certain permission item in the list. If the user's request meets the requirements of a certain permission item, the operation is allowed to be executed, and the user can successfully access the target information resource. If the user's request does not meet the requirements of any permission item, the operation is denied, and the user is returned a prompt message indicating the denial of access. Access control execution data records each access request by the user, the execution result (allowed or denied), and the specific permission item relied upon. For example, when a user attempts to edit a file that is restricted to read-only, the system checks the dynamic permissions in the user's session state and finds that there is no "edit" permission, so the edit operation is denied, and an access control execution data is recorded, indicating that the user's edit of the file was denied due to insufficient permissions. During the user's information access process, the system records and analyzes the user's operation behavior in real time, such as which files are accessed, which operations are performed, and which commands are entered. The user's real-time operation behavior is compared with predefined patterns of violation operation behavior. Patterns of violation operation behavior can include attempts to access unauthorized resources, non-normal operations on sensitive data (such as frequent copying or deletion), and execution of high-risk system commands. When the system detects that a user's operation behavior matches a predefined pattern of violation operation behavior, it immediately takes blocking measures, such as interrupting the current operation, closing the current session, or even locking the user's account. At the same time, to ensure security, the system immediately deletes the corresponding dynamic permission items in the user's current session and reinitializes the user's access session state, which means the user needs to reauthenticate and reevaluate the environmental risk to regain access permissions, and the new access permissions will be determined based on the reevaluated environmental risk, which will be more stringent than the previous permissions. For example, if a user attempts to perform a delete file operation after being granted read-only permission, the system will immediately block the delete operation, delete any write permissions in the user's session, and force the user to log in again.

[0168] Preferably, the present application further provides an information access security control system for implementing the information access security control method as described above, which comprises:

[0169] An environment benchmark collection module is configured to perform security physical space authorization on a target access environment to obtain a security physical space, deploy a security environment collection network in the security physical space, perform access environment benchmark monitoring by using the security environment collection network to obtain environment benchmark characteristic data, wherein the security environment collection network comprises a spectrum analyzer, a wireless network card, and an electromagnetic signal receiving unit.

[0170] An access environment monitoring module is configured to acquire user identity information, perform security encryption on the environment benchmark characteristic data by using the user identity information to obtain security environment benchmark data, initiate an information access request by a user through a user terminal device to obtain an access trigger signal, and perform real-time access environment monitoring by using the user terminal device based on the access trigger signal to generate real-time access environment monitoring data.

[0171] A multi-dimensional risk assessment module is configured to perform multi-dimensional access risk assessment on the real-time access environment monitoring data by using the security environment benchmark data to obtain multi-dimensional access risk assessment data.

[0172] A dynamic access control module is configured to perform dynamic information security access execution according to the multi-dimensional access risk assessment data to obtain access control execution data, and monitor the operation behavior of the user in real time based on the access control execution data to achieve information access security control.

[0173] The present application is to comprehensively and meticulously obtain the physical and electromagnetic characteristics specific to the space by deploying a secure environment acquisition network inside a secure physical space, and to form reliable environment baseline characteristic data. The environment baseline data is encrypted using user identity information, which not only ensures the security of the data, but also binds it to a specific secure environment, providing a trusted reference standard for subsequent risk assessment. When a user initiates an information access request, the system collects real-time access environment monitoring data of the current environment through the user terminal device. This active real-time monitoring method can capture the instantaneous changes of the user's current environment. By considering factors such as network environment matching degree, spatial location credibility, NFC interaction behavior, and radio frequency signal intrusion risk, the system can more accurately determine whether the user's current environment is safe and reliable, thereby effectively identifying potential unauthorized access risks, such as attackers attempting to simulate a secure environment. The system can dynamically adjust according to the real-time environment safety status. When the assessment result shows that the environment safety risk is low, the user can normally access information. When an environment anomaly or increased risk is detected, the system can immediately take appropriate security measures, such as limiting the user's access rights, performing secondary identity verification, or even interrupting the current access session. This dynamic adjustment mechanism can effectively cope with complex and changing security environments, avoid sensitive operations in potentially risky environments, and thus minimize the possibility of information leakage. After the user is allowed to access information, the system will still continuously monitor and analyze the user's operation behavior. By detecting whether the user's operation conforms to the normal behavior pattern, such as whether there is an abnormal data access frequency or irregular file operation, potential internal threats or maliciously controlled user terminals can be discovered in a timely manner. Once abnormal behavior is detected, the system can immediately issue an alarm or take further security measures, such as recording operation logs, limiting specific operations, or even locking user accounts, thereby forming an additional security line of defense and further enhancing the security of information access.

