Multi-factor authentication trusted data space access control method, platform and medium
By analyzing and matching verification gradient generation of user permissions, access records, paths and targets, access permissions are dynamically adjusted, the problem of insufficient security in data space access control is solved, and data security and credibility are improved.
Patent Information
- Application Number
- CN202510575792.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-06
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2045-05-06
AI Technical Summary
In the prior art, data space access control lacks multi-factor dynamic authentication and fine-grained access control mechanisms, resulting in insufficient data security protection capabilities.
By performing user permissions, access records, access paths, and requesting access target analysis on the user requesting access users, obtaining user access parameters, and matching security level matching based on these parameters, generating matching verification gradients, using this gradient to identify and match authentication factor record information, creating authentication demand factors, and dynamically adjusting access permissions.
Dynamic adjustment of access permissions based on multi-factor authentication is realized, improving data security and trustworthiness during data space access.
Smart Images

Figure CN120342731A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data security, and particularly to a method, platform and medium for access control of a trusted data space with multi-factor authentication. Background Art
[0002] A trusted data space refers to a controlled environment that supports data storage, exchange and sharing on the basis of meeting security, privacy and trust requirements. It usually has security protection mechanisms such as identity authentication, permission management, and behavior auditing to ensure that data is not illegally accessed, tampered with or leaked during the circulation process. In a trusted data space, access control, as a core guarantee means, is directly related to the confidentiality and integrity of data resources. At present, traditional data access control methods mostly rely on a single authentication factor, such as static passwords, biometric identification or hardware tokens. However, in diverse user access scenarios and complex network environments, single-factor authentication is difficult to effectively identify impersonation, permission abuse and abnormal behaviors, resulting in obvious shortcomings in data security protection. At the same time, although existing multi-factor authentication methods introduce multiple authentication means, the authentication strategy has no association with the specific attributes of access requests, and fails to dynamically adjust the authentication intensity according to multi-dimensional data such as access paths, request targets, and historical records, resulting in the risk of insufficient utilization of authentication resources or failure of protection measures. Summary of the Invention
[0003] The present invention provides a method, platform and medium for access control of a trusted data space with multi-factor authentication to solve the technical problem in the prior art that there is a lack of multi-factor dynamic authentication and fine-grained access control mechanisms during the access process of the data space, resulting in insufficient data security protection capabilities, and to achieve the technical effect of dynamically adjusting access permissions based on multi-factor authentication and effectively improving the data security and trustworthiness during the access process of the data space.
[0004] In a first aspect, the present invention provides a method for access control of a trusted data space with multi-factor authentication, wherein the method for access control of a trusted data space with multi-factor authentication includes:
[0005] Analyze the user permissions, access records, access paths, and request access targets of the requesting access user to obtain user access parameters; according to the user access parameters, perform access verification security level matching from the user permissions, access records, access paths, and request access targets to obtain a matching verification gradient; use the matching verification gradient to perform identification matching with the authentication factor record information of the requesting access user to create a request user authentication requirement factor, and the request user authentication requirement factor has an authentication gradient constraint; according to the authentication result of the request user authentication requirement factor, send a space access permission result, and the space access permission result is used to control the access permission of the requesting access user to the trusted data.
[0006] Second aspect, the present invention further provides a trusted data space access control platform with multi-factor authentication, wherein the trusted data space access control platform with multi-factor authentication includes:
[0007] A user parsing module: parses the user permissions, access records, access paths, and requested access targets of the requesting access user to obtain user access parameters; A security level matching module: performs access verification security level matching based on the user access parameters from the user permissions, access records, access paths, and requested access targets to obtain a matching verification gradient; A factor identification and matching module: uses the matching verification gradient to perform identification and matching with the authentication factor record information of the requesting access user to create a requested user authentication requirement factor, and the requested user authentication requirement factor has an authentication gradient constraint; An access permission sending module: sends a space access permission result according to the authentication result of the requested user authentication requirement factor, and the space access permission result is used to control the access permission of the requesting access user to the trusted data.
[0008] Third aspect, the present invention further provides a computer-readable storage medium storing a computer program, which when executed by a processor, implements the multi-factor authentication-based trusted data space access control method provided by the present invention.
[0009] The present invention discloses a multi-factor authentication-based trusted data space access control method, platform, and medium, including: parsing the user permissions, access records, access paths, and requested access targets of the requesting access user to obtain user access parameters; performing access verification security level matching based on the user access parameters from the user permissions, access records, access paths, and requested access targets to obtain a matching verification gradient; using the matching verification gradient to perform identification and matching with the authentication factor record information of the requesting access user to create a requested user authentication requirement factor, and the requested user authentication requirement factor has an authentication gradient constraint; sending a space access permission result according to the authentication result of the requested user authentication requirement factor, and the space access permission result is used to control the access permission of the requesting access user to the trusted data. The multi-factor authentication-based trusted data space access control method, platform, and medium disclosed by the present invention solve the technical problem in the prior art that there is a lack of multi-factor dynamic authentication and fine-grained access control mechanisms during the data space access process, resulting in insufficient data security protection ability, and achieve the technical effect of dynamically adjusting access permissions based on multi-factor authentication and effectively improving the data security and trustworthiness during the data space access process. BRIEF DESCRIPTION OF THE DRAWINGS
[0010] Figure 1 It is a schematic flow chart of the multi-factor authentication-based trusted data space access control method of the present invention.
