A method and system for dynamic authentication management of permissions of a trusted data space

By acquiring and correcting access anomaly rates in a trusted data space, the problems of inaccurate access control and untimely response in access control management are solved, enabling dynamic management of access control and improving the security and accuracy of the system.

CN120896792BActive Publication Date: 2026-04-07LINGSHU TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-30
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

The existing access control system does not use dynamic access control, which leads to inaccurate access control, untimely response, and is prone to misjudgment.

Method used

By obtaining the cumulative time of target users within the trusted data space, and using the access anomaly classification table and the cumulative time of other users to correct the anomaly rate, combined with the use of status parameters to calculate and correct the access anomaly rate, dynamic adjustment of permissions can be achieved.

Benefits of technology

It improves the accuracy and timeliness of access control management, avoids the risk of data being maliciously stolen, enhances system security, and realizes dynamic management of access control.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120896792B_ABST
    Figure CN120896792B_ABST
Patent Text Reader

Abstract

This invention discloses a method and system for dynamic authentication management of permissions in a trusted data space, relating to the field of dynamic authentication management of permissions. The method includes: obtaining a target cumulative time for a target user within the trusted data space after their most recent access, and classifying this time to obtain a first access anomaly rate; obtaining multiple cumulative times for other users within the trusted data space, performing integrated anomaly classification on the target cumulative time, and correcting the first access anomaly rate to obtain a second access anomaly rate; analyzing the usage status of the trusted data space based on the multiple cumulative times, and correcting the second access anomaly rate to obtain a corrected access anomaly rate; and adjusting the permissions of the target user based on the corrected access anomaly rate to complete dynamic authentication management of permissions. This invention solves the problem of untimely permission authentication management, leading to poor permission authentication management results, through this dynamic authentication management method.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of access control and authentication management, and specifically to a method for dynamic access control and authentication management of a trusted data space. Background Technology

[0002] Dynamic authentication management is an identity verification technology in the field of network security that improves database and authentication security through user permission management.

[0003] Existing access control systems do not employ dynamic access control, resulting in inaccurate and untimely responses. Therefore, a dynamic access control management method for trusted data spaces is needed to address the poor performance of existing technologies in this area. Summary of the Invention

[0004] This application provides a method and system for dynamic authentication management of permissions in a trusted data space. The method addresses the problems of poor permission authentication management, untimely dynamic permission management response, inaccurate permission authentication management, and susceptibility to misjudgment in the prior art.

[0005] In view of the above problems, this application provides a method and system for dynamic authentication management of permissions in a trusted data space.

[0006] Firstly, this application provides a method for dynamic authentication management of permissions in a trusted data space, the method comprising:

[0007] Obtain the target cumulative time of the target user in the trusted data space after the most recent access, and classify to obtain the first access anomaly rate, wherein the target user has access to the trusted data space;

[0008] Obtain multiple cumulative times from other users within the trusted data space. Using these multiple cumulative times, perform integrated anomaly classification on the target cumulative time to obtain an access anomaly coefficient. Correct the first access anomaly rate to obtain a second access anomaly rate.

[0009] Based on multiple cumulative time periods, the usage status of the trusted data space is analyzed to obtain usage status parameters, and the second access anomaly rate is corrected to obtain the corrected access anomaly rate.

[0010] Based on the corrected access anomaly rate, the permissions of the target user are determined and adjusted to complete dynamic permission authentication management.

[0011] Secondly, this application provides a dynamic authentication management system for trusted data spaces, the system comprising:

[0012] The cumulative time acquisition module is used to acquire the target cumulative time of a target user in the trusted data space after the most recent access, and classify it to obtain the first access anomaly rate, wherein the target user has access rights to the trusted data space;

[0013] The cumulative time anomaly classification module is used to obtain multiple cumulative times of other users in the trusted data space, use multiple cumulative times to perform integrated anomaly classification on the target cumulative time, obtain access anomaly coefficient, correct the first access anomaly rate, and obtain a second access anomaly rate.

[0014] The status parameter calculation module is used to perform usage status analysis of the trusted data space based on multiple cumulative time periods, obtain usage status parameters, correct the second access anomaly rate, and obtain the corrected access anomaly rate.

[0015] The anomaly rate threshold determination module is used to determine and adjust the permissions of the target user based on the corrected access anomaly rate, thereby completing dynamic permission authentication management.

[0016] Thirdly, embodiments of this application provide a computer-readable storage medium storing a first computer program, which, when executed by a processor, implements a dynamic authentication management method for trusted data space permissions according to the first aspect.

