Encrypted database storage and access control system
Patent Information
- Application Number
- CN202510457107.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-13
- Publication Date
- 2025-08-01
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
而在现有技术中,用户只能对整个数据表进行访问,由于物理表的粒度比较大,因此无法对数据访问进行精细化控制,数据泄露风险较大,无法实现最大化的数据共享,但访问控制太过精细复杂,精细化的访问控制策略需要定义大量的规则和权限,复杂的策略容易引发配置错误,如权限冲突、冗余规则等
[0035]The present invention provides an encrypted database storage and access control system, which has the following beneficial effects:
Smart Images

Figure CN120408659A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data storage and access, and particularly to an encrypted database storage and access control system. Background Art
[0002] Access control is an important part of information security, which involves the management of user permissions to access resources. With the continuous progress of technology and the change of application scenarios, access control systems also face some challenges and problems. Traditional access control policies are often static, difficult to adapt to the dynamic security requirements, lacking the ability to adjust permissions and policies in real time, which may lead to security vulnerabilities. And overly strict access control may affect the user experience, while overly loose control may sacrifice security. Finding a balance between facilitating user access and protecting sensitive data is a challenge, resulting in that access control systems may not be able to effectively respond to emerging security threats and technologies, such as the Internet of Things, cloud computing, etc.
[0003] In the Chinese invention application with the application publication number CN119720157A, a data access control method, device, equipment, medium and program product are disclosed, including requesting to obtain the field-level data access permissions of a user; wherein, the data access permissions include: one or more target data tables that the user has permission to access and one or more target fields in each target data table; controlling the user to access each target field in each target data table according to the field-level data access permissions.
[0004] In the above invention application, the user's data access permissions are at the field level granularity, so the user can only access a part of the fields in a certain data table. In the prior art, the user can only access the entire data table. Since the granularity of the physical table is relatively large, fine-grained control of data access cannot be achieved, and the risk of data leakage is relatively high. Maximized data sharing cannot be realized, but the access control is too fine and complex. Fine-grained access control policies require defining a large number of rules and permissions, and complex policies are prone to configuration errors, such as permission conflicts, redundant rules, etc.
[0005] Therefore, the present invention provides an encrypted database storage and access control system. Summary of the Invention
[0006] (1) Technical Problems to be Solved
[0007] Aiming at the deficiencies of the prior art, the present invention provides an encrypted database storage and access control system, which calculates the comprehensive user access risk index Df based on the user's first access risk coefficient Df i and the user's second access risk coefficient Ef i i , issue a real-time warning for adjusting the user's access permission outward. The system can respond to risk changes faster, limit the user's access permission in a timely manner, thereby improving the security of the system, and thus solving the technical problems recorded in the background art.
[0008] (II) Technical Solution
[0009] To achieve the above objectives, the present invention is realized through the following technical solutions: An encrypted database storage and access control system, including:
[0010] A data encryption module, including a sensitive data recognition unit and a dynamic encryption unit, is used to identify the field-sensitive data tags of the data, generate field-level encryption keys to encrypt the sensitive fields, and then encrypt all the data except the primary key plaintext as a whole to generate ciphertext for storage;
[0011] An access request analysis module, including a permission recognition unit, a first risk analysis unit, and a second risk analysis unit, is used to verify the user's login. When the user's login verification is passed, calculate the user's first access risk coefficient Df i and the user's second access risk coefficient Ef i ;
[0012] An access display module, including a comprehensive access risk analysis unit, a dynamic permission adjustment unit, and an access display unit, calculates the user's comprehensive access risk index Df based on the user's first access risk coefficient Df i and the user's second access risk coefficient Ef i calculate the user's comprehensive access risk index Df i , issue a real-time warning for adjusting the user's access permission outward. After the real-time access permission is adjusted, filter and display the user's access request data according to the user's real-time access permission.
[0013] Furthermore, the sensitive data recognition unit automatically marks sensitive fields (such as ID numbers, bank card numbers, etc.) through a machine learning model to generate field-sensitive data tags.
[0014] Collect text data containing sensitive fields, clean and preprocess it, annotate the collected data, mark the positions and types of sensitive fields, select a suitable machine learning model according to the task requirements, such as a named entity recognition (NER) model, train the model with the annotated training data, and use the trained model to predict new text data, mark the positions and sensitive levels of sensitive fields, and output field-sensitive data tags.
