Intelligent multivariate control security access method, device and system
Through the joint control of the cloud and the interviewed devices, the access signals and correct the strategies, the problem of insufficient security and flexibility of the traditional single authentication method in complex scenarios is solved, and more efficient and secure access control is achieved.
Patent Information
- Application Number
- CN202510647468.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-20
- Publication Date
- 2025-08-15
AI Technical Summary
The traditional single authentication method is difficult to meet the security access control needs in complex scenarios, especially in the fields of enterprise networks, industrial control systems and smart homes, where security and flexibility are insufficient.
The intelligent multi-control method is adopted to receive access signals through the cloud and perform screening and verification, transmit them to the interviewed devices to analyze attribute information, and match them with the access control policy. Combined with the dual control of the cloud and interviewed devices, the reasons for failing to pass the screening are analyzed and the access policy is corrected to achieve joint control of multiple parties.
It improves the security and flexibility of access control, can adapt to security needs in complex scenarios, and has a high degree of intelligence and flexibility to ensure resource security.
Smart Images

Figure CN120498776A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security, and in particular to a method, device and system for intelligent multi-control security access. Background Art
[0002] With the rapid development of information technology and the Internet of Things, more and more data are stored in databases. The security of databases has become particularly important. Database servers usually contain critical data, so access control is required to ensure the security and integrity of this data.
[0003] However, due to the diversification of existing network attack methods, various systems (such as enterprise networks, industrial control systems, smart homes, etc.) have put forward higher requirements on the security and flexibility of access control. The traditional single authentication method can no longer meet the security needs in complex scenarios. Therefore, there is an urgent need for an intelligent multi-control security access method to achieve more efficient, safer and more flexible access control.
[0004] Based on this, the present invention designs a method, device and system for secure access with intelligent multi-level control to solve the problem that the traditional single authentication method mentioned above can no longer meet the security requirements in complex scenarios. Summary of the Invention
[0005] The purpose of the present invention is to provide a method, device and system for intelligent multi-control secure access to solve the problem in the above background technology that the traditional single authentication method can no longer meet the security requirements in complex scenarios.
[0006] To achieve the above-mentioned object, the present invention provides the following technical solutions: a method, device and system for secure access with intelligent multi-level control, comprising the following steps;
[0007] S1: The cloud receives the access signal sent by the access device and screens and verifies the access signal;
[0008] S2: Transmitting the access signal that has passed the screening test to the accessed device, which analyzes the access signal that has passed the screening test and determines attribute information of the access signal;
[0009] S3: Match the attribute information with the access control policy and determine the resource access rights of the attribute information.
[0010] Preferably, the step S2 further includes:
[0011] S201: extracting access signals that fail the screening test and analyzing the specific reasons why they fail the screening test;
[0012] S202: Feedback the specific reasons for failure to pass the screening test to the cloud;
[0013] S203: The cloud receives the specific reason fed back and supplements and amends the access policy of the cloud for receiving the access signal according to the specific reason.
[0014] Preferably, the control strategy in step S3 includes control strategy one and control strategy two; if the attribute information only successfully matches control strategy one, the attribute information obtains first-level resource access rights; if the attribute information successfully matches both control strategy one and control strategy two, the attribute information obtains second-level resource access rights.
[0015] Preferably, in step S201, the access signal that fails the screening test is specifically a dangerous signal that poses a security risk to the cloud and the accessed device.
[0016] Preferably, the access policy of step S203 is specifically that when the cloud receives an access signal, the access signal is matched with the access policy. If the match is successful, the cloud directly refuses to receive the access signal.
[0017] Preferably, the first-level resource access permission is specifically the search and browsing permission for resources in the resource library, and the second-level resource access permission is specifically the additional transmission, downloading, modification, and annotation permission on the basis of the first-level resource access permission.
