Unauthorized protection method and device, electronic equipment and computer readable storage medium
By obtaining user data request information in insurance and smart medical systems and using verification rules to set management permissions, the complex problem of data overprivileges is solved, and the protection steps and flexible permission management are achieved are simplified, maintenance work is reduced, and system security is improved.
Patent Information
- Application Number
- CN202510697480.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-27
- Publication Date
- 2025-08-05
AI Technical Summary
Previous technology In the insurance and smart medical industries, data overpriced protection is complex and has a lot of workload, making it difficult to adapt to rapidly changing business needs and dynamic permission adjustments.
By obtaining user data request information, using a preset set of verification rules for matching processing, determining the target verification rules, and verifying the authorization information based on the target verification rules, feedback unified resource locators or adding exception mark information to manage user permissions.
The steps for overreach of authority are simplified, the workload of maintenance personnel is reduced, centralized management and flexible adjustment of user rights are realized, and the security and adaptability of the system are improved.
Smart Images

Figure CN120434014A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to, but are not limited to, the field of unauthorized access protection, and in particular to an unauthorized access protection method, device, electronic device, and computer-readable storage medium. Background Art
[0002] Data unauthorized access occurs when a user accesses or modifies data that they should not have accessed or modified. This can be categorized as horizontal unauthorized access and vertical unauthorized access. Horizontal unauthorized access occurs when a user unauthorizedly accesses data at the same level, while vertical unauthorized access occurs when a user unauthorizedly accesses data at a higher or lower level. The essence of data unauthorized access is accessing data for which you are not authorized, which can create security issues. In the insurance or smart healthcare industries, to address the issue of data unauthorized access, a common approach is to intercept and process specific interfaces of insurance business systems or smart healthcare systems to prevent data unauthorized access. However, as the business grows and interfaces increase, the interception rules need to be continuously updated and maintained, which increases the workload and makes unauthorized access protection more complex. Summary of the Invention
[0003] The following is a summary of the subject matter described in detail herein. This summary is not intended to limit the scope of the claims.
[0004] In order to solve the problems mentioned in the above background technology, the embodiments of the present application provide a method, device, electronic device and computer-readable storage medium for unauthorized access protection, which can simplify unauthorized access protection and reduce the workload of maintenance personnel.
[0005] In a first aspect, an embodiment of the present application provides a method for preventing unauthorized access, including:
[0006] Obtaining user data request information, wherein the user data request information includes user level information and authorization information;
[0007] Matching the user level information with a preset verification rule set to determine a target verification rule;
[0008] Performing verification processing on the authorization information based on the target verification rule to obtain verification information;
[0009] If the verification information indicates that the user has the data access rights, feeding back the target uniform resource locator to the user;
[0010] When the verification information indicates that the user does not have data access rights, preset abnormal marking information is added to the user level information.
[0011] In a second aspect, an embodiment of the present application further provides an unauthorized protection device, comprising:
[0012] an acquiring unit, configured to acquire user data request information, wherein the user data request information includes user level information and authorization information;
[0013] A matching unit, configured to match the user level information with a preset verification rule set to determine a target verification rule;
[0014] A verification unit, configured to perform verification processing on the authorization information based on the target verification rule to obtain verification information;
[0015] A feedback unit, configured to feed back a target uniform resource locator to the user if the verification information indicates that the user has data access rights;
[0016] The adding unit is configured to add preset abnormal marking information to the user level information when the verification information indicates that the user does not have data access rights.
[0017] In a third aspect, an embodiment of the present application further provides an electronic device comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the unauthorized protection method as described in the first aspect above is implemented.
[0018] In a fourth aspect, an embodiment of the present application further provides a computer-readable storage medium storing computer-executable instructions, wherein the computer-executable instructions are used to execute the unauthorized protection method as described in the first aspect above.
[0019] According to the unauthorized access protection method of the embodiment provided by the present application, there are at least the following beneficial effects: in the process of unauthorized access protection, user data request information is first obtained, wherein the user data request information includes user level information and authorization information; then the user level information is matched with a preset verification rule set to determine the target verification rule; then the authorization information can be verified based on the target verification rule to obtain verification information; when the verification information indicates that the user has data access rights, the target uniform resource locator can be fed back to the user for data access; when the verification information indicates that the user does not have data access rights, the preset abnormal marking information can be added to the user level information. Through the above technical solution, the user's access rights can be centrally managed, and the user's access rights can be verified and processed intelligently. There is no need to separately develop and maintain each interface of the system as in the past, which simplifies the steps of unauthorized access protection and reduces the workload of maintenance personnel. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] The accompanying drawings are used to provide a further understanding of the technical solution of the present application and constitute a part of the specification. Together with the embodiments of the present application, they are used to explain the technical solution of the present application and do not constitute a limitation on the technical solution of the present application.
