Data access security control method and system based on dynamic strategy linkage

CN120979752AActive Publication Date: 2025-11-18GUANGDONG QINGYUN INFORMATION TECH CO LTD

Patent Information

Application Number
CN202511208479.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-27
Publication Date
2025-11-18
Estimated Expiration
2045-08-27

Smart Images

  • Figure CN120979752A_ABST
    Figure CN120979752A_ABST
Patent Text Reader

Abstract

The invention discloses a data access security control method and system based on dynamic strategy linkage, and relates to the technical field of data access security, the method comprises the following steps: after receiving a data access request of a user, establishing a data perception set; calculating an access risk value according to the data perception set, and configuring an access strategy of the user; when the user executes access, account data of the user is called, an operation sequence is converted into behavior probability distribution, and behavior information entropy is calculated; constructing a behavior probability model, and establishing a first abnormal result; carrying out anomaly measurement on the time sequence access operation by utilizing the calibrated access behavior, and establishing a second anomaly result; and generating a safety control strategy. The technical problem that in the prior art, data access safety control is not accurate enough, and consequently data access safety and reliability are insufficient is solved, and the technical effects that accurate safety control over data access is achieved, and data access safety and reliability are improved are achieved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data access security, in particular to a data access security control method and system based on dynamic policy linkage. BACKGROUND

[0002] In the field of data access security, traditional security control methods often rely on static policies, which are difficult to cope with complex and variable access environments and user behaviors. These methods usually only perform access control based on single-dimensional risk assessment, lack comprehensive perception and dynamic linkage of environmental risks, data sensitivity, user historical behaviors and other factors, resulting in insufficient precision in identifying abnormal access behaviors, insufficient adaptability and effectiveness of security control strategies, and difficulty in meeting the growing demand for data security protection.

[0003] The prior art has the technical problem of insufficient precision in data access security control, resulting in insufficient data access security and reliability. SUMMARY

[0004] The present application provides a data access security control method and system based on dynamic policy linkage, which is used to solve the technical problem of insufficient precision in data access security control in the prior art, resulting in insufficient data access security and reliability.

[0005] In view of the above problems, the present application provides a data access security control method and system based on dynamic policy linkage.

[0006] The first aspect of the present application provides a data access security control method based on dynamic policy linkage, the method comprising: After receiving the user's data access request, the perception layer is activated to perform data perception, and a data perception set is established, the data perception set including environmental risk perception, access data sensitivity perception, user historical behavior and authentication perception; the access risk value is calculated according to the data perception set, and the user's access policy is configured based on the access risk value; after the user performs access, the user's account data is called, the operation sequence of the user's access is extracted according to the account data, the operation sequence is converted into a behavior probability distribution, and the behavior information entropy is calculated; the behavior probability model is constructed using the operation sequence and operation task, the unexpectedness of the time sequence access operation is measured using the behavior probability model, and the first abnormal result is established; the calibrated access behavior call is performed according to the user's access task, the abnormality of the time sequence access operation is measured using the calibrated access behavior, and the second abnormal result is established; the global-local fusion authentication is performed using the behavior information entropy, the first abnormal result and the second abnormal result, and the security control strategy is generated.

[0007] In a second aspect of the present application, a data access security control system based on dynamic policy linkage is provided, and the system comprises: a data perception set establishing module, configured to activate a perception layer to perform data perception and establish a data perception set after receiving a data access request of a user, wherein the data perception set comprises environmental risk perception, access data sensitivity perception, user historical behavior and authentication perception; an access policy configuration module, configured to calculate an access risk value according to the data perception set, and configure an access policy of the user based on the access risk value; a behavior information entropy calculation module, configured to call account data of the user after the user performs access, extract an operation sequence of the user access according to the account data, convert the operation sequence into a behavior probability distribution, and calculate behavior information entropy; a first abnormal result establishing module, configured to construct a behavior probability model by using the operation sequence and operation task, measure unexpectedness of time-series access operation by using the behavior probability model, and establish a first abnormal result; a second abnormal result establishing module, configured to perform calibration access behavior calling according to an access task of the user, measure abnormality of time-series access operation by using the calibration access behavior, and establish a second abnormal result; and a security control policy generation module, configured to perform global-local fusion authentication by using the behavior information entropy, the first abnormal result and the second abnormal result, and generate a security control policy.

[0008] The one or more technical solutions provided in the present application have at least the following technical effects or advantages: After receiving a data access request of a user, a perception layer is activated to perform data perception and establish a data perception set; an access risk value is calculated according to the data perception set, and an access policy of the user is configured based on the access risk value; after the user performs access, account data of the user is called, the operation sequence is converted into a behavior probability distribution, and behavior information entropy is calculated; a behavior probability model is constructed by using the operation sequence and operation task, unexpectedness of time-series access operation is measured by using the behavior probability model, and a first abnormal result is established; calibration access behavior calling is performed according to an access task of the user, abnormality of time-series access operation is measured by using the calibration access behavior, and a second abnormal result is established; global-local fusion authentication is performed, and a security control policy is generated. The technical effect of realizing precise security control of data access is achieved, and the security and reliability of data access are improved. BRIEF DESCRIPTION OF DRAWINGS

[0009] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative effort.

[0010] Figure 1 A schematic diagram of a data access security control method based on dynamic policy linkage provided in this application embodiment; Figure 2 This is a schematic diagram of a data access security control system structure based on dynamic policy linkage, provided as an embodiment of this application.

[0011] Explanation of reference numerals in the attached diagram: Data awareness set establishment module 10, access policy configuration module 20, behavior information entropy calculation module 30, first abnormal result establishment module 40, second abnormal result establishment module 50, security control policy generation module 60. Detailed Implementation

[0012] This application provides a data access security control method and system based on dynamic policy linkage, which addresses the technical problem that insufficient precision in data access security control in the prior art leads to inadequate data access security and reliability.

