College office information management system

Through modular analysis in the university office information management system, access abnormalities on the user side are identified and verified, and the problem of information leakage risks in collaborative work of multiple users is solved, thereby improving information security and improving user experience.

CN120296715AInactive Publication Date: 2025-07-11SHANXI MANAGEMENT VOCATIONAL COLLEGE
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510332019.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-20
Publication Date
2025-07-11
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

In the process of information management of colleges and universities, when multiple categories of user terminals work together, there is a user terminal that accesses information nodes that do not have access rights, resulting in an increase in the risk of information leakage, and it is difficult for the existing technology to identify and verify abnormal risks in a timely manner.

Method used

The classification sorting module, behavioral storage module, access analysis module, access verification module and verification analysis module are adopted to determine the degree of access overreach and trust of the user by analyzing the real-time operation data and movement trajectory of the user, and send verification prompt information to ensure the security of the information.

Benefits of technology

On the premise of providing normal access services, the access user side with potential abnormalities can be identified and verified, improving information security and user experience, and reducing the risk of information leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120296715A_ABST
    Figure CN120296715A_ABST
Patent Text Reader

Abstract

The invention relates to the field of information management, in particular to a college office information management system which comprises the following steps: storing conventional operation behavior data of each user side; dividing access categories of a plurality of user sides, sorting accessible information nodes of each category of user sides, and generating a corresponding form; determining non-authority access characteristics of the user side according to the real-time operation data of the user side so as to analyze an access unauthorized degree characterization value, and marking the user side; obtaining a weight level of the accessed information node to determine prompt verification information sent to the marked user side; obtaining a moving track range of the corresponding input equipment, determining a trusted representation value in combination with the operation behavior characteristics, and determining whether the user side is a trusted access user side or not; according to the method and the device, on the premise of providing normal access service, the access user side with potential abnormity can be verified and identified, and the information security and the user experience are ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information management, and particularly to a college office information management system. Background Art

[0002] With the rapid development of Internet technology, the college office environment has gradually developed towards full networking. The campus network covers various areas such as teaching, scientific research, and administration. Teachers and students can conveniently access and share information resources through the network. However, due to the networking, various security threats from the network may need to be faced, such as hacker attacks.

[0003] Moreover, there is a frequent need for information sharing and collaboration among different departments within the college and between teachers and students. For example, sharing of teaching resources, cooperation on scientific research projects, etc. Therefore, during the information sharing process, it is necessary to ensure that information can only be accessed and used by authorized personnel to prevent information leakage and abuse. At the same time, the security of information during transmission and storage needs to be guaranteed. For example, in the cooperation of scientific research projects, sensitive research data involved needs to be securely shared among different research teams. Furthermore, a corresponding office information management system is established to monitor and manage network access, data transmission, etc., to ensure the operation security of the college network environment and the security of data transmission.

[0004] Chinese Patent Application Publication No.: CN116245270A, discloses a smart school system and a method for applying the smart school system, belonging to the technical field of campus system information management. The smart school system includes: a perception and transmission layer for performing service request perception and service content perception; an application service layer for executing corresponding service responses based on service requests, and also for correcting service response contents based on service content perception results during the service response process; a display platform layer for interacting with users based on preset terminals for service requests and service response contents; and an information storage layer for integrating and storing all data in the smart school system. This invention solution solves the problems of serious information islands, poor data security performance, and low intelligence existing in current smart schools.

[0005] However, the following problems still exist in the prior art.

[0006] In the process of college information management, in addition to the single access operation behavior of various types of user terminals, there are also situations where multiple types of user terminals need to cooperate based on a common purpose. In the case of multi-type user cooperation, there are access operations on information nodes that the user terminal itself does not have access rights to. However, based on the cooperation, corresponding access to non-authority information nodes will be carried out. In this process, it is easy to ignore that the access to non-authority information nodes is not based on cooperation, but rather the situation where the user terminal is stolen or there is an abnormal risk of remote login. The above risk situations cannot be identified and verified in time, resulting in a reduction in the security of information nodes and an increased risk of leakage of the content corresponding to the information nodes. Summary of the Invention

[0007] To this end, the present invention provides a college office information management system to overcome the problems in the prior art that in the process of college information management, in addition to the single access operation behavior of various types of user terminals, there are also situations where multiple types of user terminals need to cooperate based on a common purpose. In the case of multi-type user cooperation, there are access operations on information nodes that the user terminal itself does not have access rights to. However, based on the cooperation, corresponding access to non-authority information nodes will be carried out. In this process, it is easy to ignore that the access to non-authority information nodes is not based on cooperation, but rather the situation where the user terminal is stolen or there is an abnormal risk of remote login. The above risk situations cannot be identified and verified in time, resulting in a reduction in the security of information nodes and an increased risk of leakage of the content corresponding to the information nodes.

