Security policy construction method and system based on level authentication and application auditing

By dynamically adjusting permission levels and real-time monitoring of user behavior, combined with isolated applications and on-chain technology, the problem of a single authentication method for Internet devices is solved, improving data security and management efficiency.

CN120675748APending Publication Date: 2025-09-19HUANENG INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510748828.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-05
Publication Date
2025-09-19

AI Technical Summary

Technical Problem

The authentication methods of existing Internet devices are single, which can easily lead to malicious user operations and data leakage, and lack an effective application audit mechanism.

Method used

By dynamically adjusting permission levels based on the number of historical user logins, combined with real-time monitoring of user browsing behavior, using isolated applications and real-time chain technology, limiting network speed and data display ratio, a multi-level security strategy is implemented.

Benefits of technology

It improves the pertinence of user authentication and data security, reduces the risk of data leakage, and realizes intelligent and efficient security management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120675748A_ABST
    Figure CN120675748A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of computers, in particular to a security policy construction method and system based on level authentication and application auditing. Comprising the following steps: acquiring user information of a user logging in an account; obtaining a preset permission set, wherein a permission level corresponding to the user is preset in the preset permission set; the user information is input into a detection model which is used for detecting whether a user name exists or not, and user permission is determined according to a detection result; and displaying data information corresponding to the user permission for the user according to the user permission, setting an isolation application program for the data information, and uploading the data information in real time through the isolation application program according to the browsing time of the user. Different authority levels are given to the user based on different historical login detection times of the user, the problem that a traditional authentication mode is single is solved, real-time monitoring is carried out in the data browsing process of the user, and the problem of data leakage caused by manual malicious operation is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technology, and in particular to a method and system for constructing a security policy based on level authentication and application auditing. Background Art

[0002] With the rapid development of Internet technology, the security issues facing Internet devices are becoming increasingly prominent. Specifically, the security issues facing Internet devices are essentially the same as those facing the Internet: illegal operations.

[0003] However, in the prior art, existing Internet devices usually authenticate operation requests by setting an Internet device activation password corresponding to different users, thereby preventing illegal operations on Internet devices. However, there is a problem of a single authentication method for operation requests, and it will be accompanied by malicious information theft by users. When users browse data for too long, the possibility of data leakage increases, which is not conducive to the security and stability of enterprise data. Therefore, how to provide a security policy construction method and system based on level authentication and application auditing is a technical problem that technical personnel in this field urgently need to solve. Summary of the Invention

[0004] The purpose of the present invention is to provide a security policy construction method and system based on level authentication and application auditing. The present invention grants users different authority levels based on the number of different historical login detections of users, thereby changing the problem of the single traditional authentication method, and conducting real-time monitoring during the user's data browsing process, thereby reducing the problem of data leakage caused by malicious human operations.

[0005] In order to achieve the above object, the present invention provides the following technical solutions: A method for constructing a security policy based on level authentication and application auditing, characterized by comprising: Obtain user information of the user who logged in to the account, the user information including the user name; Obtaining a preset permission set, wherein the preset permission set includes permission levels corresponding to the user, and the permission levels in the preset permission set are sorted in descending order, and each permission level corresponds to a preset threshold; The user information is input into a detection model, and the detection model is used to detect whether the user name exists and determine the user authority according to the detection result; wherein, When the user name is detected to exist, the permission level corresponding to the user name is obtained, and the number of times the user name has been obtained in history is obtained. When the number of times the user name has been obtained in history is greater than the preset threshold, the permission level corresponding to the number greater than the preset threshold is used as the permission level of the user. When the number of times the user name has been obtained in history is not greater than the preset threshold, the permission level corresponding to the user name is used as the permission level of the user. According to the user permissions, data information corresponding to the user permissions is displayed to the user, and an isolation application is set for the data information. According to the browsing time of the user, the data information is uploaded to the chain in real time through the isolation application.

