Multi-level data security access control and trusted exchange device

By building a multi-level data security access control and trusted exchange device, the problem of integrated big data security sharing management and control in the existing technology is solved, fine-grained data access control and high-reliability behavior assessment are achieved, and the comprehensiveness and reliability of big data security sharing are ensured.

CN120658491APending Publication Date: 2025-09-16SHAANXI POLICE VOCATIONAL COLLEGE (SHAANXI POLITICAL & LEGAL MANAGEMENT CADRE COLLEGE)
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510957663.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-11
Publication Date
2025-09-16

Smart Images

  • Figure CN120658491A_ABST
    Figure CN120658491A_ABST
Patent Text Reader

Abstract

The invention discloses a multi-level data security access control and trusted exchange device, and relates to the technical field of data processing, and the technical scheme is characterized in that the multi-level data security access control and trusted exchange device comprises the following steps: constructing a large-scale sensitive data multi-level security sharing management and control architecture in a data layer, and realizing formalized representation of shared data and dynamic construction of a sensitive data cross-domain access interface; the authority layer realizes data approval and authority confirmation, service feature-oriented fine-grained extensible access control and a dynamic collaborative encryption and decryption strategy in a resource-constrained environment; the behavior layer constructs a multi-dimensional trust evaluation system, a behavior evaluation model and an indirect trust synthesis mechanism. According to complex characteristics of big data, full-process management and control of data sharing are realized, security and compliance of data sharing are improved, risks of data leakage and abuse are effectively prevented, meanwhile, cross-department collaboration and data utilization efficiency are promoted, organization intellectualization and informatization processes are promoted, and the method is suitable for large-scale popularization and application. And a powerful support is provided for improving the public safety level and the treatment efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data processing, and more particularly to a multi-level data security access control and trusted exchange device. Background Art

[0002] With the rapid development of information technology, the application of big data technology is becoming increasingly widespread. Big data is characterized by high information sensitivity, wide industry coverage, and complex data management. It encompasses a wide range of data types, including video surveillance, mobile phone signaling, biometrics, and behavioral trajectories. The efficient use of this data is crucial for improving police agencies' predictive, early warning, and prevention capabilities, and for achieving smart policing. Intelligent analysis of massive data assets enables real-time perception of public security and traffic trends, providing a data foundation for scientific decision-making. It also enables the effective acquisition of intelligence leads, enabling targeted strikes and improving case detection efficiency.

[0003] There have been several related technical studies and applications in the areas of secure management and trusted exchange of big data. For example, some studies have designed intelligent systems based on big data, explored approaches and methods for establishing a new normal working model in the context of big data, and achieved the management and control of data assets. Other scholars have proposed a legal regulatory system for police data security, establishing a protection approach based on data classification and grading, and the security obligations of controllers. Regarding data exchange models and management architectures, domestic and international scholars have also proposed various models and architectures, such as a blockchain-based multi-authority fine-grained access control system and a secure data sharing system in a cloud computing environment. These studies have promoted technological advancements in the secure exchange of public data.

[0004] However, when faced with the complex characteristics of big data, existing technologies still have limitations in the following aspects: (1) Traditional security exchange architectures are difficult to achieve integrated security management of the entire process, and are unable to build a new integrated data exchange security management model from multiple dimensions such as data, permissions, and behavior; (2) In terms of access control technology, although fine-grained access control technology based on cryptography is a research hotspot, existing technologies are difficult to fully cope with the complex approval process, changing business needs, and diverse security levels of big data out-of-domain, and cannot meet the needs of dynamic permission updates and differentiated security protection; (3) In terms of data exchange behavior evaluation, existing research mainly focuses on models such as trust management, abnormal behavior detection, and behavior pattern analysis, but it is difficult to effectively integrate multi-source trust evidence and deal with uncertainty and incomplete information in complex data exchange environments, resulting in insufficient credibility and accuracy of behavior evaluation results.

[0005] Therefore, the present invention aims to provide a multi-level data security access control and trusted exchange device to solve the above problems. Summary of the Invention

[0006] The purpose of the present invention is to provide a multi-level data security access control and trusted exchange device. In view of the complex characteristics of big data, the present invention realizes the full-process control of data sharing, improves the security and compliance of data sharing, effectively prevents the risks of data leakage and abuse, and optimizes the overall performance and robustness of the device, ensuring the stable and reliable operation of the device, promoting cross-departmental collaboration and data utilization efficiency, promoting the intelligentization and informatization of government agencies, and providing strong support for improving the level of public safety and governance effectiveness.