[0017] Fourthly, embodiments of this application provide a verification terminal, the verification terminal comprising:

[0018] Memory, used to store a second computer program;

[0019] A processor is used to read and execute the second computer program, thereby implementing a dynamic authentication management method for trusted data space permissions in the first aspect.

[0020] One or more technical solutions provided in this application have at least the following technical effects or advantages:

[0021] This application proposes a dynamic authentication management method and system for trusted data spaces. By adjusting and correcting parameters during the authentication process, the accuracy of authentication parameters is improved. Compared to previous non-dynamic authentication management methods, this invention can determine the usability of a target user and the entire data space. Security risks are assessed using thresholds to determine whether to dynamically delete user access permissions, preventing malicious data theft and leakage, and enhancing system security. Furthermore, reliable data information replaces single user authentication, enabling dynamic management of authentication based on user and trusted data space usage status, thus solving the problem of low authentication accuracy. Attached Figure Description

[0022] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0023] Figure 1 This is a flowchart illustrating the dynamic authentication management method for permissions based on trusted data space proposed in this application.

[0024] Figure 2 This is a schematic diagram of the structure of the dynamic authentication management system for permissions based on trusted data space in this application;

[0025] Figure 3 This is a schematic diagram of the structure of a computer-readable storage medium provided in an embodiment of this application;

[0026] Figure 4 This is a schematic diagram of the structure of the verification terminal provided in an embodiment of this application.

[0027] In the attached diagram, the labels represent the following: cumulative time acquisition module 11; cumulative time anomaly classification module 12; usage status parameter calculation module 13; anomaly rate threshold determination module 14; computer-readable storage medium 300; first computer program 311; verification terminal 400; memory 410; processor 420; and second computer program 411. Detailed Implementation

[0028] This application proposes a method and system for dynamic authentication management of permissions in a trusted data space. By using the dynamic authentication management method, the status of users and the trusted data space is judged, which improves the accuracy of permission authentication management parameters, solves the problem of untimely permission authentication management, improves the management effect of permission authentication management, and realizes intelligent dynamic permission management.

[0029] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.

[0030] It should be noted that the terms "comprising" and "having" are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or server that includes a series of steps or units is not necessarily limited to those steps or units that are explicitly listed, but may include other steps or modules that are not explicitly listed or that are inherent to these processes, methods, products, or devices.

[0031] The present invention will now be described in detail with reference to the accompanying drawings.

[0032] Example 1, as Figure 1 As shown, this application provides a method for dynamic authentication management of permissions in a trusted data space, the method comprising:

[0033] S10: Obtain the target cumulative time of the target user in the trusted data space after the most recent access, and classify to obtain the first access anomaly rate, wherein the target user has access rights to the trusted data space.

[0034] In this embodiment, the trusted data space is, for example, an encrypted data space for a project within an enterprise, accessible only to authorized personnel. This space stores internal data, etc. The target user has access to the trusted data space, for example, a technical personnel within the enterprise.

[0035] Obtain the target cumulative time since the target user's most recent access within the trusted data space. If a user has not accessed the site for an extended period, they may have left the project. The user's permissions are highly likely to have been compromised; the longer the time elapsed, the greater the probability of such compromise. Classify the obtained target cumulative time to obtain the first access anomaly rate.

[0036] Step S10 in the method provided in this application embodiment includes:

[0037] Obtain the target cumulative time of a target user within the trusted data space since their most recent access, wherein the target user has access rights to the trusted data space;

[0038] Based on the access management data of similar trusted data spaces, construct an access anomaly classification table;

[0039] Input the target cumulative time into the access anomaly classification table, and output the first access anomaly rate.

[0040] In this embodiment, the target cumulative time of a target user within a trusted data space since their most recent access is obtained. The target user has access to the trusted data space. There is a possibility that the target user may have left the project during their most recent access; if they left the project, a larger target cumulative time can be obtained.

[0041] The cumulative time is the sum of all times since the last access time.

[0042] For example, the last access time was 8 PM, the current time is 12 AM, and the cumulative time within a day is 4 hours. Based on this cumulative time, the target cumulative time for the target user is obtained.

[0043] In this embodiment, an access anomaly classification table can be constructed based on the access management data of similar trusted data spaces. Similar trusted data spaces are, for example, encrypted data spaces within other enterprises that have similar projects.

