Data access decision-making method, device and equipment and storage medium thereof
By acquiring and extracting information representation dimension data from data access requests, and using a pre-built feature extraction model to decide whether to allow access, the problem of existing technologies being unable to dynamically adapt to changes in user and data characteristics is solved, thus improving the security of data access.
Patent Information
- Application Number
- CN202511345656.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-19
- Publication Date
- 2025-12-05
AI Technical Summary
Existing technologies cannot dynamically adapt to changes in user access behavior and the characteristics of the accessed data when making data access decisions and controls, resulting in insufficient data access security.
By acquiring data access requests, we extract information representation dimensions of the target user and the target accessed end, use a pre-built feature extraction model to extract features, and combine user features and data features to decide whether to allow access.
It enables comprehensive settings based on users' multi-dimensional representation of data and the characteristics of the data itself, thereby improving the security of data access.
Smart Images

Figure CN121077787A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of access control, and is applied to a scenario of access decision control on a data access request, and relates to a data access decision method, device, equipment and storage medium thereof. BACKGROUND
[0002] With the rapid development of information technology and the deepening of enterprise digital transformation, the data scale and complexity in enterprise information management systems have significantly increased. In these systems, data access, as a core function, is widely used in knowledge management, data analysis, and intelligent decision-making.
[0003] For example, relevant information is extracted from massive data to support task generation. Due to the increase and accumulation of the amount of managed data, the permission control problem in the data access scenario is increasingly prominent. Traditional permission control methods mainly include role-based access control and attribute-based access control, that is, the mechanical definition of roles and permission mapping relationships, thereby realizing the control of user access permissions. Although, to some extent, it can control the decision of data access, it has obvious shortcomings in dynamically adapting to changes in user access behavior and accessed data characteristics, and cannot fully guarantee the security of data access. SUMMARY
[0004] The purpose of the embodiments of the present application is to provide a data access decision method, device, equipment and storage medium, to solve the technical problem that the prior art has obvious shortcomings in dynamically adapting to changes in user access behavior and accessed data characteristics when controlling data access decision, and cannot fully guarantee the security of data access.
[0005] In a first aspect, the embodiments of the present application provide a data access decision method, which adopts the technical solution as follows:
[0006] A data access decision method includes the following steps:
[0007] Obtaining a data access request, wherein the data access request contains unique identification information of a target user in a request initiation end and unique address information of a target accessed end;
[0008] According to the unique identification information, extracting information representation dimension data corresponding to the target user in the request initiation end;
[0009] According to the unique address information, extracting information representation dimension data corresponding to the expected accessed data in the target accessed end;
[0010] The information representation dimension data corresponding to the target user and the information representation dimension data corresponding to the expected accessed data in the target accessed end are extracted by using a pre-constructed feature extraction model.
[0011] According to the feature extraction result output by the feature extraction model, it is determined whether the target user is allowed to access the expected accessed data.
[0012] In a second aspect, the embodiments of the present application further provide a data access decision device, which adopts the technical scheme as follows:
[0013] A data access decision device comprises:
[0014] A data access request acquisition module is configured to acquire a data access request, wherein the data access request comprises unique identification information of a target user in a request initiating end and unique address information of a target accessed end.
[0015] A user representation information acquisition module is configured to extract information representation dimension data corresponding to the target user in the request initiating end according to the unique identification information.
[0016] An accessed data representation information acquisition module is configured to extract information representation dimension data corresponding to the expected accessed data in the target accessed end according to the unique address information.
[0017] A feature extraction module is configured to extract the information representation dimension data corresponding to the target user and the information representation dimension data corresponding to the expected accessed data in the target accessed end by using a pre-constructed feature extraction model.
[0018] A data access decision module is configured to determine whether the target user is allowed to access the expected accessed data according to the feature extraction result output by the feature extraction model.
[0019] In a third aspect, the embodiments of the present application further provide a computer device, which adopts the technical scheme as follows:
[0020] A computer device comprises a memory and a processor, wherein the memory stores computer readable instructions, and the processor executes the computer readable instructions to realize the steps of the data access decision method.
[0021] In a fourth aspect, the embodiments of the present application further provide a computer readable storage medium, which adopts the technical scheme as follows:
[0022] A computer readable storage medium stores computer readable instructions, and the computer readable instructions are executed by a processor to realize the steps of the data access decision method.
[0023] Compared with the prior art, the embodiments of the present application have the following beneficial effects:
[0024] The data access decision method provided in the present application comprises the following steps: obtaining a data access request; extracting information representation dimension data corresponding to a target user of a request initiator; extracting information representation dimension data corresponding to expected accessed data in a target accessed end; using a pre-constructed feature extraction model to perform feature extraction on the information representation dimension data corresponding to the target user and the information representation dimension data corresponding to the expected accessed data in the target accessed end; and deciding whether to allow the target user to access the expected accessed data according to the feature extraction result. The data access decision method uses the user features of a previous access user and the data features of a previous accessed data to perform access permission feature modeling in advance, and compared with the previous fixed access permission set for different users, the user is allowed to access data according to the fixed access permission, which more fully combines the multi-dimensional representation data of the user and the data features of the accessed data itself to set the access permission features, thereby ensuring the data access security. BRIEF DESCRIPTION OF DRAWINGS
[0025] In order to more clearly illustrate the schemes in the present application, the drawings needed in the description of the embodiments of the present application will be briefly introduced. Obviously, the drawings in the following description are some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.