[0018] A system for intelligent multi-level controlled secure access, used to implement the above-mentioned method for intelligent multi-level controlled secure access, includes a cloud receiving module, a cloud screening module, a signal transmission module, a cause analysis module, a feedback module, a signal receiving module, an attribute analysis module, and a policy matching module, characterized in that:
[0019] The cloud receiving module is used to receive the access signal sent by the access device;
[0020] The cloud screening module is used to screen access signals that pose security risks to the cloud and the accessed device;
[0021] The signal transmission module is used to transmit the access signal that has passed the screening of the cloud screening module to the signal receiving module, and transmit the access signal that has not passed the screening of the cloud screening module to the cause analysis module;
[0022] The cause analysis module is used to receive access signals that have not passed the screening by the cloud screening module and analyze the specific reasons for their failure to pass the screening test;
[0023] The feedback module is used to feed back the specific reasons for failing the screening test to the cloud, and to supplement and modify the access policy for receiving access signals on the cloud based on the feedback reasons;
[0024] The signal receiving module is used to receive access signals screened by the cloud screening module;
[0025] The attribute analysis module is used to analyze and determine the attribute information of the access signal filtered by the cloud screening module;
[0026] The policy matching module is used to match the attribute information with the access control policy and determine the resource access rights of the attribute information.
[0027] A device for secure access to intelligent multi-level control includes: a storage device and a processor, wherein the storage device is used to store programs, and the storage device stores one or more programs, and the processor is provided with one or more programs. When the one or more programs are executed by the processor, the processor has one or more responses and implements any of the above-mentioned methods for secure access to intelligent multi-level control.
[0028] A computer-readable storage medium having a computer program disposed thereon, characterized in that: the computer program is stored on a storage device and can be run on a processor, and when the computer program is executed by the processor, it implements any one of the above-mentioned methods for secure access to intelligent multi-level control.
[0029] Compared with the prior art, the present invention has the following beneficial effects:
[0030] 1. The present invention utilizes the cloud to conduct a selection test on the access signal, performs preliminary control on the access signal, transmits the access signal to the accessed device, analyzes the attribute information of the access signal and matches the attribute information with the control strategy, and controls the access signal again. At the same time, the two control strategies classify and control the access signal again, and the multi-party joint control has higher security and flexibility while being intelligent.
[0031] 2. The present invention uses cloud-based analysis to detect the specific causes of dangerous signals that may indicate potential security risks, and supplements and amends access policies based on the specific causes, allowing the cloud to continuously learn and ensure resource security in the face of different complex scenarios. It is very efficient, secure, and flexible. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for describing the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0033] Figure 1 is a flow chart of the steps of the present invention;
[0034] Figure 2 A flow chart of steps of another part of the present invention;
[0035] Figure 3 It is the system principle diagram of the present invention;
[0036] Figure 4 Schematic diagram of the device structure of the present invention. DETAILED DESCRIPTION
[0037] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making any creative efforts shall fall within the scope of protection of the present invention.
[0038] Example 1
[0039] See also Figure 1 and Figure 2 As described, the present invention provides a technical solution: a method for secure access with intelligent multi-level control, comprising the following steps;
[0040] S1: The cloud receives the access signal sent by the access device and screens and verifies the access signal;
[0041] S2: Transmitting the access signal that has passed the screening test to the accessed device, which analyzes the access signal that has passed the screening test and determines attribute information of the access signal;
[0042] S3: Match the attribute information with the access control policy and determine the resource access rights of the attribute information.
[0043] Step S2 further includes:
[0044] S201: extracting access signals that fail the screening test and analyzing the specific reasons why they fail the screening test;
[0045] S202: Feedback the specific reasons for failure to pass the screening test to the cloud;
[0046] S203: The cloud receives the specific reason fed back and supplements and amends the access policy of the cloud for receiving the access signal according to the specific reason.
[0047] The control strategies in step S3 include control strategy one and control strategy two; if the attribute information only successfully matches control strategy one, the attribute information obtains first-level resource access rights; if the attribute information successfully matches both control strategy one and control strategy two, the attribute information obtains second-level resource access rights.
[0048] In step S201 , the access signal that fails the screening test is specifically a dangerous signal that poses a security risk to the cloud and the accessed device.
[0049] The access policy of step S203 is specifically that when the cloud receives an access signal, the access signal is matched with the access policy. If the match is successful, the cloud directly refuses to receive the access signal.
