Data security management and control method and device based on security threshold, equipment and medium
By obtaining the user security level and data characteristics to calculate the requested security value, the data leakage problem caused by theft of user names and passwords in the prior art is solved, and the security of data is achieved is precisely controlled and data security is improved.
Patent Information
- Application Number
- CN202510514589.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-23
- Publication Date
- 2025-07-25
AI Technical Summary
The existing data security control solution relies on username and password verification, which leads to the inability to prevent data leakage even if the password is stolen, and the security protection strength is insufficient.
By obtaining the target user security level of the data requester and the lower limit of the accessed security level of the data to be accessed, combining the access behavior characteristics of the data requester and the data characteristics of the data to be accessed, the requested security value is calculated and compared with the preset security threshold to decide whether to provide data.
It realizes that even if the user name and password are verified, the data will not be fed back, which improves the security of the data and avoids data leakage caused by the loss of user name and password.
Smart Images

Figure CN120378161A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data security, and in particular, to a data security control method, device, equipment, and medium based on a security threshold. Background Art
[0002] In recent years, data security has attracted more and more attention. Existing data security control solutions are implemented based on user identity authentication. That is, the user inputs a username and password, and the data security control device verifies the username and password and confirms the user's true identity. Then, the user can access the data. If the accessed data contains sensitive fields, the sensitive fields are desensitized.
[0003] However, in the existing solution, data security control is implemented based on the username and password. As long as the username and password are verified, the data can be accessed. If the username and password are stolen, although the sensitive data has been desensitized at this time, the data has been leaked.
[0004] It can be seen that the existing data security control effect is not good, and the security protection intensity is insufficient. Summary of the Invention
[0005] The present invention provides a data security control method, device, equipment, and medium based on a security threshold, to solve the risk of data leakage caused by the theft of the username and password in the prior art, and to achieve that even if the username and password pass the verification, no data will be fed back to the user, and further to accurately control the security of the currently to-be-accessed data according to the current access behavior of the requester.
[0006] The present invention provides a data security control method based on a security threshold, including the following steps.
[0007] Obtain the user information of the data requester; wherein, the user information includes the target user security level of the data requester; Determine the lower limit of the accessed security level of the to-be-accessed data that the data requester needs to access; If the target user security level is greater than or equal to the lower limit of the accessed security level, determine the request security value of the data requester according to the access behavior characteristics of the data requester and the data characteristics of the to-be-accessed data; Determine whether to provide the to-be-accessed data to the data requester according to the magnitude relationship between the request security value of the data requester and the preset security threshold.
[0008] A data security control method based on a security threshold provided by the present invention, wherein the access behavior characteristics of the data requester include registration duration, number of data requests, and request time sequence; the data characteristics of the data to be accessed include the proportion of sensitive data contained in the data to be accessed; if the security level of the target user is greater than or equal to the lower limit of the accessed security level, then determining the request security value of the data requester according to the access behavior characteristics of the data requester and the data characteristics of the data to be accessed includes: If the security level of the target user is greater than or equal to the lower limit of the accessed security level, calculate the average registration duration of all users in the first user set; wherein, the first user set is screened from all users based on the registration duration of the data requester and the security level of the target user; Calculate the time difference between two adjacent accesses in the request time sequence to form a time difference sequence, and calculate the standard deviation of the time difference sequence; According to the number of data requests, calculate the access frequency of the data requester after the current login; Obtain the proportion of sensitive data contained in the data to be accessed; Calculate the request security value of the data requester according to the average registration duration, the standard deviation, the proportion of sensitive data, and the access frequency.
[0009] A data security control method based on a security threshold provided by the present invention, if the security level of the target user is greater than or equal to the lower limit of the accessed security level, then if the security level of the target user is greater than or equal to the lower limit of the accessed security level, determining the average registration duration of the first user set including the data requester based on the registration duration of the data requester includes: If the security level of the target user is greater than or equal to the lower limit of the accessed security level, obtain all users with a registration duration within a preset interval range as the reference user set; wherein, the preset interval range is an interval range centered on the registration duration of the data requester; Divide the users in the reference user set into multiple user groups according to the user security level, and the users in each user group have the same user security level; Determine the first user security level corresponding to the user group with the largest number of users from the multiple user groups; Screen users with the same first user security level from all users as the first user set; Calculate the average registration duration of all users in the first user set.
