Data permission access control method and system based on department architecture and data security classification

By comprehensively evaluating the departmental relationship strength, data confidentiality, and role permissions of user operations based on departmental structure and data confidentiality, the problem of inflexible cross-departmental data permission access control is solved, and efficient cross-departmental data sharing and security management is achieved.

CN120602165APending Publication Date: 2025-09-05UNIT 95765 OF THE CHINESE PEOPLES LIBERATION ARMY

Patent Information

Application Number
CN202510793659.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-13
Publication Date
2025-09-05

AI Technical Summary

Technical Problem

The existing data permission access control system is inflexible in cross-departmental data permission access control, the permission rules are too strict and the settings are too complicated, which is not conducive to data collaboration and sharing, and does not fully consider the impact of data confidentiality and user roles on permission access control.

Method used

By using a method based on departmental structure and data confidentiality, when intercepting user operations, the strength of the relationship between the user's department and the data's department, the data confidentiality assessment value, and the user role authority assessment value are obtained, and a weighted sum is performed to comprehensively evaluate the access control value. The value is then compared with the preset threshold to decide whether to allow access.

Benefits of technology

It has achieved the goal of adapting to dynamically changing business needs, promoting cross-departmental data sharing, ensuring data security and efficient use, and adapting to user and business needs in different scenarios under the premise of effective data security control.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602165A_ABST
    Figure CN120602165A_ABST
Patent Text Reader

Abstract

The invention discloses a data authority access control method and system based on a department architecture and a data security classification, and the method comprises the steps: obtaining the department relation strength between a department # imgabs4 # to which a user # imgabs3 # belongs and a department # imgabs6 # to which data # imgabs5 # belongs when an operation # imgabs2 # initiated by the user # imgabs0 # to data # imgabs1 # is intercepted; the data security level evaluation value of the data # imgabs7 # and the role operation authority evaluation value of the user # imgabs8 # to the operation # imgabs9 # are calculated; performing weighted summation on the department relationship strength between a department # imgabs11 # to which the user # imgabs10 # belongs and a department # imgabs13 # to which the data # imgabs12 # belongs, the data security level evaluation value of the data # imgabs14 # and the role operation authority evaluation value of the user # imgabs15 # for operating the # imgabs16 # to obtain a comprehensive access control evaluation value; and comparing the comprehensive access control evaluation value with a preset threshold value to determine whether the user # imgabs17 # is allowed to access the data # imgabs18 #. According to the method, the data access permission range can be controlled in a multi-dimensional mode, the dynamically-changing service requirements can be met, the data sharing requirements among different departments are promoted, and efficient and safe data management and application are achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to permission control technology in the field of data security, and in particular to a data permission access control method and system based on department structure and data confidentiality level. Background Art

[0002] In the current context of digital transformation, data volumes are surging, application scenarios are becoming increasingly complex, and security threats are becoming increasingly diverse. This creates challenges for data rights management, leading to data leaks, unauthorized access, data silos, and inefficiencies. Lack of effective rights control and privacy protection mechanisms in data sharing and openness can lead to low-privilege users gaining access to highly sensitive data, while high-privilege users may be unable to access necessary data. Alternatively, data rights are often allocated based on traditional administrative hierarchies or job responsibilities, lacking dynamic adjustment capabilities, hindering the efficiency of data sharing and collaboration. Alternatively, data security ratings are insufficiently refined, making it difficult to meet complex rights management requirements. Balancing strictness with flexibility, security with efficiency, is a real challenge in data rights control. Overly strict access controls can limit data flow and efficiency, while overly flexible controls can lead to security issues. Regarding cross-departmental data sharing, ensuring secure data exchange and rapidly adjusting rights settings as departmental personnel shift are crucial.

[0003] The Chinese patent document with publication number "CN119168501A" discloses a data permission management method, system, device and storage medium based on organizational structure. Fields are added to the organizational structure to divide the organizational data into levels and departments, and the levels and departments are assigned values ​​to the fields according to the corresponding preset logic; according to the actual business data isolation requirements, fields are added to users or roles and business assets, and the fields are bound to the logged-in users and business assets respectively to achieve refined control of data. Constrained data isolation rules are independently configured for the organizational data of the level or department. When the user accesses the functional module, the data resources that meet the access data permission range are matched and returned to the front-end business. The disadvantage of this patent is that it does not take into account the data sharing needs between cross-level / department collaborations, and the impact of data confidentiality on the level / department data permission range. At the same time, its own scope of application is relatively narrow. The Chinese patent document with publication number "CN117436124A" discloses a data permission design method based on a multi-node organizational structure. By setting up an independent permission management system in each node and flexibly setting permission rules and authorization and inheritance across nodes, precise control of data permissions is achieved. At the same time, the design can monitor and audit the use of data permissions in real time to ensure data security. Although this patent can achieve data permission access across nodes / departments under preset rules, with the increase in user needs and dynamic adjustments, the permission rule setting and management are difficult, the operation and maintenance costs are high, and the adaptability is poor. In summary, the existing permission management system has the problems of inflexible cross-departmental data permission access control, overly strict permission rules, overly complex settings, which are not conducive to data collaboration and sharing, and insufficient consideration of the impact of data confidentiality and user roles on permission access control. Summary of the Invention

[0004] Technical problems to be solved by the present invention: In response to the above-mentioned problems of the prior art, a data permission access control method and system based on departmental structure and data confidentiality level are provided. The present invention aims to address the problems existing in the existing data permission access control, such as inflexible cross-departmental data permission access control, overly strict permission rules, overly complex settings, which are not conducive to data collaboration and sharing, and insufficient consideration of the impact of data confidentiality level and user role on permission access control. The present invention can not only control the scope of data permission access in multiple dimensions, but also adapt to dynamically changing business needs, promote cross-departmental data sharing needs, and achieve efficient and secure data management and application.