[0007] The above-mentioned technical purpose of the present invention is achieved through the following technical solutions: a multi-level data security access control and trusted exchange device, including a data layer, a permission layer and a behavior layer; the data layer is used to construct a large-scale sensitive data multi-level security sharing management and control architecture, realize the formal representation of shared data and the dynamic construction of cross-domain access interfaces for sensitive data, the permission layer is based on fine-grained hierarchical access control technology with configurable attribute encryption, and is used to realize data approval and right confirmation, fine-grained scalable access control oriented to business features, and dynamic collaborative encryption and decryption strategies in resource-constrained environments, the behavior layer is based on data exchange behavior evaluation technology based on distributed trust management, and is used to construct a multi-dimensional trust evaluation system, a behavior evaluation model and an indirect trust synthesis mechanism; the data layer, permission layer and behavior layer work together to realize integrated security sharing management and control from multiple levels of data, permissions and behavior.

[0008] The present invention is further configured as follows: the data layer includes a shared data formal representation module and a sensitive data cross-domain access interface dynamic construction module; the shared data formal representation module is used to set a variety of data classification forms and multi-dimensional data attribute information according to data characteristics, forming a formal description method based on data security level and attribute category; the sensitive data cross-domain access interface dynamic construction module is used to divide the management layer and service layer based on the data security level, and dynamically construct a data sharing access interface according to different security levels and user organizational structure information.

[0009] The present invention is further configured as follows: the permission layer includes a data approval and right confirmation module, a fine-grained extensible access control module and a dynamic collaborative encryption and decryption module; the data approval and right confirmation module is based on a weight threshold signature, and is used to combine hierarchical weight setting and threshold signature technology to set hierarchical weights for approvers of different authority levels, and generate aggregate signature information as an authorized domain certificate and a proof of right confirmation; the fine-grained extensible access control module is oriented to business characteristics, and is used to propose a dynamic extensible attribute embedding method and a hierarchical fine-grained access control strategy, and adopt different encryption processing methods according to data of different security levels; the dynamic collaborative encryption and decryption module is used to design a hierarchical game model in a resource-constrained environment, optimize the computing resources of distributed edge computing servers, and reduce the time cost of encryption and decryption.

[0010] The present invention is further configured as follows: the behavior layer includes a multidimensional trust evaluation system module, a behavior evaluation model module and an indirect trust synthesis mechanism module; the multidimensional trust evaluation system module is used to collect and analyze historical data, construct a trust evaluation system from multiple dimensions such as accuracy, completeness, timeliness, compliance and stability of data exchange, and combine multi-source data fusion technology and Transformer technology to improve the comprehensiveness and accuracy of the evaluation; the behavior evaluation model module is used to combine direct trust and indirect trust mechanisms, design a dynamic weight strategy and a trust propagation update mechanism, and generate a comprehensive trust score; the indirect trust synthesis mechanism module is used to use the Dempster-Shafer evidence theory to synthesize and analyze trust evidence from different sources, and handle conflicts and inconsistencies between evidence.

[0011] The present invention is further configured as follows: the device also includes a testing and verification module, which is used to build a sensitive data platform in a real environment, perform integrated testing, verification and improvement on the device, verify the security protection and defense capabilities of the device in diverse intelligent attack scenarios through security assessments oriented to attack scenarios, and continuously provide feedback and optimize models and algorithms to improve the performance and robustness of the device.

[0012] The present invention also provides a multi-level data security access control and trusted exchange method, comprising the following steps:

[0013] S1. Use the data layer to build a large-scale, multi-level, secure sharing and management architecture for sensitive data, enabling formal representation of shared data and dynamic construction of cross-domain access interfaces for sensitive data.

[0014] S2, fine-grained hierarchical access control technology based on configurable attribute encryption, using permission layers to achieve data approval and authorization, fine-grained scalable access control based on business characteristics, and dynamic collaborative encryption and decryption strategies in resource-constrained environments;

[0015] S3, data exchange behavior assessment technology based on distributed trust management, using the behavior layer to build a multi-dimensional trust assessment system, behavior assessment model and indirect trust synthesis mechanism;

[0016] S4. Conduct integrated testing and verification of the entire device, and continuously improve and optimize models and algorithms.