[0010] A data security control method based on a security threshold provided by the present invention, which determines whether to provide the data to be accessed to the data requester according to the magnitude relationship between the request security value of the data requester and the preset security threshold, includes: If the request security value is greater than the preset security threshold, the data to be accessed is provided to the data requester.
[0011] A data security control method based on a security threshold provided by the present invention, the method further includes: If the request security value is less than or equal to the preset security threshold, a confirmation request is sent to the management end, so that the management end returns a response message in response to the confirmation request; If the response message contains a confirmation success message, the data to be accessed is provided to the data requester.
[0012] A data security control method based on a security threshold provided by the present invention, after determining the lower limit of the accessed security level of the data to be accessed that the data requester needs to access, includes: If the target user security level is less than the lower limit of the accessed security level, the access is terminated.
[0013] The present invention also provides a data security control device based on a security threshold, including the following modules.
[0014] A user information acquisition module, configured to acquire user information of a data requester; wherein, the user information includes the target user security level of the data requester; A lower limit determination module of the accessed security level, configured to determine the lower limit of the accessed security level of the data to be accessed that the data requester needs to access; A request security value calculation module, configured to, if the target user security level is greater than or equal to the lower limit of the accessed security level, determine the request security value of the data requester according to the access behavior characteristics of the data requester and the data characteristics of the data to be accessed; A data to be accessed providing module, configured to determine whether to provide the data to be accessed to the data requester according to the magnitude relationship between the request security value of the data requester and the preset security threshold.
[0015] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, and when the processor executes the computer program, it implements the data security control method based on a security threshold as described in any one of the above.
[0016] The present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the data security control method based on a security threshold as described in any one of the above.
[0017] The present invention also provides a computer program product, including a computer program. When the computer program is executed by a processor, it implements the data security control method based on a security threshold as described in any one of the above.
[0018] The data security control method, device, equipment and medium based on a security threshold provided by the present invention obtain the target user security level of a data requester; determine the lower limit of the accessed security level of the data to be accessed; if the target user security level is above the lower limit of the accessed security level, then evaluate the request security value of the data requester according to the access behavior characteristics of the data requester and the data characteristics of the data to be accessed; and determine whether to provide the data to be accessed to the data requester according to the magnitude relationship between the request security value and a preset security threshold. This method is particularly applicable to the situation where after a user logs in to the system, for example, after the user logs in to the system using a username and password, it is still uncertain whether the user has the right to request data. Instead, the user security level of the user and the lower limit of the accessed security level of the data are set. After the target user security level is greater than or equal to the lower limit of the accessed security level, the user is still not allowed to access the data. Instead, the request security value of the user for this request is comprehensively evaluated according to the access behavior characteristics of the data requester and the data characteristics of the data to be accessed. Only when the request security value meets the requirements is it considered that the user has the right to request the data, and the desensitized data is fed back to the user. If the security value does not meet the requirements, even if the username and password pass the verification, the data will not be fed back to the user, realizing the precise security control of the currently requested data according to the current access behavior of the requester, improving the security of the data, and avoiding the problem of data leakage caused by the loss of the username and password. Description of the Drawings
[0019] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0020] Figure 1 It is a flowchart showing the data security control method based on a security threshold provided by the present invention.
[0021] Figure 2 It is a flowchart showing the calculation process of the request security value of a data requester provided by the present invention.
[0022] Figure 3It is a schematic diagram of the overall process of the data security control method based on security thresholds provided by the present invention.
[0023] Figure 4 It is a schematic structural diagram of the data security control device based on security thresholds provided by the present invention.
[0024] Figure 5 It is a schematic structural diagram of the electronic device provided by the present invention. Specific Embodiments
[0025] To make the objectives, technical solutions and advantages of the present invention clearer, the technical solutions in the present invention will be clearly and completely described below with reference to the accompanying drawings in the present invention. Apparently, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art without making creative efforts based on the embodiments in the present invention belong to the scope of protection of the present invention.
[0026] The following combines Figures 1-5 to describe the specific embodiments of the present invention.
[0027] The execution subject of the data security control method based on security thresholds proposed in this application is a data security control device, which may or may not store the data to be accessed. For example, the data security control device may be a data center server, and the data to be accessed is stored distributively. At this time, the data security control device does not store specific data, but it is the central node and scheduling center for all data transmissions.
