Protocol security sharing method for cloud dynamic permission grading
A cloud-based dynamic permission grading system addresses static management issues by separating and classifying user and administrator information, ensuring secure and efficient access based on risk assessment, enhancing security and flexibility in cloud environments.
Patent Information
- Application Number
- CN202510674745.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-23
- Publication Date
- 2025-07-15
AI Technical Summary
Traditional static permission management methods are difficult to cope with user identity changes and access requirements adjustments in cloud computing environments, resulting in lagging responses, complex management and insufficient security.
The protocol security sharing method of dynamic permission grading in the cloud is adopted. Through the hierarchical storage and hierarchical access mechanism of user platform and management platform information, the information of users and managers is stored and accessed on cloud servers of different levels, and the servers of the corresponding level are matched according to the risk score.
It improves the security and flexibility of the cloud environment, realizes hierarchical access between users and administrators, and increases security and efficiency.
Smart Images

Figure CN120321025A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical fields of information security and cloud computing, and in particular, to a protocol security sharing method for dynamic permission grading in the cloud. Background Art
[0002] With the rapid development of cloud computing technology, more and more organizations and individuals have migrated sensitive data to the cloud to improve storage efficiency and access convenience; however, the problems of data sharing and access control in the cloud environment have become increasingly prominent. Especially in the scenario of concurrent access by multiple users and multiple roles, the traditional static permission management method has been difficult to meet the actual needs; the static permission model has defects such as lagging response, complex management, and insufficient security when dealing with dynamic scenarios such as changes in user identities and adjustments of access requirements; therefore, there is an urgent need for a data sharing method that supports dynamic permission adjustment, fine-grained control, and security protocol guarantee to improve the security and flexibility of data in the cloud environment. Summary of the Invention
[0003] The purpose of the present invention is to overcome the above problems existing in the prior art and greatly improve its technical effect on the basis of the original technology; the present invention provides a protocol security sharing method for dynamic permission grading in the cloud, and the method includes:
[0004] Hierarchical storage mechanism of cloud servers: hierarchical storage of user platform information and hierarchical storage of management platform information; the hierarchical storage of user platform information is used for hierarchical storage of various information of users, and the method of hierarchical storage of user platform information is: first, classify the information accessed by users, and each classification corresponds to different levels of information; subsequently, according to the types of user information classification, divide the levels of the cloud server, and the number of levels divided by the cloud server is the same as the number of types of user information classification; finally, store the user information corresponding to the level into the cloud server; the hierarchical storage of management platform information is used for hierarchical storage of various information accessed by administrators, and the method of hierarchical storage of management platform information is: first, classify the information accessed by administrators, and each classification corresponds to different permission levels; subsequently, according to the types of administrator management permission classification, divide the management permission levels of the cloud server, and the number of levels divided by the cloud server is the same as the number of types of administrator management permission classification; finally, store the management permission information corresponding to the level into the cloud server;
[0005] Cloud server hierarchical access mechanism: If the access object is a user, the user platform determines the permitted access level of the user based on the user's access habits and environment, and calls the user platform information of the cloud server at a level not higher than the determined permitted access level of the user for the user to access; the permitted access level refers to the highest level that the user is permitted to access; if the access object is a management staff, the management platform determines the permitted access level of the management staff based on the management staff's access habits and environment, and calls the connection interface of the cloud server at the corresponding level to establish a connection with the management staff's device to perform relevant operations of the management business.
[0006] Specifically, the hierarchical storage of user platform information and the hierarchical storage of management platform information include: when storing user platform information and management platform information on the same cloud server at the same time, the user platform information and the management platform information are stored separately. The storage area for storing user platform information is called the dedicated area for user platform information, and the storage area for storing management platform information is called the dedicated area for management platform information.
