Illegal access management method and system for station equipment

Through a multi-factor authentication based on risk score and a hybrid decision-making engine of role and attributes, the problems of lag in illegal access detection and high permission misallocation rates in industrial scenarios are solved, adaptive adjustment of access permissions is achieved, and the adaptability and efficiency of security policies are improved.

CN120434010APending Publication Date: 2025-08-05DELINGHA HUANENG TUORI NEW ENERGY POWER GENERATION CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510687673.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-26
Publication Date
2025-08-05

AI Technical Summary

Technical Problem

In existing industrial scenarios, illegal access detection lags, high permission misallocation rate, and poor security policy adaptability. Especially in industrial control systems, equipment heterogeneity and protocol diversity make it difficult for traditional access control technologies to achieve cross-protocol security policy consistency management.

Method used

A multi-factor authentication based on risk scores and a hybrid decision engine for role and attributes is used to generate dynamic access tokens by calculating biometric confidence, device confidence and scenario risk factors, and dynamic permission management is carried out in combination with a hybrid decision engine for role and attributes.

Benefits of technology

It realizes adaptive adjustment of access permissions, improves the real-time nature of illegal access detection and the adaptability of security policies, reduces the permission mismatch rate, and improves the security and efficiency of industrial scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120434010A_ABST
    Figure CN120434010A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a station equipment illegal access management method and system, and belongs to the technical field of station equipment illegal access management. The method comprises the steps of collecting station access verification data, and calculating an illegal access risk score of station equipment according to the station access verification data; performing risk grade division on the access request; executing an authentication mode corresponding to the risk level, and generating a dynamic access token after the authentication is passed; and sending the dynamic access token to a role and attribute mixed decision engine, and generating a dynamic access permission based on the dynamic access token by using the role and attribute mixed decision engine, and performing illegal access management. Through the multi-factor authentication and role and attribute hybrid decision engine based on the risk score, the access permission can be adaptively adjusted, and the problems of lagging illegal access detection, high permission mismatching rate, poor security policy adaptability and the like in an industrial scene are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of illegal access management of site equipment, and in particular to a method and system for illegal access management of site equipment. Background Art

[0002] With the rapid development of the Industrial Internet and the Internet of Things (IoT) technologies, the demand for networked control and management of critical infrastructure, such as energy plants, transportation hubs, and smart manufacturing bases, is growing. Existing access control technologies primarily rely on traditional network security architectures, centered around the role-based access control (RBAC) model, combining static permission assignment with pre-set security policies to protect devices. In the industrial control system (ICS) sector, access control technology has evolved into a multi-layered protection system: at the physical layer, access control systems and biometric recognition devices are used to isolate devices; at the network layer, traditional perimeter protection technologies are deployed, including stateful inspection firewalls, deep packet inspection (DPI) systems, and dedicated gateways for industrial protocols (such as Modbus TCP / Profinet protocol filters); and at the application layer, TLS 1.3 encrypted channels and OAuth 2.0 token mechanisms are widely used to ensure communication security. In recent years, the application of attribute-based encryption (ABE) and policy-based access control (PBAC) technologies has increased the granularity of permission management. However, significant latency still exists in the policy generation and verification processes, particularly when processing massive device registration requests under the OPC UA protocol, where policy decision latency can reach 300-500ms. In the field of biometric authentication, technologies such as fingerprint recognition and iris scanning have achieved sub-second response times, but a mature solution for dynamic adaptation mechanisms for multimodal fusion authentication has yet to emerge. Existing systems, such as the BioHashing algorithm, experience false rejection rates as high as 8.7% when dealing with lighting changes or biometric degradation. Current mainstream systems generally employ a linear "authentication-authorization-audit" protection model. This single-point decision-making process leads to response lags when addressing emerging threats such as unauthorized access and spoofing attacks. This is particularly true in industrial control system (ICS) scenarios, where device heterogeneity and protocol diversity further exacerbate security policy fragmentation. Typical industrial sites often feature the coexistence of over ten heterogeneous protocols, including Modbus RTU, CANopen, and EtherCAT. Traditional access control technologies struggle to achieve consistent security policy management across these protocols. Summary of the Invention

[0003] The purpose of the embodiments of the present invention is to provide a method and system for managing illegal access to site equipment. The multi-factor authentication based on risk scoring and the hybrid decision engine of roles and attributes enable adaptive adjustment of access rights, solving problems such as delayed illegal access detection, high mismatch rate of permissions, and poor adaptability of security policies in industrial scenarios.