[0028] Figure 1 It is a schematic flow diagram of the data security control method based on security thresholds provided by the present invention. As Figure 1 shown, the method includes the following steps.
[0029] Step 101, obtain the user information of the data requester; wherein, the user information includes the target user security level of the data requester .
[0030] Among them, the target user security level refers to the security level set for the data requester in advance, representing the data range that it can access. That is to say, it can access data lower than the target user security level. When a user registers, relevant security personnel create the information storage space corresponding to the user on the information maintenance device, configure the user security level of the user in this space, and record the time at this time as the registration initial time. Subsequently, if the user's security level changes due to factors such as job adjustment, relevant personnel will modify the corresponding user security level in the storage space.
[0031] Specifically, this step can be obtained based on the login information entered by the data requester. For example, when the data requester logs in, the username and password are entered. After successful verification, the user information is retrieved using the username. The user information includes the target user security level of the data requester. 。
[0032] Optionally, the user information is maintained by a unified information maintenance device, which is a separate device independent of the data storage device and the user device.
[0033] Step 102: Determine the lower limit of the accessed security level of the data to be accessed by the data requester. 。
[0034] Among them, the lower limit of the accessed security level of the data to be accessed , is configured by the producer during the data generation process, and this value indicates the lowest user security level that can access this data.
[0035] Specifically, when the data requester sends a data request message to the data transmission device (such as entering an SQL statement), by parsing this message, the data that the data requester wants to access can be obtained, and then the pre-configured lower limit of the accessed security level of this data can be acquired. 。
[0036] Step 103: If the target user security level is greater than or equal to the lower limit of the accessed security level , then determine the request security value SS of the data requester according to the access behavior characteristics of the data requester and the data characteristics of the data to be accessed.
[0037] Among them, the access behavior characteristics of the data requester refer to the behavior characteristics of the data requester after this login, such as the number of requests, request frequency, etc.; the data characteristics of the data to be accessed, such as the proportion of sensitive data contained in the data to be accessed and other characteristics.
[0038] Specifically, if , it is determined that the data requester has the permission to access this data. However, whether the data request can be finally completed still needs to be determined according to the current situation of the user and the situation of the data to be requested, that is, it is necessary to calculate the request security value SS of the data requester according to the access behavior characteristics of the data requester and the data characteristics of the data to be accessed (such as the proportion of sensitive data). The specific calculation process is described in detail later.
[0039] Step 104: Determine whether to provide the data to be accessed to the data requester according to the size relationship between the request security value of the data requester and the preset security threshold.
[0040] Step 104 specifically includes: if the requested security value is greater than a preset security threshold, provide the data to be accessed to the target user; if the requested security value is less than or equal to the preset security threshold, abort the current access; and perform secondary verification.
[0041] Among them, the preset security threshold can be flexibly set according to actual needs.
[0042] Specifically, if the requested security value SS of the data requester is greater than the preset security threshold, it indicates that this request is secure. Then, obtain the data to be accessed, desensitize the data in the data to be accessed, and feedback it to the data requester.
[0043] If the requested security value SS of the data requester is not greater than the preset security threshold, it indicates that this request is not secure. Abort this data request, perform secondary verification on the data requester to ensure the security of the current request behavior, then obtain the data to be accessed again, desensitize the data in the data to be accessed, and feedback it to the data requester. If the secondary verification still considers there to be risks, then terminate this data request behavior, complete the data security control process, and feedback relevant prompts.
[0044] In another embodiment, the process of the above secondary verification can be: if the requested security value is less than or equal to the preset security threshold, send a confirmation request to the management end, so that the management end returns a response message in response to the confirmation request; if the response message contains a confirmation success message, provide the data to be accessed to the data requester.
[0045] Specifically, send a confirmation request to the manager of the data requester (pre-set and determined according to the user's department and position during user registration), and consider the secondary verification to be passed after obtaining the confirmation.
