Data access control method based on zero-trust architecture
Through the combination of multi-factor identity authentication and deep learning models, users' trust is evaluated in real time and permissions are assigned dynamically. The use of micro-isolation technology for logical isolation and real-time encryption is solved, and the difficulties of identity authentication and permission management in the existing technology are improved, and the security and flexibility of data access are improved.
Patent Information
- Application Number
- CN202510814833.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-18
- Publication Date
- 2025-08-15
AI Technical Summary
It is difficult for the existing technology to use multi-factor identity authentication combined with deep learning models for identity authentication, it is difficult to judge whether access permissions are granted based on the user's trust probability, it is difficult to dynamically allocate access permissions based on the user's roles and attributes, it is difficult to use micro-isolation technology to logically isolate and encrypt data resources in real time, and it is difficult to automatically recycle access permissions.
Multi-factor identity authentication is used to combine deep learning models for user authentication, real-time evaluation of trust and dynamic allocation of permissions, and use micro-isolation technology to logically isolate data and encrypt data in real time, and automatically recycle access permissions.
It realizes accurate verification and dynamic access control of user identity, improves the accuracy and security of permission management, limits the scope of attacks, and prevents data leakage.
Smart Images

Figure CN120498845A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and specifically to a data access control method based on a zero-trust architecture. Background Art
[0002] Zero Trust Architecture is a security concept whose core principle is "never trust, always verify." This architecture assumes that internal networks are no more secure than external networks, and therefore requires strict access control and authentication regardless of the location of information resources. By combining the principle of least privilege, continuous monitoring, and dynamic access control, this "never trust, always verify" approach enables precise verification of user identities, real-time assessment of trust, and dynamic adjustment of access rights. Furthermore, micro-segmentation technology is utilized to limit the scope of attacks, encrypt data in real time, and automatically reclaim permissions after access is terminated. This effectively improves the security and flexibility of data access, meeting security requirements in complex network environments.
[0003] The existing technologies have the following problems, including: it is difficult to use multi-factor authentication combined with deep learning models for identity authentication and it is difficult to determine whether to grant access rights based on the user's trust probability; it is difficult to dynamically allocate access rights based on the user's role and attributes and the zero-trust architecture; it is difficult to use micro-isolation technology for logical isolation and real-time encryption of data resources; and finally, it is difficult to automatically reclaim data access rights. Summary of the Invention
[0004] The present invention aims to solve at least one of the technical problems existing in the prior art. To this end, the present invention proposes a data access control method based on a zero-trust architecture to solve the above-mentioned problem. To this end, a first aspect of the present invention provides a data access control method based on a zero-trust architecture, comprising the following steps:
[0005] S1: When a user initiates a data access request, a multi-factor authentication method combined with a deep learning model is used to verify the user's identity. The user's trust probability is evaluated in real time and the decision on whether to grant access rights is made based on the user's trust probability.
[0006] S2: Based on the user's trust probability, by combining the user's role and attributes, access rights are dynamically allocated using the principle of least privilege in the zero trust architecture;
[0007] S3: Use micro-segmentation technology to logically isolate different data resources and users to form independent security domains. When users access data, they break through the boundary protection of the current security domain and enter the target security domain, and then perform step S1 again.
[0008] S4: When users access data, data resources are encrypted in real time;
[0009] S5: Automatically revoke the temporarily granted access rights after the user completes data access.
[0010] Furthermore, in step S1, when a user initiates a data access request, a multi-factor identity authentication method combined with a deep learning model is used to verify the user's identity, including the following steps:
[0011] When a user initiates a data access request, the user is verified using a multi-factor authentication method; the multi-factor authentication method includes: password, fingerprint, facial recognition, SMS verification code and hardware token;
[0012] Collect historical multi-source data including: user behavior data, device status information, and network environment data; the user behavior data includes: access time, geographic location, operation frequency, and operation sequence; the device status information includes: device type and device operating status; the network environment data includes: network type, network speed, and network latency;
[0013] Data preprocessing of collected historical multi-source data includes: cleaning data and standardizing data formats;
[0014] By selecting a long short-term memory network model from a deep learning model, 70% of the historical multi-source data is randomly sampled as a training set, and the remaining 30% of the historical multi-source data is used as a test set; both the training set and the test set are labeled with user authentication, including: legal and illegal; the training set is input into the long short-term memory network model for training; and the test set is used to evaluate the performance of the long short-term memory network model;
[0015] After the user uses multi-factor authentication, multi-source data is monitored and collected in real time. The collected and pre-processed multi-source data is input into the trained long short-term memory network model, and the output is whether the user's identity verification is legal or illegal.