[0026] Figure 1 is an exemplary system architecture diagram to which the present application can be applied;
[0027] Figure 2 is a flowchart of an embodiment of a data access decision method according to the present application;
[0028] Figure 3 is a flowchart of a specific embodiment of feature modeling in the data access decision method provided in the present application;
[0029] Figure 4 is Figure 3 a flowchart of a specific embodiment of step 302 shown in FIG. 3;
[0030] Figure 5 is Figure 3 a flowchart of a specific embodiment of step 304 shown in FIG. 3;
[0031] Figure 6 is Figure 3 a flowchart of a specific embodiment of step 305 shown in FIG. 3;
[0032] Figure 7 is a flow chart of one embodiment of the data access decision method described in the present application;
[0033] Figure 8 is Figure 7 is a flow chart of one embodiment of the step 702 shown in FIG. 7;
[0034] Figure 9 is Figure 2 is a flow chart of one embodiment of the step 205 shown in FIG. 2;
[0035] Figure 10 is a structural schematic diagram of one embodiment of the data access decision device according to the present application;
[0036] Figure 11 is a structural schematic diagram of one embodiment of the computer device according to the present application. DETAILED DESCRIPTION
[0037] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs; the terminology used in the description herein is for describing particular embodiments only and is not intended to be limiting of the application; the description and claims herein and the above description of drawings herein use the term "comprising" and "including" and variations thereof to mean "including but not limited to"; the description and claims herein and the above description of drawings herein use the term "first", "second", and the like to mean "different" and not necessarily "of a different order or type".
[0038] Reference herein to "embodiment" means that a particular feature, structure, or characteristic described in connection with the embodiment can be included in at least one embodiment of the application. The appearances of the phrase "in one embodiment" in various places in the specification are not necessarily all referring to the same embodiment, nor are they necessarily all referring to a common set of embodiments. It is expressly understood that the embodiments described herein are merely examples from a
[0039] In order to make the technical personnel in the art better understand the scheme of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings.
[0040] As Figure 1As shown, the system architecture 100 can include a terminal device 101, a network 102 and a server 103. The terminal device 101 can be a notebook computer 1011, a tablet computer 1012 or a mobile phone 1013. The network 102 is a medium for providing a communication link between the terminal device 101 and the server 103. The network 102 can include various connection types, such as wired, wireless communication links or optical fiber cables, etc.
[0041] A user can use the terminal device 101 to interact with the server 103 through the network 102 to receive or send messages, etc. Various communication client applications can be installed on the terminal device 101, such as web browser applications, shopping applications, search applications, instant messaging tools, email clients, social platform software, etc.
[0042] The terminal device 101 can be various electronic devices with display screens and supporting web browsing, in addition to the notebook computer 1011, the tablet computer 1012 or the mobile phone 1013, the terminal device 101 can also be an e-book reader, an MP3 player (Moving Picture Experts Group Audio Layer III), an MP4 player (Moving Picture Experts Group Audio Layer IV), a laptop computer and a desktop computer, etc.
[0043] The server 103 can be a server providing various services, such as a background server supporting a page displayed on the terminal device 101.
[0044] It should be noted that the data access decision method provided by the embodiments of the present application is generally executed by a server, and accordingly, a data access decision device is generally provided in a server.
[0045] It should be understood that Figure 1 The number of terminal devices, networks and servers in
[0046] With reference to Figure 2 , a flowchart of one embodiment of a data access decision method according to the present application is shown. The data access decision method includes the following steps:
[0047] In step 201, a data access request is obtained, wherein the data access request contains unique identification information of a target user in a request initiating end and unique address information of a target accessed end.
[0048] In this embodiment, the data access request refers to a data access request initiated by a request initiating end to a target accessed end. Specifically, the request initiating end includes a user request end, and the target accessed end includes a data cache end or a data storage end. For example, a personal user wants to obtain specific business data stored in a data storage platform managed by an enterprise. The personal user needs to initiate a data access request to the data storage platform.
[0049] Specifically, the data access decision method can be applied to a data access decision control scenario to determine whether the initiating end of the data access request has access qualification, thereby ensuring safe data access.
[0050] In step 202, information representation dimension data corresponding to a target user in the request initiating end is extracted according to the unique identification information.
[0051] In this embodiment, the unique identification information of the request initiating end includes unique IP information of the request initiating end and unique user identification information of the user bound to the request initiating end. The information representation dimension data corresponding to the target user in the request initiating end includes basic attribute data of the target user and access behavior data of the target user.
[0052] The information representation dimension data corresponding to the target user in the request initiating end is extracted, so that the user features of the target user can be extracted subsequently, and whether the target user has access permission to the expected accessed data is determined in combination with the user features.
[0053] In step 203, information representation dimension data corresponding to expected accessed data in the target accessed end is extracted according to the unique address information.
[0054] In this embodiment, the unique address information represents a unique storage address of the expected accessed data in the target accessed end (data storage platform or data storage end). The information representation dimension data corresponding to the expected accessed data in the target accessed end is extracted through the unique address information, so that the data features of the expected accessed data can be extracted subsequently, and whether the target user has access permission to the expected accessed data is determined in combination with the data features.
[0055] In step 204, a pre-constructed feature extraction model is used to extract features from the information representation dimension data corresponding to the target user and the information representation dimension data corresponding to the expected accessed data in the target accessed end, respectively.
[0056] In this embodiment, the pre-constructed feature extraction model includes a natural language-based feature extraction model, a transformer architecture-based feature extraction model, and a recurrent neural network (RNN)-based feature extraction model, which are not specifically limited here.
[0057] Before this step, the pre-constructed feature extraction model can be pre-trained using supervised learning, unsupervised learning, or semi-supervised learning training methods to learn and train the pre-constructed feature extraction model, so that the pre-constructed feature extraction model can extract multi-dimensional user features from the information representation dimension data corresponding to the target user, and also so that the pre-constructed feature extraction model can extract multi-dimensional data features from the information representation dimension data corresponding to the expected accessed data in the target accessed end.