[0044] In this embodiment of the application, the target cumulative time is input into the access anomaly classification table, and the first access anomaly rate is obtained by outputting the result.

[0045] Based on historical management permission data from the trusted data space, an access anomaly classification table is constructed to obtain the first access anomaly rate for samples within a cumulative time period. The first access anomaly rate is the ratio of the number of abnormal accesses to the total number of user accesses within the cumulative time period.

[0046] The method provided in this application embodiment includes the step of constructing an access exception classification table, which comprises:

[0047] Get multiple cumulative time intervals;

[0048] Based on the permission management data of similar trusted data spaces, the proportion of user permissions being stolen within each cumulative time interval is obtained and labeled as the first access anomaly rate of the sample, thus obtaining the first access anomaly rate of multiple samples.

[0049] Construct a mapping relationship between the multiple cumulative time intervals and the first access anomaly rate of multiple samples to obtain an access anomaly classification table.

[0050] Specifically, multiple cumulative time intervals can be set to facilitate analysis of each cumulative time interval. For example, 6h-10h, 10h-14h, 14h-18h, and 18h-22h.

[0051] Furthermore, by analyzing the proportion of abnormal user accesses within each cumulative time interval using permission management data from similar trusted data spaces, the percentage of user privileges being compromised can be calculated. This percentage is labeled as the first access anomaly rate for the sample, resulting in multiple first access anomaly rates. For example, by counting the total number of user accesses and the number of abnormal IP accesses within each cumulative time interval, the ratio of abnormal IP accesses to the total number of user accesses is calculated as the first access anomaly rate. For instance, if there are 1000 accesses within the same trusted data space between 4 hours and 8 hours, and 10 of them are from abnormal IPs, then the percentage of user privileges being compromised is 1%, which is the first access anomaly rate. In this way, multiple first access anomaly rates for multiple cumulative time intervals are obtained.

[0052] Abnormal access may be due to abnormal IP access by the user, such as access from a user's IP address in a different location or access from an uncommon device.

[0053] For example, in the cumulative time interval of 4h-8h, the proportion of user privileges being stolen was 1%. That is, the first access anomaly rate of the sample was 1%. In the cumulative time intervals of 6h-10h, 10h-14h, and 14h-18h, the access anomaly rates of multiple samples were 3%, 5%, and 6%, respectively.

[0054] It can be seen that the sample access anomaly rate is different for different cumulative time intervals, and there is a correlation between the cumulative time interval and the sample anomaly rate.

[0055] Furthermore, a mapping function is used to construct the mapping relationship between the multiple cumulative time intervals and the first access anomaly rates of the multiple samples. The VLOOKUP function is commonly used to create the mapping relationship, associating each cumulative time interval with each sample access anomaly rate to form a one-to-one mapping relationship, thus obtaining the access anomaly classification table.

[0056] In this embodiment, the target cumulative time is input into the access anomaly classification table, and the first access anomaly rate is obtained by outputting the target cumulative time. If the target cumulative time is 4 hours, inputting 4 hours into the access anomaly classification table will yield the first access anomaly rate corresponding to the entered sample cumulative time interval.

[0057] In this application example, an anomaly classification table is constructed by obtaining the target user's most recent access time. After inputting the target cumulative time, the first abnormal access rate is obtained from the anomaly classification table. Through the above steps, data can be obtained directly and accurately, and output through the anomaly classification table, taking into account the cumulative time during which the target user has not accessed the trusted data space. Anomaly classification based on historical data and quantification of the number of abnormal accesses within the cumulative time result in an accurate first access anomaly rate, improving the accuracy of access control management. Simultaneously, the access control system can record data in real time during data collection, improving the timeliness of access control management.

[0058] S20: Obtain multiple cumulative times of other users in the trusted data space, use multiple cumulative times to perform integrated anomaly classification on the target cumulative time, obtain access anomaly coefficient, correct the first access anomaly rate, and obtain the second access anomaly rate.

[0059] By obtaining the cumulative time of other users, if most of the cumulative times are close to the target cumulative time, the data in the trusted data space may no longer be valuable, for example, the project may have ended. In a normally functioning trusted data space, the unaccessed cumulative times of multiple users should differ significantly. Based on this, access anomaly coefficient analysis and access control are performed. The access anomaly coefficient is the similarity between the target cumulative time and multiple cumulative times of other users. Based on this, a second access anomaly rate can be obtained.

