A resource security information data processing method, system, terminal and medium
By combining multi-factor authentication and virtualized resource isolation mechanisms with real-time data encryption and collaborative verification, the problem of insufficient dynamic monitoring of behavior and identification of abnormal operations in existing resource security management systems is solved, achieving highly accurate and reliable access control and security interception.
Patent Information
- Application Number
- CN202511509236.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-22
- Publication Date
- 2025-12-30
- Estimated Expiration
- 2045-10-22
AI Technical Summary
In existing technologies, resource security management systems suffer from a lack of dynamic monitoring of behavior, weak ability to identify abnormal operations, and insufficient collaborative verification mechanisms during the granting of permissions and execution of operations. This makes it difficult to effectively prevent risks such as internal unauthorized access, account impersonation, or covert malicious modification.
It employs multi-factor authentication combined with virtualization resource isolation mechanisms, monitors interactive behavior in real time, encrypts data in real time by analyzing tenant identity information and operation characteristics, and enables delayed confirmation and collaborative verification mechanisms when abnormal operations are detected, making comprehensive decisions based on permission levels and physical location context.
Significantly improves the precision of access control and the accuracy of security interception, effectively prevents account impersonation, unauthorized operations and covert malicious modifications, reduces the risk of false blocking and abuse of permissions, and improves the continuity of identity verification and the scientific nature of collaborative approval.
Smart Images

Figure CN120995438B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of resource security management technology, and in particular to a resource security information data processing method, system, terminal and medium. Background Technology
[0002] In modern enterprise information and cloud computing environments, resource security information data processing technology is the core support for ensuring the isolation of resources and the security of data between different tenants.
[0003] In related technologies, resource security management systems are typically based on static identity authentication mechanisms. After a user submits an access or file operation request, the system verifies account credentials and permission policies, grants the corresponding operation permissions, and performs basic encryption transmission of data.
[0004] Regarding the aforementioned technologies, there are issues such as a lack of dynamic monitoring of behavior, weak ability to identify abnormal operations, and insufficient collaborative verification mechanisms during the granting of permissions and execution of operations. This makes it difficult for the system to effectively prevent risks such as internal unauthorized access, account impersonation, or covert malicious modification. Summary of the Invention
[0005] To ensure the isolation of resources and the security of data between different tenants, this application provides a resource security information data processing method, system, terminal, and medium.
[0006] In a first aspect, this application provides a method for processing resource security information data, which adopts the following technical solution:
[0007] A method for processing resource security information data, comprising:
[0008] Receive registration requests submitted by tenant terminals;
[0009] Based on the registration request, the tenant terminal undergoes first authentication to generate access permissions;
[0010] Based on the registration request, a dedicated virtualization resource pool is allocated to the tenant terminal in the virtualization environment;
[0011] In response to the access request submitted by the tenant terminal, obtain the access permission;
[0012] Based on the access permissions, a second authentication is performed on the tenant terminal to obtain the authentication result;
[0013] When the authentication result indicates that the authentication is successful, in response to the file operation instruction, the target data is encrypted to obtain encrypted data;
[0014] The encrypted data is transmitted via data transfer, which includes uploading the encrypted data to the dedicated virtualization resource pool and downloading the encrypted data from the dedicated virtualization resource pool to the tenant terminal.
[0015] By employing the above technical solutions, this approach analyzes tenant identity information and operational behavior characteristics, combines virtualization resource isolation mechanisms to construct a secure environment, utilizes multi-factor authentication to ensure trusted access, and encrypts data and monitors interactive behavior in real time during file operations. This solution significantly improves the accuracy of access control, effectively preventing account impersonation, unauthorized operations, and covert malicious modifications.
[0016] Optionally, interactive behavior data can be collected in real time, including mouse movement trajectory characteristics, mouse click frequency, and keyboard input delay interval.
[0017] The interaction behavior data is compared with historical operation behavior to generate a similarity score;
[0018] Based on the similarity score, it is determined whether the current operation behavior matches the tenant terminal operation behavior;
[0019] If not, the file operation instruction is interrupted and execution is refused.
[0020] By employing the aforementioned technical solution, user interaction data such as mouse movement trajectory, click frequency, and keyboard input latency are collected in real time. This data is then compared with model data to generate a behavior similarity score, which is used to determine the credibility of the operator's identity. This solution significantly improves the persistence and accuracy of identity verification, effectively identifying abnormal behaviors such as account impersonation and unauthorized operations, and intercepting high-risk file operations.
[0021] Optionally, a delay mechanism is enabled, and an operation confirmation request message is pushed to the first authorized user terminal with the highest access rights. The operation confirmation request message is used to ask whether to continue executing the file operation instruction.
[0022] Within the preset response waiting time, receive the job-level feedback result from the first authorized user terminal;
[0023] If the received job level feedback result is ambiguous, the operation confirmation request message is pushed to a second authorized user terminal located within a preset geographical location range of the tenant terminal to obtain the location feedback result;
[0024] Based on the job level feedback result and the location feedback result, determine whether to allow the continued execution of the file operation instruction according to preset rules;
[0025] If not allowed, the file operation command will be interrupted.
[0026] By adopting the above technical solution, a delayed confirmation mechanism is activated when abnormal operations are detected. Priority is given to soliciting the operational intent from high-privilege users, and if there are discrepancies in the feedback, further collaborative confirmation is initiated with geographically nearby authorized users. A comprehensive decision is made by combining permission levels and physical location context. This solution significantly improves the accuracy and rationality of security interception, effectively identifies legitimate proxy operations, temporary collaborations, and other real business scenarios, and reduces the risks of false blocking and permission abuse.
[0027] Optionally, a time-based feedback result axis is established, which is divided into a first time threshold interval and a second time threshold interval, wherein the first time threshold interval is earlier than the second time threshold interval.
[0028] According to the feedback result axis, the location feedback result is divided into a first location feedback result and a second location feedback result. The first location feedback result includes a first approval feedback result and a first disapproval feedback result. The second location feedback result includes a second approval feedback result and a second disapproval feedback result. The first location feedback result is received within the first time threshold interval, and the second location feedback result is received within the second time threshold interval.