[0046] In the above embodiments, the target user security level of the data requester is obtained; the lower limit of the accessed security level of the data to be accessed is determined; if the target user security level is above the lower limit of the accessed security level, the request security value of the data requester is evaluated according to the access behavior characteristics of the data requester and the data characteristics of the data to be accessed; according to the magnitude relationship between the request security value and the preset security threshold, it is determined whether to provide the data to be accessed to the data requester. This method is particularly applicable after the user logs in to the system. For example, after the user logs in to the system using the username and password, it is still uncertain whether the user has the right to request data. Instead, the user security level of the user and the lower limit of the accessed security level of the data are set. After the target user security level is greater than or equal to the lower limit of the accessed security level, the user is still not allowed to access the data. Instead, the request security value of the user for this request is comprehensively evaluated according to the access behavior characteristics of the data requester and the data characteristics of the data to be accessed. Only when the request security value meets the requirements is it considered that the user has the right to request the data, and the desensitized data is fed back to the user. If the security value does not meet the requirements, even if the username and password pass the verification, the data will not be fed back to the user, realizing the precise security control of the currently requested data according to the current access behavior of the requester, improving the security of the data, and avoiding the data leakage problem caused by the loss of the username and password.
[0047] In one embodiment, the access behavior characteristics of the above data requester include the registration duration , the number of data requests and the request time sequence . The data characteristics of the above data to be accessed include the proportion of sensitive data contained in the data to be accessed.
[0048] It should be noted that the access behavior characteristics of the above data requester can be obtained based on the login information input by the user when logging in. For example, after obtaining the username of the user, the registration duration of the user can be known ; the number of data requests after this login is recorded by the data security control device. After the user logs in, the data security control device records the login time of the user and creates a temporary request count counter. The initial value of this counter is 0. Each time a data request is made, the counter is incremented by 1, and the request time is recorded. In this way, a request time sequence sorted in chronological order will be formed . The data characteristics of the data to be accessed refer to the numerical values used to describe the characteristics of the data. For example, it can include the proportion of sensitive data contained in the data to be accessed.
[0049] As Figure 2 shown, Figure 2 shows a schematic diagram of the calculation process of the request security value SS of the data requester. Step 103 above includes the following steps.
[0050] Step 201, if the security level of the target user is greater than or equal to the lower limit of the accessed security level , then calculate the average registration duration of the first user set ; wherein, the first user set is filtered from all users based on the registration duration of the data requester and the security level of the target user .
[0051] Optionally, this step 201 specifically includes: if the security level of the target user is greater than or equal to the lower limit of the accessed security level , then obtain all users whose registration duration is within the preset interval range as the reference user set; wherein, the preset interval range is an interval range centered on the registration duration of the data requester; divide the users in the reference user set into multiple user groups according to the user security level, and the users in each user group have the same user security level; from the above multiple user groups, determine the first user security level corresponding to the user group with the largest number of users , filter users with the same security level as the first user security level from all users as the first user set; calculate the average registration duration of all users in this first user set .
[0052] Specifically, when , perform the following steps.
[0053] (1), determine the preset interval range ; obtain all users whose registration duration is within as the reference user set, and obtain the user security level of each user in the reference user set. Wherein, is the registration duration of the data requester, is the preset time difference used to expand , because it is unlikely that the registration duration is exactly equal to , therefore, change into a range, and as long as the registration duration is within this range, it is used as a comparison object.
[0054] (2), among all users in the reference user set obtained in (1), divide them into multiple user groups according to the user security level, and the users in each user group have the same user security level; determine the number of users in each group, determine the user group with the largest number of users, and determine the first user security level corresponding to the user group with the largest number of users , and this security level represents this registration duration range The most likely user security level of the users within.
[0055] (3) Among all registered users, combine the users with a user security level of as the first user set, and calculate the mean value of the registration durations of all users in the first user set. This duration characterizes the average registration duration of users with the same security level.
[0056] Step 202, calculate the time difference between two adjacent accesses in the above request time sequence to form a time difference sequence, and calculate the standard deviation of the time difference sequence.
[0057] Specifically, calculate the difference between two adjacent moments in the request time sequence to form a time difference sequence . Among them, the last element is obtained by subtracting the last moment in the ST sequence from the current time. Calculate the standard deviation of each time difference in the time difference sequence. Each time difference in the time difference sequence indicates the time interval between two consecutive data requests. Since the data requests of normal users will be affected by factors such as different typing familiarity or the need to insert other things, etc., they show an irregular distribution. If the values of each time difference in the time difference sequence tend to be more similar, then the regularity is more serious, and the possibility of abnormal access is greater. The standard deviation characterizes this regularity. The smaller the standard deviation , the more serious the regularity and the more abnormal.
