Access security management method and system based on data management

Through multi-level encryption, smart contracts and multi-party computing technology, combined with SIFT feature matching and Delaunay triangulation method, facial verification is solved, and the lack of dynamic and security in existing access control technologies is realized, high-precision authentication and dynamic permission management are achieved, and access control flexibility and security are improved.

CN120296758AInactive Publication Date: 2025-07-11HEFEI ZHICHENG INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510328883.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-19
Publication Date
2025-07-11
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Existing access control technologies cannot meet the highly dynamic and complex access control needs, lack refined management and multi-factor authentication, and there is a problem of weak security in key management.

Method used

Multi-level encryption technology and smart contracts are adopted, and face verification is carried out in combination with SIFT feature matching and Delaunay triangulation methods, multi-party computing management keys are used to decrypt, and refined access control based on attributes and behavioral analysis is realized through smart contracts, and intelligent auditing and risk assessment are carried out in combination with blockchain technology.

Benefits of technology

It realizes high-precision authentication and dynamic permission management, improves the flexibility and security of access control, ensures the uniqueness of user identity and the immutability of data, and enhances the system's anti-attack capabilities and data security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120296758A_ABST
    Figure CN120296758A_ABST
Patent Text Reader

Abstract

The invention discloses an access security management method and system based on data management, and relates to the technical field of data security, and the method comprises the steps: collecting data, carrying out the multi-level encryption, storing the data in an external storage system, achieving the refined access control based on attribute and behavior analysis through a smart contract, and enabling a user to access when the user applies for access. Face verification is carried out based on rigid transformation in combination with an SIFT feature matching method and a Delaunay triangulation method, fingerprint verification is carried out, and a secret key decryption process is managed by using an intelligent contract in combination with multi-party computing. The intelligent contract is combined with user attributes and behavior analysis to realize more refined access control, accurate authority verification is performed on the user through a multi-level encryption and rigid change method and an SIFT feature matching technology, so that the safety of the user identity and the accuracy of the access authority are ensured, the authority is dynamically adjusted according to real-time behaviors, and the user experience is improved. And in combination with a multi-verification technology and a block chain technology, the security and reliability of data access are remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security, and particularly to an access security management method and system based on data management. Background Art

[0002] With the rapid development of information technology, data security and access control have become crucial links in information systems. With the popularization of technologies such as big data, cloud computing, and the Internet of Things, the security threats and privacy leakage risks faced by various types of sensitive data are increasing day by day. Traditional access control methods often can only achieve simple control based on static permissions and cannot flexibly meet complex security requirements. In recent years, security control methods based on data management have received extensive attention. Among them, access control methods that combine smart contracts and multi-level encryption technologies have shown great potential in data protection and management. These methods enhance the security and transparency of data access by strengthening data encryption and authorization verification and using blockchain technology to ensure the immutability of data.

[0003] Existing technologies still have deficiencies in the refined management of access permissions and multi-factor authentication and cannot fully meet the highly dynamic and complex access control requirements. In traditional access control systems, although there are also solutions that combine multi-factor authentication (such as passwords, fingerprints, facial recognition, etc.), they often lack refined access control based on user behavior and attributes. On the other hand, although existing encryption technologies can ensure the security of data transmission and storage, they often face problems such as key leakage and single-point failures in key management and access decryption processes. In particular, the singularity of key generation and storage easily leads to weak system security. Therefore, existing technologies often cannot cope with complex security problems in large-scale distributed environments and are difficult to monitor and manage users' behaviors in real time and in a refined manner. Summary of the Invention

[0004] In view of the above existing problems, the present invention is proposed.

[0005] Therefore, the present invention provides an access security management method and system based on data management, which solves the deficiencies of existing technologies in the refined management of access permissions and multi-factor authentication and cannot fully meet the highly dynamic and complex access control requirements. Most existing access security management technologies rely on static permission settings and single authentication methods. To solve the above technical problems, the present invention provides the following technical solutions:

[0006] In a first aspect, the present invention provides an access security management method based on data management, which includes collecting data, performing multi-level encryption on the data, and storing the data in an external storage system, and implementing refined access control based on attribute and behavior analysis through a smart contract;

[0007] When a user applies for access, facial verification is performed based on rigid transformation combined with SIFT feature matching method and Delaunay triangulation method, and fingerprint verification is performed. The key decryption process is managed using smart contracts combined with multi-party computing;

[0008] Store the access records of authorized users in an external storage system and conduct intelligent auditing and risk assessment on the stored data.

