Computer data security protection method and system
By building data content risk models, data value models and visitor risk models, and dynamically adjusting operating permissions, the problem of rigid permission control in existing technologies is solved, and the accuracy and security of computer data security protection are improved.
Patent Information
- Application Number
- CN202510920388.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-04
- Publication Date
- 2025-09-26
- Estimated Expiration
- 2045-07-04
AI Technical Summary
In existing computer data security protection technologies, permission control lacks real-time assessment of data dynamic risks and visitor behavior, resulting in rigid permission allocation, difficulty in identifying abnormal behavior, and the inability to adaptively adjust security policies, affecting business efficiency and security.
By building data content risk models, data value models, visitor risk models and data-access security matching models, the data security factor and visitor security factor can be quantified in real time, and operation permissions can be dynamically adjusted to achieve precise permission control.
It improves the accuracy and security of permission control, reduces the risk of data leakage and abuse, balances security and flexibility, and achieves dynamic quantitative matching of data risks and access behaviors.
Smart Images

Figure CN120408688B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of information security technology, and in particular relates to a computer data security protection method and system. Background Art
[0002] In traditional computer data security protection technologies, permission control is mostly based on static rules (such as roles or fixed policies), lacking real-time assessment of dynamic data risks and accessor behavior. Existing methods have the following problems:
[0003] (1) Ignoring the dynamic correlation between data content risk (such as key strength and access frequency) and data value (such as business dependency and recovery cost), resulting in overly rigid permission allocation;
[0004] (2) The determination of visitor permissions relies solely on historical records or a single indicator (such as identity authentication), making it difficult to identify abnormal behavior (such as unapproved access and cross-system unauthorized operations);
[0005] (3) Security policies cannot be adjusted adaptively, which can easily lead to excessive openness or excessive restrictions on permissions, affecting business efficiency and security.
[0006] Therefore, there is an urgent need for a dynamic and fine-grained security protection method that can achieve precise permission control by quantifying the matching degree between data risks and visitor behavior. Summary of the Invention
[0007] In view of the deficiencies in the prior art, the present invention provides a computer data security protection method and system to solve the above problems.
[0008] To achieve the above objectives, the present invention is implemented through the following technical solutions: A computer data security protection method, comprising:
[0009] Obtain content risk data and value data of stored data, obtain access rights scope data and risk data of visitors;
[0010] Build and import a data content risk assessment model based on the content risk data of the stored data, and then output the data content risk coefficient;
[0011] Build a data value model based on the value data of the saved data and import and then output the data value coefficient;
[0012] Build a data security model based on the data value coefficient and data content risk coefficient, import and then output the data security coefficient;
[0013] Build an access permission range model based on the visitor's access permission range data, import it, and then output the access permission range coefficient;
[0014] Build a visitor risk model based on the visitor's risk data and import and then output the visitor risk coefficient;
[0015] Construct visitor safety factor based on visitor authority range coefficient and visitor risk coefficient and import and then output visitor safety factor;
[0016] Build a data-access security matching model based on the visitor security factor and the data security factor, import it, and then output the data-access security matching degree;
[0017] The obtained data-access security matching degree is compared with the corresponding threshold, and the operation permission of the current visitor to the currently saved data is obtained.
[0018] On the basis of the above technical solutions, the present invention also provides the following optional technical solutions:
[0019] Further technical solutions: The content risk data of the saved data includes key length, data access frequency and saver authority ratio; the value data of the saved data includes recovery time target, business dependency and data sharing scope; the visitor authority scope data includes the number of accessible sensitivity levels, the number of cross-system permissions and the proportion of accessible data fields; the visitor risk data includes unapproved access rate, abnormal session ratio and number of policy violations.