[0060] Step S20 in the method provided in this application embodiment further includes:

[0061] Calculate the similarity between multiple cumulative times and the target cumulative time to obtain multiple access similarities;

[0062] Calculate the arithmetic mean of multiple access similarities to obtain the average access similarity, and calculate the access anomaly coefficient.

[0063] The first access anomaly rate is corrected and calculated based on the ratio of the access anomaly coefficient to the average access anomaly coefficient to obtain the second access anomaly rate.

[0064] Specifically, the similarity between the cumulative times of multiple other users and the target cumulative time is calculated to obtain multiple access similarities. For example, the access similarity is 1 minus the ratio of the difference between the target cumulative time and the target cumulative time.

[0065] The access anomaly coefficient represents the similarity between the target's cumulative time and multiple cumulative times of other users. A higher access anomaly coefficient indicates greater similarity between the target's cumulative time and multiple cumulative times of other users, suggesting that the data within the trusted data space used by the target may no longer be valuable for access.

[0066] For example, the cumulative times of other users are 4h, 5h, 4h, and 3h, respectively, and the target cumulative time is 6h. The access similarity is 1-(6-4) / 6=0.66, 1-(6-5) / 6=0.83, 1-(6-4) / 6=0.66, and 1-(6-3) / 6=0.5.

[0067] Furthermore, the arithmetic mean of multiple access similarities is calculated to obtain the average access similarity, and the access anomaly coefficient is calculated.

[0068] For example, the arithmetic mean of multiple access similarities is calculated. For instance, if multiple access similarities are 0.66, 0.83, 0.66, and 0.5, the arithmetic mean of the access similarities is (0.66 + 0.83 + 0.66 + 0.5) / 4 = 0.66, and the average access similarity is 0.66. The access anomaly coefficient is 0.66.

[0069] Furthermore, the first access anomaly rate is recalculated based on the ratio of the access anomaly coefficient to the average access anomaly coefficient to obtain the second access anomaly rate. The average access anomaly coefficient is the average of the access anomaly coefficients of other users calculated over a past period, and it can be updated.

[0070] For example, the access anomaly coefficient is 0.66, while the access anomaly coefficients for other users are 0.4, 0.35, 0.4, and 0.25. The average access anomaly coefficient is (0.4 + 0.35 + 0.4 + 0.25) / 4 = 0.35, and the ratio of the access anomaly coefficient to the average access anomaly coefficient is 0.66 / 0.35 = 1.89.

[0071] The first abnormal access rate is, for example, 0.25, and the second abnormal access rate is, for example, 0.25 * 1.89 = 0.47.

[0072] The second abnormal access rate is the product of the first abnormal access rate and the ratio of the target user's access abnormality coefficient to that of other users. The larger the value, the more abnormal the target user's access permissions are, the lower the availability of the available data space, the more likely it is to be abandoned, and the more necessary it is to delete the user's permissions to prevent others from maliciously stealing data from the previously available data space.

[0073] The access anomaly coefficient can be used to correct the first anomaly coefficient. If the ratio of the obtained access anomaly coefficient to the average access anomaly coefficient is greater than 1, it indicates that the cumulative times of other users are similar to the cumulative time of the target user, suggesting that the trusted data space may have lost its value and has not been accessed by all users for a long time. If the trusted data space is in normal use, the cumulative times of other users should differ significantly from the cumulative time of the target user, and there should be access behavior at different points in time.

[0074] If the ratio of the obtained access anomaly coefficient to the average access anomaly coefficient is less than 1, it indicates that the cumulative times of other users are not similar to the cumulative time of the target user, multiple users are in a normal state of using the trusted data space, the cumulative time difference is large, the trusted data space has not lost its utilization value, and it is in a normal state of use.

[0075] In this embodiment, an access anomaly coefficient is obtained by calculating the similarity between the cumulative abnormal access time of the target user and the cumulative abnormal access time of other users. Then, based on the ratio of the access anomaly coefficient to the average access anomaly coefficient, the first access anomaly rate is corrected to obtain a second access anomaly rate. By comparing the access data of other users horizontally, anomalies such as project shutdowns are effectively eliminated, thus significantly improving the accuracy of the judgment. The calculation-based correction further ensures the reliability of the data, avoiding the influence of trusted data spaces or invalid cumulative abnormal access times of target users on the analysis results, so as to achieve accurate management of dynamic authorization authentication in the future.

[0076] S30: Based on multiple cumulative time periods, perform a usage status analysis of the trusted data space to obtain usage status parameters, and correct the second access anomaly rate to obtain a corrected access anomaly rate.

