A data access security control method and system based on dynamic policy linkage

By establishing a data awareness set, calculating access risk values, and constructing a behavioral probability model, global-local fusion authentication is performed to generate dynamic security control strategies. This solves the problem of insufficient precision in traditional data access security control and achieves precise security control over complex and ever-changing environments and user behaviors.

CN120979752BActive Publication Date: 2026-05-26GUANGDONG QINGYUN INFORMATION TECH CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
GUANGDONG QINGYUN INFORMATION TECH CO LTD
Filing Date
2025-08-27
Publication Date
2026-05-26

AI Technical Summary

Technical Problem

Traditional data access security control methods rely on static policies, which are difficult to cope with complex and ever-changing access environments and user behaviors. This results in insufficient accuracy in identifying abnormal access behaviors and inadequate adaptability and effectiveness of security control policies.

Method used

By establishing a data-aware set, calculating access risk values, constructing a behavioral probability model to measure unexpectedness and anomalies, performing global-local fusion authentication, generating dynamic security control strategies, and combining operational monitoring and energy conversion analysis, precise security control can be achieved.

Benefits of technology

It enables precise security control over data access, improves the security and reliability of data access, and adapts to complex and ever-changing access environments and user behaviors.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120979752B_ABST
    Figure CN120979752B_ABST
Patent Text Reader

Abstract

The application discloses a kind of data access security control method and system based on dynamic strategy linkage, it is related to data access security technical field, the method includes: after receiving the data access request of user, establish data perception set;According to the data perception set, calculate access risk value, configure the access strategy of user;When user executes access, call the account data of user, convert operation sequence into behavior probability distribution, calculate behavior information entropy;Build behavior probability model, establish first abnormal result;Abnormality measurement is carried out to time sequence access operation using calibration access behavior, establish second abnormal result;Security control strategy is generated.The application solves the technical problem that data access security control is not accurate enough in the prior art, leading to insufficient data access security and reliability, achieves precise security control of data access, and improves the technical effect of data access security and reliability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data access security technology, specifically to a data access security control method and system based on dynamic policy linkage. Background Technology

[0002] In the field of data access security, traditional security control methods often rely on static policies, which are difficult to cope with complex and ever-changing access environments and user behaviors. These methods typically rely on a single-dimensional risk assessment for access control, lacking a comprehensive perception and dynamic linkage of multiple factors such as environmental risks, data sensitivity, and user historical behavior. This results in inaccurate identification of abnormal access behavior, insufficient adaptability and effectiveness of security control strategies, and an inability to meet the ever-increasing demands for data security protection.

[0003] Existing technologies suffer from insufficient precision in data access security control, leading to inadequate data access security and reliability. Summary of the Invention

[0004] This application provides a data access security control method and system based on dynamic policy linkage, which is used to address the technical problem that the data access security control in the prior art is not precise enough, resulting in insufficient data access security and reliability.

[0005] In view of the above problems, this application provides a data access security control method and system based on dynamic policy linkage.

[0006] A first aspect of this application provides a data access security control method based on dynamic policy linkage, the method comprising:

[0007] Upon receiving a user's data access request, the perception layer is activated to perform data perception and establish a data perception set, which includes environmental risk perception, access data sensitivity perception, user historical behavior, and authentication perception. An access risk value is calculated based on the data perception set, and the user's access policy is configured based on the access risk value. When the user performs an access operation, the user's account data is retrieved, and the user's access operation sequence is extracted from the account data. The operation sequence is transformed into a behavior probability distribution, and behavior information entropy is calculated. A behavior probability model is constructed using the operation sequence and operation tasks, and the unexpectedness of the time-series access operation is measured using the behavior probability model to establish a first abnormal result. A calibrated access behavior is invoked based on the user's access task, and the abnormality of the time-series access operation is measured using the calibrated access behavior to establish a second abnormal result. Global-local fusion authentication is performed using the behavior information entropy, the first abnormal result, and the second abnormal result to generate a security control policy.

[0008] A second aspect of this application provides a data access security control system based on dynamic policy linkage, the system comprising:

[0009] The system comprises the following modules: a data perception set establishment module, which activates the perception layer to perform data perception and establish a data perception set upon receiving a user's data access request. The data perception set includes environmental risk perception, access data sensitivity perception, user historical behavior, and authentication perception. An access policy configuration module calculates an access risk value based on the data perception set and configures the user's access policy based on the access risk value. A behavior information entropy calculation module retrieves the user's account data after the user performs an access operation, extracts the user's access operation sequence from the account data, converts the operation sequence into a behavior probability distribution, and calculates the behavior information entropy. A first abnormal result establishment module constructs a behavior probability model using the operation sequence and operation task, uses the behavior probability model to measure the unexpectedness of time-series access operations, and establishes a first abnormal result. A second abnormal result establishment module performs a calibrated access behavior call based on the user's access task, uses the calibrated access behavior to measure the abnormality of time-series access operations, and establishes a second abnormal result. A security control policy generation module performs global-local fusion authentication using the behavior information entropy, the first abnormal result, and the second abnormal result to generate a security control policy.

[0010] One or more technical solutions provided in this application have at least the following technical effects or advantages:

[0011] Upon receiving a user's data access request, the perception layer is activated to perform data perception and establish a data perception set. An access risk value is calculated based on the data perception set, and the user's access policy is configured based on this risk value. When the user performs access, the user's account data is retrieved, and the operation sequence is transformed into a behavioral probability distribution, calculating the behavioral information entropy. A behavioral probability model is constructed using the operation sequence and task, and this model is used to measure the unexpectedness of time-series access operations, establishing a first abnormal result. Based on the user's access task, a calibrated access behavior is invoked, and the calibrated access behavior is used to measure the abnormality of time-series access operations, establishing a second abnormal result. Global-local fusion authentication is performed to generate a security control policy. This achieves precise security control of data access, improving the security and reliability of data access. Attached Figure Description

[0012] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0013] Figure 1 A schematic diagram of a data access security control method based on dynamic policy linkage provided in this application embodiment;

[0014] Figure 2 This is a schematic diagram of a data access security control system structure based on dynamic policy linkage, provided as an embodiment of this application.