[0011] Figure 2It is a schematic structural diagram of the trusted data space access control platform for multi-factor authentication of the present invention.
[0012] Explanation of reference numerals in the drawings: User parsing module 11, security level matching module 12, factor identification and matching module 13, access permission sending module 14. Specific implementation mode
[0013] The following will combine the description of the drawings and specific implementation modes to elaborate on the above technical solutions in detail to better understand the above technical solutions. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments of the present invention. It should be understood that the present invention is not limited to the example embodiments for explaining the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention. In addition, it should be noted that for the sake of description, only the parts related to the present invention are shown in the drawings rather than all.
[0014] Embodiment 1, as Figure 1 It is a schematic flowchart of the trusted data space access control method for multi-factor authentication of the present invention. Among them, the trusted data space access control method for multi-factor authentication includes:
[0015] Parse the user permissions, access records, access paths, and requested access targets of the requesting access user to obtain user access parameters.
[0016] Specifically, when a requesting user initiates a request to access the trusted data space, the access situation of the user will be analyzed from four aspects: user permissions, access records, access paths, and the target of the requested access, in order to comprehensively understand the user's access situation. Regarding user permissions, by querying the user role and permission information recorded in the database, it is determined whether the user has the permission to access the target data or resources. User permissions usually include different access levels, such as administrator, ordinary user, read-only permission, etc. Through this step, it is ensured that only authorized users can access restricted resources. Regarding access records, by analyzing the user's historical access records, including the data accessed by the user, access time, access frequency, device information, etc., it is identified whether the user has abnormal behaviors (such as frequently accessing sensitive data), and it is judged whether there are potential risks for this user. Regarding access paths, information such as the source IP address of the user's access, the device used for access, and the network environment (such as VPN or direct connection) will be checked. The purpose of this process is to understand the security of the access environment. For example, if a user accesses from an untrusted IP address, a higher authentication level may be required. Regarding the target of the requested access, the specific target of the data resource or service requested by the user for access will be analyzed, which includes identifying the sensitivity and importance of the resource requested by the user. For example, whether the user is accessing ordinary files or sensitive data. According to the security level of the resource, the policies for authentication and access permissions will be adjusted. Finally, by integrating the above four information sources, user access parameters are generated, and these access parameters will provide basic data for subsequent access verification, authentication gradient matching, etc., to ensure that when granting access permissions, the security requirements of the user's identity, historical behavior, access environment, and access target can be comprehensively considered.
[0017] According to the user access parameters, perform access verification security level matching from the user permissions, access records, access paths, and the target of the requested access, and obtain a matching verification gradient.
[0018] Specifically, based on the user access parameters obtained from the previous step of parsing, security level verification and matching are respectively performed for the four dimensions of user permissions, access records, access paths, and requested access targets. Specifically, according to the user permission information in the user access parameters, analyze the permission category and authorization scope to which the user belongs, and determine the permission verification gradient corresponding to this permission category. Generally speaking, the higher the permission level, the stricter the corresponding verification requirements. According to the access record information in the user access parameters, extract the user's historical access characteristics and determine the user record verification gradient for this user. According to the access path in the user access parameters, analyze the device, network environment, source IP, etc. used by the user for the current access in the path information, evaluate the trustworthiness of the access path, and determine the access network verification gradient for this user. According to the requested access target in the user access parameters, parse the data sensitivity and security level of the requested access target, and determine the access data verification gradient for this user. Finally, by comparing and screening the verification gradients of each dimension, extract the one with the strictest verification requirements as the final matching verification gradient. This matching verification gradient is used to dynamically guide the setting of subsequent authentication policies, ensure that the authentication intensity matches the access risk, and thus while improving data security, avoid waste of authentication resources.
[0019] In some embodiments, according to the user access parameters, access verification security level matching is performed from the user permissions, access records, access paths, and requested access targets to obtain a matching verification gradient, including:
[0020] Analyze the user permission type according to the user permissions to determine the permission verification gradient; extract memory characteristics according to the access records to obtain the user record verification gradient; parse the access device, network environment, and network access path confidence according to the access path to determine the access network verification gradient; parse the security level of the access target according to the requested access target to obtain the access data verification gradient; extract the demand constraint gradients of each dimension according to the permission verification gradient, user record verification gradient, access network verification gradient, and access data verification gradient, and screen the verification gradient with the largest demand constraint gradient to obtain the matching verification gradient.
[0021] Specifically, according to the user permissions, analyze the permission type and permission level to which the user belongs. For example, ordinary access permissions, sensitive data management permissions, or administrator permissions, etc. According to different permission types, determine the corresponding permission verification gradients. The higher the permission level, the larger the corresponding permission verification gradient, indicating that the requirements for user identity verification are stricter. Usually, the permission verification gradient directly takes the permission level.
[0022] Extract the memory features of user access behavior based on the access records. The memory features include user usage permissions, access paths, access targets, access frequencies, access time habits, verification gradients, verification results, etc. For example, if the user's historical access behavior is stable and there are no abnormalities, the verification gradient of the user record is relatively low; if there are abnormal access patterns or high-frequency burst accesses, the verification gradient of the user record increases. Usually, the scores corresponding to each memory feature can be weighted, such as the permission level of the user usage permission, the credibility of the access path, the sensitivity of the access target, the deviation amplitude of the access frequency, etc., so as to quantify the verification gradient of the user record.