[0007] Specifically, the classification of the information accessed by the user, with each classification corresponding to different levels of information includes: classifying the information accessed by the user into public information, restricted information, sensitive information, and confidential information, and classifying users into visitors, ordinary users, advanced users, and super users; among them, visitors only have the right to access public information, ordinary users have the right to access public information and restricted information, advanced users have the right to access public information, restricted information, and sensitive information, and super users have the right to access public information, restricted information, sensitive information, and confidential information; the number of levels divided by the cloud server is the same as the number of types of user information classification includes: according to the number of types of user information classification, the cloud server is divided into four levels, and the cloud servers at the four levels store the public information, restricted information, sensitive information, and confidential information accessed by the user respectively; there are multiple cloud servers at the same level, and the lower the level of the cloud server storing the user access data, the more the number of corresponding cloud servers.
[0008] Specifically, the information accessed by the administrator is classified, and each classification corresponds to a different permission level, including: classifying the administrator into ordinary administrator, content administrator, system administrator, and super administrator according to user support request records, content review records, system operation logs, and system configuration and security settings; among them, the ordinary administrator only has the permission to access user support request records, the content administrator has the permission to access user support request records and content review records, the advanced user has the permission to access user support request records, content review records, and system operation logs, and the super administrator has the permission to access user support request records, content review records, system operation logs, and system configuration and security settings; the number of levels divided by the cloud server is the same as the number of types of administrator management permission classifications, including: dividing the cloud server into four levels according to the number of types of information classifications accessed by the administrator, and the four-level cloud servers store user support request records, content review records, system operation logs, and system configuration and security settings respectively; there are multiple cloud servers of the same level, and the lower the data level stored by the administrator access, the more the number of corresponding cloud servers.
[0009] Specifically, the user platform determines the allowed access level of the user by including the user's access habits and environment, including: First, according to the formula R = α1·E 1行为 +β1·S 1环境 +γ1·C 1资源 Calculate the risk score of the user, where E 1行为 refers to the user's behavior habits, S 1环境 refers to the physical, technical, and contextual environment when the user accesses information, and C 1资源Refers to the static and dynamic attributes of information and system resources themselves. α1, β1, and γ1 are dynamic weights, and R is the risk score of the corresponding user. Subsequently, according to the principle that the lower the risk score, the higher the level of cloud server allowed for the user to access, risk score settings are made for the four levels of cloud servers. The four levels of cloud servers are regarded as L1, L2, L3, and L4 from low to high. When the risk score R < R1, the corresponding cloud server level is L4; when the risk score R1 ≤ R < R2, the corresponding cloud server level is L3; when the risk score R2 ≤ R < R3, the corresponding cloud server level is L2; when the risk score R ≥ R3, the corresponding cloud server level is L1. The user platform information of cloud servers not higher than the corresponding level is called for the user to access according to the determined allowed access level of the user, including: when the risk score R < R1, the corresponding cloud server level is L4, then all cloud servers covering levels L1, L2, L3, and L4 are called for the user to access; when the risk score R1 ≤ R < R2, the corresponding risk server level is L3, then all cloud servers covering levels L1, L2, and L3 are called for the user to access; when the risk score R2 ≤ R < R3, the corresponding risk server level is L2, then the cloud servers of levels L1 and L2 are called for the user to access; when the risk score R ≥ R3, the corresponding risk server level is L1, then only the cloud server of level L1 can be called for the user to access.