[0058] In step 205, it is determined whether to allow the target user to access the expected accessed data according to the feature extraction result output by the feature extraction model.
[0059] Specifically, it is determined whether to allow the target user to access the expected accessed data in combination with the feature extraction result output by the feature extraction model, i.e., the user features and the data features. This realizes data access security identification from the perspective of combining user features and data features, and compared with the past fixed access permissions set for different users to determine whether to allow users to access data, the basic attribute information of the user, the user access behavior data, and the data features of the expected accessed data itself are more fully combined to ensure data access security.
[0060] In this embodiment, the data access request is obtained, the information representation dimension data corresponding to the target user of the request initiator is extracted, the information representation dimension data corresponding to the expected accessed data in the target accessed end is extracted, a pre-constructed feature extraction model is used to extract features from the information representation dimension data corresponding to the target user and the information representation dimension data corresponding to the expected accessed data in the target accessed end, respectively, and it is determined whether to allow the target user to access the expected accessed data according to the feature extraction result. This data access decision method uses the user features of the previous access user and the data features of the previous accessed data to model access permissions in advance, compared with the past fixed access permissions set for different users to determine whether to allow users to access data, the user multi-dimensional representation data and the data features of the accessed data itself are more fully combined to set comprehensive access permission features, and data access security is ensured.
[0061] Continuing to refer to Figure 3In some embodiments, prior to step 204, a step of performing feature modeling is further included, Figure 3 is a flowchart of one embodiment of the data access decision method described in the present application, including:
[0062] In step 301, information representation dimension data corresponding to all access users within a preset historical time period is obtained, wherein the information representation dimension data includes user basic attribute data and user access behavior data.
[0063] In step 302, user feature modeling is performed according to the information representation dimension data corresponding to all access users.
[0064] By obtaining information representation dimension data corresponding to all access users within a preset historical time period, and performing user feature modeling in combination with multi-dimensional access user information representation dimension data, it is ensured that the final access permission modeling result is no longer limited to mechanical permission setting, and user features contained in user basic attribute data and user access behavior data are fully utilized.
[0065] In step 303, information representation dimension data corresponding to all accessed data pre-arranged in all accessed ends within the historical time period is obtained, wherein the information representation dimension data includes data source, data level, data purpose and specific data content.
[0066] In step 304, data feature modeling is performed according to the information representation dimension data corresponding to all accessed data.
[0067] Similarly, by obtaining information representation dimension data corresponding to all accessed data pre-arranged in all accessed ends within the historical time period, and performing data feature modeling in combination with information representation dimension data corresponding to all accessed data, it is ensured that the final access permission modeling result is no longer limited to mechanical permission setting, and data features contained in information representation dimension data corresponding to all accessed data are fully utilized.
[0068] In step 305, access permission modeling is performed in combination with user feature modeling result and data feature modeling result.
[0069] Specifically, the final access permission modeling result fully utilizes user features contained in user basic attribute data and user access behavior data and data features contained in information representation dimension data corresponding to all accessed data, so that the allocation and setting of access permissions are no longer too mechanical, and the user features of access users and the data features of accessed data are fully combined.
[0070] With reference to Figure 4 , Figure 4 isFigure 3 A flow chart of one specific embodiment of step 302 is shown, comprising:
[0071] Step 401, using a preset user feature extraction component to perform user feature extraction on the information representation dimension data corresponding to all access users;
[0072] In this embodiment, the preset user feature extraction component is a feature extraction component in the pre-constructed feature extraction model, which is specifically used for user feature extraction on the information representation dimension data of users.
[0073] Step 402, obtaining user basic attribute features and user access behavior features corresponding to all access users respectively;
[0074] Step 403, classifying and sorting access users with consistent user basic attribute features and user access behavior features to obtain different access user groups;
[0075] In this embodiment, since user feature extraction is performed in advance, user basic attribute features and user access behavior features corresponding to all access users are obtained, and therefore, the access user grouping classification is performed by comparing the user basic attribute features and the user access behavior features.
[0076] Step 404, setting user features corresponding to different access user groups to complete user feature modeling, wherein the user features include user basic attribute features and user access behavior features.
[0077] Continuing to refer to Figure 5 , Figure 5 is Figure 3 A flow chart of one specific embodiment of step 304 is shown, comprising:
[0078] Step 501, using a preset data feature extraction component to perform data feature extraction on the information representation dimension data corresponding to all accessed data;
[0079] In this embodiment, the preset data feature extraction component is a feature extraction component in the pre-constructed feature extraction model, which is specifically used for data feature extraction on the information representation dimension data of all accessed data.
[0080] Step 502, obtaining data source features, data level features, data usage features, and context implicit features corresponding to all accessed data respectively;
[0081] Step 503, classifying and dividing accessed data with consistent data source features, data level features, data usage features, and context implicit features to obtain access data of different permission categories;
[0082] Specifically, the data source feature, the data level feature, the data use feature, and the context implied feature are combined to classify and divide the access data into different permission categories. The data source feature, the data level feature, and the data use feature can be understood as external features of the accessed data, and the context implied feature can be understood as an association feature between internal specific data contents of the accessed data.
[0083] In step 504, data features corresponding to access data of different permission categories are set, and data feature modeling is completed. The data features include a data source feature, a data level feature, a data use feature, and a context implied feature.
[0084] With reference to Figure 6 , Figure 6 is Figure 3 a flowchart of one specific embodiment of step 305, including:
[0085] In step 601, an access association relationship between different access user groups and access data of different permission categories is obtained by analyzing historical access logs.