[0006] In some embodiments of the present application, when displaying data information corresponding to the user authority to the user according to the user authority, the method further includes: limiting the network speed when displaying the data information corresponding to the user authority to the user, including: Obtaining user information of a predetermined number of sample users and using the ratio of the number of sample users of each permission level to the predetermined number as the network speed corresponding to each permission level; Obtain the number of times the user name was obtained in history corresponding to each permission level; The product of the number of times the user name was obtained historically corresponding to each authority level and the network speed corresponding to each authority level is used as the number of times the user name was obtained historically corresponding to each authority level, and the sum of the number of times the user name was obtained historically corresponding to each authority level is used as the total number of times the user name was obtained historically; The network speed corresponding to each of the authority levels that maximizes the total number of times is determined, and the network speed is used as the network speed corresponding to the authority level.

[0007] In some embodiments of the present application, uploading the data information to the chain in real time through the isolated application according to the browsing time of the user includes: Obtaining a browsing time threshold corresponding to the user's permission; when the user's browsing time is greater than the browsing time threshold, determining the total number of bytes of the data information displayed to the user; and according to the ratio i of the user's browsing time to the total number of bytes, uploading the content of the data information to the chain in real time according to a preset ratio; wherein, The unit of the browsing time is minutes; A preset ratio parameter matrix T0 and a preset link ratio matrix A are preset. For the preset link ratio matrix A, A(A1, A2, A3, A4) is set, where A1 is the first preset link ratio, A2 is the second preset link ratio, A3 is the third preset link ratio, and A4 is the fourth preset link ratio, and 50% < A1 < A2 < A3 < A4 < 90%; For the preset scaling parameter matrix T0, set T0(T01, T02, T03, T04), where T01 is the first preset scaling parameter, T02 is the second preset scaling parameter, T03 is the third preset scaling parameter, and T04 is the fourth preset scaling parameter, and 0.06 min / Byte<T01<T02<T03<T04<0.1 min / Byte; When the browsing time of the user is greater than the browsing time threshold, a corresponding linking ratio is selected according to the relationship between i and the preset ratio parameter matrix T0 as the ratio of real-time linking of the content in the data information; When i<T01, the first preset linking ratio A1 is selected as the ratio for real-time linking of the content in the data information; When T01≤i<T02, the second preset linking ratio A2 is selected as the ratio for linking the content in the data information in real time; When T02≤i<T03, the third preset linking ratio A3 is selected as the ratio for linking the content in the data information in real time; When T03≤i<T04, the fourth preset linking ratio A4 is selected as the ratio for linking the content in the data information in real time.

[0008] In some embodiments of the present application, after obtaining the user information of the user, the method further includes: The user's face is recognized through a preset database, and the recognition result is determined. When the recognition result is that the verification is passed, the preset permission set is obtained. When the recognition result is that the verification is failed, the user's face recognition is stopped within a preset time, and the user information of the user is recorded.

[0009] In some embodiments of the present application, further comprising: When the total number of times the user information of the user is recorded is greater than three times, the login account of the user is frozen.

[0010] To achieve the above objectives, the present invention also provides a security policy construction system based on level authentication and application audit, which is applied to the security policy construction method based on level authentication and application audit, and includes: An acquiring unit, configured to acquire user information of a user who has logged into an account, the user information including a user name; a processing unit, configured to obtain a preset permission set, wherein the preset permission set includes permission levels corresponding to the user, and the permission levels in the preset permission set are sorted in descending order, and each permission level corresponds to a preset threshold; A detection unit, wherein a detection model is preset in the detection unit, and the detection model is used to detect whether the user name exists and determine the user authority according to the detection result; wherein, When the user name is detected to exist, the permission level corresponding to the user name is obtained, and the number of times the user name has been obtained in history is obtained. When the number of times the user name has been obtained in history is greater than the preset threshold, the permission level corresponding to the number greater than the preset threshold is used as the permission level of the user. When the number of times the user name has been obtained in history is not greater than the preset threshold, the permission level corresponding to the user name is used as the permission level of the user. The display unit is used to display data information corresponding to the user authority to the user according to the user authority, and set an isolation application for the data information, and upload the data information to the chain in real time through the isolation application according to the user's browsing time.

