Cloud architecture distributed data processing method and device, equipment and storage medium
Through multi-identity authentication, role access control, intelligent intrusion detection and zero-trust architecture, combined with AES and RSA encryption, the problem of insufficient dynamic security assessment in traditional cloud computing systems is solved, efficient data protection and real-time monitoring are achieved, and the system's defense capabilities and data security are improved.
Patent Information
- Application Number
- CN202510626554.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-15
- Publication Date
- 2025-07-18
AI Technical Summary
Traditional cloud computing data processing systems lack dynamic security assessment capabilities and cannot effectively deal with user identity spoofing, unauthorized access and data leakage. The existing encryption methods rely on a single algorithm to cause insufficient security.
It adopts multiple identity authentication mechanisms, role-based access control, artificial intelligence-driven intelligent intrusion detection and zero-trust architecture, combined with deep learning models, dynamic evaluation of user access requests, realize dynamic security assessment and precise permission control, and encrypt data through AES and RSA algorithms.
It improves the system's active defense capabilities, ensures the legality and security of data access, prevents abuse of permissions and unauthorized access, realizes real-time monitoring and dynamic encryption of data, and improves data security traceability and response capabilities.
Smart Images

Figure CN120342741A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of cloud architecture distributed data processing, and in particular to a cloud architecture distributed data processing method, apparatus, device, and storage medium. Background Art
[0002] In traditional cloud computing data processing systems, a static access control mechanism is usually adopted, that is, based on a preset role and permission allocation policy, a fixed access permission is granted after the user identity authentication passes. However, this static access control method lacks the ability of dynamic security assessment and cannot effectively cope with security risks such as user identity deception, unauthorized access, and data leakage. In addition, existing data encryption methods often rely on a single symmetric or asymmetric encryption algorithm. When the key is cracked, the entire data security system will face a serious threat. Summary of the Invention
[0003] In order to achieve dynamic access control and efficient data protection, the present application provides a cloud architecture distributed data processing method, apparatus, device, and storage medium.
[0004] The first invention object of the present application is achieved by the following technical solutions: A cloud architecture distributed data processing method, the cloud architecture distributed data processing method includes: Obtain the identity data of a data access user, and verify the identity data based on multi-factor authentication. If the identity authentication passes, allocate data access permissions through a role-based access control mechanism; After the identity authentication of the data access user passes, establish a cloud architecture-based distributed data center, and according to the data access permissions, receive real-time monitoring data from multiple terminals, and store the real-time monitoring data in the cloud architecture-based distributed data center; After the real-time monitoring data is stored in the cloud architecture-based distributed data center, monitor the network traffic in the cloud architecture-based distributed data center through an artificial intelligence-driven intelligent intrusion detection mechanism to obtain user access request data; Based on the user access request data, use a zero-trust architecture to perform dynamic security assessment on the access request of the data access user. If the access request meets the security policy of the zero-trust architecture, allow the data access user to access the decrypted data; If the access request of the data access user does not meet the security policy of the zero-trust architecture, reject the access request and generate an access rejection log.
[0005] By adopting the above technical solutions, the legitimacy of the identity of data access users is ensured through multiple identity authentication mechanisms, and access rights are accurately allocated in combination with role-based access control mechanisms to prevent abuse of rights or unauthorized data access. After the data access user identity authentication is passed, a distributed data center is built based on the cloud architecture to achieve real-time monitoring data storage and management of multiple terminals, and the network traffic of the data center is monitored through an intelligent intrusion detection mechanism, which can identify and detect potential security threats in real time, such as abnormal access, malicious scanning or DDoS attacks, and improve the active defense capability of the system. With the zero-trust architecture, when a user initiates an access request, the user's access behavior, device status, access history and other factors are evaluated in real time, and the access request is judged by risk scoring whether it complies with the security policy to ensure dynamic adjustment and precise control of access rights. For access requests that meet the security policy, data decryption is allowed and access rights are provided, while for access requests that do not meet the security policy, they are automatically rejected and access rejection logs are recorded to improve data security traceability and security incident response capabilities.
[0006] In a preferred example, the present application may be further configured as follows: the identity data of the data access user is obtained, and the identity data is verified based on multiple identity authentications. If the identity authentication is passed, data access rights are allocated through a role-based access control mechanism, and further includes: Verifying the identity data based on the multiple identity authentication mechanisms to obtain identity authentication results, wherein the multiple identity authentication mechanisms include static password authentication, biometric authentication, or dynamic authentication based on a one-time token; According to the identity authentication result, the access rights of the data access user are determined by using the role-based access control mechanism, and a rights allocation strategy is generated; After the permission allocation strategy is generated, the access rights are granted to the data access user through the role-based access control mechanism, and the data types, access scopes and operation rights accessible to the data access user are restricted based on the permission allocation strategy.
[0007] By adopting the above technical solutions, the identity data of data access users is verified based on a multi-factor authentication mechanism to ensure the authenticity and security of user identities. Through static password authentication, biometric authentication, or dynamic authentication based on one-time tokens, the security level of identity verification is improved to prevent unauthorized access caused by credential leakage or identity theft. After the identity verification is passed, the role-based access control mechanism accurately determines the access rights of users and generates corresponding permission allocation policies to ensure that users can only access data resources within their authorized scope, thereby reducing the risk of permission abuse. After the permission allocation policy is generated, the role-based access control mechanism dynamically grants access rights and finely restricts the data types, access scopes, and operation permissions that users can access according to the permission allocation policy to ensure that users at different levels can only perform operations that comply with the permission settings, avoiding unauthorized data reading, modification, or deletion, and improving the security and compliance of data access.
[0008] In a preferred example of the present application, it can be further configured that: after the permission allocation policy is generated, the access rights are granted to the data access user through the role-based access control mechanism, and the data types, access scopes, and operation permissions that the data access user can access are restricted based on the permission allocation policy. It further includes: When the data access user initiates a data access operation, the access rights of the data access user are verified in real time according to the permission allocation policy; If the access rights of the data access user conform to the permission allocation policy, the data access user is allowed to access the requested data; If the access rights of the data access user do not meet the permission allocation policy, the access rights are rejected; After the permission allocation policy is adjusted, if the access rights of the data access user are downgraded or revoked, the access of the data access user is automatically blocked.
[0009] By adopting the above technical solutions, when a data access user initiates an access operation, the system can verify the access rights of the user in real time based on the permission allocation policy to ensure that the user's access behavior conforms to the authorized scope, thereby effectively preventing unauthorized access or unauthorized data operations. If the user's access rights conform to the permission allocation policy, the data requested for normal access is allowed; if the access rights do not conform, the access is immediately rejected to prevent sensitive data from being leaked or tampered with, improving the access security of the system. In addition, this solution supports a dynamic permission adjustment mechanism. In the case of a change in the permission allocation policy, such as a user's permission being downgraded or revoked, the system can automatically block their access to data that is no longer authorized, ensuring that the permission change takes effect immediately and avoiding security risks caused by delays or permission management loopholes.
[0010] In a preferred example, the present application can be further configured as follows: The intelligent intrusion detection mechanism driven by artificial intelligence monitors the network traffic in the cloud - based distributed data center to obtain user access request data, including: The intelligent intrusion detection mechanism driven by artificial intelligence performs real - time analysis on the network traffic of the cloud - based distributed data center to extract network communication data packets; Perform protocol parsing on the network communication data packets, identify the communication protocol types of the network communication data packets, and parse the basic network attributes of the network communication data packets based on the communication protocol types; Based on the basic network attributes, calculate the associated data of the network communication data packets. Based on the basic network attributes and the associated data, analyze the access behavior characteristics of the network communication data packets and extract access behavior parameters; According to the access behavior parameters, construct an access request data set, and based on the access request data set, extract access patterns to determine the user access request data.
