A dynamic permission acquisition method for data usage, an electronic device, and a storage medium
By determining the access path and anomaly probability in data usage requests, establishing functional relationships, and dynamically determining data usage permissions, the security risks of the static authorization model are resolved, effective supervision of data users is achieved, and the security of the data usage process is improved.
Patent Information
- Application Number
- CN202511397610.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-28
- Publication Date
- 2025-11-28
- Estimated Expiration
- 2045-09-28
AI Technical Summary
Traditional data access control uses a static authorization model, which lacks effective supervision of data users and poses significant security risks.
By using the target access fields and intent carried in the data usage request, the access path is determined, a functional relationship is established, the estimated data volume and initial duration are obtained, and permissions are dynamically determined by combining the anomaly probability value and preset adjustment factor, including usage duration and access count, thus realizing dynamic permission management.
It improves the security of data use, reduces the risk of data leakage through dynamic access control, and enhances the supervision of data users.
Smart Images

Figure CN120874094B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of data processing, in particular to a dynamic permission acquisition method for data usage, an electronic device and a storage medium. BACKGROUND
[0002] With the rapid development of big data, cloud computing and artificial intelligence technology, data has become a key production factor and value source. In the process of business development, enterprises and organizations frequently need to provide internal data to third parties (such as partners, data analysis service providers, etc.) for use and processing, in order to mine data value, optimize business processes or develop new products and services. In this process, data security and privacy protection pose a huge challenge. Traditional data permission management mostly adopts a static authorization mode, that is, once access permission is granted to a third party, the permission is usually valid within a fixed time range, or only a simple "yes / no" binary control is made. Patent CN201310670338.3 discloses a data access method and device, which determines data access permission through a login token and an application identifier, but does not further determine the access duration of the requested data. This mode lacks supervision during the use of the data user and has a high risk. SUMMARY
[0003] To solve the above technical problems, the technical solution adopted by the present application is as follows:
[0004] According to the first aspect of the present application, a dynamic permission acquisition method for data usage is provided, when a data usage request is sent to a third party, wherein the data usage request carries at least a target access field and a data usage intention, the third party performs the following steps:
[0005] S1, based on the target access field and the data usage intention carried by the data usage request, determining an access path for realizing the data usage intention according to the target access field;
[0006] S2, obtaining a plurality of historical records of executing the access path in a historical time period, each historical record at least including: a historical data amount of inputting the field value corresponding to the target access field of the access path, and a consumption time of realizing the data usage intention through the access path;
[0007] S3, establishing a functional relationship with the historical data amount of inputting the field value corresponding to the target access field of the access path as the independent variable, and the consumption time of realizing the data usage intention through the access path as the dependent variable;
[0008] S4, obtaining an estimated data amount of the field value corresponding to the target access field in the data usage request and inputting the estimated data amount into the functional relationship to obtain the consumption time as the initial duration;
[0009] S5. Determine the abnormal probability value of the data usage request based on the feature vector of the data usage request. The abnormal probability value ranges from 0 to 1. The features corresponding to the feature vector include at least: access time.
[0010] S6, obtain dynamic permissions for the data usage request. The dynamic permissions include at least the usage duration of the target access field value. The usage duration is equal to the product of the initial duration, the reciprocal of the preset probability of successful task execution of the access path, the abnormal probability value, and the preset adjustment factor.
[0011] According to a second aspect of the present invention, a non-transitory computer-readable storage medium is provided, wherein a computer program is stored in the storage medium, and the computer program is loaded and executed by a processor to implement the aforementioned method.
[0012] According to a third aspect of the present invention, an electronic device is provided, comprising: a processor, a memory, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the aforementioned method.