[0005] In order to solve the above technical problems, the technical solution adopted by the present invention is: A data permission access control method based on department structure and data confidentiality level includes the following steps: S101, intercepting the user's operation on the data. Data Initiated operations Jump to the next step; S102, get user Department With data Department The strength of departmental relationships, data Data confidentiality assessment value and user Operation The role operation permission evaluation value; S103, the user Department With data Department The strength of departmental relationships, data Data confidentiality assessment value and user Operation The comprehensive access control evaluation value is obtained by weighted summing up the role operation permission evaluation values; S104: Compare the comprehensive access control evaluation value with a preset threshold. If the comprehensive access control evaluation value is greater than the preset threshold, the user is allowed to Accessing Data Otherwise, reject the user Accessing Data .

[0006] Optionally, in step S102, the user Department With data Department The acquisition of the strength of departmental relationships includes: S201, query the department tree structure corresponding to the department architecture through recursion or traversal method to determine the user Department With data Department The departmental hierarchical relationship between them is mapped to the departmental hierarchical relationship ; The user Department With data Department Department collaboration scores are obtained by mapping the interaction records between departments using internal communication tools. ; Get data The urgency of the project ; Get user Data Temporary access token value ; S202, calculate the user according to the following formula Department With data Department Strength of interdepartmental relationships: , in, For users Department With data Department The strength of interdepartmental relationships, 、 、 and is the weight parameter, is the departmental hierarchical relationship obtained by mapping, Score the mapped department collaboration, For data The urgency of the project, For users Data The temporary access token value.

[0007] Optionally, the mapping obtains the departmental hierarchical relationship When the user Department With data Department If they are in the same department or the same parent department, the department hierarchy relationship after mapping The value is set to a preset value greater than 0, otherwise the department hierarchy relationship after mapping The value is 0; the mapping obtains the department collaboration score When the user is involved, it includes obtaining the maximum amount of interaction record data of different departments using internal communication tools, dividing the interval between 0 and the maximum amount of interaction record data into multiple sub-intervals, and mapping each sub-interval to a department collaboration score, thereby Department With data Department The amount of interaction record data of the internal communication tools of the departments is mapped to the corresponding sub-interval to obtain the department collaboration score .

[0008] Optionally, in step S102, the user is obtained Department With data Department When the strength of the department relationship is 、 、 and Medium weight parameter Maximum, weight parameter The second largest, and the user is obtained in step S102 Department With data Department Before the strength of departmental relationships, including adjusting weight parameters according to organizational type 、 、 and , and adjust the weight parameters 、 、 and When the weight parameter and The increase and decrease complementarity, weight parameter and For highly collaborative organizations, the default weight parameters 、 、 and Based on the weight parameter Increase the preset first adjustment amount and set the weight parameter Reduce the preset first adjustment amount; for organizations of emergency projects, the default weight parameter 、 、 and Based on the weight parameter Increase the preset first adjustment amount and set the weight parameter Decrease the preset first adjustment amount.

[0009] Optionally, the data in step S102 The acquisition of data confidentiality assessment value includes: S301, calculate data according to the following formula Data security sensitivity score : , in, and are the weight coefficient and score value of the i-th scoring indicator, respectively. The scoring indicators include some or all of importance, sensitivity, scope of impact, compliance requirements, data update frequency, and data storage method; S302, according to the data Data security sensitivity score The size of the data The level of confidentiality; S303, the data The confidentiality level is mapped to data The data confidentiality assessment value.

[0010] Optionally, in step S102, the user Operation The acquisition of the role operation permission evaluation value includes: S401, get user The role hierarchy among all roles includes some or all of the system administrators, department administrators, and ordinary employees, and the role hierarchy is mapped to the role hierarchy weight; get operation The operation level in the overall operation, including some or all of delete, modify, and view, and the operation level is mapped to the operation authority weight; S402, divide the role level weight by the operation authority weight to obtain the user Operation Role operation permission evaluation value .

[0011] Optionally, the function expression for obtaining the comprehensive access control evaluation value by weighted summation in step S103 is: , in, represents the comprehensive access control evaluation value, 、 and is the weight coefficient, , For users Department With data Department The strength of interdepartmental relationships, For data The data confidentiality assessment value, For users Operation The role operation permission evaluation value.

[0012] In addition, the present invention also provides a data authority access control system based on department structure and data confidentiality level, including a microprocessor and a memory connected to each other, and the microprocessor is programmed or configured to execute the data authority access control method based on department structure and data confidentiality level.

[0013] In addition, the present invention also provides a computer-readable storage medium, which stores a computer program or instruction, and the computer program or instruction is programmed or configured to execute the data permission access control method based on department structure and data confidentiality level through a processor.

[0014] In addition, the present invention also provides a computer program product, including a computer program or instructions, which are programmed or configured to execute the data permission access control method based on department structure and data confidentiality level through a processor.

[0015] Compared with the existing technology, the present invention can achieve the following beneficial effects: In order to solve the problems of the existing data permission access control, such as the inflexible cross-departmental data permission access control, too strict permission rules, too complex settings, which are not conducive to data collaboration and sharing, and the inadequate consideration of the impact of data confidentiality and user roles on permission access control, the data permission access control method based on department structure and data confidentiality includes intercepting the user Data Initiated operations When getting the user Department With data Department The strength of departmental relationships, data Data confidentiality assessment value and user Operation The role operation permission evaluation value of the user Department With data Department The strength of departmental relationships, data Data confidentiality assessment value and user Operation The comprehensive access control evaluation value is obtained by weighted summing of the role operation permission evaluation values; the comprehensive access control evaluation value is compared with the preset threshold to determine whether to allow the user to Accessing Data The present invention unifies data permission access control rules by comprehensively considering influencing factors such as department structure, data confidentiality level and user role, and builds a dynamic and flexible data permission management system to solve the problem of meeting the requirements of strengthening cross-departmental data sharing and communication under the premise of effective data security control, dynamically adapting to the data permission access control requirements of users and businesses in different scenarios, ensuring data security and efficient utilization, and not only being able to control the scope of data permission access in multiple dimensions, but also adapting to dynamically changing business needs, promoting cross-departmental data sharing needs, and realizing efficient and secure data management and application. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 Schematic diagram of the basic process of the method of the embodiment of the present invention. DETAILED DESCRIPTION

[0017] In order to enable those skilled in the art to better understand the technical solution of the present invention, the technical solution of the present invention will be further described in detail below with reference to the accompanying drawings in the embodiments of the present invention.