[0015] The dynamic encryption unit selects an encryption algorithm according to the field-sensitive data label, generates a field-level encryption key (combined with the key derivation tree KDF), encrypts the sensitive fields, and then encrypts all data except the primary key plaintext (such as BLOB type data like files, pictures, videos, etc.) as a whole to generate ciphertext for storage.
[0016] Further, the user is verified for login through fingerprint, face recognition, SMS or password, and the user's login verification method, login verification time and login verification result are recorded. After sorting, the login verification method Dy for each user login is obtained. i 、The login verification result Dg i and the interval duration Sc since the last login verification i ;
[0017] Among them, if the login is through face recognition in the login verification method, then Dy i is recorded as 1. If the login is through fingerprint, then Dy i is recorded as 2. If the login is through SMS, then Dy i is recorded as 3. If the login is through password, then Dy i is recorded as 4.
[0018] The login verification is passed, and the login verification result Dg i is recorded as 0. The login verification fails, and the login verification result Dg i is recorded as 1.
[0019] Further, obtain the login verification method Dy for each user login i 、The login verification result Dg i and the interval duration Sc since the last login verification i , and calculate the user login risk coefficient Fx i :
[0020]
[0021] Among them, i represents the sequential number of the login time for each user login, i = 1, 2,..., n, where n is the total number of user logins, and ΔSc i represents the standard interval duration for login verification.
[0022] Further, after the user's login verification is passed, obtain the user login risk coefficient Fx i Calculate the user's first access risk coefficient Df i :
[0023]
[0024] Further, after the user's login verification is passed, obtain the user's corresponding permission level and access request. After sorting, obtain the user permission level Qd and the sensitivity level Mg of each sensitive field in the access request.j , calculate the user's second access risk coefficient Ef j :
[0025]
[0026] Among them, j represents the sequential number of each sensitive field in the user access request, j = 1, 2,..., m, and m is the total number of sensitive fields in the user access request.
[0027] Furthermore, the user permission level and the sensitivity level of sensitive fields are, from high to low, the first-level sensitivity level, the second-level sensitivity level, and the third-level sensitivity level. The first-level sensitivity level is denoted as 3, the second-level sensitivity level is denoted as 2, and the third-level sensitivity level is denoted as 1.
[0028] Furthermore, obtain the first access risk coefficient Df of the user's most recent time n and the user's second access risk coefficient Ef m Calculate the user's real-time access comprehensive risk index Zhf:
[0029]
[0030] Among them, ΔDf i represents the standard value of the first access risk coefficient, and ΔEf i represents the standard value of the second access risk coefficient.
[0031] Furthermore, when the user's real-time access comprehensive risk index Zhf exceeds , it indicates that the user's real-time access risk is high, and a warning for adjusting the user's real-time access permission is sent outwards. Among them, represents the mean value of all users' real-time access comprehensive risk indexes, and σZhf represents the variance of all users' real-time access comprehensive risk indexes.
[0032] Furthermore, after receiving the warning for adjusting the user's real-time access permission, take the next level of the original user permission level as the user's real-time access permission. If the original user permission level is already the lowest permission level, prohibit the user from accessing until the risk control is lifted.
[0033] Furthermore, dynamic data masking is a way to process data before data display. According to the user's access permission, sensitive data is masked, such as hiding some fields or replacing them with asterisks; front-end filtering is data filtering performed at the user interface layer. According to the user's permission and access request, data is dynamically displayed or hidden; API gateway control is data filtering performed at the API layer. According to the user's permission and access request, different data sets are dynamically returned.
[0034] (III) Beneficial effects
[0035] The present invention provides an encrypted database storage and access control system, which has the following beneficial effects:
[0036] 1. Identify sensitive data labels for data fields, generate field-level encryption keys to encrypt sensitive fields, and then encrypt all data except the primary key plaintext as a whole to generate ciphertext storage. This can simplify the query process and improve data query efficiency. Indexing and querying can be performed without decrypting the primary key or hashing it.
[0037] 2. When the user login verification is passed, obtain the login verification method Dy for each login of the user i , Login verification result Dg i and the interval from the last login verification Sc i , calculate the user login risk factor Fx i , and further calculate the user's first access risk coefficient Df i By quantifying login risks and upgrading traditional rule-based verification to dynamic login risk assessment, more accurate security decisions can be made and the overall security of the system can be improved.