[0020] Further technical solution: The specific steps of constructing a data content risk assessment model based on the content risk data of the stored data and importing it, and then outputting the data content risk coefficient are as follows:
[0021] Importing the key length into the formula Output key length index, To adjust the key sensitivity, is the key length;
[0022] Ratio the current data access frequency with the maximum access frequency allowed by the business to obtain the access frequency index;
[0023] The saver permission ratio is compared with the maximum allowed saver permission ratio to obtain the saver permission ratio index;
[0024] A data content risk model is constructed based on the key length index, access frequency index, and preserver authority ratio index, and the key length index, access frequency index, and preserver authority ratio index are imported to obtain the data content risk coefficient;
[0025] The data content risk model is expressed as:
[0026]
[0027] in, Indicates the data content risk factor, represents the key length exponent, represents the access frequency index, Indicates that the permission ratio index is saved. represents the weight coefficient and ,in, The value is 1, 2 or 3. The larger the value, the higher the risk of the data content.
[0028] Further technical solution: The steps for obtaining the data value coefficient are:
[0029] Ratio the recovery time objective, business dependency, and data sharing scope to their respective maximum allowable values to obtain the recovery time objective index, business dependency index, and data sharing scope index;
[0030] Import the obtained recovery time objective index, business dependency index, and data sharing scope index into the data value model to obtain the data value coefficient;
[0031] The data value model is expressed as:
[0032]
[0033] in, represents the data value coefficient, represents the recovery time objective index, represents the business dependency index, represents the data sharing scope index, represents the weight coefficient and ,in, The value is 1, 2 or 3. And the larger the value, the higher the data value.
[0034] Further technical solution: The data security model is expressed as:
[0035]
[0036] in, Indicates the data safety factor, Indicates the data content risk factor, represents the data value coefficient, And the larger the value, the higher the data value.
[0037] Further technical solution: The steps of constructing an access permission range model based on the visitor's access permission range data and importing and then outputting the access permission range coefficient are as follows:
[0038] Ratio the accessible sensitivity level number and the cross-system permission number to the corresponding maximum allowed value, and then obtain the accessible sensitivity level index and the cross-system permission number index;
[0039] Import the accessible sensitivity level index, cross-system permission quantity index, and accessible data field ratio into the constructed visitor permission range model to output the visitor permission range coefficient;
[0040] The visitor permission range model is expressed as:
[0041]
[0042] in, Indicates the visitor's authority range coefficient, Indicates the accessible sensitivity level index. Indicates the index of the number of cross-system permissions, Indicates the proportion of accessible data fields, represents the weight coefficient and ,in, The value is 1, 2 or 3. The larger the value, the wider the visitor's permissions and the higher the potential risk.
[0043] Further technical solution: The steps of constructing a visitor risk model based on the visitor's risk data and importing and then outputting the visitor risk coefficient are as follows:
[0044] The policy violation count is calculated by comparing the number of policy violations with the maximum allowed number of violations to obtain a policy violation count index.
[0045] Import the policy violation index, unapproved access rate, and abnormal session ratio into the constructed visitor risk model to output the visitor risk coefficient;
[0046] The visitor risk model is expressed as:
[0047]
[0048] in, represents the visitor risk factor, Indicates the unapproved access rate. Indicates the proportion of abnormal sessions. represents the number of policy violations index, represents the weight coefficient and ,in, The value is 1, 2 or 3. The larger the value, the higher the risk to the visitor.
[0049] Further technical solution: The visitor security model is expressed as:
[0050]
[0051] in, Indicates the visitor safety factor, represents the visitor risk factor, Indicates the visitor's authority range coefficient, Indicates the authority amplification factor.
[0052] Further technical solution: The data-access security matching model is expressed as:
[0053]
[0054] in, Indicates the data-access security matching degree, Indicates the data safety factor, Indicates the visitor safety factor, represents the asymmetry tolerance coefficient, The larger the value, the higher the match between the visitor security factor and the data security factor.
[0055] Further technical solution: The steps of comparing the acquired data-access security matching degree with the corresponding threshold and then obtaining the current visitor's operation authority for the currently saved data are as follows:
[0056] like , it means that the current visitor's security factor is highly consistent with the security factor of the saved data, allowing viewing, modification and export;
[0057] like , it means that the current visitor's security factor matches the security factor of the saved data moderately, and viewing and modification are allowed;
[0058] like , it means that the current visitor's security factor matches the security factor of the saved data and is allowed to view;
[0059] like , it means that the current visitor's security factor does not match the security factor of the saved data, access is denied and an alarm is triggered.