[0009] As a preferred solution of the access security management method based on data management described in the present invention, wherein: the data collection and multi-level encryption followed by storage in an external storage system refers to collecting historical and real-time data from various data sources and pre-processing them, and the access rights to the data are generated through a key generation center to generate an encryption key to obtain a public key KG;

[0010] Use hash function algorithm to calculate the intermediate value in the encryption step , using the public key KG Encrypt and get the encrypted data ciphertext ;

[0011] Use Shamir's secret sharing algorithm to construct a shared key polynomial based on the private key K. , distribute the generated shared key to each key provider.

[0012] As a preferred solution of the access security management method based on data management described in the present invention, wherein: the implementation of refined access control based on attribute and behavior analysis through smart contracts refers to deploying a smart contract on the blockchain, and the smart contract sets access rules and defines hierarchical access rights based on the collected user attributes and historical behavior data;

[0013] The hierarchical access rights include primary user access rights, secondary user access rights and tertiary user access rights.

[0014] As a preferred solution of the access security management method based on data management described in the present invention, when the user applies for access, facial verification is performed based on rigid transformation combined with SIFT feature matching method and Delaunay triangulation method, and fingerprint verification is performed. The user initiates a data access request through an application, and the smart contract first verifies the integrity of the requested data and verifies the access rights based on the user's identity information;

[0015] After the first-level user passes the verification, the camera is used to obtain the user's facial 2D image, and the training data set with the coordinates of the facial key points is used to train the convolutional neural network. The pre-processed facial image is input into the trained convolutional neural network, and the coordinates of each facial 2D feature point are output;

[0016] The user's facial data from different angles is acquired through 3D image capture technology and preprocessed. The point cloud stitching and alignment technology is used to obtain the complete 3D facial point cloud. One of the multi-viewpoint clouds is selected as the reference point cloud P, and the others are used as the target point cloud Q. For the target point cloud Q, the rotation matrix R and the translation vector t are solved by using the rigid transformation method with the minimized error function.

[0017] The optimal rotation matrix is calculated by using the Kabsch algorithm through aligning the central points of the two point sets. The optimal translation vector is calculated by using the least squares method. ;

[0018] The optimal rotation matrix is obtained through calculation. and the translation vector , the position coordinates in all target point clouds Q are updated to minimize the error between the two point clouds, generating more accurate 3D point cloud feature point coordinates.

[0019] Using the SIFT feature matching method, the feature point coordinates in the 2D image are corresponded to the 3D point cloud feature point coordinates. The feature point data in the 2D image is input into the shape regression model to obtain the mapped 3D point cloud feature point coordinates and integrated to generate a coordinate set. ;

[0020] The optimized 3D feature point coordinate set is segmented into multiple non-overlapping triangles by using the Delaunay triangulation method, and the geometric stability of the mesh is optimized by maximizing the minimum angle of each triangle. ;

[0021] Using the Laplacian smoothing method, the neighborhood vertex set of each vertex in the mesh is calculated, and the average value of the spatial coordinates of all neighborhood vertices is obtained to update each vertex. According to the updated vertex positions, the mesh shape is optimized to obtain the complete 3D facial model.

[0022] The 3D facial model generated by the user is transmitted to the blockchain. The similarity calculation method using the Euclidean distance is used to compare the existing facial database template with the newly generated 3D facial model. The distance threshold T is set. If the Euclidean distance is less than or equal to the threshold T, it indicates that the comparison is successful and the user identity verification is passed; otherwise, the verification fails and the access is refused.

[0023] After the user passes the facial identity verification, fingerprint recognition is required to verify the identity again.

[0024] As a preferred solution of the access security management method based on data management according to the present invention, wherein: the process of decrypting the key by using a smart contract in combination with multi-party computing means that after the user passes the permission verification, the smart contract sends a merging request to multiple key providers, and after receiving all the key parts, the held key parts are merged through the multi-party computing protocol to obtain the complete private key K, and the data is decrypted to obtain the plaintext data.

[0025] As a preferred solution of the access security management method based on data management according to the present invention, wherein: storing the access records of authorized users in an external storage system means that after the permission verification is successful, the smart contract automatically collects the access data and forms an access record, and uses the SHA256 algorithm to generate the hash value of the access record.

[0026] As a preferred solution of the access security management method based on data management according to the present invention, wherein: the intelligent auditing and risk assessment of the stored data means that in combination with blockchain technology, all the behavior data is audited, an unsupervised learning model is used to evaluate the user's behavior pattern and a risk score is generated through the isolation forest method, and a security threshold U is set. If the user risk score exceeds the set security threshold U, an alarm will be triggered and additional identity verification will be required. After the identity verification is successful, the smart contract will automatically restore the user's permission, otherwise the permission will continue to be restricted.