[0011] In some embodiments of the present application, the display unit is further configured to limit the network speed when displaying data information corresponding to the user authority to the user; The display unit is further configured to obtain user information of a predetermined number of sample users and use the ratio of the number of sample users of each authority level to the predetermined number as the network speed corresponding to each authority level; The display unit is further configured to obtain the number of times the user name is obtained in history corresponding to each authority level; The display unit is further configured to calculate the product of the number of times the user name was obtained historically corresponding to each authority level and the network speed corresponding to each authority level as the number of times the user name was obtained historically corresponding to each authority level, and calculate the sum of the number of times the user name was obtained historically corresponding to each authority level as the total number of times the user name was obtained historically; The display unit is further configured to determine a network speed corresponding to each authority level that maximizes the total number of times, and use the network speed as the network speed corresponding to the authority level.

[0012] In some embodiments of the present application, the display unit is further configured to obtain a browsing time threshold corresponding to the user authority, and when the user's browsing time is greater than the browsing time threshold, determine the total number of bytes of the data information displayed to the user, and based on the ratio i of the user's browsing time to the total number of bytes, upload the content of the data information to the chain in real time according to a preset ratio; wherein, The unit of the browsing time is minutes; The display unit is pre-set with a preset ratio parameter matrix T0 and a preset link ratio matrix A. For the preset link ratio matrix A, A(A1, A2, A3, A4) is set, where A1 is a first preset link ratio, A2 is a second preset link ratio, A3 is a third preset link ratio, and A4 is a fourth preset link ratio, and 50% < A1 < A2 < A3 < A4 < 90%; For the preset scaling parameter matrix T0, set T0(T01, T02, T03, T04), where T01 is the first preset scaling parameter, T02 is the second preset scaling parameter, T03 is the third preset scaling parameter, and T04 is the fourth preset scaling parameter, and 0.06 min / Byte<T01<T02<T03<T04<0.1 min / Byte; The display unit is further configured to select a corresponding linking ratio as a ratio for real-time linking of the content in the data information according to a relationship between i and the preset ratio parameter matrix T0 when the browsing time of the user is greater than the browsing time threshold; When i<T01, the first preset linking ratio A1 is selected as the ratio for real-time linking of the content in the data information; When T01≤i<T02, the second preset linking ratio A2 is selected as the ratio for linking the content in the data information in real time; When T02≤i<T03, the third preset linking ratio A3 is selected as the ratio for linking the content in the data information in real time; When T03≤i<T04, the fourth preset linking ratio A4 is selected as the ratio for linking the content in the data information in real time.

[0013] In some embodiments of the present application, the acquisition unit is also used to perform facial recognition on the user through a preset database and determine the recognition result. When the recognition result is verification passed, the preset permission set is obtained. When the recognition result is verification failed, the user is stopped from performing facial recognition within a preset time and the user information of the user is recorded.

[0014] In some embodiments of the present application, the acquisition unit is further configured to freeze the login account of the user when the total number of times the user information of the user is recorded is greater than three times.

[0015] The present invention provides a security policy construction method and system based on level authentication and application auditing. Compared with the existing technology, its beneficial effects are: The present invention dynamically adjusts the user's level authority in a timely manner by combining the number of times the user name is obtained historically. The more times the user name is obtained, the more adaptively the user is given higher authority, which fully ensures that each user can be authenticated in a targeted manner. It also determines different browsing times according to different authorities through the process of real-time monitoring of data display, and ensures data coverage and browsing while ensuring data security to the greatest extent. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 This is a flow chart of a method for constructing a security policy based on level authentication and application auditing in an embodiment of the present invention; Figure 2 It is a functional block diagram of a security policy construction system based on level authentication and application auditing in an embodiment of the present invention. DETAILED DESCRIPTION

[0017] The following embodiments of the present invention are described in further detail with reference to the accompanying drawings and examples. The following examples are used to illustrate the present invention but are not intended to limit the scope of the present invention.

