Access control method and device based on context awareness, equipment and medium

Through a context-aware access control method, the permission control model is used to dynamically configure access permissions and monitor activities, solving the problem of lagging permission adjustment in the prior art, improving the flexibility of access control and data security.

CN120528653APending Publication Date: 2025-08-22CHINA PING AN LIFE INSURANCE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510659418.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-21
Publication Date
2025-08-22

AI Technical Summary

Technical Problem

Existing access control solutions are difficult to adapt to changing data access needs in the face of complex and changing enterprise environments, resulting in lagging permission adjustments and increasing security risks.

Method used

By collecting user login data and operation behavior data, a context description is generated, and a pre-built and trained permission control model is used to predict permissions, dynamically configure access permissions, and monitor access activities in real time, triggering permission alerts to prevent behaviors beyond the scope of permissions.

Benefits of technology

It realizes flexible access permission control, improves adaptability with different access needs, reduces data security risks, and promptly detects and handles abnormal behaviors.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120528653A_ABST
    Figure CN120528653A_ABST
Patent Text Reader

Abstract

The invention relates to the field of big data, can be applied to business system platforms of financial science and technology, medical health and the like, and discloses an access control method, device and equipment based on context awareness and a medium. Generating context description of a data access request initiated by the current user according to the login data and the operation behavior data; performing permission prediction processing on the context background description in a pre-constructed and trained permission control model, and determining corresponding access permission configuration; setting a permission range of the data access request according to the access permission configuration, and monitoring access activity information; and when it is monitored that the access activity information exceeds the permission range, triggering a corresponding permission alarm. According to the method, the context information of the data access request of the user is combined to perform permission self-adaptive configuration, so that the flexibility of access permission control and the adaptability between different access requirements are improved, and the data security risk is reduced as much as possible.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of big data technology, and in particular to a context-aware access control method, apparatus, device, and medium. Background Art

[0002] With the widespread adoption of the internet and the development of IoT technology, the amount of data generated by enterprises is exploding daily. This data is not only massive in scale but also diverse in type. Consequently, big data processing technologies such as Hadoop and Spark are gaining increasing attention. Data security is paramount in big data processing, and in the Hadoop ecosystem, access control is key to protecting sensitive data from unauthorized access.

[0003] For example, in the financial sector, data security and compliance are crucial. Financial institutions (such as banks, securities firms, and insurance companies) handle large amounts of sensitive information, including personal customer information, account balances, transaction records, investment portfolios, and risk assessment reports. This data not only affects customer privacy but also the operational security and reputation of the financial institution. Therefore, access control must be implemented for all data to comply with financial industry laws, regulations, and regulatory requirements, preventing legal risks arising from non-compliant operations.

[0004] For example, in the healthcare sector, data security and privacy protection are equally crucial. Medical institutions (such as hospitals, clinics, and insurance companies) process large amounts of patient personal information, medical records, diagnostic results, treatment plans, and insurance claims information. Access to this data must consider patient privacy protection, medical compliance requirements, clinical research, and other requirements. Therefore, reliable access control is also necessary to ensure the quality and security of medical services.

[0005] However, existing access control solutions mainly rely on static rules and predefined role permission allocation, which is not flexible enough in the face of complex and changing enterprise environments. It is difficult to adapt to the ever-changing data access environment, resulting in delayed permission adjustments and increased security risks. Summary of the Invention

[0006] In view of the above-mentioned deficiencies in the prior art, the purpose of the present invention is to provide a context-aware access control method, device, equipment and medium that can be applied to the medical field, financial technology or other related fields. Its main purpose is to achieve flexible access permission control, improve the flexibility of responding to business needs, and reduce data security risks.

[0007] The technical solutions of the present invention are as follows:

[0008] A first aspect of the present invention provides a context-aware access control method, comprising:

[0009] Collecting the login data and operation behavior data of the current user, and generating a context description of the data access request initiated by the current user based on the login data and operation behavior data;

[0010] Perform permission prediction processing on the context description using a pre-built and trained permission control model to determine the corresponding access permission configuration;

[0011] Setting the permission scope of the data access request according to the access permission configuration and monitoring access activity information;

[0012] When it is detected that the access activity information exceeds the permission range, a corresponding permission alarm is triggered.

[0013] A second aspect of the present invention provides a context-aware access control device, comprising:

[0014] A context collection module is used to collect the login data and operation behavior data of the current user, and generate a context description of the data access request initiated by the current user based on the login data and operation behavior data;

[0015] A permission configuration module is used to perform permission prediction processing on the context description using a pre-built and trained permission control model to determine the corresponding access permission configuration;

[0016] A setting and monitoring module, configured to set the permission scope of the data access request according to the access permission configuration and monitor access activity information;

[0017] The alarm module is used to trigger a corresponding permission alarm when it is detected that the access activity information exceeds the permission range.

[0018] A third aspect of the present invention provides a computer device comprising at least one processor; and

[0019] a memory communicatively connected to the at least one processor; wherein,

[0020] The memory stores instructions that can be executed by the at least one processor. The instructions are executed by the at least one processor to enable the at least one processor to perform the above-mentioned context-awareness-based access control method.

[0021] A fourth aspect of the present invention provides a non-volatile computer-readable storage medium, which stores computer-executable instructions. When the computer-executable instructions are executed by one or more processors, the one or more processors can execute the above-mentioned context-aware access control method.