[0050] The first-level resource access permission is specifically the permission to search and browse resources in the resource library, and the second-level resource access permission is specifically the permission to transfer, download, modify, and annotate in addition to the first-level resource access permission.
[0051] This embodiment first receives the access signal of the access device through the cloud, and screens the access signal according to whether there are security risks. If it is an access signal with security risks, its specific security risks are analyzed, and the access policy of the cloud is supplemented and corrected according to the security risks, providing the cloud with deep learning capabilities, which is convenient for adapting to more complex scenario environments. If it is an access signal without security risks, the access signal is transmitted to the access device, and the access device analyzes the attribute information of the access signal and matches the attribute information with the access control policy, distinguishes the permissions possessed by the attribute information, and implements joint control, ensuring the security of resources while also being highly flexible and intelligent.
[0052] Example 2
[0053] See also Figure 3 As shown, a system for secure access with intelligent multi-level control includes a cloud receiving module, a cloud screening module, a signal transmission module, a cause analysis module, a feedback module, a signal receiving module, an attribute analysis module, and a strategy matching module:
[0054] The cloud receiving module is used to receive the access signal sent by the access device;
[0055] The cloud screening module is used to screen access signals that pose security risks to the cloud and accessed devices;
[0056] The signal transmission module is used to transmit the access signal that has passed the screening of the cloud screening module to the signal receiving module, and transmit the access signal that has not passed the screening of the cloud screening module to the cause analysis module;
[0057] The cause analysis module is used to receive access signals that have not passed the screening by the cloud screening module and analyze the specific reasons for failing the screening test;
[0058] The feedback module is used to feed back the specific reasons for not passing the screening test to the cloud, and to supplement and modify the access policy of receiving access signals on the cloud based on the feedback reasons;
[0059] The signal receiving module is used to receive access signals screened by the cloud screening module;
[0060] The attribute analysis module is used to analyze and determine the attribute information of the access signal filtered by the cloud filtering module;
[0061] The policy matching module is used to match attribute information with access control policies and determine the resource access rights of the attribute information.
[0062] The present invention receives the access signal sent by the access device through the cloud receiving module, and sends the access signal to the cloud screening module for screening and inspection. Then, the signal transmission module transmits the access signal that passes the screening to the signal receiving module according to the structure of the screening and inspection, and transmits the access signal that fails the screening to the cause analysis module. The signal receiving module receives the access signal that passes the screening and sends it to the attribute analysis module. The attribute analysis module analyzes its attribute information, and then sends the attribute information to the policy matching module for matching to determine the resource access rights of the attribute information. The cause analysis module receives the access signal that fails the screening and analyzes the specific reason why it fails the screening and inspection, and then sends the specific reason to the feedback module. The feedback module feeds back the specific reason to the cloud to supplement and correct the access policy of the access signal received by the cloud.
[0063] Example 3
[0064] See also Figure 4 As shown, a device for secure access of intelligent multi-level control includes: a storage device and a processor, the storage device is used to store programs, the storage device stores one or more programs, the processor is provided with one or more, when one or more programs are executed by the processor, the processor has one or more responses and implements any of the above-mentioned methods of secure access of intelligent multi-level control.
[0065] A computer-readable storage medium is provided with a computer program, which is stored on a storage device and can be run on a processor. When the computer program is executed by the processor, the computer program implements any one of the above-mentioned intelligent multi-control security access methods.
[0066] The computer-readable medium of the present invention may be a computer-readable signal medium or a computer-readable storage medium or any combination of the two, including permanent and non-permanent, removable and non-removable media that can implement information reading, writing and storage by any method or technology. The information may be computer-readable instructions, data structures, program modules or other data. The computer-readable storage medium includes but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices or devices, or any combination of the above. The computer-readable storage medium includes but is not limited to an electrical connection with one or more wires, a portable computer disk, a hard disk, an optical fiber, an optical (magnetic) storage device, a random access memory, a read-only memory, an erasable programmable read-only memory or any suitable combination of the above.
[0067] Throughout this specification, references to terms such as "one embodiment," "example," or "specific example" indicate that the specific features, structures, materials, or characteristics described in conjunction with that embodiment or example are included in at least one embodiment or example of the present invention. In this specification, schematic representations of these terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in any one or more embodiments or examples.