[0027] In a second aspect, the present invention provides an access security management system based on data management, including

[0028] A data management module, configured to collect data source information and encrypt the data by using an encryption algorithm;

[0029] An access control module, configured to define user access permissions and implement refined access management;

[0030] An identity verification module, configured to use various identity verification methods to ensure the authenticity of the user identity;

[0031] A decryption module, configured to decrypt the encrypted data to ensure that when the user accesses the data, the user can unlock and obtain the authorized information;

[0032] An auditing and risk assessment module, configured to audit the user's access records, monitor the user's behavior in real time and conduct risk assessment.

[0033] In a third aspect, the present invention provides a computer device, including a memory and a processor, wherein: when the computer program stored in the memory is executed by the processor, any step of the access security management method based on data management as described in the first aspect of the present invention is implemented.

[0034] Fourthly, the present invention provides a computer-readable storage medium with a computer program stored thereon, wherein: when the computer program is executed by a processor, any step of the access security management method based on data management as described in the first aspect of the present invention is implemented.

[0035] The beneficial effects of the present invention are as follows: By introducing multi-factor authentication and combining smart contracts with multi-party computing technology, the deficiencies in the prior art are made up, and a more flexible and secure access control mechanism is provided. Specifically, based on the rigid transformation combined with the SIFT feature matching method and the Delaunay triangulation method for face verification, and fingerprint recognition verification is carried out again to ensure the uniqueness and security of the user identity. During the identity verification process, by combining the rigid transformation and the SIFT feature matching method, high-precision three-dimensional face recognition is achieved, improving the reliability of the entire verification process; In addition, through smart contracts, refined access control based on user behavior and attributes is realized, and the access permissions of different levels of users will be dynamically adjusted according to behavior analysis and historical data, ensuring that the access permissions are more timely and reasonable, making the permissions no longer statically set, but updated and controlled in real time; Therefore, the present invention provides a more flexible, secure and dynamic access control method, which adapts to the highly dynamic and complex access control requirements. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for the description of the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention, and those of ordinary skill in the art can obtain other drawings based on these drawings without creative efforts.

[0037] Figure 1 It is a flowchart of an access security management method based on data management in Embodiment 1.

[0038] Figure 2 It is a schematic structural diagram of an access security management system based on data management in Embodiment 1. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0039] To make the above objects, features and advantages of the present invention more obvious and understandable, the specific embodiments of the present invention will be described in detail below with reference to the drawings in the specification.

[0040] Many specific details are set forth in the following description in order to provide a thorough understanding of the present invention, but the present invention may be implemented in other ways different from those described herein. Those skilled in the art can make similar extensions without departing from the connotation of the present invention, so the present invention is not limited by the specific embodiments disclosed below.

[0041] Second, the "one embodiment" or "embodiment" referred to herein means a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The appearances of "in one embodiment" in different places in this specification do not all refer to the same embodiment, nor are they separate or alternative embodiments that are mutually exclusive of other embodiments.

[0042] Embodiment 1, referring to Figure 1 and Figure 2 , is the first embodiment of the present invention. This embodiment provides an access security management method based on data management, including the following steps:

[0043] S1. Collect data, perform multi-level encryption, and then store the data in an external storage system, and implement fine-grained access control based on attribute and behavior analysis through a smart contract;

[0044] Specifically, collecting data, performing multi-level encryption, and storing the data in an external storage system means collecting historical and real-time data from each data source, performing data preprocessing, generating an encryption key for the access right of the data through a Key Generation Center (KGC). During the key generation process, an elliptic curve E and a prime number field are used , defining two parameters a, b and a base point G(x, q) on the curve, and randomly generating a private key K within the prime number field , performing a dot product operation on the private key K and the base point G to obtain a public key KG;

[0045] The elliptic curve E is a mathematical curve described by the following equation: b, where a and b are two parameters of the curve used to define the shape of the curve, x and y are the coordinates of the points on the curve, and the prime number field is a finite field representing the set of all integers p. The base point G(x, q) is a point defined on the field, and the coordinates (x, q) satisfy the elliptic curve equation. The dot product is a mathematical operation used to generate a public key by multiplying a scalar by the base point;

[0046] Adopt a hash function algorithm to pad the original data m to a fixed length and calculate multiple intermediate values in the encryption step:

[0047]

[0048] ,

[0049] wherein, and are random functions, r is a random number, is the original data after padding, is the calculated intermediate value, is obtained by As input, the intermediate value obtained by XOR operation; ⊕ represents the XOR operation;

[0050] Use the public key KG to perform encryption to obtain the encrypted data ciphertext , and the formula is:

[0051] ,

[0052] where is the encryption operator, indicating the operation of using the public key KG to perform encryption, and are intermediate values generated during the encryption process;

[0053] Store the public key KG and the data ciphertext in an external storage system;

[0054] Use the Shamir secret sharing algorithm to split the private key into multiple parts. Each part after splitting is called a shared key. According to the private key K, construct a polynomial of the shared key :

[0055] ,

[0056] where a is a randomly selected coefficient, s is a unique integer value specified in each shared key, is the exponent of the highest-degree term in the polynomial;

[0057] Calculate the values of the polynomial at different s points, which are the shared keys. Distribute the generated shared keys to each key provider. Each key provider can only access the part of the key stored by itself, and each shared key is stored on the server of a different key provider;

[0058] The data source information includes personal data input by users, sensor data of devices, usage frequency, network traffic logs, and system error logs.

[0059] A multi - level encryption method that combines elliptic curve encryption and Shamir secret sharing algorithm is adopted to solve the problem of key management in traditional technologies. Elliptic curve encryption generates keys by using an elliptic curve (E) and a base point G within a prime field. The public key KG is generated by the dot - product operation of the private key and the base point. This method not only improves security but also has a smaller key size, faster encryption speed and shorter key length compared with the traditional RSA encryption method, making it suitable for high - concurrency environments. At the same time, the Shamir secret sharing algorithm divides the private key into multiple parts and stores them separately on different key - providing servers. Even if an individual server is attacked, the attacker cannot obtain the complete private key alone. The private key can only be restored when multiple key - providing parties operate jointly, thus enhancing the security of key management and improving the anti - attack ability of the system.

[0060] Furthermore, implementing fine - grained access control based on attribute and behavior analysis through smart contracts means deploying a smart contract on the blockchain. The smart contract sets access rules to define hierarchical access permissions according to the collected user attributes (including user roles, devices) and historical behavior data (including access frequency, login time, access resource types):

[0061] The access permission for first - level users has no time limit and they can access all resources;

[0062] The access permission for second - level users is that they can only access specific resources (including technical documents, financial data, transaction records, R & D data) during working hours. The access permission will be verified according to the constraints of working hours, and access will be denied outside working hours. A threshold for the number of accesses is set (by calculating the standard deviation of the average frequency of the user's historical behavior data, setting a fixed upper limit), and the number of times of accessing sensitive data (including personal identity information, financial information, account vouchers) within a specified time period (such as within 1 hour) cannot exceed the set threshold ;

[0063] The access permission for third - level users is that they can only view access logs during working hours and cannot access core data (including business - critical data, security data).

[0064] By introducing smart contracts and refined access control based on behavior analysis, the limitations of traditional static access control are broken through. Smart contracts are deployed on the blockchain, combined with user attributes and historical behavior data, to dynamically adjust access permissions, so as to allocate different permissions to users according to different scenarios (such as working hours, access frequency, resource sensitivity, etc.), improving the flexibility and security of the system. At the same time, the combination of behavior analysis and real-time permission adjustment, by monitoring the user operation mode and generating a risk level, can trigger an alarm and require additional authentication when the user behavior exceeds the security threshold to ensure permission restoration or restriction, significantly enhancing the system's protection ability against potential risks.

[0065] S2. When a user applies for access, facial verification is performed based on rigid transformation combined with the SIFT feature matching method and the Delaunay triangulation method, and fingerprint verification is carried out. The smart contract is used to manage the key decryption process in combination with multi-party computation.

[0066] Specifically, when a user applies for access, 3D facial verification and fingerprint verification technologies are used, and the rigid transformation and the SIFT feature matching method are combined to verify the user's permissions. It means that the user initiates a data access request through an application (the request includes the user's identity information, the resource to be accessed, and the request time data). The smart contract first verifies the integrity of the request data and verifies the access permissions according to the user's identity information.

[0067] After the first-level user passes the verification, a two-dimensional facial image of the user is obtained using a camera. The training data set with the coordinates of facial feature points (including facial feature information such as face contour, eyes, nose bridge, and mouth) is used to train a convolutional neural network (CNN). The preprocessed facial image is input into the trained convolutional neural network, and the coordinates of each two-dimensional facial feature point are output.