[0021] Figure 1 This is a flowchart of an unauthorized protection method provided by an embodiment of the present application;
[0022] Figure 2 yes Figure 1 A schematic flow chart of a specific implementation of step S200;
[0023] Figure 3 yes Figure 1 A schematic flow chart of a specific implementation of step S300;
[0024] Figure 4 yes Figure 1 A schematic flow chart of a specific implementation of step S400;
[0025] Figure 5 yes Figure 1 A schematic flow chart of a specific implementation of step S500;
[0026] Figure 6 It is executed Figure 1 A schematic flow chart of a specific implementation method after step S500;
[0027] Figure 7 is generated Figure 1 A flowchart of a specific implementation method of the verification rule set in FIG.
[0028] Figure 8 This is a schematic diagram of an unauthorized protection device provided by an embodiment of the present application;
[0029] Figure 9 This is a schematic diagram of an electronic device provided by an embodiment of the present application. DETAILED DESCRIPTION
[0030] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.
[0031] It should be noted that although the device schematics illustrate functional module divisions and the flowcharts illustrate logical sequences, in certain circumstances, the steps shown or described may be performed in a sequence that differs from the module divisions in the device or the sequence in the flowcharts. The terms "first," "second," and so on, used in the specification, claims, and drawings, are used to distinguish similar items and are not necessarily used to describe a specific sequence or precedence.
[0032] It should be noted that, unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art to which this application belongs. The terms used herein are only for the purpose of describing the embodiments of this application and are not intended to limit this application.
[0033] The embodiments of the present application can acquire and process relevant data based on artificial intelligence technology. Artificial Intelligence (AI) is the theory, method, technology, and application system that uses digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use knowledge to achieve optimal results.
[0034] AI is a new technical discipline that studies and develops theories, methods, technologies, and application systems for simulating, extending, and expanding human intelligence. Artificial intelligence is a branch of computer science that seeks to understand the essence of intelligence and produce new intelligent machines that can respond in a manner similar to human intelligence. Research in this field includes robotics, speech recognition, image recognition, natural language processing, and expert systems. Artificial intelligence can simulate the information processes of human consciousness and thinking. It also refers to the theories, methods, technologies, and application systems that use digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use that knowledge to achieve optimal results.
[0035] Fundamental AI technologies generally include sensors, dedicated AI chips, cloud computing, distributed storage, big data processing, operating / interaction systems, and mechatronics. AI software technologies primarily encompass computer vision, robotics, biometrics, speech processing, natural language processing, and machine learning / deep learning.
[0036] Artificial intelligence, or AI, is a theory, method, technology, and application system that uses digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use knowledge to achieve optimal results.
[0037] The servers involved in artificial intelligence technology can be independent servers or cloud servers that provide basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content delivery networks (CDN), as well as big data and artificial intelligence platforms.
[0038] The present application provides a method, device, electronic device and computer-readable storage medium for unauthorized access protection. In the process of unauthorized access protection, user data request information is first obtained, wherein the user data request information includes user level information and authorization information; then the user level information is matched with a preset set of verification rules to determine the target verification rule; then the authorization information can be verified based on the target verification rule to obtain verification information; when the verification information indicates that the user has data access rights, the target uniform resource locator can be fed back to the user for data access; when the verification information indicates that the user does not have data access rights, the preset abnormal marking information can be added to the user level information. Through the above technical solution, the user's access rights can be centrally managed, and the user's access rights can be verified and processed intelligently. There is no need to separately develop and maintain each interface of the system as in the past, which simplifies the steps of unauthorized access protection and reduces the workload of maintenance personnel.
[0039] The unauthorized protection method provided in the embodiment of the present application relates to the technical field of unauthorized protection. The unauthorized protection method provided in the embodiment of the present application can be applied to a terminal, can be applied to a server side, and can also be software running in a terminal or a server side. In some embodiments, the terminal can be a smart phone, a tablet computer, a laptop computer, a desktop computer, etc.; the server side can be configured as an independent physical server, or as a server cluster or distributed system composed of multiple physical servers, or as a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms.
[0040] The present application can be used in many general or special computer system environments or configurations. For example: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, and the like. The present application can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, and the like that perform specific tasks or implement specific abstract data types. The present application can also be practiced in distributed computing environments in which tasks are performed by remote processing devices connected via a communication network. In a distributed computing environment, program modules can be located in local and remote computer storage media, including storage devices.