[0060] The present invention provides a computer data security protection method and system, which has the following advantages compared with the prior art:
[0061] 1. The present invention uses data content risk models, data value models and visitor risk models to quantify data security factors and visitor security factors in real time, thereby improving risk response capabilities. At the same time, based on the threshold rules of data-access security matching, it dynamically adjusts operating permissions, taking into account both security and flexibility. It also introduces data security models and visitor security models to suppress permission amplification in high-risk scenarios and reduce the risk of data leakage and abuse. The present invention achieves dynamic quantitative matching of data risks and access behaviors, significantly improving the accuracy and security of permission control. BRIEF DESCRIPTION OF THE DRAWINGS
[0062] Figure 1 It is a schematic diagram of the process of the present invention. DETAILED DESCRIPTION
[0063] In order to make the purpose, technical solutions and advantages of the present invention more clearly understood, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.
[0064] The specific implementation of the present invention is described in detail below with reference to specific embodiments.
[0065] See also Figure 1 , provided in one embodiment of the present invention, is a computer data security protection method, comprising the following steps:
[0066] Obtain content risk data and value data of stored data, obtain access rights scope data and risk data of visitors;
[0067] Build and import a data content risk assessment model based on the content risk data of the stored data, and then output the data content risk coefficient;
[0068] Build a data value model based on the value data of the saved data and import and then output the data value coefficient;
[0069] Build a data security model based on the data value coefficient and data content risk coefficient, import and then output the data security coefficient;
[0070] Build an access permission range model based on the visitor's access permission range data, import it, and then output the access permission range coefficient;
[0071] Build a visitor risk model based on the visitor's risk data and import and then output the visitor risk coefficient;
[0072] Construct visitor safety factor based on visitor authority range coefficient and visitor risk coefficient and import and then output visitor safety factor;
[0073] Build a data-access security matching model based on the visitor security factor and the data security factor, import it, and then output the data-access security matching degree;
[0074] The obtained data-access security matching degree is compared with the corresponding threshold, and the operation permission of the current visitor to the currently saved data is obtained.
[0075] This method acquires data content risk and value data, constructs data content risk models and data value models, and calculates the data security factor using a data security model. Simultaneously, it constructs a visitor security factor based on visitor permission range data and risk data. Finally, it dynamically matches security factors using a data-access security matching model and grants, modifies, or denies access rights based on the SM threshold. This method achieves dynamic, quantitative matching of data risks and access behaviors, significantly improving the accuracy and security of permission control.
[0076] Preferably, the content risk data of the stored data includes key length, data access frequency and saver authority ratio;
[0077] The value of the stored data includes recovery time objectives, business dependencies (the number of business processes based on the stored data, i.e., the number of core processes that would be halted due to data unavailability, such as supply chain, production, and customer service), and data sharing scope (the number of shared systems).
[0078] The visitor's permission scope data includes the number of accessible sensitivity levels, the number of cross-system permissions (the number of permissions to access different business systems, used to identify high-risk operation permissions, such as the proportion of deletion permissions), and the proportion of accessible data fields (the proportion of accessible data fields to the total number of fields);
[0079] The risk data of the visitor includes the unapproved access rate (the ratio of unapproved access times to total access times, used to evaluate the standardization of privileged permission management), the abnormal session ratio (the ratio of access times from uncommon devices or IP addresses to total access times, used to detect account theft or sharing risks), and the number of policy violations (the number of violations of access control policies, such as unauthorized access, used to measure the degree of match between permissions and actual behavior).
[0080] Preferably, the specific steps of constructing a data content risk assessment model based on the content risk data of the stored data and importing it, and then outputting the data content risk coefficient are:
[0081] Importing the key length into the formula Output key length index, To adjust the key sensitivity, is the key length;
[0082] Ratio the current data access frequency with the maximum access frequency allowed by the business to obtain the access frequency index;
[0083] The saver permission ratio is compared with the maximum allowed saver permission ratio to obtain the saver permission ratio index;
[0084] A data content risk model is constructed based on the key length index, access frequency index, and preserver authority ratio index, and the key length index, access frequency index, and preserver authority ratio index are imported to obtain the data content risk coefficient;
[0085] The data content risk model is expressed as:
[0086]
[0087] in, Indicates the data content risk factor, represents the key length exponent, represents the access frequency index, Indicates that the permission ratio index is saved. represents the weight coefficient and ,in, The value is 1, 2 or 3. The larger the value, the higher the risk of the data content.