[0068] The user's facial data at different angles is obtained through 3D image capture technology and preprocessed. The point cloud stitching and alignment technology is used to obtain a complete 3D facial point cloud. One of the multi-viewpoint clouds is selected as the reference point cloud P, and the others are used as the target point cloud Q. Based on the nearest neighbor matching method, the point closest to each point in the target point cloud Q is found in the reference point cloud P. The calculation formula is:

[0069] ,

[0070] Among them, is the coordinate in the i-th target point cloud, is the coordinate in the -th reference point cloud, is the target point and the reference point Indicates the operation of obtaining the minimum distance;

[0071] Solve the rotation matrix R and translation vector t by using the minimization error function through the rigid transformation method. The calculation formula is:

[0072] ,

[0073] where R is the rotation matrix, t is the translation vector, and n is the number of points in the point cloud;

[0074] Calculate the optimal rotation matrix by aligning the center points of two point sets using the Kabsch algorithm , and the calculation formula is:

[0075] ,

[0076] Calculate the optimal translation vector using the least squares method , and the calculation formula is:

[0077] ,

[0078] Calculate the obtained optimal rotation matrix and translation vector , and update the position coordinates in all target point clouds Q. The calculation formula is:

[0079] ,

[0080] where, is the point in the target point cloud after transformation, is the original point in the target point cloud;

[0081] Minimize the error between each point cloud by optimizing the point cloud coordinates to generate more accurate three-dimensional point cloud feature point coordinates;

[0082] Use the SIFT feature matching method to correspond the feature point coordinates in the two-dimensional image with the three-dimensional point cloud feature point coordinates. Establish a shape regression model through the training data set (the training data set includes the known corresponding relationship between the two-dimensional image feature points and the three-dimensional point cloud feature points), and input the feature point data in the two-dimensional image into the shape regression model to obtain the mapped three-dimensional point cloud feature point coordinates and integrate them to generate a coordinate set ;

[0083] Use the Delaunay triangulation method to divide the optimized three-dimensional feature point coordinate set into multiple non-overlapping triangles. The inscribed and circumscribed circles of each triangle represent the circumscribed circle of the triangle. It is required that any point coordinate cannot be located inside the circumscribed circle of the triangle. Optimize the geometric stability of the grid by maximizing the minimum angle of each triangle. The calculation formula is as follows:

[0084] ,

[0085] Among them, , , are the three vertices of a triangle, , and are indices indicating the positions of the three different vertices of the triangle in the entire grid, is the minimum angle of the th triangle in the grid, is the minimum value among the minimum angles of all triangles in the grid, is the index representing the position of each triangle in the grid, is to maximize the minimum angle;

[0086] Calculate the set of neighboring vertices of each vertex in the grid using Laplace smoothing method, and update each vertex by finding the average of the spatial coordinates of all neighboring vertices. The calculation formula is as follows: , ,

[0087] Among them, is the position of the th updated vertex, is the number of neighboring points, is the position coordinate of the th neighboring vertex;

[0088] Optimize the grid shape according to the updated vertex positions. Through texture mapping technology, map the color information of the 2D image to the surface of the 3D grid to obtain the constructed 3D facial model;

[0089] Transfer the user-generated 3D facial model to the blockchain, and use the similarity calculation method of Euclidean distance to compare the existing facial database template with the newly generated 3D facial model. The formula is as follows:

[0090] ,

[0091] Among them, A is the Euclidean distance between the 3D facial model and the facial template stored in the database, and are the coordinates of the th feature points in the 3D facial model and the facial template respectively, is the total number of feature point coordinates;

[0092] Set a distance threshold T (set by calculating the mean and standard deviation of the Euclidean distances in the training dataset). If the Euclidean distance A is less than or equal to the set threshold T, it indicates a successful comparison and the user's identity verification passes; otherwise, the verification fails and access is denied.

[0093] After the user passes the facial identity verification, fingerprint recognition is required to verify the identity. This process includes using fingerprint recognition technology to extract the user's fingerprint image (the fingerprint image contains ridges and minutiae), preprocessing the fingerprint image using image edge detection processing technology, compressing the ridges to a single-pixel width through the Zhang-Suen algorithm, and extracting the ridge structure of the fingerprint (the ridge is the basic feature of the fingerprint, and the ridge pattern of each fingerprint is unique). Use the ridge tracing method to calculate the local neighborhood of the ridges, determine the positions of the endpoints and bifurcation points (the endpoint is the end of the ridge and has only one adjacent pixel point, and the bifurcation point is the bifurcation of the ridge and has three or more adjacent pixel points). Take the coordinates of each endpoint and bifurcation point as feature points to construct a fingerprint feature vector, and compare the fingerprint features submitted by the user with the pre-stored fingerprint template. This process measures the directional similarity between the two vectors by calculating the angle between them using cosine similarity. The formula for cosine similarity is:

[0094] ,

[0095] where J is the cosine similarity, and are the fingerprint feature vectors submitted by the user and the fingerprint template feature vectors stored in the database, is the dot product of the two vectors, and are the magnitudes of the vectors;

[0096] The value of cosine similarity is between [0, 1]. 1 indicates exactly the same direction, and 0 indicates that the two vectors are orthogonal (i.e., completely different). Set a threshold θ (obtained through cross-validation using a large number of training samples). If the cosine similarity is greater than or equal to the set threshold θ, the verification is successful. If the cosine similarity is less than the set threshold θ, the user's access is denied.