[0011] By adopting the above - mentioned technical solution, using the intelligent intrusion detection mechanism driven by artificial intelligence to perform real - time analysis on the network traffic of the distributed data center can efficiently extract network communication data packets, parse the communication protocol types and their basic network attributes, ensuring accurate classification of different types of data streams. By calculating the associated data of the network communication data packets and combining historical access behaviors, it can effectively analyze access behavior characteristics, extract access behavior parameters to detect whether there are abnormal access requests, such as unauthorized access, large - scale data scraping, malicious attack behaviors, etc. In addition, this solution constructs an access request data set based on access behavior parameters and extracts access patterns through pattern recognition methods, thereby accurately determining the security of user access requests, ensuring that access requests conform to normal business logic, and being able to quickly respond to suspicious access behaviors, improving the accuracy and real - time performance of intrusion detection.
[0012] In a preferred example, the present application can be further configured as follows: The use of the zero - trust architecture to perform dynamic security assessment on the access requests of data - accessing users includes: The zero - trust architecture parses the user access request data to extract access security attribute data; According to the access security attribute data, calculate the risk score of the data - accessing user; Based on the risk score, estimate whether the access request of the data - accessing user meets the security policy of the zero - trust architecture.
[0013] By adopting the above technical solution, the user access request data is parsed through the zero-trust architecture to extract access security attribute data, including user identity information, device status, access environment, historical behavior patterns, etc., and the access request is comprehensively analyzed based on these attributes. By calculating the access security attribute data, a risk score for the user is generated, and factors such as the credibility of the access device, the abnormality degree of the access behavior, and the security of the access source are comprehensively considered to dynamically evaluate the access risk level of the user. After the risk score calculation is completed, the system can real-time evaluate whether the access request meets the security policy of the zero-trust architecture. If the risk score is lower than the security threshold, the access request is allowed to pass; if the risk score is in the suspicious range, additional identity authentication or security review is triggered; if the risk score exceeds the allowable range of the security policy, the access request is rejected, and relevant security logs are recorded for subsequent review and analysis.
[0014] In a preferred example of the present application, it can be further configured as follows: Based on the user access request data, the zero-trust architecture is used to dynamically evaluate the access request of the data access user. If the access request meets the security policy of the zero-trust architecture, the data access user is allowed to access the decrypted data, and it further includes: After the access request of the data access user meets the security policy of the zero-trust architecture, an AES encryption key is generated, and the real-time monitoring data is symmetrically encrypted using the AES algorithm to obtain encrypted data, and the encrypted data is stored; The AES encryption key is asymmetrically encrypted through the RSA algorithm to obtain encrypted key data, and the original integrity check value is calculated for the encrypted data in combination with the hash algorithm, and the original integrity check value is stored; After the encrypted data is received, the verification integrity check value of the encrypted data is recalculated, and the verification integrity check value is compared with the stored original integrity check value. If the two are consistent, it is confirmed that the encrypted data has not been tampered with; In the case that the encrypted data has not been tampered with, the encrypted key data is decrypted through the RSA private key to obtain the AES encryption key, and the encrypted data is decrypted using the AES encryption key to obtain decrypted data, and the data access user is allowed to access the decrypted data.
[0015] By adopting the above technical solution, after the user access request meets the security policy of the zero-trust architecture, an AES encryption key is dynamically generated, and the AES algorithm is used to symmetrically encrypt the real-time monitoring data to ensure that the data is encrypted before storage, preventing unauthorized access or leakage. At the same time, the RSA algorithm is used to asymmetrically encrypt the AES encryption key to ensure that the encryption key is not stolen during storage and transmission, thereby improving the security of key management. In addition, the hash algorithm is used to calculate the integrity check value of the encrypted data, and this check value is stored for subsequent verification of data integrity to prevent the data from being maliciously tampered with. After the data is received, the system can recalculate the integrity check value of the encrypted data and compare it with the original stored check value. If the two are consistent, it is ensured that the data has not been tampered with during storage or transmission, guaranteeing data integrity. After the data integrity verification passes, the system decrypts the encrypted AES key using the RSA private key, and then uses the AES key to decrypt the encrypted data, finally restoring the original data and allowing the data access user to access it normally.
[0016] In a preferred example of the present application, it can be further configured as follows: The cloud architecture distributed data processing method further includes: Based on a deep learning model, identify the behavior pattern of the user access request data, determine whether the user access request data is abnormal. If the user access request data is abnormal, generate security threat data; Determine whether the security threat data reaches a preset security policy threshold. If the security threat data reaches the preset security policy threshold, generate security defense data, and based on the security defense data, execute corresponding security defense measures.
[0017] By adopting the above technical solution, through the behavior pattern recognition of the user access request data based on a deep learning model, abnormal access behaviors can be accurately detected, such as abnormal access time, abnormal access device, abnormal access frequency, or abnormal access target data, etc., so as to quickly discover potential security threats. When an abnormal user access behavior is identified, the system generates security threat data, and further conducts a risk assessment on the security threat data according to the preset security policy threshold. If the security threat data reaches the threshold of the security policy, the security defense mechanism is triggered. The system automatically generates security defense data and takes corresponding defense measures according to different levels of security threats, such as restricting the access rights of suspicious users, triggering multi-factor authentication, terminating high-risk access requests, and even sending real-time alerts to security administrators to ensure a quick response and handling of potential security threats.
[0018] The above second invention object of the present application is achieved through the following technical solutions: A cloud architecture distributed data processing device, the cloud architecture distributed data processing device includes: The identity authentication and permission allocation module is used to obtain the identity data of the data access user and verify the identity data based on multiple identity authentications. If the identity authentication is passed, the data access rights are allocated through a role-based access control mechanism; A distributed data center construction module is used to establish a distributed data center based on a cloud architecture after the identity authentication of the data access user is passed, and receive real-time monitoring data from multiple terminals according to the data access rights, and store the real-time monitoring data in the distributed data center based on the cloud architecture; A network traffic monitoring module is used to monitor the network traffic in the distributed data center based on the cloud architecture through an artificial intelligence-driven intelligent intrusion detection mechanism after the real-time monitoring data is stored in the distributed data center based on the cloud architecture, so as to obtain user access request data; A zero-trust security assessment module, configured to perform a dynamic security assessment on the access request of the data access user using a zero-trust architecture based on the user access request data, and allow the data access user to access the decrypted data if the access request satisfies the security policy of the zero-trust architecture; The access control and log management module is used to reject the access request and generate an access rejection log if the access request of the data access user does not meet the security policy of the zero trust architecture.
[0019] By adopting the above technical solutions, the legitimacy of the identity of data access users is ensured through multiple identity authentication mechanisms, and access rights are accurately allocated in combination with role-based access control mechanisms to prevent abuse of rights or unauthorized data access. After the data access user identity authentication is passed, a distributed data center is built based on the cloud architecture to achieve real-time monitoring data storage and management of multiple terminals, and the network traffic of the data center is monitored through an intelligent intrusion detection mechanism, which can identify and detect potential security threats in real time, such as abnormal access, malicious scanning or DDoS attacks, and improve the active defense capability of the system. With the zero-trust architecture, when a user initiates an access request, the user's access behavior, device status, access history and other factors are evaluated in real time, and the access request is judged by risk scoring whether it complies with the security policy to ensure dynamic adjustment and precise control of access rights. For access requests that meet the security policy, data decryption is allowed and access rights are provided, while for access requests that do not meet the security policy, they are automatically rejected and access rejection logs are recorded to improve data security traceability and security incident response capabilities.
