Identity Authentication-based E-government Data Access Control Method
By building a frequency chart of access IP and a government data network, user credibility assessment and access content clustering are carried out, and the problems of insufficient flexibility and data leakage risks in government data access control are solved, and more efficient and secure access control is achieved.
Patent Information
- Application Number
- CN202510784246.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-12
- Publication Date
- 2025-08-05
- Estimated Expiration
- 2045-06-12
AI Technical Summary
In the prior art, the government data access control method based on identity verification is insufficient flexibility, resulting in low access efficiency and potential data leakage. Especially when offices in many places and user attributes are numerous, permission allocation is not accurate enough.
By obtaining the user's access records, building the access content of the access IP-access frequency stacking column chart, establishing a government data network, performing cluster clustering of Class I access content, determining the user's final credibility based on the user's access records and similarity, and executing permission control.
It improves the security and efficiency of government data access, avoids data leakage and untimely permission allocation caused by the limitations of identity verification, and achieves more precise access control.
Smart Images

Figure CN120316756B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology. More specifically, the present invention relates to a government affairs data access control method based on authentication. Background Art
[0002] Government affairs data are various data resources legally collected, generated, stored, and managed by government departments at all levels and their technical support units in the process of performing their duties. Due to its high sensitivity and public attributes, it has high value. In order to avoid the leakage of government affairs data from harming government departments and causing economic losses, it is necessary to authenticate the client accessing the government affairs data to perform permission control.
[0003] In order to ensure the access security and access efficiency of government affairs data, multi-dimensional identity authentication and dynamic permission allocation are often adopted at present. In related technologies, for example, a Chinese patent document with the authorization publication number CN119004426B discloses a multi-dimensional factor security management system for government affairs documents, which discloses a multi-level authentication and risk assessment strategy for users through multi-dimensional factors such as login time, accurately confirms the user identity and assesses the risk level, and can effectively prevent data leakage and unauthorized access. A Chinese patent document with the authorization publication number CN10559210B discloses a government affairs cloud access control method based on attribute encryption, which discloses a CP-ABE that can calculate outsourced multi-attribute authorities, and can revoke user attributes without changing the ciphertext, and can dynamically perform permission allocation to achieve fine-grained access control of government affairs data.
[0004] However, there is a problem of insufficient applicability in evaluating user risks based on user login behavior. For example, users who need to work in multiple locations have a relatively high risk due to time zone and geographical location differences, resulting in restricted access and affecting the access efficiency of government affairs data. In addition, when controlling user access rights based on user attributes, there are many types of user attributes in government departments, and all government affairs data need to be allocated permissions according to user attributes. The more accurate the allocation, the more manpower is required, and the flexibility is insufficient. Whenever there is new data, permission allocation is required, and inaccurate allocation will pose a hidden danger of data leakage. Summary of the Invention
[0005] To solve the above technical problems of insufficient flexibility in government affairs data access control through authentication, resulting in insufficient access efficiency of government affairs data and potential data leakage risks, the present invention provides a government affairs data access control method based on authentication, including:
[0006] Obtain the access records of several users. The access records of the users include several access units within a preset time range. The access units include access IPs and access contents. Based on the access frequencies of different access contents for each access IP, establish a stacked bar chart of access content - access frequency for all access IPs. Based on the performance of the access content pattern and access volume of the access IPs in the stacked bar chart of access content - access frequency for all access IPs, obtain the credibility of each access IP. Based on the access contents accessed in the login mode, establish a government affairs data network. Based on the similarity of the corresponding users of the access contents in the government affairs data network, cluster the type-I access contents to obtain several type-I access content clusters. According to the consistency between the requested access content of the user and the access IP in the user's access record, obtain the preliminary credibility of the user. According to the distribution similarity of the access records of the users who have already accessed the requested access content and the corresponding users of the requested access content in each type-I access content cluster, determine the final credibility of the requesting access user. Based on the final credibility of the user, perform permission control on the requested access content of the user.