[0010] Specifically, the management platform determines the allowed access level of the management personnel by including the access habits and environment of the management personnel, including: First, according to the formula R′ = α′2·E 2行为 +β′2·S 2环境 +γ2′·C 2资源 Calculate the risk score of the corresponding management personnel, where E 2行为 Refers to the behavior habits of the corresponding management personnel, S 2环境 Refers to the physical, technical, and contextual environment when the corresponding management personnel access information, C 2资源Refers to the static and dynamic attributes of information and system resources themselves. α2′, β′2, and γ2′ are the corresponding dynamic weights, and R' is the risk score of the corresponding management personnel. Subsequently, according to the principle that the lower the risk score, the higher the level of the cloud server allowed for the management personnel to access, the risk scores of the management personnel are set for the four levels of the cloud server. The four levels of the cloud server are regarded as L1′, L2′, L3′, and L4′ from low to high. When the risk score R' < R1', it corresponds to the cloud server level L4′; when the risk score R1' ≤ R' < R'2, it corresponds to the cloud server level L3′; when the risk score R'2 ≤ R' < R3', it corresponds to the cloud server level L2′; when the risk score R' ≥ R3', it corresponds to the cloud server level L1′. The connection interface of the corresponding level of the cloud server is called according to the determined allowed access level of the management personnel to establish a connection with the device of the management personnel, including: when the risk score R' < R1', corresponding to the cloud server level L4′, then call all the cloud servers covering the levels L1′, L2′, L3′, and L4′ to establish a connection with the device of the management personnel for the management personnel to conduct business processing; when the risk score R1' ≤ R' < R'2, corresponding to the risk server level L3′, then call all the cloud servers covering the levels L1′, L2′, and L3′ to establish a connection with the device of the management personnel for the management personnel to conduct business processing; when the risk score R'2 ≤ R' < R3', corresponding to the risk server level L2′, then call the cloud servers of the levels L1′ and L2′ to establish a connection with the device of the management personnel for the management personnel to conduct business processing; when the risk score R' ≥ R3', corresponding to the risk server level L1′, then only call the cloud server of the level L1′ to establish a connection with the device of the management personnel for the management personnel to conduct business processing.
[0011] Specifically, the cloud server hierarchical access mechanism includes: users can only access the user platform information stored on the cloud server, and management personnel can only access and process the management platform information stored on the cloud server.
[0012] The cloud server hierarchical access mechanism includes: establishing the protocols from the user platform to the cloud server and from the management platform to the cloud server through HTTP / HTTPS respectively, and implementing the algorithms and methods from the user platform and the management platform to the cloud server through the API (Application Programming Interface) respectively.
[0013] The beneficial effects of the present invention are:
[0014] The present invention provides a protocol security sharing method for cloud dynamic permission grading; it has the following advantages:
[0015] 1. In the present invention, the user platform information and the management platform information are respectively stored in different regions of the cloud server and hierarchically stored on cloud servers of different levels. When users and managers access information, different levels of cloud servers can be respectively matched according to the risk levels of users and managers, and users and managers can respectively complete the access and management of the corresponding level of servers. This process processes the user platform information and the management platform information separately, and matches the corresponding cloud servers for users and managers with different risk levels, increasing the security and flexibility of the cloud environment.
[0016] 2. The method designs the levels of cloud servers for user platform information and management platform information into four levels respectively, and gives the rules for users and managers with corresponding risk levels to access the corresponding level of cloud servers, enabling the access of user information and manager information to be carried out simultaneously on the same cloud server without affecting each other. This makes the access responses for users and managers more hierarchical, and increases security and efficiency. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Figure 1 It is a flowchart of the protocol security sharing method for dynamic permission grading in the cloud of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0018] The following describes the specific embodiments of the present invention in detail with reference to the accompanying drawings. It should be understood that the specific embodiments given here are only for the purpose of illustrating and explaining the present invention and should not be used to limit the present invention.
[0019] It should be noted that many specific details are set forth in the following description to facilitate a full understanding of the present invention. However, the present invention may have other embodiments and variations, and therefore, the protection scope of the present invention is not limited by the specific embodiments disclosed below.
[0020] Such as Figure 1As shown, a flowchart of a protocol security sharing method for cloud dynamic permission grading according to an embodiment of the present invention; the flowchart includes: Step S1001, cloud server grading storage mechanism: user platform information grading storage and management platform information grading storage; the user platform information grading storage is used for grading and storing various information of users, and the method of user platform information grading storage is: First, classify the information accessed by users, and each classification corresponds to different level information; Subsequently, according to the types of user information classification, divide the cloud server into levels, and the number of levels divided by the cloud server is the same as the number of types of user information classification; Finally, store the user information corresponding to the level into the cloud server; the management platform information grading storage is used for grading and storing various information accessed by administrators, and the method of management platform information grading storage is: First, classify the information accessed by administrators, and each classification corresponds to different permission levels; Subsequently, according to the types of administrator management permission classification, divide the cloud server into management permission levels, and the number of levels divided by the cloud server is the same as the number of types of administrator management permission classification; Finally, store the management permission information corresponding to the level into the cloud server; Step S1002, cloud server grading access mechanism: If the access object is a user, the user platform determines the allowed access level of the user by including the user's access habits and environment, and calls the user platform information of the cloud server not higher than the corresponding level for the user to access according to the determined allowed access level of the user; the allowed access level refers to the highest level allowed for the user to access; If the access object is a management staff, the management platform determines the allowed access level of the management staff by including the management staff's access habits and environment, and calls the connection interface of the corresponding level of the cloud server to establish a connection with the management staff's device to perform management operations.