[0020] The third objective of the present application is achieved through the following technical solutions: A computer device comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the above-mentioned cloud architecture distributed data processing method when executing the computer program.
[0021] The fourth objective of the present application is achieved through the following technical solutions: A computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of the above-mentioned cloud architecture distributed data processing method.
[0022] In summary, the present application includes at least one of the following beneficial technical effects: 1. Through multiple identity authentication mechanisms, ensure the legitimacy of the identity of data access users, and combine with role-based access control mechanisms to accurately allocate access rights to prevent abuse of rights or unauthorized data access. After the data access user identity authentication is passed, a distributed data center is built based on the cloud architecture to achieve real-time monitoring data storage and management of multiple terminals, and the network traffic of the data center is monitored through an intelligent intrusion detection mechanism, which can identify and detect potential security threats in real time, such as abnormal access, malicious scanning or DDoS attacks, and improve the system's active defense capabilities. Using a zero-trust architecture, when a user initiates an access request, the user's access behavior, device status, access history and other factors are evaluated in real time, and risk scoring is used to determine whether the access request complies with the security policy to ensure dynamic adjustment and precise control of access rights. For access requests that meet the security policy, data decryption is allowed and access rights are provided. For access requests that do not meet the security policy, they are automatically rejected and access rejection logs are recorded to improve data security traceability and security incident response capabilities; 2. After the user access request meets the security policy of the zero-trust architecture, an AES encryption key is dynamically generated, and the AES algorithm is used to symmetrically encrypt the real-time monitoring data to ensure that the data is encrypted before storage to prevent unauthorized access or leakage. At the same time, the RSA algorithm is used to asymmetrically encrypt the AES encryption key to ensure that the encryption key is not stolen during storage and transmission, thereby improving the security of key management. In addition, a hash algorithm is used to calculate the integrity check value of the encrypted data, and the check value is stored for subsequent verification of data integrity to prevent data from being maliciously tampered with. After the data is received, the system can recalculate the integrity check value of the encrypted data and compare it with the stored original check value. If the two are consistent, it ensures that the data has not been tampered with during storage or transmission, ensuring data integrity. When the data integrity verification passes, the system uses the RSA private key to decrypt the encrypted AES key, and then uses the AES key to decrypt the encrypted data, finally restoring the original data and allowing the data access user to access it normally; 3. The behavior pattern recognition of user access request data based on a deep learning model can accurately detect abnormal access behaviors, such as abnormal access time, abnormal access device, abnormal access frequency, or abnormal access target data, etc., so as to quickly discover potential security threats. When an abnormal user access behavior is recognized, the system generates security threat data and further conducts a risk assessment on the security threat data according to a preset security policy threshold. If the security threat data reaches the threshold of the security policy, the security defense mechanism is triggered, and the system automatically generates security defense data and takes corresponding defense measures according to different levels of security threats, such as restricting the access rights of suspicious users, triggering multi-factor authentication, terminating high-risk access requests, or even sending real-time alerts to security administrators to ensure a quick response and handling of potential security threats. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] Figure 1 is a schematic structural diagram of a cloud architecture distributed data processing method in an embodiment of the application; Figure 2 is an implementation flowchart of step S10 in the cloud architecture distributed data processing method in an embodiment of the application; Figure 3 is an implementation flowchart of one of the steps S103 in the cloud architecture distributed data processing method in an embodiment of the application; Figure 4 is an implementation flowchart of step S30 in the cloud architecture distributed data processing method in an embodiment of the application; Figure 5 is an implementation flowchart of step S40 in the cloud architecture distributed data processing method in an embodiment of the application; Figure 6 is an implementation flowchart after step S40 in the cloud architecture distributed data processing method in an embodiment of the application; Figure 7 is an implementation flowchart after step S50 in the cloud architecture distributed data processing method in an embodiment of the application; Figure 8 is a schematic block diagram of a cloud architecture distributed data processing device in an embodiment of the application; Figure 9 is a schematic diagram of a device in an embodiment of the application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0024] The following further describes the present application in detail with reference to the accompanying drawings.
[0025] In one embodiment, as Figure 1 shown, the present application discloses a cloud architecture distributed data processing method, which specifically includes the following steps: S10: Obtain the identity data of the data access user, and verify the identity data based on multi-factor authentication. If the identity verification is passed, allocate data access permissions through a role-based access control mechanism.
[0026] In this embodiment, the role-based access control mechanism refers to managing and allocating access permissions based on the identity role of the data access user. The role definitions can include administrator, ordinary user, visitor, auditor, etc., and different roles have different levels of data access permissions.
[0027] Specifically, receive identity data from the terminal device of the data access user. The identity data includes the user's unique identification information, such as username, user ID, email address, etc. At the same time, obtain the authentication information for identity verification. The authentication information includes static passwords, biometric data (such as fingerprints, facial features), dynamic tokens, or digital certificates. By parsing and formatting the authentication information to make it conform to the preset identity verification rules, after formatting is completed, compare it with the pre-stored identity database. If the identity verification is successful, query the role type to which the user belongs according to the user's unique identification information, match the preset access permission set according to the role type, and allocate the corresponding access permissions to the user to obtain access permission data.
[0028] S20: After the identity verification of the data access user is passed, establish a cloud-based distributed data center, and receive real-time monitoring data from multiple terminals according to the data access permissions, and store the real-time monitoring data in the cloud-based distributed data center.
[0029] In this embodiment, the cloud-based distributed data center refers to a distributed data management platform that uses cloud computing technology to support large-scale data storage and computing.
[0030] Specifically, according to the distributed resource management strategy, allocate the resources of storage and computing nodes, and initialize the communication link between the storage nodes and the computing nodes so that data can be transmitted between multiple nodes. After initialization is completed, establish a data access channel so that multiple terminals can send real-time monitoring data to the distributed data center through a preset network protocol. After receiving the real-time monitoring data, parse the source identification information in the data, and judge whether the data meets the storage conditions according to the access permission data. If it meets the storage conditions, slice the data according to the data storage rules, and allocate the sliced data to multiple storage nodes. During the storage process, set the corresponding storage index for the data according to the data type and storage requirements to obtain the stored real-time monitoring data.
[0031] S30: After the real-time monitoring data is stored in the cloud-based distributed data center, the network traffic in the cloud-based distributed data center is monitored through an AI-driven intelligent intrusion detection mechanism to obtain user access request data.
[0032] In this embodiment, the AI-driven intelligent intrusion detection mechanism refers to an intrusion detection method based on AI technology. Through technologies such as deep learning and pattern recognition, the network traffic of the distributed data center is monitored in real time, and abnormal access behaviors are identified.
[0033] Specifically, the network traffic of the distributed data center is collected in real time, and the collected data packets are subjected to protocol parsing. Network communication information such as source IP address, destination IP address, port number, protocol type, data packet size, and timestamp is extracted from the data packets. After the extraction is completed, the network communication information is input into a pre-trained AI model. The AI model performs pattern matching based on access behavior characteristics to identify whether there are abnormal access behaviors. Abnormal access behaviors include high-frequency access within a short period of time, abnormal login requests, abnormal data reading, etc. After the identification is completed, the data content of the access request is extracted, and the data content is parsed to extract information such as the user identifier, target data object, and request operation type of the access request to obtain user access request data.
[0034] S40: Based on the user access request data, the zero-trust architecture is used to dynamically evaluate the access requests of data access users. If the access request meets the security policy of the zero-trust architecture, the data access user is allowed to access the decrypted data.