[0023] Analyze the confidence levels of the access device, network environment, and network access path based on the access path information. Specifically, evaluate the credibility of the overall access path according to the security guarantee of each node in the access link in the access path information. For example, in the application scenario of the financial industry, if the access path is that the mobile banking App accesses the bank API gateway through the operator network, and the API gateway enforces two-way TLS authentication and the core system only accepts internal network requests, the confidence level of the access path is relatively high, and the corresponding access network verification gradient is relatively low. Another example is that in the medical data sharing scenario, if the path is that Hospital A accesses the data sandbox of Hospital B through the medical consortium chain node, and the consortium chain node performs identity verification and the data sandbox uses differential privacy protection, the access path also has a relatively high confidence level. If there is unencrypted transmission, weak authentication, or untrusted relay nodes in the access path, the confidence level decreases, and the access network verification gradient increases accordingly. Among them, the confidence level can be evaluated according to the risk weights of different types of nodes.
[0024] Analyze the security level of the access data according to the requested access target. For example, if the access target is public data, the access data verification gradient is relatively low; if the access target is highly sensitive data such as financial transactions and medical records, the access data verification gradient increases significantly, which is specifically determined by the security level of the data.
[0025] Finally, based on the permission verification gradient, user record verification gradient, access network verification gradient, and access data verification gradient extracted above, extract the demand constraint gradients of each dimension, that is, the specific gradient levels in the verification gradients of each dimension, and then select the verification gradient with the largest demand constraint gradient from these demand constraint gradients as the matching verification gradient for this access request. The matching verification gradient will be used to guide the subsequent authentication factor matching and authentication strength configuration to ensure that the platform can flexibly adjust the authentication strategy according to the access risk in the dynamic environment, effectively improving the security and credibility of data space access control.
[0026] In some embodiments, obtaining the matching verification gradient further includes:
[0027] Perform a cross-gradient impact based on the user permissions, access records, access paths, and requested access targets to obtain a cross-validation relationship coefficient; use the cross-validation relationship coefficient to correct the demand constraint gradient and reset the matching verification gradient.
[0028] Specifically, first, based on the access records, extract the key behavioral characteristics associated with the user during previous accesses to form access memory characteristics. The access memory characteristics include, but are not limited to, the permission categories used by the user, the access path selection patterns, the distribution of access target types, the changes in access frequency, etc. For example, if a user is accustomed to accessing the enterprise internal system through the internal network during working hours and the historical verification results are all passed normally, the access memory characteristics of this user are manifested as relatively high access regularity and credibility. Subsequently, based on the user permissions, analyze the hierarchical relationship of the user in the permission system and the corresponding relationship between the permissions and different types of data resources to form user permission relationship characteristics. For example, high-privilege users usually correspond to more access rights to highly sensitive data resources, and their permission structures are closely related to the data categories. After extracting the access memory characteristics and user permission relationship characteristics, combine the current access path information and the requested access target, and conduct cross-risk impact analysis in sequence to evaluate the adjustment direction and amplitude of the overall access risk caused by a change in a certain characteristic. For example, when it is detected that a user uses a high-privilege account but accesses sensitive data through an abnormal access path, it is determined that there is a significant upward trend in the risk of this characteristic combination, and the credible impact relationship is a negative enhancement relationship. Based on the credible impact relationships obtained from the cross-analysis of the above dimensions, configure the cross-validation relationship coefficient. The cross-validation relationship coefficient is used to quantify the risk adjustment effect between various characteristics. The larger the coefficient value, the more significant the impact of this characteristic combination on the increase in access risk, and the authentication intensity needs to be strengthened in the subsequent verification process. Finally, use the cross-validation relationship coefficient to correct the demand constraint gradient extracted from each dimension and dynamically adjust the matching verification gradient to make the overall authentication strategy more in line with the actual access risk situation.
[0029] In some embodiments, performing a cross-gradient impact based on the user permissions, access records, access paths, and requested access targets to obtain a cross-validation relationship coefficient includes:
[0030] Extract the user usage permissions, access paths, access targets, access frequencies, access time habits, verification gradients, and verification results from the access records to obtain access memory characteristics; analyze the access permission hierarchical relationship and data relationship types based on the user permissions to obtain user permission relationship characteristics; use the user permission relationship characteristics, access memory characteristics, access paths, and requested access targets to conduct cross-risk impact analysis in sequence to identify the credible impact relationships of each dimension. The credible impact relationships are used to represent the risk adjustment direction and influence degree between the dimension characteristics; use the credible impact relationships of each dimension to configure the cross-validation relationship coefficient.