[0004] In order to achieve the above-mentioned purpose, an embodiment of the present invention provides a method for managing illegal access to site equipment, including: collecting site access verification data, and calculating a risk score for illegal access to site equipment based on the site access verification data; classifying access requests into risk levels based on the risk score for illegal access to site equipment; executing an authentication method corresponding to the risk level based on the classified risk level, and generating a dynamic access token after the authentication is passed; sending the dynamic access token to a role and attribute hybrid decision engine, and using the role and attribute hybrid decision engine to generate dynamic access rights based on the dynamic access token; and performing illegal access management based on the dynamic access rights.

[0005] Optionally, the calculation of the illegal access risk score of the site equipment based on the site access verification data includes: calculating the biometric confidence, device credibility, and scenario risk factor; setting weights, and calculating the illegal access risk score of the site equipment using a weighted sum algorithm based on the set weights.

[0006] Optionally, the risk level classification of access requests based on the illegal access risk score of the site station equipment includes: setting a first risk threshold and a second risk threshold; when the illegal access risk score of the site station equipment is less than the first risk threshold, determining the risk level of the current access request to be low risk; when the first risk threshold ≤ when the illegal access risk score of the site station equipment is less than the second risk threshold, determining the risk level of the current access request to be medium risk; when the illegal access risk score of the site station equipment is greater than the second risk threshold, determining the risk level of the current access request to be high risk.

[0007] Optionally, according to the risk level classification, an authentication method corresponding to the risk level is executed, including: when the risk level of the current access request is low risk, the authentication method is set to biometric authentication; when the risk level of the current access request is medium risk, the authentication method is set to two-factor authentication of biometric authentication and dynamic token authentication; when the risk level of the current access request is high risk, the authentication method is set to three-factor authentication of biometric authentication, dynamic token authentication and device fingerprint.

[0008] Optionally, the dynamic access token includes user role information, device fingerprint information, risk level information, token issuance time, and token validity period.

[0009] Optionally, the use of the role and attribute hybrid decision engine to generate dynamic access rights based on the dynamic access token includes: verifying the integrity and validity of the dynamic access token, parsing the payload of the dynamic access token, extracting user role information, device fingerprint information, and risk level information; obtaining the real-time status of the device and network environment attributes; using the role and attribute hybrid decision engine to assign basic permissions based on the user role information; using the role and attribute hybrid decision engine to dynamically adjust the basic permissions based on the risk level information, the real-time status of the device and the network environment attributes to obtain dynamic access rights.

[0010] Optionally, the use of the role and attribute hybrid decision engine to generate dynamic access rights based on the dynamic access token also includes: setting a first adjustment trigger event, the first adjustment trigger event including a device status change, a network environment switch, and a risk level change.

[0011] Optionally, the use of the role and attribute hybrid decision engine to generate dynamic access rights based on the dynamic access token also includes: obtaining the current operation type, calculating context-aware parameters based on the user role information and the current operation type; adjusting the first trigger event based on the context-aware parameters to obtain a second trigger event; and evaluating whether the second trigger event triggers adjustment of access rights.

[0012] Optionally, performing illegal access management based on the dynamic access rights includes: sending the dynamic access rights to the target device; controlling the target device to parse the dynamic access rights, and adjusting the access control logic of the target device according to the dynamic access rights to complete illegal access management.

[0013] On the other hand, the present invention provides a site station equipment illegal access management system for implementing a site station equipment illegal access management method. The system includes a control module, the control module includes a memory, a processor, and a computer program stored in the memory and runnable on the processor. The processor executes the computer program to implement the site station equipment illegal access management method.

[0014] This technical solution achieves real-time risk quantification of access requests by constructing a three-dimensional scoring model encompassing biometric confidence, device trustworthiness, and scenario risk factors. It also employs a risk-level-driven, tiered authentication system to optimize authentication resource allocation while ensuring security. Furthermore, it introduces dynamic access tokens and a hybrid decision engine to adaptively adjust access rights based on device status, network attributes, and operational context. This technological breakthrough effectively addresses key technical challenges in industrial scenarios, such as delayed unauthorized access detection, high mismatch rates, and poor security policy adaptability.