[0058] Step 203, calculate the access frequency of the data requester after this login according to the number of data requests .
[0059] Specifically, calculate the access frequency f after this login.
[0060] ; (1) Among them, is the moment of the last element in the request time sequence ST, that is, the moment of the last access, is the moment of the first element in the request time sequence ST. is the number of data requests of the data requester after this login.
[0061] Step 204, obtain the proportion SD of sensitive data contained in the above data to be accessed.
[0062] Among them, the sensitive data ratio SD can be the number of bytes of sensitive data / the total number of bytes of data to be accessed, or the number of occurrences of sensitive data / the total number of data occurrences included in the data to be accessed, etc. The larger it is, the more sensitive data is included in the data to be accessed, and the higher the requirement for the request security value. Therefore, the larger it is, the more it will reduce the request security value .
[0063] Step 205, calculate the request security value SS of the data requester according to the above average registration duration , the standard deviation , the sensitive data ratio SD and the access frequency f.
[0064] Specifically, the calculation formula is as follows.
[0065] (2) Among them, is the target user security level of the data requester, is the lower limit of the accessed security level of the data to be accessed, is the first user security level; is a very small constant value, SD is the proportion of sensitive data included in the data to be accessed, is the registration duration of the data requester, is the standard deviation of the time difference sequence, is the average registration duration of all users in the first user set, f is the access frequency of the data requester after this login, is the minimum value of the access frequency of normal users per unit time, which is an empirical value and can be set as a constant in advance, is the maximum value of the access frequency of normal users per unit time, which is an empirical value and can be set as a constant in advance.
[0066] indicates the degree to which the user's security level is higher than the minimum security level required by the data to be accessed. The larger the ratio, the higher the user level, and the greater the possibility of accessing low-level data. Then the request security value is larger.
[0067] indicates the degree to which the user's security level is higher than the most likely security level of this registration duration. The more deviated from 1 (that is, is larger), the more the current user security level deviates from the average and the more abnormal it is. Then the request security value is smaller. is a very small value, mainly to prevent the denominator from being 0.
[0068] Indicates the degree of the security level where the user's registration duration is higher than the average registration duration of this security level. The more deviated from 1 (i.e., the larger), the more the current user registration duration deviates from the average and the more abnormal it is. Then the requested security value is smaller.
[0069] is the minimum value of the access frequency of normal users per unit time, is the maximum value of the access frequency of normal users per unit time. The two values are pre-set values. For example, the pre-set range of the user's secure access frequency is .
[0070] In the above embodiments, according to the security level, registration duration, number of data requests after this login, request time of this login, and the situation of sensitive data included in the data to be accessed of the data requester, the security value of the user is comprehensively evaluated, providing another effective judgment basis for determining whether to allow the data requester to access the data in addition to the user name and password.
[0071] In one embodiment, after the above step 102, it includes: if the target user security level is less than the lower limit of the accessed security level, terminate the access.
[0072] Specifically, as Figure 3 shown, Figure 3 shows the overall process schematic diagram of the data security control method based on the security threshold. It can be seen from Figure 3 that if the above target user security level is less than the lower limit of the accessed security level , then terminate the continued access of this data requester.
[0073] In the above embodiments, after the user passes the verification of the user name and password, by comparing the relationship between the target user security level and the lower limit of the accessed security level of the data to be accessed, when the target user security level is less than the lower limit of the accessed security level , then terminate the continued access of this data requester, further ensuring the security of the data and improving the refined management level of users and data.
[0074] Next, the data security control device based on the security threshold provided by the present invention will be described. The data security control device based on the security threshold described below can be correspondingly referred to the data security control method described above.
[0075] AsFigure 4 As shown Figure 4 The figure shows a schematic structural diagram of a data security control device based on a security threshold. The device includes the following modules: A user information acquisition module 401, configured to acquire user information of a data requester; wherein, the user information includes a target user security level of the data requester; A lower limit determination module 402 for the accessed security level, configured to determine a lower limit of the accessed security level of the data to be accessed that the data requester needs to access; A request security value calculation module 403, configured to, if the target user security level is greater than or equal to the lower limit of the accessed security level, determine a request security value of the data requester according to an access behavior feature of the data requester and a data feature of the data to be accessed; A data to be accessed providing module 404, configured to determine whether to provide the data to be accessed to the data requester according to a magnitude relationship between the request security value of the data requester and a preset security threshold.