[0017] The present invention is further configured such that the integrated testing and verification of the entire device in step S4 includes the following steps:

[0018] S41. Build a sensitive data platform in a real environment and conduct integrated testing, verification, and improvement of the device;

[0019] S42. Verify the device's security protection and defense capabilities under diverse intelligent attack scenarios through attack scenario-oriented security assessments.

[0020] S43. Based on the evaluation results, continuously provide feedback and optimize the model and algorithm to improve the overall performance and robustness of the device.

[0021] The present invention also provides a multi-level data security access control and trusted exchange device, comprising at least one processor; and a memory communicatively connected to at least one of the processors; wherein the memory stores instructions executable by the processor, and the instructions are used to be executed by the processor to implement a multi-level data security access control and trusted exchange method.

[0022] The present invention also provides a computer-readable storage medium, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to be executed by the computer to implement a multi-level data security access control and trusted exchange method.

[0023] The present invention also provides a computer program product, comprising a computer program, wherein when the computer program is executed by a processor, a multi-level data security access control and trusted exchange method is implemented.

[0024] In summary, the present invention has the following beneficial effects:

[0025] 1. This invention can achieve integrated security sharing and management. By building a multi-layered architecture in which the data layer, permission layer, and behavior layer work together, it effectively addresses the shortcomings of existing technologies in multi-layered collaborative management and control. It truly realizes an integrated security sharing and management system covering multiple layers, including data, permission, and behavior. It can comprehensively address the complex challenges in data security sharing and provide comprehensive protection for the secure sharing of big data.

[0026] 2. This invention effectively improves the granularity and efficiency of access control. Through fine-grained hierarchical access control technology based on configurable attribute encryption, it can implement dynamic and scalable access control based on business characteristics, providing differentiated protection for data of different security levels. At the same time, in resource-constrained environments, the dynamic collaborative encryption and decryption strategy adopted effectively improves encryption and decryption efficiency, meeting the needs of complex business scenarios, ensuring that data access control is both refined and efficient, and fully meeting the complex and ever-changing business needs and security requirements of big data.

[0027] 3. This invention enhances the credibility and accuracy of behavior assessments. By utilizing data exchange behavior assessment technology based on distributed trust management, integrating multi-source trust evidence, and utilizing a multi-dimensional trust assessment system, a behavior assessment model based on hybrid trust management, and an indirect trust synthesis mechanism based on evidence theory, it can effectively handle uncertainty and incomplete information in complex data exchange environments, thereby generating more reliable and accurate behavior assessment results, ensuring the credibility and controllability of large-scale data exchange behaviors and providing strong support for the trusted exchange of big data.

[0028] 4. This invention improves the security and compliance of data sharing. By utilizing a formalized representation mechanism for shared data and a method for dynamically constructing a cross-domain access interface for sensitive data, it ensures the compliance and security of data during sharing, effectively preventing the risks of data leakage and abuse. It meets the characteristics of high data sensitivity and strict compliance requirements, and lays a solid foundation for the legal and secure sharing of big data.

[0029] 5. This invention improves the performance and robustness of the device. Utilizing a closed-loop testing and verification mechanism of test-feedback-optimization, it can continuously evaluate, provide feedback, and optimize the entire device, continuously improving the performance and robustness of the device. This provides it with strong security protection and defense capabilities in diverse intelligent attack scenarios, ensuring stable and reliable operation of the device and providing strong support for the long-term secure sharing and trusted exchange of big data.

[0030] 6. This invention can promote cross-departmental collaboration and data utilization efficiency. By building an efficient and reliable data exchange environment, it breaks down data silos within the system and between other departments, promotes the improvement of cross-departmental collaboration efficiency, fully unleashes the value of big data, and provides a more reliable and accurate data foundation for big data intelligent analysis, thereby promoting the intelligentization and informatization of government agencies and improving social governance efficiency and public safety.

