User behavior data security management method based on CDP client data platform

By setting access permission levels and caching mechanisms on the CDP customer data platform, calculating risk indexes using historical data, and prioritizing parallel distributed verification of low-risk data, it solves the problem of extended system response time caused by complex permission verification, and improves user experience and system security.

CN120337257AActive Publication Date: 2025-07-18SHANGHAI TRUELAND INFORMATION & TECH CO LTD
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
CN202510422341.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-07
Publication Date
2025-07-18
Estimated Expiration
2045-04-07

AI Technical Summary

Technical Problem

In the prior art, when multiple access to user behavior data, complex permission verification leads to an extended system response time, affecting business efficiency and user experience.

Method used

By setting access permission levels and caching mechanisms, using historical access data to calculate service frequency and close values, perform identity and business comparison, dynamically evaluate data permission index and access permission index, give priority to displaying low-risk data, and parallel distributed verification.

Benefits of technology

Verify the identity of the visitor and business operations in a short period of time, reduce repeated verification time, improve user experience, prevent permission abuse, improve verification efficiency and system security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120337257A_ABST
    Figure CN120337257A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of data security management, and particularly discloses a user behavior data security management method based on a CDP client data platform, which comprises the following steps: S1, setting a plurality of business operations, and setting permission levels; when an access person wants to access the user behavior data, access information is acquired; s2, acquiring historical access data, and calculating a service frequency value and a service osculation value; s3, recording access information and target data of the visitors after the visitors complete one-time access; setting a cache time period, and performing identity comparison and service comparison when a new visitor accesses in the cache time period; if so, calculating a data permission index and an access permission index; s4, obtaining low-risk data according to the data permission index and the access permission index, and directly displaying the low-risk data to a new visitor; and predicting loading time, and performing distributed verification on the verification information within the loading time.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security management, and particularly relates to a method for managing the security of user behavior data based on a CDP (Customer Data Platform). Background Art

[0002] User behavior data refers to various data generated by users during the interaction with products or services, which can reflect users' behavior habits, preferences, and needs; it includes browsing behavior data, click behavior data, search behavior data, etc.

[0003] In today's digital age, data, as an important asset of enterprises and organizations, its security management is of vital importance. Among them, the access and management of user behavior data is a key task. In actual business scenarios, when accessing user behavior data, there is such a situation: for certain specific operations, due to the complexity of business logic or the requirements of data sensitivity, it is often necessary to access relevant data multiple times. For example, in some business processes involving multiple steps, the system may need to query and process users' behavior data multiple times at different stages to ensure the integrity and accuracy of the business process.

[0004] However, when accessing this user behavior data each time, if a complex permission verification mechanism is adopted, although it can effectively protect the data from being illegally accessed and misused from a security perspective, it will bring a significant problem, that is, the efficiency of the entire access process will become slower. Specifically, complex permission verification may involve inspections and verifications of multiple links, such as the confirmation of the authenticity of the user's identity, the matching verification of the user's role, the refinement check of the operation permissions, etc. Each link requires the system to perform corresponding processing and judgment, which undoubtedly increases the processing time and resource overhead of the system. When this situation of multiple accesses and complex permission verification each time occurs frequently, it will extend the response time of the entire system, thereby affecting the operation efficiency of the business and reducing the user experience Summary of the Invention

[0005] The purpose of the present invention is to provide a method for managing the security of user behavior data based on a CDP customer data platform to solve the above technical problems.

[0006] The purpose of the present invention can be achieved through the following technical solutions: A method for managing the security of user behavior data based on a CDP customer data platform includes the following steps: Step S1: Set a number of business operations, and set the access permission levels of each access person and the permission levels of each user behavior data; when an access person accesses user behavior data, obtain the access information of the access person; Step S2: Obtain historical access data. According to the historical access data, obtain the business frequency value of the user behavior data and the business intimacy value of the access personnel. Step S3: After an access personnel completes an access, record the access information of the access personnel and record the target data. Set a cache time period. If there is a new access personnel accessing during the cache time period, obtain the identity comparison result and the business comparison result. If both the identity comparison result and the business comparison result are consistent, obtain the data permission index and the access permission index according to the access information. Step S4: According to the data permission index and the access permission index, obtain low-risk data, directly display the low-risk data to the new access personnel, predict the loading time, and perform distributed verification on the verification information within the loading time.