[0015] Explanation of reference numerals in the attached diagram: Data awareness set establishment module 10, access policy configuration module 20, behavior information entropy calculation module 30, first abnormal result establishment module 40, second abnormal result establishment module 50, security control policy generation module 60. Detailed Implementation

[0016] This application provides a data access security control method and system based on dynamic policy linkage, which addresses the technical problem that insufficient precision in data access security control in the prior art leads to inadequate data access security and reliability.

[0017] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application.

[0018] Example 1, as Figure 1 As shown, this application provides a data access security control method based on dynamic policy linkage, the method comprising:

[0019] Step S100: After receiving the user's data access request, activate the perception layer to perform data perception and establish a data perception set, which includes environmental risk perception, access data sensitivity perception, user historical behavior and authentication perception.

[0020] Specifically, upon receiving a user's data access request, the perception layer is immediately activated to perform data perception operations. This layer collects and analyzes information from multiple aspects to establish a data perception set. Specifically, environmental risk perception identifies and assesses risks related to the network environment and device status during the user's access; access data sensitivity perception judges the sensitivity level and confidentiality of the requested data; user history behavior perception retrieves and analyzes past access records and operational habits; and authentication perception focuses on the user's authentication status, including authentication method, authentication timeliness, and authentication result. By integrating these four aspects of information, a complete data perception set is ultimately formed, encompassing environmental risk perception, access data sensitivity perception, user history behavior, and authentication perception, providing foundational data support for subsequent access risk assessment and strategy configuration.

[0021] Step S200: Calculate the access risk value based on the data awareness set, and configure the user's access policy based on the access risk value.

[0022] Specifically, when calculating the access risk value based on the established data perception set, the risk is first calculated for each perception dimension in the data perception set, including environmental risk perception, access data sensitivity perception, user historical behavior, and authentication perception, generating a local risk score set containing risk scores for each dimension, with each score bearing a confidence level indicator. Next, data interaction impact analysis is performed on the multi-dimensional perception data in the data perception set to determine interaction correlation factors. Then, these interaction correlation factors are used to fuse the interaction impact of the local risk score set under the confidence level indicator to obtain the access risk value. When configuring a user's access policy based on this access risk value, it is first determined whether the access risk value meets the access threshold. If it does, the corresponding access policy is configured; otherwise, an access denial command is executed, and an abnormal access warning is generated.

[0023] Step S300: After the user performs the access, the user's account data is called, the operation sequence of the user's access is extracted according to the account data, the operation sequence is converted into a behavior probability distribution, and the behavior information entropy is calculated.

[0024] Specifically, after a user performs an access operation, the user's account data is retrieved to extract the complete operation sequence during the access process, covering all kinds of interactive actions taken by the user. This operation sequence is then transformed into a behavioral probability distribution. By statistically analyzing the frequency and probability characteristics of different operations in the sequence, the behavioral information entropy reflecting the uncertainty of the user's overall behavioral pattern is calculated. This allows for a global analysis of the regularity and abnormal tendencies of the user's access behavior, providing a global behavioral feature basis for subsequent security authentication.

[0025] Step S400: Construct a behavioral probability model using the operation sequence and operation task, use the behavioral probability model to measure the unexpectedness of the time-series access operation, and establish a first abnormal result.

[0026] Specifically, based on the extracted user access operation sequence and corresponding operation tasks, a behavioral probability model is constructed that reflects the correlation between the operation probabilities of each step under a specific operation task. This model focuses on the probability distribution and transformation rules of each local link in the operation sequence. Subsequently, this model is used to measure the unexpectedness of the time-series access operation step by step. By comparing the difference between the actual operation and the normal operation probability predicted by the model, abnormal points that deviate from the expectations in local operation links are identified. Then, these local abnormal information are integrated to establish the first abnormal result, providing a basis for subsequent security authentication from a local level.

[0027] Step S500: Based on the user's access task, perform a labeled access behavior invocation, use the labeled access behavior to measure the anomaly of the time-series access operation, and establish a second anomaly result.

[0028] Specifically, based on the user's current access task, the system invokes the corresponding calibrated access behaviors. These calibrated access behaviors are based on the pre-defined standardized behavior patterns of the standard operating procedures for similar tasks. Subsequently, the user's actual sequential access operations are compared step by step with the calibrated access behaviors. By analyzing the matching degree between the two at local operation stages, the system measures the degree of anomaly in specific steps of the actual operation, such as deviations in the operation sequence, missing or redundant key operations, etc. Based on these local anomaly measurement results, a second anomaly result is integrated to provide another dimension of local anomaly analysis basis for subsequent security authentication.

[0029] Step S600: Perform global-local fusion authentication using the behavioral information entropy, the first abnormal result, and the second abnormal result to generate a security control strategy.

[0030] Specifically, when generating a security control policy using global-local fusion authentication based on behavioral information entropy, the first abnormal result, and the second abnormal result, the process first activates operation monitoring commands to monitor user operations and establishes an operation dataset containing keyboard key pressure, input impact energy, mouse movement speed, acceleration, click pressure, mouse wheel impact, and touch feature sets. The operation dataset undergoes energy conversion to obtain energy conversion results, which are then used for autoregressive analysis of energy events, energy-behavior coupling feature analysis, and adaptive sliding window energy stability analysis to establish first, second, and third temporal features, thereby establishing energy anomalies. Subsequently, the energy anomalies, behavioral information entropy, the first abnormal result, and the second abnormal result are normalized to the same dimension for causal association authentication under the same dimension. The authentication results are used to complete global-local fusion authentication, ultimately generating a security control policy. After generating the security control policy, the system further identifies abnormal user behavior intentions based on behavioral information entropy, the first abnormal result, and the second abnormal result, corrects the policy, reconstructs the user permission space and provides environmental warnings, extracts abnormal user behavior features to establish global dynamic linkage identification signals for global user verification, and updates the user account's security control policy and account level.