[0015] Other features and advantages of the embodiments of the present invention will be described in detail in the subsequent detailed description. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] The accompanying drawings are used to provide a further understanding of the embodiments of the present invention and constitute a part of the specification. Together with the following detailed description, they are used to explain the embodiments of the present invention, but do not constitute a limitation of the embodiments of the present invention. In the accompanying drawings: Figure 1 It is a flow chart for illegal access management of station equipment.

[0017] Figure 2 This is the flow chart for generating dynamic access tokens. DETAILED DESCRIPTION

[0018] The following is combined with Figure 1 -Attached Figure 2 The specific implementation of the embodiment of the present invention is described in detail. It should be understood that the specific implementation described here is only used to illustrate and explain the embodiment of the present invention, and is not used to limit the embodiment of the present invention.

[0019] It should be noted that the acquisition, transmission, storage, use, and processing of data in the technical solution of this application are in compliance with the relevant provisions of national laws and regulations. In the embodiments of this application, certain software, components, models, and other existing solutions in the industry may be mentioned. These should be considered as exemplary. Their purpose is only to illustrate the feasibility of implementing the technical solution of this application, but it does not mean that the applicant has or will necessarily use such solutions.

[0020] During the implementation of the present invention, the inventors discovered that existing risk assessment models lack dynamic perception capabilities. Existing systems often employ binary authentication (pass / reject) or fixed thresholds, failing to construct a dynamic risk scoring system based on multi-dimensional parameters. Existing authentication mechanisms are disconnected from risk levels, leading to resource redundancy in low-risk scenarios and insufficient protection in high-risk scenarios. Existing permission management is subject to rigid temporal and spatial constraints, and existing access control lists (ACLs) and RBAC models are unable to dynamically adjust based on the real-time status of devices (e.g., load, firmware version) or network environment attributes (e.g., topology, communication protocol). In particular, in cross-domain access scenarios, traditional technologies struggle to balance access efficiency and security requirements, severely restricting the real-time, adaptability, and security of device access control in industrial Internet scenarios.

[0021] Example 1 Reference Figure 1-Figure 2 , which is the first embodiment of the present invention, provides a method for managing illegal access to station equipment, comprising: S100: collecting site access verification data, and calculating a site equipment illegal access risk score based on the site access verification data.

[0022] Specifically, terminal devices (fingerprint sensors, cameras, etc.) are used to collect user biometrics, including fingerprint images and facial images, for identity recognition. The unique device identifier is collected and hashed. For the MAC address (Media Access Control Address), all colons or hyphens in the MAC address are removed to make the MAC address a continuous string. The continuous string is hashed with SHA-256 (Secure Hash Algorithm-256) to obtain a 64-bit character string. For the IP address, a SHA-256 hash is performed to obtain the device fingerprint hash value.

[0023] Furthermore, the TOTP dynamic token provided by the user is obtained and its validity is verified. Environmental data, including geographic location, network type, and operation time, are obtained through the device API, and the collected environmental data is preprocessed to obtain structured scene parameters.

[0024] Furthermore, calculating the risk score of illegal access to the site equipment based on the site access verification data includes: calculating the biometric confidence, device credibility, and scenario risk factor; setting weights, and using a weighted sum algorithm to calculate the risk score of illegal access to the site equipment based on the set weights.

[0025] Specifically, the collected biometric data is compared with the pre-stored template using a similarity algorithm. Fingerprints use Minutia Cylinder Code (fingerprint feature point cylindrical coding) and faces use ArcFace (arc face algorithm). The similarity confidence of the biometric data is calculated (ranging from 0-100%). A threshold of ≥95% is considered a pass, and the biometric confidence is obtained.

[0026] Furthermore, the device fingerprint hash value is checked to see if it is in the registered database. If the device fingerprint hash value exists in the database and is not marked as abnormal, the device credibility is 100 points. If the device fingerprint hash value appears for the first time but its IP address matches the historical record, the device credibility is 70 points. If the device fingerprint hash value is not in the database, the device credibility is 0 points. The device credibility here refers to the degree of match between the device fingerprint hash value and the registered device fingerprint and the quantitative score of the trust status.