[0018] like Figure 1 As shown, the data permission access control method based on department structure and data confidentiality level in this embodiment includes the following steps: S101, intercepting the user's operation on the data. Data Initiated operations Jump to the next step; S102, get user Department With data Department The strength of departmental relationships, data Data confidentiality assessment value and user Operation The role operation permission evaluation value; S103, the user Department With data Department The strength of departmental relationships, data Data confidentiality assessment value and user Operation The comprehensive access control evaluation value is obtained by weighted summing up the role operation permission evaluation values; S104: Compare the comprehensive access control evaluation value with a preset threshold. If the comprehensive access control evaluation value is greater than the preset threshold, the user is allowed to Accessing Data Otherwise, reject the user Accessing Data .

[0019] user Department With data Department The strength of the relationship between departments is used to ensure that users u Department d u With data t Department d tThere is a direct hierarchical relationship between departments, which limits cross-departmental data access. The strength of the relationship between the data demand department and the data generation department, such as affiliation, collaboration, project requirements, etc., affects the user's access rights to data and information sharing strategies to varying degrees. By analyzing the depth of the inter-departmental hierarchy, the frequency of collaboration, and the importance of data sharing, etc., and considering their weight factors, an accurate relationship assessment result is provided. In this embodiment, in step S102, the user Department With data Department The acquisition of the strength of departmental relationships includes: S201, query the department tree structure corresponding to the department architecture through recursion or traversal method to determine the user Department With data Department The departmental hierarchical relationship between them is mapped to the departmental hierarchical relationship ; The user Department With data Department Department collaboration scores are obtained by mapping the interaction records between departments using internal communication tools. ; Get data The urgency of the project ; Get user Data Temporary access token value ; S202, calculate the user according to the following formula Department With data Department Strength of interdepartmental relationships: , in, For users Department With data Department The strength of interdepartmental relationships, 、 、 and is the weight parameter, is the departmental hierarchical relationship obtained by mapping, Score the mapped department collaboration, For data The urgency of the project, For users Data The temporary access token value.

[0020] is the departmental hierarchical relationship term, where the weight coefficient Represents the weight of the department hierarchy. Use recursive or traversal methods to query the department tree structure and determine the department d where user u belongs. u Department d where data t is located t The hierarchical relationship between departments is given, and the quantitative parameters of the inter-departmental hierarchy are given. If d u and d t If they belong to the parent-child department or the same department, the relationship between the two is relatively close. On the contrary, if they belong to different departments, the relationship is relatively distant, thereby controlling the scope of data confidentiality and ensuring data security. In this embodiment, the departmental hierarchical relationship is mapped When the user Department With data Department If they are in the same department or the same parent department, the department hierarchy relationship after mapping The value is a preset value greater than 0. In this embodiment, the preset value is specifically 5, which can be expressed as Otherwise, the departmental hierarchy relationship after mapping The value is 0, which can be expressed as .

[0021] is the department collaboration scoring item, where the weight coefficient Indicates the weight of department collaboration score. Use the interaction record data of internal communication tools (such as email system, instant messaging platform) of the department to evaluate the communication activity and collaboration depth between departments, and reflect the department's d u and departments d t The collaboration needs between departments are met, and cross-departmental data circulation channels are realized based on the degree of collaboration and cooperation, which enhances the flexibility of data access control. When the user is involved, it includes obtaining the maximum amount of interaction record data of different departments using internal communication tools, dividing the interval between 0 and the maximum amount of interaction record data into multiple sub-intervals, and mapping each sub-interval to a department collaboration score, thereby Department With data Department The amount of interaction record data of the internal communication tools of the departments is mapped to the corresponding sub-interval to obtain the department collaboration score As an optional implementation, in this embodiment, department collaboration scoring The value ranges from 0 to 5.

[0022] is the urgency item of the project, where the weight coefficient Representation data The weight of the urgency of the project. According to the urgency of the current project, if a legitimate cross-departmental demand is detected, a dynamic adjustment factor is added, the requirements of the departmental hierarchy are appropriately relaxed, and the applicability of the departmental relationship function scenario is enhanced. As an optional implementation method, in this embodiment, the data The urgency of the project The value range is 0 to 5.

[0023] It is a temporary authorization item for the project, The weight of the temporary authorization item of the project. This embodiment introduces a dynamic authorization mechanism to grant users temporary access rights to cross-departmental data under specific conditions. For example, during the project collaboration, Provide data Temporary access token value ,user u Temporary cross-departmental access to data during certain events t As an optional implementation, in this embodiment, the user Data Temporary access token value The value ranges from 0 to 5.