[0013] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.

[0014] Example 1, as Figure 1 As shown, this application provides a data access security control method based on dynamic policy linkage, the method comprising: Step S100: After receiving the user's data access request, activate the perception layer to perform data perception and establish a data perception set, which includes environmental risk perception, access data sensitivity perception, user historical behavior and authentication perception.

[0015] Specifically, upon receiving a user's data access request, the perception layer is immediately activated to perform data perception operations. This layer collects and analyzes information from multiple aspects to establish a data perception set. Specifically, environmental risk perception identifies and assesses risks related to the network environment and device status during the user's access; access data sensitivity perception judges the sensitivity level and confidentiality of the requested data; user history behavior perception retrieves and analyzes past access records and operational habits; and authentication perception focuses on the user's authentication status, including authentication method, authentication timeliness, and authentication result. By integrating these four aspects of information, a complete data perception set is ultimately formed, encompassing environmental risk perception, access data sensitivity perception, user history behavior, and authentication perception, providing foundational data support for subsequent access risk assessment and strategy configuration.

[0016] Step S200: calculating an access risk value according to the data perception set, and configuring an access strategy of the user based on the access risk value.

[0017] Specifically, when calculating the access risk value according to the established data perception set, each perception dimension in the data perception set, such as the environmental risk perception, the access data sensitivity perception, the user historical behavior and the authentication perception, is calculated for risk respectively, to generate a local risk score set containing risk scores of each dimension and each score with a confidence identifier; then, the multi-dimensional perception data in the data perception set is analyzed for data interaction influence to determine an interaction correlation factor; subsequently, the local risk score set under the confidence identifier is fused for interaction influence by using the interaction correlation factor, to obtain the access risk value. When configuring the access strategy of the user based on the access risk value, it is determined whether the access risk value meets an access threshold, if yes, the corresponding access strategy is configured, if not, a rejection access instruction is executed, and an abnormal access early warning is generated.

[0018] Step S300: when the user performs access, account data of the user is called, an operation sequence of the user access is extracted from the account data, the operation sequence is converted into a behavior probability distribution, and behavior information entropy is calculated.

[0019] Specifically, when the user performs an access operation, the account data of the user is called, and the complete operation sequence of the user in the access process is extracted therefrom, covering various interaction actions of the user in the access process; then, the operation sequence is converted into a behavior probability distribution, the frequency and probability characteristics of different operations in the sequence are counted, and the behavior information entropy reflecting the uncertainty of the overall behavior pattern of the user is calculated, so as to analyze the regularity and abnormal tendency of the user access behavior from a global level, and provide a global dimension behavior feature basis for subsequent security authentication.

[0020] Step S400: constructing a behavior probability model by using the operation sequence and the operation task, performing unexpectedness measurement of time sequence access operation by using the behavior probability model, and establishing a first abnormal result.

[0021] Specifically, based on the extracted operation sequence of the user access and the corresponding operation task, a behavior probability model reflecting the probability correlation of each step operation under a specific operation task is constructed, the model focuses on the probability distribution and conversion law of each local link in the operation sequence; then, the model is used to measure the unexpectedness of the time sequence access operation step by step, by comparing the difference between the actual operation and the normal operation probability predicted by the model, the abnormal points deviating from the expectation in the local operation link are identified, and then the first abnormal result is established by integrating these local abnormal information, to provide a basis for subsequent security authentication from a local level.

[0022] Step S500: According to the user's access task, the calibrated access behavior is called, the abnormality measurement of the time sequence access operation is performed by using the calibrated access behavior, and the second abnormality result is established.

[0023] Specifically, according to the current access task of the user, the calibrated access behavior corresponding to the task is called, and the calibrated access behavior is a standard behavior mode preset based on the standard operation process under the same task; then, the actual time sequence access operation of the user is compared with the calibrated access behavior step by step, the abnormality degree of the actual operation at the specific step is measured by analyzing the matching degree of the two in the local operation link, for example, the deviation of the operation sequence, the omission or redundancy of the key operation, etc.; based on the local abnormality measurement result, the second abnormality result is integrated to provide another dimension of local abnormality analysis basis for subsequent security authentication.

[0024] Step S600: Global-local fusion authentication is performed by using the behavior information entropy, the first abnormality result, and the second abnormality result to generate a security control strategy.

[0025] Specifically, when the behavior information entropy, the first abnormality result, and the second abnormality result are used for global-local fusion authentication to generate a security control strategy, the operation monitoring instruction is activated first, the user operation is monitored, and the operation data set containing the keyboard key pressure, the typing impact energy, the mouse moving speed, the acceleration, the click pressure, the mouse wheel impact, and the touch feature set is established; the energy conversion result is obtained by performing energy conversion on the operation data set, and then the energy event is analyzed by using the result, the energy-behavior coupling feature is analyzed, and the energy stability of the adaptive sliding window is analyzed to establish the first, second, and third time sequence features, and the energy abnormality is established accordingly; then, the energy abnormality, the behavior information entropy, the first abnormality result, and the second abnormality result are normalized to the same dimension, the causal correlation authentication under the same dimension is performed, the global-local fusion authentication is completed by using the authentication result, and finally the security control strategy is generated. After the security control strategy is generated, the user abnormal behavior intention is identified according to the behavior information entropy, the first abnormality result, and the second abnormality result, and the strategy is corrected, the user permission space is reconstructed, the environment is warned, the user abnormal behavior features are extracted, the global dynamic linkage recognition signal is established for global user verification, and the security control strategy and the account level of the user account are updated.

[0026] In one possible implementation manner, step S600 further includes: Step S610: The operation monitoring instruction is activated, the operation monitoring of the user is performed by using the operation monitoring instruction, and the operation data set is established, the operation data set including the keyboard key pressure, the typing impact energy, the mouse moving speed, the acceleration, the click pressure, the mouse wheel impact, and the touch feature set.