[0088] The above technical solution is achieved by comprehensively analyzing the key security (key length index ), access frequency index, and the permission ratio index used to evaluate the risk of data content, namely the key length index The larger (longer the key), the lower the risk The greater the access frequency index and the percentage of stored permissions, the higher the risk. From the overall performance, the data content risk coefficient The larger the value, the higher the risk of the data content.
[0089] Preferably, the steps for obtaining the data value coefficient are:
[0090] Ratio the recovery time objective, business dependency, and data sharing scope to their respective maximum allowable values to obtain the recovery time objective index, business dependency index, and data sharing scope index;
[0091] Import the obtained recovery time objective index, business dependency index, and data sharing scope index into the data value model to obtain the data value coefficient;
[0092] The data value model is expressed as:
[0093]
[0094] in, represents the data value coefficient, represents the recovery time objective index, represents the business dependency index, represents the data sharing scope index, represents the weight coefficient and ,in, The value is 1, 2 or 3. And the larger the value, the higher the data value.
[0095] The above technical solution is based on the comprehensive recovery time objective index ( ), business dependence index ( ) and the Data Sharing Coverage Index ( ) to assess data value, namely the recovery time objective index ( ) and business dependency index ( ) is larger, the higher the value is, and the data sharing scope index ( ) is larger, the wider the sharing range, and the lower the value ( ) decreases, and from the overall performance point of view, the data value coefficient ( ) The larger it is, the higher the value.
[0096] Preferably, the data security model is expressed as:
[0097]
[0098] in, Indicates the data safety factor, Indicates the data content risk factor, represents the data value coefficient, And the larger the value, the higher the data value.
[0099] The above technical solution balances the risk factor of data content ( ) and data value coefficient ( ), measure the data security factor ( ), when the data content risk factor ( ) and data value coefficient ( ) are high, the denominator increases, suppressing the data safety factor ( ) excessive growth, from the overall performance point of view data safety factor ( ), the larger the data value, the higher the data security requirements.
[0100] Preferably, the steps of constructing an access permission range model based on the visitor's access permission range data and importing and then outputting the access permission range coefficient are:
[0101] Ratio the accessible sensitivity level number and the cross-system permission number to the corresponding maximum allowed value, and then obtain the accessible sensitivity level index and the cross-system permission number index;
[0102] Import the accessible sensitivity level index, cross-system permission quantity index, and accessible data field ratio into the constructed visitor permission range model to output the visitor permission range coefficient;
[0103] The visitor permission range model is expressed as:
[0104]
[0105] in, Indicates the visitor's authority range coefficient, Indicates the accessible sensitivity level index. Indicates the index of the number of cross-system permissions, Indicates the proportion of accessible data fields, represents the weight coefficient and ,in, The value is 1, 2 or 3. The larger the value, the wider the visitor's permissions and the higher the potential risk.
[0106] The above technical solution is based on the comprehensive accessibility sensitivity level index ( ), cross-system permission quantity index ( ) and the percentage of accessible fields ( ), evaluate the visitor's authority range, and look at the visitor's authority range coefficient from the overall performance ( ) value, the wider the visitor's permissions are and the higher the potential risk is.
[0107] Preferably, the steps of constructing a visitor risk model based on the visitor risk data and importing and then outputting the visitor risk coefficient are:
[0108] The policy violation count is calculated by comparing the number of policy violations with the maximum allowed number of violations to obtain a policy violation count index.
[0109] Import the policy violation index, unapproved access rate, and abnormal session ratio into the constructed visitor risk model to output the visitor risk coefficient;
[0110] The visitor risk model is expressed as:
[0111]
[0112] in, represents the visitor risk factor, Indicates the unapproved access rate. Indicates the proportion of abnormal sessions. represents the number of policy violations index, represents the weight coefficient and ,in, The value is 1, 2 or 3. The larger the value, the higher the risk to the visitor.