[0007] As a further solution of the present invention: The access information includes the identity information, verification information, and target business operation of the access personnel, and the target business operation is the business operation to be executed by the access personnel.

[0008] As a further solution of the present invention: The historical access data includes the identity information of the access personnel and the target business operation when each user behavior data is accessed.

[0009] As a further solution of the present invention: The obtaining process of the business frequency value and the business intimacy value includes: According to the historical access data, obtain the business frequency value Bfv between the user behavior data and the i-th business operation i =Nob i / Ntv, where Ntv represents the total number of times the user behavior data is accessed, and Nob i represents the number of times the target business operation of the user behavior data when accessed is the i-th business operation; And according to the historical access data, obtain the business intimacy value Bcv between the access personnel and the i-th business operation i =nob i / ntv, where ntv represents the total number of times the access personnel accesses all user behavior data, and nob i represents the number of times the target business operation of the access personnel when accessing is the i-th business operation.

[0010] As a further solution of the present invention: The setting process of the cache time period includes, according to the historical access data, obtaining the time interval between each access, obtaining the average value of all time intervals, and recording it as the cache time period.

[0011] As a further solution of the present invention: The obtaining process of the identity comparison result and the business comparison result includes: Record the new access personnel as the current access personnel, obtain the identity information of the current access personnel, denoted as the current identity information, and obtain the target business operation of the current access personnel, denoted as the current business operation; Respectively obtain the texts of the identity information and the current identity information, and denote them as the identity information text and the current identity information text respectively. Respectively perform text recognition on the identity information text and the current identity information text to respectively obtain the text features of the identity information text and the current identity information text, and obtain the similarity of the two text features, denoted as the identity comparison result; Respectively obtain the texts of the target business operation and the current business operation, and denote them as the target business operation text and the current business operation text respectively. Respectively perform text recognition on the target business operation text and the current business operation text to respectively obtain the text features of the target business operation text and the current business operation text, both denoted as business text features, and obtain the similarity of the two business text features, denoted as the business similarity; Denote the business similarity as the business comparison result.

[0012] As a further solution of the present invention: The process of determining whether the identity comparison result or the business comparison result is consistent includes: Set a first similarity threshold and a second similarity threshold. If the similarity exceeds the first similarity threshold, then record the identity comparison result as consistent; otherwise, record the identity comparison result as inconsistent; If the business similarity exceeds the second similarity threshold, then record the business comparison result as consistent; otherwise, record the business comparison result as inconsistent.

[0013] As a further solution of the present invention: The process of obtaining the permission index and the access permission index includes: Obtain all the permission levels of the target data, and after sorting them from low to high, obtain the permission level sequence {L1, L2,..., L n}, where L n represents the nth permission level, and n is the total number of permission levels; Number each permission level in the permission level sequence to obtain the number corresponding to the permission level of the target data, denoted as the permission level index; According to the permission level of the target data, obtain the permission level index Pi of the target data; According to the permission level index, obtain the data permission index DPI of the target data = β 1Pi + β 2Bfv, where β 1 is the first weight coefficient, β 2 is the second weight coefficient, and β 1 > β2 > 0, where Bfv is the business frequency value between the target data and the current business operation; Obtain all the access permission levels of the access personnel, and after sorting them from low to high, obtain the access permission level sequence {L1´, L2´,..., L m ´}, where L m ´ represents the m-th access permission level, and m is the total number of access permission levels; number each access permission level in the access permission level sequence, denoted as the level number; obtain the level number corresponding to the access permission level of the current access personnel, denoted as the access level index; According to the access permission level of the current access personnel, obtain the access level index Ai of the current access personnel; according to the access level index, obtain the access permission index API of the current access personnel = β 1Ai + β 2Bcv, where Bcv is the business closeness value between the current access personnel and the current business operation.