[0024] As an optional implementation, in step S102 of this embodiment, the user Department With data Department When the strength of the department relationship is 、 、 and Medium weight parameter Maximum, weight parameter The second largest, and the user is obtained in step S102 Department With data Department Before the strength of departmental relationships, including adjusting weight parameters according to organizational type 、 、 and , and adjust the weight parameters 、 、 and When the weight parameter and The increase and decrease complementarity, weight parameter and For highly collaborative organizations, the default weight parameters 、 、 and Based on the weight parameter Increase the preset first adjustment amount and set the weight parameter Reduce the preset first adjustment amount; for organizations of emergency projects, the default weight parameter 、 、 and Based on the weight parameter Increase the preset first adjustment amount and set the weight parameter Reduce the first adjustment of the preset. Hierarchical relationships are usually basic, so the weight coefficient w 1 is probably the largest. Collaboration score is also important, especially when cross-departmental collaboration is frequent, so the weight coefficient w Second place. Urgency and temporary authorization vary depending on the specific situation and may become very important in some cases, so their weights may be adjusted dynamically. The hierarchical relationship w1 determines the basic data access rules and is usually fundamental. Direct affiliation between departments has the greatest impact on data access rights, so the weight coefficient w1 = 0.4; the collaboration score reflects the closeness of inter-departmental cooperation and affects cross-departmental data flow. In the case of frequent collaboration, a higher weight can promote flexible data sharing, so the following is true: w 2 = 0.3. Dynamic adjustment factors relax access restrictions in emergency situations. Although the impact is significant, it is usually temporary and needs to be adjusted according to specific circumstances. w 3 = 0.2. Grant temporary access rights under specific conditions to support project collaboration. As a dynamic factor, its weight may change with project needs, including: w 4 = 0.1; The weight design should be adjusted according to the actual situation of the specific enterprise to ensure the most appropriate proportion distribution. In actual application, the weight distribution can be adjusted according to the specific situation to ensure the best adaptability and practicality. For example: highly collaborative enterprises increase w 2 to 0.35, reduce accordingly w 1 to 0.35. If there are more urgent items, the w 3 to 0.25, reduce accordingly w 4 to 0.05.

[0025] Data confidentiality is the core basis for the design of data access control, which determines the security and availability of data. By scientifically classifying data confidentiality, clarifying the evaluation criteria, reasonably allocating weights, and establishing a clear classification, and quantifying the security sensitivity of data items, we can maximize the value and utilization of data while ensuring data security. The acquisition of data confidentiality assessment value includes: S301, calculate data according to the following formula Data security sensitivity score : , in, and are the weight coefficient and score value of the i-th scoring indicator, respectively. The scoring indicators include some or all of importance, sensitivity, scope of impact, compliance requirements, data update frequency, and data storage method; S302, according to the data Data security sensitivity score The size of the data The level of confidentiality; S303, the data The confidentiality level is mapped to data The data confidentiality assessment value.

[0026] The weighting coefficients for the scoring indicators in step S301 of this embodiment include: s1: Importance, which indicates the data's centrality to the business. For example, public information (such as content on a company's official website) is of lower importance; core business data (such as financial statements and private customer information) is of higher importance. s2: Sensitivity, which represents the potential risks posed by a data breach. For example, the impact on personal privacy (such as employee personal information) or the impact on corporate reputation (such as undisclosed strategic plans). s3: Scope of Impact, which indicates the departments, personnel, or business scope affected by the data. For example, company-wide important data (high impact); data within a specific department (low impact). s4: Compliance Requirements, which indicates whether the data is protected by specific laws or industry regulations. s5: Other Customized Factors, which indicate that additional scoring indicators can be added based on the specific needs of the enterprise. For example, the frequency of data updates (real-time data may be more sensitive); the data storage medium (such as cloud storage or local servers). As an optional implementation, the specific weighting coefficients and scoring values ​​for the scoring indicators in this embodiment are shown in Tables 1 and 2.

[0027] Table 1: Rating value table of scoring indicators

[0028] Table 2: Weight coefficient value table of scoring indicators

[0029] Finally, according to The data security sensitivity score can be calculated.

[0030] In step S302 of this embodiment, according to the data Data security sensitivity score The size of the data When the confidentiality level is set, the confidentiality level is shown in Table 3.

[0031] Table 3: Confidentiality Level Table

[0032] In step S303 of this embodiment, the data The confidentiality level is mapped to data When the data confidentiality evaluation value is calculated, the data confidentiality evaluation values ​​of each confidentiality level are as follows: Public = 1; Internal = 2; Secret = 3; Confidential = 4; Top Secret = 5. The mapping can be expressed as a function expression: , Among them, S(t) is the data confidentiality evaluation value. S′ ( t ) is within the interval [0,1.1), the data confidentiality assessment value S(t)=1, indicating that the data belongs to the public level. S′ ( t ) is within the interval [1.1,2.1), the data confidentiality assessment value S(t)=2, indicating that the data belongs to the internal level. S′ ( t ) is within the interval [2.1,3.1), the data confidentiality evaluation value S(t)=3, indicating that the data belongs to the confidential level. S′ ( t ) is within the interval [3.1,4.1), the data confidentiality level evaluation value S(t)=4, indicating that the data is classified as confidential. S′ ( t ) is in the interval [4.1,4.5], the data confidentiality assessment value S(t)=5, indicating that the data is top secret.

[0033] In step S102 of this embodiment, the user Operation The acquisition of the role operation permission evaluation value includes: S401, get user The role hierarchy among all roles includes some or all of the system administrators, department administrators, and ordinary employees, and the role hierarchy is mapped to the role hierarchy weight; get operation The operation level in the overall operation, including some or all of delete, modify, and view, and the operation level is mapped to the operation authority weight; S402, divide the role level weight by the operation authority weight to obtain the user Operation Role operation permission evaluation value Access control not only considers the department level and data confidentiality level, but also the role level of the user and the type of data operation performed. In order to strictly limit the permissions of high-risk operations (such as deletion, modification, etc.) and ensure the permission control capabilities of high-level roles, that is, high-level roles have greater permissions, and high-risk operations require higher permissions to be performed, so that different role levels have appropriate operation permissions to protect sensitive data and promote effective management, and improve the flexibility and security of access control, in this embodiment, users are Operation Role operation permission evaluation value It is defined as the result of dividing the role level weight by the operation permission weight, that is: = Role level weight / operation permission weight.

[0034] When obtaining the role hierarchy weight in step S401, a weight value is assigned to each role based on the role's scope of responsibilities and the size of the authority. For example, system administrator: has full control over the entire system, so the weight is 3 (highest authority). Department administrator: is responsible for managing the users and permissions of the department, so the weight is 2 (medium authority). Ordinary user: is limited to completing tasks related to their own work, so the weight is 1 (lowest authority). When obtaining the operation authority weight in step S401, a weight value is assigned to each operation based on the risk and sensitivity of the operation, such as: (1) Deleting data: the highest risk, requires strict control to ensure data security, so the weight is 3 (high-risk operation). (2) Modifying data: medium risk, requires review and is in line with the scope of responsibilities, so the weight is 2 (medium-risk operation). (3) Viewing data: the lowest risk, accessible to ordinary users, meets basic needs, so the weight is 1 (low-risk operation).