[0022] Beneficial effects: The present invention discloses a context-aware access control method, apparatus, device and medium. Compared with the prior art, the embodiments of the present invention collect the login data and operation behavior data of the current user, and generate a context background description of the data access request initiated by the current user based on the login data and operation behavior data; perform permission prediction processing on the context background description in a pre-built and trained permission control model to determine the corresponding access permission configuration; set the permission range of the data access request according to the access permission configuration, and monitor access activity information; trigger a corresponding permission alarm when it is detected that the access activity information exceeds the permission range. By combining the context information of the user data access request for permission adaptive configuration and timely outputting an alarm when the access activity exceeds the permission range, the flexibility of access permission control and its adaptability to different access requirements are improved, thereby minimizing data security risks. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] In order to more clearly illustrate the solutions in the present invention, a brief introduction is given below to the drawings required for use in describing the embodiments of the present invention. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0024] Figure 1 A schematic diagram of an application environment for the context-aware access control method provided by an embodiment of the present invention;

[0025] Figure 2 A flow chart of a context-aware access control method provided by an embodiment of the present invention;

[0026] Figure 3 Another flow chart of the context-aware access control method provided by an embodiment of the present invention;

[0027] Figure 4 A flowchart of step S201 in the context-aware access control method provided by an embodiment of the present invention;

[0028] Figure 5 A flowchart of step S202 in the context-aware access control method provided in an embodiment of the present invention;

[0029] Figure 6 A schematic diagram of the functional modules of a context-aware access control device provided by an embodiment of the present invention;

[0030] Figure 7 A schematic diagram of the hardware structure of a computer device provided in an embodiment of the present invention. DETAILED DESCRIPTION

[0031] To make the objectives, technical solutions, and effects of the present invention more clear and distinct, the present invention is further described in detail below. It should be understood that the specific embodiments described herein are merely for the purpose of explaining the present invention and are not intended to limit the present invention. The embodiments of the present invention are described below with reference to the accompanying drawings.

[0032] The context-aware access control method provided by the embodiment of the present invention can be applied in the following situations: Figure 1 In an application environment, the system includes a first terminal device 101, a second terminal device 102, a third terminal device 103, a network 104, and a server 105. The network 104 is a medium for providing a communication link between the first terminal device 101, the second terminal device 102, the third terminal device 103, and the server 105. The network 104 may include various connection types, such as wired and / or wireless communication links, etc.

[0033] The user may use the first terminal device 101, the second terminal device 102, and the third terminal device 103 to interact with the server 105 via the network 104 to receive or send messages, etc. Various communication client applications may be installed on the first terminal device 101, the second terminal device 102, and the third terminal device 103, such as knowledge reading applications, web browser applications, search applications, instant messaging tools, email clients, and / or social platform software (for example only).

[0034] The first terminal device 101 , the second terminal device 102 , and the third terminal device 103 may be various electronic devices having display screens and supporting web browsing, including but not limited to smart phones, tablet computers, laptop computers, desktop computers, and the like.

[0035] The server 105 may be a server that provides various services, such as a backend server that provides support for the content browsed by the user using the first terminal device 101, the second terminal device 102, and the third terminal device 103 (for example only). The backend server may analyze and process the received user requests and other data, and feed back the processing results (such as web pages, information, or data obtained or generated according to the user request) to the terminal device. The server 105 may be a cloud server, also known as a cloud computing server or cloud host, which is a host product in the cloud computing service system to solve the defects of difficult management and weak business scalability in traditional physical hosts and VPS services ("Virtual Private Server", or "VPS" for short). The server 105 may also be a server for a distributed system, or a server combined with a blockchain.

[0036] It should be noted that the context-aware access control method provided in the embodiments of the present application can generally be executed by the first terminal device 101, the second terminal device 102, or the third terminal device 103. Accordingly, the context-aware access control apparatus provided in the embodiments of the present invention can also be set in the first terminal device 101, the second terminal device 102, or the third terminal device 103. Alternatively, the context-aware access control method provided in the embodiments of the present invention can generally be executed by the server 105. Accordingly, the context-aware access control apparatus provided in the embodiments of the present invention can generally be set in the server 105.

[0037] It should be understood that the numbers of the above terminal devices, networks and servers are merely illustrative and any number of terminal devices, networks and servers may be provided as required.

[0038] like Figure 2 As shown, the context-aware access control method provided by the embodiment of the present invention specifically includes the following steps:

[0039] S201: Collect the login data and operation behavior data of the current user, and generate a context description of the data access request initiated by the current user based on the login data and operation behavior data.

[0040] In this embodiment, when a user logs in to the system and performs relevant operations to initiate a data access request, the current user's login data is collected, that is, the data generated when the user logs in to the system, including login time, location, device type, identity information, etc., and the current user's operation behavior data is also collected, that is, the data generated when the user performs operations in the system, including operation type, operation timestamp, data type, etc.

[0041] In specific implementations, for the collection of login data, the timestamp of the user logging into the system is recorded as the login time; the user's geographic location information is obtained through IP address resolution, or the IP address is directly recorded as the login location; the type of device used by the user to log in (such as PC, mobile device, operating system version, etc.) is recorded; and the user's identity information, such as user ID, department, position, etc., is recorded. For the collection of operational behavior data, the types of operations performed by the user (such as query, update, delete, download, etc.) are recorded; the types of data the user currently or requests to access (such as sensitive data, general data, public data, etc.) are recorded; and the types of tasks the user currently or requests to perform (such as routine query, data analysis, report generation, etc.) are recorded.

[0042] The collected login and operational data generates a contextual description of the data access request initiated by the current user. This description comprehensively describes the user's current access request, including information such as user identity, login time and location, operation type, and data type. By collecting rich contextual information, we can more accurately evaluate user access requests, provide more flexible access control policies, and help identify abnormal behavior patterns and promptly detect potential security threats.

[0043] For example, in a banking system in the financial field, the time, location, and device type of the account manager's login to the system, as well as the operations performed (such as querying customer account balances, modifying customer information, etc.) are recorded. Based on this information, a context description is generated for subsequent permission prediction.