[0016] Combining the results of multi-factor identity authentication and the analysis results of the long short-term memory network model, when the user identity authentication passes and is legal, the user is allowed to access the data; when the user identity authentication fails or is illegal, the user is denied access to the data.
[0017] Furthermore, the step S1 of performing a real-time evaluation on the user's trust probability and determining whether to grant access rights based on the user's trust probability includes the following steps:
[0018] Based on the multi-source data collected and pre-processed in real time, the probability formula for evaluating the user's trustworthiness is calculated in real time:
[0019]
[0020] Among them, Ai is the value of the i-th data of user behavior data; B j is the value of the jth data of the device status information; C k is the value of the kth data in the network environment data; w i 、w j and w k are weight coefficients respectively; w0 indicates that the intercept value is 0.5; T is the user's trust value;
[0021] When the user trust probability is higher than 0.8, access permission is granted; when the user trust probability is lower than 0.8, access permission is not granted.
[0022] Furthermore, the step S2 includes the following steps:
[0023] When a user is granted access rights based on the probability of their trustworthiness, a dynamic access control mechanism is introduced by introducing roles. A deep learning model is used to automatically identify the user's role based on real-time monitored multi-source data. User roles are labeled as ordinary users, administrators, and auditors, and the labeled historical multi-source data is input into the deep learning model for training. The multi-source data collected and pre-processed in real time is input into the trained deep learning model to automatically identify and output the user's role.
[0024] Based on the identified user roles, basic permissions are assigned according to the principle of least privilege;
[0025] A dynamic permission baseline is generated based on user roles and attributes; the permission baseline dynamically adjusts user access rights based on real-time multi-source data.
[0026] Furthermore, the step S3 includes the following steps:
[0027] Use micro-isolation technology to logically isolate different data resources and users to form independent security domains;
[0028] By using access control lists, firewall rules and intrusion detection or prevention systems, a protection mechanism for the security domain boundary is designed; when a user requests to access data resources in the target security domain, the protection mechanism of the current security domain boundary is broken through, and after entering the target security domain, the system returns to step S1 for identity authentication and authorization again; when the user performs data access operations in the target security domain, the user is monitored in real time.
[0029] Furthermore, the step S4 includes the following steps:
[0030] Use the AES-256 algorithm to encrypt data resources; use quantum key distribution technology to generate AES keys, and distribute the AES keys to the server through the asymmetric encryption RSA algorithm;
[0031] The encrypted data resources are transmitted over the network, using the encryption protection protocols TLS and SSL for encrypted transmission and end-to-end encryption;
[0032] Data resources are stored on the server side, using full disk encryption or file encryption technology to keep the stored data resources encrypted until authorized access.
[0033] Furthermore, step S5 includes the following steps: when the user completes access to the data, the permission recovery mechanism is automatically triggered by exiting the data access operation or detecting that the user has not performed any operation for a long time; the permission recovery mechanism includes: immediately revoking all temporary permissions granted to the user during the access process, clearing the user's temporary data, and recording the permission recovery event in the log.
[0034] Compared with the prior art, the present invention has the following beneficial effects:
[0035] The present invention uses multi-factor identity authentication combined with a deep learning model to authenticate the user; it evaluates the user's trustworthiness in real time and determines whether the user can be granted access rights based on the trustworthiness;
[0036] By dynamically allocating access rights using the principle of least privilege in a zero-trust architecture, this invention can effectively prevent unauthorized users from accessing the system while ensuring that users only obtain the minimum privileges required for their work, significantly improving the accuracy and security of privilege management.