[0013] The present invention has at least the following beneficial effects: In summary, based on the target access field and data usage intent carried in the data usage request, an access path to realize the data usage intent based on the access data is determined. Several historical records of executing the access path within a historical time period are obtained. The amount of historical data corresponding to the field value of the target access field of the access path is used as the independent variable, and the time consumed to realize the data usage intent through the access path is used as the dependent variable. A functional relationship is established, the estimated amount of data corresponding to the field value of the target access field in the data usage request is obtained, and the estimated amount of data is input into the functional relationship. The consumption time is obtained as the initial duration. Based on the feature vector of the data usage request, the abnormal probability value of the data usage request is determined, and the dynamic permissions of the data usage request are obtained. The present invention determines the dynamic permissions of the data usage request through multiple aspects such as the initial duration, the preset probability of successful execution of the task through the access path, and the abnormal probability value. By setting dynamic permissions, the data user can be monitored during the data usage process, thereby improving the security of the data usage process. Attached Figure Description
[0014] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0015] Figure 1 This is a flowchart illustrating a method for obtaining dynamic permissions for data usage, as provided in an embodiment of the present invention. DETAILED DESCRIPTION
[0016] The technical solutions in the embodiments of the present application will be apparently and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all the other embodiments obtained by a person skilled in the art without any creative work fall within the protection scope of the present application.
[0017] It should be noted that the terms "first", "second" and the like in the description and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily indicate a specific order or sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "comprise" and "have" and any variations thereof are used for the purpose of covering non-exclusive inclusion, for example, a process, method, system, product or server comprising a series of steps or units does not necessarily limit to those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0018] The embodiments of the present application provide a dynamic permission acquisition method for data use. A data provider stores information of private data in a trusted third-party platform. A data user sends a data use request to the third party. After the third party agrees to the data use request of the data user, the data provider sends a field value of a target access field of the data use request to the third party. The third party sends the field value of the target access field of the data use request to the data user. However, if the data user can always use the field value of the target access field, this mode poses a threat to the security of the accessed data and has a great risk. Therefore, the permission of the data user to the field value of the target access field needs to be dynamically managed.
[0019] For example, the permission of the data user to the field value of the target access field is determined according to the access time, geographic location, IP location and network type of the data user, and the data sensitivity, data type and data use intention declared in advance by the data user.
[0020] In an embodiment of the present application, as shown in Figure 1 When the data user sends a data use request to the third party, at least the target access field and the data use intention are carried in the data use request. The third party performs the following steps:
[0021] S1, determining an access path for realizing the data usage intention according to the target access field based on the target access field and the data usage intention carried by the data usage request.
[0022] Specifically, the target access field is a field that the data usage party wants to access data in this data usage request; the data usage intention is the purpose of the data usage party wanting to use the access data, such as using the access data for attribution analysis, using the access data for statistical reporting.
[0023] In an embodiment of the present application, the target access field and the data usage intention are input into a large model to obtain an execution path for realizing the data usage intention according to the target access field, and one execution path is selected from the execution path as the access path.
[0024] Further, selecting one execution path from the execution path as the access path further includes: obtaining the usage frequency of the execution path for realizing the data usage intention of the target access field in a historical time period, and taking the execution path corresponding to the maximum usage frequency as the access path.
[0025] S2, obtaining a plurality of historical records of executing the access path in a historical time period, each historical record at least including: historical data amount of a field value corresponding to the target access field input into the access path, and consumption time for realizing the data usage intention through the access path. It can be understood that the historical record is obtained to predict the time for the data usage party to realize the data usage intention by accessing the data.
[0026] S3, establishing a functional relationship formula with the historical data amount of the field value corresponding to the target access field input into the access path as the independent variable and the consumption time for realizing the data usage intention through the access path as the dependent variable.
[0027] In an embodiment of the present application, the functional relationship formula is z=k1xlog2r+b1, k1 is a first coefficient, b1 is a second coefficient, and the values of k1 and b1 are obtained by fitting the data amount of the same historical data as the access data and the consumption time for realizing the data usage intention through the access path according to the historical data. Those skilled in the art know that any fitting method in the prior art belongs to the protection scope of the present application, and will not be repeated here.
[0028] In a preferred embodiment of the present application, the functional relationship formula is z=k2x r+b2, k2 is a first factor, b2 is a second factor, and the values of k2 and b2 are obtained by fitting the data amount of the same historical data as the access data and the consumption time of the data usage intention achieved by the access path according to the historical data. It can be understood that as the data amount increases, the time consumed will also increase. Therefore, the function relationship uses an exponential relationship.
[0029] S4, obtaining the estimated data amount of the field value corresponding to the target access field in the data usage request and inputting the estimated data amount into the function relationship to obtain the consumption time as the initial duration.