[0008] To achieve the above object, the present invention provides a college office information management system, which includes:

[0009] A classification and sorting module, which includes a classification unit for dividing the access categories of several user terminals and a sorting unit for sorting the accessible information nodes of each type of user terminal and generating an information node form;

[0010] A behavior storage module for storing the regular operation behavior data of each user terminal;

[0011] An access analysis module, which is connected to the classification and sorting module, and is used to determine the non-authority access characteristics of the user terminal according to the real-time operation data of the user terminal, analyze the access over-authority degree characterization value for the user terminal, and mark the user terminal;

[0012] An access verification module, which is respectively connected to the classification and sorting module and the access analysis module, and is used to obtain the weight level of the information node accessed by the user terminal, and determine the prompt verification information sent to the marked user terminal according to the weight level;

[0013] A verification analysis module, which is respectively connected to the behavior storage module and the access verification module, is used to obtain the movement trajectory range of the input device corresponding to the client and determine the trusted representation value of the client in combination with the operation behavior characteristics, so as to determine whether the client is a trusted access client;

[0014] A permission opening module, which is connected to the verification analysis module, is used to determine whether to open the access permission of the corresponding information node to the client based on the analysis result of the verification analysis module;

[0015] Among them, the non-permission access characteristics include non-permission access depth and non-permission application access frequency within a predetermined time; the operation behavior characteristics include access path deviation degree and network flow port increment.

[0016] Further, the sorting unit is used to sort the information nodes in descending order based on the update frequency of the content corresponding to each information node.

[0017] Further, the access analysis module is used to analyze the access over-authorization degree representation value for the client, including,

[0018] Using the ratio of the non-permission access depth to the non-permission access depth threshold as the first access over-authorization feature;

[0019] Using the ratio of the non-permission application access frequency within a predetermined time to the non-permission application access frequency threshold as the second access over-authorization feature;

[0020] Using the sum of the first access over-authorization feature and the second access over-authorization feature as the access over-authorization degree representation value of the client.

[0021] Further, the access analysis module is used to mark the client, including,

[0022] If the access over-authorization degree representation value of any client is greater than or equal to the access over-authorization degree representation threshold, then mark the client as an access abnormal client.

[0023] Further, the access verification module is used to obtain the weight level of the information node accessed by the client, including,

[0024] Used to call the update frequency of the content corresponding to each information node;

[0025] Used to divide several information node intervals based on each update frequency;

[0026] Used to preset the corresponding relationship between the weight level and the information node interval;

[0027] To determine the node interval to which the information node belongs, and determine the weight level corresponding to the node interval as the weight level of the information node;

[0028] Among them, the weight levels correspond one-to-one with the node intervals.

[0029] Furthermore, the access verification module is used to determine the verification prompt information sent to the marked client according to the weight level, including,

[0030] To preset the corresponding relationship between the weight level and the verification prompt information;

[0031] Among them, the weight levels correspond one-to-one with the verification prompt information.

[0032] Furthermore, the verification analysis module is used to determine the trusted representation value corresponding to the access operation, including,

[0033] To use the ratio of the farthest distance between the input device and the edge of the input box to the farthest distance threshold as the first trusted feature;

[0034] To use the ratio of the access path deviation degree to the access path deviation degree threshold and the ratio of the network flow port increment to the increment threshold as the second trusted feature;

[0035] To perform weighted summation of the first trusted feature and the second trusted feature as the trusted representation value;

[0036] Among them, the farthest distance between the input device and the edge of the input box is determined according to the movement trajectory range of the input device corresponding to the client, and the access path deviation degree is determined by comparing the real-time operation data of the client with the conventional operation behavior data.