[0035] In this embodiment, the zero-trust architecture refers to a security management mechanism for user access behaviors based on the principle of "never trust, always verify", adopting mechanisms such as multi-factor authentication, dynamic risk assessment, and fine-grained access control. Under the zero-trust architecture, all access requests must undergo strict security verification, and even if the access comes from the internal network, it cannot be trusted by default. The security policy refers to access control rules dynamically evaluated based on multi-dimensional information such as the identity of the access user, device status, network environment, and historical access behaviors.
[0036] Specifically, the user access request data is parsed, and the data access attributes of the user access request are obtained. The data access attributes include user identity information, access device information, network environment information, historical access behaviors, etc. Weight calculations are performed on the data access attributes. Among them, the weight of the user identity information is set according to the authentication strength of the user identity, the weight of the access device information is set according to the security level of the device, the weight of the network environment information is set according to whether the access source is trustworthy, and the weight of the historical access behaviors is set according to whether the user has abnormal access records. After the weight setting is completed, risk score calculations are performed on each data access attribute, and a total risk score is generated based on the calculation results. When the total risk score is lower than the security policy threshold, it is determined that the access request complies with the security policy to obtain the decrypted data.
[0037] S50: If the access request of the data access user does not meet the security policy of the zero-trust architecture, the access request is rejected, and an access rejection log is generated.
[0038] Specifically, when the total risk score exceeds the security policy threshold, the access request is rejected, and the reasons for rejection are recorded. The reasons for rejection include authentication failure, untrusted access device, abnormal access source, abnormal access behavior, etc. The rejected access request data is formatted. The formatting process includes converting information such as the timestamp of the access request, user identity information, access target, risk score, etc. into a storable log format. After the log format conversion is completed, the log data is stored in the access log repository, and an index is set for subsequent audit analysis to obtain the access rejection log.
[0039] In one embodiment, as Figure 2 shown, in step S10, that is, the identity data of the data access user is obtained, and the identity data is verified based on multi-factor authentication. If the authentication is passed, data access permissions are assigned through a role-based access control mechanism, and it further includes: S101: Verify the identity data based on the multi-factor authentication mechanism to obtain the authentication result. The multi-factor authentication mechanism includes static password authentication, biometric authentication, or dynamic authentication based on a one-time token.
[0040] Specifically, after receiving the identity data submitted by the data access user, the identity data is formatted to conform to the preset identity verification rules. For static password authentication, the password entered by the user is encrypted through a hashing algorithm and matched with the pre-stored encrypted password; for biometric authentication, feature values are extracted from the biometric data submitted by the user and compared with the pre-stored feature templates in the identity database. The feature values include fingerprint texture, iris image features, facial key point data, etc.; for dynamic authentication based on a one-time token, the dynamic token data submitted by the user is parsed, and the current valid token value is calculated according to the preset time synchronization mechanism or based on the challenge-response method. It is compared whether the token value submitted by the user matches. After the match is successful, the identity verification is confirmed to pass to obtain the verification result.
[0041] S102: According to the identity verification result, use the role-based access control mechanism to determine the access rights of the data access user and generate a permission allocation policy.
[0042] Specifically, according to the identity verification result, the user identification information of the data access user is extracted, and the preset role permission mapping table is queried. The role permission mapping table stores the access permission information corresponding to different user roles, including the data types that can be accessed, data access operation permissions, and access ranges, etc. After querying the role information corresponding to the data access user, the permission set matching the role is obtained, and the access permissions are dynamically adjusted in combination with the current security policy. For example, if the user's access environment changes, such as the login device is different from the historical record, the access network is in a high-risk area, etc., additional security verification requirements are added or some sensitive data access permissions are restricted on the basis of the original access permissions. After the permissions are determined, the corresponding permission allocation policy is generated and recorded in the permission management database to obtain the permission allocation policy.
[0043] S103: After the permission allocation policy is generated, the access permissions are granted to the data access user through the role-based access control mechanism, and the data types, access ranges, and operation permissions that the data access user can access are restricted based on the permission allocation policy.
[0044] Specifically, after the permission allocation policy is generated, read the permission allocation policy from the permission management database, associate the permission allocation policy with the identity identifier of the data access user, generate an access token, where the access token includes parameters such as user identity information, role permission information, data access scope, data operation permissions, and access validity period, bind the access token to the session information of the data access user, and when the data access user initiates a data access request, parse the submitted access token, extract the access permission information therein, and perform permission verification on the data access request based on the access permission information. For example, when the data access user attempts to access a data type beyond its authorized scope, reject the access request, or when the data access user attempts to perform an unauthorized operation (such as modification, deletion), block the operation execution. In the case where the permission verification passes, allow the data access user to perform legal data access operations to obtain controlled data access permissions.
[0045] In one embodiment, as Figure 3 shown, in step S103, that is, after the permission allocation policy is generated, grant access permissions to the data access user through a role-based access control mechanism, and limit the data types, access scope, and operation permissions that the data access user can access based on the permission allocation policy. It further includes: S1031: When the data access user initiates a data access operation, perform real-time verification of the access permissions of the data access user according to the permission allocation policy.
[0046] Specifically, after receiving the access request from the data access user, extract the user identity identifier, the unique identifier of the access target data, and the requested operation type from the access request data, match the user identity identifier with the permission allocation policy in the permission management database, and extract the corresponding access permission information of the user. After the matching is completed, compare whether the data type, access scope, and operation permissions of the access request match the authorized scope in the permission allocation policy. For example, when the target data requested by the data access user belongs to the sensitive data category, further verify whether the user has additional security authentication information. If the requested operation permission exceeds the permission level already assigned to the user, it is determined that the user does not have the corresponding data access permission. If the requested data access time or access location does not conform to the preset security policy, trigger dynamic security verification to obtain the verification result of the data access permission.
[0047] S1032: If the access permissions of the data access user conform to the permission allocation policy, allow the data access user to access the requested data.
[0048] Specifically, after determining that the access permission of the data access user complies with the permission allocation policy, parse the storage path of the requested data, and locate the target data file based on the storage path. After the data file is located, verify the data integrity. The data integrity verification includes calculating the hash value of the data and comparing it with the stored integrity verification value to confirm that the data has not been tampered with. After the verification passes, create a data access channel for the data access user, and set the validity period of the access channel according to the permission allocation policy. When the data access user requests to read data, extract the corresponding data content from the storage path, and determine the returned data format according to the permission policy. For example, when the permission level of the data access user is read-only, only the standard format of the data is allowed to be obtained, while when the user's permission level supports data modification, the data in editable format is allowed to be obtained. After the data content is returned, record the access log for this time to obtain the data request response after the access.
[0049] S1033: If the access permission of the data access user does not meet the permission allocation policy, reject the access permission.
[0050] Specifically, after determining that the access permission of the data access user does not meet the permission allocation policy, generate an access rejection response, and append the reason for rejection to the response data. The reasons for rejection include insufficient access permission, restricted access time, untrusted access device, unauthorized request operation, etc. After the rejection response is generated, record the rejection log in the security log database, and append the access request data to the log record, including user identity identifier, access target data identifier, access request time, reason for rejection, etc. After the log storage is completed, if it is detected that there are consecutive multiple access failures, trigger the access restriction mechanism. The access restriction mechanism includes temporarily locking the access permission of the data access user, sending an alarm message to the security administrator, or requiring the data access user to perform additional identity verification. After the rejection response is returned, terminate the current access request to obtain the recorded data of the access rejection.