[0037] The present invention uses micro-isolation technology to logically isolate different data resources and users to form independent security domains, and re-verify during cross-domain access. At the same time, it encrypts the data in real time and automatically reclaims permissions after the access ends, effectively limiting the scope of attacks, preventing data leakage, and further enhancing security. BRIEF DESCRIPTION OF THE DRAWINGS
[0038] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0039] Figure 1 Flow chart of the method of the present invention. DETAILED DESCRIPTION
[0040] The technical solutions of the present invention will be clearly and completely described below in conjunction with the embodiments. Obviously, the embodiments described are only some embodiments of the present invention, not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0041] See also Figure 1 As shown, the first embodiment of the present invention provides a data access control method based on a zero trust architecture, comprising the following steps:
[0042] S1: When a user initiates a data access request, a multi-factor authentication method combined with a deep learning model is used to verify the user's identity. The user's trust probability is evaluated in real time and the decision on whether to grant access rights is made based on the user's trust probability.
[0043] S2: Based on the user's trust probability, by combining the user's role and attributes, access rights are dynamically allocated using the principle of least privilege in the zero trust architecture;
[0044] S3: Use micro-segmentation technology to logically isolate different data resources and users to form independent security domains. When users access data, they break through the boundary protection of the current security domain and enter the target security domain, and then perform step S1 again.
[0045] S4: When users access data, data resources are encrypted in real time;
[0046] S5: Automatically revoke the temporarily granted access rights after the user completes data access.
[0047] Specifically, when a user initiates a data access request, preliminary identity verification is performed using multi-factor authentication methods such as passwords, biometrics, and mobile phone verification codes. Subsequently, a deep learning model is used to further verify the user's identity. A real-time assessment of the user's trustworthiness probability is performed, derived from a comprehensive analysis of multi-source data. Based on this trustworthiness probability, a decision is made as to whether to grant access rights to the user. After completing step S1, access rights are dynamically assigned based on the user's role and attributes using the principle of least privilege within a zero-trust architecture. This means that users are limited to accessing the minimum dataset required for their work, mitigating potential data breaches. Access rights are dynamically adjusted based on factors such as real-time multi-source data and changes in the user's trustworthiness probability. Micro-segmentation technology is used to logically isolate different data resources and users, forming independent security domains. Each security domain has its own perimeter protection and access control policies. When a user needs to access data resources in another security domain, they must first breach the perimeter protection of their own security domain and then undergo identity verification and trustworthiness assessment again in step S1. This process ensures strict access control across different data resources. When users access data, data resources are encrypted in real time; this ensures that even if the data is intercepted during transmission, it cannot be decrypted and read by unauthorized users. Advanced encryption algorithms and technologies, such as AES and RSA, can be used to ensure data security. After the user completes data access, temporarily granted access rights are automatically revoked. This ensures that users can access data resources only when needed, and their permissions are immediately revoked once access ends.
[0048] In this embodiment, when a user initiates a data access request in step S1, a multi-factor identity authentication method combined with a deep learning model is used to verify the user's identity, including the following steps:
[0049] When a user initiates a data access request, the user is verified using a multi-factor authentication method; the multi-factor authentication method includes: password, fingerprint, facial recognition, SMS verification code and hardware token;
[0050] Collect historical multi-source data including: user behavior data, device status information, and network environment data; the user behavior data includes: access time, geographic location, operation frequency, and operation sequence; the device status information includes: device type and device operating status; the network environment data includes: network type, network speed, and network latency;
[0051] Data preprocessing of collected historical multi-source data includes: cleaning data and standardizing data formats;
[0052] By selecting a long short-term memory network model from a deep learning model, 70% of the historical multi-source data is randomly sampled as a training set, and the remaining 30% of the historical multi-source data is used as a test set; both the training set and the test set are labeled with user authentication, including: legal and illegal; the training set is input into the long short-term memory network model for training; and the test set is used to evaluate the performance of the long short-term memory network model;
[0053] After the user uses multi-factor authentication, multi-source data is monitored and collected in real time. The collected and pre-processed multi-source data is input into the trained long short-term memory network model, and the output is whether the user's identity verification is legal or illegal.