[0018] In the description of this application, it should be understood that the terms "center", "up", "down", "front", "back", "left", "right", "vertical", "horizontal", "top", "bottom", "inside", "outside", etc., indicating the orientation or position relationship, are based on the orientation or position relationship shown in the accompanying drawings, and are only for the convenience of describing this application and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as a limitation on this application.

[0019] The terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of the technical features being referred to. Thus, a feature specified as "first" or "second" may explicitly or implicitly include one or more of such features. Throughout this application, unless otherwise specified, "plurality" means two or more.

[0020] In the description of this application, it should be noted that, unless otherwise expressly specified or limited, the terms "mounted," "connected," and "connected" should be understood in a broad sense. For example, they can refer to fixed connections, detachable connections, or integral connections; mechanical connections or electrical connections; direct connections or indirect connections through an intermediate medium; and internal connections between two components. Those skilled in the art will understand the specific meanings of the above terms in this application based on the specific circumstances.

[0021] See Figure 1 As shown, the disclosed embodiment of the present invention provides a security policy construction method based on level authentication and application auditing, which is characterized by including: Get the user information of the user who logged in to the account, including the user name; Obtain a preset permission set, wherein the preset permission set contains permission levels corresponding to the user, and the permission levels in the preset permission set are sorted in descending order, and each permission level corresponds to a preset threshold; The user information is input into the detection model, which is used to detect whether the user name exists and determine the user permissions based on the detection results; When the user name is detected, the permission level corresponding to the user name is obtained, and the number of times the user name has been obtained in the past is obtained. When the number of times the user name has been obtained in the past is greater than a preset threshold, the permission level corresponding to the threshold is used as the user's permission level. When the number of times the user name has been obtained in the past is not greater than the preset threshold, the permission level corresponding to the user name is used as the user's permission level. According to the user's permissions, data information corresponding to the user's permissions is displayed to the user, and an isolated application is set for the data information. The data information is uploaded to the chain in real time through the isolated application according to the user's browsing time.

[0022] In a specific embodiment of the present application, when displaying data information corresponding to the user's authority to the user according to the user's authority, it also includes: limiting the network speed when displaying the data information corresponding to the user's authority to the user, including: Obtaining user information of a predetermined number of sample users and using the ratio of the number of sample users at each permission level to the predetermined number as the network speed corresponding to each permission level; Get the number of times the user name was obtained in history for each permission level; The product of the number of historical user name acquisitions corresponding to each authority level and the network speed corresponding to each authority level is used as the number of historical user name acquisitions corresponding to each authority level, and the sum of the number of historical user name acquisitions corresponding to each authority level is used as the total number of historical user name acquisitions; The network speed corresponding to each authority level that maximizes the total number of times is determined, and the network speed is used as the network speed corresponding to the authority level.

[0023] In a specific embodiment of the present application, data information is uploaded to the chain in real time through an isolated application based on the user's browsing time, including: Obtain a browsing time threshold corresponding to the user's permission. When the user's browsing time is greater than the browsing time threshold, determine the total number of bytes of the data information displayed to the user, and based on the ratio i of the user's browsing time to the total number of bytes, upload the content of the data information to the chain in real time according to a preset ratio; wherein, The unit of browsing time is minutes; A preset ratio parameter matrix T0 and a preset link ratio matrix A are preset. For the preset link ratio matrix A, A(A1, A2, A3, A4) is set, where A1 is the first preset link ratio, A2 is the second preset link ratio, A3 is the third preset link ratio, and A4 is the fourth preset link ratio, and 50% < A1 < A2 < A3 < A4 < 90%; For the preset scaling parameter matrix T0, set T0(T01, T02, T03, T04), where T01 is the first preset scaling parameter, T02 is the second preset scaling parameter, T03 is the third preset scaling parameter, and T04 is the fourth preset scaling parameter, and 0.06 min / Byte < T01 < T02 < T03 < T04 < 0.1 min / Byte; When the user's browsing time is greater than the browsing time threshold, the corresponding link-up ratio is selected according to the relationship between i and the preset ratio parameter matrix T0 as the ratio of real-time link-up of the content in the data information; When i<T01, the first preset linking ratio A1 is selected as the ratio for real-time linking of the content in the data information; When T01≤i<T02, the second preset linking ratio A2 is selected as the ratio for real-time linking of the content in the data information; When T02≤i<T03, the third preset chain-up ratio A3 is selected as the ratio for real-time chain-up of the content in the data information; When T03≤i<T04, the fourth preset linking ratio A4 is selected as the ratio for linking the content in the data information in real time.