[0174] Therefore, embodiments should be considered in all respects as illustrative and not restrictive, the scope of the application being defined by the appended claims rather than the above description, and all changes that come within the meaning and range of equivalency of the claims are intended to be embraced therein.

[0175] The above description is merely one specific implementation of the application, which enables those skilled in the art to understand or implement the application. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the application. Therefore, the application should not be limited to the embodiments shown herein, but should be consistent with the widest scope of the principles and novel features disclosed herein.

Claims

1. A method for controlling information access security, characterized in that: The following steps are involved: Step S1: Authorize the target access environment to obtain a secure physical space; Deploy a secure environment collection network in a secure physical space; Using a secure environment acquisition network to perform access environment benchmark monitoring to obtain environmental benchmark feature data; wherein the secure environment acquisition network includes a spectrum analyzer, a wireless network card, and an electromagnetic signal receiving unit; Step S2: Obtain user identity information; securely encrypt environmental baseline feature data using the user identity information to obtain secure environmental baseline data; the user initiates an information access request through a user terminal device to obtain an access trigger signal; based on the access trigger signal, the user terminal device performs real-time access environment monitoring to generate real-time access environment monitoring data; Step S3: Performing a multi-dimensional access risk assessment on the real-time access environment monitoring data using the security environment benchmark data to obtain multi-dimensional access risk assessment data; Step S4: Perform dynamic information security access execution based on the multi-dimensional access risk assessment data to obtain access control execution data; monitor the user's operation behavior in real time based on the access control execution data to achieve information access security control.

2. The information access security control method according to claim 1, characterized in that: The access environment benchmark monitoring using the secure environment collection network in step S1 includes: Use a spectrum analyzer to continuously collect RF signals for 10 minutes at a sampling rate of 2MS / s. Transmit the collected raw RF signals to the edge computing node through a high-speed data interface to obtain the original RF sampling signals. Perform RF fingerprint feature analysis on the original RF sampling signal to obtain a RF fingerprint feature vector. The RF fingerprint feature analysis includes signal harmonic distortion calculation, zero-level crossing count, and carrier frequency offset estimation. Using a wireless network card to scan surrounding Bluetooth and Wi-Fi devices every 2 seconds, recording MAC addresses, signal strengths, and device names for 5 minutes, to obtain an original baseline environment network list; wherein the wireless network card supports 2.4GHz and 5GHz frequency bands and has concurrent scanning capabilities; The original baseline environment network list is filtered by a preset trusted network threshold to obtain the baseline environment trusted network data; Marking a trusted device group in a secure physical space; broadcasting a low-power Bluetooth beacon to the trusted device group, and then generating trusted device electromagnetic signal strength data based on the electromagnetic signal strength received by the electromagnetic signal receiving unit; Calculate the average value of the electromagnetic signal strength data of the trusted device and associate the anchor point signals with the trusted device group to obtain the trusted anchor point signal feature data; The radio frequency fingerprint feature vector, the baseline environment trusted network data and the trusted anchor point signal feature data are integrated into the environment baseline feature to generate the environment baseline feature data.