[0054] Combining the results of multi-factor identity authentication and the analysis results of the long short-term memory network model, when the user identity authentication passes and is legal, the user is allowed to access the data; when the user identity authentication fails or is illegal, the user is denied access to the data.
[0055] Specifically, when a user initiates a data access request, multi-factor authentication is first performed to verify the user's identity, including: password, fingerprint, facial recognition, SMS verification code, and hardware token. The password is a string of characters pre-agreed by the user and is used to verify the user's identity. Fingerprint verification involves scanning the user's fingerprint pattern and comparing it with a pre-stored fingerprint template to verify identity. Facial recognition uses a camera to capture the user's facial features, analyze facial geometry, texture, and other information, and determine whether it matches the registered facial information. The SMS verification code involves sending a one-time password to the user's registered mobile phone number, which the user enters to complete authentication. The hardware token is a physical device that generates a dynamic password, which the user must match with the requested password. The selection of these multi-factor authentication methods is based on actual circumstances and data sensitivity requirements. Historical user behavior data collected includes, but is not limited to, access time, geographic location, operation frequency, and operation sequence, which can reflect user habits and behavioral patterns. Historical device status information collected includes, but is not limited to, device type and device operating status. Device operating status includes, but is not limited to, CPU usage, memory usage, battery level, and network connection status. Historical network environment data collected includes, but is not limited to, network type, network speed, and network latency, reflecting the network environment at the time of user access. The collected historical multi-source data undergoes data preprocessing, including data cleaning and standardization, to ensure data quality and consistency. A long short-term memory (LSTM) network model is selected as a deep learning model to analyze and process the preprocessed historical multi-source data. A 70% random sample of the historical multi-source data is used as the training set, and the remaining 30% is used as the test set. Both the training and test sets contain user authentication labels indicating legal or illegal. The training set is fed into the LSTM network model for training, enabling the model to learn the behavioral characteristics of legal and illegal users. The test set is used to evaluate the performance of the LSTM network model to ensure high accuracy and generalization. After users authenticate using multi-factor authentication, multi-source data is monitored and collected in real time. The collected and preprocessed multi-source data is fed into the trained LSTM network model, which outputs a user authentication result indicating legal or illegal. Combining the results of multi-factor authentication and the analysis results of the long short-term memory network model, an access control decision is made: if the user's identity authentication passes and is legitimate, the user is allowed to access the data. If the user's identity authentication fails or is illegal, the user is denied access to the data.
[0056] In this embodiment, the step S1 of performing real-time evaluation on the user's trust probability and determining whether to grant access rights based on the user's trust probability includes the following steps:
[0057] Based on the multi-source data collected and pre-processed in real time, the probability formula for evaluating the user's trustworthiness is calculated in real time:
[0058]
[0059] Among them, A i is the value of the i-th data of user behavior data; B j is the value of the jth data of the device status information; C k is the value of the kth data in the network environment data; w i 、w j and w k are weight coefficients respectively; w0 indicates that the intercept value is 0.5; T is the user's trust value;
[0060] When the user trust probability is higher than 0.8, access permission is granted; when the user trust probability is lower than 0.8, access permission is not granted.
[0061] Specifically, the multi-source data collected and pre-processed in real time is converted into numerical form to calculate the trust probability. i 、w j and w k They are 0.5, 0.3 and 0.2 respectively; the weight coefficient is dynamically assigned to different data sources based on actual needs and experience, and the weight coefficient reflects the importance of each data source in the trust assessment. Substitute the quantified real-time multi-source data and the weight coefficient into the formula to calculate the user's trust probability. The intercept term in the formula takes a value of 0.5; the intercept term is obtained by the least squares method; in actual applications, the selection of a suitable method to solve the intercept term needs to be determined based on the characteristics of the data and the purpose of the research. Based on the user trust probability calculated in real time, this embodiment sets the threshold to 0.8. When the user trust probability is higher than 0.8, access permission is granted; when the user trust probability is lower than 0.8, access permission is not granted. The threshold is dynamically adjusted according to the actual application and the sensitivity of the data.