[0051] S1034: After the permission allocation policy is adjusted, if the access permission of the data access user is downgraded or revoked, automatically block the access of the data access user.
[0052] Specifically, after the permission allocation policy adjustment is completed, resynchronize the latest permission allocation policy from the permission management database, and for each active access session, parse the access token and extract the role permission information contained in the access token. Compare the extracted role permission information with the latest permission allocation policy. If the comparison result shows that the access permission of the data access user has been downgraded or revoked, terminate the current access session, disconnect the data access user from the cloud-based distributed data center, and prevent the data access user from continuing to perform data access operations.
[0053] In one embodiment, as Figure 4 shown, in step S30, that is, the network traffic in the cloud - architecture - based distributed data center is monitored through an AI - driven intelligent intrusion detection mechanism to obtain user access request data, including: S301: The network traffic of the cloud - architecture - based distributed data center is analyzed in real - time through an AI - driven intelligent intrusion detection mechanism to extract network communication data packets.
[0054] Specifically, an intelligent intrusion detection mechanism is deployed inside the cloud - architecture - based distributed data center, and the data stream of the network interface is captured through a traffic monitoring module. After capturing the data stream, the data is screened according to preset network traffic filtering rules, and data streams irrelevant to the service are excluded, such as broadcast data packets, normal heartbeat data packets, etc. After the screening is completed, the integrity of the data packets that meet the analysis conditions is detected to ensure that the data packets are not lost or tampered with. After the integrity detection passes, the data stream is re - organized into independent network communication data packets according to the traffic characteristics, and metadata such as a timestamp, source IP address, destination IP address, protocol type, data length, etc. is attached to each data packet to obtain complete network communication data packets.
[0055] S302: The communication protocol of the network communication data packet is parsed to identify the communication protocol type of the network communication data packet, and the basic network attributes of the network communication data packet are parsed based on the communication protocol type.
[0056] Specifically, after receiving the network communication data packet, the protocol header field of the data packet is extracted, and its belonging communication protocol type is parsed according to the protocol identification information. For example, when the protocol field value is "0x06", it is identified that the data packet is a TCP protocol data packet; when the protocol field value is "0x11", it is identified that the data packet is a UDP protocol data packet. After the identification is completed, the data packet is parsed in detail according to different communication protocol types. For TCP data packets, basic network attributes such as source port number, destination port number, sequence number, acknowledgment number, flag bits, window size, etc. are extracted; for UDP data packets, basic network attributes such as source port number, destination port number, data length, etc. are extracted; for ICMP data packets, basic network attributes such as type code, code field, checksum, etc. are extracted. After the parsing is completed, the basic network attributes are stored in a structured database for subsequent analysis.
[0057] S303: Based on the basic network attributes, the associated data of the network communication data packet is calculated. Based on the basic network attributes and the associated data, the access behavior characteristics of the network communication data packet are analyzed, and access behavior parameters are extracted.
[0058] Specifically, after obtaining the basic network attributes of the network communication packet, calculate the communication path of the packet based on the source IP address and the destination IP address, and calculate the access frequency of the packet in combination with the historical access records. During the calculation process, count the number of accesses of a specific IP address within a unit time and the historical communication pattern with the same destination IP address. In addition, analyze the service usage situation by combining the port number information. For example, when it is detected that the access frequency of a specific port increases abnormally, it may indicate the existence of port scanning behavior. After the associated data calculation is completed, analyze the access behavior characteristics based on the time series information of the packet. For example, when the transmission interval time of the packet is abnormally shortened, it may indicate the existence of a Denial of Service (DoS) attack behavior. In addition, calculate the data traffic characteristics based on the packet size and the transmission time. For example, when the size of the packet far exceeds the normal range, it may indicate the existence of abnormal data leakage behavior. After completing the analysis of the access behavior characteristics, extract the access behavior parameters. The access behavior parameters include the access path category, data transmission rate, access duration, data traffic pattern, etc., to obtain the access behavior characteristic information of the packet.
[0059] S304: According to the access behavior parameters, construct an access request data set, and extract the access pattern based on the access request data set to determine the user access request data.
[0060] Specifically, after extracting the access behavior parameters, classify the access behavior data according to the user identity information, and construct an access request data set. The access request data set includes the user's historical access records, network behavior patterns, access time distribution, access device information, etc. After construction, analyze the access pattern based on the clustering algorithm. During the access pattern extraction process, first calculate the time distribution characteristics of the access behavior. For example, if a certain user usually accesses the data center during a specific time period and the current access request occurs during an abnormal time period, then this access request may be abnormal. At the same time, by calculating the consistency of the access path, judge whether the user's current access path conforms to the historical access pattern. For example, when there is a large deviation between the destination IP address accessed by the user and the previous access targets, then this access may have a malicious attack behavior. In addition, combine the user's historical access device information to judge whether the current access device is trustworthy. For example, if a user usually accesses using a fixed device and the current access device does not match the historical device, then further identity verification may be required. After completing the access pattern extraction, determine the user access request data based on the matching degree of the access pattern.
[0061] In one embodiment, as Figure 5 shown, in step S40, that is, use the zero-trust architecture to perform dynamic security assessment on the access requests of data access users, including: S401: Parse the user access request data through the zero-trust architecture and extract the access security attribute data.
[0062] Specifically, after receiving the user access request data, preprocess the request data and parse the key attributes of the user access request. The key attributes include user identity information, access device information, access network environment information, access behavior historical data, etc. When parsing the user identity information, extract the user unique identifier from the identity credentials submitted by the user and verify whether its identity authentication method complies with the security policy. For example, if the user uses static password authentication, extract its encrypted hash value and compare it with the pre-stored data. If multi-factor authentication is used, verify whether all authentication factors match. When parsing the access device information, extract the device identification information from the user request header or terminal environment variables, such as device model, operating system version, device fingerprint, etc., and determine whether the device is the user's historical usage device. When parsing the access network environment information, extract the access source IP address, network type (such as company intranet, public Wi-Fi, cellular network, etc.), and compare the historical access records to determine the stability of the access environment. When parsing the access behavior historical data, extract the user's past access records, including the access time period, frequency, target resource, operation type, etc., and calculate its access behavior pattern. After all the access security attribute data is parsed, store it in a structured manner for subsequent risk score calculation.
[0063] S402: Calculate the risk score of the data access user according to the access security attribute data.
[0064] Specifically, after extracting the access security attribute data, assign weights to each security attribute and calculate the risk score of the data access user according to the preset risk calculation model. During the calculation process, conduct a risk assessment on the user identity information. If the identity authentication method used by the user is relatively simple, such as only using a static password, increase the risk score. If the user uses multi-factor authentication, reduce the risk score. Conduct a risk assessment on the access device information. If the user's device does not appear in the historical access records or the device operating system version is too old, increase the risk score accordingly. Conduct a risk assessment on the access network environment information. If the user access request comes from public Wi-Fi or a high-risk IP address, increase the risk score. If the user access request comes from a known company intranet or a trusted VPN, reduce the risk score. Conduct a risk assessment on the access behavior historical data. If the user's current access request deviates significantly from its historical access behavior, such as abnormal access time, different access target resources from the historical records, and access operations not conforming to the previous behavior pattern, increase the risk score. After the risk calculation of all security attributes is completed, conduct a weighted average of the scores of each item and generate the final risk score.
[0065] S403: Based on the risk score, estimate whether the access request of the data access user meets the security policy of the zero trust architecture.