[0024] In a specific embodiment of the present application, after obtaining the user information of the user, the method further includes: The user's face is recognized through the preset database, and the recognition result is determined. When the recognition result is verification passed, the preset permission set is obtained. When the recognition result is verification failed, the user is stopped from performing face recognition within the preset time and the user's user information is recorded.

[0025] In a specific embodiment of the present application, it further includes: When the total number of times the user's user information is recorded exceeds three times, the user's login account will be frozen.

[0026] Based on the same technical concept, see Figure 2 As shown, the present invention also provides a security policy construction system based on level authentication and application audit, which is applied to the security policy construction method based on level authentication and application audit, including: An acquisition unit, configured to acquire user information of a user who has logged into an account, the user information including a user name; A processing unit is configured to obtain a preset permission set, wherein the preset permission set contains permission levels corresponding to the user, and the permission levels in the preset permission set are sorted in descending order, and each permission level corresponds to a preset threshold; The detection unit has a detection model preset in the detection unit. The detection model is used to detect whether the user name exists and determine the user authority based on the detection result; wherein, When the user name is detected, the permission level corresponding to the user name is obtained, and the number of times the user name has been obtained in the past is obtained. When the number of times the user name has been obtained in the past is greater than a preset threshold, the permission level corresponding to the threshold is used as the user's permission level. When the number of times the user name has been obtained in the past is not greater than the preset threshold, the permission level corresponding to the user name is used as the user's permission level. The display unit is used to display data information corresponding to the user's authority to the user according to the user's authority, and set an isolation application for the data information, and upload the data information to the chain in real time through the isolation application according to the user's browsing time.

[0027] In a specific embodiment of the present application, the display unit is further configured to limit the network speed when displaying data information corresponding to the user's authority to the user; The display unit is further configured to obtain user information of a predetermined number of sample users and use the ratio of the number of sample users of each authority level to the predetermined number as the network speed corresponding to each authority level; The display unit is also used to obtain the number of historical acquisitions of user names corresponding to each authority level; The display unit is further configured to calculate the product of the number of times the user name was obtained historically corresponding to each authority level and the network speed corresponding to each authority level as the number of times the user name was obtained historically corresponding to each authority level, and calculate the sum of the number of times the user name was obtained historically corresponding to each authority level as the total number of times the user name was obtained historically; The display unit is further configured to determine the network speed corresponding to each authority level that maximizes the total number of times, and use the network speed as the network speed corresponding to the authority level.

[0028] In a specific embodiment of the present application, the display unit is further configured to obtain a browsing time threshold corresponding to the user's permission. When the user's browsing time is greater than the browsing time threshold, the total number of bytes of the data information displayed to the user is determined, and based on the ratio i of the user's browsing time to the total number of bytes, the content in the data information is uploaded to the chain in real time according to a preset ratio; wherein, The unit of browsing time is minutes; The display unit is pre-set with a preset ratio parameter matrix T0 and a preset link ratio matrix A. For the preset link ratio matrix A, set A(A1, A2, A3, A4), where A1 is the first preset link ratio, A2 is the second preset link ratio, A3 is the third preset link ratio, and A4 is the fourth preset link ratio, and 50% < A1 < A2 < A3 < A4 < 90%; For the preset scaling parameter matrix T0, set T0(T01, T02, T03, T04), where T01 is the first preset scaling parameter, T02 is the second preset scaling parameter, T03 is the third preset scaling parameter, and T04 is the fourth preset scaling parameter, and 0.06 min / Byte < T01 < T02 < T03 < T04 < 0.1 min / Byte; The display unit is further configured to select a corresponding link-up ratio as a ratio for real-time link-up of the content in the data information according to the relationship between i and the preset ratio parameter matrix T0 when the user's browsing time is greater than a browsing time threshold; When i<T01, the first preset linking ratio A1 is selected as the ratio for real-time linking of the content in the data information; When T01≤i<T02, the second preset linking ratio A2 is selected as the ratio for real-time linking of the content in the data information; When T02≤i<T03, the third preset chain-up ratio A3 is selected as the ratio for real-time chain-up of the content in the data information; When T03≤i<T04, the fourth preset linking ratio A4 is selected as the ratio for linking the content in the data information in real time.