[0030] S5, determining the abnormal probability value of the data usage request based on the feature vector of the data usage request, and the value range of the abnormal probability value is 0 to 1. The features corresponding to the feature vector at least include: access time. The access time is the time when the third party obtains the data usage request. For example, 23:00-24:00 and 0:00-5:00 of the access time are set as high abnormal probability values.
[0031] Specifically, the features corresponding to the feature vector further include: the sensitivity of the target access field. The fields of the data provider are set to a preset sensitivity, and the sensitivity of the corresponding field of the target access field is used as the feature value of the feature.
[0032] Further, the qualification data of the data usage party is obtained, and the features of the data usage request are obtained based on the qualification data of the data usage party. The features corresponding to the feature vector of the data usage request further include: the IP address of the data usage party, the MAC address of the data usage party, the network type of the data usage party, the geographic location of the data usage party, etc.
[0033] In an embodiment of the present application, an abnormal feature vector composed of feature values of a preset abnormal behavior occurring in a preset time period is obtained, the abnormal feature vector is input into a large model for training, the feature vector of the data usage request is input into the large model, and the abnormal probability value of the data usage request being an abnormal request is obtained. The greater the probability of the data usage request being an abnormal request, the smaller the abnormal probability value.
[0034] S6, obtaining the dynamic permission of the data usage request, and the dynamic permission at least includes the use duration of the field value of the target access field. The use duration is equal to the product value of the initial duration, the inverse of the preset probability of the success of the access path in executing the task, the abnormal probability value and a preset adjustment factor.
[0035] Specifically, the execution of the access path may fail to achieve the data request purpose, and therefore, when the usage duration is designed, the probability of the execution failure of the access path needs to be considered, and the preset probability of the successful execution of the access path is equal to 1 minus the probability of the execution failure of the access path in the historical data.
[0036] In an embodiment of the present application, the preset adjustment factor is 5.
[0037] In summary, based on the target access field and the data usage intention carried by the data usage request, the access path for achieving the data usage intention by accessing data is determined, a plurality of historical records of the execution of the access path in a historical time period are obtained, the historical data amount of the field value corresponding to the target access field of the access path is taken as the independent variable, and the consumption time of achieving the data usage intention by the access path is taken as the dependent variable to establish a functional relationship, the estimated data amount of the field value corresponding to the target access field in the data usage request is obtained and input into the functional relationship to obtain the consumption time as the initial duration, the abnormal probability value of the data usage request is determined based on the feature vector of the data usage request, and the dynamic permission of the data usage request is obtained. The initial duration, the preset probability of the successful execution of the access path, the abnormal probability value, and the like are used to determine the dynamic permission of the data usage request, and the data usage party is supervised during the use process through the setting of the dynamic permission, and the security in the data usage process is improved.
[0038] Further, the dynamic permission of the data usage request further includes the access times per day. The access times per day are the times of the access data obtained by the data usage party through the third party per day.
[0039] Specifically, the access times are determined by the following steps:
[0040] S61, a first limit value is obtained, and the first limit value is equal to the quotient value of the time of one day divided by the initial duration. It can be understood that the unit of the initial duration and the unit of the time of one day are the same, and if the unit of the initial duration is minute and the time of one day is 1440 minutes.
[0041] S62, a second limit value is obtained, and the second limit value is equal to the product value of the abnormal probability value and the preset adjustment factor. It can be understood that if the execution failure of the access path is not considered, the usage duration is equal to the product value of the initial duration, the abnormal probability value, and the preset adjustment factor, and at this time, the abnormal probability value and the preset adjustment factor play the role of times, and therefore, the product value of the abnormal probability value and the preset adjustment factor is taken as the second limit value of the access times.
[0042] S63, the access times are obtained, and the access times are equal to the minimum limit value after the upward rounding, and the minimum limit value is the smaller one of the first limit value and the second limit value.
[0043] In summary, the first limit value is obtained, the second limit value is obtained, the access times are obtained, the access times are equal to the minimum limit value after being rounded up, and the minimum limit value is the smaller one of the first limit value and the second limit value. The application determines the access times by the initial time length and dynamically determines the access times of the access data, thereby realizing the safety monitoring of the data.