[0066] Specifically, after obtaining the risk score of the data access user, the risk score is evaluated according to the security policy of the zero-trust architecture, and the processing method of the access request is determined according to the evaluation result. During the evaluation process, first compare it with the preset security threshold. If the risk score is lower than the lowest security threshold, the access request is considered safe and the user is allowed to access the target resource. If the risk score is in the middle security range, an additional authentication mechanism is triggered, such as requiring the user to perform secondary authentication through a mobile phone verification code, dynamic token or biometric identification. After the secondary authentication is passed, the access request is re-evaluated. If the verification is passed, access is allowed; otherwise, access is denied. If the risk score exceeds the highest security threshold, it is determined that the access request has a high risk, the access request is directly rejected, and the access log is recorded. After rejecting the access, further analyze whether there is a potential threat in the access request. For example, by comparing the similarity between the access request and the historical attack pattern, determine whether it is necessary to trigger security defense measures, such as temporarily blocking the user account, restricting device access, sending an alarm to the security administrator, etc.
[0067] In one embodiment, as Figure 6 shown, after step S40, that is, based on the user access request data, the access request of the data access user is dynamically and securely evaluated using the zero-trust architecture. If the access request meets the security policy of the zero-trust architecture, the data access user is allowed to access the decrypted data, and it further includes: S404: After the access request of the data access user meets the security policy of the zero-trust architecture, generate an AES encryption key, and use the AES algorithm to perform symmetric encryption on the real-time monitoring data to obtain encrypted data, and store the encrypted data.
[0068] Specifically, after confirming that the access request of the data access user meets the security policy of the zero-trust architecture, an AES encryption key is randomly generated. The length of the AES encryption key can be selected according to the preset encryption security level, such as 128 bits, 192 bits or 256 bits. After the AES encryption key is generated, the AES algorithm is used to perform symmetric encryption on the real-time monitoring data. During the encryption process, the data to be encrypted is first divided into blocks, and each data block is encrypted according to the AES encryption mode (such as CBC mode, GCM mode). If the CBC mode is selected, a random initial vector (IV) is first generated and the data blocks are encrypted in a chained manner. If the GCM mode is selected, an encryption tag is calculated for data integrity verification. After all data blocks are encrypted, the encrypted data is combined with the initial vector (IV) and stored.
[0069] S405: Asymmetrically encrypt the AES encryption key using the RSA algorithm to obtain the encrypted key data, calculate the original integrity check value for the encrypted data in combination with the hashing algorithm, and store the original integrity check value.
[0070] Specifically, after the AES encryption key is generated, obtain the preset RSA public key and use the RSA encryption algorithm to asymmetrically encrypt the AES encryption key. During the encryption process, first perform padding processing on the AES encryption key to meet the requirements of the RSA encryption algorithm. For example, if PKCS#1 padding is used, random padding data is added before the encryption key to enhance encryption security. After the padding is completed, perform exponentiation and modulo operations using the RSA public key to generate the encrypted key data. After the key encryption is completed, perform a hashing operation on the AES encrypted data. The hashing operation is based on a preset hashing algorithm, such as SHA-256 or SHA-512. During the calculation process, perform hashing calculations on all data blocks of the encrypted data to generate the original integrity check value of a fixed length.
[0071] S406: After the encrypted data is received, recalculate the verification integrity check value of the encrypted data and compare the verification integrity check value with the stored original integrity check value. If the two are consistent, confirm that the encrypted data has not been tampered with.
[0072] Specifically, after the encrypted data is requested and received by the accessing user, read the encrypted data from the storage medium and recalculate the verification integrity check value of the encrypted data according to the same hashing algorithm as the original encryption process. During the calculation process, traverse all data blocks of the encrypted data and perform hashing operations respectively to generate the final hash check value. After the hashing calculation is completed, compare the verification integrity check value with the stored original integrity check value. If the hash values of the two are exactly the same, it indicates that the data has not been tampered with or damaged during storage or transmission, and the data integrity is confirmed to be valid. If the two are inconsistent, it is considered that the data may have a tampering risk, and the decryption operation for the encrypted data is refused.
[0073] S407: In the case where the encrypted data has not been tampered with, decrypt the encrypted key data using the RSA private key to obtain the AES encryption key, and use the AES encryption key to decrypt the encrypted data to obtain the decrypted data, and allow the data accessing user to access the decrypted data.
[0074] Specifically, after confirming that the encrypted data has not been tampered with, the encrypted key data is read from the key storage database, and the RSA private key is used to decrypt the key data. During the decryption process, first, the padding method of the key data is checked, and modular inversion calculation is performed according to the inverse operation of the RSA decryption algorithm to recover the AES encryption key. After the AES encryption key is decrypted, according to the stored AES encryption mode, the corresponding decryption algorithm is selected to decrypt the encrypted data. If the AES encryption uses the CBC mode, the stored initialization vector (IV) is first extracted, and then the AES decryption operation is performed block by block to recover the original data block. If the AES encryption uses the GCM mode, the integrity of the GCM tag is verified at the same time. After the data is decrypted, the decrypted data is organized into a format accessible to the user and provided to the data access user for normal access to the requested data.
[0075] In one embodiment, as Figure 7 shown, after step S50, that is, the cloud architecture distributed data processing method further includes: S501: Based on the deep learning model, identify the behavior pattern of the user access request data, and determine whether the user access request data is abnormal. If the user access request data is abnormal, security threat data is generated.
[0076] In this embodiment, the deep learning model refers to the LSTM model.
[0077] Specifically, after receiving the user access request data, first, format the access request data and extract the access behavior characteristics. The access behavior characteristics include the user identifier of the access request, access device information, access source IP address, type of the requested target data, data access method, etc. After the feature extraction is completed, the extracted features are input into the deep learning model. The deep learning model makes a prediction based on the historical training data and determines whether the current access request conforms to the normal behavior pattern of the user. For example, if the time period of the user's past access data is mainly concentrated during weekdays during the day, and the current request occurs during non-working hours and the access source has changed significantly, it may indicate an abnormal access. In addition, if the data range accessed by the user suddenly expands, involves multiple sensitive data sets, and the access frequency increases abnormally, it may indicate a risk of data leakage. After identifying the abnormal access behavior, security threat data is generated. The security threat data includes information such as abnormal access time, abnormal access target, abnormal score, risk level, etc., for subsequent security policy evaluation.
[0078] S502: Determine whether the security threat data reaches the preset security policy threshold. If the security threat data reaches the preset security policy threshold, security defense data is generated, and based on the security defense data, the corresponding security defense measures are executed.
[0079] Specifically, after generating security threat data, risk assessment is performed on the security threat data according to a preset security policy, and its risk score is calculated. The risk score is calculated based on multiple factors, including the deviation degree of abnormal behavior, the matching degree of historical access records, the sensitivity level of the accessed target data, whether the access method complies with the security policy, etc. During the calculation process, if the abnormal behavior deviates greatly from the normal mode, the risk score is increased. If the accessed target data is highly sensitive data, the risk score is further increased. After all factors are calculated, the final risk score is generated and compared with the preset security policy threshold. If the risk score is lower than the security threshold, the abnormal access record is stored and subsequent access behaviors are continuously monitored. If the risk score reaches or exceeds the security policy threshold, it is determined that there is a high security risk in this access behavior, and security defense data is generated. The security defense data includes threat type, risk level, recommended security defense measures, etc. After generating the security defense data, corresponding security defense measures are executed according to the security defense data. The security defense measures include but are not limited to: Multiple Factor Authentication (MFA) trigger: When the risk score is high but does not reach the blocking level, the accessing user is required to perform additional identity verification, such as dynamic token, SMS verification code, face recognition, etc. Access privilege downgrade: If the risk score exceeds the security threshold but does not reach the highest level, the access privilege of this user is temporarily lowered, and only low-sensitive data is allowed to be accessed, and the abnormal access behavior is recorded. Access blocking: If the risk score reaches the highest threshold, the access request is immediately rejected, the access log is recorded, and an alarm notification is sent to the security administrator for further investigation. Account freezing: When a serious security threat is detected, such as continuous multiple high-risk access failures, the risk of data leakage, etc., the user account is temporarily frozen to prevent malicious operations from continuing.