[0031] 7. The present invention can protect citizens' privacy and enhance their sense of trust. While realizing data sharing, it can effectively protect citizens' privacy, avoid data leakage and abuse, and enhance citizens' trust in the government and departments. By establishing a reliable data exchange mechanism, it promotes data sharing under the premise of legality and compliance, improves data utilization efficiency, and makes positive contributions to building a harmonious and stable social environment. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] Figure 1 This is a schematic diagram of the hierarchical structure of a multi-level data security access control and trusted exchange device in Example 1 of the present invention;

[0033] Figure 2 This is a schematic diagram of the module structure of the data layer in Example 1 of the present invention;

[0034] Figure 3 This is a schematic diagram of the module structure of the permission layer in Example 1 of the present invention;

[0035] Figure 4 This is a schematic diagram of the module structure of the behavior layer in Example 1 of the present invention;

[0036] Figure 5 This is a schematic diagram of the structure of a multi-level data security access control and trusted exchange device in Example 3 of the present invention;

[0037] Figure 6 This is a flow chart of a multi-level data security access control and trusted exchange method in Example 2 of the present invention;

[0038] Figure 7 is a schematic flow chart of step S4 in Example 2 of the present invention;

[0039] Figure 8 This is a block diagram of a computer-readable storage medium in Example 4 of the present invention.

[0040] Figure 9 This is an axial schematic diagram of the device hardware terminal in Example 3 of the present invention.

[0041] In the figure: 1. Data layer; 101. Shared data formal representation module; 102. Dynamic construction module of sensitive data cross-domain access interface; 2. Permission layer; 201. Data approval and right confirmation module; 202. Fine-grained extensible access control module; 203. Dynamic collaborative encryption and decryption module; 3. Behavior layer; 301. Multi-dimensional trust assessment system module; 302. Behavior assessment model module; 303. Indirect trust synthesis mechanism module; 4. Memory; 5. Processor; 6. Device hardware terminal. DETAILED DESCRIPTION

[0042] The following is combined with Figures 1-9 The present invention is described in further detail.

[0043] Embodiment 1: A multi-level data security access control and trusted exchange device, comprising a data layer 1, an authority layer 2 and a behavior layer 3; wherein the data layer 1 is used to construct a large-scale multi-level secure sharing and control architecture for sensitive data, to realize the formal representation of shared data and the dynamic construction of cross-domain access interfaces for sensitive data; the authority layer 2 is based on fine-grained hierarchical access control technology with configurable attribute encryption, to realize data approval and right confirmation, fine-grained scalable access control oriented to business features, and dynamic collaborative encryption and decryption strategies in resource-constrained environments; the behavior layer 3 is based on data exchange behavior evaluation technology with distributed trust management, to construct a multi-dimensional trust evaluation system, a behavior evaluation model and an indirect trust synthesis mechanism; the data layer 1, the authority layer 2 and the behavior layer 3 work together to realize integrated secure sharing and control from multiple levels of data, authority and behavior.

[0044] At the data layer 1, building a multi-level secure sharing and control architecture for large-scale sensitive data is the basis for achieving secure data sharing. Due to its high sensitivity, wide range of industry involvement, and complex business management characteristics, data requires a universal and scalable architecture to ensure the security and compliance of data during the sharing process.

[0045] Preferably, in this embodiment, the data layer 1 includes a shared data formal representation module 101 and a sensitive data cross-domain access interface dynamic construction module 102; the shared data formal representation module 101 is used to set a variety of data classification forms and multi-dimensional data attribute information according to the characteristics of the data, and form a formal description method based on data security levels and attribute categories; the sensitive data cross-domain access interface dynamic construction module 102 is used to divide the management layer and the service layer based on the data security level, and dynamically construct a data sharing access interface according to different security levels and user organizational structure information.

[0046] In the optimization of the formal representation mechanism of shared data, in view of the particularity of data, this embodiment not only sets up multiple data classification forms, such as public, general, important and special, but also refines data attribute information from multiple dimensions such as basic information, biometric information, geographic location information, behavioral information, etc. Through intelligent analysis and understanding of information metadata, key identification features can be extracted, thereby providing an accurate theoretical basis for the rule model of dynamic access automation judgment. For example, when processing data containing citizen identity information, the device can automatically identify and mark sensitive fields to ensure that these data are subject to strict security control during subsequent circulation.