[0021] Specifically, in step S1001, the user platform information grading storage and the management platform information grading storage include: When storing user platform information and management platform information on the same cloud server at the same time, store the user platform information and the management platform information separately. The storage area for storing user platform information is called the user platform information dedicated area, and the storage area for storing management platform information is called the management platform information dedicated area.
[0022] Specifically, it further includes: classifying users into visitors, ordinary users, premium users, and super users according to the information accessed by the users, which includes public information, restricted information, sensitive information, and confidential information; among them, visitors only have the permission to access public information, ordinary users have the permission to access public information and restricted information, premium users have the permission to access public information, restricted information, and sensitive information, and super users have the permission to access public information, restricted information, sensitive information, and confidential information; the number of levels divided by the cloud server is the same as the number of types of user information classification, including: dividing the cloud server into four levels according to the number of types of user information classification, and the four-level cloud servers store the public information, restricted information, sensitive information, and confidential information accessed by the users respectively; there are multiple cloud servers of the same level, and the lower the level of the cloud server storing the user access data, the more the corresponding number of cloud servers.
[0023] Subsequently, according to the user support request records, content review records, system operation logs, system configuration, and security settings, administrators are divided into ordinary administrators, content administrators, system administrators, and super administrators; among them, ordinary administrators only have the permission to access user support request records, content administrators have the permission to access user support request records and content review records, premium users have the permission to access user support request records, content review records, and system operation logs, and super administrators have the permission to access user support request records, content review records, system operation logs, system configuration, and security settings; the number of levels divided by the cloud server is the same as the number of types of administrator management permission classification, including: dividing the cloud server into four levels according to the number of types of information accessed by the administrator, and the four-level cloud servers store the user support request records, content review records, system operation logs, system configuration, and security settings respectively; there are multiple cloud servers of the same level, and the lower the level of the cloud server storing the administrator access data, the more the corresponding number of cloud servers.
[0024] In step S1002, the method for the user platform to determine the allowed access level of the user by including the user's access habits and environment is: First, calculate the risk score of the user according to the formula R = α1·E 1行为 +β1·S 1环境 +γ1·C 1资源 where E 1行为 refers to the user's behavior habits, S 1环境 refers to the physical, technical, and contextual environment when the user accesses information, and C 1资源Refers to the static and dynamic attributes of information and system resources themselves. α1, β1, and γ1 are dynamic weights, and R is the risk score of the corresponding user. Subsequently, according to the principle that the lower the risk score, the higher the level of cloud server allowed for the user to access, risk score settings are made for the four levels of cloud servers. The four levels of cloud servers are regarded as L1, L2, L3, and L4 from low to high. When the risk score R < R1, it corresponds to the cloud server level L4; when the risk score R1 ≤ R < R2, it corresponds to the cloud server level L3; when the risk score R2 ≤ R < R3, it corresponds to the cloud server level L2; when the risk score R ≥ R3, it corresponds to the cloud server level L1. The method of calling the user platform information of cloud servers not higher than the corresponding level for the user to access according to the determined allowed access level of the user includes: when the risk score R < R1, corresponding to the cloud server level L4, then call all cloud servers covering levels L1, L2, L3, and L4 for the user to access; when the risk score R1 ≤ R < R2, corresponding to the risk server level L3, then call all cloud servers covering levels L1, L2, and L3 for the user to access; when the risk score R2 ≤ R < R3, corresponding to the risk server level L2, then call the cloud servers of levels L1 and L2 for the user to access; when the risk score R ≥ R3, corresponding to the risk server level L1, then only the cloud server of level L1 can be called for the user to access.