[0077] By analyzing the usage of the trusted data space and utilizing the obtained usage status parameters, the second access anomaly rate is adjusted. A higher adjusted access anomaly rate indicates a higher overall anomaly rate in both the trusted data space usage and user access, and a greater probability that the trusted data space will be abandoned.

[0078] In this embodiment of the application, step S30 includes:

[0079] The average cumulative time is calculated based on multiple cumulative time periods.

[0080] The ratio of the average cumulative time to the historical average cumulative time of the abandoned trusted data space is calculated and used as a usage status parameter.

[0081] Using the usage status parameters, the second access anomaly rate is corrected and calculated to obtain the corrected access anomaly rate.

[0082] Specifically, the average cumulative time is calculated based on multiple cumulative times. For example, if the cumulative times are 7h, 8h, 8h, and 6h, the average cumulative time is (7h+8h+8h+6h) / 4=7.25h.

[0083] Furthermore, the ratio of the average cumulative time to the historical average cumulative time when the abandoned trusted data space was verified as abandoned is calculated and used as a usage status parameter. The larger the ratio, the more likely the trusted data space has lost its usability and is considered an invalid trusted data space. To ensure data security, access permissions for each user need to be dynamically deleted to prevent malicious theft and leakage of data.

[0084] The smaller the ratio, the longer the user spends within the trusted data space, and the stronger the usability of the trusted data space.

[0085] If the average cumulative time is greater than the historical average cumulative time of the abandoned trusted data space, it indicates that the trusted data space is likely no longer in use. In this case, the user's access permissions can be dynamically deleted, as well as the permissions of other users, to prevent malicious theft of data from the previously used trusted data space. If the ratio of the average cumulative time to the historical average cumulative time of the abandoned trusted data space is greater than 1, it can be considered an extremely high risk. In this case, the user's access permissions need to be dynamically deleted immediately to prevent data theft.

[0086] For example, the historical average cumulative time of abandoned trusted data space is verified to be 5.5 hours, and the usage status parameter is 7.25 / 5.5=1.3.

[0087] Furthermore, based on the usage status parameters, the second access anomaly rate is adjusted to obtain the adjusted access anomaly rate. The adjusted access anomaly rate is the product of the usage status parameters and the second access anomaly rate.

[0088] For example, the second abnormal access rate is 0.25 * 1.89 = 0.47. The corrected abnormal access rate is (1.3 * 0.47) * 100% = 61%.

[0089] In this embodiment, the usage status parameter for dynamic access control is obtained by calculating the ratio of the average cumulative time to the historical average cumulative time of the abandoned trusted data space. A corrected access anomaly rate is then calculated to obtain the corrected access anomaly rate. This corrected access anomaly rate not only determines the user's usage status but also the overall usage status of the trusted data space, providing further analytical support for access control, promoting dynamic access control, and enhancing the security of the access control system.

[0090] S40: Based on the corrected access anomaly rate, the permissions of the target user are determined and adjusted to complete dynamic permission authentication management.

[0091] In this embodiment, the permissions of a target user can be determined and adjusted based on the corrected access anomaly rate. The obtained corrected access anomaly rate is the final basis for determining user permissions. A threshold judgment is performed on the corrected access anomaly rate. If the corrected access anomaly rate is greater than the threshold, the target user's permissions are revoked, thus completing dynamic and timely permission management.

[0092] In this embodiment of the application, step S40 includes:

[0093] Get the access anomaly rate threshold;

[0094] Determine whether the corrected access anomaly rate is greater than or equal to the access anomaly rate threshold; if so, adjust the permission to delete the target user.

[0095] If not, the permissions of the target user will not be adjusted, and dynamic authentication management of permissions will be completed.

[0096] Specifically, the first step is to obtain the access anomaly rate threshold.

[0097] For example, if the access anomaly rate threshold is 60%, those skilled in the art can adjust the setting. A higher anomaly rate threshold provides more lenient management of user permissions, while a lower threshold provides stricter management. Simultaneously, a lower anomaly rate threshold offers stronger protection for the target user.

[0098] Furthermore, it is determined whether the access anomaly rate is greater than or equal to the access anomaly rate threshold. If so, the permissions of the target user to be deleted are adjusted; otherwise, the permissions of the target user are not adjusted, thus completing the dynamic authentication management of permissions.