[0029] Count the total number of first feedback results from the first location;
[0030] Count the number of first sub-feedbacks of the first positive feedback result;
[0031] The ratio is obtained based on the first total feedback quantity and the first sub-feedback quantity;
[0032] If the ratio is higher than the consistency threshold, and the proportion of the first sub-feedback quantity to the preset total feedback quantity exceeds the first quantity threshold, then the first approval feedback result is taken as the preset rule.
[0033] If the ratio is lower than the consensus threshold, a second majority feedback result is determined from the second approval feedback result and the second disapproval feedback result;
[0034] If the second majority feedback result is the second approval feedback result, and the proportion of the second approval feedback result to the preset total number of feedback results is not less than the second quantity threshold, then the second approval feedback result shall be used as the preset rule.
[0035] By adopting the above technical solution, a time-based feedback result axis is established to perform phased analysis of early and subsequent user confirmation feedback. The operational intent is determined by combining the feedback consistency ratio and quantity coverage. This solution significantly improves the scientific rigor and reliability of collaborative approvals, reducing false interceptions caused by scattered or delayed feedback.
[0036] Optionally, receive modification requests for target files submitted by the tenant terminal;
[0037] Obtain the access control policy of the target file, wherein the access control policy includes multiple authorized user identifiers associated with the target file;
[0038] The modification request is pushed to the user terminals corresponding to the multiple authorized user identifiers, and a voting timer is activated;
[0039] During the timing period of the voting timer, the voting intention of the user terminal is received;
[0040] Determine whether the number of votes received agreeing to modify the target file meets the voting threshold;
[0041] If so, grant file modification permissions to the tenant terminal.
[0042] By adopting the above technical solution, the permission relationships of the target file are obtained, modification requests are pushed to all relevant authorized users, and voting opinions are collected within a limited time. The decision on whether to authorize modification is made based on the majority opinion. This solution significantly improves the transparency and collaboration of file modification approval, effectively avoids the risks caused by unauthorized or accidental operations, and reduces security risks caused by the concentration of power.
[0043] Optionally, monitor modifications to the target file and obtain the modified content data;
[0044] The content data is analyzed to obtain analysis results, which include at least one of the following: whether sensitive fields have been modified, whether there is unauthorized operation, or abnormal data changes.
[0045] Detect whether the user interface operation behavior of the tenant terminal on the target file meets the abnormal operation mode, the abnormal operation mode includes the number of page switching times per unit time exceeding a first threshold or the single page dwell time being less than a second threshold;
[0046] If the conditions are met, based on the analysis results, determine whether there is any malicious modification.
[0047] If so, generate a warning signal.
[0048] By employing the above technical solution, file modifications are monitored in real time to identify whether sensitive information has been altered or abnormal data changes have occurred. Simultaneously, by combining this with user behavior analysis, it identifies suspicious operation patterns such as frequent page switching and excessively short dwell times. This solution significantly improves the identification of malicious modification activities, effectively distinguishes between normal modifications and covert sabotage, and reduces data risks caused by accidental operations or internal attacks.
[0049] Optionally, a switching page is obtained, wherein the switching page includes a first switching page and a second switching page;
[0050] Based on the differences between the first and second switching pages, the difference results are obtained;
[0051] Based on the user interface operation behavior and the difference results, an operation sequence for switching pages is generated. The operation sequence includes multiple page switching events recorded in chronological order. Each page switching event includes a switching time, an entry page identifier, an exit page identifier, and a page dwell time.
[0052] Match the operation sequence with the abnormal operation pattern;
[0053] If a match is found, proceed to the step of determining whether malicious modification exists based on the analysis results.
[0054] By employing the above technical solution, the complete process of user page switching is recorded, and the time, source, target, and duration of each switch are extracted. Combined with the content differences between pages, an ordered sequence of operational behaviors is generated and then matched against abnormal patterns. This solution significantly improves the ability to identify covert operational behaviors, effectively detects suspicious actions such as frequent jumps and brief pauses, and reduces the risk of missed detections due to fragmented behavior.
[0055] Secondly, this application provides a resource security information data processing system, which adopts the following technical solution:
[0056] A resource security information data processing system, comprising:
[0057] The acquisition module is used to obtain registration requests, access requests, and access permissions;
[0058] A memory for storing the program of the resource security information data processing method;
[0059] The processor and the program in the memory can be loaded and executed by the processor to implement the resource security information data processing method.
[0060] By adopting the above technical solution, the acquisition module collects tenant registration requests, access requests and permission information in real time. The processor calls the security processing program pre-stored in the memory to perform security operations such as identity verification, behavior analysis, collaborative decision-making and encrypted transmission. This realizes closed-loop control of the entire process from user access to file operation. While ensuring data security and operational reliability, it provides an efficient and reliable integrated solution for resource security management in a multi-tenant environment.
[0061] Thirdly, this application provides a smart terminal, which adopts the following technical solution:
[0062] A smart terminal includes a memory and a processor, wherein the memory stores a computer program that can be loaded by the processor and execute the method described in any of the above-mentioned embodiments.
[0063] Fourthly, this application provides a computer storage medium capable of storing corresponding programs, which facilitates the isolation of resources and the security of data between different tenants, and adopts the following technical solution:
[0064] A computer-readable storage medium storing a computer program that can be loaded by a processor and executed by any of the above-described resource security information data processing methods.
[0065] In summary, this application includes at least one of the following beneficial technical effects:
[0066] 1. By analyzing tenant identity information and operational behavior characteristics, and combining this with virtualization resource isolation mechanisms, a secure environment is constructed. Multi-factor authentication is used to ensure trusted access, and data is encrypted and interactive behavior is monitored in real time during file operations. This solution significantly improves the accuracy of access control and effectively prevents account impersonation, unauthorized operations, and covert malicious modifications.