[0038] 3. When the user login verification is passed, the corresponding permission level and access request of the user are obtained, and the user permission level Qd and the sensitivity level Mg of each sensitive field in the access request are obtained after sorting. j , calculate the user's second access risk coefficient Ef j , which can achieve dynamic and fine-grained security protection.
[0039] 4. Based on the user's first access risk factor Df i and the user's second access risk factor Ef i Calculate the user access comprehensive risk index Df i , and issue real-time user access rights adjustment warnings. The system can respond to risk changes more quickly and promptly limit or expand user access rights, thereby improving system security. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] Figure 1 The diagram is a structural diagram of an encrypted database storage and access control system of the present invention. DETAILED DESCRIPTION
[0041] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0042] See alsoFigure 1 The present invention provides an encrypted database storage and access control system, comprising:
[0043] The data encryption module includes a sensitive data identification unit and a dynamic encryption unit, which are used to identify field sensitive data labels of data, generate field-level encryption keys to encrypt sensitive fields, and then encrypt all data except the primary key plaintext as a whole to generate ciphertext storage.
[0044] The sensitive data identification unit automatically marks sensitive fields (such as ID card number, bank card number, etc.) through machine learning models and generates field sensitive data labels.
[0045] Collect text data containing sensitive fields, clean and preprocess it, annotate the collected data, mark the location and type of sensitive fields, select an appropriate machine learning model based on task requirements, such as a named entity recognition (NER) model, train the model using annotated training data, use the trained model to predict new text data, mark the location and sensitivity level of sensitive fields, and output field sensitive data labels.
[0046] The dynamic encryption unit selects an encryption algorithm based on the sensitive data label of the field, generates a field-level encryption key (combined with the key derivation tree KDF) to encrypt the sensitive field, and then encrypts all data except the primary key plaintext (such as BLOB type data such as files, pictures, videos, etc.) as a whole to generate ciphertext storage.
[0047] After identifying sensitive data labels for data fields and generating field-level encryption keys to encrypt sensitive fields, all data except the primary key plaintext is encrypted as a whole and stored as ciphertext. This can simplify the query process and improve data query efficiency. Indexing and querying can be performed without decrypting or hashing the primary key.
[0048] The access request analysis module includes a permission identification unit, a first risk analysis unit, and a second risk analysis unit, which is used to perform login verification on the user. When the user login verification is passed, the user's first access risk coefficient Df is calculated. i and the user's second access risk factor Ef i .
[0049] The authority identification unit is used to perform login verification on the user and record the user's login verification method, login verification time and login verification result.
[0050] Verify the user's login through fingerprint, facial recognition, SMS or password, record the user's login verification method, login verification time and login verification result, and obtain the login verification method Dy for each login of the user after sorting. i , Login verification result Dgi And the interval duration Sc since the last login verification i .
[0051] Among them, if face recognition login is used in the login verification method, then Dy i is recorded as 1, if fingerprint login is used, then Dy i is recorded as 2, if SMS login is used, then Dy i is recorded as 3, if password login is used, then Dy i is recorded as 4.
[0052] The login verification result Dg for successful login verification i is recorded as 0, and the login verification result Dg for failed login verification i is recorded as 1.
[0053] The first risk analysis unit, after the user's login verification is successful, obtains the login verification method Dy for each user login i , the login verification result Dg i and the interval duration Sc since the last login verification i , calculates the user login risk coefficient Fx i , and further calculates the user's first access risk coefficient Df i .
[0054] Obtains the login verification method Dy for each user login i , the login verification result Dg i and the interval duration Sc since the last login verification i , calculates the user login risk coefficient Fx i :
[0055]
[0056] Among them, i represents the sequential number of the login time for each user login, i = 1, 2,..., n, where n is the total number of user logins, and ΔSc i represents the standard interval duration for login verification.
[0057] After the user's login verification is successful, obtains the user login risk coefficient Fx i Calculates the user's first access risk coefficient Df i :
[0058]
[0059] After the user's login verification is successful, obtains the login verification method Dy for each user login i , the login verification result Dg i and the interval duration Sc since the last login verification i , calculates the user login risk coefficient Fx i, and further calculate the user's first access risk coefficient Df i , by quantifying the login risk and upgrading the traditional rule-based verification to dynamic login risk assessment, more accurate security decisions can be brought, and the overall security of the system can be improved.