[0047] To enhance the dynamic construction method for cross-domain access interfaces for sensitive data, this embodiment divides the exchange model into management and service layers based on the security level of public security information metadata, effectively isolating sensitive information from public information. When dynamically constructing data-sharing access interfaces, the device comprehensively considers factors such as user organizational structure information, security level, and business needs. For example, when different police departments need to share sensitive data related to a specific case, the system can quickly generate a secure and reliable access interface based on pre-set security policies and user permissions, ensuring the confidentiality and integrity of the data during cross-domain transmission.

[0048] As the core link of data access control, permission layer 2 realizes precise control of data access based on fine-grained hierarchical access control technology with configurable attribute encryption. In this embodiment, permission layer 2 preferably includes a data approval and right confirmation module 201, a fine-grained extensible access control module 202, and a dynamic collaborative encryption and decryption module 203; the data approval and right confirmation module 201 is based on a weight threshold signature, which is used to combine hierarchical weight setting and threshold signature technology to set hierarchical weights for approvers of different authority levels, and generate aggregate signature information as an authorization certificate and proof of right confirmation; the fine-grained extensible access control module 202 is oriented to business characteristics, and is used to propose a dynamic extensible attribute embedding method and a hierarchical fine-grained access control strategy, and adopt different encryption processing methods according to different security levels of data; the dynamic collaborative encryption and decryption module 203 is used to design a hierarchical game model in a resource-constrained environment, optimize the computing resources of distributed edge computing servers, and reduce the time cost of encryption and decryption.

[0049] In the refinement of data approval and authorization methods based on weighted threshold signatures, including complex data sharing scenarios, the data approval process often involves multiple departments and levels. By assigning hierarchical weights to approvers of varying authority, we can ensure that data can only be legally shared when a consensus is reached among approvers with sufficient weight. For example, when processing data related to major cases involving national security, the signatures of multiple high-level approvers may be required to complete data authorization and confirmation. This weighted threshold signature mechanism not only improves the efficiency of data approval, but also enhances the security and credibility of data flow.

[0050] In the process of expanding the fine-grained extensible access control method for business features, the diversity and dynamism of the business require that the access control strategy can flexibly adapt to different business scenarios. The dynamic extensible attribute embedding method proposed in this embodiment enables the system to adjust the access control attributes in a timely manner according to changes in business needs. For example, when facing new types of criminal activities, the system can quickly expand the access control attributes and incorporate new business features into the scope of access control considerations. At the same time, different encryption processing methods are used according to different security levels of data, such as using more efficient attribute-based encryption for low-sensitivity data and using more secure semi-homomorphic encryption for highly sensitive data, to ensure the security and privacy of data in circulation.

[0051] In the process of improving the dynamic collaborative encryption and decryption strategy in a resource-constrained environment, this embodiment takes into account the limited computing power of terminal devices and the uneven distribution of node computing resources, and designs a hierarchical game model to optimize the computing resource allocation of distributed edge computing servers. By analyzing the competition and cooperation relationship between terminal devices and edge computing nodes, the optimal resource allocation strategy can be found, thereby reducing the time cost in the encryption and decryption process. For example, in a large-scale data sharing scenario, when multiple terminal devices request access to encrypted data at the same time, the system can reasonably allocate computing resources through dynamic collaborative encryption and decryption strategies to ensure that each device can quickly complete the encryption and decryption operations of the data, thereby improving the efficiency of data access.

[0052] Behavior layer 3 is based on the data exchange behavior evaluation technology of distributed trust management, which provides a strong guarantee for ensuring the credibility and controllability of data exchange behavior. In this embodiment, behavior layer 3 preferably includes a multi-dimensional trust evaluation system module 301, a behavior evaluation model module 302, and an indirect trust synthesis mechanism module 303; the multi-dimensional trust evaluation system module 301 is used to collect and analyze historical data, build a trust evaluation system from multiple dimensions such as the accuracy, completeness, timeliness, compliance, and stability of data exchange, and combine multi-source data fusion technology and Transformer technology to improve the comprehensiveness and accuracy of the evaluation; the behavior evaluation model module 302 is used to combine direct trust and indirect trust mechanisms, design a dynamic weight strategy and trust propagation update mechanism, and generate a comprehensive trust score; the indirect trust synthesis mechanism module 303 is used to use the Dempster-Shafer evidence theory to synthesize and analyze trust evidence from different sources and handle conflicts and inconsistencies between evidence.