[0027] Step S620: performing energy conversion on the operation data set to establish an energy conversion result.

[0028] Step S630: performing autoregressive analysis of the energy event using the energy conversion result to establish a first time sequence feature.

[0029] Step S640: performing energy-behavior coupling feature analysis using the energy conversion result to establish a second time sequence feature.

[0030] Step S650: performing adaptive sliding window energy stability analysis using the energy conversion result to establish a third time sequence feature.

[0031] Step S660: establishing an energy anomaly according to the first time sequence feature, the second time sequence feature, and the third time sequence feature.

[0032] Step S670: performing global-local fusion authentication based on the energy anomaly, the behavior information entropy, the first anomaly result, and the second anomaly result to generate a security control strategy.

[0033] Specifically, an operation monitoring instruction is activated, and through the instruction, various operation behaviors of the user in the data access process are monitored in real time and comprehensively. During the monitoring process, the key pressing force when the user operates the keyboard, the typing impact energy, the moving speed, the acceleration, the click pressure, the mouse wheel impact when the user operates the mouse, and the feature set related to touch operation are accurately collected. The multi-dimensional operation data collected is integrated and summarized to construct an operation data set containing the above-mentioned content, thereby providing basic data support for subsequent energy conversion and anomaly analysis.

[0034] For the established operation data set, various operation parameters are processed by a preset energy conversion algorithm. The keyboard key pressing force, typing impact energy, mouse moving speed, acceleration, click pressure, mouse wheel impact, and related parameters in the touch feature set are uniformly converted into quantifiable energy values according to respective corresponding physical energy conversion models to form an energy conversion result covering energy features of each operation link, thereby realizing mapping of operation data to energy dimension data.

[0035] In autoregressive analysis of energy events using energy conversion results, the energy values in the energy conversion results are sorted by time sequence to form a continuous energy event sequence. Then, an autoregressive model is constructed, the energy value at the current time is taken as the dependent variable, and the energy values at several time points before the current time are taken as the independent variables. The model parameters are solved by the least square method to determine the autocorrelation of the energy events in time sequence. Based on this model, the trend and fluctuation rule of the energy events over time are analyzed, and the characteristic parameters reflecting the time sequence dependence of the energy events are extracted, such as the autoregressive coefficient and residual variance, and then the first time sequence feature is established to describe the dynamic change pattern of the energy events in the time dimension.

[0036] In energy-behavior coupling feature analysis using energy conversion results, each energy value in the energy conversion results is bound to the corresponding operation behavior (such as keyboard key, mouse click, scroll wheel operation, touch action, etc.) by time stamp to form an associated data set containing “behavior type-occurrence time-energy value”. Then, the data set is segmented by a sliding time window, and the Pearson correlation coefficient of energy value and behavior frequency is calculated in each window to measure the linear correlation degree between them. At the same time, the energy peak value and the behavior key node in the window are extracted, such as the time difference between the start / end time of operation, to construct the time coordination feature. Then, the coupling degree index is calculated by combining the transition probability of the behavior sequence and the change rate of the energy sequence. The correlation coefficient, time coordination feature and coupling degree index are combined to extract the parameters reflecting the dynamic correlation rule of energy and behavior, and the second time sequence feature is established.

[0037] In adaptive sliding window energy stability analysis using energy conversion results, the size of the sliding window is dynamically adjusted according to the amplitude of the energy value in the energy conversion results. When the energy fluctuates violently, the window is reduced to capture the instantaneous change, and when the energy tends to be stable, the window is increased to reflect the overall trend. Then, in each adaptively adjusted window, the mean, variance, standard deviation and coefficient of variation of the energy value are calculated to measure the concentration and dispersion of the energy in the window. By tracking the above indicators of consecutive windows in time sequence, the change rule of energy stability is analyzed, and the characteristic parameters reflecting the energy fluctuation stability under different windows are extracted, and then the third time sequence feature is established to describe the dynamic stability characteristics of energy in the time dimension.

[0038] When the energy anomaly is established according to the first time sequence feature, the second time sequence feature and the third time sequence feature, first, normal threshold ranges corresponding to the three time sequence features are respectively set, wherein the normal threshold of the first time sequence feature is determined based on a parameter interval of a normal time sequence dependent characteristic in an energy event autoregressive analysis, the normal threshold of the second time sequence feature is delimited according to a conventional degree of cooperation of energy and behavior coupling association, and the normal threshold of the third time sequence feature is set with reference to a common range of stable fluctuation of energy under different windows; then, the actually extracted first time sequence feature, second time sequence feature and third time sequence feature are respectively compared with the corresponding normal threshold ranges, and abnormal features exceeding the threshold ranges are identified; finally, whether there is an anomaly at an energy level is judged by comprehensively considering the occurrence frequency, deviation degree and mutual correlation of these abnormal features, and if there is, an energy anomaly is integrated to form, so as to reflect abnormal change of operating energy in a data access process.

[0039] When the global-local fusion authentication is performed based on the energy anomaly, the behavior information entropy, the first abnormal result and the second abnormal result to generate a security control strategy, first, the four types of indexes are normalized to the same dimension to eliminate the measurement difference between different indexes; then, the four types of indexes under the same dimension are subjected to causal correlation authentication, the correlation between the global behavior uncertainty reflected by the energy anomaly and the behavior information entropy is analyzed, and the mutual influence between the local operation anomaly embodied by the first abnormal result and the second abnormal result and the energy anomaly and the global behavior feature is analyzed, through cross verification and correlation analysis between the global level (overall features of the behavior information entropy and the energy anomaly) and the local level (specific operation anomaly of the first abnormal result and the second abnormal result), the fusion authentication is completed, and finally the security control strategy adapted to the current access scene is generated.