[0086] In step 602, user features corresponding to access data of different permission categories are determined according to the access association relationship, or
[0087] In step 603, data features corresponding to different access user groups are determined according to the access association relationship.
[0088] In this embodiment, steps 602 and 603 actually determine the lowest dimension user features corresponding to access data of different permission categories, and determine the lowest dimension data features corresponding to different access user groups. That is, assuming that access data of the same permission category may correspond to multiple user features in multiple access association relationships, the corresponding least user features are used as the user features corresponding to the access data of the permission category.
[0089] In step 604, combined features corresponding to all access association relationships are integrated, where the combined features refer to combinations of user features and data features.
[0090] Specifically, the combined features refer to combinations of multi-dimensional user features and data features. For example, a combined feature corresponding to a current access association relationship includes user feature 1, user feature 2, user feature 3, data feature 1, data feature 2, and data feature 3. The combined feature is [user feature 1, user feature 2, user feature 3, data feature 1, data feature 2, data feature 3].
[0091] At step 605, based on the combination feature, access permissions corresponding to different access user groups are set respectively, access permission modeling is completed, and specifically, the combination feature corresponding to different access user groups is set as the corresponding access permission feature.
[0092] Specifically, the combination feature: [user feature 1, user feature 2, user feature 3, data feature 1, data feature 2, data feature 3] is set as the access permission feature corresponding to the corresponding access user group.
[0093] With reference to Figure 7 In some embodiments, after step 605, a step of performing access permission layering processing is further included, Figure 7 is a flowchart of one specific embodiment of the data access decision method described in the present application, which includes:
[0094] At step 701, the access permission feature corresponding to each access user group is identified, and the number of access permission features corresponding to each access user group is counted.
[0095] Specifically, the more the number of access permission features corresponding to the current access user group, the higher the access permission of the current access user group; on the contrary, the fewer the number of access permission features corresponding to the current access user group, the lower the access permission of the current access user group.
[0096] At step 702, according to the access permission feature corresponding to each access user group and the number of access permission features corresponding to each access user group, access permission layering processing is performed in combination with the decision tree rule.
[0097] With reference to Figure 8 , Figure 8 is Figure 7 a flowchart of one specific embodiment of step 702, which includes:
[0098] At step 801, the access permission feature contained in the first access user group when the number of access permission features is the minimum value is identified.
[0099] Specifically, assuming that the number of access permission features contains 4 to 10, when the number of access permission features is set to 4, the four access permission features are set to the lowest level of access permission.
[0100] At step 802, the access permission feature contained in the first access user group is set at the lowest level of access permission.
[0101] Step 803, according to the order from small to large of the difference, the access permission feature quantity gradually increases the other access user groups containing the access permission feature compared with the minimum value is identified in turn;
[0102] Step 804, from the access permission feature contained in the other access user groups, the access permission feature increased compared with the previous permission access level is filtered out, and the access permission level where the increased access permission feature is located is set;
[0103] Specifically, when the number of identified access permission features is 5, the 5 access permission features contained are compared, and the increased access permission features compared with the above-mentioned 4 access permission features are identified, and the increased access permission features are set to the upper layer of the lowest level.
[0104] In the feature case, if the number of identified access permission features is 5, it corresponds to two different combination features, that is, the first 4 access permission features are consistent, and the 5th access permission feature is inconsistent, then for the two different combination features, step 804 is executed respectively, and the increased access permission features compared with the access permission feature quantity of 4 are filtered out, that is, 2 access permission features are set in the upper layer of the lowest level of the access permission.
[0105] Step 805, until the number of identified access permission features is the maximum value, the access permission feature contained in the second access user group is increased compared with the previous access permission level;
[0106] Step 806, the increased access permission feature is set in the highest layer of the access permission level, and the access permission layering processing is completed.
[0107] Specifically, the increased access permission features of 4 to 5, 5 to 6, 6 to 7, 7 to 8, 8 to 9 and 9 to 10 are identified in turn, until the increased access permission feature of the maximum value of 10 is identified, and the increased access permission feature is set in the highest layer of the access permission level, and the access permission layering processing is completed.
[0108] By combining the access permission feature corresponding to each access user group and the access permission feature quantity corresponding to each access user group, the decision tree rule is combined, and the access permission layering processing is performed, so as to facilitate subsequent access permission confirmation in actual more complex access permission identification combined with the access permission layering processing result.
[0109] Continue to refer to Figure 9 , Figure 9 is Figure 2 a flow chart of one specific embodiment of step 205, which includes:
[0110] Step 901, screening all user features and all data features from the feature extraction result;
[0111] Step 902, determining the access user group corresponding to the target user according to all the screened user features;
[0112] Specifically, since the user feature modeling is completed by setting different user features corresponding to different access user groups in the previous step 602, after screening all the user features of the target user, the access user group corresponding to the target user can be determined.
[0113] Step 903, identifying the access permission features contained in the access user group;
[0114] Specifically, the access permission modeling is completed by setting different access permissions corresponding to different access user groups in step 605, so after identifying the access user group to which the target user belongs, the access permission features corresponding to the target user can be determined by further identifying the access permission features contained in the access user group.
[0115] Step 904, if the access permission features contain all the data features, allowing the target user to access the desired accessed data;
[0116] Specifically, since the access permission features are composed of user features and data features, whether the access permission features contain all the data features of the desired accessed data is judged, and according to the judgment result, it is finally determined whether the target user is allowed to access the desired accessed data.
[0117] Step 905, if the access permission features do not contain all the data features, the target user is not allowed to access the desired accessed data.