[0035] In this embodiment, the user Operation Role operation permission evaluation value The design principles include: (1) Clear hierarchical division: The role hierarchy should form a clear hierarchical structure, and the authority will gradually expand as the hierarchy rises. For example, system administrators usually have comprehensive control rights, while department administrators only operate within their management scope, and ordinary users are limited to viewing data. (2) The principle of least privilege: The authority of each role should be limited to the minimum scope required to complete their duties to avoid unnecessary abuse and leakage of authority. For example, system administrators can delete data because they have sufficient authority to handle high-risk tasks; ordinary users cannot delete data in order to protect data security and prevent losses caused by misoperation. (3) Scalability design: New role levels or operation types can be added according to actual needs, and the corresponding weights can be adjusted to achieve a flexible and dynamic authority management mechanism. Based on the above design principles, by analyzing the relationship between role hierarchy, operation type and role operation permission evaluation value, it can be seen that high-level roles have a positive contribution to the permission evaluation value. The higher the role hierarchy, the greater the permission control ability and the higher the permission evaluation value; while high-risk operations have a reverse reduction effect on the permission evaluation value. The higher the operation risk, the stronger the permission restriction ability and the lower the permission evaluation value, so as to ensure the effectiveness and security of permission control.

[0036] According to the designed role level weight and operation type weight, through the user Operation Role operation permission evaluation value By calculating, we can construct a clear role authority evaluation matrix, as shown in Table 4.

[0037] Table 4: Role authority evaluation matrix

[0038] The above role permission evaluation matrix shows the permission evaluation values ​​of different roles when performing various operations. Assuming that other factors are not considered, only the threshold of the role operation permission evaluation is set to 1 to determine whether the operation is allowed. By analyzing the matrix, the following conclusions can be drawn: Impact analysis of role hierarchy: System Administrator: Has the highest authority weight (3), and can therefore perform all operations. Even for the high-risk operation of deleting data, its authority evaluation value just hits the threshold, meeting the execution conditions. Department Administrator: With an authority weight of 2, can perform operations such as modifying and viewing data, but cannot perform operations such as deleting data, as its authority evaluation value (0.67) is below the threshold. Ordinary User: Has the lowest authority weight (1), and can only perform operations such as viewing data. For the high-risk operations of deleting and modifying data, its authority evaluation value is below the threshold and cannot be executed.

[0039] Impact analysis of operational risks: Deleting data is the highest-risk operation, so only system administrators can perform this operation. Modifying data is the next highest risk operation, and department administrators and system administrators can perform this operation, while ordinary users cannot. Viewing data is the lowest risk operation and can be performed by all roles.

[0040] As can be seen from the role permission assessment matrix, the "principle of least privilege" is embodied, with each role granted only the minimum permissions required to fulfill their responsibilities. For example, ordinary users can only view data but cannot modify or delete it; high-risk operations require higher permissions to execute, thereby reducing the risk of misoperation or malicious behavior. Therefore, role operation permission assessment serves as a clear and effective method for allocating and managing access rights to operations for different roles. By quantifying role and operation weights, it can effectively implement the principle of least privilege and separation of duties. This design not only ensures system security, but also provides flexibility and scalability, adapting to different security requirements and business scenarios.

[0041] The function expression for obtaining the comprehensive access control evaluation value by weighted summation in step S103 of this embodiment is: , in, represents the comprehensive access control evaluation value, 、 and is the weight coefficient, , For users Department With data Department The strength of interdepartmental relationships, For data The data confidentiality assessment value, For users Operation The role operation authority evaluation value. Among them, the weight coefficient 、 and It is used to balance the impact of different factors on the access control policy, representing the importance of department relationships, data confidentiality, and role permissions. Ultimately, if the comprehensive access control evaluation value (abbreviated as A) is greater than or equal to the preset threshold, access is granted. Otherwise, the access request is denied.

[0042] In planning weight coefficient α, β, γWhen balancing departmental relationship strength, data confidentiality, and role operation permissions, we need to pay more attention to balancing departmental relationship strength, data confidentiality, and role operation permissions. According to the organization's security strategy, business needs, and risk preferences, we can build a flexible, secure, and efficient access control strategy by rationally planning and adjusting the weight coefficients. In this embodiment, we plan the weight coefficients. α, β, γ The specific principles adopted are: Combined with the core idea of ​​the BLP model, which is "read downwards and write upwards", the access control policy needs to meet the following requirements: users can only access data with a security level lower than or equal to their own security level. Users can only write data to targets with a security level higher than or equal to their own security level. Therefore, the allocation of weight coefficients needs to consider the following factors: Data security level scoring calculation function S ( t ) is the core factor: the security level of the data directly determines whether the user can access it. Therefore, β is usually the largest weight coefficient. Department relationship strength function D(d u ,d t ) And role operation permission evaluation function R ( u,o) are auxiliary factors: these factors are used to further refine the access control policy. According to actual needs and scenarios, the values ​​of weight coefficients α, β and γ need to meet the following conditions: 0≤α,β,γ≤1; α+β+γ=1. In the BLP model, the data confidentiality score calculation function S(t) is the most core factor, so: the value of β is usually the largest (for example, 0.5≤β≤0.7). α and γ are adjusted according to the specific scenario. The specific values ​​of the weight coefficients include the following scenarios: (1) High security environment: data confidentiality is the highest priority, followed by departmental hierarchical relationships, then β=0.7; α=0.2; γ=0.1; (2) Medium security environment (such as enterprise management system): data confidentiality and the relationship between users and resources are equally important, and departmental hierarchical relationships are auxiliary, then β=0.5; α=0.3; γ=0.2. (3) Flexible working environment (such as collaborative platform): The relationship between users and resources is the highest priority, followed by the data confidentiality level, then β=0.4; α=0.3; γ=0.3. In actual applications, the weight coefficient may need to be dynamically adjusted according to the scenario. For example, when processing sensitive data, the value of β can be temporarily increased. When collaborating within a specific department, the value of α can be appropriately increased. Dynamic adjustment can be achieved in the following ways: Time-based adjustment: The weight coefficient will change during certain time periods (such as emergencies). Event-based adjustment: Specific events (such as increased risk of data leakage) trigger the adjustment of the weight coefficient. In actual applications, the rationality of the weight coefficient needs to be verified through the following methods: Simulation testing: Test different weight combinations in a simulated environment to verify whether the access control policy meets expectations. User feedback: Collect user feedback and adjust the weight to optimize user experience and security. Security audit: Conduct security audits regularly to ensure that the access control policy meets compliance requirements.