[0041] It should be noted that in each specific embodiment of the present application, when it comes to the need to perform relevant processing based on data related to the user's identity or characteristics, such as user information, user behavior data, user historical data, and user location information, the user's permission or consent will be obtained first, and the collection, use, and processing of such data will comply with relevant laws, regulations, and standards. In addition, when the embodiment of the present application needs to obtain the user's sensitive personal information, the user's separate permission or consent will be obtained through a pop-up window or by jumping to a confirmation page. After clearly obtaining the user's separate permission or consent, the necessary user-related data for the normal operation of the embodiment of the present application will be obtained.
[0042] The embodiments of the present application are further described below with reference to the accompanying drawings.
[0043] like Figure 1 As shown, Figure 1 This is a flowchart of a method for protecting against unauthorized access provided by an embodiment of the present application. The method for protecting against unauthorized access includes the following steps:
[0044] Step S100: Obtain user data request information, wherein the user data request information includes user level information and authorization information.
[0045] The unauthorized access protection method provided in the embodiment of the present application first needs to obtain user data request information, wherein the user data request information includes user level information and authorization information; subsequently, access permission verification processing can be performed based on the user level information and authorization information in the user data request information to determine whether the corresponding user has data access permission.
[0046] For example, in an insurance business system, when a user needs to access the insurance business system, when the user clicks on the relevant interface in the insurance business system to trigger access, user data request information will be generated; for example, when a user accesses the "personal information" in the insurance business system. Alternatively, in a smart medical system, when a user needs to query the number of inpatients in the smart medical system, corresponding user data request information will also be generated, or when a user needs to query the price of a specific drug in the smart medical system, corresponding user data request information will also be generated.
[0047] It is worth noting that data unauthorized access refers to users accessing or modifying data that they should not access or modify, which can be divided into horizontal unauthorized access and vertical unauthorized access. Horizontal unauthorized access refers to users unauthorized access to data at the same level, and vertical unauthorized access refers to users unauthorized access to data at higher or lower levels. The essence of data unauthorized access is access to data that is not authorized, which can cause serious security problems, such as user privacy leakage, data tampering, etc. At present, the industry generally adopts the method of intercepting and processing specific interfaces to prevent data unauthorized access, but this method has the following defects: interception processing for specific interfaces cannot fully cover all potential risk points, resulting in blind spots in protection; with the development of business and the increase of interfaces, it is necessary to continuously update and maintain interception rules, which increases workload and complexity; existing solutions often lack flexibility and are difficult to adapt to rapidly changing business needs and dynamic permission adjustments. In order to solve the above technical problems, the embodiments of the present application provide an unauthorized access protection method, which centrally manages the verification rules, can well simplify the steps of unauthorized access protection, and enables the authorization information to be flexibly adjusted, so that subsequent unauthorized access protection can be more flexible.
[0048] It is worth noting that the user level information in the user data request information is used to represent the user attribute information of the user in the corresponding system; the authorization information in the user data request information is used to represent whether the user has the authority to access a certain data.
[0049] It is worth noting that in the process of obtaining user data request information, when it comes to the need to perform relevant processing based on data related to the user's identity or characteristics, such as user information, user behavior data, user historical data, and user location information, the user's permission or consent will be obtained first, and the collection, use, and processing of such data will comply with relevant laws, regulations, and standards. In addition, when the embodiment of the present application needs to obtain the user's sensitive personal information, the user's separate permission or consent will be obtained through a pop-up window or by jumping to a confirmation page. After clearly obtaining the user's separate permission or consent, the necessary user-related data for the normal operation of the embodiment of the present application will be obtained.
[0050] Step S200: Match the user level information with a preset verification rule set to determine a target verification rule.
[0051] The unauthorized protection method provided in the embodiment of the present application, after obtaining the user data request information, since the user data request information includes user level information and authorization information; then the user level information can be matched with a pre-set verification rule set, and the corresponding target verification rule can be determined to prepare for the subsequent authorization information verification.
[0052] It is worth noting that the verification rule set includes multiple verification rules, and each verification rule carries level attribute information. Subsequently, the user level information can be matched with the level attribute information of each verification rule to obtain the corresponding target verification rule. Through the above technical solution, the determination of the target verification rule can be more accurate.
[0053] like Figure 2 As shown, the verification rule set includes multiple verification rules, each of which carries level attribute information. Matching the user level information with the preset verification rule set to determine the target verification rule may include the following steps:
[0054] Step S210: Match the user level information with the level attribute information of each verification rule in the verification rule set to obtain target level attribute information;
[0055] Step S220: Determine the verification rule corresponding to the target level attribute information as the target verification rule.