[0113] The above technical solution is based on the comprehensive unapproved access rate ( ), abnormal session ratio ( ) and the policy violation index ( ), assess the risk of visitors, and look at the visitor risk coefficient from the overall performance The larger the value, the riskier the visitor.
[0114] Preferably, the visitor security model is expressed as:
[0115]
[0116] in, Indicates the visitor safety factor, represents the visitor risk factor, Indicates the visitor's authority range coefficient, Indicates the authority amplification factor.
[0117] Combined with the visitor risk factor ( ) and the visitor authority range coefficient ( ) Calculate the visitor safety factor, that is, the visitor risk factor ( ) is larger, ( ) is smaller, the security factor is reduced, and the visitor authority range coefficient ( ) is larger (wider scope of authority), Amplify risk (need ), looking at the visitor safety factor from the overall performance The larger the value, the higher the visitor security.
[0118] Preferably, the data-access security matching model is expressed as:
[0119]
[0120] in, Indicates the data-access security matching degree, Indicates the data safety factor, Indicates the visitor safety factor, represents the asymmetry tolerance coefficient, The larger the value, the higher the match between the visitor security factor and the data security factor.
[0121] This technical solution measures the data security factor through the data-access security matching model ( ) and visitor safety factor ( ) of the matching degree, when When the denominator is the smallest, the data-access security matching degree Highest, judging from the overall performance of data-access security matching The larger the value, the higher the security match and the looser the access rights.
[0122] Preferably, the steps of comparing the acquired data-access security matching degree with the corresponding threshold value and then acquiring the current visitor's operation authority for the currently stored data are:
[0123] like , it means that the current visitor's security factor is highly consistent with the security factor of the saved data, allowing viewing, modification and export;
[0124] like , it means that the current visitor's security factor matches the security factor of the saved data moderately, and viewing and modification are allowed;
[0125] like , it means that the current visitor's security factor matches the security factor of the saved data and is allowed to view;
[0126] like , it means that the current visitor's security factor does not match the security factor of the saved data, access is denied and an alarm is triggered.
[0127] As an embodiment of the present invention, a computer data security protection system adopts the above-mentioned computer data security protection method.
[0128] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that includes a list of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus.
[0129] While embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions, and variations may be made to these embodiments without departing from the principles and spirit of the invention, and that the scope of the invention is defined by the appended claims and their equivalents.
Claims
1. A computer data security protection method, characterized in that: The following steps are involved: Obtain content risk data and value data of stored data, obtain access rights scope data and risk data of visitors; Build and import a data content risk assessment model based on the content risk data of the stored data, and then output the data content risk coefficient; Build a data value model based on the value data of the saved data and import and then output the data value coefficient; Build a data security model based on the data value coefficient and data content risk coefficient, import and then output the data security coefficient; Build an access permission range model based on the visitor's access permission range data, import it, and then output the access permission range coefficient; Build a visitor risk model based on the visitor's risk data and import and then output the visitor risk coefficient; Construct visitor safety factor based on visitor authority range coefficient and visitor risk coefficient and import and then output visitor safety factor; Build a data-access security matching model based on the visitor security factor and the data security factor, import it, and then output the data-access security matching degree; Compare the obtained data-access security matching degree with the corresponding threshold, and then obtain the current visitor's operation permissions for the currently saved data; The content risk data of the stored data includes key length, data access frequency and the percentage of the saver's authority; The specific steps for building a data content risk assessment model based on the content risk data of the stored data and importing it, and then outputting the data content risk coefficient, are as follows: Importing the key length into the formula Output key length index, To adjust the key sensitivity, is the key length; Ratio the current data access frequency with the maximum access frequency allowed by the business to obtain the access frequency index; The saver permission ratio is compared with the maximum allowed saver permission ratio to obtain the saver permission ratio index; A data content risk model is constructed based on the key length index, access frequency index, and preserver authority ratio index, and the key length index, access frequency index, and preserver authority ratio index are imported to obtain the data content risk coefficient; The data content risk model is expressed as: ; in, Indicates the data content risk factor, represents the key length exponent, represents the access frequency index, Indicates that the permission ratio index is saved. represents the weight coefficient and ,in, The value is 1, 2 or 3. The larger the value, the higher the risk of the data content.