[0118] In the embodiment, a data access request is acquired, information representation dimension data corresponding to a target user at a request initiation end is extracted, information representation dimension data corresponding to expected accessed data in a target accessed end is extracted, a pre-constructed feature extraction model is used to perform feature extraction on the information representation dimension data corresponding to the target user and the information representation dimension data corresponding to the expected accessed data in the target accessed end respectively, and whether the target user is allowed to access the expected accessed data is determined according to a feature extraction result. The data access decision method preforms access permission feature modeling by using user features of a previous access user and data features of a previous accessed data, compared with a fixed access permission set for different users in the past, whether a user is allowed to access data is determined according to the fixed access permission, user multi-dimensional representation data and data features of the accessed data are more fully combined to comprehensively set access permission features, and data access security is ensured.
[0119] Embodiments of the present application can acquire and process related data based on artificial intelligence technology. Artificial intelligence (AI) is the use of digital computers or computer-controlled machines to simulate, extend and expand human intelligence, perceive the environment, acquire knowledge and use knowledge to obtain the best results.
[0120] Artificial intelligence basic technologies generally include technologies such as sensors, special artificial intelligence chips, cloud computing, distributed storage, big data processing technology, operation / interaction system, mechatronics, etc. Artificial intelligence software technology mainly includes computer vision technology, robot technology, biometric technology, speech processing technology, natural language processing technology, and machine learning / deep learning, etc.
[0121] In the embodiment, a data access request is acquired, information representation dimension data corresponding to a target user at a request initiation end is extracted, information representation dimension data corresponding to expected accessed data in a target accessed end is extracted, a pre-constructed feature extraction model is used to perform feature extraction on the information representation dimension data corresponding to the target user and the information representation dimension data corresponding to the expected accessed data in the target accessed end respectively, and whether the target user is allowed to access the expected accessed data is determined according to a feature extraction result. The data access decision method preforms access permission feature modeling by using user features of a previous access user and data features of a previous accessed data, compared with a fixed access permission set for different users in the past, whether a user is allowed to access data is determined according to the fixed access permission, user multi-dimensional representation data and data features of the accessed data are more fully combined to comprehensively set access permission features, and data access security is ensured.
[0122] Further reference Figure 10 , as the implementation of the method shown above Figure 2 , the present application provides a data access decision device embodiment, the device embodiment corresponds to the method embodiment shown in Figure 2 , the device can be applied to various electronic devices.
[0123] As shown in Figure 10 , the data access decision device 10 comprises: data access request acquisition module 10a, user representation information acquisition module 10b, accessed data representation information acquisition module 10c, feature extraction module 10d and data access decision module 10e. Wherein:
[0124] Data access request acquisition module 10a, for acquiring data access request, wherein the data access request contains the unique identification information of the target user in the request initiator and the unique address information of the target accessed end;
[0125] User representation information acquisition module 10b, for extracting the information representation dimension data corresponding to the target user in the request initiator according to the unique identification information;
[0126] Accessed data representation information acquisition module 10c, for extracting the information representation dimension data corresponding to the expected accessed data in the target accessed end according to the unique address information;
[0127] Feature extraction module 10d, for using pre-constructed feature extraction model to extract features of the information representation dimension data corresponding to the target user and the information representation dimension data corresponding to the expected accessed data in the target accessed end respectively;
[0128] Data access decision module 10e, for deciding whether to allow the target user to access the expected accessed data according to the feature extraction result output by the feature extraction model.
[0129] The application obtains a data access request, extracts information representation dimension data corresponding to a target user at a request initiation end, extracts information representation dimension data corresponding to expected accessed data in a target accessed end, uses a pre-constructed feature extraction model to perform feature extraction on the information representation dimension data corresponding to the target user and the information representation dimension data corresponding to the expected accessed data in the target accessed end respectively, and decides whether to allow the target user to access the expected accessed data according to a feature extraction result. The data access decision method uses user features of a previous access user and data features of a previous accessed data to perform access permission feature modeling in advance, compared with a fixed access permission set for different users in the past, whether to allow a user to access data is determined according to the fixed access permission, the access permission features are more comprehensively set by combining multi-dimensional representation data of the user and data features of the accessed data itself, and data access security is ensured.
[0130] In the embodiment, the data access decision device 10 further includes a first information representation dimension data acquisition module, a user feature modeling processing module, a second information representation dimension data acquisition module, a data feature modeling processing module, and an access permission modeling processing module. Wherein:
[0131] The first information representation dimension data acquisition module is used to acquire information representation dimension data corresponding to all access users in a preset historical time limit, wherein the information representation dimension data includes user basic attribute data and user access behavior data.
[0132] The user feature modeling processing module is used to perform user feature modeling according to the information representation dimension data corresponding to all the access users.
[0133] The second information representation dimension data acquisition module is used to acquire information representation dimension data corresponding to all accessed data previously sorted out in all accessed ends in the historical time limit, wherein the information representation dimension data includes data source, data level, data use, and specific data content.
[0134] The data feature modeling processing module is used to perform data feature modeling according to the information representation dimension data corresponding to all the accessed data.
[0135] The access permission modeling processing module is used to perform access permission modeling by combining the user feature modeling result and the data feature modeling result.
[0136] In the embodiment, the user feature modeling processing module includes a user feature extraction unit, a user feature acquisition unit, an access user group classification unit, and a user feature modeling unit. Wherein:
[0137] The user feature extraction unit is configured to extract user features of information representation dimension data corresponding to all access users by using a preset user feature extraction component.
[0138] The user feature acquisition unit is configured to obtain user basic attribute features and user access behavior features corresponding to all access users respectively.