[0007] The present invention classifies access contents and determines the final credibility of a user according to the access situations of similar users to the requested access content, which can avoid the insufficient efficiency of government affairs data access caused by untrustworthy user access information. The present invention combines the access records of users to judge the permissions of the requested access content of users, avoids users from accessing irrelevant access contents, and improves the security of government affairs data access.
[0008] Preferably, the obtaining of the credibility of each access IP includes:
[0009] Based on the login status of the access record, establish an access status function;
[0010] The credibility of the i-th access IP satisfies the expression:
[0011] ;
[0012] In the formula, represents the number of access units of the i-th access IP; represents the access status function; represents the h-th access unit of the i-th access IP; represents the number of access contents; 、 represent the access frequencies of all access IPs and the i-th access IP for the c-th access content; represents the set of access frequencies of all access IPs for each access content; represents a normalization function.
[0013] The present invention determines the credibility of an access IP based on the access frequency of different access contents for the access IP, analyzes the access behavior of the access IP, and makes the access control for users more precise.
[0014] Preferably, the establishment of the access content - access frequency stacked bar chart for all access IPs includes:
[0015] Count the number of access units of each access IP, obtain all the access contents of each access IP, count the access frequency of each access IP for each access content, use the access content as the horizontal axis and the access frequency as the vertical axis to construct a coordinate system, and draw the access content - access frequency stacked bar chart for all access IPs.
[0016] Preferably, the access status function satisfies the expression:
[0017] ;
[0018] In the formula, represents the access status function, the access status is 1 when the access unit is in the login mode, and the access status is 0 when the access unit is in the guest mode; represents the h-th access unit of the i-th access IP.
[0019] The present invention distinguishes the access modes of access units by constructing an access status function, providing a basis for the credibility of the access IP.
[0020] Preferably, the establishment of the government affairs data network based on the access contents accessed in the login mode includes: extracting all the access contents accessed in the login mode, denoted as type I access contents; regarding the users whose access contents include type I access contents as type I users; taking each type I access content and each type I user as entities, and connecting each type I user entity with all the type I access content entities accessed correspondingly to obtain the government affairs data network.
[0021] The present invention can visually represent the connection between users and access contents by constructing the government affairs data network, providing a basis for the classification of access contents and the similarity of users.
[0022] Preferably, the obtaining of several Class-I access content cluster classes includes: obtaining the similarity between any two Class-I access contents based on the differences of users connected to different access contents in the government affairs data network; presetting an initial number of seeds, evenly selecting initial seed points in the government affairs data network, and performing region growing on the initial seed points. During the region growing process, Class-I access contents can grow in different growing regions; the growing condition is that the similarity between the initial seed point and the neighboring Class-I access content is greater than a first threshold; when there is no Class-I access content in the neighborhood of each growing region whose similarity with the Class-I access content in the corresponding growing region is greater than the first threshold, stop the region growing; obtain several growing regions, and record any growing region as a Class-I access content cluster class.
[0023] Preferably, the obtaining of the similarity between any two Class-I access contents includes: taking the ratio of the intersection to the union of all Class-I users connected to the m-th Class-I access content and the n-th Class-I access content as the similarity between the m-th Class-I access content and the n-th Class-I access content.
[0024] Preferably, the obtaining of the preliminary credibility of a user includes:
[0025] Obtaining the number of access units of each access IP of the r-th user; obtaining the access IP of the access content of the r-th user's query, and obtaining the number of access units in the access record of the r-th user that are the same as the access IP of the access content of the query;
[0026] ;
[0027] In the formula, represents the preliminary credibility of the r-th user; represents the number of access IPs of the r-th user; represents the number of access units in the access record of the r-th user that are the same as the access IP of the access content of the query; represents the credibility set of each access IP of the r-th user; represents a normalization function.
[0028] The present invention obtains the preliminary credibility of a user through the credibility of each access IP of the user and the number of access units of the user on the access IP, improving the accuracy of access control of user government affairs data.