[0025] Specifically, it also includes that the method for the management platform to determine the allowed access level of the management staff through the access habits and environment of the management staff is as follows: First, according to the formula R′ = α′2·E 2行为 +β′2·S 2环境 +γ2′·C 2资源 Calculate the risk score of the corresponding management staff, where E 2行为 Refers to the behavior habits of the corresponding management staff, S 2环境 Refers to the physical, technical, and contextual environment where the corresponding management staff accesses information, and C 2资源Refers to the static and dynamic attributes of information and system resources themselves. α2′, β′2, and γ2′ are the corresponding dynamic weights, and R' is the risk score of the corresponding management personnel. Subsequently, according to the principle that the lower the risk score, the higher the level of cloud server allowed for the management personnel to access, the risk score settings of the management personnel are carried out for the four levels of cloud servers. The four levels of cloud servers are regarded as L1′, L2′, L3′, and L4′ from low to high. When the risk score R' < R1', the corresponding cloud server level is L4′; when the risk score R1' ≤ R' < R'2, the corresponding cloud server level is L3′; when the risk score R'2 ≤ R' < R3', the corresponding cloud server level is L2′; when the risk score R' ≥ R3', the corresponding cloud server level is L1′. The connection interface of the corresponding level of cloud server is called according to the determined allowed access level of the management personnel to establish a connection with the device of the management personnel, which includes: when the risk score R' < R1' and the corresponding cloud server level is L4′, all cloud servers covering levels L1′, L2′, L3′, and L4′ are called to establish a connection with the device of the management personnel for the management personnel to conduct business processing; when the risk score R1' ≤ R' < R'2 and the corresponding risk server level is L3′, all cloud servers covering levels L1′, L2′, and L3′ are called to establish a connection with the device of the management personnel for the management personnel to conduct business processing; when the risk score R'2 ≤ R' < R3' and the corresponding risk server level is L2′, the cloud servers of levels L1′ and L2′ are called to establish a connection with the device of the management personnel for the management personnel to conduct business processing; when the risk score R' ≥ R3' and the corresponding risk server level is L1′, only the cloud server of level L1′ can be called to establish a connection with the device of the management personnel for the management personnel to conduct business processing.
[0026] Specifically, it further includes: users can only access the user platform information stored on the cloud server, and management personnel can only access and process the management platform information stored on the cloud server. That is, even if users and management personnel access the same cloud server simultaneously, the cloud server respectively provides the user platform information for users to access and the management platform information for management personnel to access according to the algorithm process. The two processes can be implemented on the same computer, saving resources and enhancing security.
[0027] In the above embodiment, specifically, the cloud server hierarchical access mechanism includes: establishing the protocol from the user platform to the cloud server and the hierarchical protocol from the management platform to the cloud server through HTTP / HTTPS respectively, and implementing the algorithms and methods of the user platform and the management platform to the cloud server in step S1002 through the API (Application Programming Interface) respectively.
Claims
1. A protocol security sharing method for dynamic permission grading in the cloud, characterized in that, The method includes: Hierarchical storage mechanism of the cloud server: Hierarchical storage of user platform information and hierarchical storage of management platform information; the hierarchical storage of user platform information is used to hierarchically store various information of users. The method of hierarchical storage of user platform information is as follows: First, classify the information accessed by users, and each classification corresponds to different levels of information; subsequently, according to the types of user information classification, divide the levels of the cloud server, and the number of levels divided by the cloud server is the same as the number of types of user information classification; finally, store the user information corresponding to the level into the cloud server; the hierarchical storage of management platform information is used to hierarchically store various information accessed by administrators. The method of hierarchical storage of management platform information is as follows: First, classify the information accessed by administrators, and each classification corresponds to different permission levels; subsequently, according to the types of administrator management permission classification, divide the management permission levels of the cloud server, and the number of levels divided by the cloud server is the same as the number of types of administrator management permission classification; finally, store the management permission information corresponding to the level into the cloud server. Hierarchical access mechanism of the cloud server: If the access object is a user, the user platform determines the allowed access level of the user through the user's access habits and environment, and calls the user platform information of the cloud server not higher than the corresponding level for the user to access according to the determined allowed access level of the user; the allowed access level refers to the highest level allowed for the user to access; if the access object is a management personnel, the management platform determines the allowed access level of the management personnel through the management personnel's access habits and environment, and calls the connection interface of the cloud server at the corresponding level to establish a connection with the equipment of the management personnel to perform management operations.