[0099] If the access anomaly rate is 61%, it indicates that the target user's account has experienced abnormal access (i.e., the access anomaly rate is greater than 60%), and the target user's permissions will be adjusted and removed. If the access anomaly rate is 50% (i.e., the access anomaly rate is less than 60%), it indicates that the target user's account is not currently experiencing abnormal access or that the trusted data space is invalid, and the target user's permissions do not need to be adjusted. Ultimately, dynamic authentication management of permissions is completed.

[0100] If the target user is not using the target account due to special circumstances such as taking leave, resulting in the accidental deletion of the target account's permissions, the permissions can be manually re-authenticated to correct the accidental deletion.

[0101] This application provides a method and system for dynamic authentication management of permissions in a trusted data space. The method employs four steps: cumulative time collection, cumulative time anomaly classification, calculation using status parameters, and anomaly rate threshold determination. The first step, cumulative time classification, yields a first access anomaly rate. This classification obtains an access anomaly coefficient, which is used to correct the first access anomaly rate, resulting in a second access anomaly rate. Usage status analysis is performed to obtain usage status parameters, which are then used to correct the second access anomaly rate, resulting in a corrected access anomaly rate. Threshold determination using the precisely calculated corrected access anomaly rate allows for accurate and rapid numerical comparison to determine the permission assessment result, ultimately achieving precise management of dynamic permission authentication. Threshold determination of the calculated corrected access anomaly rate provides timely results for dynamic permission authentication. It can also determine whether a target user or the entire data space is obsolete. Threshold determination identifies security risks and determines whether to dynamically delete user access permissions, preventing malicious data theft and significantly enhancing system security. Through the collection, calculation, and judgment processes, automated permission management is achieved, making the permission authentication management system dynamic. This enables the system to handle the risks of user account theft and data space failure, achieving more comprehensive dynamic management. It reduces problems with ineffective and inaccurate access control. It effectively improves access control performance, increases timeliness, and results in a dynamic and precise management system.

[0102] Example 2, as Figure 2 As shown, based on the same inventive concept as the novel dynamic authentication management method for a trusted data space provided in Embodiment 1, this embodiment of the invention also provides a dynamic authentication management system for permissions in a trusted data space, including:

[0103] The cumulative time acquisition module 11 is used to acquire the target cumulative time of the target user in the trusted data space after the most recent access, and classify to obtain the first access anomaly rate, wherein the target user has access to the trusted data space;

[0104] The cumulative time anomaly classification module 12 is used to obtain multiple cumulative times of other users in the trusted data space, use multiple cumulative times to perform integrated anomaly classification on the target cumulative time, obtain access anomaly coefficient, correct the first access anomaly rate, and obtain a second access anomaly rate.

[0105] The status parameter calculation module 13 is used to perform a usage status analysis of the trusted data space based on multiple cumulative times, obtain usage status parameters, correct the second access anomaly rate, and obtain a corrected access anomaly rate.

[0106] The anomaly rate threshold determination module 14 is used to determine and adjust the permissions of the target user based on the corrected access anomaly rate, thereby completing dynamic permission authentication management.

[0107] In one embodiment, the cumulative time acquisition module 11 is used for:

[0108] Obtain the target cumulative time of a target user within the trusted data space since their most recent access, wherein the target user has access rights to the trusted data space;

[0109] Based on the access management data of similar trusted data spaces, construct an access anomaly classification table;

[0110] Input the target cumulative time into the access anomaly classification table, and output the first access anomaly rate.

[0111] Among them, the construction of an access anomaly classification table based on the permission management data of the same trusted data space includes:

[0112] Get multiple cumulative time intervals;

[0113] Based on the permission management data of similar trusted data spaces, the proportion of user permissions being stolen within each cumulative time interval is obtained and labeled as the first access anomaly rate of the sample, thus obtaining the first access anomaly rate of multiple samples.

[0114] Construct a mapping relationship between the multiple cumulative time intervals and the first access anomaly rate of multiple samples to obtain an access anomaly classification table.

[0115] In one embodiment, the cumulative time anomaly classification module 12 is used for:

[0116] Obtain multiple cumulative times from multiple other users within the trusted data space;

[0117] Multiple cumulative time periods are randomly selected over multiple cumulative time periods, and the average is calculated to obtain multiple average cumulative time periods. Each cumulative time period includes several cumulative time periods.

[0118] Based on multiple average cumulative times and target cumulative times, an access anomaly coefficient is calculated, and the first access anomaly rate is corrected to obtain a second access anomaly rate.