[0031] Specifically, first, extract from the access records the permission categories used by the user during past accesses, typical access path selections, common access target types, changes in access frequency, distribution of access time habits, verification gradients during each verification, and the corresponding verification pass or rejection results. By organizing and summarizing these historical data, establish access memory features that reflect the characteristics of the user's access behavior. Subsequently, based on the permissions currently held by the user, analyze the corresponding relationship between the permission level and the accessible data types to form user permission relationship features. This feature not only reflects the user's permission hierarchy within the organization but also describes the degree of association between the user and different data categories in the data classification system. For example, a certain user mainly processes the data generated by themselves or specific business data, or has extensive data access permissions. After completing the extraction of the access memory features and the permission relationship features, conduct a cross-risk impact analysis on the user's current access path, the requested access target, and the extracted user permission relationship features and access memory features. Specifically, conduct a cross-analysis of the user permission relationship features and the access memory features to evaluate the consistency between the user's permission level and the historical access behavior pattern. For example, if the user holds high permissions but the historical access behavior is concentrated on low-sensitivity data and the access behavior is regular, it will be recognized that the risk of permission use is relatively low, and the credible impact relationship shows a negative adjustment, indicating a reduction in access risk; conversely, if a high-permission user has frequently accessed sensitive data historically and is accompanied by abnormal access records, the system will recognize a positive adjustment relationship, indicating an increase in the risk level. Secondly, conduct a cross-analysis of the access path and the access memory features to detect whether the current access path conforms to the user's past access habits. For example, if the user has long accessed through a secure network environment and suddenly changes to an uncontrolled public network for this access, a positive adjustment relationship will be recognized, meaning that there is a trend of increasing risk in the access path. Thirdly, conduct a cross-analysis of the access path and the requested access target to determine whether there is a match between the path security and the sensitivity of the accessed data. For example, when the security confidence level of the access path is low and the access target is high-sensitivity data, a strong positive adjustment relationship will be recognized, indicating an overall increase in the risk of the access request. Through the above cross-analysis, establish the credible impact relationship between each pair of features. The credible impact relationship includes two aspects of information. One is the risk adjustment direction, that is, whether the feature combination causes the risk to increase (positive) or decrease (negative); the other is the risk adjustment degree, that is, according to the neural network model corresponding to each feature combination, quantify the magnitude of the impact. Through the above cross-risk impact analysis, identify the credible impact relationship between the features in each dimension, which is used to describe the adjustment direction and impact degree of different feature combinations on the overall access risk.According to these credible influence relationships, configure the cross-validation relationship coefficient, that is, use the risk adjustment direction as the sign of the risk adjustment degree, such as the positive risk adjustment degree and the negative risk adjustment degree, so as to quantify the risk changes brought about by the interaction between features. Then, weight the risk adjustment degrees between features to obtain the cross-validation relationship coefficient. This cross-validation relationship coefficient will be used to dynamically correct the demand constraint gradients of each dimension during the subsequent matching verification gradient adjustment process, so as to more accurately reflect the true security situation of access requests.
[0032] In some embodiments, obtaining the matching verification gradient includes:
[0033] Construct an analysis network diagram, including a first-order analysis network and a second-order analysis network. The first-order analysis network is used to analyze the self-verification demand gradients of user permissions, access records, access paths, and requested access targets. The second-order analysis network is used to analyze the cross-validation relationships of each dimension. Among them, the user permission relationship features, access memory features, access paths, and requested access targets are imported in sequence according to the configured user permission, access record, access path, and requested access target graph nodes, and the verification gradients of each dimension of the first order and the second-order cross-validation relationship coefficients are output; use the second-order cross-validation relationship coefficient to adjust and correct the verification gradients of each dimension of the first order to obtain the matching verification gradient.
[0034] Specifically, in the process of obtaining the matching verification gradient, it is necessary to pre-construct an analysis network diagram. This analysis network diagram includes a first-order analysis network and a second-order analysis network. Among them, the role of the first-order analysis network is to analyze each independent dimension of the user access request, including user permissions, access records, access paths, and requested access targets. Each dimension is represented as a graph node in the first-order analysis network, and each graph node has an analysis logic for a specific dimension (which is the aforementioned process of determining each verification gradient). Based on the access data provided by the user, the features of each dimension are imported into the corresponding nodes, and each node will generate corresponding verification gradients, such as permission verification gradients, user record verification gradients, access network verification gradients, and access data verification gradients. These verification gradients will be sorted into the verification gradients of each dimension in the first order and uniformly output by the first-order analysis network. The second-order analysis network is used to analyze the cross-verification relationship between different dimensions. Each combination of features corresponds to a graph node, and each graph node has a neural network model for a specific combination, which is used to perform cross-analysis based on the input combination, establish the risk adjustment direction and influence degree, and then the output node will perform weighted calculation on the risk adjustment direction and influence degree generated by each graph node and output the calculation result as the second-order cross-verification relationship coefficient. Among them, the neural network model of each graph node can be constructed using a multi-layer perceptron and iteratively trained through steps such as forward propagation, loss calculation (cross-entropy loss and mean squared error), backpropagation, and parameter optimization (Adam optimizer). The data used for training is sample combination data and corresponding cross-verification identifiers. Finally, according to the cross-verification relationship coefficient output by the second-order analysis network, the maximum verification gradient determined based on the verification gradients of each dimension in the first order is adjusted and corrected, that is, 1 is added to the cross-verification relationship coefficient, and then the added result is multiplied by the maximum verification gradient to obtain the matching verification gradient. Generally speaking, in this way, the verification gradient can be dynamically corrected to more accurately reflect the comprehensive risk level of each access request, laying a foundation for subsequent authentication decisions and access control.
[0035] Use the matching verification gradient to identify and match with the authentication factor record information of the requested access user, create a requested user authentication requirement factor, and the requested user authentication requirement factor has an authentication gradient constraint.
[0036] Specifically, after generating the matching verification gradient based on the access request, based on this matching verification gradient, enter the verification factor library corresponding to the user, and perform the screening and matching operations of the authentication means. In this process, according to the matching verification gradient, first retrieve the authentication means that can meet the requirements of this gradient. For example, when the matching verification gradient is relatively high, it is inclined to select high-strength authentication methods, such as the combination of biometric features and dynamic passwords; when the matching verification gradient is medium or low, traditional password authentication or device binding authentication and other means can be matched. Finally, through the identification and screening based on the matching verification gradient, create the request user authentication requirement factors corresponding to this access request. The authentication requirement factors clearly define the selected authentication means and the corresponding authentication gradient constraints, ensuring the dynamic matching of the authentication method and the access risk level, and both ensuring the security of data space access and taking into account the user authentication experience.