[0040] In a possible implementation manner, the step S670 further includes: Step S671: normalizing the energy anomaly, the behavior information entropy, the first abnormal result and the second abnormal result to the same dimension.

[0041] Step S672: performing causal correlation authentication of the energy anomaly, the behavior information entropy, the first abnormal result and the second abnormal result under the same dimension, and completing the global-local fusion authentication by using the causal correlation authentication result.

[0042] Specifically, for the energy anomaly, the behavior information entropy, the first anomaly result and the second anomaly result, a standardization processing method is adopted to normalize them to the same dimension, by setting a unified numerical mapping interval, the original values of various indicators are converted to the interval according to the proportion, the incommensurability caused by the differences in measurement methods and numerical ranges of different indicators is eliminated, the energy level anomaly degree reflected by the energy anomaly, the global behavior uncertainty embodied by the behavior information entropy, the local operation anomaly degree presented by the first anomaly result and the second anomaly result are kept consistent in the numerical scale, and a unified standard analysis basis is provided for subsequent causal correlation authentication.

[0043] When the energy anomaly, the behavior information entropy, the first anomaly result and the second anomaly result are subjected to causal correlation authentication under the same dimension, a Granger causality test method is adopted to analyze the causal relationship among the four in the time sequence change, the influence direction and degree between variables are judged by calculating the significance of lag items; meanwhile, a Bayesian network model is combined to construct a probability correlation graph of the four, the conditional probability distribution between different abnormal indicators is quantified, and the correlation strength of the global behavior characteristics and the local operation anomaly in the influence path is clarified. Based on these analysis results, the global analysis conclusion and the local abnormal information are weighted and fused, the feature combination with significant causal relationship is screened out by setting a correlation threshold, the global-local fusion authentication is completed, and the authentication result can comprehensively reflect the overall behavior safety and the local operation abnormal details.

[0044] In one possible implementation manner, the step S600 further includes: According to the behavior information entropy, the first anomaly result and the second anomaly result, an abnormal behavior intention recognition of the user is performed, and an intention task set is established.

[0045] A virtual test task is created by using the intention task set, and the virtual test task is sorted by an initial confidence degree of the intention task set.

[0046] After a random factor is configured based on the initial confidence degree sorting, a random test insertion of the virtual test task is performed, wherein the random test insertion is a test insertion in a normal equivalent template.

[0047] Operation feedback of the user is obtained, and the safety control strategy is corrected according to the operation feedback.

[0048] Specifically, a bidirectional long short-term memory network based on attention mechanism (BiLSTM-Attention) is used for user abnormal behavior intention recognition: the behavior information entropy, the first abnormal result, and the second abnormal result are input into the model as sequence features, the BiLSTM layer is used to capture the time sequence dependence of the three, and the attention mechanism is used to give higher weights to key features to highlight abnormal associations; the model output layer combines a softmax classifier to map the features to the preset abnormal intention categories (such as unauthorized access, data tampering, etc.), and then the classification results are sorted by intention categories, the corresponding behavior feature descriptions and risk levels are added, and a structured intention task set is formed.

[0049] When creating a virtual test task using the established intention task set, first, the abnormal behavior intentions in the intention task set are sorted from high to low according to the initial confidence, so that the virtual test task corresponding to the intention with high confidence has a higher priority; then, according to the sorting result, a virtual test task matching each intention task is generated, which can simulate the operation scenarios and data access requests that may be involved in the corresponding abnormal behavior intention, and finally a virtual test task sequence sorted by initial confidence is formed.

[0050] After determining the priority of the virtual test task based on the initial confidence sorting of the intention task set, a corresponding random factor is configured for each virtual test task, which is used to regulate the timing and frequency of test insertion; then, the random insertion operation of the virtual test task is performed in the normal equivalent templates, which are consistent with the normal data access scenarios and operation processes, and the inserted virtual test task not only meets the characteristics of the regular operation, but also implicitly contains the test points of the corresponding abnormal behavior intention, so that the concealed detection of the user's abnormal behavior can be realized without affecting the user's normal operation experience.

[0051] By monitoring the operation behavior of the user when facing the virtual test task in real time, operation feedback data including operation path, response time, instruction execution accuracy, etc. are collected; the feedback data are analyzed in multiple dimensions to judge the matching degree of the user's operation and the abnormal behavior intention, and to identify possible misjudgments or omissions in the security control strategy; according to the analysis results, the parameter threshold and abnormal identification rules of the security control strategy are adjusted, such as optimizing the risk score weight, correcting the abnormal behavior judgment standard, etc., so that the security control strategy can more accurately adapt to the actual behavior mode of the user, and the effectiveness of the data access security control is improved.

[0052] In one possible implementation, step S600 further includes: According to the security control strategy, the user's permission space is reconstructed, and an environment warning of the access environment is established.

[0053] After adjusting the user's permissions based on the permission space, the environment warning is reported according to the environment warning.

[0054] Specifically, according to the limitation of user access permissions and the division of security levels in the security control strategy, the user's permission space is reconstructed, and the data categories, operation ranges, and permission time limits that each user can access are determined to ensure that the permission allocation and security control requirements are accurately matched. At the same time, the network environment, device state, and data transmission link involved in data access are comprehensively monitored, and an environmental risk index threshold is set. When the monitored index exceeds the threshold, the early warning mechanism is triggered, and the environmental warning of the access environment is established.

[0055] After adjusting the user's permissions based on the reconstructed permission space to ensure that the user can only perform data access operations within the authorized range, the indicators of the access environment are continuously monitored. When the environmental warning mechanism detects that the access environment is abnormal, such as potential threats to the network, unstable device operation state, or risks in the data transmission link, the warning information is reported to the relevant security management personnel or system administrator according to the preset warning rules and notification methods, so that timely measures can be taken to deal with security risks.