[0139] The access user group classification unit is configured to classify and arrange access users with consistent user basic attribute features and user access behavior features to obtain different access user groups.
[0140] The user feature modeling unit is configured to set user features corresponding to different access user groups respectively to complete user feature modeling, wherein the user features include user basic attribute features and user access behavior features.
[0141] In the embodiment, the data feature modeling processing module includes a data feature extraction unit, a data feature acquisition unit, an accessed data classification and division unit, and a data feature modeling unit. Specifically,
[0142] The data feature extraction unit is configured to extract data features of information representation dimension data corresponding to all accessed data by using a preset data feature extraction component.
[0143] The data feature acquisition unit is configured to obtain data source features, data level features, data usage features, and context implicit features corresponding to all accessed data respectively.
[0144] The accessed data classification and division unit is configured to classify and divide accessed data with consistent data source features, data level features, data usage features, and context implicit features to obtain access data of different permission categories.
[0145] The data feature modeling unit is configured to set data features corresponding to access data of different permission categories respectively to complete data feature modeling, wherein the data features include data source features, data level features, data usage features, and context implicit features.
[0146] In the embodiment, the access permission modeling processing module includes an access association relationship acquisition unit, a first determination unit, a second determination unit, a combined feature integration unit, and an access permission modeling unit. Specifically,
[0147] The access association relationship acquisition unit is configured to acquire access association relationships between different access user groups and access data of different permission categories by analyzing historical access logs.
[0148] The first determining unit is configured to determine user features corresponding to the access data of different permission categories according to the access association relationship, or
[0149] The second determining unit is configured to determine data features corresponding to different access user groups according to the access association relationship.
[0150] The combined feature integration unit is configured to integrate combined features corresponding to all the access association relationships, wherein the combined features refer to combinations of the user features and the data features.
[0151] The access permission modeling unit is configured to set access permissions corresponding to different access user groups based on the combined features, complete access permission modeling, and specifically, set the combined features corresponding to different access user groups as corresponding access permission features.
[0152] In this embodiment, the data access decision device 10 further includes an access permission feature identification and statistics module and an access permission hierarchical processing module. Wherein:
[0153] The access permission feature identification and statistics module is configured to identify access permission features corresponding to each access user group and count the number of access permission features corresponding to each access user group.
[0154] The access permission hierarchical processing module is configured to perform access permission hierarchical processing according to the access permission features corresponding to each access user group, the number of access permission features corresponding to each access user group, and a decision tree rule.
[0155] In this embodiment, the access permission hierarchical processing module includes a permission hierarchical first identification unit, a lowest level setting unit, a permission hierarchical sequential identification unit, an access permission level setting unit, a permission hierarchical second identification unit, and a highest level setting unit. Wherein:
[0156] The permission hierarchical first identification unit is configured to identify access permission features contained in a first access user group corresponding to a minimum value of the number of access permission features.
[0157] The lowest level setting unit is configured to set the access permission features contained in the first access user group at a lowest level of access permission.
[0158] The permission hierarchical sequential identification unit is configured to sequentially identify access permission features contained in other access user groups with gradually increasing numbers of access permission features than the minimum value according to an order from small to large difference.
[0159] The access permission hierarchy setting unit is configured to set the added access permission feature in the access permission hierarchy.
[0160] The permission hierarchy second identification unit is configured to identify the added access permission feature included in the second access user group compared with the previous access permission hierarchy until the number of access permission features is the maximum value.
[0161] The highest hierarchy setting unit is configured to set the added access permission feature in the highest hierarchy of the access permission hierarchy, and complete the access permission hierarchy processing.
[0162] In the embodiment, the data access decision module 10e includes a feature screening unit, an access user group determination unit, an access permission feature identification unit, a first decision judgment unit and a second decision judgment unit. Among them:
[0163] The feature screening unit is configured to screen all user features and all data features from the feature extraction result.
[0164] The access user group determination unit is configured to determine the access user group corresponding to the target user according to the screened all user features.
[0165] The access permission feature identification unit is configured to identify the access permission feature included in the access user group.
[0166] The first decision judgment unit is configured to allow the target user to access the expected accessed data if the access permission feature fully contains all the data features.
[0167] The second decision judgment unit is configured to not allow the target user to access the expected accessed data if the access permission feature does not fully contain all the data features.
[0168] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by computer readable instructions instructing related hardware, and the computer readable instructions can be stored in a computer readable storage medium. When the program is executed, it can include the processes of the above-mentioned embodiments. Among them, the storage medium can be a magnetic disc, an optical disc, a read-only memory (ROM) and other non-volatile storage medium, or a random access memory (RAM).
[0169] It should be understood that although each step in the flowchart of the accompanying drawings is shown in sequence according to the direction of the arrow, these steps are not necessarily executed in sequence according to the direction of the arrow. Unless explicitly stated herein, the execution of these steps is not strictly limited in sequence, and they can be executed in other sequences. Moreover, at least part of the steps in the flowchart of the accompanying drawings can include multiple sub-steps or multiple stages, which are not necessarily executed at the same time, but can be executed at different times, and the execution sequence is not necessarily sequential, but can be alternately or alternately executed with at least part of other steps or sub-steps or stages of other steps.
[0170] To solve the above technical problems, the embodiments of the present application further provide a computer device. For details, please refer to Figure 11 , Figure 11 The basic structure block diagram of the computer device of the present embodiment is shown in FIG. 1.