[0037] In some embodiments, use the matching verification gradient to perform identification and matching with the authentication factor record information of the requested access user, and create the request user authentication requirement factors, including:
[0038] Establish a verification factor library for the access user, which stores the authentication factor record means and factor verification evaluations of the user; use the matching verification gradient to perform identification in the verification factor library according to the verification gradient requirements, obtain the matching verification means and the authentication gradient constraints corresponding to the verification means, and obtain the request user authentication requirement factors.
[0039] Specifically, first, a verification factor library is established for each accessing user. This library stores various authentication factor recording means of the user and the corresponding factor verification evaluations. Among them, the authentication factor recording means include, but are not limited to, static passwords, biometric recognition (such as fingerprints, facial recognition), dynamic tokens, and multi-device binding authentication; the factor verification evaluations include evaluation data such as the historical success rate, usage stability, error rate, and abnormal event records of each authentication factor recording means, indicating the performance and credibility of this authentication means in previous applications. Subsequently, according to the matching verification gradient generated from the access request, identification and matching are performed in the verification factor library according to the verification gradient requirements. Specifically, the verification intensity requirements of the current access request will be analyzed, and a search for each gradient scheme of the authentication factor recording means will be carried out with the goal of minimizing the gradient means overlap and maximizing the evaluation requirement value, ensuring that the selected authentication means not only meets the gradient requirements but also has high stability and reliability. For example, if a certain authentication means has failed multiple times or has a high error rate in historical verifications, other authentication means with better performance will tend to be selected to ensure that while meeting the verification gradient requirements, the failure risk is minimized to the greatest extent. After the matching is completed, the matching verification means and the authentication gradient constraints corresponding to the verification means are generated and used as the authentication requirement factors for the requesting user. These authentication requirement factors clearly specify which authentication steps the user needs to complete (such as password + fingerprint verification), and at the same time define the security level requirements for each step, ensuring that the authentication policy matches the actual risk of the access request. Finally, the authentication requirement factors of the requesting user are applied to the subsequent authentication process, and the verification process is guided by these constraints to ensure a balance between security and efficiency.
[0040] In some embodiments, using the matching verification gradient to perform identification in the verification factor library according to the verification gradient requirements to obtain the matching verification means and the authentication gradient constraints corresponding to the verification means includes:
[0041] Analyze the multi-modal verification forms of the authentication factor recording means to determine the verification evaluation values of each form; analyze the verification gradient and the evaluation requirement values of each gradient according to the matching verification gradient; based on the evaluation requirement values of each gradient, search for each gradient scheme of the authentication factor recording means with the goal of minimizing the gradient means overlap and maximizing the evaluation requirement value to obtain the matching verification means of each gradient and its verification form that meets the gradient evaluation requirement value as the authentication gradient constraint.
[0042] Specifically, first, the authentication factor recording means of the requesting access user is parsed in a multi-modal verification form. Each authentication means (such as password, fingerprint, hardware token, etc.) may have different verification forms. For example, biometric recognition may have two verification methods: fingerprint scanning and facial recognition. Dynamic tokens may have time-based one-time passwords and location-based verification methods. According to the characteristics of each authentication means, its multi-modal verification form is parsed, and the verification evaluation of each form is obtained, such as success rate, stability, user experience and other indicators, so as to obtain the verification evaluation value of each verification form. This value represents the performance and reliability of this authentication form in historical use. Subsequently, the authentication means is further parsed according to the current matching verification gradient. The matching verification gradient represents the requirement of the current access request for authentication strength. A higher verification gradient means a stronger authentication means is needed. The platform will parse the gradient requirement value of each verification means according to this verification gradient requirement, that is, the minimum authentication strength that each authentication means (or its verification form) needs to meet. Each verification means has a predetermined verification gradient range, and it will be judged whether the authentication means meets the current gradient requirement according to this range. After that, based on the verification gradient and evaluation requirement value of each authentication means, a gradient scheme search for the authentication factor recording means is carried out. In this process, different combinations of authentication means or authentication methods will be evaluated. The goal is to find an authentication scheme with the smallest overlap of gradient means and the largest evaluation requirement value. Among them, the smallest overlap means that it is necessary to avoid using multiple verification means with the same characteristics as much as possible, and the largest evaluation requirement value means that it is necessary to select those authentication means with the best performance to meet the current verification strength requirements. Finally, according to the search results, the matching verification means of each authentication means is obtained, that is, the authentication method that meets the current verification gradient requirement. At the same time, the verification form of each authentication means in the authentication process is also determined and applied as an authentication gradient constraint to ensure that in the subsequent authentication process, the selected verification means and form meet the security requirements of the access request, while improving the efficiency and user experience in the authentication process.
[0043] According to the authentication result of the authentication demand factor of the requesting user, a space access permission result is sent, and the space access permission result is used to control the access permission of the requesting access user to the trusted data.