[0014] As a further solution of the present invention: the process of obtaining the low-risk data includes selecting a number of target data whose data permission index is less than or equal to the access permission index, denoted as low-risk data.

[0015] As a further solution of the present invention: the process of distributed verification includes: Obtain the time required to consume the user behavior data of the query unit data volume, denoted as the query time t c , and obtain the time required to consume the user behavior data of the display unit data volume, denoted as the display time t z ; obtain the data volume V of each low-risk data, then the loading time T = V(t c + t z ); Establish a number of verification nodes, and the verification nodes are used to distributively verify the verification information; obtain the access information of the current access personnel to obtain the verification information of the current access personnel; divide the verification information into several sub-information, and distribute the sub-information to each verification node, and the distribution process satisfies the constraint , where t k represents the time consumed by the verification node to verify the k-th sub-information, k is the total number of sub-information, and num is the total number of verification nodes; If the verification information passes the verification, continue to query and display the remaining data to the current access personnel, and the remaining data is all the user behavior data in the target data except the low-risk data.

[0016] The beneficial effects of the present invention: Through the caching mechanism and identity and service comparison, the present invention can verify the identity and business operations of the accessing personnel in a short time, reducing the time consumption of repeated verification; give priority to displaying low-risk data to ensure that the accessing personnel can quickly obtain the required information and improve the user experience; verify the verification information of the accessing personnel in parallel through multiple verification nodes, which can effectively prevent single-point failures and malicious attacks and enhance the overall security; by calculating the data permission index (DPI) and access permission index (API), it can dynamically evaluate the risk level of data access to ensure that only accessing personnel meeting the permission requirements can access specific data; by dividing the verification information into multiple sub-information and distributing them to multiple verification nodes for parallel verification, it can make full use of computing resources and improve the verification efficiency; it can dynamically adjust the distribution method of sub-information according to the performance and current load of the verification nodes to ensure the high efficiency of the verification process; by setting time constraint conditions, it ensures that the verification process is completed within a reasonable time to prevent the verification process from being too long and affecting the user experience; by calculating DPI and API, it can conduct risk classification management on data, give priority to processing low-risk data, and reduce system risks; according to the historical behavior data of the accessing personnel, dynamically adjust their access permissions to ensure that they can complete their work efficiently while preventing abuse of permissions. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] The present invention will be further described below with reference to the drawings.