[0056] For steps S210 to S220, in the process of matching the user level information with the pre-set verification rule set to determine the target verification rule, the user level information is first matched with the level attribute information of each verification rule in the verification rule set to obtain the target level attribute information; finally, the verification rule corresponding to the target level attribute information can be used to determine the corresponding target verification rule, in preparation for the subsequent authorization information verification processing.
[0057] It is worth noting that the verification rule set includes multiple verification rules, and each verification rule carries level attribute information. Therefore, in the subsequent target verification rule selection process, the user level information and the level attribute information of each verification rule in the verification rule set can be matched to obtain the corresponding target level attribute information; subsequently, the verification rule corresponding to the target level attribute information can be determined as the target verification rule.
[0058] For example, in an insurance business system, when business personnel need to query the insurance information of transactions in the insurance business system, they can match the user level information corresponding to the business personnel with the level attribute information of each verification rule in the verification rule set in the insurance business system to obtain the target level attribute information. Subsequently, the verification rule corresponding to the target level attribute can be determined to obtain the target verification rule, in preparation for subsequent insurance business data queries. Alternatively, in a smart medical system, when medical staff need to query the number of vacant beds in the inpatient department, they can first match the user level information corresponding to the medical staff with the level attribute information of each verification rule in the verification rule set to obtain the target level attribute information. Subsequently, the verification rule corresponding to the target level attribute information can be determined as the target verification rule, in preparation for subsequent inpatient department vacant bed queries.
[0059] Step S300: Verify the authorization information based on the target verification rule to obtain verification information.
[0060] The unauthorized protection method provided in the embodiment of the present application can verify the authorization information based on the target verification rule to obtain verification information after matching the user level information with a preset verification rule set to determine the target verification rule, and then verify and determine the user's unauthorized protection based on the verification information.
[0061] For example, in an insurance business system, unauthorized access refers to an unauthorized user accessing or operating system resources, data, or functions beyond their authorized scope. Unauthorized access may include the following: horizontal unauthorized access, vertical unauthorized access, unauthorized privilege escalation, data access privilege escalation, and functional operation privilege escalation. Horizontal unauthorized access can include a customer logging into the system being able to view or modify other customers' policy information and claims records, or an insurance agent being able to view or modify other agents' sales performance and client lists. Vertical unauthorized access can include a regular customer logging into the system being able to access the system administrator's backend interface, such as user rights management and data backup, or customer service personnel being able to view or modify financial data, such as premium income and claims expenses. Unauthorized privilege escalation can include a user changing their role in a request to become an administrator, or a user exploiting a security vulnerability in the system to gain higher privileges. Data access privilege escalation can include employees in one department accessing sensitive data from another department, such as actuarial department data being accessed by sales department employees, or partners or third-party service providers accessing insurance data beyond their scope of collaboration. Unauthorized functional operations may include ordinary users being able to modify key information such as the terms and conditions of the insurance policy, the insurance amount, etc.; or non-claims personnel being able to review or approve claims applications. Based on the embodiments of the present application, the authorization information is verified and processed based on the obtained target verification rules to obtain verification information, and the user's access rights can be subsequently determined and processed based on the verification information. Alternatively, in a smart medical system, unauthorized access not only involves data security, but may also affect the patient's life safety and the normal operation of the medical system. Therefore, the technical solution based on the embodiments of the present application can effectively prevent unauthorized access from occurring in the smart medical system, thereby improving the security of the smart medical system.
[0062] like Figure 3 As shown, the authorization information is verified based on the target verification rule to obtain verification information, which may include the following steps:
[0063] Step S310: determining verification round information and verification parameter information corresponding to the verification round information based on the target verification rule;
[0064] Step S320: splitting the authorization information to obtain multiple authorization sub-information;
[0065] Step S330: Match the authorization sub-information with the verification parameter information of the corresponding verification round information to obtain verification information.
[0066] For steps S310 to S330, in the process of verifying the authorization information based on the target verification rules to obtain the verification information, first determine the verification round information and the verification parameter information corresponding to the verification round information based on the target verification rules, then split the authorization information to obtain multiple authorization sub-information; finally, match the authorization sub-information with the verification parameter information of the corresponding verification round information to obtain the corresponding verification information; through the above technical solution, the determination of the verification information can be more accurate.