[0044] Specifically, first, according to the authentication requirement factors of the requesting user, and based on the information provided by the user during the verification process (such as password, biometric identification, hardware token, etc.), the user's access request is verified. If the user's authentication means meet the verification gradient requirements of the current access request, the authentication is passed; if the verification fails, the authentication fails. The authentication result will be fed back to the platform as the basis for subsequent access decisions. When the user's authentication request passes the verification, a spatial access permission result is generated according to the authentication result, which clearly indicates whether the user has the right to access the requested data resources. For example, if the user passes a high-intensity authentication and their permissions allow access to a certain sensitive data, then the user will be allowed to access the data; on the contrary, if the user authentication fails to meet the requirements, or their permissions are insufficient to access a certain resource, the access request will be rejected. Generally speaking, according to the access permission result, the data access permissions can be dynamically adjusted to ensure that only authenticated users who meet the security requirements can access the corresponding data resources, while ensuring the dynamic adaptation of the authentication mechanism to the access requirements to prevent unauthorized access and potential security risks.
[0045] In some embodiments, sending the spatial access permission result further includes:
[0046] Establish a trust framework between different security domains, define the trust relationship and the authentication information exchange mechanism; when the requesting user attempts to access cross-domain resources, initiate a collaborative verification request based on the trust relationship and the authentication information exchange mechanism, and provide the authentication information of the requesting user; the domain where the resource is located makes an authentication decision according to the received authentication information and the matching authentication gradient, and sends the spatial access permission result.
[0047] Specifically, to achieve secure access to cross - domain resources, a cross - domain trust framework needs to be established, and trust relationships and authentication information exchange mechanisms are defined within this framework. Specifically, first, the trust relationships between different security domains are defined. The core purpose of the trust framework is to ensure that in different security domains, only authenticated and authorized users can access resources in other domains. The access control system within each security domain will establish trust connections with other domains, allowing trusted users to access data and services in another domain. Trust relationships are usually set based on multiple factors such as identity authentication, data protection levels, access permission rules, and authentication history. Subsequently, on the basis of establishing the trust framework, an authentication information exchange mechanism is defined, that is, how to securely transmit the user's authentication information during cross - domain access. Usually, encryption is used for cross - domain transmission to prevent data from being maliciously tampered with or leaked. At the same time, protocols and data formats are also designed to ensure the compatibility of authentication information and the efficiency of exchange. For example, after a user successfully passes identity authentication in Domain A, Domain A will transmit the user's authentication information, authentication status, and authentication level to Domain B through a secure communication channel. Later, when a requesting user attempts to access cross - domain resources, the platform will initiate a collaborative verification request based on the trust relationship and the authentication information exchange mechanism. At this time, the user's authentication information will be transmitted from the source domain (such as Domain A) to the target resource domain (such as Domain B) through the authentication information exchange mechanism. Domain B makes an authentication decision based on the received authentication information, combined with the user's access permissions in Domain B and the matching authentication gradient. For example, if a user accesses highly sensitive data from Domain B, Domain B may require additional authentication measures (such as two - factor authentication); otherwise, the authentication strength requirement is lower. After the authentication decision, the access control system in the resource - hosting domain will generate a spatial access permission result according to the authentication result. This result will clearly indicate whether the user has obtained access rights to the target resource. If the user passes the authentication and meets the access conditions, the resource - hosting domain will allow the user to access the corresponding resource and send an access - permitted permission result; if the authentication fails or the user's permissions are insufficient, the access request will be rejected and a permission result for access denial will be returned. Through this process, it is possible to ensure the secure access of cross - domain resources, guarantee the efficient and secure exchange of authentication information between different domains, and effectively control the user's access rights to resources, thereby protecting the security and integrity of data.
[0048] In summary, the multi - factor authentication - based trusted data space access control method provided by the present invention has the following technical effects:
[0049] Parse the user permissions, access records, access paths, and requested access targets for the requesting access user to obtain user access parameters; according to the user access parameters, perform access verification security level matching from the user permissions, access records, access paths, and requested access targets to obtain a matching verification gradient; use the matching verification gradient to perform identification matching with the authentication factor record information of the requesting access user to create a requested user authentication requirement factor, and the requested user authentication requirement factor has an authentication gradient constraint; according to the authentication result of the requested user authentication requirement factor, send a space access permission result, and the space access permission result is used to control the access permission of the requesting access user to the trusted data, so as to achieve the technical effects of dynamically adjusting the access permission based on multi-factor authentication and effectively improving the data security and credibility in the data space access process.
[0050] Embodiment 2, such as Figure 2 is a schematic structural diagram of the trusted data space access control platform for multi-factor authentication of the present invention. For example, Figure 1 in the present invention, the flowchart of the trusted data space access control method for multi-factor authentication can be implemented by a structure such as Figure 2 shown.
[0051] Based on the same concept as the trusted data space access control method for multi-factor authentication in the above embodiment, the present invention also provides a trusted data space access control platform for multi-factor authentication, including:
[0052] A user parsing module 11: Parse the user permissions, access records, access paths, and requested access targets for the requesting access user to obtain user access parameters; a security level matching module 12: According to the user access parameters, perform access verification security level matching from the user permissions, access records, access paths, and requested access targets to obtain a matching verification gradient; a factor identification matching module 13: Use the matching verification gradient to perform identification matching with the authentication factor record information of the requesting access user to create a requested user authentication requirement factor, and the requested user authentication requirement factor has an authentication gradient constraint; an access permission sending module 14: According to the authentication result of the requested user authentication requirement factor, send a space access permission result, and the space access permission result is used to control the access permission of the requesting access user to the trusted data.