[0018] Figure 1 It is a schematic flow chart of a user behavior data security management method based on the CDP customer data platform of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0019] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0020] Please refer to Figure 1 as shown, the present invention is a user behavior data security management method based on the CDP customer data platform, including the following steps: Step S1: Set a number of business operations, and set the access permission levels of each accessing personnel and the permission levels of each user behavior data; when an accessing personnel accesses user behavior data, obtain the identity information and verification information of the accessing personnel, and obtain the target business operation of the accessing personnel, where the target business operation is the business operation to be executed by the accessing personnel; when the accessing personnel accesses user behavior data, verify the verification information, and if the verification is passed, allow the accessing personnel to access the user behavior data; It is understandable that several business operations are set first, and corresponding permission levels are assigned to each access person and user behavior data; when an access person attempts to access user behavior data, their identity information and verification information are obtained, and the target business operation to be executed is determined; the verification information of the access person is verified; As a preferred embodiment of the present invention, the setting of the business operations includes product recommendation, user grouping, abnormal login monitoring, and sales prediction; It should be noted that the business operation is the name of the business operation that needs to be completed by querying user behavior data within an enterprise. The business operation can be diversely classified according to different industries, different business fields, and specific business processes. The business operation covers the core business links of the daily operation of the enterprise; As a preferred embodiment of the present invention, the identity information includes an account number, a mobile phone number, or a name; As a preferred embodiment of the present invention, if the verification fails, the access person is not allowed to access the user behavior data, and the access person is prompted that the verification has failed; It should be noted that the verification information of the access person varies according to the different verification methods adopted. When the verification method is password verification, the verification information is the password input by the access person; when the verification method is biometric verification, the verification information is the biometric of the access person, and the biometric includes fingerprints and facial features; Step S2: Obtain historical access data, where the historical access data includes the identity information and target business operation of the access person when each user behavior data is accessed; according to the historical access data, obtain the business frequency value Bfv between the user behavior data and the i-th business operation i =Nob i / Ntv, where Ntv represents the total number of times the user behavior data is accessed, and Nob i represents the number of times the target business operation when the user behavior data is accessed is the i-th business operation; And according to the historical access data, obtain the business closeness value Bcv between the access person and the i-th business operation i =nob i / ntv, where ntv represents the total number of times the access person accesses all user behavior data, and nob i represents the number of times the target business operation when the access person accesses is the i-th business operation; It can be understood that the business frequency value quantifies the dependence degree or association strength of a specific business operation on the user behavior data by calculating the access frequency between a certain user behavior data and the specific business operation. A high Bfv value indicates a high correlation between the user behavior data and the specific business operation; the business closeness value quantifies the dependence degree or association strength of a certain access person on the specific business operation by calculating the access frequency between the access person and the specific business operation. A high Bcv value indicates that the access person has a high operation frequency for the specific business operation. Step S3: After the access person completes an access, record the target business operation, identity information, and verification information of the access person, and record all the user behavior data accessed by the access person, denoted as target data. Set a cache time period. If there is a new access person accessing during the cache time period, record the new access person as the current access person; obtain the identity information of the current access person, denoted as the current identity information, and obtain the target business operation of the current access person, denoted as the current business operation; compare the identity information and the current identity information to obtain an identity comparison result, and compare the target business operation and the current business operation to obtain a business comparison result. When and only when both the identity comparison result and the business comparison result are consistent, obtain the permission level index Pi of the target data according to the permission level of the target data, and obtain the access level index Ai of the current access person according to the access permission level of the current access person; according to the permission level index, obtain the data permission index DPI of the target data = β 1Pi + β 2Bfv, where β 1 is the first weight coefficient, β 2 is the second weight coefficient, and β 1 > β 2 > 0, Bfv is the business frequency value between the target data and the current business operation; and according to the access level index, obtain the access permission index API of the current access person = β 1Ai + β 2Bcv, where Bcv is the business closeness value between the current access person and the current business operation. It can be understood that by comparing the identity information and target business operation of the current access person with the previously recorded information, an identity comparison result and a business comparison result are obtained; only when both the identity comparison result and the business comparison result are consistent, will subsequent permission evaluation be carried out; by calculating the data permission index (DPI) and the access permission index (API), the risk level of data access is quantified. It should be noted that in the data permission index and the access permission index, the level of the permission of the target data or the access personnel is one of the factors affecting the risk level of its access; and the business frequency value of the target business operation represents the intensity of the correlation between the target business operation and the target data, and the business closeness value represents the intensity of the correlation between the access personnel and the target business operation. Both of these are used to reflect the level of risk of the behavior of the access personnel; In a preferred embodiment of the present invention, the process of setting the cache time period includes: According to the historical access data, obtain the time intervals between each access, and obtain the average value of all the time intervals, which is recorded as the cache time period; In a preferred embodiment of the present invention, the process of obtaining the identity comparison result and the business comparison result includes: Respectively obtain the texts of the identity information and the current identity information, and record them as the identity information text and the current identity information text respectively. Respectively perform text recognition on the identity information text and the current identity information text to obtain the text features of the identity information text and the current identity information text respectively. Obtain the similarity of the two text