[0029] In a specific embodiment of the present application, the acquisition unit is also used to perform facial recognition on the user through a preset database and determine the recognition result. When the recognition result is verification passed, a preset permission set is obtained. When the recognition result is verification failed, the user is stopped from performing facial recognition within a preset time and the user information of the user is recorded.

[0030] In a specific embodiment of the present application, the acquisition unit is further configured to freeze the user's login account when the total number of times the user information of the user is recorded is greater than three times.

[0031] In summary, the present invention dynamically adjusts user permissions in a timely manner based on the number of times a user name is historically acquired. As the number of times a user name is acquired increases, the user's permissions are adaptively increased, fully ensuring that each user can be authenticated at a specific level. Furthermore, by monitoring data display in real time, different browsing times are determined based on different permissions, ensuring data coverage and browsing while maximizing data security. The present invention has the advantages of being intelligent, secure, and efficient.

[0032] The above is only an embodiment of the present invention, but it cannot be used to limit the scope of the present invention. Any structural changes made according to the present invention should be deemed to fall within the scope of protection of the present invention and be subject to restrictions as long as they do not lose the essence of the present invention.

[0033] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working process and related instructions of the system described above can refer to the corresponding process in the aforementioned method embodiment and will not be repeated here.

[0034] It should be noted that the system provided in the above embodiment is only illustrated by the division of the above functional modules. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the modules or steps in the embodiments of the present invention can be further decomposed or combined. For example, the modules in the above embodiment can be combined into one module, or further divided into multiple sub-modules to complete all or part of the functions described above. The names of the modules and steps involved in the embodiments of the present invention are only for distinguishing the modules or steps and are not to be regarded as improper limitations of the present invention.

[0035] Those skilled in the art should be able to appreciate that the modules and method steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two, and the programs corresponding to the software modules and method steps can be placed in random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disks, removable disks, CD-ROMs, or any other form of storage medium known in the art. In order to clearly illustrate the interchangeability of electronic hardware and software, the above description has generally described the components and steps of each example according to their functions. Whether these functions are performed in electronic hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art may use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present invention.

[0036] The term "comprise" or any other similar term is intended to cover non-exclusive inclusion such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed or inherent to such process, method, article, or apparatus.

[0037] Thus far, the technical solutions of the present invention have been described in conjunction with the preferred embodiments shown in the accompanying drawings. However, it will be readily understood by those skilled in the art that the scope of protection of the present invention is obviously not limited to these specific embodiments. Without departing from the principles of the present invention, those skilled in the art may make equivalent changes or substitutions to the relevant technical features, and the technical solutions after such changes or substitutions will fall within the scope of protection of the present invention.

[0038] The above are only preferred embodiments of the present invention and are not intended to limit the scope of protection of the present invention.

Claims

1. A security policy construction method based on level authentication and application audit, characterized in that: include: Obtain user information of the user who logged in to the account, the user information including the user name; Obtaining a preset permission set, wherein the preset permission set includes permission levels corresponding to the user, and the permission levels in the preset permission set are sorted in descending order, and each permission level corresponds to a preset threshold; The user information is input into a detection model, and the detection model is used to detect whether the user name exists and determine the user authority according to the detection result; wherein, When the user name is detected to exist, the permission level corresponding to the user name is obtained, and the number of times the user name has been obtained in history is obtained. When the number of times the user name has been obtained in history is greater than the preset threshold, the permission level corresponding to the number greater than the preset threshold is used as the permission level of the user. When the number of times the user name has been obtained in history is not greater than the preset threshold, the permission level corresponding to the user name is used as the permission level of the user. According to the user permissions, data information corresponding to the user permissions is displayed to the user, and an isolation application is set for the data information. According to the browsing time of the user, the data information is uploaded to the chain in real time through the isolation application.