[0067] 2. Upon detecting abnormal operations, a delayed confirmation mechanism is activated. Priority is given to soliciting the operational intent from high-privilege users, and if discrepancies exist in the feedback, further collaborative confirmation is initiated with geographically proximate authorized users. A comprehensive decision is made based on a combination of permission levels and physical location context. This solution significantly improves the accuracy and rationality of security interception, effectively identifying legitimate proxy operations, temporary collaborations, and other real-world business scenarios, reducing the risk of false blocking and permission abuse.
[0068] 3. Establish a time-based feedback result axis to conduct phased analysis of early and subsequent user confirmation feedback, and determine operational intent by combining the feedback consistency ratio and quantity coverage. This solution significantly improves the scientific rigor and reliability of collaborative approval, and reduces false interceptions caused by scattered or delayed feedback. Attached Figure Description
[0069] Figure 1This is a flowchart illustrating a resource security information data processing method provided in an embodiment of this application.
[0070] Figure 2 This is a flowchart illustrating a behavioral feature-based authentication method provided in an embodiment of this application.
[0071] Figure 3 This is a flowchart illustrating a collaborative confirmation method based on permissions and location provided in an embodiment of this application.
[0072] Figure 4 This is a flowchart illustrating a time-segmented feedback decision-making method provided in an embodiment of this application.
[0073] Figure 5 This is a flowchart illustrating a document authorization method based on collaborative voting, as provided in an embodiment of this application.
[0074] Figure 6 This is a flowchart illustrating a content- and behavior-based file modification method provided in an embodiment of this application.
[0075] Figure 7 This is a flowchart illustrating an anomaly detection method based on page switching behavior provided in an embodiment of this application.
[0076] Figure 8 This is a schematic diagram of the structure of a resource security information data processing system provided in an embodiment of this application. Detailed Implementation
[0077] To make the purpose, technical solution, and advantages of this application clearer, the following description is provided in conjunction with the appendix. Figures 1 to 8 The present application will be further described in detail below with reference to embodiments. It should be understood that the specific embodiments described herein are for illustrative purposes only and are not intended to limit the scope of the application.
[0078] This application discloses a method for processing resource security information data. (Refer to...) Figure 1 The method includes:
[0079] Step S101: Receive the registration request submitted by the tenant terminal.
[0080] Before receiving a registration request, the virtualization environment must be initialized and its basic parameters configured. The virtualization environment includes at least one of the following: virtualized server, storage space, and network configuration.
[0081] A registration request is a data packet containing identity information sent by a tenant terminal to the backend server when it first accesses the system.
[0082] For example, an employee of Company A uses their personal office computer to access the system, fills in basic information such as name, employee number, and department, and submits a registration request. The system backend receives the employee's registration request.
[0083] Step S102: Based on the registration request, perform the first authentication on the tenant terminal and generate access permissions.
[0084] First-level identity verification refers to the initial identity verification performed by the user during the registration phase.
[0085] Access permissions refer to the scope of operations granted based on a user's identity or role, including accessible data resources, types of operations that can be performed, and functional modules that can be used. Operation types include viewing, editing, and deleting.
[0086] Based on the user's identity information in the registration request, combined with their department and job level, the corresponding resource access scope and operation permissions are assigned, and the access permissions for the tenant's terminal are generated.
[0087] Step S103: Based on the registration request, allocate a dedicated virtualization resource pool to the tenant terminal in the virtualization environment.
[0088] A virtualized environment refers to a logically isolated operating environment built using virtualization technology.
[0089] A dedicated virtualization resource pool refers to a collection of virtual resources that are allocated separately for a specific tenant.
[0090] Based on the tenant's department and business type in the registration request, independent computing, storage, and network resources are allocated according to the preset resource configuration to form a logically isolated dedicated virtualization resource pool and bind it to the tenant's terminal.
[0091] For example, when a tenant registers, their department is the finance department, and this information is allocated independent storage space and network channel, configured with 2 CPU cores and 4GB of memory.
[0092] Step S104: In response to the access request submitted by the tenant terminal, obtain access permissions.
[0093] An access request is a data access or operation request initiated by a tenant to the system after completing registration and obtaining permissions.
[0094] Access permissions refer to the scope of operable resources pre-assigned based on the tenant's identity.
[0095] Step S105: Perform a second authentication on the tenant terminal based on access permissions and obtain the authentication result.
[0096] Secondary authentication refers to the identity verification performed again when a tenant logs into the system.
[0097] The authentication result refers to the output of the second authentication process, including two states: pass and fail.
[0098] Based on access permissions, the verification method is triggered. After the user completes the SMS verification code input or fingerprint recognition, the verification information is compared, and a result indicating successful identity verification is generated after confirmation that the information is correct.
[0099] Step S106: When the authentication result indicates that the authentication is successful, in response to the file operation instruction, the target data is encrypted to obtain encrypted data.
[0100] File operation commands refer to specific data processing commands initiated by the tenant, including operations such as editing, saving, deleting, uploading, and downloading.
[0101] Target data refers to the specific data objects involved in the tenant's current operation, such as a document, database record, and configuration file.
[0102] Encryption processing refers to encrypting target data using an encryption algorithm, making the target data unreadable without authorization. Here, the AES-256 encryption algorithm is used to encrypt the target data in blocks, and a unique session key is used for encryption transformation to generate unreadable ciphertext data, thus completing the encryption process.
[0103] Encrypted data refers to data that has been encrypted; the original content has been converted into ciphertext and needs to be decrypted using the corresponding decryption key.
[0104] Step S107: Perform data transmission operations on the encrypted data. The data transmission operations include uploading the encrypted data to the dedicated virtualization resource pool and downloading the encrypted data from the dedicated virtualization resource pool to the tenant terminal.
[0105] Data transmission refers to the process of transmitting encrypted data between the tenant's terminal and the dedicated virtualization resource pool.
[0106] The system continuously runs security check scripts in the background, regularly reviews the system's health status, and sends reports to relevant personnel. If any anomalies are found, measures are taken to isolate the affected areas and notify relevant tenant personnel.