[0043] In step S104, the threshold comparison is used to make a decision. The comprehensive access control evaluation value is compared with the preset threshold. If the comprehensive access control evaluation value is greater than the preset threshold, the user is allowed to access the system. Accessing Data Otherwise, reject the user Accessing Data Threshold comparison and judgment decision-making is a scientific and systematic decision-making method. By setting clear standards (i.e. thresholds), different options are compared and evaluated, and the final decision is made based on whether these standards are met or exceeded, which helps to improve the quality and consistency of decision-making. How to set the threshold scientifically and reasonably is a key issue. If the threshold is too high, it may lead to waste of resources or loss of opportunities; if it is too low, the expected effect may not be achieved. Therefore, in practical applications, it is necessary to reasonably set and adjust the threshold according to the specific situation, and flexibly use multi-dimensional evaluation models to cope with various challenges and ensure the effectiveness of decision-making. It needs to be compared with the preset threshold T to determine whether to allow the operation. ≥ T, the user is allowed to perform operation o. If < T, the access request is rejected.

[0044] Meanwhile, it should be noted that the preset threshold is not fixed. Instead, with the change of the environment or the acquisition of new information, the original threshold T may need to be adjusted. A dynamic adjustment mechanism should be established to implement real-time monitoring and feedback mechanisms, and dynamically adjust T according to the changes in access requests; regularly review and update the value of T to adapt to the changing security threats and business requirements, such as: 1) Data sensitivity and importance: The classification score S(t) of the data reflects its sensitivity and importance. For highly confidential or critical business data, a higher T is set to strictly control access rights. For low-sensitivity data, T can be appropriately reduced to allow wider access. 2) Department relationship strength: The relationship strength D(d u , d t ) ensures that there is a direct hierarchical relationship between the department to which the user belongs and the department to which the data belongs. If the relationship between departments is close (such as at the same level or上下级), a lower T can be set to allow more flexible access. For cross-departmental or non-directly affiliated situations, increase T to limit unnecessary access. 3) User role and permissions: The role and operation permissions R(u, o) of the user determine their operation ability on the data. High-level users (such as administrators) may require a lower T for efficient task execution. Ordinary users or low-permission users should be set a higher T to increase the strictness of access control.

[0045] To verify the data permission access control method based on the department architecture and data classification level in this embodiment, by distinguishing different levels of security environments in this embodiment and listing specific cases such as government agency departments, enterprise management systems, and collaboration platforms, it can be verified whether the configuration of weights and thresholds is reasonable in different environments, ensuring the balance between security and efficiency. The specific scenarios include: (1) High-security environment (government agency) In the government agency department, assume that a senior official accesses and modifies highly confidential files. Here, there is a direct subordination relationship between departments, the user has high permissions, and has the role of system administrator. Calculate (The value of A) whether it exceeds the preset threshold T to determine whether to allow access.

[0046] Step 1: Set weight and threshold parameters: a. Weight assignment: α = 0.2; β = 0.7; γ = 0.1 b. Preset threshold T: For high-sensitivity data, set a higher preset threshold T to control access rights. For example, T = 3.5.

[0047] Step 2: Calculate the access control evaluation value: a. Interdepartmental relationship strength D(d u ,d t ) Emphasis on hierarchical structure and strict access control, cross-departmental data sharing is rare, unless there is an emergency or special project requirement, then: w1=0.4; w2=0.3; w3=0.2; w4=0.1; H(d u ,d t )=5,C(d u ,d t )=2, E(t)=4, P(u,t)=3; D(d u ,d t )=0.4×5+0.3×2+0.2×4+0.1×3=2+0.6+0.8+0.3=3.7; b. Data confidentiality assessment value S(t): For highly confidential data files, S(t)=4.

[0048] c. User operation authority R(u,o): Senior officials have high authority, R(u,o)=1.5.

[0049] A(u,t,d u ,d t ,o)=α×D(d u ,d t )+β×S(t)+γ×R(u,o)=0.2×3.7+0.7×4+0.1×2=3.69; Step 3: Compare the threshold value with the evaluation result: A(u,t,d u ,d t ,o)=3.69≥T(T=3.5), the result is that access modification is allowed.

[0050] Conclusion: Senior officials were allowed access to highly confidential data files, consistent with strict control policies in a high-security environment.

[0051] (2) Medium security environment (enterprise management system) In the enterprise management system, ordinary employees request access to view sensitive customer data. They have no direct affiliation with other departments, have low authority, and have the role of ordinary employees. (A value) and compare it with the preset threshold T.

[0052] Step 1: Weight and threshold parameter setting: a. Weight distribution: α=0.3; β=0.5; γ=0.2 b. Preset threshold T: For sensitive customer data, set a moderate preset threshold T. For example, T=2.5 Step 2: Calculate the access control evaluation value: a. Inter-departmental relationship strength D(d u ,d t ): Emphasize collaboration between departments, but there is also a certain hierarchical structure. There will be flexible data sharing under project requirements. Then: w1 = 0.35; w2 = 0.35; w3 = 0.2; w4 = 0.1 H(d u ,d t ) = 5, C(d u ,d t ) = 4, E(t) = 3, P(u,t) = 2 D(d u ,d t ) = 0.35×5 + 0.35×4 + 0.2×3 + 0.1×2 = 1.75 + 1.4 + 0.6 + 0.2 = 4.0; b. Data classification evaluation value S(t): For moderately secret data files, S(t) = 3.