[0031] In one possible implementation, step S600 further includes:

[0032] Step S610: Activate the operation monitoring command, use the operation monitoring command to perform user operation monitoring, and establish an operation dataset. The operation dataset includes keyboard key pressure, typing impact energy, mouse movement speed, acceleration, click pressure, mouse wheel impact, and touch feature set.

[0033] Step S620: Perform energy conversion on the operation dataset and establish the energy conversion result.

[0034] Step S630: Use the energy conversion results to perform autoregressive analysis of energy events and establish the first time series features.

[0035] Step S640: Utilize the energy conversion results to perform energy-behavior coupling feature analysis and establish a second time series feature.

[0036] Step S650: Use the energy conversion results to perform an adaptive sliding window energy stability analysis and establish a third time series feature.

[0037] Step S660: Establish an energy anomaly based on the first time series feature, the second time series feature, and the third time series feature.

[0038] Step S670: Perform global-local fusion authentication based on the energy anomaly, the behavioral information entropy, the first anomaly result, and the second anomaly result to generate a security control strategy.

[0039] Specifically, an operation monitoring command is activated to monitor various user actions during data access in real time and comprehensively. During monitoring, the system accurately collects information such as key pressure and impact energy generated when typing, mouse movement speed, acceleration, click pressure, mouse wheel impact, and touch operation-related feature sets. This multi-dimensional operation data is then integrated and summarized to construct an operation dataset containing the above information, providing fundamental data support for subsequent energy conversion and anomaly analysis.

[0040] For the established operation dataset, various operation parameters are converted and processed using a preset energy conversion algorithm. The relevant parameters in the keyboard key pressure, typing impact energy, mouse movement speed, acceleration, click pressure, mouse wheel impact, and touch feature set are uniformly converted into quantifiable energy values ​​according to their respective physical energy conversion models, forming an energy conversion result that covers the energy characteristics of each operation link, and realizing the mapping of operation data to energy dimension data.

[0041] When performing autoregressive analysis of energy events using energy conversion results, the energy values ​​in the energy conversion results are first sorted by time series to form a continuous energy event sequence. Then, an autoregressive model is constructed, with the energy value at the current moment as the dependent variable and the energy values ​​at several time points before this moment as independent variables. The model parameters are solved using the least squares method to determine the autocorrelation relationship of energy events in time series. Based on this model, the trend and fluctuation pattern of energy events over time are analyzed, and characteristic parameters that can reflect the time series dependence of energy events, such as autoregressive coefficients and residual variance, are extracted. Then, the first time series feature is established to depict the dynamic change pattern of energy events in the time dimension.

[0042] When performing energy-behavior coupling feature analysis using energy conversion results, each energy value in the energy conversion results is first bound to its corresponding operation behavior (such as keyboard key press, mouse click, scroll wheel operation, touch action, etc.) according to the timestamp, forming a related dataset containing "behavior type-occurrence time-energy value". Then, the dataset is segmented by a sliding time window, and the Pearson correlation coefficient between energy value and behavior frequency is calculated in each window to measure the degree of linear correlation between the two. At the same time, the energy peak and key behavior nodes in the window are extracted, such as the time difference between the start / end time of the operation, to construct temporal co-operation features. Then, the coupling degree index is calculated by combining the transition probability of the behavior sequence and the rate of change of the energy sequence. By combining the correlation coefficient, temporal co-operation features and coupling degree index, parameters that can reflect the dynamic correlation between energy and behavior are extracted to establish the second temporal feature.

[0043] When performing energy stability analysis using adaptive sliding windows based on energy conversion results, the size of the sliding window is dynamically adjusted according to the magnitude of energy value changes in the energy conversion results. When energy fluctuations are drastic, the window is reduced to capture instantaneous changes, and when energy tends to stabilize, the window is increased to reflect the overall trend. Subsequently, within each adaptively adjusted window, the mean, variance, standard deviation, and coefficient of variation of the energy values ​​are calculated to measure the concentration and dispersion of energy within the window. By tracking the above indicators of continuous windows over time, the changing patterns of energy stability are analyzed, and characteristic parameters that can reflect the stability of energy fluctuations under different windows are extracted. In this way, a third time-series feature is established to depict the dynamic stability characteristics of energy in the time dimension.

[0044] When establishing energy anomalies based on the first, second, and third time-series features, normal threshold ranges are first set for each of the three time-series features. The normal threshold for the first time-series feature is determined based on the parameter range of the normal time-series dependency characteristics in the autoregressive analysis of energy events. The normal threshold for the second time-series feature is defined based on the normal degree of synergy between energy and behavior. The normal threshold for the third time-series feature is set with reference to the common range of stable fluctuations of energy under different windows. Subsequently, the actual extracted first, second, and third time-series features are compared with their corresponding normal threshold ranges to identify anomalous features that exceed the threshold ranges. Finally, the frequency of occurrence, degree of deviation, and interrelationship of these anomalous features are combined to determine whether there are anomalies at the energy level. If so, they are integrated to form energy anomalies, thereby reflecting the abnormal changes in operational energy during data access.