[0107] By employing the above technical solutions, analyzing tenant identity information and operational behavior characteristics, and combining this with a virtualization resource isolation mechanism to construct a secure environment, multi-factor authentication ensures trusted access, and real-time data encryption and monitoring of interactive behavior occur during file operations. This solution significantly improves the accuracy of access control and effectively prevents account impersonation, unauthorized operations, and covert malicious modifications.
[0108] This application discloses an identity verification method based on behavioral characteristics. (Refer to...) Figure 2 The method includes:
[0109] Step S201: Collect interactive behavior data in real time. The interactive behavior data includes mouse movement trajectory characteristics, mouse click frequency, and keyboard input delay interval.
[0110] Interactive behavior data refers to behavioral information generated during user operations on the system interface of a tenant's terminal. The interactive behavior data involved in this application was collected with the tenant's consent, and the collection complies with relevant laws and regulations.
[0111] For example, during the process of editing a document, the system can record in real time the arc of the mouse trajectory from the title bar to the toolbar, the frequency of clicking the save button, and the interval between typing adjacent characters on the keyboard.
[0112] Step S202: Compare the interaction behavior data with historical operation behavior to generate a similarity score.
[0113] Historical operational behavior refers to the collection of interaction behavior data accumulated by the same user during normal use of the system in the past.
[0114] Similarity score is a quantitative value obtained by matching interactive behavior data with historical operation behavior, indicating the degree of consistency between the current operator's behavior pattern and the current operator's historical behavior.
[0115] The trajectory similarity score is obtained by calculating the difference between the current average mouse movement speed and the data from the user's past 30 normal logins; the click behavior score is obtained by comparing the current click frequency with the historical click frequency; the keystroke score is obtained by comparing the delay interval sequence of adjacent characters input on the keyboard with the historical records; finally, the similarity score between 0 and 100 is generated by weighting the trajectory (40%), click (20%), and keystroke (40%).
[0116] For example, during the user's current operation, the average mouse movement speed is 320 pixels per second, the click frequency is 48 times per minute, and the interval sequence of adjacent characters input on the keyboard is 180 milliseconds, 210 milliseconds, and 190 milliseconds. By comparing this with the user's historical operation behavior, the weighted similarity score is calculated after calculating various deviations and is thus obtained as 88 points.
[0117] Step S203: Based on the similarity score, determine whether the current operation behavior is consistent with the tenant terminal operation behavior.
[0118] The system compares a similarity score with a preset threshold to determine whether the current operator is a legitimate user of the tenant's terminal. If the score is higher than the threshold, the current operation is considered to be consistent with the tenant's terminal operation behavior; if the score is lower than the threshold, the current operation is considered to be inconsistent with the tenant's terminal operation behavior, and there may be a risk of account impersonation or operation by someone other than the user.
[0119] For example, a preset threshold of 85 points is set. The current similarity score is 92 points, which is higher than the threshold. Therefore, the current operation is deemed to conform to Xiao Li's own operating habits, and subsequent operations are allowed to continue. If the score is 76 points, it is deemed not to conform.
[0120] Step S204: If not, interrupt the file operation instruction and refuse to execute the file operation instruction.
[0121] If the current operation is determined to be inconsistent with the tenant's terminal operation behavior, the file operation request that the user is initiating, such as saving, modifying, deleting or uploading, is interrupted.
[0122] Specifically, it will not send file operation instructions, nor will it modify or transmit file content. At the same time, it will return an operation rejection prompt to the user terminal to ensure that the data is not accessed or modified by unauthorized or abnormal behavior.
[0123] By employing the aforementioned technical solution, user interaction data such as mouse movement trajectory, click frequency, and keyboard input latency are collected in real time. This data is then compared with model data to generate a behavior similarity score, which is used to determine the credibility of the operator's identity. This solution significantly improves the persistence and accuracy of identity verification, effectively identifying abnormal behaviors such as account impersonation and unauthorized operations, and intercepting high-risk file operations.
[0124] This application discloses a collaborative confirmation method based on permissions and location. (Refer to...) Figure 3 The method includes:
[0125] Step S301: Enable the delay mechanism and push an operation confirmation request message to the first authorized user terminal with the highest access rights. The operation confirmation request message is used to ask whether to continue executing the file operation command.
[0126] The delay mechanism refers to not immediately interrupting file operation instructions when they do not conform to the tenant's terminal operation behavior, but pausing execution and reserving a period of time to confirm the tenant's terminal operation behavior.
[0127] The highest level of access refers to the user's permissions that grant the highest level of operational control. This user can approve or veto critical operations and typically corresponds to roles such as department heads, system administrators, or project managers.
[0128] The first authorized user terminal refers to the device used by the user with the highest authority, which is pre-defined by the tenant, and is used to receive operation confirmation request messages and make approval decisions.
[0129] An operation confirmation request message is a prompt message sent to the first authorized user terminal. The content usually includes contextual information such as operation type, target file, initiator, and time, and is accompanied by an option to agree or refuse.
[0130] For example, after a user submits an instruction to delete the core database, execution is paused and delayed for 30 seconds. At the same time, a confirmation pop-up is sent to the department head's office computer, asking whether to continue executing the file operation instruction and waiting for approval or rejection.
[0131] Step S302: Within the preset response waiting time, receive the post-level feedback result from the first authorized user terminal.
[0132] The response wait time refers to the time window set for operation confirmation, which is usually 30 seconds to 5 minutes, and the specific duration can be adjusted.
[0133] The feedback result at the job level refers to the decision response made by the first authorized user terminal based on its management responsibilities and authority level, including explicit instructions such as agreeing, refusing, or transferring the matter to others for processing.
[0134] For example, after sending a confirmation request to the department head's terminal, a 2-minute waiting window is started. Before the countdown ends, the head clicks the "agree" or "disagree" button and receives the response as the job level feedback result.
[0135] Step S303: If the received job level feedback result is ambiguous, push an operation confirmation request message to the second authorized user terminal located within the preset geographical location range of the tenant terminal to obtain the location feedback result.