2. The computer data security protection method according to claim 1, characterized in that: The value data of the saved data includes the recovery time target, business dependency and data sharing scope; the visitor's permission scope data includes the number of accessible sensitivity levels, the number of cross-system permissions and the proportion of accessible data fields; the visitor's risk data includes the unapproved access rate, the proportion of abnormal sessions and the number of policy violations.
3. The computer data security protection method according to claim 2, characterized in that: The steps for obtaining the data value coefficient are: Ratio the recovery time objective, business dependency, and data sharing scope to their respective maximum allowable values to obtain the recovery time objective index, business dependency index, and data sharing scope index; Import the obtained recovery time objective index, business dependency index, and data sharing scope index into the data value model to obtain the data value coefficient; The data value model is expressed as: ; in, represents the data value coefficient, represents the recovery time objective index, represents the business dependency index, represents the data sharing scope index, represents the weight coefficient and ,in, The value is 1, 2 or 3. And the larger the value, the higher the data value.
4. The computer data security protection method according to claim 3, characterized in that: The data security model is expressed as: ; in, Indicates the data safety factor, Indicates the data content risk factor, represents the data value coefficient, And the larger the value, the higher the data value.
5. The computer data security protection method according to claim 4, characterized in that: The steps for building an access rights range model based on the visitor's access rights range data, importing it, and then outputting the access rights range coefficients are as follows: Ratio the accessible sensitivity level number and the cross-system permission number to the corresponding maximum allowed value, and then obtain the accessible sensitivity level index and the cross-system permission number index; Import the accessible sensitivity level index, cross-system permission quantity index, and accessible data field ratio into the constructed visitor permission range model to output the visitor permission range coefficient; The visitor permission range model is expressed as: ; in, Indicates the visitor's authority range coefficient, Indicates the accessible sensitivity level index. Indicates the index of the number of cross-system permissions, Indicates the proportion of accessible data fields, represents the weight coefficient and ,in, The value is 1, 2 or 3. The larger the value, the wider the visitor's permissions and the higher the potential risk.
6. The computer data security protection method according to claim 5, characterized in that: The steps for building a visitor risk model based on the visitor risk data and importing and then outputting the visitor risk coefficient are as follows: The policy violation count is calculated by comparing the number of policy violations with the maximum allowed number of violations to obtain a policy violation count index. Import the policy violation index, unapproved access rate, and abnormal session ratio into the constructed visitor risk model to output the visitor risk coefficient; The visitor risk model is expressed as: ; in, represents the visitor risk factor, Indicates the unapproved access rate. Indicates the proportion of abnormal sessions. represents the number of policy violations index, represents the weight coefficient and ,in, The value is 1, 2 or 3. The larger the value, the higher the risk to the visitor.
7. The computer data security protection method according to claim 6, characterized in that: The visitor security model is expressed as: ; in, Indicates the visitor safety factor, represents the visitor risk factor, Indicates the visitor's authority range coefficient, Indicates the authority amplification factor.
8. The computer data security protection method according to claim 7, characterized in that: The data-access security matching model is expressed as: ; in, Indicates the data-access security matching degree, Indicates the data safety factor, Indicates the visitor safety factor, represents the asymmetry tolerance coefficient, The larger the value, the higher the match between the visitor security factor and the data security factor.
9. The computer data security protection method according to claim 8, characterized in that: The steps for comparing the acquired data-access security matching degree with the corresponding threshold and obtaining the current visitor's operation permissions for the currently saved data are as follows: like , it means that the current visitor's security factor is highly consistent with the security factor of the saved data, allowing viewing, modification and export; like , it means that the current visitor's security factor matches the security factor of the saved data moderately, and viewing and modification are allowed; like , it means that the current visitor's security factor matches the security factor of the saved data and is allowed to view; like , it means that the current visitor's security factor does not match the security factor of the saved data, access is denied and an alarm is triggered.
Citation Information
Patent Citations
Access control method and system for data security protection
CN119109614A