[0037] Furthermore, the verification analysis module is used to determine whether the client is a trusted access client, including,

[0038] If the trusted representation value of the client is less than the trusted representation threshold, then determine the client as a trusted access client.

[0039] Furthermore, the permission opening module is used to determine whether to open the access permission of the corresponding information node to the client, including,

[0040] If the client is a trusted access client, then open the access permission of the corresponding information node to the client.

[0041] Furthermore, by determining the semantic generalization degree of the information node name corresponding to the information node accessed by the client, the non-permission access depth is obtained;

[0042] Among them, the information node name is obtained through the information node form.

[0043] Compared with the prior art, the present invention provides a classification and sorting module, which includes a classification unit for classifying the access categories of several client terminals and a sorting unit for sorting the accessible information nodes of each category of client terminals and generating an information node form; a behavior storage module for storing the regular operation behavior data of each client terminal; an access analysis module for determining the unauthorized access characteristics of the client terminal based on the real-time operation data of the client terminal, analyzing the access over-authorization degree characterization value for the client terminal, and marking the client terminal; an access verification module for obtaining the weight level of the information node accessed by the client terminal and determining the prompt verification information sent to the marked client terminal according to the weight level; a verification analysis module for obtaining the movement trajectory range of the input device corresponding to the client terminal and determining the trusted characterization value of the client terminal in combination with the operation behavior characteristics to determine whether the client terminal is a trusted access client terminal; and a permission opening module for determining whether to open the access permission of the corresponding information node to the client terminal based on the analysis result of the verification analysis module. The present invention can verify and identify the access client terminals with potential anomalies on the premise of providing normal access services, ensuring information security and user experience.

[0044] In particular, the present invention provides an access analysis module to analyze the degree of exceeding authority of the access operations performed by the client terminal based on the real-time operation data of the client terminal. In actual situations, client terminals usually perform regular access operations within their own authorities. When a client terminal shows an abnormal situation of frequently accessing information nodes without access authority, it indicates that there are potential anomalies in the client terminal; even if the information nodes without access authority accessed by the client terminal are deeper in the overall information nodes, it can reflect that the over-authorization behavior of the client terminal is more serious. Therefore, the present invention uses the unauthorized access depth to reflect the abstraction degree and content coverage of the information covered by the information nodes accessed by the client terminal without permission; and uses the unauthorized access frequency within a predetermined time to reflect the intensity of the client terminal's attempt to perform over-authorization access behavior. Thus, the access over-authorization degree characterization value of the client terminal is analyzed based on these two characteristics to characterize the abnormal degree of the client terminal's access over-authorization, providing data support for subsequent marking of the client terminal. The present invention can verify and identify the access client terminals with potential anomalies on the premise of providing normal access services, ensuring information security and user experience.

[0045] In particular, the present invention provides a verification and analysis module that analyzes the trustworthiness of the client by obtaining the operation behavior characteristics of the client and combining the movement trajectory range of the corresponding input device. When the client frequently applies to access non-authority information nodes, or the access depth of the accessed non-authority information nodes is relatively deep, it is considered that the client has been stolen or logged in from a different location. Under normal circumstances, a trusted client will promptly provide a verification feedback according to the prompt information after receiving the verification prompt information, rather than performing unconventional operations such as attempting to skip or avoid the verification. The security level of the client operation reflected by the feedback verification is determined based on the distance between the input device and the input box when the client should provide a feedback verification prompt information. At the same time, the matching situation between the real-time operation data of the client and the conventional operation behavior data is considered. A normal client usually operates according to a certain logic and workflow, and corresponding data transmission and interaction will occur during the use of the system. Under normal circumstances, the operation transmission based on the category corresponding to the normal client is relatively fixed. Therefore, the trustworthiness of the client is further analyzed and confirmed by detecting the number of network flow ports. Therefore, the present invention determines the trustworthiness characterization value through the access path deviation degree, the network flow port increment, and the maximum distance between the input device and the edge of the input box to characterize the trustworthiness and security level of the client, providing data support for subsequent determination of whether the client is a trusted access client. The present invention can verify and identify access clients with potential anomalies on the premise of providing normal access services, ensuring information security and user experience. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] Figure 1 FIG. is a functional module diagram of a university office information management system according to an embodiment of the invention;