2. A security policy construction method based on level authentication and application auditing according to claim 1, characterized in that: When displaying data information corresponding to the user authority to the user according to the user authority, the method further includes: limiting the network speed when displaying the data information corresponding to the user authority to the user, including: Obtaining user information of a predetermined number of sample users and using the ratio of the number of sample users of each permission level to the predetermined number as the network speed corresponding to each permission level; Obtain the number of times the user name was obtained in history corresponding to each permission level; The product of the number of times the user name was obtained historically corresponding to each authority level and the network speed corresponding to each authority level is used as the number of times the user name was obtained historically corresponding to each authority level, and the sum of the number of times the user name was obtained historically corresponding to each authority level is used as the total number of times the user name was obtained historically; The network speed corresponding to each of the authority levels that maximizes the total number of times is determined, and the network speed is used as the network speed corresponding to the authority level.

3. A security policy construction method based on level authentication and application auditing according to claim 1, characterized in that: The data information is uploaded to the chain in real time through the isolated application according to the browsing time of the user, including: Obtaining a browsing time threshold corresponding to the user's permission; when the user's browsing time is greater than the browsing time threshold, determining the total number of bytes of the data information displayed to the user; and according to the ratio i of the user's browsing time to the total number of bytes, uploading the content of the data information to the chain in real time according to a preset ratio; wherein, The unit of the browsing time is minutes; A preset ratio parameter matrix T0 and a preset link ratio matrix A are preset. For the preset link ratio matrix A, A(A1, A2, A3, A4) is set, where A1 is the first preset link ratio, A2 is the second preset link ratio, A3 is the third preset link ratio, and A4 is the fourth preset link ratio, and 50% < A1 < A2 < A3 < A4 < 90%; For the preset scaling parameter matrix T0, set T0(T01, T02, T03, T04), where T01 is the first preset scaling parameter, T02 is the second preset scaling parameter, T03 is the third preset scaling parameter, and T04 is the fourth preset scaling parameter, and 0.06 min / Byte<T01<T02<T03<T04<0.1 min / Byte; When the browsing time of the user is greater than the browsing time threshold, a corresponding linking ratio is selected according to the relationship between i and the preset ratio parameter matrix T0 as the ratio of real-time linking of the content in the data information; When i<T01, the first preset linking ratio A1 is selected as the ratio for real-time linking of the content in the data information; When T01≤i<T02, the second preset linking ratio A2 is selected as the ratio for linking the content in the data information in real time; When T02≤i<T03, the third preset linking ratio A3 is selected as the ratio for linking the content in the data information in real time; When T03≤i<T04, the fourth preset linking ratio A4 is selected as the ratio for linking the content in the data information in real time.

4. A security policy construction method based on level authentication and application auditing according to claim 1, characterized in that: After obtaining the user's user information, it also includes: The user's face is recognized through a preset database, and the recognition result is determined. When the recognition result is that the verification is passed, the preset permission set is obtained. When the recognition result is that the verification is failed, the user's face recognition is stopped within a preset time, and the user information of the user is recorded.

5. A security policy construction method based on level authentication and application auditing according to claim 4, characterized in that: Also includes: When the total number of times the user information of the user is recorded is greater than three times, the login account of the user is frozen.