[0029] Preferably, obtaining the final credibility of the user includes: recording the corresponding user requesting to access the content as the target user; obtaining the users whose access records contain the requested access content, and recording them as the relevant users of the target user; recording the I-type access content cluster class to which the access record of the target user belongs as the target I-type access content cluster class; obtaining the number of access units belonging to each target I-type access content cluster class in the access records of the target user and the relevant users of the target user; obtaining the difference between the access content of the target user and all relevant users, performing negative correlation normalization, and then multiplying it by the preliminary credibility of the target user to obtain the final credibility of the target user.
[0030] Preferably, the difference between the access content of the target user and all relevant users satisfies the expression:
[0031] ;
[0032] In the formula, Z represents the number of target I-type access content cluster classes; represents the number of relevant users of the target user; , represent the number of access units belonging to the z-th target I-type access content cluster class in the access records of the target user and the v-th relevant user of the target user; represents the absolute value function.
[0033] The beneficial effects of the present invention are as follows:
[0034] (1) The present invention judges the credibility of the content requested by the user by referring to the user's access record, which can avoid the leakage of government affairs data of non-regularly accessed content caused by account loss, improve the accuracy of government affairs data access control, and avoid the limitations of identity authentication;
[0035] (2) The present invention refers to the access situations of users with similar access content to the requested access content, which can improve the efficiency of users accessing government affairs data and avoid insufficient access efficiency caused by problems such as untimely permission allocation. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] Figure 1 is a flowchart schematically showing the method for accessing government affairs data based on identity authentication in the present invention;
[0037] Figure 2 is a schematic diagram showing a stacked bar chart of access content - access frequency. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0038] The embodiment of the present invention discloses a method for accessing government affairs data based on identity authentication. Referring to Figure 1 , it includes steps S1 - step S4:
[0039] S1: Obtain the access records of several users.
[0040] It should be noted that the government affairs platform is a public platform. Therefore, the users accessing the government affairs data cover various groups, including relevant personnel of the government affairs platform, ordinary users, and also those who steal government affairs data. In order to distinguish the access habits of various groups and detect abnormal behaviors, the present invention obtains the access records of several users, so as to further analyze the users.
[0041] Specifically, for the government affairs platform, obtain the access records of several users within a preset time range. The preset time range is set by the implementer according to the actual implementation situation and can be set to one month. The access records of the users include several access units of the users within the preset time range, and the access unit includes the access IP and the access content.
[0042] It should be noted that the government affairs platform has a login mode and a guest mode. When a user accesses the government affairs platform, it may be in the login mode or the guest mode. Therefore, the access records of the user include all the access units in the login mode of the user, and also include all the access units accessed by the client with the same access IP in the guest mode.
[0043] So far, the access records of several users have been obtained.
[0044] S2: Obtain the credibility of each access IP based on the pattern and volume of the access content of the access IP.
[0045] It should be noted that according to the confidentiality requirements, government affairs data is divided into public data, restricted data, and sensitive data. Public data is the data that can be accessed in the guest mode. Both restricted data and sensitive data are the data that can be accessed in the login mode, and different ranges of access can be performed according to the permissions of the login account. However, there is also value hidden in public data. If it is accessed abnormally in large quantities and data leakage occurs, it may cause incalculable losses. Therefore, the present invention first analyzes the access records of the access IP, that is, the client, and judges the credibility of each access IP in combination with the login situation of the access IP.
[0046] It should be noted that when an access IP usually accesses data in the login mode and the access content is regular and focused, it indicates that the possibility of the corresponding user's normal access behavior is relatively high. When an access IP quickly accesses a small amount of data in the guest mode, it indicates that the corresponding user is purposefully looking for the required data, and the possibility of normal access behavior is relatively high. If an access IP accesses a large amount of access data irregularly in the guest mode, it means that the possibility of the abnormal purpose of the access IP is relatively high. Therefore, the present invention obtains the credibility of each access IP based on the pattern and volume of the access content of the access IP.