[0027] Furthermore, the scenario risk factor is calculated, including the degree of geographic location anomaly and the setting of network threat level weights. The geographic location anomaly calculation involves calculating the Haversine distance between the current coordinates and frequently logged-in locations. If the distance is greater than 100 km, the anomaly is set to 1.0. If the distance is ≤100 km, the anomaly is linearly normalized to a value between 0 and 1 (the smaller the distance, the lower the anomaly). To account for the possibility of business trips, the geographic location anomaly can be dynamically learned from the user's frequently logged-in locations before calculating the geographic location anomaly. In this case, the geographic location anomaly calculation incorporates the calculation of travel locations. Setting the network threat level weight involves setting the network threat level weight for the public network to 1.0, VPN to 0.3, and intranet to 0.1. The scenario risk factor is obtained by multiplying the geographic location anomaly and the network threat level weight. The scenario risk factor ranges from 0 to 100, with higher values indicating higher risk.

[0028] Furthermore, weights are set for biometric confidence, device credibility, and scenario risk factors respectively. The weight setting is not fixed and can be adjusted according to actual conditions. If it is in a high-risk area (such as a nuclear power plant or the core system of a financial institution), the weight of the scenario risk factor can be appropriately increased, while the weight of the biometric confidence or device credibility can be reduced.

[0029] Preferably, based on the data analysis results during actual operation, if it is found that one of the biometric confidence, device credibility, and scenario risk factors has a stronger ability to predict risk, its weight can be appropriately increased.

[0030] Furthermore, the calculation formula for the risk score of illegal access to station equipment is as follows:

[0031] in, 、 、 are all set weights, and + + =1, and the risk score ranges from 0 to 100.

[0032] Optimally, by calculating the risk score for unauthorized access to site equipment, integrating biometrics (fingerprint / face), device fingerprints (MAC / IP hashing), and dynamic tokens (TOTP), a multi-layered protection system significantly improves authentication reliability. Device identifiers are hashed using SHA-256 to prevent the clear transmission of sensitive information (such as MAC addresses and IP addresses), complying with the principle of data minimization. The system can also adjust the weighting of biometrics, device trustworthiness, and scenario risk based on business scenarios (such as high-risk areas in nuclear power plants), balancing security and efficiency.

[0033] S200: Classifying the access request into risk levels according to the risk score of illegal access to the site equipment.

[0034] Furthermore, setting the first and second risk thresholds requires determining acceptable risk levels based on the sensitivity and importance of the business. User experience must also be considered to avoid overly stringent threshold settings that cause legitimate users to frequently trigger high-risk authentication. High-risk behavior must also be effectively identified and prevented. After comprehensive consideration, the first risk threshold was set at 30, and the second risk threshold was set at 70.

[0035] Furthermore, when the illegal access risk score of the site equipment is less than the first risk threshold, 30, the risk level of the current access request is determined to be low risk; when the first risk threshold 30≤when the illegal access risk score of the site equipment is less than the second risk threshold, 70, the risk level of the current access request is determined to be medium risk; when the illegal access risk score of the site equipment is greater than the second risk threshold, 70, the risk level of the current access request is determined to be high risk.

[0036] Optimally, the risk threshold (default 30 / 70) can be adjusted based on business sensitivity and user experience requirements to avoid misjudgments or missed detections caused by a one-size-fits-all strategy. Risks are categorized into three levels: low, medium, and high. This tiered strategy can provide a basis for subsequent differentiated authentication, ensuring stricter authentication methods in high-risk scenarios and streamlining processes and improving efficiency in low-risk scenarios.

[0037] S300: Execute an authentication method corresponding to the risk level according to the risk level, and generate a dynamic access token after the authentication is successful.

[0038] Furthermore, when the risk level of the current access request is low risk, the authentication method is set to biometric authentication; when the risk level of the current access request is medium risk, the authentication method is set to two-factor authentication of biometric authentication and dynamic token authentication; when the risk level of the current access request is high risk, the authentication method is set to three-factor authentication of biometric authentication, dynamic token authentication and device fingerprint.

[0039] Specifically, when the risk level of the current access request is low risk, the user is prompted to perform biometric authentication, compare the collected biometric data with the pre-stored template, and calculate the similarity confidence. If the similarity confidence is ≥95%, the biometric authentication is successful and the process proceeds to the next step; otherwise, the authentication fails and an error message is displayed. When the risk level of the current access request is medium risk, the user first performs biometric authentication, which is the same as the biometric authentication when the risk level is low risk; if the biometric authentication passes, the user is prompted to enter a dynamic token and then verify the dynamic token. If the dynamic token verification passes, the two-factor authentication is successful and the process proceeds to the next step; otherwise, the authentication fails and an error message is displayed. When the risk level of the current access request is high risk, the user must first complete the two-factor authentication of biometric authentication and dynamic token authentication. The two-factor authentication of biometric authentication and dynamic token authentication here is the same as when the risk level is medium risk. After the two-factor authentication is successful, check whether the device fingerprint hash value is in the registration database and calculate the device credibility. If the device credibility meets the requirements, the authentication request will be sent to the manual review link; the auditor will manually review the authentication request and approve the authentication after confirmation; if the manual review passes, the three-factor authentication is successful and proceeds to the next step; otherwise, the authentication fails and an error prompt will be given.