[0045] When generating security control strategies based on global-local fusion authentication using energy anomalies, behavioral information entropy, first anomaly results, and second anomaly results, these four types of indicators are first normalized to the same dimension to eliminate measurement differences between different indicators. Then, causal correlation authentication is performed on the four types of indicators under the same dimension. The correlation between energy anomalies and the global behavioral uncertainty reflected by behavioral information entropy is analyzed, as well as the mutual influence between local operational anomalies reflected by the first and second anomaly results and energy anomalies and global behavioral characteristics. Through this cross-validation and correlation analysis at the global level (overall characteristics of behavioral information entropy and energy anomalies) and the local level (specific operational anomalies of the first and second anomaly results), fusion authentication is completed, and finally, a security control strategy adapted to the current access scenario is generated.

[0046] In one possible implementation, step S670 further includes:

[0047] Step S671: Normalize the energy anomaly, the behavioral information entropy, the first anomaly result, and the second anomaly result to the same dimension.

[0048] Step S672: Perform causal correlation authentication of the energy anomaly, the behavioral information entropy, the first anomaly result, and the second anomaly result under the same dimension, and use the causal correlation authentication results to complete the global-local fusion authentication.

[0049] Specifically, for energy anomalies, behavioral information entropy, first anomaly results, and second anomaly results, a standardization method is used to normalize them to the same dimension. By setting a unified numerical mapping range, the original values ​​of various indicators are converted into this range proportionally, eliminating the incomparability caused by differences in measurement methods and numerical ranges among different indicators. This ensures that the degree of energy-level anomaly reflected by energy anomalies, the global behavioral uncertainty reflected by behavioral information entropy, and the measurement of local operational anomalies presented by first and second anomaly results are consistent in numerical scale, providing a unified standard analytical basis for subsequent causal correlation verification.

[0050] When performing causal association verification on energy anomalies, behavioral information entropy, the first anomalous outcome, and the second anomalous outcome under the same dimension, the Granger causality test is used to analyze the causal relationship of the four factors in their temporal changes. The significance of the lag terms is used to determine the direction and degree of influence between variables. Simultaneously, a Bayesian network model is used to construct a probabilistic association graph of the four factors, quantifying the conditional probability distribution between different anomaly indicators and clarifying the correlation strength between global-level behavioral characteristics and local-level operational anomalies along the influence path. Based on these analytical results, the global-level analytical conclusions and local-level anomaly information are weighted and fused. By setting an association threshold, feature combinations with significant causal relationships are selected to complete the global-local fusion verification, enabling the verification results to comprehensively reflect both overall behavioral security and the details of local operational anomalies.

[0051] In one possible implementation, step S600 further includes:

[0052] Based on the behavioral information entropy, the first abnormal result, and the second abnormal result, the user's abnormal behavioral intent is identified, and an intent task set is established.

[0053] Virtual test tasks are created using the intent task set, and the virtual test tasks are sorted by the initial confidence level of the intent task set.

[0054] After configuring a random factor based on the initial confidence ranking, random test insertion is performed for the virtual test task, wherein the random test insertion is a test insertion in the normal equivalent template.

[0055] Obtain user feedback and adjust the security control strategy based on the feedback.

[0056] Specifically, a Bi-LSTM-Attention network based on an attention mechanism is used to identify user abnormal behavior intentions: the behavioral information entropy, the first abnormal result, and the second abnormal result are used as sequence features input into the model. The BiLSTM layer captures the temporal dependency relationship among the three, and the attention mechanism is used to give higher weights to key features to highlight abnormal correlations. The model output layer combines a softmax classifier to map the features to preset abnormal intention categories (such as unauthorized access, data tampering, etc.). The classification results are then organized according to the intention category, and corresponding behavioral feature descriptions and risk levels are added to form a structured intention task set.

[0057] When creating virtual test tasks using an established intent task set, the intent tasks are first sorted from high to low based on the initial confidence level of each abnormal behavior intent in the intent task set, so that the virtual test tasks corresponding to intents with high confidence levels have higher priority. Then, based on the sorting results, a matching virtual test task is generated for each intent task. These virtual test tasks can simulate the operation scenarios and data access requests that the corresponding abnormal behavior intent may involve, and finally form a sequence of virtual test tasks sorted by initial confidence level.

[0058] After determining the priority of virtual test tasks based on the initial confidence ranking of the intent task set, a corresponding random factor is configured for each virtual test task. This random factor is used to regulate the timing and frequency of test insertion. Subsequently, the random insertion operation of virtual test tasks is performed in normal equivalent templates. These normal equivalent templates are consistent with normal data access scenarios and operation processes. The inserted virtual test tasks not only conform to the characteristics of normal operations, but also implicitly contain test points corresponding to abnormal behavior intentions. Thus, the covert detection of abnormal user behavior is achieved without affecting the user's normal operating experience.

[0059] By monitoring users' actions in real time when facing virtual testing tasks, operational feedback data is collected, including operation paths, response times, and command execution accuracy. This feedback data is then analyzed in multiple dimensions to determine the degree of matching between user operations and abnormal behavioral intentions, and to identify potential misjudgments or oversights in security control strategies. Based on the analysis results, targeted adjustments are made to the parameter thresholds and anomaly identification rules of the security control strategies, such as optimizing risk scoring weights and revising abnormal behavior judgment criteria, so that the security control strategies can more accurately adapt to users' actual behavioral patterns and improve the effectiveness of data access security control.

[0060] In one possible implementation, step S600 further includes:

[0061] The user's permission space is reconstructed according to the security control policy, and an environment early warning system for the access environment is established.

[0062] After adjusting user permissions based on the aforementioned permission space, an early warning is issued based on the environmental alert.

[0063] Specifically, based on the user access permissions and security level classifications in the security control strategy, the user permission space is reconstructed, clarifying the data categories, operation scope, and permission validity periods that each user can access, ensuring that permission allocation is accurately matched with security control requirements. At the same time, comprehensive monitoring is conducted on the network environment, device status, and data transmission links involved in data access, and environmental risk indicator thresholds are set. When the monitored indicators exceed the thresholds, an early warning mechanism is triggered, thereby establishing an environmental early warning system for the access environment.