[0067] It is worth noting that the verification round information and the verification parameter information corresponding to the verification round information are determined based on the target verification rule; the target verification rule is extracted to obtain multiple verification round information and verification parameter information, so that multiple rounds of verification operations can be performed during the subsequent verification process, making the subsequent verification processing more accurate and improving the accuracy and precision of the verification processing. Among them, each verification round will correspond to verification parameter information, so the authorization information can be split to obtain multiple authorization sub-information, and then the authorization sub-information can be compared and matched with the verification parameters of the corresponding verification round information to determine the corresponding verification information.
[0068] Step S400: When the verification information indicates that the user has data access rights, a target uniform resource locator is fed back to the user.
[0069] The unauthorized access protection method provided in the embodiment of the present application can provide the user with a target uniform resource locator when the verification information indicates that the user has data access rights, and the user can subsequently access, view and process the relevant data based on the target uniform resource locator.
[0070] It is worth noting that the target uniform resource locator can uniquely identify a resource on the Internet, whether it is a web page, image, file or other type of data; through the target uniform resource locator, users can use browsers, client software and other tools to access specified resources; the target uniform resource locator can also pass parameters, and the query string part can be used to pass dynamic parameters to the server, such as search keywords, paging information, etc.; the target uniform resource locator can also be used for page navigation, and anchors can be used to quickly locate specific parts within the page to improve user experience.
[0071] For example, in an insurance business system, when an insurance salesperson needs to query and process the policy information in the system, if the verification information indicates that the insurance salesperson has data access rights, the target uniform resource locator will be fed back to the insurance salesperson, and the insurance salesperson can then access the corresponding policy information based on the target uniform resource locator. Alternatively, in a smart medical system, when a medical staff needs to view and process a patient's examination report, if the verification information indicates that the medical staff has data access rights, the target uniform resource locator will be fed back to the medical staff, and the medical staff can then access the patient's examination report based on the target uniform resource locator, providing an examination basis for subsequent diagnosis and treatment.
[0072] like Figure 4 As shown, when the verification information indicates that the user has the data access permission, feeding back the target uniform resource locator to the user may include the following steps:
[0073] Step S410: if the verification information indicates that the user has data access rights, determine the target database from the preset database system based on the verification information;
[0074] Step S420, determining a target uniform resource locator according to a target database;
[0075] Step S430: Feedback the target uniform resource locator to the user.
[0076] For steps S410 to S430, when the verification information indicates that the user has data access rights, in the process of feeding back the target uniform resource locator to the user, when the verification information indicates that the user has data access rights, the target database can be determined from the pre-set database system based on the verification information; then the target uniform resource locator can be determined based on the target database; finally, the target uniform resource locator can be fed back to the user, and the user can subsequently query and access related data based on the target uniform resource locator.
[0077] It is worth noting that when the verification information indicates that the user has the relevant data access rights, the target database can be determined from the pre-set database system based on the verification information; then the target uniform resource locator can be determined from the target database; finally, the target uniform resource locator can be fed back to the target user, and then the target user can perform data access processing based on the target uniform resource locator.
[0078] Step S500: When the verification information indicates that the user does not have data access rights, preset abnormality mark information is added to the user level information.
[0079] The unauthorized access protection method provided in the embodiment of the present application verifies and processes the authorization information based on the target verification rules, and then determines and processes the verification information; when it is determined according to the verification information that the user does not have data access rights, the pre-set abnormal mark information can be added to the user level information corresponding to the user, so that the user's illegal identity can be quickly locked in the subsequent data access process, and the data access service for the user can be stopped.
[0080] It is worth noting that the pre-set abnormal marking information is used to mark the user level information; it is understandable that when the user level information contains the pre-set abnormal marking information, the user corresponding to the user level information can be identified as an illegal user, and in the presence of the abnormal marking information, data access operations are not allowed. For example, in an insurance business system, when the verification information indicates that the user does not have data access rights, the abnormal marking information can be added to the user level information of the corresponding user, and the data access rights of the user can be suspended; or, in a smart medical system, when the verification information indicates that the user does not have the data access right limit, the abnormal marking information can also be added to the user level information of the corresponding user, and the data access rights of the user can be suspended to prevent information leakage.
[0081] like Figure 5 As shown, when the verification information indicates that the user does not have data access rights, adding preset abnormal marking information to the user level information may include the following steps:
[0082] Step S510: if the verification information indicates that the user does not have data access rights, generating access exception information based on a preset interceptor;
[0083] Step S520: Analyze and process the access exception information to obtain exception analysis information;
[0084] Step S530: When the abnormal analysis information indicates that the user has unauthorized access, abnormal marking information is added to the user level information.