[0053] This embodiment enriches the multi-dimensional trust evaluation system based on historical data. By collecting and analyzing historical data from different departments or data sharing entities, we have built a comprehensive trust evaluation system for exchange behavior. This system covers indicators in multiple dimensions such as accuracy, completeness, timeliness, compliance, and stability of data exchange. For example, a department that frequently provides high-quality and accurate data will have a higher score in the trust evaluation system; while departments with unstable data quality or violations will have their scores penalized accordingly. At the same time, by combining multi-source data fusion technology and Transformer technology, we can more deeply understand and analyze multimodal historical data, improving the comprehensiveness and accuracy of the evaluation results.

[0054] In optimizing the behavior assessment model based on hybrid trust management, including in complex and dynamic data exchange environments, this embodiment utilizes a hybrid trust assessment model designed to fully leverage both direct and indirect trust information. Direct trust is based on direct interactions and historical experience between nodes, while indirect trust is gained through trust propagation and information sharing. For example, when there is no direct interaction record between one department and another, the system can assess their trust value through other trusted intermediaries. By dynamically adjusting the weights of direct and indirect trust, this embodiment can generate a more comprehensive and reliable trust score, thereby achieving a more accurate assessment of data exchange behavior.

[0055] In improving the indirect trust synthesis mechanism based on evidence theory, this embodiment utilizes the Dempster-Shafer evidence theory to effectively integrate trust evidence from multiple sources, even if there are conflicts and inconsistencies between these evidence sources. For example, when evaluating the trust value of a newly added data sharing node, the system can comprehensively consider the evaluation and feedback of the node from different departments and generate a reasonable trust score through evidence synthesis rules. Furthermore, this embodiment considers the sequential reward and penalty effects of continuous trusted and untrusted operations, further improving the reliability and effectiveness of the indirect trust synthesis mechanism.

[0056] Preferably, the device of this embodiment further includes a testing and verification module, which is used to build a sensitive data platform in a real environment, perform integrated testing, verification and improvement on the device, verify the security protection and defense capabilities of the device in diverse intelligent attack scenarios through security assessments oriented to attack scenarios, and continuously provide feedback and optimize models and algorithms to improve the performance and robustness of the device.

[0057] Example 2: A multi-level data security access control and trusted exchange method, comprising the following steps:

[0058] S1. Use data layer 1 to build a large-scale multi-level secure sharing and control architecture for sensitive data, achieving formal representation of shared data and dynamic construction of cross-domain access interfaces for sensitive data;

[0059] S2, fine-grained hierarchical access control technology based on configurable attribute encryption, using permission layer 2 to achieve data approval and authorization, fine-grained scalable access control based on business characteristics, and dynamic collaborative encryption and decryption strategies in resource-constrained environments;

[0060] S3, data exchange behavior evaluation technology based on distributed trust management, uses behavior layer 3 to build a multi-dimensional trust evaluation system, behavior evaluation model and indirect trust synthesis mechanism;

[0061] S4. Conduct integrated testing and verification of the entire device, and continuously improve and optimize models and algorithms.

[0062] In this embodiment, the integrated testing and verification of the entire device in step S4 preferably includes the following steps:

[0063] S41. Build a sensitive data platform in a real environment and conduct integrated testing, verification, and improvement of the device;

[0064] S42. Verify the device's security protection and defense capabilities under diverse intelligent attack scenarios through attack scenario-oriented security assessments.

[0065] S43. Based on the evaluation results, continuously provide feedback and optimize the model and algorithm to improve the overall performance and robustness of the device.

[0066] Embodiment 3: A multi-level data security access control and trusted exchange device, comprising a device hardware terminal 6 and at least one processor 5; and a memory 4 communicatively connected to the at least one processor 5; wherein the memory 4 stores instructions that can be executed by the processor 5, and the instructions are used to be executed by the processor 5 to implement a multi-level data security access control and trusted exchange method, the method comprising: using the data layer 1 to construct a large-scale sensitive data multi-level security sharing management and control architecture to achieve formal representation of shared data and dynamic construction of cross-domain access interfaces for sensitive data; based on fine-grained hierarchical access control technology with configurable attribute encryption, using the permission layer 2 to achieve data approval and right confirmation, fine-grained scalable access control oriented to business features, and dynamic collaborative encryption and decryption strategies in resource-constrained environments; based on distributed trust management, data exchange behavior assessment technology, using the behavior layer 3 to construct a multi-dimensional trust assessment system, behavior assessment model, and indirect trust synthesis mechanism; building a sensitive data platform in a real environment, and performing integrated testing, verification, and improvement on the device; verifying the security protection and defense capabilities of the device in diverse intelligent attack scenarios through security assessments oriented to attack scenarios; and continuously providing feedback and optimizing models and algorithms based on the assessment results to improve the overall performance and robustness of the device.