[0044] Specifically, if the target access field includes statistical report data, the following steps are performed:
[0045] S11, obtaining a target statistical report result value of a target access field.
[0046] S12, obtaining a historical statistical report result value of a data user in a preset time period.
[0047] S13, if the statistical objects corresponding to the target statistical report result value and the historical statistical report result value are the same, obtaining a difference value of the target statistical report result value and the historical statistical report result value, and if the absolute value of the difference value is less than a preset difference threshold and not less than 0, terminating the data use request.
[0048] For example, the statistical object is a user ID, the target access field is having disease A and having disease B, and the historical statistical report result value is having disease A. If the difference value is small, the differential comparison will cause the accurate identification of the individual to infringe on the personal privacy.
[0049] In summary, the target statistical report result of the access data is obtained, the historical statistical report result of the data user in history is obtained, if the statistical objects corresponding to the target statistical report result and the historical statistical report result are the same, the difference value of the target statistical report result and the historical statistical report result is obtained, and if the absolute value of the difference value is less than a preset difference threshold and not less than 0, the data use request is terminated, thereby avoiding that the data user obtains the private data through the differential comparison.
[0050] Further, if the target access field includes statistical report data, the target statistical report result value is subjected to noise addition processing, and the target statistical report result value after the noise addition processing is sent to the data user, wherein the noise size is y percent of the target statistical report result value, y is equal to the product value of 1 / 2 power of 1 / 2 of the logarithm value of x with 2 as the base and a, a is a preset weight coefficient, and x is the target statistical report result value. By adding noise to the statistical report data, the data user can be prevented from obtaining the real data, and the access data after the noise addition does not affect the use of the data user. That is, y=a x (log2x) 1 / 2 .
[0051] In an embodiment of the application, a is equal to 1.
[0052] In a preferred embodiment of the present application, a is determined by the following steps:
[0053] In S64, a first reciprocal value is obtained, which is equal to a sum of an intermediate product value and 1 / 2, and the intermediate product value is equal to a product of an inverse of π and an arctan T, where T is a usage duration of the field value of the target access field. It can be understood that the longer the access time is, the greater the first reciprocal value is. The first reciprocal value C1 = 1 / 2 + (1 / π) x arctan T.
[0054] In S65, a second reciprocal value is obtained, which is equal to an inverse of an intermediate sum value, and the intermediate sum value is equal to a sum of 1 and e raised to the power of -N, where N is the access number. It can be understood that the greater the access number is, the greater the second reciprocal value is. The second reciprocal value C2 = 1 + e -N .
[0055] In S66, a is obtained, which is equal to a difference of 1 minus an intermediate weight value, and the intermediate weight value is equal to a weighted sum of the first reciprocal value and the second reciprocal value. a = 1 - (d1 x C1 + d2 x C2), where d1 is a weight value corresponding to C1, and d2 is a weight value corresponding to C2.
[0056] Specifically, the weight of the first reciprocal value and the weight of the second reciprocal value are both equal to 1 / 2.
[0057] In summary, the first reciprocal value is obtained, the second reciprocal value is obtained, and a is obtained. The longer the access time is, the greater the access number is, and the more secure the data usage party is, so the smaller the preset weight coefficient is.
[0058] The embodiment of the present application further provides a non-transitory computer readable storage medium, which can be arranged in an electronic device to save a computer program used for implementing a method related to the method in the method embodiment, and the computer program is loaded and executed by the processor to implement the method provided by the above embodiment.
[0059] The embodiment of the present application further provides an electronic device, which comprises a processor, a memory and a computer program stored in the memory and executable on the processor, and the processor implements the method provided by the above embodiment when executing the computer program.
[0060] The embodiment of the present application further provides a computer program product, which comprises program code, and when the program product is executed on an electronic device, the program code is used to make the electronic device execute the steps in the method according to various exemplary embodiments of the present application described in the specification.
[0061] While certain specific embodiments of the application have been described in detail herein for the purposes of exemplification, it will be understood by those skilled in the art that the examples are for illustration only and are not intended to limit the scope of the application. It will be further understood by those skilled in the art that various modifications can be made to the embodiments without departing from the scope and spirit of the application.