[0080] It should be understood that the sequence numbers of the steps in the above embodiments do not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.
[0081] In one embodiment, a cloud architecture distributed data processing device is provided, which corresponds one-to-one with the cloud architecture distributed data processing method in the above embodiment. As Figure 8 shown, the cloud architecture distributed data processing device includes an identity authentication and privilege assignment module, a distributed data center construction module, a network traffic monitoring module, a zero-trust security assessment module, and an access control and log management module. The detailed description of each functional module is as follows: The identity authentication and privilege assignment module is used to obtain the identity data of the data access user, verify the identity data based on multiple factor authentication, and if the identity verification is passed, assign data access privileges through a role-based access control mechanism; A distributed data center construction module, which is used to establish a cloud-based distributed data center after the authentication of the data access user passes, and receive real-time monitoring data from multiple terminals according to the data access permissions, and store the real-time monitoring data in the cloud-based distributed data center; A network traffic monitoring module, which is used to monitor the network traffic in the cloud-based distributed data center through an artificial intelligence-driven intelligent intrusion detection mechanism after the real-time monitoring data is stored in the cloud-based distributed data center, and obtain user access request data; A zero-trust security assessment module, which is used to dynamically assess the security of the access request of the data access user based on the user access request data by using the zero-trust architecture. If the access request meets the security policy of the zero-trust architecture, the data access user is allowed to access the decrypted data; An access control and log management module, which is used to reject the access request and generate an access rejection log if the access request of the data access user does not meet the security policy of the zero-trust architecture.
[0082] Optionally, the identity authentication and permission allocation module includes: An identity authentication sub-module, which is used to verify the identity data based on a multi-factor identity authentication mechanism to obtain an identity authentication result. The multi-factor identity authentication mechanism includes static password authentication, biometric authentication, or dynamic authentication based on a one-time token; A permission allocation policy generation sub-module, which is used to determine the access permissions of the data access user according to the identity authentication result by using a role-based access control mechanism and generate a permission allocation policy; An access control sub-module, which is used to grant the access permissions to the data access user through a role-based access control mechanism after the permission allocation policy is generated, and restrict the data types, access scopes, and operation permissions that the data access user can access based on the permission allocation policy.
[0083] Optionally, the access control sub-module includes: An access request verification unit, which is used to verify the access permissions of the data access user in real time according to the permission allocation policy when the data access user initiates a data access operation; An access decision unit, which is used to allow the data access user to access the requested data if the access permissions of the data access user conform to the permission allocation policy; An access rejection processing unit, which is used to reject the access permissions if the access permissions of the data access user do not meet the permission allocation policy; A permission change response unit, which is used to automatically prevent the data access user from accessing if the access permissions of the data access user are downgraded or revoked after the permission allocation policy is adjusted.
[0084] Optionally, the network traffic monitoring module includes: A network traffic analysis sub-module for performing real-time analysis on the network traffic of a distributed data center based on a cloud architecture through an AI-driven intelligent intrusion detection mechanism to extract network communication data packets; A communication protocol parsing sub-module for parsing the protocol of network communication data packets, identifying the communication protocol type of network communication data packets, and parsing the basic network attributes of network communication data packets based on the communication protocol type; An access behavior analysis sub-module for calculating the associated data of network communication data packets based on the basic network attributes, analyzing the access behavior characteristics of network communication data packets based on the basic network attributes and the associated data, and extracting access behavior parameters; An access pattern recognition sub-module for constructing an access request data set according to the access behavior parameters, extracting access patterns based on the access request data set, and determining user access request data.
[0085] Optionally, the zero-trust security assessment module includes: An access security attribute extraction sub-module for parsing user access request data through a zero-trust architecture to extract access security attribute data; A risk score calculation sub-module for calculating the risk score of data access users according to the access security attribute data; A security policy evaluation sub-module for evaluating whether the access requests of data access users meet the security policies of the zero-trust architecture based on the risk score.
[0086] Optionally, after the zero-trust security assessment module, there is: A data encryption sub-module for generating an AES encryption key after the access request of the data access user meets the security policies of the zero-trust architecture, symmetrically encrypting the real-time monitoring data using the AES algorithm to obtain encrypted data, and storing the encrypted data; A key protection and integrity verification sub-module for asymmetrically encrypting the AES encryption key using the RSA algorithm to obtain encrypted key data, calculating the original integrity verification value for the encrypted data in combination with the hash algorithm, and storing the original integrity verification value; An integrity verification sub-module for recalculating the verification integrity verification value of the encrypted data after the encrypted data is received, and comparing the verification integrity verification value with the stored original integrity verification value. If the two are consistent, it is confirmed that the encrypted data has not been tampered with; A data decryption sub-module for decrypting the encrypted key data using the RSA private key in the case that the encrypted data has not been tampered with to obtain the AES encryption key, and decrypting the encrypted data using the AES encryption key to obtain the decrypted data, allowing the data access user to access the decrypted data.
[0087] Optionally, the log management module further includes: A user behavior analysis module, configured to identify a behavior pattern of user access request data based on a deep learning model, determine whether the user access request data is abnormal, and generate security threat data if the user access request data is abnormal; A security defense decision module, configured to determine whether the security threat data reaches a preset security policy threshold, generate security defense data if the security threat data reaches the preset security policy threshold, and execute corresponding security defense measures based on the security defense data.
[0088] For the specific limitations of the cloud architecture distributed data processing device, reference may be made to the limitations of the cloud architecture distributed data processing method in the foregoing text, which will not be elaborated herein. Each module in the above cloud architecture distributed data processing device can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in the processor of the computer device in hardware form or independent of it, or stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to the above modules.
[0089] In one embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as shown in Figure 9 the figure. The computer device includes a processor, a memory, a network interface, and a database connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used for permission management database. The network interface of the computer device is used to communicate with an external terminal through a network connection. The computer program, when executed by the processor, implements a cloud architecture distributed data processing method.
[0090] In one embodiment, a computer device is provided, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the following steps are implemented: Obtain identity data of a data access user, and verify the identity data based on multiple identity authentications. If the identity verification is passed, allocate data access permissions through a role-based access control mechanism; After the identity verification of the data access user is passed, establish a cloud architecture-based distributed data center, and receive real-time monitoring data from multiple terminals according to the data access permissions, and store the real-time monitoring data in the cloud architecture-based distributed data center; After the real-time monitoring data is stored in the cloud-based distributed data center, the network traffic in the cloud-based distributed data center is monitored by an AI-driven intelligent intrusion detection mechanism to obtain user access request data; Based on the user access request data, the zero-trust architecture is used to dynamically evaluate the access requests of data access users. If the access request meets the security policy of the zero-trust architecture, the data access user is allowed to access the decrypted data; If the access request of the data access user does not meet the security policy of the zero-trust architecture, the access request is rejected and an access rejection log is generated.