features, which is recorded as the identity comparison result; Respectively obtain the texts of the target business operation and the current business operation, and record them as the target business operation text and the current business operation text respectively. Respectively perform text recognition on the target business operation text and the current business operation text to obtain the text features of the target business operation text and the current business operation text respectively, both of which are recorded as business text features. Obtain the similarity of the two business text features, which is recorded as the business similarity; Record the business similarity as the business comparison result; In a preferred embodiment of the present invention, the process of determining whether the identity comparison result or the business comparison result is consistent includes: Set a first similarity threshold and a second similarity threshold. If the similarity exceeds the first similarity threshold, record the identity comparison result as consistent; otherwise, record the identity comparison result as inconsistent; if the business similarity exceeds the second similarity threshold, record the business comparison result as consistent; otherwise, record the business comparison result as inconsistent; In a preferred embodiment of the present invention, the process of obtaining the access level index and the data permission index includes: Obtain all the permission levels of the target data, and after sorting them from low to high, obtain a permission level sequence {L1, L2,..., L n}, where L n represents the nth permission level, and n is the total number of permission levels; number each permission level in the permission level sequence, and obtain the number corresponding to the permission level of the target data, which is recorded as the permission level index; Obtain all access privilege levels of the access personnel, and after sorting them from low to high, obtain an access privilege level sequence {L1´, L2´,..., L m ´}, where L m ´ represents the m-th access privilege level, and m is the total number of access privilege levels; number each access privilege level in the access privilege level sequence, denoted as the level number; obtain the level number corresponding to the access privilege level of the current access personnel, denoted as the access level index; As a preferred embodiment of the present invention, if both the identity comparison result and the service comparison result are inconsistent, then obtain the verification information of the current access personnel, denoted as the current verification information, verify the current verification information, and after passing the verification, allow the current access personnel to access; It should be noted that when and only when both the identity comparison result and the service comparison result are consistent, it indicates that the current access personnel and the previous access personnel are the same person, and the business operations they perform are also the same; the consistency of the identity comparison result means that the identity information of the current access personnel is completely matched with the identity information in the previous access record, indicating that the current access personnel and the previous access personnel are the same person; the consistency of the service comparison result means that the target business operation of the current access personnel is completely matched with the target business operation in the previous access record, indicating that the current access personnel and the previous access personnel perform the same business operation; Step S4: Establish a number of verification nodes, which are used to distributively verify the verification information; select a number of target data whose data privilege index is less than or equal to the access privilege index, denoted as low-risk data; directly display the low-risk data to the current access personnel, predict the loading time of the low-risk data, where the loading time is the time consumed to query and display the low-risk data, and obtain the verification information of the current access personnel, and the verification nodes distributively verify the verification information within the loading time; if the verification information passes the verification, continue to query and display the remaining data to the current access personnel, and the remaining data is all user behavior data other than the low-risk data among the target data; As a preferred embodiment of the present invention, if the privilege indices of all target data are greater than the access privilege index, then obtain the verification information of the current access personnel, denoted as the current verification information, verify the current verification information, and after passing the verification, allow the current access personnel to access; As a preferred embodiment of the present invention, the prediction process of the loading time includes: Obtain the time required to query user behavior data with a unit data volume, denoted as the query time t c, and obtain the time required to consume the user behavior data showing the data volume of the display unit, denoted as the display time t z ; obtain the data volume V of each low-risk data, then the loading time T = V(t c +t z ); As a preferred embodiment of the present invention, the process of the distributed verification includes: Divide the verification information into several sub-information, and distribute the sub-information to each verification node, and the distribution process satisfies the constraint , where t k represents the time consumed by the verification node to verify the k-th sub-information, k is the total number of sub-information, and num is the total number of verification nodes; As a preferred embodiment of the present invention, the process of the distributed verification further includes: Obtain the verification duration T t =t1+t2+...+t k , if in the case of k = num, T t >T always holds, then obtain the minimum value of the verification duration, obtain the allocation method corresponding to the minimum value, and perform distributed verification on the verification information according to the allocation method; It can be understood that the verification information is divided into several sub-information, and each sub-information can be verified independently. These sub-information are distributed to different verification nodes to achieve parallel processing; the loading time T is the maximum allowed verification time, and the total number of sub-information cannot exceed the total number of verification nodes; if all verification nodes are used and the verification duration exceeds the loading time, the system searches for the minimum value of the verification duration and performs distributed verification according to this allocation method; It should be noted that by dividing the verification information into multiple sub-information and distributing them to multiple verification nodes for parallel verification, the efficiency of the verification process can be significantly improved. Parallel processing reduces the total verification time and improves the response speed; by setting constraints, it is ensured that the verification process is completed within a reasonable time. This real-time performance guarantees the user experience and prevents the verification process from being too long and affecting the system performance; by optimizing the allocation method of sub-information, the system can make full use of the computing resources of all verification nodes; As a preferred embodiment of the present invention, if the verification of the verification information fails, no further query and display of the remaining data will be made to the current access person, and the current access person will be prompted that the verification fails; The above has described a detailed description of an embodiment of the present invention, but the content described above is only a preferred embodiment of the present invention and cannot be considered as limiting the scope of implementation of the present invention. Any equal changes and improvements made according to the scope of the application of the present invention shall still fall within the scope covered by the patent of the present invention.