[0044] In the healthcare sector, hospital information systems record the time, location, and device type of doctors logging into the system, as well as the actions they perform (such as querying patient medical records and issuing prescriptions). This information is used to generate contextual descriptions for subsequent permission predictions.

[0045] S202: Perform permission prediction processing on the context description using a pre-built and trained permission control model to determine corresponding access permission configuration.

[0046] In this embodiment, a permission control model is pre-built and trained. This permission control model uses machine learning algorithms (such as K-means, decision trees, neural networks, etc.) to learn and train historical access records to obtain a mapping relationship between context information and permissions. This allows the trained model to perform permission prediction processing based on the current context description input, automatically recommend the optimal permission setting, and thus determine the corresponding access permission configuration. Through the machine learning model, access permission configurations can be predicted more efficiently and accurately based on the context description, achieving automated generation of permission configurations, reducing the need for manual permission setting, and achieving more accurate permission management.

[0047] For example, in the financial field, based on the context description (such as department, position, operation type, etc.) of the data access request initiated by the account manager, the permission control model predicts the permission level (such as read-only, editable, etc.) to access customer account information.

[0048] In the healthcare field, based on the contextual description of the doctor's data access request (such as department, position, operation type, etc.), the permission control model predicts the permission level of the doctor to access the patient's medical records (such as read-only, editable, etc.).

[0049] S203: Setting the permission scope of the data access request according to the access permission configuration, and monitoring access activity information.

[0050] In this embodiment, after the access permission configuration is automatically generated based on context awareness, the current user is assigned a corresponding permission range, namely the data range and permission level that the user is allowed to access and operate. By setting the user's access permission in the system, the access and operation of the data by the current data access request is restricted. When the user begins to access the data, the agent program or log analysis tool deployed in the network monitors the user's access activity information in real time. This access activity information is a record of the user's access behavior in the system, including access time, access data type, operation type, etc. By setting the permission range, the user's access rights are restricted, data leakage and abuse are prevented, and data security is improved. In addition, by monitoring access activities in real time, abnormal behavior can be discovered and handled in a timely manner, ensuring a rapid response to abnormal access behavior.

[0051] For example, in the financial sector, access rights are dynamically assigned based on the user's identity (e.g., account manager, customer service representative, etc.) and contextual description (e.g., login time, login location, task type, etc.). For example, when an account manager logs into the system through the company intranet during working hours, they can access the customer's account balance and transaction history, but can only perform query operations (read-only permissions); customer service representatives can access the customer's contact information and basic account information to handle customer inquiries, but cannot view the customer's transaction history, etc. Furthermore, the monitoring system continuously analyzes user access behavior to detect any abnormal behavior (e.g., access to unauthorized data, access to sensitive information during non-working hours, etc.).

[0052] In the healthcare field, access rights are dynamically assigned based on the identity of the medical staff (such as doctors, nurses, laboratory technicians, etc.) and context descriptions (such as login time, login location, task type, etc.). For example, the attending physician can access the patient's complete medical records, diagnosis results and treatment plans, including modification permissions; nurses can access the patient's medical records and treatment plans, but can only perform query operations (read-only permissions). Continuously analyze the access behavior of medical staff to detect any abnormal behavior (such as accessing unauthorized medical records, accessing sensitive information during non-working hours, etc.)

[0053] S204: When it is detected that the access activity information exceeds the permission range, a corresponding permission alarm is triggered.

[0054] In this embodiment, monitored access activity information is matched against the user's permission range to check for any behavior that exceeds the permission range. If behavior that exceeds the permission range is identified, such as accessing unauthorized data types or performing unauthorized operations, a corresponding permission alert is triggered and sent to the system administrator or relevant personnel, informing them to take appropriate measures. Preferably, abnormal access behavior can also be automatically blocked to ensure data access security as much as possible. By monitoring access activity and triggering alerts, abnormal behavior can be discovered and handled in a timely manner, preventing data leakage and abuse, and improving system security.

[0055] For example, in the financial sector, if an account manager is detected accessing sensitive client information through the company intranet outside of working hours, or a customer service representative attempts to access a client's transaction records; or in the healthcare sector, if a nurse is detected attempting to modify a patient's medical record, a permission alert will be immediately triggered and the system administrator will be notified. A detailed event log will also be recorded for subsequent investigation. Through real-time monitoring and alert mechanisms, abnormal behavior can be promptly detected and addressed, effectively protecting the security and privacy of sensitive data.

[0056] In the above embodiment, the present invention discloses an access control method based on context perception, which collects the login data and operation behavior data of the current user, generates a context background description of the data access request initiated by the current user based on the login data and operation behavior data; performs permission prediction processing on the context background description in a pre-built and trained permission control model to determine the corresponding access permission configuration; sets the permission range of the data access request based on the access permission configuration, and monitors the access activity information; triggers the corresponding permission alarm when it is detected that the access activity information exceeds the permission range. By combining the context information of the user data access request for permission adaptive configuration and outputting an alarm in time when the access activity exceeds the permission range, the flexibility of access permission control and the adaptability to different access requirements are improved, and the data security risk is reduced as much as possible.

[0057] In one embodiment, Figure 3 As shown, after step S202, the method further includes:

[0058] S301, obtaining preset fine-grained access control rules and user attributes of the current user;

[0059] S302: Match the user attributes with the fine-grained access control rules to obtain a corresponding fine-grained access adjustment policy;

[0060] S303: Perform fine-grained access rule adjustment on the currently generated access permission configuration according to the fine-grained access adjustment policy to obtain an adjusted access permission configuration.