[0062] In this embodiment, step S2 includes the following steps:
[0063] When a user is granted access rights based on the probability of their trustworthiness, a dynamic access control mechanism is introduced by introducing roles. A deep learning model is used to automatically identify the user's role based on real-time monitored multi-source data. User roles are labeled as ordinary users, administrators, and auditors, and the labeled historical multi-source data is input into the deep learning model for training. The multi-source data collected and pre-processed in real time is input into the trained deep learning model to automatically identify and output the user's role.
[0064] Based on the identified user roles, basic permissions are assigned according to the principle of least privilege;
[0065] A dynamic permission baseline is generated based on user roles and attributes; the permission baseline dynamically adjusts user access rights based on real-time multi-source data.
[0066] Specifically, user roles are first labeled, including regular users, administrators, and auditors. Historical multi-source data with user role labels is then fed into a deep learning model for training. The goal of this training is to enable the model to learn the characteristics and behavioral patterns of users with different roles. After model training is complete, the real-time collected and pre-processed multi-source data is fed into the trained deep learning model, which automatically identifies and outputs the user's role. Based on the identified user role, basic permissions are assigned according to the principle of least privilege. The principle of least privilege states that each user is granted only the minimum permissions necessary to complete their work, reducing the potential for operational errors and abuse of permissions. In addition to basic permissions, a dynamic permissions baseline is generated based on user roles and attributes, such as position, department, and responsibilities, combined with real-time multi-source data. This dynamic permissions baseline is a set of permissions that dynamically adjusts based on real-time user behavior and environmental changes to ensure that users have appropriate access rights in the current context. By monitoring and collecting multi-source data in real time, user trust probabilities are assessed and changes in user roles are identified. When a user's trust probabilities or role changes, the user's access rights are automatically adjusted according to the dynamic permissions baseline. If a user's behavior indicates that they may be attempting unauthorized operations, their permission level may be temporarily reduced or their access to certain sensitive data may be restricted.
[0067] In this embodiment, step S3 includes the following steps:
[0068] Use micro-isolation technology to logically isolate different data resources and users to form independent security domains;
[0069] By using access control lists, firewall rules and intrusion detection or prevention systems, a protection mechanism for the security domain boundary is designed; when a user requests to access data resources in the target security domain, the protection mechanism of the current security domain boundary is broken through, and after entering the target security domain, the system returns to step S1 for identity authentication and authorization again; when the user performs data access operations in the target security domain, the user is monitored in real time.
[0070] Specifically, micro-segmentation technology uses a software-defined approach to achieve distributed and adaptive network isolation by separating the policy control center from the policy execution unit. It eliminates the concept of internal and external networks and instead isolates the data center network into numerous tiny computing units or nodes. Each node must authenticate itself by the micro-segmentation client before accessing resources from other nodes. If a node fails authentication or lacks access rights, the client will intercept the access. Different data resources and users are divided into several tiny network nodes based on specific principles. Access control is applied to these nodes based on dynamic policy analysis, logically isolating them and restricting user lateral movement. When a user requests access to data resources in the target security domain, they must first bypass the protection mechanisms of the current security domain boundary, including access control lists, firewall rules, and intrusion detection. Upon entering the target security domain, the user must re-authenticate and re-authorize, returning to step S1. Users are monitored in real time as they access data within the target security domain.
[0071] In this embodiment, step S4 includes the following steps:
[0072] Use the AES-256 algorithm to encrypt data resources; use quantum key distribution technology to generate AES keys, and distribute the AES keys to the server through the asymmetric encryption RSA algorithm;
[0073] The encrypted data resources are transmitted over the network, using the encryption protection protocols TLS and SSL for encrypted transmission and end-to-end encryption;
[0074] Data resources are stored on the server side, using full disk encryption or file encryption technology to keep the stored data resources encrypted until authorized access.