[0136] Ambiguity refers to inconsistent feedback results received from two or more job levels.
[0137] The preset geographical location range refers to the pre-configured physical area range, such as a ten-meter range centered on the tenant's terminal.
[0138] The second authorized user terminal refers to a user terminal within a preset geographical location range.
[0139] Location feedback results refer to the opinions of the second authorized user terminal located within the preset geographical area on the operation confirmation request message.
[0140] For example, if the feedback result received from the job level is determined to be ambiguous, an operation confirmation request message is sent to the second authorized user terminal within a 100-meter range centered on the tenant terminal, and the response is received as the location feedback result.
[0141] Step S304: Based on the job level feedback results and location feedback results, determine whether to allow the continued execution of file operation instructions according to preset rules.
[0142] Preset rules refer to pre-configured decision logic used to comprehensively determine whether to allow the continued execution of file operation instructions.
[0143] Step S305: If not allowed, interrupt the file operation command.
[0144] For example, if both the job level feedback result and the location feedback result fail to meet the confirmation conditions, the file deletion operation will be interrupted and no data modification will be performed.
[0145] By adopting the above technical solution, a delayed confirmation mechanism is activated when abnormal operations are detected. Priority is given to soliciting the operational intent from high-privilege users, and if there are discrepancies in the feedback, further collaborative confirmation is initiated with geographically nearby authorized users. A comprehensive decision is made by combining permission levels and physical location context. This solution significantly improves the accuracy and rationality of security interception, effectively identifies legitimate proxy operations, temporary collaborations, and other real business scenarios, and reduces the risks of false blocking and permission abuse.
[0146] This application discloses a time-segmented feedback decision-making method. (Refer to...) Figure 4 The method includes:
[0147] Step S401: Establish a feedback result axis based on time. The feedback result axis is divided into a first time threshold interval and a second time threshold interval. The first time threshold interval is earlier than the second time threshold interval.
[0148] The feedback result axis refers to the time series coordinates established to collect the responses of the second authorized user terminal to the operation confirmation request message, which is used to record the type and quantity of feedback received in different time periods.
[0149] The first time threshold interval refers to the early time period on the feedback result axis close to the moment the operation was initiated, such as within 0 to 2 minutes after the operation. Feedback within this interval typically reflects the user's immediate judgment of the operation; the faster the response, the higher the credibility.
[0150] The second threshold interval refers to the time period following the first time threshold interval, such as 2 to 5 minutes after the operation. This interval is used to receive delayed responses, supplementing the first time threshold interval.
[0151] For example, after initiating an operation confirmation request message, a timeline is established, with 0 to 2 minutes set as the first time threshold interval and 2 to 5 minutes set as the second time threshold interval, for collecting feedback from the second authorized user terminal in segments.
[0152] Step S402: According to the feedback result axis, the location feedback results are divided into first location feedback results and second location feedback results. The first location feedback results include first approval feedback results and first disapproval feedback results. The second location feedback results include second approval feedback results and second disapproval feedback results. The first location feedback results are received within the first time threshold interval, and the second location feedback results are received within the second time threshold interval.
[0153] The first position feedback result refers to the feedback result received within the first time threshold interval.
[0154] The second position feedback result refers to the feedback result received within the second time threshold interval.
[0155] The first approval feedback result refers to the confirmation response sent by an authorized user located within a preset geographical range within the first time threshold interval, indicating agreement to perform the operation.
[0156] The first denial feedback result refers to the confirmation response sent by an authorized user located within a preset geographical range within the first time threshold interval, indicating a refusal to perform the operation.
[0157] The second approval feedback result refers to the confirmation response sent by an authorized user located within a preset geographical range within the second time threshold interval, indicating agreement to perform the operation.
[0158] The second denial feedback result refers to the confirmation response sent by an authorized user located within a preset geographical range within the second time threshold interval, indicating a refusal to perform the operation.
[0159] Step S403: Count the total number of first feedback results for the first position.
[0160] The first total feedback quantity refers to the total number of all first position feedback results received within the first time threshold interval.
[0161] For example, if feedback is received from 5 authorized personnel on site within 0 to 2 minutes, with 3 agreeing and 2 disagreeing, then the first total number of feedback is 5.
[0162] Step S404: Count the number of first sub-feedbacks of the first positive feedback result.
[0163] The first sub-feedback quantity refers to the number of positive feedback received within the first time threshold interval, i.e., the number of first positive feedback results.
[0164] For example, if 3 out of the 5 people mentioned in the previous example choose "agree", then the number of first feedback is 3.
[0165] Step S405: Obtain the ratio value based on the first total feedback quantity and the first sub-feedback quantity.
[0166] The ratio is the ratio of the number of first sub-feedbacks to the number of first total feedbacks, used to measure the degree of agreement among the first position feedback results.
[0167] For example, the first total feedback number is 5, the first sub-feedback number is 3, and the calculated ratio is 60%.
[0168] Step S406: If the proportion value is higher than the consistency threshold, and the proportion of the number of first sub-feedbacks to the preset total number of feedbacks exceeds the first quantity threshold, then the first approval feedback result is taken as the preset rule.
[0169] The preset total feedback count refers to the total number of feedback collected within the time range covered by the feedback result axis, used to determine whether the current feedback has reached the minimum required sample size.
[0170] Preset rules refer to the criteria determined based on the statistical analysis of feedback results, used to determine whether to allow the continued execution of operation instructions.
[0171] The first quantity threshold refers to the minimum proportion that the number of first sub-feedbacks must reach to reach the preset total number of feedbacks.
[0172] For example, if the consistency threshold is set to 70%, the first quantity threshold is 30%, and the preset total number of feedback is 10, the current proportion of 80% is higher than 70%, which does not meet the condition. Therefore, the first positive feedback result is adopted as the preset rule.
[0173] Step S407: If the proportion is lower than the consistency threshold, determine the second majority feedback result from the second approval feedback result and the second disapproval feedback result.