[0060] The second risk analysis unit, after the user's login verification passes, obtains the user's corresponding permission level and access request, and after sorting, obtains the user's permission level Qd and the sensitivity level Mg of each sensitive field in the access request j , and calculate the user's second access risk coefficient Ef j .
[0061] After the user's login verification passes, obtain the user's corresponding permission level and access request, and after sorting, obtain the user's permission level Qd and the sensitivity level Mg of each sensitive field in the access request j , and calculate the user's second access risk coefficient Ef j :
[0062]
[0063] Among them, j represents the sequential number of each sensitive field in the user's access request, j = 1, 2,..., m, and m is the total number of sensitive fields in the user's access request.
[0064] The sensitivity levels of the user's permission level and sensitive fields from high to low are the first-level sensitivity level, the second-level sensitivity level, and the third-level sensitivity level. The first-level sensitivity level is recorded as 3, the second-level sensitivity level is recorded as 2, and the third-level sensitivity level is recorded as 1.
[0065] After the user's login verification passes, obtain the user's corresponding permission level and access request, and after sorting, obtain the user's permission level Qd and the sensitivity level Mg of each sensitive field in the access request j , and calculate the user's second access risk coefficient Ef j , which can achieve dynamic and fine-grained security protection.
[0066] The access display module, including the comprehensive access risk analysis unit, the dynamic permission adjustment unit, and the access display unit, calculates the user's comprehensive access risk index Df based on the user's first access risk coefficient Df i and the user's second access risk coefficient Ef i , sends out a warning for the user's real-time access permission adjustment, and after the real-time access permission is adjusted, filters and displays the user's access request data according to the user's real-time access permission. i
[0067] The comprehensive access risk analysis unit, based on the user's first access risk coefficient Df i and the user's second access risk coefficient Ef i Calculate the comprehensive risk index Df of user access i , and send out a warning for adjusting the real-time access permission of the user.
[0068] Obtain the first access risk coefficient Df of the user with the most recent time n and the second access risk coefficient Ef of the user m Calculate the real-time access comprehensive risk index Zhf of the user:
[0069]
[0070] where, ΔDf i represents the standard value of the first access risk coefficient, and ΔEfi 表 represents the standard value of the second access risk coefficient.
[0071] When the real-time access comprehensive risk index Zhf of the user exceeds , it indicates that the real-time access risk of the user is high, and a warning for adjusting the real-time access permission of the user is sent out. Among them, represents the mean value of the real-time access comprehensive risk index of all users, and σZhf represents the variance of the real-time access comprehensive risk index of all users.
[0072] According to the first access risk coefficient Df of the user i and the second access risk coefficient Ef of the user i Calculate the comprehensive risk index Df of user access i , and send out a warning for adjusting the real-time access permission of the user. The system can respond to risk changes faster, limit or expand the access permission of the user in a timely manner, thereby improving the security of the system.
[0073] The dynamic permission adjustment unit, after receiving the warning for adjusting the real-time access permission of the user, takes the next level of the original user permission level as the real-time access permission of the user.
[0074] Among them, if the original user permission level is already the lowest permission, the user is prohibited from accessing until the risk control is lifted.
[0075] The access display unit filters and displays the user access request data according to the real-time access permission of the user.
[0076] Dynamic data desensitization is a way to process data before data display. According to the access permission of the user, sensitive data is desensitized, such as hiding some fields or replacing them with asterisks; front-end filtering is data filtering performed at the user interface layer, and data is dynamically displayed or hidden according to the user's permission and access request; API gateway control is data filtering performed at the API layer, and different data sets are dynamically returned according to the user's permission and access request.
[0077] The present invention provides another specific embodiment:
[0078] After receiving the warning of real-time access permission adjustment for the user, if the original user permission level is 2, adjust the user's real-time access permission to 1, filter the sensitive fields in the user access request data with a sensitivity level higher than 1, and display the filtered data.
[0079] The above embodiments can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, the above embodiments can be implemented in whole or in part in the form of a computer program product. Those of ordinary skill in the art will realize that the units and algorithm steps of the examples described in conjunction with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in hardware or software depends on the specific application and design constraints of the technical solution.
[0080] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0081] As described above, the above are only specific embodiments of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of changes or substitutions, which should all be covered within the protection scope of the present application.