[0047] Specifically, obtain all the access contents of each access IP, count the access frequencies of each access IP to each access content, use the access content as the horizontal axis and the access frequency as the vertical axis to construct a coordinate system, and draw a stacked bar chart of the access content - access frequency of all access IPs. It should be noted that as Figure 2 is a schematic diagram of the stacked bar chart of access content - access frequency, which includes three access IPs, A1, A2, and A3, and four access contents, a1, a2, a3, and a4. Figure 2 Among them, the access frequencies of A1 to a1, a2, a3, and a4 are 1, 2, 1, and 0, the access frequencies of A2 to a1, a2, a3, and a4 are 3, 1, 10, and 0, and the access frequencies of A3 to a1, a2, a3, and a4 are 0, 1, 0, and 1.
[0048] It should be noted that the access content with a higher cumulative access frequency is relatively more popular and has more people's attention. Therefore, the corresponding access IP has a higher credibility. For access content with a lower access frequency, if the access IP accesses in the guest mode and there are a large number of access behaviors, it indicates that the credibility of the access IP is lower.
[0049] Preferably, the credibility of any access IP satisfies the expression:
[0050] ;
[0051] ;
[0052] ;
[0053] In the formula, represents the credibility of the i-th access IP; represents the number of access units of the i-th access IP; represents the access status function. When the access unit is in the login mode is 1, and when the access unit is in the guest mode is 0; represents the h-th access unit of the i-th access IP; represents the number of access contents; represents the access frequency of all access IPs to the c-th access content; represents the set of access frequencies of all access IPs to each access content; represents the access frequency of the i-th access IP to the c-th access content; represents the set of access frequencies of the i-th access IP to each access content; represents the normalization function.
[0054] In the formula, represents the cumulative access status of the i-th access IP. It represents the ratio of the access units in the login mode among all the access units of the i-th access IP. The larger this value is, the more the i-th access IP tends to access in the login mode, and thus the higher the credibility of the i-th access IP.
[0055] In the formula, It represents the total access frequency of all access contents. It represents the proportion of the access frequency of the c-th access content in the total access frequency of all access contents. The larger this value is, the more popular the c-th access content is and the more times the c-th access content is accessed, indicating that the access behavior of the c-th access content is more normal. It represents the proportion of the access frequency of the i-th access IP to the c-th access content in the total access frequency of the i-th access IP to all access contents. The larger this value is, the more the i-th access IP focuses on the c-th access content. The larger it is, it means that when the access behavior of the c-th access content is relatively normal, the more the i-th access IP accesses the c-th access content, indicating that the access behavior of the i-th access IP to the c-th access content is more normal. It represents the normal performance of the access behavior of the i-th access IP to all access contents. The larger this value is, the more normal the access behavior of the i-th access IP to all access contents is, and thus the higher the credibility of the i-th access IP.
[0056] Thus far, the credibility of each access IP has been obtained.
[0057] S3: Based on the access contents accessed in the login mode, establish a government affairs data network; based on the similarity of the corresponding users of the access contents in the government affairs data network, cluster the type-I access contents to obtain several type-I access content clusters; according to the consistency between the requested access content of the user and the access IP of the user's access record, obtain the preliminary credibility of the user; according to the distribution similarity of the users who have accessed the requested access content and the access records of the corresponding users of the requested access content in each type-I access content cluster, determine the final credibility of the requested access user.
[0058] It should be noted that S2 has conducted a preliminary analysis on the access records of the access IPs, and can display different ranges of government affairs data according to the credibility of the access IPs, improving the overall security of government affairs data. However, for users who have access to restricted data and sensitive data, due to certain loopholes in identity verification, such as the leakage of account passwords, it may cause more serious leakage of government affairs data. Therefore, the present invention further analyzes the access units in the login mode of each user.
[0059] It should be noted that users with certain permissions to access restricted data and sensitive data are responsible for the management of certain government affairs data in the government affairs platform. All users who can access restricted data and sensitive data enable the operation of the government affairs platform by managing the government affairs data related to their responsibilities. Therefore, first, users who can access restricted data and sensitive data are extracted, and a government affairs data network is constructed based on their access records. Considering that a knowledge graph constructs a data association network by connecting a number of entities with relationships, the present invention establishes a government affairs data association network through a knowledge graph.