[0174] The second majority feedback result refers to the side with the larger number of second approval feedback results and second disapproval feedback results within the second time threshold interval.
[0175] For example, if 6 feedbacks are received within 2 to 5 minutes, with 4 people agreeing and 2 people disagreeing, then the second majority feedback result is the second approval feedback result.
[0176] Step S408: If the second majority of feedback results are the second approval feedback results, and the proportion of the second approval feedback results to the preset total number of feedback results is not less than the second quantity threshold, then the second approval feedback results are used as the preset rule.
[0177] The second quantity threshold refers to the minimum proportion of the preset total number of positive feedback results that the second positive feedback result must reach.
[0178] For example, if the second positive feedback result is 4, and the preset total number of feedback is 10, accounting for 40%, which meets the second quantity threshold, then the file operation instruction will continue to be executed.
[0179] By adopting the above technical solution, a time-based feedback result axis is established to perform phased analysis of early and subsequent user confirmation feedback. The operational intent is determined by combining the feedback consistency ratio and quantity coverage. This solution significantly improves the scientific rigor and reliability of collaborative approvals, reducing false interceptions caused by scattered or delayed feedback.
[0180] This application discloses a file authorization method based on collaborative voting. (Refer to...) Figure 5 The method includes:
[0181] Step S501: Receive the modification request for the target file submitted by the tenant terminal.
[0182] The target file refers to the specific data object that the user is currently modifying, such as a document, table, or configuration file.
[0183] A modification request is a user-initiated instruction to edit, update, or adjust a target file, and typically includes information such as the operation type and the request time.
[0184] Step S502: Obtain the access control policy of the target file. The access control policy includes multiple authorized user identifiers associated with the target file.
[0185] Access control policies are permission management rules set for specific files, defining which users have the right to view, edit, or approve the file.
[0186] Multiple authorized user identifiers refer to user identifiers that are explicitly listed in the access control policy and have approval or management permissions for the target file. These users have voting rights in the file modification process.
[0187] Step S503: Push modification requests to user terminals corresponding to multiple authorized user identifiers and enable voting timers.
[0188] A voting timer is a time limit set for this vote. It starts counting from the moment the request is pushed and continues for a certain duration to control the decision-making cycle and avoid indefinite waiting.
[0189] For example, the modification request is sent to the office computers of the finance director, department manager, and audit specialist, while a 10-minute countdown timer for voting is started.
[0190] Step S504: During the timing period of the voting timer, receive the voting intention from the user terminal.
[0191] Voting intention refers to the explicit response made by multiple authorized users to whether they agree to modify the target file. It usually includes options of agreeing, rejecting, or abstaining, and only valid responses are counted.
[0192] For example, if user 1 clicks "agree," user 2 clicks "reject," and user 3 does not respond within an 8-minute timer, then two valid voting intentions are recorded: one "agree" and one "reject."
[0193] Step S505: Determine whether the number of votes received agreeing to modify the target file meets the voting threshold.
[0194] The voting threshold refers to the preset minimum number of people who agree, used to determine whether to approve the modification.
[0195] For example, if the voting threshold is set to require at least two people to agree, but only one person actually agrees, the vote is not passed because the threshold is not met.
[0196] Step S506: If yes, grant file modification permissions to the tenant terminal.
[0197] File modification permissions refer to the temporary granting of edit permissions for a target file to a tenant terminal after a vote is passed, allowing them to perform modification operations. File modification permissions are usually time-limited and are automatically revoked after modification is completed.
[0198] If the number of votes agreeing to modify the target file does not meet the voting threshold, the tenant terminal is not allowed to modify the target file.
[0199] For example, if two out of three authorized users agree to the modification, then the tenant terminal is granted editing permissions for the file, allowing them to make changes. If only one out of the three authorized users agrees to the modification, then the tenant terminal is not allowed to make changes.
[0200] By adopting the above technical solution, the permission relationships of the target file are obtained, modification requests are pushed to all relevant authorized users, and voting opinions are collected within a limited time. The decision on whether to authorize modification is made based on the majority opinion. This solution significantly improves the transparency and collaboration of file modification approval, effectively avoids the risks caused by unauthorized or accidental operations, and reduces security risks caused by the concentration of power.
[0201] This application discloses a method for modifying files based on content and behavior. (Refer to...) Figure 6 The method includes:
[0202] Step S601: Monitor modifications to the target file and obtain the modified content data.
[0203] Content data refers to the information contained in the target file after this modification operation is completed, including the specific content such as modified text, values, or formats.
[0204] When the user clicks save, the system reads the entire current content of the file, records the text, numerical values, and formatting information, compares it with the content of the previous version of the file, identifies the modified parts, and uses them as content data.
[0205] For example, when a user modifies the amount field in a contract file and clicks save, the file's latest content is read, and the modified amount is recorded as the modified content data.
[0206] Step S602: Analyze the content data to obtain analysis results. The analysis results include at least one of the following: whether sensitive fields have been modified, whether there are unauthorized operations, or abnormal data changes.
[0207] The analysis results refer to the judgment information generated after checking the modified content.
[0208] Sensitive fields refer to information fields in a document that involve privacy, security, or critical business information, such as ID card numbers, bank account numbers, and price parameters.
[0209] Abnormal data changes refer to data changes that do not conform to normal business logic, such as a sudden increase of hundreds of times in amount or a jump in status field, which may indicate misoperation or malicious behavior.
[0210] The modified content is compared with the content of the previous version of the file to identify whether it involves sensitive fields such as ID card numbers and bank account numbers. Then, the user permission table is used to determine whether unauthorized fields have been modified. At the same time, the changes in values are checked to see if they exceed the normal business scope, and the analysis results are obtained.
[0211] Step S603: Detect whether the user interface operation behavior of the tenant terminal on the target file meets the abnormal operation mode. The abnormal operation mode includes the number of page switching times per unit time exceeding the first threshold or the single page dwell time being less than the second threshold.
[0212] User interface behavior refers to the sequence of actions a user takes to interact with a file on the interface, such as clicking, scrolling, and switching tabs.