[0061] In this embodiment, after automatically generating access rights configuration based on context awareness, an attribute-driven access control mechanism is introduced. A set of fine-grained access control rules is pre-defined. These rules define specific permissions based on user attributes (such as department, position, and responsibilities) and operation context (such as time, location, and task type), achieving more detailed access control. The fine-grained access control rules can be manually defined by the system administrator or automatically generated by a machine learning algorithm. In addition to basic attributes such as department, position, and responsibilities, user attributes can also include biometrics (such as fingerprints and facial recognition) or behavioral characteristics (such as operation frequency and operation type). For example, in a banking system, the corresponding fine-grained access control rules are obtained, along with the account manager's department (such as credit department), position (such as senior account manager), and task type (such as loan approval); in a hospital information system, the corresponding fine-grained access control rules are obtained, along with the doctor's department (such as internal medicine), position (such as attending physician), and task type (such as patient diagnosis). By obtaining fine-grained access control rules, access rights can be dynamically adjusted based on the user's specific attributes, more accurately restricting the user's access behavior.

[0062] Based on the acquired user attributes and fine-grained access control rules, the user attributes of the current user (such as department, position, responsibility, etc.) are matched with the fine-grained access control rules to find applicable rules. Specifically, the matching can be performed through a simple rule engine, or through a machine learning algorithm (such as decision tree, random forest, etc.), which is not limited in this embodiment. A corresponding fine-grained access adjustment policy is generated based on the matching results. The adjustment policy includes specific adjustment suggestions for access rights, such as limiting access time, limiting access data type, etc. According to the fine-grained access adjustment policy, the currently generated access rights configuration is adjusted, and the adjusted access rights configuration is applied to the system to update the user's access rights. Preferably, while the access rights configuration is automatically adjusted according to the fine-grained access adjustment policy, manual adjustment rights are also retained, that is, the administrator can manually modify the currently generated access rights configuration based on the matching results and the fine-grained access adjustment policy to ensure the accuracy of the rights configuration.

[0063] In one embodiment, Figure 4 As shown, step S201 includes:

[0064] S401: Collect the login data and operation behavior data of the current user, perform data screening on the login data and operation behavior data, and obtain key data related to data access security;

[0065] S402: When a user initiates a data access request, a corresponding background description template is called according to the current business scenario, and data is filled into the background description template based on the key data to generate a context description of the data access request.

[0066] In this embodiment, when generating the context description of the data access request, the login data of the current user is collected, including the user's login time, login location (IP address, geographic location), device type used (such as PC, mobile device, operating system version, etc.), user identity information (such as user ID, department, position, etc.), and the current user's operation behavior data, including the user's operation behavior in the system, including operation type (such as query, update, delete, download, etc.), operation timestamp, accessed data type (such as sensitive data, ordinary data, public data, etc.), task type (such as regular query, data analysis, report generation, etc.). According to the requirements of data access security, key data fields related to data access security are pre-defined, such as login time, login location, operation type, data type, etc., and key data directly related to data access security, such as login time, login location, operation type, data type, etc., are extracted from the data through data screening processing such as rule-based screening or statistical-based screening, ensuring that only key data related to security is used for subsequent access control decisions, reducing the possibility of misjudgment and improving data processing efficiency.

[0067] When a user initiates a data access request, the system identifies the current business scenario based on the user's operation type, task type, data type, and other information. Examples include general queries, data analysis, and report generation. Based on the identified business scenario, the corresponding context description template is invoked. Each template contains fields and formats relevant to the business scenario. Extracted key data is then populated into the corresponding context description template to generate a detailed, contextual description. The context description can also be dynamically adjusted based on real-time data to ensure its timeliness and accuracy.

[0068] For example, when an account manager initiates a request to query a customer's account balance, the current business scenario is identified as "general query" and the corresponding background description template is called. Key data (such as login time, operation type, and data type) are filled into the template to generate a contextual description, such as:

[0069] User ID:12345

[0070] Department: Credit Department

[0071] Position: Senior Account Manager

[0072] Login time: 2025-04-30 09:00:00

[0073] Login location:Company intranet

[0074] Device type: Windows 10 PC

[0075] Current operation type: Query

[0076] Operation timestamp: 2025-04-30 09:05:00

[0077] Operation data type: customer account balance

[0078] Current task type: General query

[0079] Network environment: company intranet

[0080] Is it during working hours: Yes

[0081] For example, when a doctor initiates a request to query a patient's medical records, the current business scenario is identified as "patient diagnosis" and the corresponding background description template is called. Key data (such as login time, operation type, and data type) are filled into the template to generate a context description, such as:

[0082] User ID:67890

[0083] Department: Internal Medicine

[0084] Position: Attending Physician

[0085] Login time: 2025-04-30 09:00:00

[0086] Login location: Hospital intranet

[0087] Device type: Windows 10 PC

[0088] Current operation type: Query

[0089] Operation timestamp: 2025-04-30 09:05:00

[0090] Data type operated on: patient medical records

[0091] Current task type: Patient diagnosis

[0092] Network environment: Hospital intranet

[0093] Is it during working hours: Yes

[0094] By comprehensively collecting users' login data and behavior data, a comprehensive and detailed context description is generated. This multi-dimensional perception method can more accurately reflect the user's current access status and behavior characteristics, providing a more reliable basis for dynamic access control decisions.

[0095] In one embodiment, Figure 5 As shown, step S202 includes:

[0096] S501, performing feature extraction processing on the context background description to obtain corresponding context features;

[0097] S502: Input the context features into a pre-built and trained permission control model, where the permission control model is built and trained based on a clustering algorithm;

[0098] S503: Calculate the distance between the context feature and each cluster center in the authority control model, where each cluster center has a corresponding behavior pattern category;

[0099] S504: Identify the behavior pattern category of the closest cluster center as the predicted behavior pattern of the current user, query a preset mapping table according to the predicted behavior pattern, and obtain access permission configuration corresponding to the predicted behavior pattern.