[0085] For steps S510 to S530, when the verification information indicates that the user does not have data access rights, the pre-set exception marking information is added to the user level information. First, when the verification information indicates that the user does not have data access rights, access exception information can be generated based on the pre-set interceptor, and then the access exception information can be analyzed and processed to obtain exception analysis information; finally, when the exception analysis information indicates that the user has unauthorized access, the corresponding exception marking information can be added to the user level information corresponding to the user to mark the user's illegal identity.
[0086] It is worth noting that when the verification information indicates that the user does not have data access rights, the interceptor will generate corresponding access exception information; subsequent analysis and processing of the access exception information can obtain exception analysis information; finally, when the exception analysis information indicates that the user has exceeded authorization, the exception mark information can be added to the corresponding user level information, so that the user corresponding to the user level information containing the exception mark information can be quickly locked and his data access rights can be suspended.
[0087] like Figure 6 As shown, when the verification information indicates that the user does not have the data access permission, after adding the preset abnormal marking information to the user level information, the following steps may also be included:
[0088] Step S610: obtaining new user data request information within a preset time interval, wherein the user level information of the new user data request information carries abnormality mark information;
[0089] Step S620: Lock and suspend access to the user account corresponding to the new user data request information.
[0090] For steps S610 to S620, when the verification information indicates that the user does not have data access rights, after the pre-set abnormal marking information is added to the user level information, new user data request information is first obtained within a pre-set time interval, wherein the user level information of the new user data request information carries the abnormal marking information; when the user level information of the new user data request information carries the abnormal marking information, the corresponding user account will be locked to suspend the access rights of the corresponding user, which can speed up the management and control of illegal users and improve the security of the system.
[0091] For example, in an insurance business system, after 30 minutes, new user data request information is obtained again, and the user level information in the new user data request information carries the previous abnormal marking information; at this time, the system will lock the user account corresponding to the new user data request information and suspend its data access request. Alternatively, in a smart medical system, after 10 minutes, new user data request information is obtained again, and the user level information in the new user data request information also carries the previous abnormal marking information; at this time, the system will also lock the user account corresponding to the new user data request information and suspend its data access request. It is worth noting that the abnormal marking information carried in the user level information needs to be verified and checked, and the user's identity needs to be verified again. Only when the relevant requirements are met can the abnormal marking information carried in the user level information be deleted, thereby improving the security of the system operation.
[0092] like Figure 7 As shown, the verification rule set can be obtained through but not limited to the following steps.
[0093] Step S710, determining multiple access interfaces from a preset operating system;
[0094] Step S720: collect and process access rule information of each access interface to obtain a verification rule set.
[0095] In steps S710 to S720, when obtaining the verification rule set, multiple access interfaces are first identified from the pre-defined operational system. Then, the access rule information for each access interface is collected and processed to obtain the corresponding verification rule set. This technical solution centrally manages access rule information for all interfaces, eliminating the need for separate development and maintenance for each interface, reducing the workload for maintenance personnel. Access rule information can also be quickly adjusted based on new business needs and security threats, increasing the flexibility of unauthorized access protection.
[0096] In addition, if Figure 8 As shown, an embodiment of the present application further provides an unauthorized protection device 10, comprising:
[0097] The acquisition unit 100 is configured to acquire user data request information, wherein the user data request information includes user level information and authorization information;
[0098] The matching unit 200 is used to match the user level information with a preset verification rule set to determine a target verification rule;
[0099] The verification unit 300 is used to verify the authorization information based on the target verification rule to obtain verification information;
[0100] The feedback unit 400 is configured to feedback the target uniform resource locator to the user when the verification information indicates that the user has the data access right;
[0101] The adding unit 500 is configured to add preset abnormality marking information to the user level information when the verification information indicates that the user does not have data access rights.
[0102] It should be noted that, in the process of performing unauthorized access protection, user data request information is first obtained, wherein the user data request information includes user level information and authorization information; then the user level information is matched with a preset set of verification rules to determine the target verification rule; then the authorization information can be verified based on the target verification rule to obtain verification information; when the verification information indicates that the user has data access rights, the target uniform resource locator can be fed back to the user for data access; when the verification information indicates that the user does not have data access rights, the preset abnormal marking information can be added to the user level information. Through the above technical solution, the user's access rights can be centrally managed, and the user's access rights can be verified and processed intelligently. There is no need to separately develop and maintain each interface of the system as in the past, which simplifies the steps of unauthorized access protection and reduces the workload of maintenance personnel.
[0103] The specific implementation of the unauthorized protection device 10 is substantially the same as the specific embodiment of the unauthorized protection method described above, and will not be described in detail here.