[0075] Specifically, AES-256 is an advanced encryption standard that converts the data to be encrypted into a byte array. This byte array is then encrypted using the AES-256 algorithm and the generated key to produce the encrypted data. Quantum key distribution (QKD) is a technology that leverages the principles of quantum mechanics to securely transmit keys between communicating parties. QKD generates a secure AES key, which is then encrypted using the asymmetric RSA algorithm and distributed to the server. The RSA algorithm uses a public key to encrypt the key and a private key to decrypt it, ensuring the security of the AES key during transmission. After receiving the encrypted AES key, the server uses its own private key to decrypt it, obtaining the plaintext AES key. Both the server and client should properly safeguard the AES key to ensure its security and confidentiality. The TLS transport layer security protocol and the SSL secure socket layer protocol are protocols used to provide confidentiality and data integrity between two communicating applications. They establish an encrypted channel between the client and server, ensuring that transmitted data cannot be eavesdropped or tampered with. The client and server perform a handshake to negotiate the encryption algorithm and key. The encrypted data is then encrypted using the agreed-upon encryption algorithm and key for transmission. During transmission, TLS and SSL protocols provide integrity verification and encryption to ensure data confidentiality and integrity. Servers can use full-disk encryption or file encryption to store data resources. Full-disk encryption encrypts the entire disk or partition, while file encryption encrypts individual files. Regardless of the storage method used, ensure that stored data resources remain encrypted until authorized access.
[0076] In this embodiment, step S5 includes the following steps: when the user completes access to the data, the permission recovery mechanism is automatically triggered by exiting the data access operation or detecting that the user has not performed any operation for a long time; the permission recovery mechanism includes: immediately revoking all temporary permissions granted to the user during the access process, clearing the user's temporary data, and recording the permission recovery event in the log.
[0077] Specifically, the permission revocation mechanism is automatically triggered when a user completes data access or when a prolonged period of user inactivity is detected. These two conditions ensure timely permission revocation, preventing abuse of permissions due to users forgetting to log out and addressing security risks that may arise from prolonged user inactivity. All temporary permissions granted to the user during the access process are automatically revoked, including read, write, and execute permissions on data resources. This revocation ensures that the user can no longer access the data resources previously granted permissions. All temporary data generated during the user's access process is cleared, including cached data, session data, and temporary files. This clearing of temporary data prevents the user from accessing or using this data. Permission revocation events are logged, including the user who revoked the permissions, the time of revocation, the type of permissions revoked, and the reason for revocation. The permission revocation mechanism is implemented using database access control technology. When a user completes data access or has been inactive for an extended period, the database access control module automatically revokes the user's temporary permissions and clears the associated temporary data. Logging can also be used to record permission revocation events.
[0078] The above embodiments are only used to illustrate the technical method of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical method of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical method of the present invention.
Claims
1. A data access control method based on a zero-trust architecture, characterized in that: The following steps are involved: S1: When a user initiates a data access request, a multi-factor authentication method combined with a deep learning model is used to verify the user's identity. The user's trust probability is evaluated in real time and the decision on whether to grant access rights is made based on the user's trust probability. S2: Based on the user's trust probability, by combining the user's role and attributes, access rights are dynamically allocated using the principle of least privilege in the zero trust architecture; S3: Use micro-segmentation technology to logically isolate different data resources and users to form independent security domains. When users access data, they break through the boundary protection of the current security domain and enter the target security domain, and then perform step S1 again. S4: When users access data, data resources are encrypted in real time; S5: Automatically revoke the temporarily granted access rights after the user completes data access.