6. A security policy construction system based on level authentication and application audit, applied to the security policy construction method based on level authentication and application audit as described in any one of claims 1 to 5, characterized in that: include: An acquiring unit, configured to acquire user information of a user who has logged into an account, the user information including a user name; a processing unit, configured to obtain a preset permission set, wherein the preset permission set includes permission levels corresponding to the user, and the permission levels in the preset permission set are sorted in descending order, and each permission level corresponds to a preset threshold; A detection unit, wherein a detection model is preset in the detection unit, and the detection model is used to detect whether the user name exists and determine the user authority according to the detection result; wherein, When the user name is detected to exist, the permission level corresponding to the user name is obtained, and the number of times the user name has been obtained in history is obtained. When the number of times the user name has been obtained in history is greater than the preset threshold, the permission level corresponding to the number greater than the preset threshold is used as the permission level of the user. When the number of times the user name has been obtained in history is not greater than the preset threshold, the permission level corresponding to the user name is used as the permission level of the user. The display unit is used to display data information corresponding to the user authority to the user according to the user authority, and set an isolation application for the data information, and upload the data information to the chain in real time through the isolation application according to the user's browsing time.

7. A security policy construction system based on level authentication and application auditing according to claim 6, characterized in that: The display unit is further configured to limit the network speed when displaying data information corresponding to the user authority to the user; The display unit is further configured to obtain user information of a predetermined number of sample users and use the ratio of the number of sample users of each authority level to the predetermined number as the network speed corresponding to each authority level; The display unit is further configured to obtain the number of times the user name is obtained in history corresponding to each authority level; The display unit is further configured to calculate the product of the number of times the user name was obtained historically corresponding to each authority level and the network speed corresponding to each authority level as the number of times the user name was obtained historically corresponding to each authority level, and calculate the sum of the number of times the user name was obtained historically corresponding to each authority level as the total number of times the user name was obtained historically; The display unit is further configured to determine a network speed corresponding to each authority level that maximizes the total number of times, and use the network speed as the network speed corresponding to the authority level.

8. A security policy construction system based on level authentication and application auditing according to claim 6, characterized in that: The display unit is further configured to obtain a browsing time threshold corresponding to the user's permission, and when the user's browsing time is greater than the browsing time threshold, determine the total number of bytes of the data information displayed to the user, and based on the ratio i of the user's browsing time to the total number of bytes, upload the content of the data information to the chain in real time according to a preset ratio; wherein, The unit of the browsing time is minutes; The display unit is pre-set with a preset ratio parameter matrix T0 and a preset link ratio matrix A. For the preset link ratio matrix A, A(A1, A2, A3, A4) is set, where A1 is a first preset link ratio, A2 is a second preset link ratio, A3 is a third preset link ratio, and A4 is a fourth preset link ratio, and 50% < A1 < A2 < A3 < A4 < 90%; For the preset scaling parameter matrix T0, set T0(T01, T02, T03, T04), where T01 is the first preset scaling parameter, T02 is the second preset scaling parameter, T03 is the third preset scaling parameter, and T04 is the fourth preset scaling parameter, and 0.06 min / Byte<T01<T02<T03<T04<0.1 min / Byte; The display unit is further configured to select a corresponding linking ratio as a ratio for real-time linking of the content in the data information according to a relationship between i and the preset ratio parameter matrix T0 when the browsing time of the user is greater than the browsing time threshold; When i<T01, the first preset linking ratio A1 is selected as the ratio for real-time linking of the content in the data information; When T01≤i<T02, the second preset linking ratio A2 is selected as the ratio for linking the content in the data information in real time; When T02≤i<T03, the third preset linking ratio A3 is selected as the ratio for linking the content in the data information in real time; When T03≤i<T04, the fourth preset linking ratio A4 is selected as the ratio for linking the content in the data information in real time.

9. A security policy construction system based on level authentication and application auditing according to claim 6, characterized in that: The acquisition unit is also used to perform face recognition on the user through a preset database and determine the recognition result. When the recognition result is verification passed, the preset permission set is obtained. When the recognition result is verification failed, the user is stopped from performing face recognition within a preset time and the user information of the user is recorded.

10. A security policy construction system based on level authentication and application auditing according to claim 9, characterized in that: The acquisition unit is further configured to freeze the login account of the user when the total number of times the user information of the user is recorded is greater than three times.