[0097] The smart contract verifies the integrity of the user access request to ensure that the request data has not been tampered with. By combining 3D face verification and fingerprint verification technologies, it accurately verifies the user's identity and provides a more secure and efficient data access permission management solution. During the identity verification process, the rigid transformation optimizes the three-dimensional face data through the rotation matrix and translation vector to ensure the alignment of the data with the face image. The SIFT feature matching further optimizes the matching between the two-dimensional face image and the three-dimensional point cloud, solving the deviation problem in traditional face recognition. The combination of these two methods enables the precise correspondence between the two-dimensional image and the three-dimensional face data, which is the basis for high-precision face recognition and modeling. The Delaunay triangulation optimizes the face mesh structure, making the three-dimensional model smoother, while the Laplace smoothing rule finely adjusts the vertex positions of the mesh, further improving the stability and accuracy of the model. Through the close combination of these technical methods, a multi-level security protection system is formed to ensure the effective management and protection of data security while performing high-precision identity verification, ultimately resulting in an intelligent and efficient access control system.

[0098] Furthermore, using a smart contract combined with multi-party computation to manage the key decryption process means that after the user passes the permission verification, the smart contract sends a merge request to multiple key providers. After receiving all the key parts, the held key parts are merged through the multi-party computation (MPC) protocol to obtain the complete private key K. The smart contract will use this key to decrypt the target data C. The decryption process is as follows:

[0099]

[0100] Where C is the ciphertext data (encrypted data), is the key used for decryption (the merged key), and D is the decrypted data;

[0101] After decryption, the data becomes plaintext for legitimate users to access.

[0102] During the decryption process, the smart contract automatically coordinates multiple key providers to merge their respective held key parts through multi-party computation to obtain the complete private key K, and then decrypts the ciphertext data C, ensuring the secure decryption of the data without exposing the private key. This process avoids the risk of trusting a single key storage party in traditional methods and realizes automated management through the smart contract, reducing manual operations and potential management vulnerabilities. Through this innovative method, the present invention not only improves the security of the data encryption and decryption processes but also enhances the anti-attack ability of the system, ensuring the security and privacy protection of sensitive data.

[0103] S3. Store the access records of authorized users in an external storage system and perform intelligent auditing and risk assessment on the stored data;

[0104] Specifically, storing the access records of authorized users in an external storage system means that after successful permission verification, the smart contract automatically collects access data and forms an access record, generates a hash value of the access record using the SHA256 algorithm. Before storage, the server calculates the hash value and checks whether the hash value already exists. If the data already exists, duplicate storage is avoided. If the data is new, the storage process continues.

[0105] Combining the smart contract and the SHA256 hash algorithm significantly improves the security and efficiency of data storage when storing the access records of authorized users. In traditional access record storage methods, data duplication or tampering is likely to occur. However, in the present invention, by calculating the hash value of each access record and performing verification before storage, the uniqueness of each record is ensured. When the hash value of an access record already exists, the system avoids duplicate storage, thereby reducing waste of storage space and improving data processing efficiency. When the smart contract automatically collects and stores access records, it not only improves management efficiency but also ensures the transparency and traceability of the records. This improvement effectively enhances the security of the system, safeguards the integrity of user data, and ensures the efficient operation of the system.

[0106] Furthermore, intelligent auditing and risk assessment of the stored data means combining blockchain technology. All access records and permission changes will be uploaded to the blockchain. The smart contract will automatically collect and audit (analyze user operation behaviors such as access frequency and type, access time period, and the user's historical risks to identify any abnormal behaviors and potential security threats) the user's behavior data, use historical data to train an unsupervised learning model, and evaluate the user's behavior pattern through the trained model. The isolation forest method (using multiple trees to "isolate" data, each tree is constructed on different sub-datasets, and data points are "isolated" by randomly selecting features and split points. The degree of "isolation" is used to determine whether a point is abnormal. The shorter the isolation path length, the more abnormal the behavior. The range of the anomaly score is [0, 1], where a score close to 1 indicates a high degree of abnormality, and a score close to 0 indicates that the behavior is normal) is used to calculate the risk score based on the isolation path length of each behavior pattern data point. The access permission is adjusted according to the user's risk score, and a security threshold U (obtained by calculating the security threshold through a machine learning model based on the user's historical behavior data) is set. If the user's risk score exceeds the set security threshold U, an alarm will be triggered and additional identity verification will be required. After successful identity verification, the smart contract will automatically restore the user's permission; otherwise, the permission will continue to be restricted.