[0067] Example 4: A computer-readable storage medium, which stores computer instructions, and the computer instructions are used to be executed by a computer to implement a multi-level data security access control and trusted exchange method, the method comprising: using data layer 1 to construct a large-scale multi-level security sharing management and control architecture for sensitive data, to achieve formal representation of shared data and dynamic construction of cross-domain access interfaces for sensitive data; based on fine-grained hierarchical access control technology with configurable attribute encryption, using permission layer 2, to achieve data approval and right confirmation, fine-grained scalable access control oriented to business features, and dynamic collaborative encryption and decryption strategies in resource-constrained environments; based on distributed trust management, data exchange behavior evaluation technology, using behavior layer 3, to construct a multi-dimensional trust evaluation system, behavior evaluation model, and indirect trust synthesis mechanism; building a sensitive data platform in a real environment, and performing integrated testing, verification, and improvement on the device; verifying the security protection and defense capabilities of the device in diverse intelligent attack scenarios through security evaluation oriented to attack scenarios; based on the evaluation results, continuously providing feedback and optimizing models and algorithms to improve the overall performance and robustness of the device.

[0068] Example 5: A computer program product includes a computer program, which implements a multi-level data security access control and trusted exchange method when executed by a processor 5, the method including: using the data layer 1 to construct a large-scale multi-level security sharing management and control architecture for sensitive data, to achieve formal representation of shared data and dynamic construction of cross-domain access interfaces for sensitive data; based on fine-grained hierarchical access control technology with configurable attribute encryption, using the permission layer 2 to achieve data approval and right confirmation, fine-grained scalable access control oriented to business features, and dynamic collaborative encryption and decryption strategies in resource-constrained environments; based on distributed trust management, data exchange behavior evaluation technology, using the behavior layer 3 to construct a multi-dimensional trust evaluation system, a behavior evaluation model, and an indirect trust synthesis mechanism; building a sensitive data platform in a real environment, and performing integrated testing, verification, and improvement on the device; verifying the security protection and defense capabilities of the device in diversified intelligent attack scenarios through security evaluation oriented to attack scenarios; and continuously providing feedback and optimizing models and algorithms based on the evaluation results to improve the overall performance and robustness of the device.

[0069] This specific embodiment is merely an explanation of the present invention and is not intended to limit the present invention. After reading this specification, those skilled in the art may make non-creative modifications to this embodiment as needed. However, as long as such modifications are within the scope of the claims of the present invention, they are protected by patent law.

Claims

1. A multi-level data security access control and trusted exchange device, characterized by: It includes a data layer, a permission layer and a behavior layer; the data layer is used to build a multi-level secure sharing and control architecture for large-scale sensitive data, realize the formal representation of shared data and the dynamic construction of cross-domain access interfaces for sensitive data; the permission layer is based on fine-grained hierarchical access control technology with configurable attribute encryption, and is used to realize data approval and right confirmation, fine-grained scalable access control for business features, and dynamic collaborative encryption and decryption strategies in resource-constrained environments; the behavior layer is based on data exchange behavior evaluation technology with distributed trust management, and is used to build a multi-dimensional trust evaluation system, a behavior evaluation model and an indirect trust synthesis mechanism; the data layer, permission layer and behavior layer work together to realize integrated secure sharing and control from multiple levels of data, permission and behavior.

2. A multi-level data security access control and trusted exchange device according to claim 1, characterized in that: The data layer includes a shared data formal representation module and a sensitive data cross-domain access interface dynamic construction module; the shared data formal representation module is used to set multiple data classification forms and multi-dimensional data attribute information according to data characteristics, and form a formal description method based on data security level and attribute category; the sensitive data cross-domain access interface dynamic construction module is used to divide the management layer and service layer based on the data security level, and dynamically construct a data sharing access interface according to different security levels and user organizational structure information.