[0091] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented: Obtain the identity data of the data access user, and verify the identity data based on multi-factor authentication. If the identity verification is passed, data access permissions are assigned through a role-based access control mechanism; After the identity verification of the data access user is passed, a cloud-based distributed data center is established, and according to the data access permissions, real-time monitoring data from multiple terminals is received and stored in the cloud-based distributed data center; After the real-time monitoring data is stored in the cloud-based distributed data center, the network traffic in the cloud-based distributed data center is monitored by an AI-driven intelligent intrusion detection mechanism to obtain user access request data; Based on the user access request data, the zero-trust architecture is used to dynamically evaluate the access requests of data access users. If the access request meets the security policy of the zero-trust architecture, the data access user is allowed to access the decrypted data; If the access request of the data access user does not meet the security policy of the zero-trust architecture, the access request is rejected and an access rejection log is generated.
[0092] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the embodiments provided in the present application can include non-volatile and / or volatile memories. Non-volatile memories can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memories can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.
[0093] Those skilled in the art can clearly understand that, for the convenience and brevity of description, only the above division of each functional unit and module is used as an example. In actual applications, the above functions can be allocated to different functional units and modules according to needs, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above.
[0094] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be included in the protection scope of the present application.
Claims
1. A cloud architecture distributed data processing method, characterized in that, The cloud architecture-based distributed data processing method includes: Obtain the identity data of the data access user, and verify the identity data based on multi-factor authentication. If the identity verification is passed, allocate data access permissions through a role-based access control mechanism; After the identity verification of the data access user is passed, establish a cloud architecture-based distributed data center, and receive real-time monitoring data from multiple terminals according to the data access permissions, and store the real-time monitoring data in the cloud architecture-based distributed data center; After the real-time monitoring data is stored in the cloud architecture-based distributed data center, monitor the network traffic in the cloud architecture-based distributed data center through an artificial intelligence-driven intelligent intrusion detection mechanism to obtain user access request data; Based on the user access request data, perform dynamic security assessment on the access request of the data access user using the zero-trust architecture. If the access request meets the security policy of the zero-trust architecture, allow the data access user to access the decrypted data; If the access request of the data access user does not meet the security policy of the zero-trust architecture, reject the access request and generate an access rejection log.
2. The cloud architecture distributed data processing method according to claim 1, characterized in that The obtaining the identity data of the data access user, and verifying the identity data based on multi-factor authentication. If the identity verification is passed, allocate data access permissions through a role-based access control mechanism, further includes: Verify the identity data based on the multi-factor authentication mechanism to obtain an identity verification result. The multi-factor authentication mechanism includes static password authentication, biometric authentication, or one-time token-based dynamic authentication; According to the identity verification result, use the role-based access control mechanism to determine the access permissions of the data access user and generate a permission allocation policy; After the permission allocation policy is generated, grant the access permissions to the data access user through the role-based access control mechanism, and limit the data types, access scopes, and operation permissions that the data access user can access based on the permission allocation policy.
3. The cloud architecture distributed data processing method according to claim 2, wherein The after the permission allocation policy is generated, grant the access permissions to the data access user through the role-based access control mechanism, and limit the data types, access scopes, and operation permissions that the data access user can access based on the permission allocation policy, further includes: When the data access user initiates a data access operation, perform real-time verification on the access permissions of the data access user according to the permission allocation policy; If the access permissions of the data access user comply with the permission allocation policy, allow the data access user to access the requested data; If the access permissions of the data access user do not meet the permission allocation policy, reject the access permissions; After the permission allocation policy is adjusted, if the access permissions of the data access user are downgraded or revoked, automatically block the access of the data access user.
4. The cloud architecture distributed data processing method according to claim 1, characterized in that, The network traffic in the cloud - based distributed data center is monitored by the AI - driven intelligent intrusion detection mechanism to obtain user access request data, including: The network traffic of the cloud - based distributed data center is analyzed in real - time by the AI - driven intelligent intrusion detection mechanism to extract network communication data packets; The network communication data packets are protocol - parsed to identify the communication protocol types of the network communication data packets, and the basic network attributes of the network communication data packets are parsed based on the communication protocol types; Based on the basic network attributes, the associated data of the network communication data packets is calculated. Based on the basic network attributes and the associated data, the access behavior characteristics of the network communication data packets are analyzed, and access behavior parameters are extracted; According to the access behavior parameters, an access request data set is constructed, and an access pattern is extracted based on the access request data set to determine the user access request data.
5. The cloud architecture distributed data processing method according to claim 1, characterized in that The dynamic security assessment of the access requests of the data access users by using the zero - trust architecture includes: The user access request data is parsed by the zero - trust architecture to extract access security attribute data; According to the access security attribute data, the risk score of the data access user is calculated; Based on the risk score, it is estimated whether the access request of the data access user meets the security policy of the zero - trust architecture.
6. The cloud architecture distributed data processing method according to claim 1, wherein Based on the user access request data, when the dynamic security assessment of the access requests of the data access users is performed by using the zero - trust architecture, if the access request meets the security policy of the zero - trust architecture, the data access user is allowed to access the decrypted data, and it further includes: After the access request of the data access user meets the security policy of the zero - trust architecture, an AES encryption key is generated, and the real - time monitoring data is symmetrically encrypted by using the AES algorithm to obtain encrypted data, and the encrypted data is stored; The AES encryption key is asymmetrically encrypted by using the RSA algorithm to obtain encrypted key data, and the original integrity check value of the encrypted data is calculated by combining with the hash algorithm, and the original integrity check value is stored; After the encrypted data is received, the verification integrity check value of the encrypted data is recalculated, and the verification integrity check value is compared with the stored original integrity check value. If the two are consistent, it is confirmed that the encrypted data has not been tampered with; In the case that the encrypted data has not been tampered with, the encrypted key data is decrypted by using the RSA private key to obtain the AES encryption key, and the encrypted data is decrypted by using the AES encryption key to obtain the decrypted data, and the data access user is allowed to access the decrypted data.
7. The cloud architecture distributed data processing method according to claim 1, wherein The user access request data further includes: Based on the deep - learning model, the behavior pattern of the user access request data is identified, and it is judged whether the user access request data is abnormal. If the user access request data is abnormal, security threat data is generated; Determine whether the security threat data reaches a preset security policy threshold. If the security threat data reaches the preset security policy threshold, generate security defense data and execute corresponding security defense measures based on the security defense data.
8. A cloud architecture distributed data processing device, characterized in that, The cloud architecture distributed data processing device includes: An identity authentication and permission allocation module, configured to obtain identity data of a data access user and verify the identity data based on multiple identity authentications. If the identity verification is passed, allocate data access permissions through a role-based access control mechanism; A distributed data center construction module, configured to establish a cloud architecture-based distributed data center after the identity verification of the data access user is passed, and receive real-time monitoring data from multiple terminals according to the data access permissions, and store the real-time monitoring data in the cloud architecture-based distributed data center; A network traffic monitoring module, configured to monitor the network traffic in the cloud architecture-based distributed data center through an artificial intelligence-driven intelligent intrusion detection mechanism after the real-time monitoring data is stored in the cloud architecture-based distributed data center, and obtain user access request data; A zero-trust security assessment module, configured to perform dynamic security assessment on the access request of the data access user by using a zero-trust architecture based on the user access request data. If the access request meets the security policy of the zero-trust architecture, allow the data access user to access the decrypted data; An access control and log management module, configured to reject the access request and generate an access rejection log if the access request of the data access user does not meet the security policy of the zero-trust architecture.
9. A computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the cloud architecture distributed data processing method according to any one of claims 1 to 7.
10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the cloud architecture distributed data processing method according to any one of claims 1 to 7.
Citation Information
Cited By
Intrusion detection system based on big data analysis
CN120811756A
Internet of Things security control method and device, and medium
CN121077824A