[0064] After adjusting user permissions based on the restructured permission space to ensure that users can only access data within their authorized scope, the system continuously monitors various indicators of the access environment. When the environment early warning mechanism detects anomalies in the access environment, such as potential network threats, unstable device operation, or risks in data transmission links, it immediately reports the warning information to relevant security administrators or system administrators according to preset warning rules and notification methods, so that timely measures can be taken to address the security risks.

[0065] In one possible implementation, step S600 further includes:

[0066] Abnormal behavior is extracted from the user, and abnormal behavior features are established.

[0067] Obtain the user's risk intent, and establish a global dynamic linkage identification signal based on the abnormal behavior characteristics and the risk intent.

[0068] Global user verification is performed using global dynamic linkage identification signals to establish a group anomaly management strategy.

[0069] Specifically, the system monitors and records user behavior during data access in real time, filtering out operations that deviate from normal behavior patterns from multiple dimensions such as operation sequence, access frequency, and data interaction methods. Examples include sudden batch data downloads, access to unauthorized data areas, and sensitive operations during unusual time periods. Features of these abnormal operations are extracted, including key information such as operation type, sensitivity level of the data involved, execution duration, and operation path. These features are then integrated into structured abnormal behavior characteristics to accurately characterize users' abnormal behavior patterns.

[0070] By constructing a risk intent reasoning model to obtain users' risk intent, the abnormal behavior characteristics of users are matched with a preset risk intent tag library. Combined with the context of the behavior, such as access time and data type involved, the probability distribution of different risk intents is calculated through a Bayesian network to determine the user's most likely risk intent. Subsequently, a feature fusion algorithm is used to weight and concatenate the abnormal behavior feature vector and the risk intent probability vector. Principal component analysis is used to extract key linkage features to generate a global dynamic linkage identification signal that includes the strength and temporal variation of the behavior-intent association.

[0071] A distributed user authentication architecture is adopted, using global dynamic linkage identification signals as the authentication benchmark. Distributed nodes perform parallel comparisons of the behavioral characteristics and risk intentions of all users in the system to calculate the matching degree between user behavior and signal characteristics. Density clustering algorithm is used to divide users with matching degree into groups to identify user clusters with similar abnormal patterns. Differentiated management strategies are formulated based on the abnormal characteristics of different clusters and the risk level, including collective reduction of cluster permissions, real-time synchronization and auditing of operation logs, and trigger-based secondary authentication. The management rules are pushed to each access control node through the policy engine to achieve dynamic control of group anomalies.

[0072] In one possible implementation, step S600 further includes:

[0073] Update the security control policy to the user's user account and update the user account's account level.

[0074] Data access security management is based on the updated user accounts.

[0075] Specifically, the generated security control policies will be synchronously updated to the user's account, enabling the account to perform data access-related permission management and security control according to the new policies. At the same time, the user's account level will be adjusted according to factors such as user behavior and risk level. For example, the account level of users with low risk and compliant behavior will be appropriately increased, while the account level of users with abnormal behavior and high risk will be decreased.

[0076] Based on the updated user account information, full-process security management is implemented for user data access behavior: combining the account's current security control policy and account level, data access requests initiated by users are reviewed in real time, and their operations are strictly restricted to the authorized scope; at the same time, user access operations are continuously monitored, operation logs are recorded and compared with the account's historical behavior patterns, and once abnormal behavior deviating from the normal range is detected, the corresponding security response mechanism is immediately triggered, such as suspending access and secondary verification, so as to ensure the security and compliance of data access.

[0077] In one possible implementation, step S200 further includes:

[0078] Step S210: Perform risk calculation on each perception dimension of the data perception set to generate a local risk score set, wherein each risk score in the local risk score set is set with a confidence level identifier.

[0079] Step S220: Perform data interaction impact analysis on the multidimensional sensing data in the data sensing set and establish interaction correlation factors.

[0080] Step S230: Utilize the interactive correlation factor to perform local risk score set interaction influence fusion under the confidence level identifier to establish an access risk value.

[0081] Specifically, when calculating risk for each perception dimension in the data perception set, the random forest algorithm is used. First, a training dataset containing historical risk cases, feature variables, and corresponding risk levels is constructed for each perception dimension. The dataset is then trained using a random forest model, leveraging the ensemble learning capability of multiple decision trees to capture the nonlinear relationship between features and risk within the perception dimension. Subsequently, real-time data from each perception dimension is input into the trained model, which outputs the risk probability distribution for the corresponding dimension. The risk value corresponding to the peak of the distribution is taken as the risk score for that dimension, and these are aggregated to form a local risk score set. Simultaneously, the prediction accuracy and variance of the model in cross-validation are calculated, and the weighted result of the accuracy and variance is used as the confidence indicator for each risk score, thereby quantifying the reliability of the score.

[0082] A graph neural network is used to analyze the interaction effects of multidimensional sensory data in a data perception set. Each sensory dimension is treated as a node, and initial association edges are constructed by calculating the feature similarity between nodes. The graph neural network model is used to iteratively update the node features and edge weights to learn the potential interaction patterns between different sensory dimensions. Attention mechanism is introduced to enable the model to automatically assign weights to different interaction relationships. Finally, the node association strength matrix output by the model is transformed into a quantified interaction association factor, thereby accurately capturing the dynamic interaction effects between multidimensional sensory data.