[0171] The computer device 11 includes a memory 11a, a processor 11b, and a network interface 11c, which are connected to each other for communication through a system bus. It should be noted that Figure 11 only the computer device 11 with components of the memory 11a, the processor 11b, and the network interface 11c is shown in the figure, but it should be understood that it is not required to implement all the components shown, and more or fewer components can be alternatively implemented. Among them, those skilled in the art can understand that the computer device here is a device capable of automatically performing numerical calculation and / or information processing according to pre-set or stored instructions, and its hardware includes but is not limited to microprocessors, application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), digital signal processors (DSPs), embedded devices, etc.
[0172] The computer device can be a desktop computer, a notebook computer, a palm computer, a cloud server, and other computing devices. The computer device can interact with the user through a keyboard, a mouse, a remote controller, a touchpad, a voice control device, and other means.
[0173] The memory 11a includes at least one type of readable storage medium, such as a flash memory, a hard disk, a multimedia card, a card-type memory (e.g., an SD or DX memory, etc.), a random access memory (RAM), a static random access memory (SRAM), a read-only memory (ROM), an electrically erasable programmable read-only memory (EEPROM), a programmable read-only memory (PROM), a magnetic memory, a magnetic disk, an optical disk, etc. In some embodiments, the memory 11a can be an internal storage unit of the computer device 11, such as a hard disk or a memory of the computer device 11. In other embodiments, the memory 11a can also be an external storage device of the computer device 11, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the computer device 11. Of course, the memory 11a can also include both an internal storage unit and an external storage device of the computer device 11. In this embodiment, the memory 11a is generally used to store an operating system and various application software installed on the computer device 11, such as computer readable instructions of a data access decision method, etc. In addition, the memory 11a can also be used to temporarily store various data that have been output or will be output.
[0174] The processor 11b can be a central processing unit (CPU), a controller, a microcontroller, a microprocessor, or other data processing chip in some embodiments. The processor 11b is generally used to control the overall operation of the computer device 11. In this embodiment, the processor 11b is used to run computer readable instructions or process data stored in the memory 11a, such as computer readable instructions of the data access decision method.
[0175] The network interface 11c can include a wireless network interface or a wired network interface, and is generally used to establish a communication connection between the computer device 11 and other electronic devices.
[0176] The computer device provided in the embodiment belongs to the technical field of access control and is applied to the scene of access decision control on data access requests. The application obtains a data access request, extracts information representation dimension data corresponding to a target user of a request initiation end, extracts information representation dimension data corresponding to expected accessed data in a target accessed end, respectively performs feature extraction on the information representation dimension data corresponding to the target user and the information representation dimension data corresponding to the expected accessed data in the target accessed end by using a pre-constructed feature extraction model, and decides whether to allow the target user to access the expected accessed data according to a feature extraction result. The data access decision method preforms access permission feature modeling by using user features of a previous access user and data features of previous accessed data, compared with setting fixed access permissions for different users in the past, determines whether to allow a user to access data according to the fixed access permissions, more fully combines user multi-dimensional representation data and data features of the accessed data itself to set access permission features, and guarantees data access security.
[0177] The application further provides another implementation, namely providing a computer readable storage medium storing computer readable instructions, which can be executed by a processor to make the processor execute steps of a data access decision method as described above.
[0178] The computer readable storage medium provided in the embodiment belongs to the technical field of access control and is applied to the scene of access decision control on data access requests. The application obtains a data access request, extracts information representation dimension data corresponding to a target user of a request initiation end, extracts information representation dimension data corresponding to expected accessed data in a target accessed end, respectively performs feature extraction on the information representation dimension data corresponding to the target user and the information representation dimension data corresponding to the expected accessed data in the target accessed end by using a pre-constructed feature extraction model, and decides whether to allow the target user to access the expected accessed data according to a feature extraction result. The data access decision method preforms access permission feature modeling by using user features of a previous access user and data features of previous accessed data, compared with setting fixed access permissions for different users in the past, determines whether to allow a user to access data according to the fixed access permissions, more fully combines user multi-dimensional representation data and data features of the accessed data itself to set access permission features, and guarantees data access security.
[0179] Those skilled in the art can clearly understand the above-mentioned method of the embodiment can be realized by means of software and the necessary general hardware platform, of course, it can also be realized by hardware, but in many cases, the former is a better embodiment. Based on such understanding, the technical solutions of the present application can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes a plurality of instructions for making a terminal device (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) execute the method described in each embodiment of the present application.
[0180] Obviously, the above-described embodiments are only some of the embodiments of the present application, not all the embodiments, the drawings give the preferred embodiments of the present application, but do not limit the patent scope of the present application. The present application can be realized in many different forms, and conversely, the purpose of providing these embodiments is to make the disclosure of the present application more thorough and comprehensive. Although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions recorded in the foregoing specific embodiments, or make equivalent replacements to some technical features. Any equivalent structure made by using the content of the specification and drawings, directly or indirectly applied to other related technical fields, is also within the scope of the patent protection of the present application. The non-company software tools or components appearing in the embodiments of the present application are only illustrative, not representative of actual use.
Claims
1. A method of data access decision, characterized by, The method comprises the following steps: obtaining a data access request, wherein the data access request comprises unique identification information of a target user in a request initiating end and unique address information of a target accessed end; extracting information representation dimension data corresponding to the target user in the request initiating end according to the unique identification information; extracting information representation dimension data corresponding to expected accessed data in the target accessed end according to the unique address information; performing feature extraction on the information representation dimension data corresponding to the target user and the information representation dimension data corresponding to the expected accessed data in the target accessed end respectively by using a pre-constructed feature extraction model; deciding whether to allow the target user to access the expected accessed data according to a feature extraction result output by the feature extraction model.