2. The protocol security sharing method for cloud dynamic permission grading according to claim 1, characterized in that, The hierarchical storage of user platform information and the hierarchical storage of management platform information include: When storing user platform information and management platform information on the same cloud server at the same time, store the user platform information and management platform information separately. The storage area for storing user platform information is called the dedicated area for user platform information, and the storage area for storing management platform information is called the dedicated area for management platform information.
3. The protocol security sharing method for cloud dynamic permission grading according to claim 1, characterized in that, Classify the information accessed by users. Each classification corresponds to different levels of information, including: classifying the information accessed by users into public information, restricted information, sensitive information, and confidential information, and classifying users into visitors, ordinary users, advanced users, and super users; among them, visitors only have the permission to access public information, ordinary users have the permission to access public information and restricted information, advanced users have the permission to access public information, restricted information, and sensitive information, and super users have the permission to access public information, restricted information, sensitive information, and confidential information; the number of levels divided by the cloud server is the same as the number of types of user information classifications, including: according to the number of types of user information classifications, the cloud server is divided into four levels, and the four-level cloud servers store public information, restricted information, sensitive information, and confidential information accessed by users respectively; there are multiple cloud servers of the same level, and the lower the level of the data accessed by users stored, the more the number of corresponding cloud servers.
4. The protocol security sharing method for cloud dynamic permission grading according to claim 1, wherein Classify the information accessed by administrators. Each classification corresponds to different permission levels, including: classifying administrators into ordinary administrators, content administrators, system administrators, and super administrators according to user support request records, content review records, system operation logs, and system configuration and security settings; among them, ordinary administrators only have the permission to access user support request records, content administrators have the permission to access user support request records and content review records, advanced users have the permission to access user support request records, content review records, and system operation logs, and super administrators have the permission to access user support request records, content review records, system operation logs, and system configuration and security settings; the number of levels divided by the cloud server is the same as the number of types of administrator management permission classifications, including: according to the number of types of information classifications accessed by administrators, the cloud server is divided into four levels, and the four-level cloud servers store user support request records, content review records, system operation logs, and system configuration and security settings respectively; there are multiple cloud servers of the same level, and the lower the level of the data accessed by administrators stored, the more the number of corresponding cloud servers.
5. The protocol security sharing method for cloud dynamic permission grading according to claim 1, characterized in that, The user platform determines the user's allowed access level by including the user's access habits and environment, which includes: First, according to the formula R = α1·E 1行为 +β1·S 1环境 +γ1·C 1资源 Calculate the risk score of the user. Among them, E 1行为 refers to the user's behavior habits, S 1环境 refers to the physical, technical and contextual environment when the user accesses information, C 1资源 refers to the static and dynamic attributes of the information and system resources themselves. α1, β1 and γ1 are dynamic weights, and R is the risk score corresponding to the user. Subsequently, according to the principle that the lower the risk score, the higher the level of the cloud server allowed for the user to access, set the risk scores for the four levels of the cloud server; regard the four levels of the cloud server from low to high as L1, L2, L3 and L4 respectively. When the risk score R < R1, it corresponds to the cloud server level L4; when the risk score R1 ≤ R < R2, it corresponds to the cloud server level L3; when the risk score R2 ≤ R < R3, it corresponds to the cloud server level L2; when the risk score R ≥ R3, it corresponds to the cloud server level L1; The user platform information that calls the cloud server not higher than the corresponding level according to the determined user's allowed access level for the user to access includes: when the risk score R < R1, it corresponds to the cloud server level L4, then call all cloud servers covering levels L1, L2, L3 and L4 for the user to access; when the risk score R1 ≤ R < R2, it corresponds to the risk server level L3, then call all cloud servers covering levels L1, L2 and L3 for the user to access; when the risk score R2 ≤ R < R3, it corresponds to the risk server level L2, then call the cloud servers of levels L1 and L2 for the user to access; when the risk score R ≥ R3, it corresponds to the risk server level L1, then only the cloud server of level L1 can be called for the user to access.