[0056] In one possible implementation, step S600 further includes: Abnormal behavior extraction is performed on the user to establish abnormal behavior characteristics.

[0057] The risk intention of the user is obtained, and a global dynamic linkage recognition signal is established based on the abnormal behavior characteristics and the risk intention.

[0058] Global user verification is performed using the global dynamic linkage recognition signal, and a group abnormality management strategy is established.

[0059] Specifically, the operation behavior of the user during data access is monitored and recorded in real time, and the operation that deviates from the normal behavior pattern of the user is selected from multiple dimensions such as operation sequence, access frequency, and data interaction mode, such as sudden batch data download, access to unauthorized data area, and sensitive operation in an irregular time period. The characteristics of these abnormal operations are extracted, including operation type, sensitive level of involved data, execution duration, operation path, and other key information, which are integrated into structured abnormal behavior characteristics to accurately depict the abnormal behavior pattern of the user.

[0060] The risk intention reasoning model is constructed to obtain the risk intention of the user, the abnormal behavior characteristics of the user are matched with a preset risk intention label library, the context environment in which the behavior occurs, such as access time and data type involved, is combined, the probability distribution of different risk intentions is calculated through a Bayesian network, and the most possible risk intention of the user is determined; subsequently, a feature fusion algorithm is used to splice the abnormal behavior characteristic vector and the risk intention probability vector, key linkage characteristics are extracted through principal component analysis, and a global dynamic linkage recognition signal containing the behavior-intention correlation strength and the timing change rule is generated.

[0061] The distributed user verification architecture is adopted, the global dynamic linkage recognition signal is taken as a verification benchmark, the behavior characteristics and risk intentions of all users in the system are compared in parallel through distributed nodes, the matching degree of the user behavior and the signal characteristics is calculated, the density clustering algorithm is used to divide the user groups whose matching degrees meet the standard, and a user cluster with similar abnormal patterns is identified; different management strategies are formulated for the abnormal characteristics of different clusters in combination with risk levels, including collective down-regulation of cluster permissions, real-time synchronization audit of operation logs, triggered secondary authentication, and the like, the management rules are pushed to each access control node through a strategy engine, and dynamic management and control of group abnormalities are realized.

[0062] In a possible implementation manner, the step S600 further includes: The security control strategy is updated to the user account of the user, and the account level of the user account is updated.

[0063] Data access security management is performed according to the updated user account.

[0064] Specifically, the generated security control strategy is synchronously updated to the user account of the user, so that the account can perform permission management and security control related to data access according to the new strategy; meanwhile, the account level of the user is adjusted according to the behavior performance, risk level and other factors of the user, such as appropriately improving the account level for a user with low risk and compliant behavior, and reducing the account level for a user with abnormal behavior and high risk.

[0065] According to the updated user account information, full-process security management is implemented on the data access behavior of the user: in combination with the current security control strategy and the account level of the account, the data access request initiated by the user is audited in real time, and the operation of the user within the authorized range is strictly limited; meanwhile, the access operation of the user is continuously monitored, the operation log is recorded and compared with the historical behavior pattern of the account, and once the abnormal behavior deviating from the normal range is found, the corresponding security response mechanism is triggered, such as suspension of access and secondary verification, so as to guarantee the security and compliance of data access.

[0066] In a possible implementation manner, the step S200 further includes: Step S210: risk calculation is performed on each perception dimension in the data perception set to generate a local risk score set, and a confidence identifier is set for each risk score in the local risk score set.

[0067] Step S220: data interaction influence analysis is performed on the multi-dimensional perception data in the data perception set to establish an interaction correlation factor.

[0068] Step S230: the interaction correlation factor is used to perform interaction influence fusion of the local risk score set under the confidence identifier to establish an access risk value.

[0069] Specifically, when performing risk calculation on each perception dimension in the data perception set, a random forest algorithm is adopted. First, a training data set containing historical risk cases, feature variables and corresponding risk levels is constructed for each perception dimension. The data set is trained through a random forest model to capture the non-linear relationship between features and risks within the perception dimension using the ensemble learning capability of multiple decision trees. Then, real-time data of each perception dimension is input into the trained model to output the risk probability distribution of the corresponding dimension. The risk value corresponding to the distribution peak is taken as the risk score of the dimension, and the local risk score set is formed by summarizing. At the same time, the prediction accuracy and variance of the model in cross-validation are calculated, and the weighted result of the accuracy and variance is taken as the confidence identifier of each risk score to quantify the reliability of the score.

[0070] The graph neural network is used to realize the interaction influence analysis of the multi-dimensional perception data in the data perception set. The data of each perception dimension is taken as a node, and the initial correlation edge is constructed by calculating the feature similarity between nodes. The node features and edge weights are iteratively updated using a graph neural network model to learn the potential interaction patterns between different perception dimension data. At the same time, the attention mechanism is introduced to automatically assign weights to different interaction relationships. Finally, the node correlation strength matrix output by the model is converted into a quantitative interaction correlation factor to accurately capture the dynamic interaction influence between multi-dimensional perception data.

[0071] The weighted fusion algorithm is used to perform interaction influence fusion of the local risk score set with confidence identifier using the interaction correlation factor. First, the interaction correlation factor is taken as the influence weight matrix between different perception dimension risk scores. Then, the confidence identifier of each risk score is converted into a weight coefficient in the 0-1 interval. The access risk value is calculated by the formula: access risk value = Σ (local risk score × confidence weight × Σ (interaction correlation factor × other dimension risk score × corresponding confidence weight)). The interaction of each dimension risk and its reliability is comprehensively considered, and finally the access risk value reflecting the overall risk is obtained.

[0072] In one possible implementation, step S200 further includes: Step S240: judging whether the access risk value meets an access threshold.

[0073] Step S250: if the access risk value meets the access threshold, configuring an access policy of the user based on the access risk value.