[0213] Abnormal operating patterns refer to behavioral characteristics that do not conform to normal human operating habits.
[0214] Record the time and number of page switches during the tenant's operation, count the switching frequency per unit time, and record the time interval from entering the page to leaving each time. If the number of switches exceeds the preset first threshold or the single stay time is shorter than the preset second threshold, it is determined that the abnormal operation mode is met.
[0215] For example, if a user switches between 25 different worksheets within 5 minutes during the editing process, and the average time spent on each worksheet is less than 2 seconds, it is determined that the abnormal operation mode is met.
[0216] Step S604: If satisfied, determine whether there is malicious modification based on the analysis results.
[0217] Malicious modification refers to having the subjective intent to damage or tamper with data.
[0218] Based on a comprehensive analysis of content analysis results and operational behavior, an assessment is made to determine whether the modifications were intentionally malicious or intended to tamper with data. Only when both content anomalies and behavioral anomalies are present is the modification considered malicious.
[0219] Step S605: If yes, generate a warning signal.
[0220] Warning signals are automatic pop-up messages that appear when suspicious modifications are detected. They are used to alert system administrators to abnormal operations and, if necessary, to lock files or accounts.
[0221] For example, if user E is detected modifying the contract amount and frequently switching pages, it is determined to be malicious modification. A red warning box will pop up on the administrator's computer, prompting "Abnormal modification behavior detected, operator U2025, involving contract number HT2025001, please check immediately."
[0222] By employing the above technical solution, file modifications are monitored in real time to identify whether sensitive information has been altered or abnormal data changes have occurred. Simultaneously, by combining this with user behavior analysis, it identifies suspicious operation patterns such as frequent page switching and excessively short dwell times. This solution significantly improves the identification of malicious modification activities, effectively distinguishes between normal modifications and covert sabotage, and reduces data risks caused by accidental operations or internal attacks.
[0223] This application discloses an anomaly detection method based on page switching behavior. (Refer to...) Figure 7 The method includes:
[0224] Step S701: Obtain the switching page, which includes the first switching page and the second switching page.
[0225] Switching pages refers to the process by which a user jumps from one interface to another during operation. For example, jumping from the customer list to contract management.
[0226] The first page to switch to refers to the page the user is currently leaving, i.e., the page to switch to.
[0227] The second page to switch to refers to the page the user is currently on, i.e., the page they are switching to.
[0228] By listening to the user's page navigation actions on the interface, recording the page they leave and the page they enter each time, the first and second page switching can be obtained.
[0229] Step S702: Based on the differences between the first and second switching pages, obtain the difference results.
[0230] The difference results refer to the differences between the first and second switching pages in terms of function type, data sensitivity level, or access permissions, and are used to determine whether the page jump is abnormal.
[0231] By comparing the function types and data sensitivity of the first and second switching pages, if differences are found in the types or the sensitivity level is increased, it is determined that there is a discrepancy.
[0232] Step S703: Based on the user interface operation behavior and the difference results, generate an operation sequence for switching pages. The operation sequence contains multiple page switching events recorded in chronological order. The page switching events include the switching time, the entry page identifier, the exit page identifier, and the page dwell time.
[0233] An operation sequence refers to an operation record formed by linking the time of each page jump, the page from which the user switches, the page to which the user enters, and how long the user stayed on the previous page in chronological order. This sequence is used to reconstruct the operation trajectory.
[0234] A page switching event refers to the process by which a user jumps from one page to another.
[0235] Step S704: Match the operation sequence with the abnormal operation pattern.
[0236] The number of page switches per unit time in the operation sequence is compared with the first threshold, and the page dwell time is checked to see if it is lower than the second threshold. If one or both of them are met, it is determined to match the abnormal operation mode.
[0237] Step S705: If the match is successful, proceed to the step of determining whether there is malicious modification based on the analysis results.
[0238] For example, if a user switches between 25 pages within 3 minutes, and most of them stay for less than 3 seconds, it is determined to be an abnormal operation pattern. Based on the analysis results, it is determined whether there is malicious modification.
[0239] By employing the above technical solution, the complete process of user page switching is recorded, and the time, source, target, and duration of each switch are extracted. Combined with the content differences between pages, an ordered sequence of operational behaviors is generated and then matched against abnormal patterns. This solution significantly improves the ability to identify covert operational behaviors, effectively detects suspicious actions such as frequent jumps and brief pauses, and reduces the risk of missed detections due to fragmented behavior.
[0240] Based on the same inventive concept, embodiments of this application provide a resource security information data processing system. Please refer to [link / reference needed]. Figure 8 The system includes:
[0241] Module 801 is used to obtain registration requests, access requests, and access permissions.
[0242] Memory 802 is used to store programs for resource security information data processing methods;
[0243] Processor 803: The program in memory can be loaded and executed by the processor and implement resource security information data processing methods.
[0244] By adopting the above technical solution, the acquisition module collects tenant registration requests, access requests and permission information in real time. The processor calls the security processing program pre-stored in the memory to perform security operations such as identity verification, behavior analysis, collaborative decision-making and encrypted transmission. This realizes closed-loop control of the entire process from user access to file operation. While ensuring data security and operational reliability, it provides an efficient and reliable integrated solution for resource security management in a multi-tenant environment.
[0245] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional modules is used as an example. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. The specific working process of the system, device, and unit described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.
[0246] This application provides a computer-readable storage medium storing a computer program that can be loaded by a processor and executed as a resource security information data processing method.
[0247] Computer storage media include, for example, USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, optical disks, and other media that can store program code.
[0248] Based on the same inventive concept, embodiments of this application provide a smart terminal, including a memory and a processor, wherein the memory stores a computer program that can be loaded by the processor and executed as a resource security information data processing method.
[0249] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the above-described division of functional modules is used as an example. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. The specific working process of the system, device, and unit described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.