[0053] c. User operation permission R(u,o): Ordinary employees have relatively low permissions, R(u,o) = 1.

[0054] A(u,t,d u ,d t ,o) = α×D(d u ,d t ) + β×S(t) + γ×R(u,o) = 0.2×4.0 + 0.5×3 + 0.1×1 = 2.4 Step 3: Compare the threshold with the evaluation result: A(u,t,d u ,d t ,o) = 2.4 < T (T = 2.5), and the result is to reject the view.

[0055] Conclusion: Ordinary employees are rejected access to sensitive customer data, which conforms to the control strategy of a medium-security environment.

[0056] (3) Collaborative security environment (collaboration platform) In the case of the collaboration platform, the project manager and team members work closely together and request access to view project documents. The department relationship is strong, the permissions are moderate, and the department administrator role is available. Similarly, calculate (the A value) and compare it with the preset threshold T.

[0057] Step 1: Set weight and threshold parameters: a. Weight assignment: α = 0.3; β = 0.4; γ = 0.3; b. Preset threshold T: For internal project documentation, set a lower preset threshold T to facilitate collaboration, for example, T = 2.

[0058] Step 2: Calculate the access control evaluation value a. Interdepartmental relationship strength D(d u ,d t ): It focuses on collaboration between departments, but also has a certain hierarchical structure. Flexible data sharing is possible under project requirements, including: w1=0.25; w2=0.4; w3=0.2; w4=0.15; H(d u ,d t )=5,C(d u ,d t )=5, E(t)=4, P(u,t)=2; D(d u ,d t )=0.25×5+0.4×5+0.2×4+0.15×3=1.25+2+0.8+0.45=4.5; b. Data confidentiality assessment value S(t): For data files within the project, S(t)=2.

[0059] c. User operation authority R(u,o): The project manager has moderate authority, R(u,o)=2.

[0060] A(u,t,d u ,d t ,o)=α×D(du,dt)+β×S(t)+γ×R(u,o)=0.3×4.5+0.4×2+0.3×2=2.75 Step 3: Compare the threshold value with the evaluation result: A(u,t,d u ,d t ,o)=2.75≥T (T=2), the result is access is allowed.

[0061] Conclusion: The project manager is allowed to access project documents, which complies with the control policy of the collaborative security environment and promotes team collaboration.

[0062] As can be seen, by adjusting the weight coefficients and other parameters, the data permission access control model implemented by the method of this embodiment can adapt to the needs of different security environments. High-security environments emphasize hierarchical structure and strict control, medium-security environments focus on balancing hierarchy and collaboration, and collaborative environments prioritize flexible data sharing mechanisms. This flexibility allows the model to be optimized according to specific needs in actual applications, ensuring data security and efficient use.

[0063] Compared with the existing technology, the data permission access control method based on department structure and data confidentiality level in this embodiment has the following advantages: 1) Multi-dimensional comprehensive evaluation: By combining the data confidentiality level score S(t), department relationship strength D(d u ,d t ) and role-based operation permission evaluation R(u,o) to comprehensively assess user access requests. This approach more accurately reflects the actual security needs of resources and avoids misjudgments caused by single-factor decisions. 2) Dynamic Weight Adjustment: The weight coefficients α, β, and γ can be flexibly configured based on different security environments (such as high security, medium security, and flexible collaboration), and support dynamic adjustment based on time and events. This mechanism enhances the system's adaptability, enabling it to respond to evolving security threats and business needs. 3) Fine-grained Access Control: This not only considers user roles but also addresses each operation (such as read, edit, and delete) to provide more refined permission management. This reduces potential security risks and avoids the over- or under-authorization issues that can exist in traditional approaches. 4) Dynamic Threshold Comparison Decision: The comprehensive evaluation results are compared with a dynamically adjusted threshold T to determine whether to allow access. This mechanism not only improves the scientific nature of decision-making but also supports flexible setting and adjustment of thresholds based on different data sensitivity and user roles, enhancing the system's flexibility and security. 5) Adaptability to multiple environments: The method is applicable to scenarios with different security levels, including high-security environments (such as military systems), medium-security environments (such as enterprise management systems), and flexible collaborative environments (such as collaborative work platforms). This wide applicability enhances the practicality and scalability of the method. 6) Enhanced security and user experience: Through multi-dimensional evaluation and dynamic adjustment mechanisms, unnecessary access restrictions are reduced, the false rejection rate is lowered, and sensitive data is effectively protected, thereby improving the security and user experience of the overall system. These methods of the data permission access control method based on departmental structure and data confidentiality in this embodiment are superior to traditional permission management solutions in terms of flexibility, security, adaptability, and accuracy, and can better meet the data permission access control needs in complex environments.

[0064] In addition, this embodiment also provides a data authority access control system based on department structure and data confidentiality level, including a microprocessor and a memory connected to each other, and the microprocessor is programmed or configured to execute the data authority access control method based on department structure and data confidentiality level.

[0065] In addition, this embodiment also provides a computer-readable storage medium, which stores a computer program or instruction. The computer program or instruction is programmed or configured to execute the data permission access control method based on department structure and data confidentiality level through a processor.

[0066] In addition, this embodiment also provides a computer program product, including a computer program or instructions, which are programmed or configured to execute the data permission access control method based on department structure and data confidentiality level through a processor.

[0067] Those skilled in the art should understand that the technical solution provided by the present invention may be in the form of a method, a system, or a computer program product. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-readable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code. The present invention is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present invention. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of processes and / or boxes in the flowchart and / or block diagram, may be implemented by computer program instructions. These computer program instructions may be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the functions described in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 These computer program instructions can also be stored in a computer-readable memory that can guide a computer or other programmable data processing device to work in a specific way, so that the instructions stored in the computer-readable memory produce a product including the instruction device, which implements the function specified in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 The steps for the function specified in one or more boxes.