[0047] Figure 2 FIG. is a logical decision diagram for marking a client according to an embodiment of the invention;

[0048] Figure 3 FIG. is a logical decision diagram for determining whether a client is a trusted access client according to an embodiment of the invention;

[0049] Figure 4 FIG. is a logical decision diagram for determining whether to open the access permission of a corresponding information node to a client according to an embodiment of the invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0050] In order to make the objectives and advantages of the present invention clearer, the present invention will be further described below in conjunction with embodiments; it should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0051] The preferred embodiments of the present invention will be described below with reference to the accompanying drawings. Those skilled in the art should understand that these embodiments are only used to explain the technical principles of the present invention and do not limit the protection scope of the present invention.

[0052] It should be noted that in the description of the present invention, terms indicating directions or positional relationships such as "inside" are based on the directions or positional relationships shown in the drawings. This is only for convenience of description and does not indicate or imply that the device or element must have a specific orientation, be constructed and operated in a specific orientation. Therefore, it should not be construed as a limitation to the present invention.

[0053] In addition, it should also be noted that in the description of the present invention, unless otherwise clearly specified and limited, the term "connection" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection. For those skilled in the art, the specific meanings of the above terms in the present invention can be understood according to specific circumstances.

[0054] Please refer to Figure 1 as shown, which is a functional module diagram of the college office information management system according to an embodiment of the present invention. The college office information management system according to an embodiment of the present invention includes:

[0055] A classification and sorting module, which includes a classification unit for dividing the access categories of several user terminals and a sorting unit for sorting the accessible information nodes of each category of user terminals and generating an information node form;

[0056] A behavior storage module, which is used to store the regular operation behavior data of each user terminal;

[0057] An access analysis module, which is connected to the classification and sorting module, and is used to determine the unauthorized access characteristics of the user terminal according to the real-time operation data of the user terminal, analyze the access over-authorization degree characterization value for the user terminal, and mark the user terminal;

[0058] An access verification module, which is respectively connected to the classification and sorting module and the access analysis module, and is used to obtain the weight level of the information node accessed by the user terminal, and determine the prompt verification information sent to the marked user terminal according to the weight level;

[0059] A verification analysis module, which is respectively connected to the behavior storage module and the access verification module, and is used to obtain the movement trajectory range of the input device corresponding to the user terminal and combine the operation behavior characteristics to determine the trusted characterization value of the user terminal, so as to determine whether the user terminal is a trusted access user terminal;

[0060] The permission opening module, which is connected to the verification and analysis module, is used to determine whether to open the access permission of the corresponding information node to the client based on the analysis result of the verification and analysis module;

[0061] Among them, the non-permission access characteristics include the non-permission access depth and the non-permission application access frequency within a predetermined time; the operation behavior characteristics include the access path deviation degree and the network flow port increment.

[0062] Specifically, there is no specific limitation on the classification method adopted by the classification unit, as long as it can distinguish the clients that can access each information node. For example, the clients are divided into student clients, teacher clients, and administrator clients. Of course, other classification methods can also be used, which will not be elaborated here.

[0063] It can be understood that on the premise of dividing the access categories of the clients, the information nodes that the clients can access are used as the accessible information nodes. Then, if the clients access information nodes other than the accessible information nodes, the corresponding accessed information nodes are non-permission access nodes, which will not be elaborated here.

[0064] Specifically, the information node refers to the object that the client can access, interact, etc. within the system.

[0065] Specifically, there is no limitation on the specific structures of the classification and sorting module, the behavior storage module, the access analysis module, the access verification module, the verification and analysis module, and the permission opening module. It itself or each unit therein can be composed of logic components or a combination of logic components. The logic components include field programmable processors, computers, or microprocessors in computers.

[0066] Specifically, the sorting unit is used to sort each of the information nodes in descending order based on the update frequency of the corresponding content of each information node.

[0067] It can be understood that the update frequency usually refers to the number of times the corresponding content of the information node is modified, added, or deleted within a predetermined time period. In this embodiment, a single semester is used as the predetermined time period, which will not be elaborated here.