Claims
1. A method for dynamically obtaining permissions for data usage, characterized in that, When a data user sends a data access request to a third party, the request must include at least the target access field and the data access intent. The third party then performs the following steps: S1, based on the target access field and data usage intent carried in the data usage request, determine the access path to realize the data usage intent according to the target access field; S2, obtain several historical records of the execution of the access path within a historical time period, each historical record including at least: the amount of historical data corresponding to the field value of the target access field of the access path, and the time consumed to realize the data usage intention through the access path; S3, taking the historical data volume of the field value corresponding to the target access field of the input access path as the independent variable and the time consumed to realize the data usage intention through the access path as the dependent variable, establish a functional relationship; S4, obtain the estimated data volume using the field value corresponding to the target access field in the request and input the estimated data volume into the function formula to obtain the time consumed as the initial duration; S5. Determine the abnormal probability value of the data usage request based on the feature vector of the data usage request. The abnormal probability value ranges from 0 to 1. The features corresponding to the feature vector include at least: access time. S6, obtain dynamic permissions for the data usage request. The dynamic permissions include at least the usage duration of the target access field value. The usage duration is equal to the product of the initial duration, the reciprocal of the preset probability of successful task execution of the access path, the abnormal probability value, and the preset adjustment factor.
2. The method for obtaining dynamic permissions for data use according to claim 1, characterized in that, The dynamic permissions requested for the data usage also include: the number of accesses per day.
3. The method for obtaining dynamic permissions for data use according to claim 2, characterized in that, Determine the number of visits using the following steps: S61, obtain the first limit value, which is equal to the quotient of one day's time divided by the initial duration; S62, obtain the second limit value, which is equal to the product of the anomaly probability value and the preset adjustment factor; S63, get the number of accesses. The number of accesses is equal to the minimum limit value after rounding up. The minimum limit value is the smaller of the first limit value and the second limit value.
4. The method for obtaining dynamic permissions for data use according to claim 3, characterized in that, If the target access field includes statistical report data, perform the following steps: S11, obtain the target statistical report result value of the target access field; S12, obtain the historical statistical report results of the data user within the preset time period; S13, if the target statistical report result value and the historical statistical report result value correspond to the same statistical object, obtain the difference between the target statistical report result value and the historical statistical report result value. If the absolute value of the difference is less than the preset difference threshold and not less than 0, terminate the data usage request.
5. The method for obtaining dynamic permissions for data use according to claim 4, characterized in that, If the target access field includes statistical report data, noise is added to the target statistical report result value, and the noise-added target statistical report result value is sent to the data user. The noise level is y percent of the target statistical report result value, where y is equal to the product of 1 / 2 power of the logarithm of x (base 2) and a, where a is a preset weighting coefficient, and x is the target statistical report result value.
6. The method for obtaining dynamic permissions for data use according to claim 5, characterized in that, a equals 1.
7. The method for obtaining dynamic permissions for data use according to claim 5, characterized in that, a is determined through the following steps: S64, obtain the first inverse ratio value, which is equal to the sum of the intermediate product value and 1 / 2. The intermediate product value is equal to the product of the reciprocal of π and arctan T, where T is the usage duration of the field value of the target access field. S65, obtain the second inverse ratio value, which is equal to the reciprocal of the intermediate sum value, which is equal to the sum of 1 and e raised to the power of -N, where N is the number of accesses; S66, obtain a, a equals the difference between 1 and the intermediate weight value, the intermediate weight value is equal to the weighted sum of the first inverse ratio value and the second inverse ratio value.
8. The method for obtaining dynamic permissions for data use according to claim 7, characterized in that, The weights of the first inverse ratio and the second inverse ratio are both equal to 1 / 2.
9. A non-transitory computer-readable storage medium, characterized in that, The storage medium stores a computer program, which is loaded and executed by a processor to implement the dynamic permission acquisition method for data use as described in any one of claims 1-8.
10. An electronic device, comprising: A processor, a memory, and a computer program stored in the memory and executable on the processor, characterized in that, when the processor executes the computer program, it implements the dynamic permission acquisition method for data use as described in any one of claims 1-8.
Citation Information
Patent Citations
Data access method and device
CN103685267A
Honeyhouse access request forwarding method based on dynamic probability, electronic equipment and medium
CN117411670A
Data transferring method and apparatus and storage system
WO2014166276A1