[0250] The above are all preferred embodiments of this application and are not intended to limit the scope of protection of this application. Any feature disclosed in this specification (including the abstract and drawings) may be replaced by other equivalent or similar features unless specifically stated otherwise. That is, unless specifically stated otherwise, each feature is only one example of a series of equivalent or similar features.
Claims
1. A resource security information data processing method, characterized by, The method comprises: receiving a registration request submitted by a tenant terminal; performing first identity verification on the tenant terminal according to the registration request, and generating access rights; allocating a dedicated virtualization resource pool for the tenant terminal in a virtualization environment according to the registration request; obtaining the access rights in response to an access request submitted by the tenant terminal; performing second identity verification on the tenant terminal according to the access rights, and obtaining an identity verification result; when the identity verification result indicates that the verification is passed, performing encryption processing on target data in response to a file operation instruction, and obtaining encrypted data; performing a data transmission operation on the encrypted data, the data transmission operation comprising uploading the encrypted data to the dedicated virtualization resource pool and downloading the encrypted data from the dedicated virtualization resource pool to the tenant terminal; before the file operation instruction, the method further comprises: collecting interactive behavior data in real time, the interactive behavior data comprising mouse movement trajectory features, mouse click frequency, and keyboard input delay interval; comparing the interactive behavior data with historical operation behavior, and generating a similarity score; judging whether the current operation behavior conforms to the tenant terminal operation behavior based on the similarity score; if not, interrupting the file operation instruction and refusing to execute the file operation instruction; enabling a time delay mechanism, and pushing an operation confirmation request message to a first authorized user terminal with the highest access rights, the operation confirmation request message being used to inquire whether to continue executing the file operation instruction; within a preset response waiting time, receiving a post-level feedback result of the first authorized user terminal; if the received post-level feedback result is ambiguous, pushing the operation confirmation request message to a second authorized user terminal located within a preset geographical location range of the tenant terminal, and obtaining a location feedback result; based on the post-level feedback result and the location feedback result, judging whether to allow the file operation instruction to continue to be executed according to a preset rule; if not, interrupting the file operation instruction.
2. The resource security information data processing method of claim 1, wherein, The method further comprises: establishing a feedback result axis based on time, the feedback result axis being divided into a first time threshold interval and a second time threshold interval, the first time threshold interval being earlier than the second time threshold interval; dividing the location feedback result into a first location feedback result and a second location feedback result according to the feedback result axis, the first location feedback result comprising a first approval feedback result and a first denial feedback result, and the second location feedback result comprising a second approval feedback result and a second denial feedback result, the first location feedback result being received within the first time threshold interval, and the second location feedback result being received within the second time threshold interval; counting a first total feedback quantity of the first location feedback result; counting a first sub-feedback quantity of the first approval feedback result; obtaining a proportion value based on the first total feedback quantity and the first sub-feedback quantity; If the proportion value is higher than the consistency threshold value, and the proportion of the first sub-feedback quantity in the preset total feedback quantity exceeds a first quantity threshold value, the first approval feedback result is taken as the preset rule; If the proportion value is lower than the consistency threshold value, a second majority feedback result is determined from the second approval feedback result and the second denial feedback result; In a case where the second majority feedback result is the second approval feedback result, and the proportion of the second approval feedback result in the preset total feedback quantity is not lower than a second quantity threshold value, the second approval feedback result is taken as the preset rule.
3. The method of claim 1, wherein, Further comprising: receiving a modification request of a target file submitted by the tenant terminal; obtaining an access control policy of the target file, the access control policy comprising a plurality of authorized user identifiers associated with the target file; pushing the modification request to user terminals corresponding to the plurality of authorized user identifiers, and enabling a voting timer; during the counting period of the enabled voting timer, receiving voting intentions of the user terminals; judging whether the number of the received voting intentions agreeing to modify the target file satisfies a voting threshold value; if yes, granting the tenant terminal a file modification permission.
4. The resource security information data processing method of claim 3, wherein, After the tenant terminal is granted the file modification permission, comprising: monitoring the modification of the target file to obtain modified content data; analyzing the content data to obtain an analysis result, the analysis result comprising at least one of whether a sensitive field is modified, whether there is an unauthorized operation or an abnormal data change; detecting whether a user interface operation behavior of the tenant terminal on the target file satisfies an abnormal operation mode, the abnormal operation mode comprising a page switching frequency per unit time exceeding a first threshold value or a single page dwell time being lower than a second threshold value; if yes, generating a warning signal. The detection of whether the user interface operation behavior of the tenant terminal in the modification of the target file satisfies the abnormal operation mode comprises:
5. The resource security information data processing method of claim 4, wherein, obtaining switching pages, the switching pages comprising a first switching page and a second switching page; obtaining a difference result according to differences existing in the first switching page and the second switching page; generating an operation sequence of the switching pages based on the user interface operation behavior and the difference result, the operation sequence comprising a plurality of switching page events recorded in time sequence, the switching page events comprising switching time, switching-in page identifier, switching-out page identifier and page dwell time; matching the operation sequence with the abnormal operation mode; if the matching is successful, executing the step of judging whether there is malicious modification based on the analysis result if yes. The system is used to execute the resource security information data processing method in any one of claims 1 to 5, comprising:
6. A resource security information data processing system, characterized by, an acquisition module for acquiring a registration request, an access request and an access permission; a memory for storing a program of the resource security information data processing method; a processor, the program in the memory being loadable and executable by the processor and realizing the resource security information data processing method. 7. A smart terminal, characterized by A computer program product comprising a memory and a processor, the memory having stored thereon a computer program which is loadable into the processor and which, when carried out by the processor, causes the method as claimed in any one of claims 1 to 5 to be performed.
8. A computer-readable storage medium, characterized in that, A computer program product comprising a memory and a processor, the memory having stored thereon a computer program which is loadable into the processor and which, when carried out by the processor, causes the method as claimed in any one of claims 1 to 5 to be performed.
Citation Information
Patent Citations
Software value evaluation method and device, electronic equipment and storage medium
CN120807007A
Efficient server side data retrieval for execution of client side applications
US6615253B1