[0074] Step S260: if the access risk value does not meet the access threshold, executing an access rejection instruction and generating an abnormal access warning.

[0075] Specifically, the calculated access risk value is compared with the preset access threshold, and whether the access risk value is in an acceptable range is determined by comparing the numerical values of the two, i.e., whether it meets the requirement of the access threshold, which is used as a key basis for subsequent processing of the user access request.

[0076] When the access risk value meets the preset access threshold, an appropriate access policy is configured for the user according to the specific size of the access risk value. For example, if the risk value is at a low level, the user is given a wider data access range and fewer restrictions; if the risk value is at a medium level, the access range is appropriately reduced and some necessary verification steps are added; through this dynamic adjustment according to the risk value, it is ensured that the user's access behavior meets the security requirements and meets the reasonable data use needs.

[0077] When it is judged that the access risk value does not reach the preset access threshold, an access rejection instruction is immediately sent to the user to prevent him from continuing the data access operation, and an abnormal access warning containing the access time, access terminal information, risk value specific value and threshold value not reached reason and other contents is automatically generated to know and intervene in the potential security risk in time.

[0078] In some possible embodiments, since the above-mentioned embodiments calculate the access risk value to configure the access policy after receiving the user data access request by activating the perception layer to establish the data perception set (such as environmental risk perception, user historical behavior), the data perception set may be affected by noise, conflict or environmental interference (such as environmental risk misreading caused by network delay), the above-mentioned embodiments only process local risk score through confidence identification, but do not systematically process overall uncertainty. This may cause risk value calculation deviation, and further incorrect configuration of access policy, reducing the accuracy of security control. For example, in a dynamic network environment, transient fluctuations in perceived data may not be effectively smoothed, resulting in misauthorization of high-risk users or excessive restriction of low-risk users.

[0079] To make up for this defect, an embodiment is proposed, which introduces a data uncertainty model into the original system access strategy configuration module to enhance the robustness of risk calculation. This embodiment is based on the local risk score set and the interaction correlation factor in the above-mentioned manner, and adds a Bayesian uncertainty reasoning layer. In specific implementation, after step 200, a new uncertainty evaluation sub-step is added: using the multi-dimensional data in the data perception set (such as environmental risk perception and authentication perception), a Gaussian process model is constructed to simulate the perception noise distribution; a plurality of risk score replicas are generated through Monte Carlo sampling, and a weighted average risk value is calculated in combination with the confidence identifier. This can effectively quantify uncertainty and introduce a dynamic compensation mechanism in risk value calculation.

[0080] In specific implementation, when calculating the access risk value, the original interaction influence fusion (step S230) is first performed, and then uncertainty evaluation is applied. For example, when the environmental risk perception data fluctuates due to network interference, the model automatically identifies the abnormal confidence identifier and adjusts the weight of the interaction correlation factor. At the same time, the system includes the uncertainty index (such as the variance value) in the access strategy configuration, and when the uncertainty exceeds the threshold value, an additional authentication step (such as a rejection access instruction) is triggered. Finally, the accuracy of the risk value in a noisy environment is improved, the access strategy is more reliable, the risk of misconfiguration is reduced, and the overall security is enhanced.

[0081] In some possible implementations, since the above-mentioned embodiment utilizes operation sequences and operation tasks to construct a behavior probability model, establishes a first abnormal result (based on unexpectedness measurement), and establishes a second abnormal result (based on abnormality measurement) in combination with the calibrated access behavior, global-local fusion authentication is used. However, this model is mainly trained on historical user behavior data and does not integrate an online learning mechanism. When encountering a new attack mode or user behavior drift (such as a zero-day vulnerability or a compliance behavior change), the model cannot be updated in real time, resulting in missed detection (such as a new type of data tampering that is not identified) or false detection (such as normal operation being misjudged). Therefore, there is a possibility that model updating is only indirectly corrected through a security control strategy, but the adaptability is not embedded in the core abnormality measurement step.

[0082] To address this defect, the solution of the present embodiment is to integrate an online learning and adaptive model updating framework to directly enhance the behavior probability model. In the original first abnormal result establishment module (step S400) and the second abnormal result establishment module (step S500), an incremental learning component is added: the behavior probability model uses an online support vector machine (SVM) or a deep learning architecture to absorb new operation sequence data in real time; the model triggers updating according to the change rate of the behavior information entropy, and automatically re-trains the probability distribution when the entropy value mutates (such as exceeding a threshold value). At the same time, the dynamic calibration library is introduced in the calibrated access behavior calling step (step S500), an adaptive calibration template is generated using the intent task set to simulate emerging behavior patterns, and the abnormality measurement is strengthened.

[0083] In a specific implementation, after the user performs the access, the system calls the account data and extracts the operation sequence (step S300), a new real-time feedback loop is added: the operation sequence data is input into the model, and the behavior probability distribution is updated; the first and second abnormal results in the authentication stage (step S600) are fused to reflect the new data in real time. For example, when the user operation sequence appears a pattern that is not seen in history, the online SVM adjusts the probability model parameters to reduce the false detection rate. The group anomaly management strategy is used to share the learning signal and improve the global adaptability. This makes the anomaly detection maintain high precision in a dynamic environment, improves the response ability of the system to unknown threats, and strengthens the creativity and forward-looking of data access security control.

[0084] Embodiment two, based on the same inventive concept as the data access security control method based on dynamic strategy linkage in the foregoing embodiments, as shown in the figure, the application provides a data access security control system based on dynamic strategy linkage. The system and method embodiments in the application are based on the same inventive concept. Wherein, the system comprises: Figure 2 As shown in the figure, the application provides a data access security control system based on dynamic strategy linkage. The system and method embodiments in the application are based on the same inventive concept. Wherein, the system comprises: The data perception set establishment module 10 is configured to activate the perception layer to perform data perception after receiving the data access request of the user, and establish a data perception set, wherein the data perception set comprises environmental risk perception, access data sensitivity perception, user historical behavior and authentication perception.