Claims

1. A method for user behavior data security management based on a CDP customer data platform, characterized in that, It includes the following steps: Step S1: Set a number of business operations, and set the access privilege levels of each access person and the privilege levels of each user behavior data; When an access person accesses user behavior data, obtain the access information of the access person; Step S2: Obtain historical access data, and based on the historical access data, obtain the business frequency value of the user behavior data and the business closeness value of the access person; Step S3: After an access person completes an access, record the access information of the access person and record the target data; Set a cache time period. If there is a new access person accessing during the cache time period, obtain the identity comparison result and the business comparison result; If both the identity comparison result and the business comparison result are consistent, obtain the data privilege index and the access privilege index based on the access information; Step S4: Based on the data privilege index and the access privilege index, obtain low-risk data, directly display the low-risk data to the new access person, and predict the loading time, and perform distributed verification on the verification information within the loading time.

2. The user behavior data security management method based on the CDP customer data platform according to claim 1, wherein, In step S1, the access information includes the identity information, verification information, and target business operation of the access person, and the target business operation is the business operation to be performed by the access person.

3. A method for user behavior data security management based on a CDP customer data platform according to claim 2, characterized in that, In step S2, the historical access data includes the identity information and target business operation of the access person when each user behavior data is accessed.

4. A user behavior data security management method based on a CDP customer data platform according to claim 3, characterized in that In step S2, the obtaining process of the business frequency value and the business closeness value includes: Based on the historical access data, obtain the business frequency value Bfv between the user behavior data and the i-th business operation i =Nob i / Ntv, where Ntv represents the total number of times the user behavior data is accessed, and Nob i represents the number of times the target business operation is the i-th business operation when the user behavior data is accessed; And based on the historical access data, obtain the business closeness value Bcv between the access person and the i-th business operation i =nob i / ntv, where ntv represents the total number of times the access person accesses all user behavior data, and nob i represents the number of times the target business operation at the time of the access person's access is the i-th business operation.

5. A method for user behavior data security management based on a CDP customer data platform according to claim 3, characterized in that, In step S3, the setting process of the cache time period includes obtaining the time interval between each access based on the historical access data, obtaining the average value of all time intervals, and recording it as the cache time period.