3. The information access security control method according to claim 1, characterized in that: The secure encryption of the environmental baseline feature data using the user identity information in step S2 includes: Perform hash operation on user identity information to generate user identity hash value; Generate a 256-bit random number using a random number generator, and perform an XOR operation on the user identity hash value and the random number to obtain a mixed key seed; Perform key derivation based on the hybrid key seed to generate a user-specific encryption key; Symmetrically encrypt the environmental benchmark feature data using the user's exclusive encryption key to generate encrypted and secure environmental benchmark data; The user identity information is associated with the encrypted security environment benchmark data, and then the security environment benchmark data is obtained based on the secure storage of the security element.

4. The information access security control method according to claim 1, characterized in that: The real-time security environment monitoring using the user terminal device based on the access trigger signal in step S2 includes: Perform user identity authentication according to the access trigger signal to obtain user identity authentication data; When the user authentication data is true, the access trigger signal is responded to and the current system status of the user terminal device is judged. When the network connection status of the user terminal device is greater than the preset transmission bandwidth threshold and the battery power is greater than 20%, an environment detection readiness signal is obtained; otherwise, an environment detection capability insufficient signal is generated and a prompt message is sent to the user; Perform detection task processing according to the environment detection ready signal to obtain environment detection task configuration data; Based on the environmental detection task configuration data, the user terminal device is controlled to perform real-time access environment monitoring and generate real-time access environment monitoring data; the real-time access environment monitoring includes radio frequency monitoring and network environment monitoring, and the real-time access environment monitoring data includes real-time radio frequency collection metadata and real-time network environment data.

5. The information access security control method according to claim 4, characterized in that: The real-time access to environmental monitoring data includes: Based on the environmental detection task configuration data, the built-in or external RF acquisition module of the user terminal device is used to continuously collect and access RF signals in the physical environment to obtain the original RF sampling data stream; Perform data preprocessing on the original RF sampling data stream, and then perform time stamp marking to generate RF time domain sampling data; Perform fast Fourier transform on the RF time domain sampling data to obtain real-time RF spectrum data; Calculate real-time power spectrum density based on real-time radio frequency spectrum data; Extract the average power value of each sub-band according to the real-time power spectrum density to obtain the real-time frequency band power distribution vector data; Perform noise floor estimation and significant peak detection based on real-time frequency band power distribution vector data to generate a real-time significant RF peak feature list; The real-time significant RF peak feature list is arranged in frequency order, and the RF acquisition metadata is integrated according to the real-time frequency band power distribution vector data to obtain the real-time RF acquisition metadata.

6. The information access security control method according to claim 4, characterized in that: The network environment monitoring includes: Based on the environment detection task configuration data, the Bluetooth and Wi-Fi API interfaces in the user terminal device are called to perform active scanning for 15 seconds to obtain real-time environment network list data; Analyze Bluetooth beacons based on real-time environmental network list data, extract MAC addresses and signal strengths, and record signals greater than -75dBm as valid signals to obtain real-time Bluetooth anchor point data. Based on the environment detection task configuration data, the NFC module in the user terminal device is controlled to read the surrounding NFC tags at a frequency of 13.56MHz to obtain the NFC status data of the access device. The NFC status data of the access device includes whether NFC is turned on, whether it is in the polling state, and the device ID of the most recent NFC interaction. The real-time environment network list data, real-time Bluetooth anchor point data and access device NFC status data are combined into a network environment to obtain real-time network environment data.