[0100] In this embodiment, when automatically generating access rights configuration based on context awareness, feature extraction is first performed on the context description to extract feature vectors that can be used for model input. For example, user identity information (such as user ID, department, position, etc.) can be converted into one-hot encoding; time information (such as access time, login time) can be converted into timestamps or time periods (such as working hours / non-working hours); location information (such as IP address, geographic location) can be converted into geographic coordinates or area codes; the nature of the operation (such as read, write, modify) can be converted into category labels, and so on. Through feature extraction, complex context descriptions are converted into feature vectors that can be processed by the model, improving the input quality of the model and ensuring the accuracy of the access configuration.

[0101] The extracted context features are input into a pre-built and trained permission control model. This model is built and trained based on a clustering algorithm (such as K-means, DBSCAN, etc.), that is, the feature data is trained using a clustering algorithm to build a permission control model. Each cluster center represents a category of user behavior pattern. The extracted context features are input into the permission control model, and the distance between the input context features and each cluster center in the permission control model is calculated using distance measurement methods such as Euclidean distance, cosine distance, Manhattan distance, Mahalanobis distance, etc., so as to find the cluster center with the closest distance, and confirm the behavior pattern category corresponding to the cluster center as the predicted behavior pattern of the current user. By calculating the distance, the predicted behavior pattern of the current user can be accurately identified, thereby improving the accuracy of classification.

[0102] After confirming the behavior pattern category of the nearest cluster center as the current user's predicted behavior pattern, the access rights configuration corresponding to the predicted behavior pattern is retrieved through a preset mapping table query. Specifically, during clustering algorithm training, each cluster category is analyzed to determine the typical behavior patterns and contextual characteristics of users in that category. The most appropriate permission configuration is assigned to each category and a corresponding preset mapping table is generated. This establishes a mapping relationship between category and permission configuration, allowing for quick querying of the corresponding access rights configuration in the mapping table based on the confirmed predicted behavior pattern. By leveraging the intelligent model built using the clustering algorithm, dynamic prediction and optimization of access rights configurations are achieved, providing more intelligent and refined data security management.

[0103] In one embodiment, the method further comprises:

[0104] If the context feature does not match the behavior pattern category of all current cluster centers, it is marked as an abnormal behavior pattern;

[0105] Summarize all context descriptions marked as abnormal behavior patterns at preset intervals, and perform cluster learning on the authority control model based on the summary results to obtain new cluster centers and new behavior pattern categories;

[0106] The preset mapping table is updated with permission configuration according to the new cluster center and the new behavior pattern category.

[0107] In this embodiment, the permission control model obtained by training based on the clustering algorithm can not only identify known types of access patterns, but also capture new behavioral features to achieve more accurate and comprehensive permission management. Specifically, the extracted context features are input into the permission control model, and the distance between the context features and all cluster centers is calculated. If the distance between the context features and all cluster centers is greater than a preset threshold, or no matching behavior pattern category is found, the context feature is marked as an abnormal behavior pattern, and the context background description marked as the abnormal behavior pattern is recorded, including detailed information such as user ID, login time, login location, operation type, data type, etc. By marking abnormal behavior patterns, potential security threats can be discovered in a timely manner or data support can be provided for subsequent model updates, thereby enhancing the model's adaptability to new behavior patterns.

[0108] At preset intervals (e.g., weekly, monthly, etc.), all contextual descriptions of abnormal behavior patterns are collected, and these abnormal behavior patterns are summarized to form an abnormal behavior pattern dataset. Based on the summary results, cluster learning is performed on the permission control model. That is, cluster learning is performed on the abnormal behavior pattern data collected over a period of time through a clustering algorithm (e.g., K-means, DBSCAN), generating new cluster centers and new behavior pattern categories. By regularly learning new behavior patterns, the model can adapt to changes in user behavior, improving the model's adaptability and accuracy. Based on the new cluster centers and new behavior pattern categories, the preset mapping table is updated, and the new behavior pattern categories and their corresponding access permission configurations are added to the mapping table. By dynamically updating the mapping table, the access permission configuration can be flexibly adjusted according to the new behavior pattern, and reasonable access permissions can be assigned to the new behavior pattern, reducing potential security risks.

[0109] In one embodiment, before step S202, the method further includes:

[0110] Collecting historical access records and constructing context training data based on the historical access records;

[0111] Constructing an initial permission control model, randomly initializing several cluster centers, assigning the context training data to the nearest cluster center, and recalculating the cluster center of each category;

[0112] Repeat the cluster center update process until the preset convergence condition is met to obtain several trained cluster centers, each of which corresponds to a behavior pattern category;

[0113] Perform permission configuration analysis on the behavior pattern category of each cluster center, set corresponding access permission configuration for each behavior pattern category, and generate a corresponding preset mapping table.

[0114] In this embodiment, during the model training phase, historical access records of users are first collected from the access control system, including user identity information, access time, access location, access device type, access data type, operation nature, etc., and corresponding background descriptions are generated based on the historical access records to construct context training data. An initial permission control model is constructed, that is, a suitable clustering algorithm, such as K-means or DBSCAN, is selected, and several data points are randomly selected as initial cluster centers. Each data point in the context training data is assigned to the nearest cluster center, and then the cluster center of each category is recalculated, for example, by taking the mean of all data points in the category. The process of iteratively assigning data points and updating cluster centers is repeated until convergence conditions are met, such as the change in cluster center is less than a certain threshold, or the maximum number of iterations is reached, thereby obtaining the final cluster center. Each cluster center corresponds to a behavior pattern category, that is, data belonging to the same category have user behavior patterns similar to the cluster center.

[0115] Analyze the behavior pattern category of each cluster center to determine the typical characteristics and behavior patterns of the category. Then analyze its access permission requirements based on the characteristics of the behavior pattern category. For example, some categories may require higher permissions to access sensitive data, while other categories may only require lower permissions. Based on the permission requirements of the behavior pattern category, the corresponding access permission configuration is assigned to it. Based on the mapping relationship between the behavior pattern category and the access permission configuration, a corresponding mapping table is generated.