[0060] It should be further noted that in the government affairs data network, the access data content and permissions of different users are different. To ensure the security of government affairs data, it is necessary to restrict the access permissions of data that is not part of a user's responsibilities. To avoid insufficient robustness and affect the efficiency of permission allocation due to overly fine permission restrictions, the present invention clusters the access content and determines several access content cluster classes based on the number of similar users between the access contents in the government affairs data network. On this basis, if the user's identity verification information is weak, for example, when the user accesses government affairs data from an unusual access IP and the credibility of each access IP is low, the access content cluster class to which the user's requested access content belongs can be determined first, and then the final credibility of the user can be determined according to the access situation of the users corresponding to the accessed content cluster class to which the requested access content belongs, so as to finally determine the access permission of the user to the requested access content.
[0061] Specifically, all access contents accessed in the login mode are extracted and recorded as type-I access contents; users whose access contents include type-I access contents are recorded as type-I users; each type-I access content and each type-I user are used as entities, and each type-I user entity is connected to all type-I access content entities corresponding to the access, to obtain a government affairs data network.
[0062] It should be noted that for any two type-I access contents, the higher the proportion of the same connected type-I users, the higher the similarity of the two type-I access contents.
[0063] Preferably, the ratio of the intersection to the union of all type-I users connected by the m-th type-I access content and the n-th type-I access content is recorded as the similarity between the m-th type-I access content and the n-th type-I access content.
[0064] It should be noted that the higher the similarity between the m-th type-I access content and the n-th type-I access content, the more consistent the permissions of the m-th type-I access content and the n-th type-I access content. Therefore, in order to initially allocate permissions for the government affairs data network, the government affairs data network can be divided into several type-I access content cluster classes with stronger permission consistency.
[0065] Preferably, according to the similarity of type-I access content, cluster the type-I access content to obtain several type-I access content clusters: preset an initial number of seeds, evenly select initial seed points in the government data network, and perform region growing on the initial seed points. During the region growing process, the type-I access content can grow in different growing regions; the growing condition is that the similarity between the initial seed point and the neighboring type-I access content is greater than a first threshold; when there is no type-I access content in the neighborhood of each growing region whose similarity with the type-I access content in the corresponding growing region is greater than the first threshold, stop the region growing; obtain several growing regions, and record any growing region as a type-I access content cluster. It should be noted that the initial number of seeds and the first threshold are set by the implementers according to the actual implementation situation. For example, the initial number of seeds can be set to 100, and the first threshold can be set to 0.5.
[0066] It should be noted that the user's access habits can be reflected in the user's access records. For example, the access IPs of users at fixed office locations are usually the same. If not at a fixed office location, the user will have several access IPs. Then, accessing government data using an infrequently used access IP does not necessarily mean that the user is accessing abnormally. Therefore, in this invention, the access IP of the user's requested access content is compared with the user's access records. When the user has more access IPs, if the access IP of the user's requested access content appears in the access records, it indicates that the user's initial credibility is relatively high. When the user has fewer access IPs, the more frequently the access IP of the user's requested access content appears in the access records, the higher the user's initial credibility. In addition, if the credibility of all the user's access IPs is relatively high, then the user's initial credibility is relatively high.
[0067] Preferably, obtain the user's initial credibility according to the consistency between the user's requested access content and the access IP in the user's access records, including:
[0068] Obtain the number of access units of each access IP of the r-th user; obtain the access IP of the r-th user's requested access content, and obtain the number of access units in the r-th user's access records that are the same as the access IP of the requested access content.
[0069] The user's initial credibility satisfies the expression:
[0070] ;
[0071] In the formula, represents the initial credibility of the r-th user; represents the number of access IPs of the r-th user; represents the number of access units in the r-th user's access records that are the same as the access IP of the requested access content; represents the credibility set of each access IP of the r-th user; represents a normalization function.