7. The information access security control method according to claim 4, characterized in that: Step S3 includes the following steps: Step S31: performing shared MAC address identification on the benchmark environment trusted network data in the security environment benchmark data and the real-time environment network list data in the real-time network environment data, and then performing a network environment matching score to obtain a network environment matching degree; Step S32: Calculate the coverage of a single trusted anchor point for the real-time Bluetooth anchor point data in the real-time network environment data using the trusted anchor point signal feature data in the security environment benchmark data, and then perform a spatial position credibility assessment to generate a spatial position matching degree; Step S33: Analyze abnormal interaction behavior based on the NFC status data of the access device to obtain NFC abnormal behavior data; Step S34: performing an NFC security risk assessment on the NFC abnormal behavior data to generate NFC risk assessment data; Step S35: performing intrusion risk detection on the real-time RF collection metadata using the RF fingerprint feature vector in the security environment benchmark data to generate intrusion risk assessment data; Step S36: Perform a multi-dimensional access risk assessment based on the network environment matching degree, the spatial location matching degree, the NFC risk assessment data, and the intrusion risk assessment data to obtain multi-dimensional access risk assessment data.

8. The information access security control method according to claim 7, characterized in that: The intrusion risk detection of real-time radio frequency collection metadata using radio frequency fingerprint feature vectors in the security environment benchmark data includes: Compare the spectrum difference between the real-time frequency band power distribution vector data in the real-time RF acquisition metadata and the RF fingerprint feature vector to generate a spectrum difference measurement value; Perform time series stability analysis on the spectrum difference measurement value to obtain the frequency band fluctuation stability coefficient; Based on the frequency band fluctuation stability coefficient, abnormal high-power frequency points are detected on the real-time significant RF peak feature list in the real-time RF acquisition metadata to obtain abnormal frequency point detection data; The abnormal frequency detection data is matched with known interference sources through the preset interference signal feature library. If it cannot be identified as a known interference source, it is determined to be a potential intrusion signal; Perform abnormal peak correlation analysis on potential intrusion signals, then identify the intrusion type and generate intrusion type risk assessment data.

9. The information access security control method according to claim 1, characterized in that: Step S4 includes the following steps: Step S41: Calculate the threat probability distribution based on the multi-dimensional access risk assessment data to generate the user's current access risk level; Step S42: Based on the user's current access risk level and the multi-dimensional access risk assessment data, a corresponding access control policy is searched from a predefined risk level-access control mapping table to obtain an initial access control policy; Step S43: extracting specific permission items according to the initial access control policy to obtain a dynamic permission item list; Step S44: Associating the dynamic permission item list with the access request and updating the user access session status; Step S45: performing information security access execution on the user based on the user access session status to obtain access control execution data; Step S46: Based on the access control execution data, the user operation behavior is monitored in real time during the information access process. When the user has illegal operation behavior, the operation is immediately blocked, the corresponding dynamic permission item is deleted, and the user access session status is reinitialized to achieve information access security control.

10. An information access security control system, characterized in that: For executing the information access security control method according to claim 1, the information access security control system comprises: An environmental benchmark acquisition module is used to authorize a target access environment to a secure physical space and obtain a secure physical space; deploy a secure environment acquisition network in the secure physical space; and utilize the secure environment acquisition network to monitor the access environment benchmark and obtain environmental benchmark feature data; wherein the secure environment acquisition network includes a spectrum analyzer, a wireless network card, and an electromagnetic signal receiving unit; Access the environmental monitoring module to obtain user identity information; securely encrypt environmental baseline feature data using the user identity information to obtain secure environmental baseline data; the user initiates an information access request through a user terminal device to obtain an access trigger signal; based on the access trigger signal, the user terminal device is used to perform real-time access to environmental monitoring to generate real-time access to environmental monitoring data; A multi-dimensional risk assessment module is used to perform a multi-dimensional access risk assessment on real-time access environment monitoring data using security environment benchmark data to obtain multi-dimensional access risk assessment data; The dynamic access control module is used to perform dynamic information security access execution based on multi-dimensional access risk assessment data to obtain access control execution data; based on the access control execution data, the user's operation behavior is monitored in real time to achieve information access security control.

Citation Information

Patent Citations

  • Security engine method, IoT device and non-transitory computer readable storage medium

    CN109582354A

  • Electromagnetic environment monitoring system

    CN114398240A