[0083] A weighted fusion algorithm is adopted to perform interactive influence fusion on the local risk score set with confidence labels using interactive correlation factors. First, the interactive correlation factors are used as the influence weight matrix between risk scores of different perception dimensions. Then, the confidence labels of each risk score are converted into weight coefficients in the range of 0-1. The access risk value is calculated by the formula: Access Risk Value = Σ(Local Risk Score × Confidence Weight × Σ(Interactive Correlation Factor × Other Dimension Risk Scores × Corresponding Confidence Weight)). Taking into account the interaction of risks in each dimension and their own reliability, the access risk value reflecting the overall risk is finally obtained.

[0084] In one possible implementation, step S200 further includes:

[0085] Step S240: Determine whether the access risk value meets the access threshold.

[0086] Step S250: If the access risk value meets the access threshold, then configure the user's access policy based on the access risk value.

[0087] Step S260: If the access risk value does not meet the access threshold, execute the access denial instruction and generate an abnormal access warning.

[0088] Specifically, the calculated access risk value is compared with the preset access threshold. By comparing the magnitudes of the two values, it is determined whether the access risk value is within an acceptable range, i.e., whether it meets the access threshold requirements. This serves as the key basis for subsequent processing of user access requests.

[0089] When the access risk value meets the preset access threshold, an appropriate access policy will be configured for the user based on the specific magnitude of the access risk value. For example, if the risk value is at a low level, the user will be given a wider range of data access and fewer restrictions; if the risk value is at a medium level, the access range will be appropriately narrowed and some necessary verification steps will be added. Through this dynamic adjustment based on the risk value, it is ensured that the user's access behavior meets both security requirements and their reasonable data usage needs.

[0090] When it is determined that the access risk value has not reached the preset access threshold, an access denial instruction will be immediately issued to the user to prevent them from continuing to perform data access operations. At the same time, an abnormal access warning will be automatically generated, which includes the access time, access terminal information, the specific value of the risk value and the reason for not reaching the threshold, so as to promptly know and intervene to verify potential security risks.

[0091] In some possible implementations, the above embodiments, upon receiving a user data access request, establish a data perception set (such as environmental risk perception and user historical behavior) by activating the perception layer, and calculate an access risk value based on this set to configure access policies. However, the data perception set may be affected by noise, conflicts, or environmental interference (such as misinterpretation of environmental risks due to network latency). The above embodiments only process local risk scores through confidence level indicators, but do not systematically handle overall uncertainty. This may lead to deviations in risk value calculation, resulting in incorrect configuration of access policies and reduced accuracy of security control. For example, in a dynamic network environment, instantaneous fluctuations in perception data may not be effectively smoothed, causing high-risk users to be mistakenly authorized or low-risk users to be overly restricted.

[0092] To address this deficiency, an embodiment is proposed that introduces a data uncertainty model into the original system access policy configuration module to enhance the robustness of risk calculation. This embodiment adds a Bayesian uncertainty inference layer based on the local risk score set and interactive correlation factors described above. Specifically, after step 200, a new uncertainty assessment sub-step is added: using multidimensional data (such as environmental risk perception and authentication perception) from the data perception set, a Gaussian process model is constructed to simulate the perception noise distribution; multiple risk score copies are generated through Monte Carlo sampling, and a weighted average risk value is calculated by combining the confidence level identifier. This effectively quantifies uncertainty and introduces a dynamic compensation mechanism in the risk value calculation.

[0093] In practice, when calculating the access risk value, the original interaction impact fusion is performed first (step S230), followed by uncertainty assessment. For example, when environmental risk perception data fluctuates due to network interference, the model automatically identifies abnormal confidence indicators and adjusts the weights of interaction correlation factors. Simultaneously, the system incorporates uncertainty indicators (such as variance) into the access policy configuration. When uncertainty exceeds a threshold, additional authentication steps (such as a denial of access command) are triggered. Ultimately, this improves the accuracy of the risk value in noisy environments, ensures more reliable access policies, reduces mismatch risks, and enhances overall security.

[0094] In some possible implementations, the above embodiments utilize operation sequences and tasks to construct a behavioral probability model, establish a first anomaly result (based on unexpectedness measurement), and combine it with calibrated access behavior to establish a second anomaly result (based on anomaly measurement) for global-local fusion authentication. However, this model is primarily trained on historical user behavior data and does not integrate an online learning mechanism. When encountering new attack patterns or user behavior drift (such as zero-day vulnerabilities or changes in compliance behavior), the model cannot be updated in real time, leading to missed detections (such as new types of data tampering not being identified) or false positives (such as normal operations being misjudged). Therefore, it is possible that model updates are only indirectly corrected through security control strategies, but without embedding adaptability into the core anomaly measurement step.

[0095] To address this deficiency, the solution in this embodiment integrates an online learning and adaptive model update framework to directly enhance the behavioral probability model. Incremental learning components are added to the original first abnormal result establishment module (step S400) and second abnormal result establishment module (step S500): the behavioral probability model employs an online support vector machine (SVM) or deep learning architecture to absorb new operation sequence data in real time; the model is updated based on the rate of change of behavioral information entropy, and automatically retrains the probability distribution when the entropy value abruptly changes (e.g., exceeds a threshold). Simultaneously, the calibration access behavior invocation step (step S500) introduces a dynamic calibration library, using intent task sets to generate adaptive calibration templates, simulating emerging behavioral patterns, and strengthening the measurement of abnormality.

[0096] In practice, after a user performs an access operation, when the system retrieves account data and extracts the operation sequence (step S300), a new real-time feedback loop is added: the operation sequence data is streamed into the model to update the behavior probability distribution; the first and second anomaly results from the fusion authentication phase (step S600) reflect the new data in real time. For example, when a user's operation sequence exhibits a pattern not seen in the past, the online SVM adjusts the probability model parameters to reduce the false detection rate. A group anomaly management strategy is used to share learning signals and improve global adaptability. This enables anomaly detection to maintain high accuracy in dynamic environments, enhances the system's responsiveness to unknown threats, and strengthens the creativity and foresight of data access security control.