2. A data access control method based on a zero trust architecture according to claim 1, characterized in that: In step S1, when a user initiates a data access request, a multi-factor identity authentication method combined with a deep learning model is used to verify the user's identity, including the following steps: When a user initiates a data access request, the user is verified using a multi-factor authentication method; the multi-factor authentication method includes: password, fingerprint, facial recognition, SMS verification code and hardware token; Collect historical multi-source data including: user behavior data, device status information, and network environment data; the user behavior data includes: access time, geographic location, operation frequency, and operation sequence; the device status information includes: device type and device operating status; the network environment data includes: network type, network speed, and network latency; Data preprocessing of collected historical multi-source data includes: cleaning data and standardizing data formats; By selecting a long short-term memory network model from a deep learning model, 70% of the historical multi-source data is randomly sampled as a training set, and the remaining 30% of the historical multi-source data is used as a test set; both the training set and the test set are labeled with user authentication, including: legal and illegal; the training set is input into the long short-term memory network model for training; and the test set is used to evaluate the performance of the long short-term memory network model; After the user uses multi-factor authentication, multi-source data is monitored and collected in real time. The collected and pre-processed multi-source data is input into the trained long short-term memory network model, and the output is whether the user's identity verification is legal or illegal. Combining the results of multi-factor identity authentication and the analysis results of the long short-term memory network model, when the user identity authentication passes and is legal, the user is allowed to access the data; when the user identity authentication fails or is illegal, the user is denied access to the data.
3. A data access control method based on a zero trust architecture according to claim 2, characterized in that: The step S1 includes the following steps: evaluating the user's trust probability in real time and determining whether to grant access rights based on the user's trust probability: Based on the multi-source data collected and pre-processed in real time, the probability formula for evaluating the user's trustworthiness is calculated in real time: Among them, A i is the value of the i-th data of user behavior data; B j is the value of the jth data of the device status information; C k is the value of the kth data in the network environment data; w i 、w j and w k are weight coefficients respectively; w0 indicates that the intercept value is 0.5; T is the user's trust value; When the user trust probability is higher than 0.8, access permission is granted; when the user trust probability is lower than 0.8, access permission is not granted.
4. A data access control method based on a zero trust architecture according to claim 3, characterized in that: The step S2 comprises the following steps: When a user is granted access rights based on the probability of their trustworthiness, a dynamic access control mechanism is introduced by introducing roles. A deep learning model is used to automatically identify the user's role based on real-time monitored multi-source data. User roles are labeled as ordinary users, administrators, and auditors, and the labeled historical multi-source data is input into the deep learning model for training. The multi-source data collected and pre-processed in real time is input into the trained deep learning model to automatically identify and output the user's role. Based on the identified user roles, basic permissions are assigned according to the principle of least privilege; A dynamic permission baseline is generated based on user roles and attributes; the permission baseline dynamically adjusts user access rights based on real-time multi-source data.
5. The data access control method based on zero trust architecture according to claim 1 is characterized in that: The step S3 comprises the following steps: Use micro-isolation technology to logically isolate different data resources and users to form independent security domains; By using access control lists, firewall rules and intrusion detection or prevention systems, a protection mechanism for the security domain boundary is designed; when a user requests to access data resources in the target security domain, the protection mechanism of the current security domain boundary is broken through, and after entering the target security domain, the system returns to step S1 for identity authentication and authorization again; when the user performs data access operations in the target security domain, the user is monitored in real time.
6. The data access control method based on zero trust architecture according to claim 1 is characterized in that: The step S4 comprises the following steps: Use the AES-256 algorithm to encrypt data resources; use quantum key distribution technology to generate AES keys, and distribute the AES keys to the server through the asymmetric encryption RSA algorithm; The encrypted data resources are transmitted over the network, using the encryption protection protocols TLS and SSL for encrypted transmission and end-to-end encryption; Data resources are stored on the server side, using full disk encryption or file encryption technology to keep the stored data resources encrypted until authorized access.
7. The data access control method based on zero trust architecture according to claim 1, characterized in that: Said step S5 comprises the following steps: when the user completes access to the data, the permission recovery mechanism is automatically triggered by exiting the data access operation or detecting that the user has not performed any operation for a long time; said permission recovery mechanism comprises: immediately revoking all temporary permissions granted to the user during the access process, clearing the user's temporary data and recording the permission recovery event in the log.
Citation Information
Cited By
Micro-service security isolation method and system for multi-tenant SaaS platform
CN121262021A
Micro-service security isolation method and system for multi-tenant saas platform
CN121262021B