[0116] In one embodiment, after step S202, the method further includes:

[0117] Receive user feedback on the execution of the access rights configuration and regularly collect the latest business demand information;

[0118] Evaluate the performance of the permission control model based on the execution feedback information and the latest business demand information to obtain corresponding performance indicators;

[0119] When the performance indicator is lower than a preset threshold, the authority control model is updated according to the execution feedback information and the latest business demand information.

[0120] In this embodiment, after automatically generating access permission configuration feedback, users can provide corresponding execution feedback information through the feedback mechanism. For example, users can provide feedback on whether the permission settings are reasonable, whether there are insufficient permissions, or whether there are excessive permissions. The user's feedback information is recorded in the system, including the user ID, feedback content, feedback time, etc. By receiving user feedback, user needs can be better met and the system usability can be improved. At the same time, business requirement information is collected. For example, the latest business requirement information is regularly collected through questionnaires and interviews, or information related to business requirements is extracted by analyzing system logs, such as user access frequency and commonly used functions. By regularly collecting business requirement information, access control policies can be adjusted in a timely manner to adapt to business changes.

[0121] The performance of the permission control model is evaluated based on execution feedback information and the latest business demand information. For example, the accuracy of the access permission configuration predicted by the model is evaluated, whether the model can adapt to new business needs and changes in user behavior, and the response time and computing resource consumption of the model are evaluated. Several performance indicators are obtained, including accuracy, adaptability, and efficiency, to quantitatively evaluate the model performance, ensure that the model's performance meets business needs, and improve system reliability. The threshold of the performance indicator is set according to business needs and security requirements. When the performance indicator falls below the preset threshold, the model update process is triggered. For example, when the prediction accuracy is less than 90%, the model update is triggered. At this time, the latest user feedback information and business demand information are collected as training data for the model update. The new data is used to retrain the permission control model and optimize the model parameters. By regularly evaluating the effectiveness of the existing model, the access control policy can be continuously optimized to ensure long-term applicability and effectiveness.

[0122] It should be noted that there is not necessarily a certain order between the above steps. A person skilled in the art can understand, based on the description of the embodiments of the present invention, that in different embodiments, the above steps may have different execution orders, that is, they may be executed in parallel, or may be executed interchangeably, etc.

[0123] Further references Figure 6 , as a response to the above Figure 2 The present invention provides an embodiment of a context-aware access control device. Figure 2 Corresponding to the method embodiment shown, the device can be specifically applied to various electronic devices.

[0124] like Figure 6 As shown, the context-aware access control device 60 described in this embodiment includes:

[0125] The context collection module 601 is used to collect the login data and operation behavior data of the current user, and generate a context description of the data access request initiated by the current user based on the login data and operation behavior data;

[0126] The permission configuration module 602 is used to perform permission prediction processing on the context description using a pre-built and trained permission control model to determine the corresponding access permission configuration;

[0127] A setting and monitoring module 603 is used to set the permission scope of the data access request according to the access permission configuration and monitor access activity information;

[0128] The alarm module 604 is configured to trigger a corresponding permission alarm when it is detected that the access activity information exceeds the permission range.

[0129] The module referred to in the present invention refers to a series of computer program instruction segments that can perform specific functions. It is more suitable for describing the context-aware access control execution process than a program. For the specific implementation of each module, please refer to the corresponding method embodiment above, which will not be repeated here.

[0130] In one embodiment, the device 60 further includes:

[0131] A fine-grained acquisition module is used to obtain preset fine-grained access control rules and user attributes of the current user;

[0132] A fine-grained matching module, configured to match the user attributes with the fine-grained access control rules to obtain a corresponding fine-grained access adjustment policy;

[0133] The fine-grained adjustment module is used to perform fine-grained access rule adjustment on the currently generated access permission configuration according to the fine-grained access adjustment policy to obtain an adjusted access permission configuration.

[0134] In one embodiment, the context collection module 601 includes:

[0135] A data collection unit is used to collect the login data and operation behavior data of the current user, and perform data screening and processing on the login data and operation behavior data to obtain key data associated with data access security;

[0136] The calling and filling unit is used to call the corresponding background description template according to the current business scenario when the user initiates a data access request, fill the background description template with data based on the key data, and generate a context background description of the data access request.

[0137] In one embodiment, the permission configuration module 602 includes:

[0138] A feature extraction unit, configured to perform feature extraction processing on the context background description to obtain corresponding context features;

[0139] An input unit, configured to input the context features into a pre-built and trained permission control model, wherein the permission control model is built and trained based on a clustering algorithm;

[0140] a calculation unit, configured to calculate a distance between the context feature and each cluster center in the permission control model, each cluster center having a corresponding behavior pattern category;

[0141] The permission configuration unit is used to confirm the behavior pattern category of the nearest cluster center as the predicted behavior pattern of the current user, query in a preset mapping table according to the predicted behavior pattern, and obtain the access permission configuration corresponding to the predicted behavior pattern.

[0142] In one embodiment, the device 60 further includes:

[0143] An abnormal marking module, configured to mark as an abnormal behavior pattern if the context feature does not match the behavior pattern category of all current cluster centers;

[0144] A statistical learning module is used to summarize the context descriptions of all abnormal behavior patterns at preset intervals, and perform cluster learning on the authority control model based on the summary results to obtain new cluster centers and new behavior pattern categories;

[0145] A configuration update module is used to update the permission configuration of the preset mapping table according to the new cluster center and the new behavior pattern category.