6. The protocol security sharing method for cloud dynamic permission grading according to claim 1, wherein, The management platform determines the allowed access level of the management personnel by including the access habits and environment of the management personnel, including: First, according to the formula R′ = α′2·E 2行为 +β′2·S 2环境 +γ2′·C 2资源 Calculate the risk score corresponding to the management personnel, where E 2行为 Refers to the behavior habits of the corresponding management personnel, S 2环境 Refers to the physical, technical, and contextual environment when the corresponding management personnel access information, C 2资源 Refers to the static and dynamic attributes of the information and system resources themselves, α2′, β′2, and γ2′ are the corresponding dynamic weights, and R' is the risk score corresponding to the management personnel; Subsequently, according to the principle that the lower the risk score, the higher the level of the cloud server allowed for the management personnel to access, set the risk scores of the management personnel for the four levels of the cloud server; Consider the four levels of the cloud server from low to high as L1′, L2′, L3′, and L4′ respectively. When the risk score R' < R1', it corresponds to the cloud server level L4′; When the risk score R1' ≤ R' < R'2, it corresponds to the cloud server level L3′; When the risk score R'2 ≤ R' < R3', it corresponds to the cloud server level L2′; When the risk score R' ≥ R3', it corresponds to the cloud server level L1′; The connection interface of the corresponding level of the cloud server is called according to the determined allowed access level of the management personnel to establish a connection with the device of the management personnel, including: When the risk score R' < R1', it corresponds to the cloud server level L4′, then call all the cloud servers covering the levels L1′, L2′, L3′, and L4′ to establish a connection with the device of the management personnel for the management personnel to conduct business processing; When the risk score R1' ≤ R' < R'2, it corresponds to the risk server level L3′, then call all the cloud servers covering the levels L1′, L2′, and L3′ to establish a connection with the device of the management personnel for the management personnel to conduct business processing; When the risk score R'2 ≤ R' < R3', it corresponds to the risk server level L2′, then call the cloud servers of the levels L1′ and L2′ to establish a connection with the device of the management personnel for the management personnel to conduct business processing; When the risk score R' ≥ R3', it corresponds to the risk server level L1′, then only the cloud server of the level L1′ can be called to establish a connection with the device of the management personnel for the management personnel to conduct business processing.
7. The protocol security sharing method for cloud dynamic permission grading according to claim 1, characterized in that, The hierarchical access mechanism of the cloud server includes: users can only access the user platform information stored on the cloud server, and administrators can only access and process the management platform information stored on the cloud server.
8. The protocol security sharing method for cloud dynamic permission grading according to claim 1, characterized in that The hierarchical access mechanism of the cloud server includes: establishing protocols between the user platform, the management platform, and the cloud server through HTTP / HTTPS respectively; the steps for establishing the protocol are: the user platform receives a new protocol library file joined by the user and transmits the file to the management platform; the management platform reviews the new protocol library file and transmits the approved new protocol library file to all cloud servers; the cloud server establishes a hierarchical storage and access mechanism with the user platform and the management platform through the protocol in the received new protocol library file; and implements the algorithms and methods from the user platform and the management platform to the cloud server through the API (Application Programming Interface) respectively.
Citation Information
Patent Citations
Hierarchical management method and system for cloud platform resource access authorities
CN106453395A
Access control method based on industrial Internet of Things
CN117395037A
Data security sharing method and system based on lake and platform integration
CN118101261A
Multi-tenant management and control method, device and equipment, storage medium and computer program product
CN119602997A