[0072] In the formula, represents the average credibility of the access IP of the r-th user. The larger this value is, the greater the initial credibility of the r-th user; represents that based on the credibility of the access IP of the r-th user, the more access IPs there are and the more access units that are the same as the access IP of the access content, the higher the initial credibility of the r-th user.
[0073] It should be noted that when the corresponding user requesting access to the content uses a new access IP for the access request, since there is no access unit in the access record of the corresponding user requesting access to the content that is the same as the new access IP, the initial credibility of the corresponding user requesting access to the content is relatively low, which will affect the timely viewing of government affairs data by the requesting access user. Therefore, the final credibility of the requesting access user can be determined through the distribution of the access records of the users who have already requested access to the content and the corresponding user requesting access to the content in each type-I access content cluster class.
[0074] Preferably, according to the access records of the users who have already requested access to the content and the corresponding user requesting access to the content, and the distribution similarity in each type-I access content cluster class, obtaining the final credibility of the requesting access user includes:
[0075] Denote the corresponding user requesting access to the content as the target user; obtain the users whose access records contain the content being requested access, and denote them as the relevant users of the target user; denote the type-I access content cluster class to which the access record of the target user belongs as the target type-I access content cluster class; obtain the number of access units belonging to each target type-I access content cluster class in the access records of the target user and the relevant users of the target user.
[0076] The final credibility of the target user satisfies the expression:
[0077] ;
[0078] In the formula, represents the final credibility of the target user; represents the initial credibility of the target user; Z represents the number of target type-I access content cluster classes; represents the number of relevant users of the target user; 、 represent the number of access units belonging to the z-th target type-I access content cluster class in the access records of the target user and the v-th relevant user of the target user; represents the absolute value function; represents the exponential function with the natural constant as the base.
[0079] In the formula, It represents the difference in the number of access units belonging to the z-th target I-type access content cluster class in the access records of the target user and the v-th related user of the target user. It represents the sum of the differences in the number of access units belonging to each target I-type access content cluster class in the access records of the target user and the v-th related user of the target user. The larger this value is, the greater the difference in the access content between the target user and the v-th related user of the target user, the smaller the similarity between the target user and the v-th related user of the target user, and the lower the final credibility of the target user. It represents the difference in the access content between the target user and all related users. The larger this value is, the greater the difference in the access content between the target user and all related users, and the lower the final credibility of the target user.
[0080] Thus, the final credibility of the user is obtained.
[0081] S4: Based on the final credibility of the user, perform permission control on the requested access content of the user.
[0082] It should be noted that when the user requests access, the final credibility of the user is obtained based on the content requested by the user, and a threshold is set. When the final credibility of the user is greater than the preset threshold, it indicates that the user's request is safe, so the user can successfully access.
[0083] Specifically, a second threshold is preset. When the user clicks to request access to content, the final credibility of the user is obtained by the method in steps S1 - S3. If the final credibility of the user is greater than the second threshold, the user can access the requested access content. If the final credibility of the user is less than or equal to the second threshold, the user cannot access the requested access content. It should be noted that the second threshold is set by the implementer according to the actual implementation situation. For example, the first threshold can be set to 0.7.
[0084] Thus, the access control of the user to government affairs data is completed.
[0085] Although this specification has shown and described multiple embodiments of the present invention, it is obvious to those skilled in the art that such embodiments are provided only by way of example. Those skilled in the art will think of many changes, alterations, and alternative ways without departing from the spirit and idea of the present invention.