[0076] In an embodiment, the access behavior feature of the data requester includes a registration duration, a data request count, and a request time sequence; the data feature of the data to be accessed includes a proportion of sensitive data included in the data to be accessed; the above request security value calculation module 403 is further configured to: If the target user security level is greater than or equal to the lower limit of the accessed security level, calculate an average registration duration of all users in a first user set; wherein, the first user set is filtered from all users based on the registration duration of the data requester and the target user security level; Calculate a time difference between two adjacent accesses in the request time sequence to form a time difference sequence, and calculate a standard deviation of the time difference sequence; Calculate an access frequency of the data requester after the current login according to the data request count; Obtain a proportion of sensitive data included in the data to be accessed; Calculate the request security value of the data requester according to the average registration duration, the standard deviation, the proportion of sensitive data SD, and the access frequency.
[0077] In an embodiment, the above request security value calculation module 403 is further configured to: If the target user security level is greater than or equal to the lower limit of the accessed security level, obtain all users whose registration duration is within a preset interval range as a reference user set; wherein, the preset interval range is an interval range centered on the registration duration of the data requester; The users in the reference user set are divided into multiple user groups according to the user security level, and the users in each user group have the same user security level; From the multiple user groups, determine the first user security level corresponding to the user group with the largest number of users; Among all the users, screen out the users with the same security level as the first user security level as the first user set; Calculate the average registration duration of all users in the first user set.
[0078] In one embodiment, the above-mentioned to-be-accessed data providing module 404 is further configured to: If the requested security value is greater than the preset security threshold, provide the to-be-accessed data to the data requester.
[0079] In one embodiment, the above-mentioned to-be-accessed data providing module 404 is further configured to: If the requested security value is less than or equal to the preset security threshold, send a confirmation request to the management end so that the management end returns a response message in response to the confirmation request; If the response message contains a confirmation success message, provide the to-be-accessed data to the data requester.
[0080] In one embodiment, the above-mentioned accessed security level lower limit determining module 402 is further configured to: If the target user security level is less than the accessed security level lower limit, terminate the access.
[0081] Figure 5 An example of the physical structure diagram of an electronic device is shown in Figure 5 As shown, the electronic device may include: a processor 510, a communication interface 520, a memory 530, and a communication bus 540. Among them, the processor 510, the communication interface 520, and the memory 530 communicate with each other through the communication bus 540. The processor 510 may call the logical instructions in the memory 530 to execute a data security control method based on a security threshold. The method includes: obtaining user information of a data requester; where the user information includes the target user security level of the data requester; determining the lower limit of the accessed security level of the to-be-accessed data that the data requester needs to access; if the target user security level is greater than or equal to the lower limit of the accessed security level, determining the requested security value of the data requester according to the access behavior characteristics of the data requester and the data characteristics of the to-be-accessed data; determining whether to provide the to-be-accessed data to the data requester according to the size relationship between the requested security value of the data requester and the preset security threshold.
[0082] In addition, when the logical instructions in the above-mentioned memory 530 can be implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.
[0083] On the other hand, the present invention also provides a computer program product. The computer program product includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the data security control method based on a security threshold provided by the above-mentioned various methods. The method includes: obtaining user information of a data requester; wherein the user information includes the target user security level of the data requester; determining the lower limit of the accessed security level of the data to be accessed that the data requester needs to access; if the target user security level is greater than or equal to the lower limit of the accessed security level, then determining the request security value of the data requester according to the access behavior characteristics of the data requester and the data characteristics of the data to be accessed; and determining whether to provide the data to be accessed to the data requester according to the magnitude relationship between the request security value of the data requester and a preset security threshold.
[0084] On another aspect, the present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the data security control method based on a security threshold provided by the above-mentioned various methods. The method includes: obtaining user information of a data requester; wherein the user information includes the target user security level of the data requester; determining the lower limit of the accessed security level of the data to be accessed that the data requester needs to access; if the target user security level is greater than or equal to the lower limit of the accessed security level, then determining the request security value of the data requester according to the access behavior characteristics of the data requester and the data characteristics of the data to be accessed; and determining whether to provide the data to be accessed to the data requester according to the magnitude relationship between the request security value of the data requester and a preset security threshold.