[0107] By integrating blockchain technology, intelligent auditing, and risk assessment mechanisms, the security and intelligent management capabilities of the access control system have been significantly enhanced; all access records and permission changes are uploaded to the blockchain, ensuring the immutability and transparency of data for real-time auditing and traceability; training with unsupervised learning models further strengthens the monitoring and anomaly recognition of user behavior. By calculating risk scores through the Isolation Forest algorithm, it can intelligently evaluate the security risks of users and dynamically adjust access permissions according to the evaluation results. This dynamic permission adjustment mechanism based on behavior analysis is more flexible than traditional static permission management and can respond to potential security threats in real time.

[0108] This embodiment also provides an access security management system based on data management, including:

[0109] A data management module for collecting data source information and encrypting the data using encryption algorithms;

[0110] An access control module for defining user access permissions and implementing refined access management;

[0111] An authentication module for various authentication methods to ensure the authenticity of user identities;

[0112] A decryption module for decrypting encrypted data to ensure that users can unlock and obtain authorized information when accessing data;

[0113] An auditing and risk assessment module for auditing user access records, monitoring user behavior in real time, and conducting risk assessments.

[0114] This embodiment also provides a computer device applicable to a situation of an access security management method based on data management, including: a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions to implement an access security management method based on data management as proposed in the above embodiment.

[0115] The computer device may be a terminal, and the computer device includes a processor, a memory, a communication interface, a display screen, and an input device connected via a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The communication interface of the computer device is used to communicate with external terminals in a wired or wireless manner, and the wireless manner can be achieved through WIFI, a carrier network, NFC (Near Field Communication), or other technologies. The display screen of the computer device may be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device may be a touch layer covering the display screen, or a button, a trackball, or a touchpad provided on the housing of the computer device, or an external keyboard, touchpad, or mouse, etc.

[0116] This embodiment also provides a storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements the access security management method and system based on data management proposed in the above embodiment; the storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (Static Random Access Memory, abbreviated as SRAM), electrically erasable programmable read-only memory (Electrically Erasable Programmable Read-Only Memory, abbreviated as EEPROM), erasable programmable read-only memory (Erasable Programmable Read Only Memory, abbreviated as EPROM), programmable read-only memory (Programmable Red-Only Memory, abbreviated as PROM), read-only memory (Read-Only Memory, abbreviated as ROM), magnetic memory, flash memory, a magnetic disk, or an optical disc.

[0117] In summary, the present invention introduces multi-factor authentication and combines smart contracts with multi-party computing technology to make up for the deficiencies in the prior art and provides a more flexible and secure access control mechanism. Specifically, based on the rigid transformation combined with the SIFT feature matching method and the Delaunay triangulation method for facial verification, and fingerprint recognition verification is carried out again to ensure the uniqueness and security of the user identity. During the identity verification process, by combining the rigid transformation and the SIFT feature matching method, high-precision three-dimensional facial recognition is achieved, improving the reliability of the entire verification process. In addition, through smart contracts, refined access control based on user behavior and attributes is realized, and different levels of user access rights will be dynamically adjusted according to behavior analysis and historical data, ensuring that the access rights are more timely and reasonable, making the rights no longer statically set but updated and controlled in real time. Therefore, the present invention provides a more flexible, secure and dynamic access control method, which adapts to the highly dynamic and complex access control requirements.

[0118] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered by the scope of the claims of the present invention.

Claims

1. An access security management method based on data management, characterized in that: include, Collect data and store it in an external storage system after multi-level encryption, and use smart contracts to implement refined access control based on attribute and behavior analysis; When a user applies for access, facial verification is performed based on rigid transformation combined with SIFT feature matching method and Delaunay triangulation method, and fingerprint verification is performed. The key decryption process is managed using smart contracts combined with multi-party computing; Store the access records of authorized users in an external storage system and conduct intelligent auditing and risk assessment on the stored data.

2. The access security management method based on data management according to claim 1, characterized in that: The data collection and multi-level encryption followed by storing the data in an external storage system refers to collecting historical and real-time data from various data sources and pre-processing them, and generating encryption keys through a key generation center for the access rights to the data to obtain a public key KG; Calculate the intermediate value in the encryption step using the hash function algorithm , encrypt using the public key KG to obtain the encrypted data ciphertext ; Using the Shamir secret sharing algorithm, construct a polynomial of the shared key based on the private key K , and distribute the generated shared key to each key provider.