[0053] In some embodiments, the security level matching module 12 includes:
[0054] Analyze the user permission type according to the user permission to determine the permission verification gradient; extract the memory features according to the access record to obtain the user record verification gradient; analyze the access device, network environment, and network access path confidence according to the access path to determine the access network verification gradient; analyze the security level of the access target according to the requested access target to obtain the access data verification gradient; extract the requirement constraint gradients of each dimension according to the permission verification gradient, user record verification gradient, access network verification gradient, and access data verification gradient, and filter the verification gradient with the largest requirement constraint gradient to obtain the matching verification gradient.
[0055] In some embodiments, the security level matching module 12 includes:
[0056] Perform cross-gradient influence on the user permission, access record, access path, and requested access target to obtain the cross-verification relationship coefficient; use the cross-verification relationship coefficient to correct the requirement constraint gradient and reset the matching verification gradient.
[0057] In some embodiments, the security level matching module 12 includes:
[0058] Extract the user usage permissions, access path, access target, access frequency, access time habit, verification gradient, and verification result from the access record to obtain the access memory features; analyze the access permission level relationship and data relationship type according to the user permission to obtain the user permission relationship features; use the user permission relationship features, access memory features, access path, and requested access target to perform cross-risk impact analysis in sequence to identify the credible impact relationships of each dimension, where the credible impact relationships are used to represent the risk adjustment direction and impact degree between dimension features; configure the cross-verification relationship coefficient using the credible impact relationships of each dimension.
[0059] In some embodiments, the security level matching module 12 includes:
[0060] Construct an analysis network diagram, including a first-order analysis network and a second-order analysis network. The first-order analysis network is used to analyze the self-verification requirement gradients of the user permission, access record, access path, and requested access target, and the second-order analysis network is used to analyze the cross-verification relationships of each dimension. Among them, the user permission relationship features, access memory features, access path, and requested access target are imported in sequence according to the configured user permission, access record, access path, and requested access target graph nodes, and the verification gradients of each dimension of the first order and the cross-verification relationship coefficient of the second order are output; use the cross-verification relationship coefficient of the second order to adjust and correct the verification gradients of each dimension of the first order to obtain the matching verification gradient.
[0061] In some embodiments, the factor identification and matching module 13 includes:
[0062] Establish a verification factor library for accessing users, which stores the authentication factor recording means and factor verification evaluations of users; use the matching verification gradient to identify in the verification factor library according to the verification gradient requirements, obtain the matching verification means and the authentication gradient constraints corresponding to the verification means, and obtain the authentication requirement factors of the requesting user.
[0063] In some embodiments, the factor identification and matching module 13 includes:
[0064] Analyze the multi-modal verification forms of the authentication factor recording means to determine the verification evaluation values of each form; analyze the verification gradient and the evaluation requirement values of each gradient according to the matching verification gradient; based on the evaluation requirement values of each gradient, search for each gradient scheme of the authentication factor recording means with the goal of minimizing the gradient means overlap and maximizing the evaluation requirement value, obtain the matching verification means of each gradient, and its verification form that meets the gradient evaluation requirement value as the authentication gradient constraint.
[0065] In some embodiments, the access permission sending module 14 includes:
[0066] Establish a trust framework between different security domains, define the trust relationship and the authentication information exchange mechanism; when a requesting user attempts to access cross-domain resources, initiate a collaborative verification request based on the trust relationship and the authentication information exchange mechanism, and provide the authentication information of the requesting user; the domain where the resource is located makes an authentication decision according to the received authentication information and the matching authentication gradient, and sends the spatial access permission result.
[0067] Embodiment 3, the present invention also provides a computer-readable storage medium, which can be used to store software programs, computer-executable programs, and modules, such as the program instructions / modules corresponding to the multi-factor authentication-based trusted data space access control method in the embodiments of the present invention, so as to implement the above-mentioned multi-factor authentication-based trusted data space access control method.
[0068] It should be understood that the disclosed embodiments of the present invention and the above descriptions can enable those skilled in the art to implement the present invention using the present invention. At the same time, the present invention is not limited to the above-mentioned part of the embodiments. It should be understood that those of ordinary skill in the art can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included in the protection scope of the present invention.
Claims
1. A method for access control of a trustworthy data space with multi-factor authentication, characterized in that, Including: Analyze the user permissions, access records, access paths, and requested access targets of the requesting access user to obtain user access parameters; According to the user access parameters, perform access verification security level matching from the user permissions, access records, access paths, and requested access targets to obtain a matching verification gradient; Use the matching verification gradient to perform identification matching with the authentication factor record information of the requesting access user to create a requested user authentication requirement factor, and the requested user authentication requirement factor has an authentication gradient constraint; According to the authentication result of the requested user authentication requirement factor, send a space access permission result, and the space access permission result is used to control the access permission of the requesting access user to trusted data.
2. The multi-factor authentication-based trusted data space access control method according to claim 1, wherein According to the user access parameters, perform access verification security level matching from the user permissions, access records, access paths, and requested access targets to obtain a matching verification gradient, including: Analyze the user permission type according to the user permissions to determine the permission verification gradient; Extract memory features according to the access records to obtain a user record verification gradient; Analyze the access device, network environment, and network access path confidence according to the access path to determine the access network verification gradient; Analyze the security level of the access target according to the requested access target to obtain an access data verification gradient; Extract the demand constraint gradients of each dimension according to the permission verification gradient, user record verification gradient, access network verification gradient, and access data verification gradient, and screen the verification gradient with the largest demand constraint gradient to obtain the matching verification gradient.