[0085] The access strategy configuration module 20 is configured to calculate an access risk value according to the data perception set, and configure the access strategy of the user based on the access risk value.

[0086] The behavior information entropy calculation module 30 is configured to call the account data of the user after the user performs the access, extract the operation sequence of the user access according to the account data, convert the operation sequence into a behavior probability distribution, and calculate the behavior information entropy.

[0087] The first abnormal result establishment module 40 is configured to construct a behavior probability model using the operation sequence and operation task, measure the unexpectedness of the time sequence access operation using the behavior probability model, and establish a first abnormal result.

[0088] The second abnormal result establishment module 50 is configured to call a calibration access behavior according to the access task of the user, measure the abnormality of the time sequence access operation using the calibration access behavior, and establish a second abnormal result.

[0089] The security control strategy generation module 60 is configured to perform global-local fusion authentication using the behavior information entropy, the first abnormal result and the second abnormal result, and generate a security control strategy.

[0090] Further, the system is also used to realize the following functions: The activation operation monitoring instruction is used to perform operation monitoring of the user, to establish an operation data set, the operation data set including keyboard key pressure, typing impact energy, mouse movement speed, acceleration, click pressure, mouse wheel impact, touch feature set; the operation data set is used to perform energy conversion to establish an energy conversion result; the energy conversion result is used to perform autoregressive analysis of energy events to establish a first time sequence feature; the energy conversion result is used to perform energy-behavior coupling feature analysis to establish a second time sequence feature; the energy conversion result is used to perform adaptive sliding window energy stability analysis to establish a third time sequence feature; the first time sequence feature, the second time sequence feature, and the third time sequence feature are used to establish an energy anomaly; based on the energy anomaly, the behavior information entropy, the first anomaly result, and the second anomaly result, global-local fusion authentication is performed to generate a security control strategy.

[0091] Further, the system is also used to implement the following functions: The energy anomaly, the behavior information entropy, the first anomaly result, and the second anomaly result are normalized to the same dimension; the energy anomaly, the behavior information entropy, the first anomaly result, and the second anomaly result in the same dimension are subjected to causal correlation authentication, and the global-local fusion authentication is completed using the causal correlation authentication result.

[0092] Further, the system is also used to implement the following functions: Risk calculation is performed on each perception dimension in the data perception set to generate a local risk score set, each risk score in the local risk score set being provided with a confidence identifier; data interaction influence analysis is performed on multi-dimensional perception data in the data perception set to establish an interaction correlation factor; the interaction correlation factor is used to perform local risk score set interaction influence fusion under the confidence identifier to establish an access risk value.

[0093] Further, the system is also used to implement the following functions: Abnormal behavior intention recognition of the user is performed according to the behavior information entropy, the first anomaly result, and the second anomaly result to establish an intention task set; a virtual test task is created using the intention task set, the virtual test task being sorted by initial confidence of the intention task set; after a random factor is configured based on the initial confidence sorting, random test insertion of the virtual test task is performed, wherein the random test insertion is a test insertion in a normal equivalent template; operation feedback of the user is obtained, and the security control strategy is corrected according to the operation feedback.

[0094] Further, the system is also used to implement the following functions: According to the security control strategy, the permission space of the user is reconstructed, and an environment warning of the access environment is established; after adjusting the permission of the user based on the permission space, the environment warning is used for warning.

[0095] Further, the system is also used to realize the following functions: The abnormal behavior of the user is extracted, and an abnormal behavior feature is established; the risk intention of the user is obtained, and a global dynamic linkage recognition signal is established according to the abnormal behavior feature and the risk intention; the global user verification is performed by using the global dynamic linkage recognition signal, and a group abnormality management strategy is established.

[0096] Further, the system is also used to realize the following functions: It is judged whether the access risk value meets the access threshold value; if the access risk value meets the access threshold value, the access strategy of the user is configured based on the access risk value; if the access risk value does not meet the access threshold value, the access rejection instruction is executed, and an abnormal access warning is generated.

[0097] Further, the system is also used to realize the following functions: The security control strategy is updated to the user account of the user, and the account level of the user account is updated; the data access security management is performed according to the updated user account.

[0098] It should be noted that the above-mentioned sequence of the embodiments of the present application is only for description, and does not represent the advantages and disadvantages of the embodiments. And the above describes the specific embodiments of the present application. In addition, the processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multi-task processing and parallel processing are also possible or can be advantageous.

[0099] The above only describes the preferred embodiments of the present application, and does not limit the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.

[0100] The present application is only an exemplary description of the present application, and should be considered to cover any and all modifications, changes, combinations or equivalents within the scope of the present application. Obviously, those skilled in the art can make various modifications and changes to the present application without departing from the scope of the present application. Thus, if these modifications and changes of the present application belong to the scope of the present application and its equivalents, the present application intends to include these modifications and changes.

Claims

1. A data access security control method based on dynamic policy linkage, characterized in that, The method includes: After receiving a user's data access request, the perception layer is activated to perform data perception and establish a data perception set, which includes environmental risk perception, access data sensitivity perception, user historical behavior and authentication perception. Calculate the access risk value based on the data awareness set, and configure the user's access policy based on the access risk value; After a user performs an access operation, the user's account data is retrieved, and the operation sequence of the user's access operation is extracted based on the account data. The operation sequence is then transformed into a behavioral probability distribution, and the behavioral information entropy is calculated. A behavioral probability model is constructed using the operation sequence and operation task. The unexpectedness of the time-series access operation is measured using the behavioral probability model, and a first abnormal result is established. Based on the user's access task, the access behavior is called with a label, and the abnormality of the time-series access operation is measured using the label access behavior to establish a second abnormal result. Global-local fusion authentication is performed using the behavioral information entropy, the first abnormal result, and the second abnormal result to generate a security control strategy.