Claims
1. The government data access control method based on identity authentication is characterized by: include: Obtain access records of several users. The user's access records include several access units of the user within a preset time range. The access units include the access IP and access content. Based on the frequency of access to different content by each access IP, a stacked bar chart showing access content and access frequency for all access IPs is created. Based on the regularity of access content and access volume of each IP, the credibility of each access IP is determined. Based on the access content accessed in the login mode, a government data network is established, including: extracting all access content accessed in the login mode, recorded as Class access content; the access content contains The user who accesses the content is recorded as Type of user; Class access content and various Class users are regarded as entities, and each Class user entity and all corresponding access The class access content entity is connected to obtain the government data network; Based on the similarity of corresponding users accessing content in the government data network, Cluster the access content and obtain several Class access content clusters include: based on the differences of users with different access content connections in the government data network, obtaining any two The similarity of the access content of the class is determined; the number of initial seeds is preset, the initial seed points are evenly selected in the government data network, and the initial seed points are subjected to regional growth. Class access content can grow in different growth areas; the growth conditions are the initial seed point and the neighborhood The similarity of the access content of the class is greater than the first threshold; when the neighborhood of each growing area does not exist with the corresponding growing area The similarity of the class access content is greater than the first threshold When the class accesses the content, stop the region growing; get several growing regions, and record any growing region as a Class access content cluster class; According to the consistency of the access IP of the user's request to access the content and the user's access record, the user's preliminary credibility is obtained; according to the access records of the user who has accessed the requested content and the corresponding user who requested the content, the user's initial credibility is obtained. The distribution similarity of the access content clusters is used to determine the final credibility of the user requesting access; Based on the user's ultimate credibility, the user's access rights to the content are controlled.
2. The government data access control method based on identity authentication according to claim 1 is characterized in that: The process of obtaining the credibility of each access IP address includes: Establish access status function based on login status of access record; The credibility of the i-th access IP satisfies the expression: ; Where, Indicates the number of access units of the i-th access IP; Represents access status function; represents the hth access unit of the i-th access IP; Indicates the number of accessed content; 、 Indicates the access frequency of all access IPs and the i-th access IP to the c-th access content; Represents the access frequency set of all access IPs to each access content; Represents the normalization function.
3. The government data access control method based on identity authentication according to claim 1 is characterized in that: The access content-access frequency stacked bar chart of all access IP addresses is established, including: Count the number of access units of each access IP, obtain all access content of each access IP, count the access frequency of each access IP to each access content, build a coordinate system with access content as the horizontal axis and access frequency as the vertical axis, and draw a stacked column chart of access content-access frequency of all access IPs.
4. The government data access control method based on identity authentication according to claim 2 is characterized in that: The access state function satisfies the expression: ; Where, Indicates the access status function. When the access unit is in login mode, the access status is 1; when the access unit is in visitor mode, the access status is 0.
5. The government data access control method based on identity authentication according to claim 1 is characterized in that: Obtain any two Similarity of class access content, including: The mth Class access content, nth Class access content connection all The ratio of the intersection and union of class users, recorded as the mth Class access content and nth Similarity of class access content.
6. The government data access control method based on identity authentication according to claim 1 is characterized in that: The obtaining of the user's preliminary credibility includes: Obtain the number of access units of each access IP of the r-th user; obtain the access IP of the r-th user accessing the content, and obtain the number of access units in the r-th user's access record that is the same as the access IP of the r-th user accessing the content; ; Where, represents the initial credibility of the rth user; Indicates the number of access IP addresses of the rth user; Indicates the number of access units in the access record of the rth user that has the same access IP as the access content; Represents the credibility set of each access IP of the r-th user; Represents the normalization function.
7. The government data access control method based on identity authentication according to claim 1 is characterized in that: The obtaining of the final credibility of the user includes: The corresponding user who requests to access the content is recorded as the target user; the user whose access record contains the user who requests to access the content is recorded as the related user of the target user; Class access content cluster class is recorded as target Class access content cluster class; obtain the access records of the target user and the target user's related users belonging to each target The number of access units of the class access content cluster class; The difference in access content between the target user and all related users is obtained, and negative correlation normalization is performed. Then, it is multiplied by the preliminary credibility of the target user to obtain the final credibility of the target user.
8. The government data access control method based on identity authentication according to claim 7 is characterized in that: The difference between the access content of the target user and all related users satisfies the expression: ; Where Z represents the target Class access content cluster class number; Indicates the number of related users of the target user; 、 Indicates the target user and the target user's vth related user's access record belonging to the zth target The number of access units of the class access content cluster class; represents the absolute value function.