[0040] Furthermore, after the authentication is passed, the dynamic access token generation phase begins. The dynamic access token uses the JWT (JSON Web Token) format. The dynamic access token contains user role information, device fingerprint information, risk level information, token issuance time, and token validity period.

[0041] Preferably, after the dynamic access token is generated, it is sent to the user. The user needs to carry this dynamic access token during subsequent system operations. The system will verify the content and validity of the dynamic access token to determine whether the user has the corresponding authority and whether to allow the user to perform specific operations.

[0042] Preferably, low-risk authentication uses single-factor biometrics, which is convenient and efficient; medium-risk authentication uses two-factor authentication (biometrics + dynamic token) to prevent token leakage or biometric forgery; and high-risk authentication uses three-factor authentication (biometrics + dynamic token + device fingerprint + manual review) to provide multiple guarantees for the security of key operations.

[0043] S400: Send the dynamic access token to a role and attribute hybrid decision engine, and use the role and attribute hybrid decision engine to generate dynamic access rights based on the dynamic access token.

[0044] Furthermore, the dynamic access token is sent to the role-based access control-attribute based access control hybrid decision engine (RBAC-ABAC hybrid decision engine). The role-based access control hybrid decision engine is a dynamic permission decision engine that combines role-based access control (RBAC) and attribute-based access control (ABAC).

[0045] Furthermore, the role and attribute hybrid decision engine needs to verify the integrity and validity of the dynamic access token, and parse the payload of the dynamic access token to extract user role information, device fingerprint information, and risk level information; obtain the real-time status of the device and network environment attributes; use the role and attribute hybrid decision engine to assign basic permissions based on the user role information; use the role and attribute hybrid decision engine to dynamically adjust the basic permissions based on the risk level information, the real-time status of the device and the network environment attributes to obtain dynamic access permissions.

[0046] Specifically, encryption algorithms such as HMAC (Hash-based Message Authentication Code) are used to perform integrity verification on dynamic access tokens to ensure that the dynamic access token has not been tampered with during transmission; the expiration of the dynamic access token is checked based on the token issuance time and token validity period; and a digital signature is used to verify whether the issuer of the token is trustworthy to prevent token forgery.

[0047] Furthermore, according to the format of the dynamic access token, the corresponding parsing library is used to parse the payload part of the dynamic access token, and key information is extracted from the payload part. The key information extracted here includes but is not limited to user role information, device fingerprint information, and risk level information.

[0048] Furthermore, the real-time status of the device is obtained through the API or message queue, and the user's current network environment attributes are obtained by analyzing the user's IP address, the network protocol used, and other information.

[0049] Furthermore, the basic permissions corresponding to the user role are searched in the configured permissions database or configuration file. For example, for the administrator role, the corresponding device configuration modification, log download, and user management permissions are obtained; for the operator role, the corresponding device status query, reboot operation, and alarm confirmation permissions are obtained; and for the guest role, the corresponding basic device information read-only permission is obtained. Using the role identifier, such as the role name, as the key, the corresponding basic permissions list is retrieved from the permissions mapping table, and the basic permissions data in the basic permissions list is formatted.

[0050] Furthermore, a rule engine or conditional judgment logic is used to configure basic permission adjustment rules based on risk level information, real-time status of the device, and network environment attributes; for example, if-else statements are used to judge different condition combinations; basic permission adjustment rules, such as when the risk level information shows that the risk level is high risk, the device configuration modification permission is prohibited; when the device status is an alarm, only emergency shutdown permission is allowed. Set the priority of the basic permission adjustment rules; according to the risk level information, the real-time status of the device, and the network environment attributes, use the basic permission adjustment rules to modify the basic permissions, for example, if the current risk level is high risk and the user attempts to perform a device configuration modification operation, then the permission is set to disabled, etc.; obtain dynamic access rights.