[0085] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative efforts.
[0086] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0087] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A data security control method based on a security threshold, characterized in that, Including: Obtain the user information of the data requester; wherein, the user information includes the target user security level of the data requester; Determine the lower limit of the accessed security level of the data to be accessed that the data requester needs to access; If the target user security level is greater than or equal to the lower limit of the accessed security level, determine the request security value of the data requester according to the access behavior characteristics of the data requester and the data characteristics of the data to be accessed; Determine whether to provide the data to be accessed to the data requester according to the size relationship between the request security value of the data requester and the preset security threshold.
2. The data security control method based on a security threshold according to claim 1, wherein The access behavior characteristics of the data requester include registration duration, number of data requests, and request time sequence; the data characteristics of the data to be accessed include the proportion of sensitive data contained in the data to be accessed; the step of if the target user security level is greater than or equal to the lower limit of the accessed security level, then determine the request security value of the data requester according to the access behavior characteristics of the data requester and the data characteristics of the data to be accessed, includes: If the target user security level is greater than or equal to the lower limit of the accessed security level, calculate the average registration duration of all users in the first user set; wherein, the first user set is screened from all users based on the registration duration of the data requester and the target user security level; Calculate the time difference between two adjacent accesses in the request time sequence to form a time difference sequence, and calculate the standard deviation of the time difference sequence; According to the number of data requests, calculate the access frequency of the data requester after this login; Obtain the proportion of sensitive data contained in the data to be accessed; Calculate the request security value of the data requester according to the average registration duration, the standard deviation, the proportion of sensitive data, and the access frequency.
3. The data security control method based on a security threshold according to claim 1, characterized in that The step of if the target user security level is greater than or equal to the lower limit of the accessed security level, then determine the average registration duration of the first user set including the data requester based on the registration duration of the data requester, includes: If the target user security level is greater than or equal to the lower limit of the accessed security level, obtain all users with registration duration within a preset interval range as the reference user set; wherein, the preset interval range is an interval range with the registration duration of the data requester as the midpoint; Divide the users in the reference user set into multiple user groups according to the user security level, and the users in each user group have the same user security level; Determine the first user security level corresponding to the user group with the largest number of users from the multiple user groups; Screen users with the same first user security level from all users as the first user set; Calculate the average registration duration of all users in the first user set.
4. The data security control method based on a security threshold according to claim 1, wherein The step of determining whether to provide the data to be accessed to the data requester according to the size relationship between the request security value of the data requester and the preset security threshold, includes: If the requested security value is greater than a preset security threshold, provide the data to be accessed to the data requester.
5. The data security control method based on a security threshold according to claim 4, wherein The method further includes: If the requested security value is less than or equal to the preset security threshold, send a confirmation request to the management terminal so that the management terminal returns response information in response to the confirmation request; If the response information contains confirmation success information, provide the data to be accessed to the data requester.
6. The data security control method based on a security threshold according to any one of claims 1 to 5, characterized in that After determining the lower limit of the accessed security level of the data to be accessed that the data requester needs to access, it includes: If the target user security level is less than the lower limit of the accessed security level, terminate the access.
7. A data security control device based on a security threshold, characterized in that, It includes: A user information acquisition module, configured to acquire user information of the data requester; wherein, the user information includes the target user security level of the data requester; A lower limit determination module for the accessed security level, configured to determine the lower limit of the accessed security level of the data to be accessed that the data requester needs to access; A requested security value calculation module, configured to, if the target user security level is greater than or equal to the lower limit of the accessed security level, determine the requested security value of the data requester according to the access behavior characteristics of the data requester and the data characteristics of the data to be accessed; A module for providing data to be accessed, configured to determine whether to provide the data to be accessed to the data requester according to the size relationship between the requested security value of the data requester and a preset security threshold.
8. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and running on the processor, characterized in that, When the processor executes the computer program, it implements the data security control method based on a security threshold according to any one of claims 1 to 6.
9. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the data security control method based on a security threshold according to any one of claims 1 to 6.
10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the data security control method based on a security threshold according to any one of claims 1 to 6.