[0119] The process of calculating an access anomaly coefficient based on multiple average cumulative times and a target cumulative time, and then correcting the first access anomaly rate to obtain a second access anomaly rate, includes:

[0120] Calculate the similarity between multiple cumulative times and the target cumulative time to obtain multiple access similarities;

[0121] Calculate the arithmetic mean of multiple access similarities to obtain the average access similarity, and calculate the access anomaly coefficient.

[0122] The first access anomaly rate is corrected and calculated based on the ratio of the access anomaly coefficient to the average access anomaly coefficient to obtain the second access anomaly rate.

[0123] In one embodiment, the state parameter calculation module 13 is used for:

[0124] The average cumulative time is calculated based on multiple cumulative time periods.

[0125] The ratio of the average cumulative time to the historical average cumulative time of the abandoned trusted data space is calculated and used as a usage status parameter.

[0126] Using the usage status parameters, the second access anomaly rate is corrected and calculated to obtain the corrected access anomaly rate.

[0127] In one embodiment, the anomaly rate threshold determination module 14 is used for:

[0128] Get the access anomaly rate threshold;

[0129] Determine whether the corrected access anomaly rate is greater than or equal to the access anomaly rate threshold; if so, adjust the permission to delete the target user.

[0130] If not, the permissions of the target user will not be adjusted, and dynamic authentication management of permissions will be completed.

[0131] The embodiments of this application, through the specific implementation methods described above, achieve the following technical effects:

[0132] It should be noted that the order of the embodiments described above is merely for descriptive purposes and does not represent the superiority or inferiority of the embodiments. Furthermore, the above description focuses on specific embodiments of this specification. Additionally, the processes depicted in the accompanying drawings do not necessarily require a specific or sequential order to achieve the desired results. In some implementations, multitasking and parallel processing are possible or may be advantageous.

[0133] Example 3, as shown in the appendix Figure 3 As shown, based on the inventive concept of a dynamic authentication management method for trusted data space provided in Embodiment 1, this application also provides a computer-readable storage medium 300, on which a first computer program 311 is stored.

[0134] When the first computer program 311 is executed by the processor 420, it implements a dynamic authentication management method for trusted data space permissions in Embodiment 1.

[0135] Example 4, as shown in the appendix Figure 4As shown, based on the inventive concept of a dynamic authentication management method for trusted data space provided in Embodiment 1, this application also provides a verification terminal 400, which comprises:

[0136] Memory 410 is used to store the second computer program 411;

[0137] Processor 420 is used to read and execute the second computer program 411.

[0138] When the second computer program 411 is executed by the processor 420, it implements a dynamic authentication management method for trusted data space permissions as described in Embodiment 1.

[0139] The above description is only a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the protection scope of this application.

[0140] This specification and accompanying drawings are merely illustrative examples of this application and are intended to cover any and all modifications, variations, combinations, or equivalents within the scope of this application. Clearly, those skilled in the art can make various alterations and modifications to this application without departing from its scope. Therefore, if such modifications and variations fall within the scope of this application and its equivalents, this application intends to include such modifications and variations.

Claims

1. A method for dynamic authentication management of permissions in a trusted data space, characterized in that, The method includes: Obtain the target cumulative time since the most recent visit of the target user within the trusted data space, and classify it to obtain the first visit anomaly rate, including: Obtain the target cumulative time for the target user within the trusted data space since their most recent visit; Based on the access management data of similar trusted data spaces, construct an access anomaly classification table; The target cumulative time is input into the access anomaly classification table, and the first access anomaly rate is output, wherein the target user has access to the trusted data space; Obtain multiple cumulative times from other users within the trusted data space. Using these multiple cumulative times, perform integrated anomaly classification on the target cumulative time to obtain an access anomaly coefficient. Correct the first access anomaly rate to obtain a second access anomaly rate, including: Calculate the similarity between multiple cumulative times and the target cumulative time to obtain multiple access similarities; Calculate the arithmetic mean of multiple access similarities to obtain the average access similarity, and calculate the access anomaly coefficient. The first access anomaly rate is corrected and calculated based on the ratio of the access anomaly coefficient to the average access anomaly coefficient to obtain the second access anomaly rate. Based on multiple cumulative time periods, a usage status analysis of the trusted data space is performed to obtain usage status parameters. The second access anomaly rate is then corrected to obtain a corrected access anomaly rate, including: The average cumulative time is calculated based on multiple cumulative time periods. The ratio of the average cumulative time to the historical average cumulative time of the abandoned trusted data space is calculated and used as a usage status parameter. Using the usage status parameters, the second access anomaly rate is corrected and calculated to obtain the corrected access anomaly rate; Based on the corrected access anomaly rate, the permissions of the target user are determined and adjusted to complete dynamic permission authentication management.