[0051] Preferably, a first adjustment trigger event is set, wherein the first adjustment trigger event includes a device status change, a network environment switch, or a risk level change. The current operation type is obtained, and a context-aware parameter is calculated based on the user role information and the current operation type; the first trigger event is adjusted based on the context-aware parameter to obtain a second trigger event; and whether the second trigger event triggers an adjustment of access rights is evaluated.

[0052] Specifically, a first adjustment trigger event is set. The first adjustment trigger event includes a device status change, a network environment switch, or a risk level change. The user's currently attempted operation type is obtained, and context-aware parameters are calculated based on the user's role information and the current operation type. Context-aware parameters include, but are not limited to, the degree of compatibility between the user role and the current operation, the risk weight of the current operation, and the relevance of historical operation behavior to the current operation. The first trigger event is adjusted based on the context-aware parameters, such as by adjusting the trigger conditions or response strategy of the first trigger event, to generate a second trigger event. Adjustments may include, but are not limited to, adjusting the trigger threshold, such as lowering the risk weight threshold; upgrading the response measures, such as changing from "logging" to "blocking the operation"; and applying additional verification, such as requiring secondary authentication. These adjustments generate a second trigger event, such as "blocking high-risk operations" or "requiring secondary authentication." The second trigger event is evaluated based on the degree of compatibility between the user role and the current operation, the risk weight of the current operation, and the relevance of historical operation behavior to the current operation. If any of these conditions are met, access rights are adjusted. If the risk weight of the current operation exceeds a preset threshold, the trigger condition is met, and access rights are adjusted accordingly, thereby obtaining dynamic access rights.

[0053] Optimally, RBAC provides basic role permissions (such as administrator and operator), while ABAC dynamically adjusts permissions based on real-time attributes (risk level, device status, and network environment), balancing flexibility and security. Permission adjustments are triggered by context-aware parameters (operation risk weight, role matching, and historical behavior relevance), avoiding the rigidity of static permissions. It also supports real-time response to changing risks (such as automatically tightening permissions when the network switches to the public network). Conditional judgment logic (such as if-else) and priority settings ensure that critical rules (such as disabling high-risk operations) are prioritized, improving policy execution efficiency.

[0054] S500: Perform illegal access management based on the dynamic access rights.

[0055] Furthermore, the dynamic access permission is sent to the target device; the target device is controlled to parse the dynamic access permission, and the access control logic of the target device is adjusted according to the dynamic access permission to complete illegal access management.

[0056] Specifically, the dynamic access rights are converted into a format suitable for transmission. The specific format can be selected based on the requirements of the target device. A communication protocol is selected to transmit the dynamic access rights data to the target device. The target device receives the dynamic access rights data by monitoring the specified communication protocol, parses the dynamic access rights data, extracts specific permission information, and uses a flag-based method to adjust the device's access control logic based on the extracted permission information. Based on the updated access control logic, the target device monitors user operation requests in real time. If the user's operation request does not exceed the current permission range, the device will allow the request and perform the corresponding operation. If the user's operation request exceeds the current permission range, the device will reject the request and record the relevant log.

[0057] Ideally, the device should log all access requests and operation results for subsequent auditing and analysis. However, to ensure efficient operation and data security, all recorded access requests and operation results need to be properly managed and regularly cleared. If an illegal access attempt is detected, the device can send a notification to the administrator so that timely action can be taken.

[0058] Preferably, dynamic access rights are issued to the target device in real time, and access logic is controlled by flags to ensure that permission changes take effect immediately and prevent unauthorized operations. The device side parses permission data and executes control, which can effectively reduce the risk of single points of failure in centralized systems.

[0059] An embodiment of the present invention provides a storage medium on which a program is stored. When the program is executed by a processor, the method for managing illegal access to site equipment is implemented.

[0060] An embodiment of the present invention provides a processor, which is used to run a program, wherein the method for managing illegal access to site equipment is executed when the program is running.

[0061] An embodiment of the present invention provides a device comprising a processor, a memory, and a program stored in the memory and executable on the processor. When the processor executes the program, a method for managing illegal access to station equipment is implemented. The device herein may be a server, a PC, a PAD, a mobile phone, or the like.

[0062] The present application also provides a computer program product, which, when executed on a data processing device, is suitable for executing a method for managing illegal access to site equipment.

[0063] Those skilled in the art will appreciate that the embodiments of the present application may provide methods, systems, or computer program products. Therefore, the present application may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0064] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0065] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0066] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 The steps for the function specified in one or more boxes.

[0067] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.