[0097] Example 2 is based on the same inventive concept as the data access security control method based on dynamic policy linkage in the foregoing examples, such as... Figure 2 As shown, this application provides a data access security control system based on dynamic policy linkage. The system and method embodiments in this application are based on the same inventive concept. The system includes:

[0098] The data perception set establishment module 10 is used to activate the perception layer to perform data perception and establish a data perception set after receiving a user's data access request. The data perception set includes environmental risk perception, access data sensitivity perception, user historical behavior and authentication perception.

[0099] The access policy configuration module 20 is used to calculate the access risk value based on the data awareness set and configure the user's access policy based on the access risk value.

[0100] The behavior information entropy calculation module 30 is used to call the user's account data after the user performs an access, extract the operation sequence of the user's access based on the account data, convert the operation sequence into a behavior probability distribution, and calculate the behavior information entropy.

[0101] The first abnormal result establishment module 40 is used to construct a behavior probability model using the operation sequence and operation task, use the behavior probability model to measure the unexpectedness of the time-series access operation, and establish a first abnormal result.

[0102] The second abnormal result establishment module 50 is used to call the calibrated access behavior according to the user's access task, use the calibrated access behavior to measure the abnormality of the time-series access operation, and establish the second abnormal result.

[0103] The security control policy generation module 60 is used to perform global-local fusion authentication using the behavioral information entropy, the first abnormal result, and the second abnormal result to generate a security control policy.

[0104] Furthermore, the system is also used to implement the following functions:

[0105] Activate the operation monitoring command, and use the operation monitoring command to perform user operation monitoring, establish an operation dataset, the operation dataset including keyboard key pressure, typing impact energy, mouse movement speed, acceleration, click pressure, mouse wheel impact, and touch feature set; perform energy conversion on the operation dataset to establish energy conversion results; use the energy conversion results to perform autoregressive analysis of energy events to establish a first time-series feature; use the energy conversion results to perform energy-behavior coupling feature analysis to establish a second time-series feature; use the energy conversion results to perform energy stability analysis of an adaptive sliding window to establish a third time-series feature; establish energy anomalies based on the first time-series feature, the second time-series feature, and the third time-series feature; perform global-local fusion authentication based on the energy anomaly, the behavior information entropy, the first anomaly result, and the second anomaly result to generate a security control strategy.

[0106] Furthermore, the system is also used to implement the following functions:

[0107] The energy anomaly, the behavioral information entropy, the first anomaly result, and the second anomaly result are normalized to the same dimension; causal association authentication of the energy anomaly, the behavioral information entropy, the first anomaly result, and the second anomaly result under the same dimension is performed, and the global-local fusion authentication is completed using the causal association authentication results.

[0108] Furthermore, the system is also used to implement the following functions:

[0109] Risk calculation is performed on each perception dimension of the data perception set to generate a local risk score set, and each risk score in the local risk score set is assigned a confidence level label; data interaction impact analysis is performed on the multidimensional perception data in the data perception set to establish interaction correlation factors; the interaction correlation factors are used to perform interaction impact fusion of the local risk score set under the confidence level label to establish an access risk value.

[0110] Furthermore, the system is also used to implement the following functions:

[0111] Based on the behavioral information entropy, the first abnormal result, and the second abnormal result, the user's abnormal behavioral intent is identified, and an intent task set is established. Virtual test tasks are created using the intent task set, and these virtual test tasks are sorted by the initial confidence level of the intent task set. After configuring a random factor based on the initial confidence level sorting, random test insertion of the virtual test tasks is performed, wherein the random test insertion is a test insertion within a normal equivalent template. User operation feedback is obtained, and the security control strategy is corrected based on the operation feedback.

[0112] Furthermore, the system is also used to implement the following functions:

[0113] The user's permission space is reconstructed according to the security control strategy, and an environment warning is established for the access environment; after adjusting the user's permissions based on the permission space, an early warning is issued based on the environment warning.

[0114] Furthermore, the system is also used to implement the following functions:

[0115] Abnormal behavior is extracted from the user to establish abnormal behavior features; the user's risk intent is obtained, and a global dynamic linkage identification signal is established based on the abnormal behavior features and the risk intent; the global dynamic linkage identification signal is used to perform global user verification and establish a group abnormality management strategy.

[0116] Furthermore, the system is also used to implement the following functions:

[0117] Determine whether the access risk value meets the access threshold; if the access risk value meets the access threshold, configure the user's access policy based on the access risk value; if the access risk value does not meet the access threshold, execute an access denial instruction and generate an abnormal access warning.

[0118] Furthermore, the system is also used to implement the following functions:

[0119] Update the security control policy to the user's account and update the user's account level; perform data access security management based on the updated user account.

[0120] It should be noted that the order of the embodiments described above is merely for descriptive purposes and does not represent the superiority or inferiority of the embodiments. Furthermore, the above description focuses on specific embodiments of this specification. Additionally, the processes depicted in the accompanying drawings do not necessarily require a specific or sequential order to achieve the desired results. In some implementations, multitasking and parallel processing are possible or may be advantageous.

[0121] The above description is only a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the protection scope of this application.

[0122] This specification and accompanying drawings are merely illustrative examples of this application and are intended to cover any and all modifications, variations, combinations, or equivalents within the scope of this application. Clearly, those skilled in the art can make various alterations and modifications to this application without departing from its scope. Therefore, if such modifications and variations fall within the scope of this application and its equivalents, this application intends to include such modifications and variations.