[0068] The preferred embodiments of the present invention disclosed above are intended only to help illustrate the present invention. These preferred embodiments do not exhaustively describe all details, nor do they limit the present invention to the specific embodiments described. Obviously, many modifications and variations are possible based on the content of this specification. These embodiments are selected and described in detail in this specification to better explain the principles and practical applications of the present invention, thereby enabling those skilled in the art to better understand and utilize the present invention. The present invention is limited only by the claims and their full scope and equivalents.
Claims
1. A method for secure access with intelligent multi-level control, characterized in that: The following steps are included: S1: The cloud receives the access signal sent by the access device and screens and verifies the access signal; S2: Transmitting the access signal that has passed the screening test to the accessed device, which analyzes the access signal that has passed the screening test and determines attribute information of the access signal; S3: Match the attribute information with the access control policy and determine the resource access rights of the attribute information.
2. The method for secure access of intelligent multi-level control according to claim 1, characterized in that: The step S2 further includes: S201: extracting access signals that fail the screening test and analyzing the specific reasons why they fail the screening test; S202: Feedback the specific reasons for failure to pass the screening test to the cloud; S203: The cloud receives the specific reason fed back and supplements and amends the access policy of the cloud for receiving the access signal according to the specific reason.
3. The method for secure access with intelligent multi-level control according to claim 1, characterized in that: The control strategies in step S3 include control strategy one and control strategy two; if the attribute information only successfully matches control strategy one, the attribute information obtains first-level resource access rights; if the attribute information successfully matches both control strategy one and control strategy two, the attribute information obtains second-level resource access rights.
4. The method for secure access with intelligent multi-level control according to claim 2, characterized in that: In step S201, the access signal that fails the screening test is specifically a dangerous signal that poses a security risk to the cloud and the accessed device.
5. The method for secure access with intelligent multi-level control according to claim 4, characterized in that: The access policy of step S203 is specifically that when the cloud receives an access signal, the access signal is matched with the access policy. If a match is successful, the cloud directly refuses to receive the access signal.
6. The method for secure access with intelligent multi-level control according to claim 3, characterized in that: The first-level resource access rights specifically include the rights to search and browse resources in the resource library, and the second-level resource access rights specifically include the rights to transmit, download, modify, and annotate in addition to the first-level resource access rights.
7. A system for intelligent multi-level controlled secure access, for executing the method for intelligent multi-level controlled secure access described in any one of claims 1 to 6, comprising a cloud receiving module, a cloud screening module, a signal transmission module, a cause analysis module, a feedback module, a signal receiving module, an attribute analysis module, and a policy matching module, characterized in that: The cloud receiving module is used to receive the access signal sent by the access device; The cloud screening module is used to screen access signals that pose security risks to the cloud and the accessed device; The signal transmission module is used to transmit the access signal that has passed the screening of the cloud screening module to the signal receiving module, and transmit the access signal that has not passed the screening of the cloud screening module to the cause analysis module; The cause analysis module is used to receive access signals that have not passed the screening by the cloud screening module and analyze the specific reasons for their failure to pass the screening test; The feedback module is used to feed back the specific reasons for failing the screening test to the cloud, and to supplement and modify the access policy for receiving access signals on the cloud based on the feedback reasons; The signal receiving module is used to receive access signals screened by the cloud screening module; The attribute analysis module is used to analyze and determine the attribute information of the access signal filtered by the cloud screening module; The policy matching module is used to match the attribute information with the access control policy and determine the resource access rights of the attribute information.
8. An intelligent multi-control secure access device, characterized in that: include: A storage device and a processor, wherein the storage device is used to store programs, the storage device stores one or more programs, and the processor is provided with one or more programs. When the one or more programs are executed by the processor, the processor has one or more responses and implements a method for secure access to intelligent multi-control as described in any one of claims 1 to 6.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: The computer program is stored in a memory and can be run on a processor. When executed by the processor, the computer program implements the method for secure access to intelligent multi-level control according to any one of claims 1 to 6.