Claims
1. An encrypted database storage and access control system, characterized in that: Including: A data encryption module, including a sensitive data recognition unit and a dynamic encryption unit, is used to identify field-sensitive data tags of data, generate field-level encryption key pairs to encrypt sensitive fields, and then encrypt all data except the primary key plaintext as a whole to generate ciphertext for storage. An access request analysis module, including a permission identification unit, a first risk analysis unit, and a second risk analysis unit, is used to perform login verification on a user. After the user's login verification is passed, the first access risk coefficient Df of the user is calculated i and the second access risk coefficient Ef of the user i ; An access display module, including a comprehensive access risk analysis unit, a dynamic permission adjustment unit, and an access display unit, based on the user's first access risk coefficient Df i and the user's second access risk coefficient Ef i Calculate the user's comprehensive access risk index Df i , send out a warning for real-time adjustment of the user's access permission. After the real-time access permission is adjusted, filter and display the user's access request data according to the user's real-time access permission.
2. The encryption database storage and access control system according to claim 1, characterized in that: Verify the user's login through fingerprint, facial recognition, SMS or password, record the user's login verification method, login verification time and login verification result, and obtain the login verification method Dy for each user login after sorting i , the login verification result Dg i and the interval duration Sc since the last login verification i ; Among them, in the login verification method, if it is face recognition login, then Dy i is recorded as 1, if it is fingerprint login, then Dy i is recorded as 2, if it is SMS login, then Dy i is recorded as 3, if it is password login, then Dy i is recorded as 4; The login verification is passed, and the login verification result is Dg i It is recorded as 0 when the login verification fails, and the login verification result is Dg i It is recorded as 1 3. The encryption database storage and access control system according to claim 1, characterized in that: Obtain the login verification method Dy for each user login i , login verification result Dg i and the interval duration Sc since the last login verification i , and calculate the user login risk coefficient Fx i : Among them, i represents the sequential number of the login time for each user login, i = 1, 2, …, n, where n is the total number of user logins, and ΔSc i represents the standard interval duration for login verification.
4. The encryption database storage and access control system according to claim 1, characterized in that: After the user's login verification is passed, obtain the user's login risk coefficient Fx i Calculate the user's first access risk coefficient Df i :
5. The encryption database storage and access control system according to claim 1, characterized in that: After the user's login verification passes, obtain the user's corresponding permission level and access request. After sorting, obtain the user permission level Qd and the sensitivity level Mg of each sensitive field in the access request j , and calculate the user's second access risk coefficient Ef j : Wherein, j represents the sequence number of each sensitive field in the user access request, j = 1, 2,..., m, and m is the total number of sensitive fields in the user access request.
6. The encryption database storage and access control system according to claim 1, characterized in that: The user permission level and the sensitivity level of sensitive fields are, from high to low, a first-level sensitivity level, a second-level sensitivity level, and a third-level sensitivity level. The first-level sensitivity level is denoted as 3, the second-level sensitivity level is denoted as 2, and the third-level sensitivity level is denoted as 1.
7. The encryption database storage and access control system according to claim 1, characterized in that: Obtain the first access risk coefficient Df of the user's most recent time n and the second access risk coefficient Ef of the user m Calculate the user's real-time access comprehensive risk index Zhf: Among them, ΔDf i represents the standard value of the first access risk coefficient, and ΔEf i represents the standard value of the second access risk coefficient.
8. The encryption database storage and access control system according to claim 1, characterized in that: When the user's real-time access to the comprehensive risk index Zhf exceeds , it indicates that the user's real-time access risk is high, and a warning for adjusting the user's real-time access permission is sent out; among them, represents the mean value of the comprehensive risk index of all users' real-time access, and σZhf represents the variance of the comprehensive risk index of all users' real-time access.
9. The encryption database storage and access control system according to claim 1, characterized in that: After receiving the early warning of real-time user access permission adjustment, take the next level of the original user permission level as the real-time user access permission. If the original user permission level is already the lowest permission, prohibit the user from accessing until the risk control is lifted.
Citation Information
Patent Citations
Method and device for conducting risk assessment on login of user
CN107239680A
Risk control method, device and storage medium
CN108667828A
Project data authority management method and system
CN115982679A
Safety protection method and device for customer service management system
CN118611899A
Government affair file multi-dimensional factor safety management system
CN119004426A