3. The access security management method based on data management according to claim 2, characterized in that: The implementation of refined access control based on attribute and behavior analysis through smart contracts refers to deploying a smart contract on the blockchain, which sets access rules and defines hierarchical access rights based on collected user attributes and historical behavior data; The hierarchical access rights include primary user access rights, secondary user access rights and tertiary user access rights.

4. A method for access security management based on data management according to claim 3, characterized in that: When the user applies for access, facial verification is performed based on rigid transformation combined with SIFT feature matching method and Delaunay triangulation method, and fingerprint verification is performed. The user initiates a data access request through the application, and the smart contract first verifies the integrity of the requested data and verifies the access rights based on the user's identity information; After the first-level user passes the verification, the camera is used to obtain the user's facial 2D image, and the pre-processed facial image is input into the convolutional neural network to output the coordinates of each facial 2D feature point; The user's facial data from different angles is acquired through 3D image capture technology and preprocessed. A complete 3D facial point cloud is obtained using point cloud stitching and alignment technology. One point cloud is selected from the multi-view point cloud as a reference point cloud P, and the others are used as target point clouds Q. The rotation matrix R and the translation vector t are solved for the target point cloud Q using the rigid transformation method and the minimization error function. Calculate the optimal rotation matrix by aligning the centroids of two point sets using the Kabsch algorithm , using Least Squares Method for Calculating the Optimal Translation Vector ; Obtain the optimal rotation matrix through calculation and translation vector , update the position coordinates in all target point clouds Q to minimize the error between the two point clouds and generate more accurate three-dimensional point cloud feature point coordinates; Using the SIFT feature matching method, the coordinates of the feature points in the two-dimensional image are corresponded to the coordinates of the feature points in the three-dimensional point cloud. The feature point data in the two-dimensional image is input into the shape regression model to obtain the coordinates of the feature points in the mapped three-dimensional point cloud and integrated to generate a coordinate set ; Using the Delaunay triangulation method, the optimized three-dimensional feature point coordinate set is divided into multiple non-overlapping triangles, and the geometric stability of the grid is optimized by maximizing the minimum angle of each triangle; The Laplace smoothing method is used to calculate the set of neighboring vertices of each vertex in the mesh, and the average value of the spatial coordinates of all neighboring vertices is calculated to update each vertex. The mesh shape is optimized according to the updated vertex position to construct a complete three-dimensional facial model. The 3D facial model generated by the user is transferred to the blockchain, and the existing facial database template is compared with the newly generated 3D facial model using the Euclidean distance similarity calculation method. A distance threshold T is set. If the Euclidean distance is less than or equal to the threshold T, it means that the comparison is successful and the user identity verification is passed. Otherwise, the verification fails and access is denied. After the user passes the facial authentication, he / she needs to verify his / her identity through fingerprint recognition.

5. A method for access security management based on data management according to claim 4, characterized in that: The process of using smart contracts combined with multi-party computing to manage key decryption means that after the user passes the authority verification, the smart contract sends a merge request to multiple key providers. After receiving all the key parts, the key parts held are merged through the multi-party computing protocol to obtain the complete private key K, decrypt the data, and obtain the plaintext data.

6. The access security management method based on data management according to claim 5, characterized in that: Storing the access records of authorized users in an external storage system means that after successful permission verification, the smart contract automatically collects access data to form access records, and uses the SHA256 algorithm to generate the hash value of the access records.

7. The access security management method based on data management according to claim 6, characterized in that: Performing intelligent auditing and risk assessment on the stored data means combining blockchain technology to audit all behavior data, using an unsupervised learning model to evaluate the user's behavior pattern and generating a risk score through the isolation forest method. A security threshold U is set. If the user's risk score exceeds the set security threshold U, an alarm will be triggered and additional identity verification will be required. After successful identity verification, the smart contract will automatically restore the user's permissions; otherwise, the permissions will continue to be restricted.

8. An access security management system based on data management, based on the access security management method based on data management according to any one of claims 1 to 7, characterized in that: Including, A data management module, which is used to collect data source information and encrypt the data using an encryption algorithm; An access control module, which is used to define user access permissions and implement refined access management; An identity verification module, which is used for various identity verification methods to ensure the authenticity of the user's identity; A decryption module, which is used to decrypt the encrypted data to ensure that when the user accesses the data, they can unlock and obtain the authorized information; An auditing and risk assessment module, which is used to audit the user's access records, monitor the user's behavior in real time, and conduct risk assessment.

9. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that: When the processor executes the computer program, it implements the steps of an access security management method based on data management according to any one of claims 1 to 7.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by the processor, it implements the steps of an access security management method based on data management according to any one of claims 1 to 7.