[0104] In addition, if Figure 9 As shown, an embodiment of the present application further provides an electronic device 700 , which includes: a memory 720 , a processor 710 , and a computer program stored in the memory 720 and executable on the processor 710 .
[0105] The processor 710 and the memory 720 may be connected via a bus or other means.
[0106] The non-transitory software programs and instructions required to implement the unauthorized protection methods of the above embodiments are stored in the memory 720 , and when executed by the processor 710 , the unauthorized protection methods of the above embodiments are executed.
[0107] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, i.e., they may be located in one place or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of this embodiment.
[0108] In addition, an embodiment of the present application also provides a computer-readable storage medium, which stores computer-executable instructions, and the computer-executable instructions are executed by a processor 710 or a controller, for example, by a processor 710 in the above-mentioned device embodiment, so that the above-mentioned processor 710 can execute the unauthorized protection method in the above-mentioned embodiment.
[0109] The above embodiments may be used in combination, and modules with the same name in different embodiments may be the same or different.
[0110] The foregoing description describes specific embodiments of the present application, and other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in an order different from that described in the embodiments and still achieve the desired results. In addition, the processes depicted in the accompanying drawings do not necessarily require the specific order shown or the sequential order to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0111] The various embodiments in this application are described in a progressive manner. Similar portions between the various embodiments can be referenced to each other, and each embodiment focuses on the differences from the other embodiments. In particular, the device, equipment, and computer-readable storage medium embodiments are generally similar to the method embodiments, so their descriptions are relatively simple. For relevant portions, refer to the descriptions of the method embodiments.
[0112] The apparatus, device, computer-readable storage medium and method provided in the embodiments of the present application correspond to each other. Therefore, the apparatus, device and non-volatile computer storage medium also have similar beneficial technical effects as the corresponding method. Since the beneficial technical effects of the method have been described in detail above, the beneficial technical effects of the corresponding apparatus, device and computer storage medium will not be repeated here.
[0113] In the 1990s, technological improvements could be clearly distinguished as either hardware improvements (for example, improvements to circuit structures like diodes, transistors, and switches) or software improvements (improvements to process flows). However, with the advancement of technology, many process flow improvements today can now be considered direct improvements to hardware circuit structures. Designers almost always create the corresponding hardware circuit structure by programming the improved process flow into the hardware circuit. Therefore, it cannot be said that a process flow improvement cannot be implemented using hardware modules. For example, a programmable logic device (PLD), such as a field programmable gate array (FPGA), is an integrated circuit whose logical function is determined by user programming. Designers can "integrate" a digital system on a PLD by programming it themselves, without having to hire a chip manufacturer to design and manufacture a dedicated integrated circuit chip. Moreover, nowadays, instead of manually fabricating integrated circuit chips, this programming is mostly performed using "logic compiler" software. This is similar to the software compilers used during program development. Before compilation, the original code must be written in a specific programming language, called a hardware description language (HDL). There are many HDLs, including ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, and RHDL (Ruby Hardware Description Language). Currently, the most commonly used are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art will also appreciate that simply programming a method flow in one of these hardware description languages and programming it into an integrated circuit can easily create a hardware circuit that implements the logic method flow.
[0114] The controller can be implemented in any suitable manner. For example, the controller can take the form of a microprocessor or processor and a computer-readable medium storing computer-readable program code (e.g., software or firmware) executable by the (micro)processor, logic gates, switches, application-specific integrated circuits (ASICs), programmable logic controllers, and embedded microcontrollers. Examples of controllers include, but are not limited to, the following microcontrollers: ARC625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicone Labs C8051F320. The memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art will also know that in addition to implementing the controller in a purely computer-readable program code manner, it is entirely possible to implement the same function in the form of logic gates, switches, application-specific integrated circuits, programmable logic controllers, and embedded microcontrollers by logically programming the method steps. Therefore, such a controller can be considered a hardware component, and the devices included therein for implementing various functions can also be considered as structures within the hardware component. Or even, the devices for implementing various functions can be considered as both software modules implementing the method and structures within the hardware component.
[0115] The systems, devices, modules, or units described in the above embodiments may be implemented by computer chips or entities, or by products having certain functions. A typical implementation device is a computer. Specifically, the computer may be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smartphone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.
[0116] For the convenience of description, the above devices are described as being divided into various units according to their functions. Of course, when implementing the embodiments of the present application, the functions of each unit can be implemented in the same or multiple software and / or hardware.
[0117] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the embodiments of the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the embodiments of the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0118] This specification is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the steps in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0119] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0120] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0121] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.