[0068] It can be understood that for some information nodes with a higher degree of importance and a higher permission level, their corresponding content may involve core key data and generally does not need to be updated and modified frequently. However, for information nodes with a lower weight level and a wider coverage of accessible clients, due to the nature of their data itself, such as the announcement information of various campus activities, they can be updated and modified flexibly. Therefore, in this embodiment, the importance of each information node and the degree of access affected by permissions are characterized according to the update frequency of the corresponding content of each information node, which will not be elaborated here.

[0069] Specifically, the access analysis module is used to analyze the access over-authorization degree characterization value for the client, including:

[0070] Taking the ratio of the non-authorization access depth to the non-authorization access depth threshold as the first access over-authorization feature;

[0071] Taking the ratio of the non-authorization application access frequency within a predetermined time to the non-authorization application access frequency threshold as the second access over-authorization feature;

[0072] Taking the sum of the first access over-authorization feature and the second access over-authorization feature as the access over-authorization degree characterization value for the client.

[0073] Specifically, the purpose of setting the non-authorization access depth threshold and the non-authorization application access frequency threshold is to characterize the situation where the severity of the client's unauthorized access operation is too high. Among them, the non-authorization access depth threshold and the non-authorization application access frequency threshold are obtained by pre-setting. By obtaining the historical operation behavior data of the client, calling the non-authorization access depth historical data and the non-authorization application access frequency historical data, and determining the non-authorization access depth average value and the non-authorization application access frequency average value, it is set that the non-authorization access depth threshold is the product of the non-authorization access depth average value and the first deviation coefficient; the non-authorization application access frequency threshold is the product of the non-authorization application access frequency average value and the second deviation coefficient, where the first deviation coefficient is selected within the interval [1.05, 1.1], and the second deviation coefficient is selected within the interval [1.15, 1.2].

[0074] Specifically, the present invention sets up an access analysis module to analyze the degree of exceeding authority of the access operations performed by the client based on the real-time operation data of the client. In actual situations, the client usually performs regular access operations within its own authority. When the client shows an abnormal situation of frequently accessing information nodes that it does not have access authority to, it indicates that there is a potential abnormality in the client; even more, if the depth of the information nodes that the client accesses without permission is relatively deep in the overall information nodes, it can reflect that the unauthorized behavior of the client is more serious. Therefore, the present invention reflects the abstract degree of the information covered by the information nodes accessed by the client without permission and the extensive degree of the content through the non-authorization access depth; it reflects the intensity of the client's attempt to perform unauthorized access behavior through the non-authorization application access frequency within a predetermined time. Thus, the access over-authorization degree characterization value of the client is analyzed based on the two features to characterize the abnormal degree of the client's access over-authorization, providing data support for subsequent marking of the client. The present invention can verify and identify the access clients with potential abnormalities on the premise of providing normal access services, ensuring information security and user experience.

[0075] Specifically, please refer to Figure 2 As shown, it is a logical decision diagram for the client to be marked in the embodiment of the present invention. The access analysis module is used to mark the client, including

[0076] If there exists an access over-authorization degree characterization value of any client greater than or equal to the access over-authorization degree characterization threshold, then mark the client as an access abnormal client.

[0077] The access over-authorization degree characterization threshold is selected within the interval [2.25, 2.34].

[0078] Specifically, the access verification module is used to obtain the weight level of the information node accessed by the client, including

[0079] Used to call the update frequency of the corresponding content of each information node;

[0080] Used to divide several information node intervals based on each update frequency;

[0081] Used to preset the corresponding relationship between the weight level and the information node interval;

[0082] Used to determine the node interval to which the information node belongs, and determine the weight level corresponding to the node interval as the weight level of the information node;

[0083] Among them, the weight level and the node interval correspond one by one.