[0146] In one embodiment, the device 60 further includes:

[0147] A feedback module is used to receive user feedback on the execution of the access rights configuration and regularly collect the latest business demand information;

[0148] A performance evaluation module is used to evaluate the performance of the permission control model based on the execution feedback information and the latest business demand information to obtain corresponding performance indicators;

[0149] The model updating module is used to update the authority control model according to the execution feedback information and the latest business demand information when the performance indicator is lower than a preset threshold.

[0150] In one embodiment, the device 60 further includes:

[0151] A construction module, configured to collect historical access records and construct context training data based on the historical access records;

[0152] An initialization module, used to build an initial permission control model, randomly initialize several cluster centers, assign the context training data to the nearest cluster center, and recalculate the cluster center of each category;

[0153] The training module is used to repeat the cluster center update process until the preset convergence conditions are met to obtain several trained cluster centers, each of which corresponds to a behavior pattern category;

[0154] The association configuration module is used to perform permission configuration analysis on the behavior pattern category of each cluster center, set corresponding access permission configuration for each behavior pattern category, and generate a corresponding preset mapping table.

[0155] In the above embodiment, the present invention discloses an access control device based on context perception, which collects the login data and operation behavior data of the current user, and generates a context background description of the data access request initiated by the current user based on the login data and operation behavior data; performs permission prediction processing on the context background description in a pre-built and trained permission control model to determine the corresponding access permission configuration; sets the permission range of the data access request according to the access permission configuration, and monitors the access activity information; triggers the corresponding permission alarm when it is detected that the access activity information exceeds the permission range. By combining the context information of the user data access request for permission adaptive configuration and outputting an alarm in time when the access activity exceeds the permission range, the flexibility of access permission control and the adaptability to different access requirements are improved, and the data security risk is reduced as much as possible.

[0156] Another embodiment of the present invention provides a computer device, such as Figure 7 As shown, the computer device 70 includes:

[0157] One or more processors 701 and memory 702, Figure 7 A processor 701 is used as an example for the description. The processor 701 and the memory 702 may be connected via a bus or other means. Figure 7 The bus connection is taken as an example.

[0158] The processor 701 is used to complete various control logics of the computer device 70. It can be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), a single-chip microcomputer, an ARM (Acorn RISC Machine) or other programmable logic device, discrete gate or transistor logic, discrete hardware components or any combination of these components. In addition, the processor 701 can also be any traditional processor, microprocessor or state machine. The processor 701 can also be implemented as a combination of computing devices, for example, a combination of a DSP and a microprocessor, multiple microprocessors, one or more microprocessors combined with a DSP and / or any other such configuration.

[0159] Memory 702, as a non-volatile computer-readable storage medium, can be used to store non-volatile software programs, non-volatile computer executable programs, and modules, such as program instructions corresponding to the context-aware access control method in the embodiments of the present invention. Processor 701 executes the non-volatile software programs, instructions, and modules stored in memory 702 to execute various functional applications and data processing of computer device 70, thereby implementing the context-aware access control method in the above-mentioned method embodiments.

[0160] The memory 702 may include a program storage area and a data storage area, wherein the program storage area may store an operating system and application programs required for at least one function; the data storage area may store data created according to the use of the computer device 70, etc. In addition, the memory 702 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, or other non-volatile solid-state storage device. In some embodiments, the memory 702 may optionally include a memory remotely located relative to the processor 701, and these remote memories may be connected to the computer device 70 via a network. Examples of the above-mentioned network include but are not limited to the Internet, an intranet, a local area network, a mobile communication network, and a combination thereof. One or more units are stored in the memory 702, and when executed by one or more processors 701, the steps of the context-aware access control method in any of the above-mentioned method embodiments are executed.

[0161] In the above embodiment, the present invention discloses a computer device, which collects the login data and operation behavior data of the current user, generates a context description of the data access request initiated by the current user based on the login data and operation behavior data; performs permission prediction processing on the context description in a pre-built and trained permission control model to determine the corresponding access permission configuration; sets the permission range of the data access request according to the access permission configuration, and monitors access activity information; triggers a corresponding permission alarm when it is detected that the access activity information exceeds the permission range. By combining the context information of the user data access request for permission adaptive configuration and outputting an alarm in time when the access activity exceeds the permission range, the flexibility of access permission control and the adaptability to different access requirements are improved, thereby minimizing data security risks.

[0162] An embodiment of the present invention provides a non-volatile computer-readable storage medium, which stores computer-executable instructions. When the computer-executable instructions are executed by one or more processors, the steps of the context-aware access control method in any of the above method embodiments are executed.

[0163] In the above embodiment, the present invention discloses a non-volatile computer-readable storage medium, which collects the login data and operation behavior data of the current user, and generates a context description of the data access request initiated by the current user based on the login data and operation behavior data; performs permission prediction processing on the context description in a pre-built and trained permission control model to determine the corresponding access permission configuration; sets the permission range of the data access request according to the access permission configuration, and monitors access activity information; when it is monitored that the access activity information exceeds the permission range, a corresponding permission alarm is triggered. By combining the context information of the user data access request for permission adaptive configuration and outputting an alarm in a timely manner when the access activity exceeds the permission range, the flexibility of access permission control and the adaptability to different access requirements are improved, and data security risks are minimized as much as possible.

[0164] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus the necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is a better embodiment. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes a number of instructions for enabling a terminal device (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in each embodiment of the present invention.

[0165] The present invention can be used in a wide variety of general or special computer system environments or configurations. For example: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputers, mainframe computers, distributed computing environments including any of the above systems or devices, and the like. The present invention can be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. The present invention can also be practiced in distributed computing environments in which tasks are performed by remote processing devices connected via a communications network. In a distributed computing environment, program modules can be located in local and remote computer storage media, including storage devices.