[0122] Memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. Memory is an example of a computer-readable medium.
[0123] Computer-readable media includes permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic disk storage or other magnetic storage devices, or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media (transitory media), such as modulated data signals and carrier waves.
[0124] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.
[0125] In the embodiments of the present application, "at least one" refers to one or more, and "more" refers to two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can represent the existence of A alone, the existence of A and B at the same time, and the existence of B alone. Among them, A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following" and similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one of a, b and c can represent: a, b, c, a and b, a and c, b and c or a and b and c, where a, b, c can be single or multiple.
[0126] Embodiments of the present application may be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, and the like that perform specific tasks or implement specific abstract data types. Embodiments of the present application may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communications network. In a distributed computing environment, program modules may be located in local and remote computer storage media, including storage devices.
[0127] The various embodiments in this application are described in a progressive manner. Similar parts between the various embodiments can be referred to in conjunction with each other. Each embodiment focuses on the differences between the other embodiments. In particular, the system embodiment is generally similar to the method embodiment, so the description is relatively simple. For relevant parts, refer to the partial description of the method embodiment.
[0128] The foregoing is merely an embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application may have various modifications and variations. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application should be included within the scope of the claims of the present application.
Claims
1. A method for protecting against unauthorized access, characterized in that: include: Obtaining user data request information, wherein the user data request information includes user level information and authorization information; Matching the user level information with a preset verification rule set to determine a target verification rule; Performing verification processing on the authorization information based on the target verification rule to obtain verification information; If the verification information indicates that the user has the data access rights, feeding back the target uniform resource locator to the user; When the verification information indicates that the user does not have data access rights, preset abnormal marking information is added to the user level information.
2. The unauthorized protection method according to claim 1, wherein: The verification rule set includes a plurality of verification rules, each of which carries level attribute information. Matching the user level information with the preset verification rule set to determine the target verification rule includes: Matching the user level information with the level attribute information of each verification rule in the verification rule set to obtain target level attribute information; The verification rule corresponding to the target level attribute information is determined as the target verification rule.
3. The unauthorized protection method according to claim 1, wherein: The verifying the authorization information based on the target verification rule to obtain verification information includes: Determining verification round information and verification parameter information corresponding to the verification round information based on the target verification rule; Splitting the authorization information to obtain multiple authorization sub-information; The authorization sub-information is matched with the verification parameter information of the corresponding verification round information to obtain the verification information.
4. The unauthorized protection method according to claim 1, wherein: Feedback of the target uniform resource locator to the user when the verification information indicates that the user has the data access right includes: If the verification information indicates that the user has data access rights, determining a target database from a preset database system according to the verification information; determining a target uniform resource locator according to the target database; The target uniform resource locator is fed back to the user.
5. The unauthorized protection method according to claim 1, wherein: When the verification information indicates that the user does not have data access rights, adding preset abnormal marking information to the user level information includes: When the verification information indicates that the user does not have data access rights, generating access exception information based on a preset interceptor; Analyzing and processing the access exception information to obtain exception analysis information; In the case where the abnormality analysis information indicates that the user has unauthorized access, the abnormality marking information is added to the user level information.
6. The unauthorized protection method according to claim 1, wherein: When the verification information indicates that the user does not have data access rights, after adding preset abnormality mark information to the user level information, the method further includes: within a preset time interval, obtaining new user data request information, wherein the user level information in the new user data request information carries the abnormality mark information; The user account corresponding to the new user data request information is locked and access is suspended.
7. The unauthorized protection method according to claim 1, wherein: The verification rule set is obtained in the following way: Determine multiple access interfaces from the preset operating system; The access rule information of each access interface is collected and processed to obtain the verification rule set.
8. An unauthorized protection device, characterized in that: include: an acquiring unit, configured to acquire user data request information, wherein the user data request information includes user level information and authorization information; A matching unit, configured to match the user level information with a preset verification rule set to determine a target verification rule; A verification unit, configured to perform verification processing on the authorization information based on the target verification rule to obtain verification information; A feedback unit, configured to feed back a target uniform resource locator to the user if the verification information indicates that the user has data access rights; The adding unit is configured to add preset abnormal marking information to the user level information when the verification information indicates that the user does not have data access rights.
9. An electronic device comprising: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the unauthorized protection method according to any one of claims 1 to 7 when executing the computer program.
10. A computer-readable storage medium storing computer-executable instructions, characterized in that: The computer-executable instructions are used to execute the unauthorized protection method according to any one of claims 1 to 7.
Citation Information
Cited By
Data operation processing method and server
CN120915617A