3. The multi-factor authentication-based trusted data space access control method according to claim 2, characterized in that Obtaining the matching verification gradient further includes: Perform cross-gradient influence on the user permissions, access records, access paths, and requested access targets to obtain a cross-verification relationship coefficient; Use the cross-verification relationship coefficient to correct the demand constraint gradient and reset the matching verification gradient.
4. The multi-factor authentication-based trusted data space access control method according to claim 3, wherein Performing cross-gradient influence on the user permissions, access records, access paths, and requested access targets to obtain a cross-verification relationship coefficient, including: Extract the user usage permissions, access paths, access targets, access frequencies, access time habits, verification gradients, and verification results according to the access records to obtain access memory features; Analyze the access permission level relationship and data relationship type according to the user permissions to obtain user permission relationship features; Use the user permission relationship features, access memory features, access paths, and requested access targets to perform cross-risk influence analysis in sequence to identify the trusted influence relationships of each dimension, and the trusted influence relationships are used to represent the risk adjustment direction and influence degree between dimension features; Configure the cross-verification relationship coefficient using the trusted influence relationships of each dimension.
5. The multi-factor authentication-based trusted data space access control method according to claim 4, wherein Obtaining the matching verification gradient includes: Construct an analysis network diagram, including a first-order analysis network and a second-order analysis network, wherein the first-order analysis network is used to analyze the self-verification demand gradient of user authority, access record, access path, and requested access target, and the second-order analysis network is used to analyze the cross-validation relationship of each dimension, wherein the user authority relationship characteristics, access memory characteristics, access path, and requested access target are sequentially imported according to the configured user authority, access record, access path, and requested access target graph nodes, and the verification gradient of each first-order dimension and the second-order cross-validation relationship coefficient are output; The validation gradients of the first-order dimensions are adjusted and corrected using the second-order cross-validation relationship coefficient to obtain the matching validation gradients.
6. The multi-factor authentication-based trusted data space access control method according to claim 1, wherein Using the matching verification gradient and the authentication factor record information of the user requesting access to perform identification and matching, and creating the authentication requirement factor of the requesting user, includes: Establish a verification factor database for access users, which stores the user's authentication factor record means and factor verification evaluation; The matching verification gradient is used to identify in the verification factor library according to the verification gradient requirement, obtain the matching verification means and the authentication gradient constraint corresponding to the verification means, and obtain the authentication requirement factor of the requesting user.
7. The multi-factor authentication-based trusted data space access control method according to claim 6, characterized in that, Using the matching verification gradient to identify in the verification factor library according to the verification gradient requirement, obtaining matching verification means and authentication gradient constraints corresponding to the verification means, including: Analyze the multi-modal verification forms of the authentication factor recording means and determine the verification evaluation value of each form; Analyze the verification gradient and evaluate the required value of each gradient according to the matching verification gradient; Based on the evaluation requirement values of each gradient, a search is performed on each gradient scheme of the authentication factor recording means with the goal of minimizing the overlap of gradient means and maximizing the evaluation requirement value, and the matching verification means of each gradient and the verification form that meets the gradient evaluation requirement value are obtained as the authentication gradient constraint.
8. The multi-factor authentication-based trusted data space access control method according to claim 1, wherein Send space access permission results, including: Establish a trust framework between different security domains and define trust relationships and authentication information exchange mechanisms; When a user who requests access attempts to access cross-domain resources, a collaborative verification request is initiated based on the trust relationship and authentication information exchange mechanism, and the authentication information of the user who requests access is provided; The domain where the resource is located makes an authentication decision based on the received authentication information and the matching authentication gradient, and sends the space access permission result.
9. A trusted data space access control platform for multi-factor authentication, characterized in that A trusted data space access control method for implementing the multi-factor authentication described in any one of claims 1 to 8, comprising: User parsing module: parses the user's access rights, access records, access paths, and access target of the user requesting access, and obtains the user's access parameters; Security level matching module: according to the user access parameters, performs access verification security level matching from the user authority, access record, access path, and requested access target to obtain a matching verification gradient; Factor identification and matching module: using the matching verification gradient and the authentication factor record information of the user requesting access to perform identification and matching, and creating a requesting user authentication requirement factor, wherein the requesting user authentication requirement factor has an authentication gradient constraint; Access permission sending module: According to the authentication result of the authentication requirements factors of the requesting user, send a space access permission result, where the space access permission result is used to control the access permission of the requesting access user to the trusted data.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When executed by a processor, the program implements the multi-factor authentication-based trusted data space access control method according to any one of claims 1 to 8.
Citation Information
Patent Citations
Verification of access to secured electronic resources
CA3089255A1
Access control method and device, electronic equipment and medium
CN111935165A
Access security control method and system for industrial control network
CN116915515A
System architecture and database for context-based authentication
US20200007536A1
Systems and methods for multi-factor authentication
WO2007089503A2
Cited By
Secret data security management system and method based on role access control
CN121333740A
Medical data management system based on trusted space
CN121356806A
Medical data management system based on trusted space
CN121356806B
Cross-border VPN data access authority management and control method and system based on multi-factor authentication
CN121396678A
A method and system for cross-border VPN data access control based on multi-factor authentication
CN121396678B