Claims

1. A data access security control method based on dynamic policy linkage, characterized in that, The method includes: After receiving a user's data access request, the perception layer is activated to perform data perception and establish a data perception set, which includes environmental risk perception, access data sensitivity perception, user historical behavior and authentication perception. Calculate the access risk value based on the data awareness set, and configure the user's access policy based on the access risk value; After a user performs an access operation, the user's account data is retrieved, and the operation sequence of the user's access operation is extracted based on the account data. The operation sequence is then transformed into a behavioral probability distribution, and the behavioral information entropy is calculated. A behavioral probability model is constructed using the operation sequence and operation task. The unexpectedness of the time-series access operation is measured using the behavioral probability model, and a first abnormal result is established. Based on the user's access task, the access behavior is called with a label, and the abnormality of the time-series access operation is measured using the label access behavior to establish a second abnormal result. Global-local fusion authentication is performed using the behavioral information entropy, the first abnormal result, and the second abnormal result to generate a security control strategy; The step of performing global-local fusion authentication using the behavioral information entropy, the first abnormal result, and the second abnormal result to generate a security control strategy includes: Activate the operation monitoring command, use the operation monitoring command to perform user operation monitoring, and establish an operation dataset. The operation dataset includes keyboard key pressure, typing impact energy, mouse movement speed, acceleration, click pressure, mouse wheel impact, and touch feature set. Perform energy conversion on the aforementioned operational dataset and establish the energy conversion results; Autoregressive analysis of energy events is performed using the energy conversion results to establish the first time-series characteristics; Energy-behavior coupling feature analysis is performed using the energy conversion results to establish a second time-series feature; The energy conversion results are used to perform energy stability analysis using an adaptive sliding window to establish a third time series feature; An energy anomaly is established based on the first time-series feature, the second time-series feature, and the third time-series feature; Based on the energy anomaly, the behavioral information entropy, the first anomaly result, and the second anomaly result, a global-local fusion authentication is performed to generate a security control strategy.

2. The data access security control method based on dynamic policy linkage as described in claim 1, characterized in that, The step of performing global-local fusion authentication based on the energy anomaly, the behavioral information entropy, the first anomaly result, and the second anomaly result to generate a security control strategy includes: Normalize the energy anomaly, the behavioral information entropy, the first anomaly result, and the second anomaly result to the same dimension; Perform causal correlation authentication on the energy anomaly, the behavioral information entropy, the first anomaly result, and the second anomaly result under the same dimension, and use the causal correlation authentication results to complete the global-local fusion authentication.

3. The data access security control method based on dynamic policy linkage as described in claim 1, characterized in that, The step of calculating an access risk value based on the data awareness set and configuring a user's access policy based on the access risk value includes: Risk calculation is performed on each perception dimension of the data perception set to generate a local risk score set, and each risk score in the local risk score set is set with a confidence level identifier. Data interaction impact analysis is performed on the multidimensional sensing data in the data sensing set to establish interaction correlation factors; The interaction and correlation factors are used to perform local risk score set interaction and influence fusion under the confidence level identifier to establish access risk value.

4. The data access security control method based on dynamic policy linkage as described in claim 1, characterized in that, After generating the security control policy, the following are included: Based on the behavioral information entropy, the first abnormal result, and the second abnormal result, the user's abnormal behavioral intent is identified, and an intent task set is established. Virtual test tasks are created using the intent task set, and the virtual test tasks are sorted by the initial confidence level of the intent task set; After configuring a random factor based on the initial confidence ranking, random test insertion is performed for the virtual test task, wherein the random test insertion is a test insertion in the normal equivalent template; Obtain user feedback and adjust the security control strategy based on the feedback.

5. The data access security control method based on dynamic policy linkage as described in claim 1, characterized in that, After generating the security control policy, the following is also included: The user's permission space is reconstructed according to the security control policy, and an environment early warning system for the access environment is established. After adjusting user permissions based on the aforementioned permission space, an early warning is issued based on the environmental alert.

6. The data access security control method based on dynamic policy linkage as described in claim 1, characterized in that, After generating the security control policy, the following is also included: Extract abnormal behavior from the user and establish abnormal behavior features; Obtain the user's risk intent, and establish a global dynamic linkage identification signal based on the abnormal behavior characteristics and the risk intent; Global user verification is performed using global dynamic linkage identification signals to establish a group anomaly management strategy.

7. The data access security control method based on dynamic policy linkage as described in claim 1, characterized in that, The step of calculating the access risk value based on the data-aware set includes: Determine whether the access risk value meets the access threshold; If the access risk value meets the access threshold, then the user's access policy is configured based on the access risk value; If the access risk value does not meet the access threshold, an access denial instruction is executed, and an abnormal access warning is generated.

8. The data access security control method based on dynamic policy linkage as described in claim 1, characterized in that, After generating the security control policy, the following is also included: Update the security control policy to the user's user account and update the user account's account level; Data access security management is based on the updated user accounts.

9. A data access security control system based on dynamic policy linkage, characterized in that, The system is used to implement the data access security control method based on dynamic policy linkage as described in any one of claims 1-8, and the system includes: The data perception set establishment module is used to activate the perception layer to perform data perception and establish a data perception set after receiving a user's data access request. The data perception set includes environmental risk perception, access data sensitivity perception, user historical behavior and authentication perception. The access policy configuration module is used to calculate the access risk value based on the data awareness set and configure the user's access policy based on the access risk value. The behavior information entropy calculation module is used to call the user's account data after the user performs an access, extract the operation sequence of the user's access based on the account data, convert the operation sequence into a behavior probability distribution, and calculate the behavior information entropy. The first abnormal result establishment module is used to construct a behavior probability model using the operation sequence and operation task, use the behavior probability model to measure the unexpectedness of the time-series access operation, and establish the first abnormal result. The second abnormal result establishment module is used to call the marked access behavior according to the user's access task, use the marked access behavior to measure the abnormality of the time-series access operation, and establish the second abnormal result. The security control strategy generation module is used to perform global-local fusion authentication using the energy anomaly, the behavioral information entropy, the first anomaly result, and the second anomaly result to generate a security control strategy.