[0084] In this embodiment, the information node intervals corresponding to each information node are determined in the following manner:

[0085] The information nodes with an update frequency in the range of [0, 10 times / term) are correspondingly assigned to the first information node interval;

[0086] The information nodes with an update frequency in the range of [10 times / term, 50 times / term] are correspondingly assigned to the second information node interval;

[0087] The information nodes with an update frequency in the range of (50 times / term, +∞) are correspondingly assigned to the third information node interval;

[0088] Based on this, the corresponding relationship between the weight level and the information node interval is determined in the following manner:

[0089] If the information node belongs to the first information node interval, then determine the weight level of the information node as the first weight level;

[0090] If the information node belongs to the second information node interval, then determine the weight level of the information node as the second weight level;

[0091] If the information node belongs to the third information node interval, determine the weight level of the information node as the third weight level;

[0092] Specifically, the access verification module is used to determine the verification prompt information sent to the marked client according to the weight level, including,

[0093] Used to preset the corresponding relationship between the weight level and the verification prompt information;

[0094] Among them, the weight level and the verification prompt information are in one-to-one correspondence.

[0095] In this embodiment, the corresponding relationship between the weight level and the verification prompt information is determined in the following manner:

[0096] If the weight level is the first weight level, send the first verification prompt information;

[0097] If the weight level is the second weight level, send the second verification prompt information;

[0098] If the weight level is the third weight level, send the third verification prompt information;

[0099] Among them, the first verification prompt information includes security question verification;

[0100] The second verification prompt information includes SMS verification code verification;

[0101] The third verification prompt information includes hardware token verification.

[0102] Specifically, the verification analysis module is used to determine the trusted representation value corresponding to the access operation, including,

[0103] Used to take the ratio of the farthest distance between the input device and the edge of the input box to the farthest distance threshold as the first trusted feature;

[0104] Used to take the ratio of the access path deviation degree to the access path deviation degree threshold and the ratio of the network flow port increment to the increment threshold as the second trusted feature;

[0105] Used to perform weighted summation of the first trusted feature and the second trusted feature as the trusted representation value;

[0106] Among them, the farthest distance between the input device and the edge of the input box is determined according to the movement trajectory range of the input device corresponding to the client, and the access path deviation degree is determined by comparing the real-time operation data of the client with the conventional operation behavior data.

[0107] It can be understood that when the client feedbacks and verifies the prompt information, the correct verification content needs to be input in the corresponding input box to prove the authenticity of the identity to the system background. Based on this, when the client inputs the verification content, the virtual reference of the input device is usually placed inside or at the edge of the input box. If the position where the virtual reference is located is far from the input box, it may indicate that the client currently performing the operation has an abnormal operation of avoiding or attempting to skip the feedback verification prompt information, thereby reducing the trust level of the client. Therefore, in this embodiment, the maximum distance between the input device and the edge of the input box is used to characterize the response degree of the client to the feedback verification information, and thus the security level of the client. Among them, the input device includes a mouse, and the virtual reference includes the arrow corresponding to the mouse, which will not be elaborated here.

[0108] In this embodiment, when performing weighted summation, the weight of the first trusted feature is set to 0.4, and the weight of the second trusted feature is set to 0.6;

[0109] Specifically, the purpose of setting the maximum distance threshold between the input device and the edge of the input box, the access path deviation degree threshold, and the network flow port increment threshold is to characterize the situation where the abnormal degree of the client is too high and the trust level is too low. The maximum distance threshold between the input device and the edge of the input box, the access path deviation degree threshold, and the network flow port increment threshold are obtained by pre-setting. The historical data of the client completing several feedback verification information is obtained, and the average value of the maximum distance between the input device and the edge of the input box is determined. It is set that the maximum distance threshold between the input device and the edge of the input box is the product of the average value of the maximum distance between the input device and the edge of the input box and the distance deviation coefficient;

[0110] The conventional operation behavior data of the client is obtained, the access path deviation degree data and the network flow port increment data are called, and the average value of the access path deviation degree and the average value of the network flow port increment are solved. It is set that the access path deviation degree threshold is the product of the average value of the access path deviation degree and the first operation offset coefficient, and the network flow port increment threshold is the product of the average value of the network flow port increment and the second operation offset coefficient. Among them, the distance deviation coefficient is selected within the interval [1.1, 1.2], the first operation offset coefficient is selected within the interval [1.15, 1.25], and the second operation offset coefficient is selected within the interval [1.5, 1.8].