[0166] In summary, the context-aware access control method, device, equipment and medium disclosed in the present invention include: collecting the login data and operation behavior data of the current user, and generating a context background description of the data access request initiated by the current user based on the login data and operation behavior data; performing permission prediction processing on the context background description in a pre-built and trained permission control model to determine the corresponding access permission configuration; setting the permission range of the data access request according to the access permission configuration, and monitoring access activity information; triggering a corresponding permission alarm when it is detected that the access activity information exceeds the permission range. By combining the context information of the user data access request for permission adaptive configuration and outputting an alarm in a timely manner when the access activity exceeds the permission range, the flexibility of access permission control and its adaptability to different access requirements are improved, and data security risks are minimized as much as possible.

[0167] Of course, those skilled in the art will appreciate that all or part of the processes in the above-described method embodiments can be implemented by instructing related hardware (such as a processor, controller, etc.) through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes in the above-described method embodiments. The storage medium can be a memory, a magnetic disk, a floppy disk, a flash memory, an optical storage device, etc.

[0168] It should be noted that if any software tools or components not developed by our company appear in the examples of this application, they are for illustration purposes only and do not represent actual use. It should be understood that the application of the present invention is not limited to the examples above. Those skilled in the art can make improvements or modifications based on the above description, and all such improvements and modifications shall fall within the scope of protection of the appended claims.

Claims

1. A context-aware access control method, characterized in that: include: Collecting the login data and operation behavior data of the current user, and generating a context description of the data access request initiated by the current user based on the login data and operation behavior data; Perform permission prediction processing on the context description using a pre-built and trained permission control model to determine the corresponding access permission configuration; Setting the permission scope of the data access request according to the access permission configuration and monitoring access activity information; When it is detected that the access activity information exceeds the permission range, a corresponding permission alarm is triggered.

2. The context-aware access control method according to claim 1, wherein: After performing permission prediction processing on the context description using a pre-built and trained permission control model to determine the corresponding access permission configuration, the method further includes: Obtain preset fine-grained access control rules and user attributes of the current user; Matching the user attributes with the fine-grained access control rules to obtain corresponding fine-grained access adjustment policies; Fine-grained access rule adjustment is performed on the currently generated access permission configuration according to the fine-grained access adjustment policy to obtain an adjusted access permission configuration.

3. The context-aware access control method according to claim 1, wherein: The collecting of the login data and operation behavior data of the current user and generating a context description of the data access request initiated by the current user based on the login data and operation behavior data includes: Collect the current user's login data and operation behavior data, perform data screening on the login data and operation behavior data, and obtain key data related to data access security; When a user initiates a data access request, the corresponding background description template is called according to the current business scenario, and the background description template is filled with data based on the key data to generate a context description of the data access request.

4. The context-aware access control method according to claim 1, wherein: The method of performing permission prediction processing on the context description in a pre-built and trained permission control model to determine the corresponding access permission configuration includes: Performing feature extraction processing on the context background description to obtain corresponding context features; Inputting the context features into a pre-built and trained permission control model, wherein the permission control model is built and trained based on a clustering algorithm; Calculating the distance between the context feature and each cluster center in the permission control model, each cluster center having a corresponding behavior pattern category; The behavior pattern category of the closest cluster center is determined as the predicted behavior pattern of the current user, and a query is performed in a preset mapping table according to the predicted behavior pattern to obtain the access permission configuration corresponding to the predicted behavior pattern.

5. The context-aware access control method according to claim 4, characterized in that: The method also includes: If the context feature does not match the behavior pattern category of all current cluster centers, it is marked as an abnormal behavior pattern; Summarize all context descriptions marked as abnormal behavior patterns at preset intervals, and perform cluster learning on the authority control model based on the summary results to obtain new cluster centers and new behavior pattern categories; The preset mapping table is updated with permission configuration according to the new cluster center and the new behavior pattern category.

6. The context-aware access control method according to claim 1, wherein: After performing permission prediction processing on the context description using a pre-built and trained permission control model and determining the corresponding access permission configuration, the method includes: Receive user feedback on the execution of the access rights configuration and regularly collect the latest business demand information; Evaluate the performance of the permission control model based on the execution feedback information and the latest business demand information to obtain corresponding performance indicators; When the performance indicator is lower than a preset threshold, the authority control model is updated according to the execution feedback information and the latest business demand information.

7. The context-aware access control method according to claim 1, wherein: Before performing permission prediction processing on the context description using a pre-built and trained permission control model to determine the corresponding access permission configuration, the method further includes: Collecting historical access records and constructing context training data based on the historical access records; Constructing an initial permission control model, randomly initializing several cluster centers, assigning the context training data to the nearest cluster center, and recalculating the cluster center of each category; Repeat the cluster center update process until the preset convergence condition is met to obtain several trained cluster centers, each of which corresponds to a behavior pattern category; Perform permission configuration analysis on the behavior pattern category of each cluster center, set corresponding access permission configuration for each behavior pattern category, and generate a corresponding preset mapping table.

8. A context-aware access control device, characterized in that: include: A context collection module is used to collect the login data and operation behavior data of the current user, and generate a context description of the data access request initiated by the current user based on the login data and operation behavior data; A permission configuration module is used to perform permission prediction processing on the context description using a pre-built and trained permission control model to determine the corresponding access permission configuration; A setting and monitoring module, configured to set the permission scope of the data access request according to the access permission configuration and monitor access activity information; The alarm module is used to trigger a corresponding permission alarm when it is detected that the access activity information exceeds the permission range.

9. A computer device, characterized in that: comprising at least one processor; and, a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the context-aware access control method according to any one of claims 1 to 7.

10. A non-volatile computer-readable storage medium, characterized in that: The non-volatile computer-readable storage medium stores computer-executable instructions, which, when executed by one or more processors, enable the one or more processors to execute the context-aware access control method according to any one of claims 1 to 7.