2. The method for dynamic authentication management of trusted data space permissions according to claim 1, characterized in that, Based on access control data from similar trusted data spaces, construct an access anomaly classification table, including: Get multiple cumulative time intervals; Based on the permission management data of similar trusted data spaces, the proportion of user permissions being stolen within each cumulative time interval is obtained and labeled as the first access anomaly rate of the sample, thus obtaining the first access anomaly rate of multiple samples. A mapping relationship is constructed between the multiple cumulative time intervals and the first access anomaly rate of multiple samples to obtain an access anomaly classification table.

3. The method for dynamic authentication management of trusted data space permissions according to claim 1, characterized in that, Obtain multiple cumulative times from other users within the trusted data space. Using these multiple cumulative times, perform integrated anomaly classification on the target cumulative time to obtain an access anomaly coefficient. Correct the first access anomaly rate to obtain a second access anomaly rate, including: Obtain multiple cumulative times from multiple other users within the trusted data space; Multiple cumulative time periods are randomly selected over multiple cumulative time periods, and the average is calculated to obtain multiple average cumulative time periods. Each cumulative time period includes several cumulative time periods. Based on multiple average cumulative times and target cumulative times, an access anomaly coefficient is calculated, and the first access anomaly rate is corrected to obtain a second access anomaly rate.

4. The method for dynamic authentication management of trusted data space permissions according to claim 1, characterized in that, Based on the corrected access anomaly rate, the permissions of the target user are assessed and adjusted to complete dynamic permission authentication management, including: Get the access anomaly rate threshold; Determine whether the corrected access anomaly rate is greater than or equal to the access anomaly rate threshold; if so, adjust the permission to delete the target user. If not, the permissions of the target user will not be adjusted, and dynamic authentication management of permissions will be completed.

5. A dynamic authentication management system for trusted data spaces, characterized in that, The system is used to implement the dynamic authentication management method for a trusted data space according to any one of claims 1-4, the system comprising: The cumulative time acquisition module is used to obtain the target cumulative time of a target user within the trusted data space since their most recent access, and classifies it to obtain the first access anomaly rate, including: Obtain the target cumulative time for the target user within the trusted data space since their most recent visit; Based on the access management data of similar trusted data spaces, construct an access anomaly classification table; The target cumulative time is input into the access anomaly classification table, and the first access anomaly rate is output, wherein the target user has access to the trusted data space; The cumulative time anomaly classification module is used to obtain multiple cumulative times from multiple other users within the trusted data space. Using these multiple cumulative times, it performs integrated anomaly classification on the target cumulative time to obtain an access anomaly coefficient. The first access anomaly rate is then corrected to obtain a second access anomaly rate, including: Calculate the similarity between multiple cumulative times and the target cumulative time to obtain multiple access similarities; Calculate the arithmetic mean of multiple access similarities to obtain the average access similarity, and calculate the access anomaly coefficient. The first access anomaly rate is corrected and calculated based on the ratio of the access anomaly coefficient to the average access anomaly coefficient to obtain the second access anomaly rate. The status parameter calculation module is used to analyze the usage status of the trusted data space based on multiple cumulative time periods, obtain usage status parameters, and correct the second access anomaly rate to obtain a corrected access anomaly rate, including: The average cumulative time is calculated based on multiple cumulative time periods. The ratio of the average cumulative time to the historical average cumulative time of the abandoned trusted data space is calculated and used as a usage status parameter. Using the usage status parameters, the second access anomaly rate is corrected and calculated to obtain the corrected access anomaly rate; The anomaly rate threshold determination module is used to determine and adjust the permissions of the target user based on the corrected access anomaly rate, thereby completing dynamic permission authentication management.

6. A computer-readable storage medium, characterized in that, The storage medium stores a first computer program, which, when executed by a processor, implements a dynamic authentication management method for trusted data space permissions as described in any one of claims 1-4.

7. A verification terminal, characterized in that, The verification terminal includes a processor and a memory: Memory, used to store a second computer program; A processor is configured to read and execute the second computer program, thereby implementing the dynamic authentication management method for trusted data space as described in any one of claims 1-4.

Citation Information

Patent Citations

  • Abnormal flow control method and system

    CN116743501A

  • Industrial internet identification data security access method

    CN116933324A