[0111] Specifically, the present invention sets up a verification and analysis module to analyze the trust level of the client by obtaining the operation behavior characteristics of the client and combining the movement track range of the corresponding input device. When there is a situation where the client frequently applies to access non-permission information nodes, or the access depth of the accessed non-permission information nodes is relatively deep, it is considered that the client may be stolen or logged in from a different location. Under normal circumstances, a trusted client will promptly provide a verification feedback according to the verification prompt information after receiving it, rather than performing unconventional operations such as trying to skip or avoid it. The security level of the client operation reflected by the feedback verification is determined based on the distance between the input device and the input box when the client should provide a feedback verification prompt. At the same time, the matching situation between the real-time operation data of the client and the conventional operation behavior data is considered. A normal client usually operates according to a certain logic and workflow. For example, the order of accessing several information nodes. If the access path of the client is chaotic and frequently jumps to access different information nodes, it may indicate that the client is not a normal trusted client. And during the use of the system, corresponding data transmission interactions will occur. Under normal circumstances, the operation transmission based on the category of a normal client is relatively fixed. Therefore, the trust representation value is determined by combining the access path deviation degree, the network flow port increment, and the maximum distance between the input device and the edge of the input box to represent the trust level and security level of the client, providing data support for subsequent determination of whether the client is a trusted access client. The present invention can verify and identify access clients with potential abnormalities on the premise of providing normal access services, ensuring information security and user experience.

[0112] Specifically, please refer to Figure 3 As shown, it is a logical decision diagram for the present invention embodiment to determine whether the client is a trusted access client. The verification and analysis module is used to determine whether the client is a trusted access client, including

[0113] If the trust representation value of the client is less than the trust representation threshold, the client is determined to be a trusted access client;

[0114] If the trust representation value of the client is greater than or equal to the trust representation threshold, the client is determined to be a non-trusted access client.

[0115] The trust representation threshold is selected within the range of [1.78, 1.86].

[0116] Specifically, please refer to Figure 4As shown, it is a logical decision diagram for the embodiment of the present invention to determine whether to open the access permission of the corresponding information node to the client. The permission opening module is used to determine whether to open the access permission of the corresponding information node to the client, including:

[0117] If the client is a trusted access client, the access permission of the corresponding information node to the client is opened;

[0118] If the client is a non-trusted access client, the access permission of the corresponding information node to the client is restricted.

[0119] Specifically, by determining the semantic generalization degree of the information node name corresponding to the information node accessed by the client, the non-permission access depth is obtained;

[0120] Among them, the information node name is obtained through the information node form.

[0121] It can be understood that an information node corresponds to an information node name, and the importance and core degree of the content corresponding to the information node can be reflected by the abstraction degree of the information node name. Therefore, in this embodiment, the access depth of the information node accessed by the client is determined by analyzing the semantic generalization degree of each information node name. Correspondingly, if the information node accessed by the client is a non-permission access node, the semantic generalization degree of the information node name corresponding to the non-permission access node is determined as the non-permission access depth, which will not be elaborated here.

[0122] Specifically, there is no limitation on the method for determining the semantic generalization degree of each information node name. In some possible implementations, through the word vector model in natural language processing (NLP) technology, such as Word2Vec, GloVe, etc., words are mapped into a low-dimensional vector space, and words with similar semantics are closer in the vector space. Therefore, by calculating the vectors of the words in the information node name, the richness and coverage of its semantics are analyzed; if the word vector of the information node name has a higher similarity with more different types of related vocabulary vectors, it indicates that its semantic generalization degree is higher; specifically, it can be determined by the following method: First, use the pre-trained word vector model to obtain the vector representation of each word in the information node name; then, calculate the relationship between these word vectors and the similarity with other related vocabulary vectors; the semantic generalization degree is measured by calculating the cosine similarity between the vectors, and the semantic generalization degree is used as the non-permission access depth.

[0123] So far, the technical solution of the present invention has been described in conjunction with the preferred embodiments shown in the accompanying drawings. However, it is easily understood by those skilled in the art that the protection scope of the present invention is obviously not limited to these specific embodiments. Without departing from the principle of the present invention, those skilled in the art can make equivalent changes or substitutions to the relevant technical features, and the technical solutions after these changes or substitutions will fall within the protection scope of the present invention.