[0068] The above description is merely a preferred embodiment of the present invention. The scope of protection of the present invention is not limited to the above embodiment. All technical solutions based on the concept of the present invention are within the scope of protection of the present invention. It should be noted that for those skilled in the art, various improvements and modifications that do not depart from the principles of the present invention should also be considered within the scope of protection of the present invention.

Claims

1. A data authority access control method based on department structure and data confidentiality level, characterized in that: The steps include: S101, intercepting the user's operation on the data. Data Initiated operations Jump to the next step; S102, get user Department With data Department The strength of departmental relationships, data Data confidentiality assessment value and user Operation The role operation permission evaluation value; S103, the user Department With data Department The strength of departmental relationships, data Data confidentiality assessment value and user Operation The comprehensive access control evaluation value is obtained by weighted summing up the role operation permission evaluation values; S104: Compare the comprehensive access control evaluation value with a preset threshold. If the comprehensive access control evaluation value is greater than the preset threshold, the user is allowed to Accessing Data Otherwise, reject the user Accessing Data .

2. The data authority access control method based on department structure and data confidentiality level according to claim 1 is characterized in that: In step S102, the user Department With data Department The acquisition of the strength of departmental relationships includes: S201, query the department tree structure corresponding to the department architecture through recursion or traversal method to determine the user Department With data Department The departmental hierarchical relationship between them is mapped to the departmental hierarchical relationship ; The user Department With data Department Department collaboration scores are obtained by mapping the interaction records between departments using internal communication tools. ; Get data The urgency of the project ; Get user Data Temporary access token value ; S202, calculate the user according to the following formula Department With data Department Strength of interdepartmental relationships: , in, For users Department With data Department The strength of interdepartmental relationships, 、 、 and is the weight parameter, is the departmental hierarchical relationship obtained by mapping, Score the mapped department collaboration, For data The urgency of the project, For users Data The temporary access token value.

3. The data authority access control method based on department structure and data confidentiality level according to claim 2 is characterized in that: The mapping obtains the departmental hierarchical relationship When the user Department With data Department If they are in the same department or the same parent department, the department hierarchy relationship after mapping The value is set to a preset value greater than 0, otherwise the department hierarchy relationship after mapping The value is 0; the mapping obtains the department collaboration score When the user is involved, it includes obtaining the maximum amount of interaction record data of different departments using internal communication tools, dividing the interval between 0 and the maximum amount of interaction record data into multiple sub-intervals, and mapping each sub-interval to a department collaboration score, thereby Department With data Department The amount of interaction record data of the internal communication tools of the departments is mapped to the corresponding sub-interval to obtain the department collaboration score .

4. The data authority access control method based on department structure and data confidentiality level according to claim 2 is characterized in that: In step S102, the user is obtained Department With data Department When the strength of the department relationship is 、 、 and Medium weight parameter Maximum, weight parameter The second largest, and the user is obtained in step S102 Department With data Department Before the strength of departmental relationships, including adjusting weight parameters according to organizational type 、 、 and , and adjust the weight parameters 、 、 and When the weight parameter and The increase and decrease complementarity, weight parameter and For highly collaborative organizations, the default weight parameters 、 、 and Based on the weight parameter Increase the preset first adjustment amount and set the weight parameter Reduce the preset first adjustment amount; for organizations of emergency projects, the default weight parameter 、 、 and Based on the weight parameter Increase the preset first adjustment amount and set the weight parameter Decrease the preset first adjustment amount.

5. The data authority access control method based on department structure and data confidentiality level according to claim 1 is characterized in that: Data in step S102 The acquisition of data confidentiality assessment value includes: S301, calculate data according to the following formula Data security sensitivity score : , in, and are the weight coefficient and score value of the i-th scoring indicator, respectively. The scoring indicators include some or all of importance, sensitivity, scope of impact, compliance requirements, data update frequency, and data storage method; S302, according to the data Data security sensitivity score The size of the data The level of confidentiality; S303, the data The confidentiality level is mapped to data The data confidentiality assessment value.

6. The data authority access control method based on department structure and data confidentiality level according to claim 1 is characterized in that: In step S102, the user Operation The acquisition of the role operation permission evaluation value includes: S401, get user The role hierarchy among all roles includes some or all of the system administrators, department administrators, and ordinary employees, and the role hierarchy is mapped to the role hierarchy weight; get operation The operation level in the overall operation, including some or all of delete, modify, and view, and the operation level is mapped to the operation authority weight; S402, divide the role level weight by the operation authority weight to obtain the user Operation Role operation permission evaluation value .

7. The data authority access control method based on department structure and data confidentiality level according to claim 1 is characterized in that: The function expression for obtaining the comprehensive access control evaluation value by weighted summation in step S103 is: , in, represents the comprehensive access control evaluation value, 、 and is the weight coefficient, , For users Department With data Department The strength of interdepartmental relationships, For data The data confidentiality assessment value, For users Operation The role operation permission evaluation value.

8. A data authority access control system based on departmental structure and data confidentiality level, comprising a microprocessor and a memory connected to each other, characterized in that: The microprocessor is programmed or configured to execute the data authority access control method based on department structure and data confidentiality level as described in any one of claims 1 to 7.

9. A computer-readable storage medium having a computer program or instruction stored therein, characterized in that: The computer program or instruction is programmed or configured to execute the data authority access control method based on department structure and data confidentiality level described in any one of claims 1 to 7 through a processor.

10. A computer program product comprising a computer program or instructions, characterized in that The computer program or instruction is programmed or configured to execute the data authority access control method based on department structure and data confidentiality level described in any one of claims 1 to 7 through a processor.

Citation Information

Patent Citations

  • Data permission design method based on multi-node organization mechanism

    CN117436124A

  • Data authority management method, system and device based on organization and storage medium

    CN119168501A

Cited By

  • A message transmission control method of a secret-involved instant communication system

    CN122554424A