6. The user behavior data security management method based on the CDP customer data platform according to claim 2, wherein, In step S3, the obtaining process of the identity comparison result and the business comparison result includes: Record the new access person as the current access person, obtain the identity information of the current access person, record it as the current identity information, and obtain the target business operation of the current access person, record it as the current business operation; Respectively obtain the texts of the identity information and the current identity information, and record them as the identity information text and the current identity information text respectively. Respectively perform text recognition on the identity information text and the current identity information text, respectively obtain the text features of the identity information text and the current identity information text, and obtain the similarity of the two text features, record it as the identity comparison result; Respectively obtain the texts of the target business operation and the current business operation, and record them as the target business operation text and the current business operation text respectively. Respectively perform text recognition on the target business operation text and the current business operation text, respectively obtain the text features of the target business operation text and the current business operation text, both are recorded as business text features, obtain the similarity of the two business text features, record it as the business similarity; Record the business similarity as the business comparison result.

7. A user behavior data security management method based on a CDP customer data platform according to claim 6, characterized in that In step S3, the process of determining whether the identity comparison result or the business comparison result is consistent includes: Set a first similarity threshold and a second similarity threshold. If the similarity exceeds the first similarity threshold, record the identity comparison result as consistent; otherwise, record the identity comparison result as inconsistent. If the business similarity exceeds the second similarity threshold, record the business comparison result as consistent; otherwise, record the business comparison result as inconsistent.

8. A user behavior data security management method based on a CDP customer data platform according to claim 1, characterized in that, In step S3, the process of obtaining the permission index and the access permission index includes: Obtain all the permission levels of the target data, and after sorting them from low to high, obtain a permission level sequence {L1, L2,..., L n}, where L n represents the nth permission level, and n is the total number of permission levels; number each permission level in the permission level sequence to obtain the number corresponding to the permission level of the target data, which is denoted as the permission level index; Obtain the privilege level index Pi of the target data according to the privilege level of the target data; obtain the data privilege index DPI of the target data according to the privilege level index DPI = β 1Pi + β 2Bfv, where β 1 is the first weight coefficient, β 2 is the second weight coefficient, and β 1 > β 2 > 0, Bfv is the business frequency value between the target data and the current business operation; Obtain all access privilege levels of the said visiting personnel, and after sorting them from low to high, obtain an access privilege level sequence {L1´, L2´,..., L m ´}, where L m ´ represents the m-th access privilege level, and m is the total number of access privilege levels; number each access privilege level within the said access privilege level sequence, and denote it as a level number; obtain the level number corresponding to the access privilege level of the said current visiting personnel, and denote it as an access level index; Obtain the access level index Ai of the current access personnel according to the access privilege level of the current access personnel; obtain the access privilege index API of the current access personnel according to the access level index β 1Ai + β 2Bcv, where Bcv is the business closeness value between the current access personnel and the current business operation.

9. A user behavior data security management method based on a CDP customer data platform according to claim 1, wherein, In step S4, the process of obtaining the low-risk data includes selecting a number of target data whose data permission index is less than or equal to the access permission index, and recording them as low-risk data.

10. A method for user behavior data security management based on a CDP customer data platform according to claim 6, characterized in that, In step S4, the process of distributed verification includes: The time required to obtain the user behavior data of the query unit data volume is denoted as the query time t c , and the time required to obtain the user behavior data of the display unit data volume is denoted as the display time t z ; Obtain the data volume V of each low-risk data, then the loading time T = V(t c +t z ); Establish a number of verification nodes, which are used to verify the verification information distributively; obtain the access information of the current access person to obtain the verification information of the current access person; divide the verification information into several sub-information, and distribute the sub-information to each verification node, and the distribution process satisfies the constraint , where t k represents the time consumed by the verification node to verify the k-th sub-information, k is the total number of sub-information, and num is the total number of verification nodes; If the verification information passes the verification, continue to query and display the remaining data to the current access personnel. The remaining data is all user behavior data in the target data except the low-risk data.

Citation Information

Patent Citations

  • Access control method and device, electronic equipment and medium

    CN111935165A

  • Data access control method and device

    CN114417399A

  • Full-process risk monitoring method and device based on large-scale parallel processing database

    CN117633834A

  • Software authorization authentication method

    CN118228211A

  • Data access authority control method

    CN118646603A