[0068] Memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. Memory is an example of a computer-readable medium.

[0069] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can be implemented using any method or technology to store information. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change RAM (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic disk storage or other magnetic storage devices, or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media, such as modulated data signals and carrier waves.

[0070] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.

[0071] The above are merely embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various modifications and variations. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application should be included within the scope of the claims of the present application.

Claims

1. A method for managing illegal access to station equipment, characterized in that: include: Collecting site access verification data, and calculating a site equipment illegal access risk score based on the site access verification data; Classifying the access request into risk levels according to the risk score of illegal access to the site equipment; According to the risk level, the authentication method corresponding to the risk level is executed, and a dynamic access token is generated after the authentication is passed; Sending the dynamic access token to a role and attribute hybrid decision engine, and using the role and attribute hybrid decision engine to generate a dynamic access permission based on the dynamic access token; Based on the dynamic access rights, illegal access management is performed.

2. The method for managing illegal access to station equipment according to claim 1, characterized in that: include: Calculating the risk score of illegal access to the site equipment according to the site access verification data includes: Calculate biometric confidence, device trustworthiness, and scenario risk factors; Set weights, and use a weighted sum algorithm to calculate the risk score of illegal access to site equipment based on the set weights.

3. The method for managing illegal access to station equipment according to claim 1, characterized in that: The risk level classification of the access request according to the risk score of illegal access to the site equipment includes: Setting a first risk threshold and a second risk threshold; When the risk score of illegal access to the site equipment is less than the first risk threshold, the risk level of the current access request is determined to be low risk; When the first risk threshold ≤ the illegal access risk score of the site equipment ≤ the second risk threshold, determining that the risk level of the current access request is medium risk; When the risk score of illegal access to the site equipment is greater than the second risk threshold, the risk level of the current access request is determined to be high risk.

4. The method for managing illegal access to station equipment according to claim 1, characterized in that: The step of executing an authentication method corresponding to the risk level according to the risk level classification includes: When the risk level of the current access request is low risk, the authentication method is set to biometric authentication; When the risk level of the current access request is medium risk, the authentication method is set to two-factor authentication of biometric authentication and dynamic token authentication; When the risk level of the current access request is high risk, the authentication method is set to three-factor authentication consisting of biometric authentication, dynamic token authentication, and device fingerprint.

5. The method for managing illegal access to station equipment according to claim 1, characterized in that: The dynamic access token includes user role information, device fingerprint information, risk level information, token issuance time, and token validity period.

6. The method for managing illegal access to station equipment according to claim 1, characterized in that: The generating of dynamic access rights based on the dynamic access token by using the role and attribute hybrid decision engine includes: Verify the integrity and validity of the dynamic access token, and parse the payload of the dynamic access token to extract user role information, device fingerprint information, and risk level information; Obtain real-time device status and network environment attributes; Using the role and attribute hybrid decision engine, basic permissions are assigned according to the user role information; The role and attribute hybrid decision engine is used to dynamically adjust the basic permissions according to the risk level information, the real-time status of the device and the network environment attributes to obtain dynamic access permissions.

7. The method for managing illegal access to station equipment according to claim 6, characterized in that: The method of generating dynamic access rights based on the dynamic access token using the role and attribute hybrid decision engine also includes: setting a first adjustment trigger event, wherein the first adjustment trigger event includes a device status change, a network environment switch, and a risk level change.

8. The method for managing illegal access to station equipment according to claim 7, characterized in that: The generating of dynamic access rights based on the dynamic access token by using the role and attribute hybrid decision engine further includes: Obtaining a current operation type, and calculating a context awareness parameter based on the user role information and the current operation type; adjusting the first trigger event according to the context awareness parameter to obtain a second trigger event; Evaluate whether the second triggering event triggers adjustment of access rights.

9. The method for managing illegal access to station equipment according to claim 1, characterized in that: The illegal access management based on the dynamic access permission includes: sending the dynamic access permission to the target device; controlling the target device to parse the dynamic access permission, and adjusting the access control logic of the target device according to the dynamic access permission to complete the illegal access management.

10. A system for managing illegal access to station equipment, characterized in that: The system includes a control module, which includes a memory, a processor, and a computer program stored in the memory and executable on the processor. The processor executes the computer program to implement the method for managing illegal access to site equipment according to any one of claims 1 to 9.

Citation Information

Cited By

  • Equipment authority management method and electronic equipment

    CN121644153A