3. The multi-level data security access control and trusted exchange device according to claim 1, characterized in that: The permission layer includes a data approval and right confirmation module, a fine-grained extensible access control module and a dynamic collaborative encryption and decryption module; the data approval and right confirmation module is based on weight threshold signature, and is used to combine hierarchical weight setting and threshold signature technology to set hierarchical weights for approvers of different levels of authority, and generate aggregate signature information as an authorized domain certificate and right confirmation certificate; the fine-grained extensible access control module is oriented towards business characteristics, and is used to propose a dynamic extensible attribute embedding method and a hierarchical fine-grained access control strategy, and adopt different encryption processing methods according to data of different security levels; the dynamic collaborative encryption and decryption module is used to design a hierarchical game model in a resource-constrained environment, optimize the computing resources of distributed edge computing servers, and reduce the time cost of encryption and decryption.

4. The multi-level data security access control and trusted exchange device according to claim 1, characterized in that: The behavior layer includes a multi-dimensional trust evaluation system module, a behavior evaluation model module and an indirect trust synthesis mechanism module; The multi-dimensional trust assessment system module is used to collect and analyze historical data, build a trust assessment system from multiple dimensions such as accuracy, completeness, timeliness, compliance and stability of data exchange, and combine multi-source data fusion technology and Transformer technology to improve the comprehensiveness and accuracy of the assessment; the behavioral assessment model module is used to combine direct trust and indirect trust mechanisms, design dynamic weighting strategies and trust propagation update mechanisms, and generate comprehensive trust scores; the indirect trust synthesis mechanism module is used to use the Dempster-Shafer evidence theory to synthesize and analyze trust evidence from different sources and handle conflicts and inconsistencies between evidence.

5. The multi-level data security access control and trusted exchange device according to claim 1, characterized in that: The device also includes a testing and verification module, which is used to build a sensitive data platform in a real environment, perform integrated testing, verification and improvement on the device, verify the device's security protection and defense capabilities in diverse intelligent attack scenarios through attack scenario-oriented security assessments, and continuously provide feedback and optimize models and algorithms to improve the performance and robustness of the device.

6. A multi-level data security access control and trusted exchange method, applied to a multi-level data security access control and trusted exchange device according to any one of claims 1 to 5, characterized in that: The following steps are involved: S1. Use the data layer to build a large-scale, multi-level, secure sharing and management architecture for sensitive data, enabling formal representation of shared data and dynamic construction of cross-domain access interfaces for sensitive data. S2, fine-grained hierarchical access control technology based on configurable attribute encryption, using permission layers to achieve data approval and authorization, fine-grained scalable access control based on business characteristics, and dynamic collaborative encryption and decryption strategies in resource-constrained environments; S3, data exchange behavior assessment technology based on distributed trust management, using the behavior layer to build a multi-dimensional trust assessment system, behavior assessment model and indirect trust synthesis mechanism; S4. Conduct integrated testing and verification of the entire device, and continuously improve and optimize models and algorithms.

7. A multi-level data security access control and trusted exchange method according to claim 6, characterized in that: The integrated testing and verification of the entire device in step S4 includes the following steps: S41. Build a sensitive data platform in a real environment and conduct integrated testing, verification, and improvement of the device; S42. Verify the device's security protection and defense capabilities under diverse intelligent attack scenarios through attack scenario-oriented security assessments. S43. Based on the evaluation results, continuously provide feedback and optimize the model and algorithm to improve the overall performance and robustness of the device.

8. A multi-level data security access control and trusted exchange device, characterized by: It includes at least one processor; and a memory communicatively connected to at least one of the processors; wherein the memory stores instructions executable by the processor, and the instructions are used to be executed by the processor to implement a multi-level data security access control and trusted exchange method as described in any one of claims 6-7.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to be executed by the computer to implement a multi-level data security access control and trusted exchange method according to any one of claims 6-7.

10. A computer program product, characterized in that: The invention comprises a computer program, which, when executed by a processor, implements a multi-level data security access control and trusted exchange method according to any one of claims 6 to 7.

Citation Information

Cited By

  • Information management system of government affair information system based on data sharing and exchange

    CN121353043A