2. The data access security control method based on dynamic policy linkage as described in claim 1, characterized in that, The step of performing global-local fusion authentication using the behavioral information entropy, the first abnormal result, and the second abnormal result to generate a security control strategy includes: Activate the operation monitoring command, use the operation monitoring command to perform user operation monitoring, and establish an operation dataset. The operation dataset includes keyboard key pressure, typing impact energy, mouse movement speed, acceleration, click pressure, mouse wheel impact, and touch feature set. Perform energy conversion on the aforementioned operational dataset and establish the energy conversion results; Autoregressive analysis of energy events is performed using the energy conversion results to establish the first time-series characteristics; Energy-behavior coupling feature analysis is performed using the energy conversion results to establish a second time-series feature; The energy conversion results are used to perform energy stability analysis using an adaptive sliding window to establish a third time series feature; An energy anomaly is established based on the first time-series feature, the second time-series feature, and the third time-series feature; Based on the energy anomaly, the behavioral information entropy, the first anomaly result, and the second anomaly result, a global-local fusion authentication is performed to generate a security control strategy.

3. The data access security control method based on dynamic policy linkage as described in claim 2, characterized in that, The step of performing global-local fusion authentication based on the energy anomaly, the behavioral information entropy, the first anomaly result, and the second anomaly result to generate a security control strategy includes: Normalize the energy anomaly, the behavioral information entropy, the first anomaly result, and the second anomaly result to the same dimension; Perform causal correlation authentication on the energy anomaly, the behavioral information entropy, the first anomaly result, and the second anomaly result under the same dimension, and use the causal correlation authentication results to complete the global-local fusion authentication.

4. The data access security control method based on dynamic policy linkage as described in claim 1, characterized in that, The step of calculating an access risk value based on the data awareness set and configuring a user's access policy based on the access risk value includes: Risk calculation is performed on each perception dimension of the data perception set to generate a local risk score set, and each risk score in the local risk score set is set with a confidence level identifier. Data interaction impact analysis is performed on the multidimensional sensing data in the data sensing set to establish interaction correlation factors; The interaction and correlation factors are used to perform local risk score set interaction and influence fusion under the confidence level identifier to establish access risk value.

5. The data access security control method based on dynamic policy linkage as described in claim 1, characterized in that, After generating the security control policy, the following are included: Based on the behavioral information entropy, the first abnormal result, and the second abnormal result, the user's abnormal behavioral intent is identified, and an intent task set is established. Virtual test tasks are created using the intent task set, and the virtual test tasks are sorted by the initial confidence level of the intent task set; After configuring a random factor based on the initial confidence ranking, random test insertion is performed for the virtual test task, wherein the random test insertion is a test insertion in the normal equivalent template; Obtain user feedback and adjust the security control strategy based on the feedback.

6. The data access security control method based on dynamic policy linkage as described in claim 1, characterized in that, After generating the security control policy, the following is also included: The user's permission space is reconstructed according to the security control policy, and an environment early warning system for the access environment is established. After adjusting user permissions based on the aforementioned permission space, an early warning is issued based on the environmental alert.

7. The data access security control method based on dynamic policy linkage as described in claim 1, characterized in that, After generating the security control policy, the following is also included: Extract abnormal behavior from the user and establish abnormal behavior features; Obtain the user's risk intent, and establish a global dynamic linkage identification signal based on the abnormal behavior characteristics and the risk intent; Global user verification is performed using global dynamic linkage identification signals to establish a group anomaly management strategy.

8. The data access security control method based on dynamic policy linkage as described in claim 1, characterized in that, The step of calculating the access risk value based on the data-aware set includes: Determine whether the access risk value meets the access threshold; If the access risk value meets the access threshold, then the user's access policy is configured based on the access risk value; If the access risk value does not meet the access threshold, an access denial instruction is executed, and an abnormal access warning is generated.

9. The data access security control method based on dynamic policy linkage as described in claim 1, characterized in that, After generating the security control policy, the following is also included: Update the security control policy to the user's user account and update the user account's account level; Data access security management is based on the updated user accounts.

10. A data access security control system based on dynamic strategy linkage, characterized in that, The system is used to implement the data access security control method based on dynamic policy linkage as described in any one of claims 1-9, and the system includes: The data perception set establishment module is used to activate the perception layer to perform data perception and establish a data perception set after receiving a user's data access request. The data perception set includes environmental risk perception, access data sensitivity perception, user historical behavior and authentication perception. The access policy configuration module is used to calculate the access risk value based on the data awareness set and configure the user's access policy based on the access risk value. The behavior information entropy calculation module is used to call the user's account data after the user performs an access, extract the operation sequence of the user's access based on the account data, convert the operation sequence into a behavior probability distribution, and calculate the behavior information entropy. The first abnormal result establishment module is used to construct a behavior probability model using the operation sequence and operation task, use the behavior probability model to measure the unexpectedness of the time-series access operation, and establish the first abnormal result. The second abnormal result establishment module is used to call the marked access behavior according to the user's access task, use the marked access behavior to measure the abnormality of the time-series access operation, and establish the second abnormal result. The security control policy generation module is used to perform global-local fusion authentication using the behavioral information entropy, the first abnormal result, and the second abnormal result to generate a security control policy.

Citation Information

Patent Citations

  • Privacy protection-oriented trusted data space access control method and system

    CN120257251A

  • User behavior intelligent analysis and management system based on big data technology

    CN120316448A

  • Self-adaptive data security management and risk early warning system based on intelligent analysis under cloud platform

    CN120358082A

  • System and method for unauthorized activity detection

    US20210152555A1

  • Operation and maintenance processing method, and terminal device

    WO2023159994A1

Cited By

  • Data element access control method, device and system

    CN122339856A