Claims

1. A college office information management system, characterized in that, Including: A classification and sorting module, which includes a classification unit for classifying the access categories of several client terminals and a sorting unit for sorting the accessible information nodes of each category of client terminals and generating an information node form; A behavior storage module for storing the regular operation behavior data of each client terminal; An access analysis module, which is connected to the classification and sorting module, for determining the unauthorized access characteristics of the client terminal according to the real-time operation data of the client terminal, analyzing the access overstep degree characterization value for the client terminal, and marking the client terminal; An access verification module, which is respectively connected to the classification and sorting module and the access analysis module, for obtaining the weight level of the information node accessed by the client terminal, and determining the prompt verification information sent to the marked client terminal according to the weight level; A verification analysis module, which is respectively connected to the behavior storage module and the access verification module, for obtaining the moving track range of the input device corresponding to the client terminal and combining the operation behavior characteristics to determine the trusted characterization value of the client terminal, so as to determine whether the client terminal is a trusted access client terminal; A permission opening module, which is connected to the verification analysis module, for determining whether to open the access permission of the corresponding information node to the client terminal based on the analysis result of the verification analysis module; Wherein, the unauthorized access characteristics include the unauthorized access depth and the unauthorized access request frequency within a predetermined time; the operation behavior characteristics include the access path deviation degree and the network flow port increment.

2. The university office information management system according to claim 1, characterized in that The sorting unit is used to sort each of the information nodes in descending order based on the update frequency of the corresponding content of each information node.

3. The college office information management system according to claim 1, characterized in that, The access analysis module is used to analyze the access overstep degree characterization value for the client terminal, including, Using the ratio of the unauthorized access depth to the unauthorized access depth threshold as the first access overstep feature; Using the ratio of the unauthorized access request frequency within a predetermined time to the unauthorized access request frequency threshold as the second access overstep feature; Using the sum of the first access overstep feature and the second access overstep feature as the access overstep degree characterization value of the client terminal.

4. The university office information management system according to claim 1, characterized in that, The access analysis module is used to mark the client terminal, including, If the access overstep degree characterization value of any client terminal is greater than or equal to the access overstep degree characterization threshold, then mark the client terminal as an access abnormal client terminal.

5. The college office information management system according to claim 1, characterized in that, The access verification module is used to obtain the weight level of the information node accessed by the client terminal, including, Used to call the update frequency of the corresponding content of each information node; Used to divide several information node intervals based on each of the update frequencies; Used to preset the corresponding relationship between the weight level and the information node interval; Used to determine the node interval to which the information node belongs, and determine the weight level corresponding to the node interval as the weight level of the information node; Wherein, the weight level corresponds one-to-one with the node interval.

6. The college office information management system according to claim 5, wherein The access verification module is used to determine the verification prompt information sent to the marked client terminal according to the weight level, including, Used to preset the corresponding relationship between the weight level and the verification prompt information; Among them, the weight levels correspond one by one to the verification prompt messages.

7. The college office information management system according to claim 1, characterized in that, The verification analysis module is used to determine the trusted representation value corresponding to the access operation, including: using the ratio of the maximum distance between the input device and the edge of the input box to the maximum distance threshold as the first trusted feature; using the ratio of the access path deviation degree to the access path deviation degree threshold and the ratio of the network flow port increment to the increment threshold as the second trusted feature; using the weighted sum of the first trusted feature and the second trusted feature as the trusted representation value; Among them, the maximum distance between the input device and the edge of the input box is determined according to the movement trajectory range of the input device corresponding to the client, and the access path deviation degree is determined by comparing the real-time operation data of the client with the conventional operation behavior data.

8. The college office information management system according to claim 1, wherein, The verification analysis module is used to determine whether the client is a trusted access client, including: if the trusted representation value of the client is less than the trusted representation threshold, then the client is determined as a trusted access client.

9. The college office information management system according to claim 1, characterized in that The permission opening module is used to determine whether to open the access permission of the corresponding information node to the client, including: if the client is a trusted access client, then open the access permission of the corresponding information node to the client.

10. The college office information management system according to claim 1, characterized in that, The non-permission access depth is obtained by determining the semantic generalization degree of the information node name corresponding to the information node accessed by the client; Among them, the information node name is obtained through the information node form.

Citation Information

Patent Citations

  • Smart school system and smart school system application method

    CN116245270A