2. The data access decision method of claim 1, wherein, Before the step of performing feature extraction on the information representation dimension data corresponding to the target user and the information representation dimension data corresponding to the expected accessed data in the target accessed end respectively by using the pre-constructed feature extraction model, the method further comprises: obtaining information representation dimension data corresponding to all access users in a preset historical time limit, wherein the information representation dimension data comprises user basic attribute data and user access behavior data; performing user feature modeling according to the information representation dimension data corresponding to all the access users; obtaining information representation dimension data corresponding to all accessed data pre-arranged in all accessed ends in the historical time limit, wherein the information representation dimension data comprises data source, data level, data purpose and specific data content; performing data feature modeling according to the information representation dimension data corresponding to all the accessed data; combining the user feature modeling result and the data feature modeling result to perform access permission modeling.
3. The data access decision method of claim 2, wherein, The step of performing user feature modeling according to the information representation dimension data corresponding to all the access users comprises: performing user feature extraction on the information representation dimension data corresponding to all the access users by using a preset user feature extraction component; obtaining user basic attribute features and user access behavior features corresponding to all the access users respectively; grouping and classifying access users with consistent user basic attribute features and user access behavior features to obtain different access user groups; setting user features corresponding to different access user groups respectively to complete user feature modeling, wherein the user features comprise user basic attribute features and user access behavior features.
4. The data access decision method of claim 2, wherein, The step of performing data feature modeling according to the information representation dimension data corresponding to all the accessed data comprises: performing data feature extraction on the information representation dimension data corresponding to all the accessed data by using a preset data feature extraction component; obtaining data source features, data level features, data purpose features and context implicit features corresponding to all the accessed data respectively; grouping and classifying accessed data with consistent data source features, data level features, data purpose features and context implicit features to obtain access data of different permission categories. The data characteristics corresponding to the access data of different permission categories are set, and data characteristic modeling is completed, wherein the data characteristics include data source characteristics, data level characteristics, data use characteristics, and context implicit characteristics.
5. The data access decision method of claim 2, wherein, The step of combining the user characteristic modeling result and the data characteristic modeling result to perform access permission modeling specifically includes: By analyzing the historical access log, the access association relationship between different access user groups and access data of different permission categories is obtained; According to the access association relationship, the user characteristics corresponding to the access data of different permission categories are determined, or According to the access association relationship, the data characteristics corresponding to different access user groups are determined; All combination characteristics corresponding to the access association relationship are integrated, wherein the combination characteristics refer to the combination of user characteristics and data characteristics; Based on the combination characteristics, the access permissions corresponding to different access user groups are set, and access permission modeling is completed. Specifically, the combination characteristics corresponding to different access user groups are set as corresponding access permission characteristics.
6. The data access decision method of claim 2, wherein, After the step of combining the user characteristic modeling result and the data characteristic modeling result to perform access permission modeling, the method further includes: Identify the access permission characteristics corresponding to each access user group, and count the number of access permission characteristics corresponding to each access user group; According to the access permission characteristics corresponding to each access user group and the number of access permission characteristics corresponding to each access user group, the decision tree rule is combined to perform access permission layering processing.
7. The data access decision method of claim 6, wherein, The step of combining the access permission characteristics corresponding to each access user group and the number of access permission characteristics corresponding to each access user group to perform access permission layering processing according to the decision tree rule specifically includes: Identify the access permission characteristics contained in the first access user group corresponding to the minimum value of the number of access permission characteristics; Set the access permission characteristics contained in the first access user group at the lowest level of access permission; According to the order from small to large, the access permission characteristics contained in other access user groups with gradually increasing number of access permission characteristics than the minimum value are identified in turn; From the access permission characteristics contained in other access user groups, the access permission characteristics added compared to the previous permission access level are filtered out, and the access permission level where the added access permission characteristics are located is set; Until the access permission characteristics contained in the second access user group corresponding to the maximum value of the number of access permission characteristics are identified, the access permission characteristics added compared to the previous access permission level are identified; The added access permission characteristics are set at the highest level of the access permission level, and the access permission layering processing is completed.
8. The data access decision method of claim 1 or 5, wherein, The step of determining whether to allow the target user to access the expected accessed data according to the feature extraction result output by the feature extraction model specifically includes: Filter all user characteristics and all data characteristics from the feature extraction result; According to all filtered user characteristics, determine the access user group corresponding to the target user; identifying an access permission feature contained in the access user group; if the access permission feature contains all the data features, allowing the target user to access the expected accessed data; if the access permission feature does not contain all the data features, not allowing the target user to access the expected accessed data.
9. A data access decision apparatus, characterized by comprising: a data access request acquisition module, configured to acquire a data access request, wherein the data access request contains unique identification information of a target user in a request initiating end and unique address information of a target accessed end; a user representation information acquisition module, configured to extract information representation dimension data corresponding to the target user in the request initiating end according to the unique identification information; an accessed data representation information acquisition module, configured to extract information representation dimension data corresponding to expected accessed data in the target accessed end according to the unique address information; a feature extraction module, configured to perform feature extraction on the information representation dimension data corresponding to the target user and the information representation dimension data corresponding to the expected accessed data in the target accessed end respectively by using a pre-constructed feature extraction model; a data access decision module, configured to decide whether to allow the target user to access the expected accessed data according to a feature extraction result output by the feature extraction model.
10. A computer device, comprising: comprising a memory and a processor, wherein the memory stores computer readable instructions, and the processor executes the computer readable instructions to realize the steps of the data access decision method according to any one of claims 1 to 8.
11. A computer readable storage medium, characterized in that, the computer readable storage medium stores computer readable instructions, and the computer readable instructions are executed by the processor to realize the steps of the data access decision method according to any one of claims 1 to 8.
Citation Information
Patent Citations
Data access method and device and equipment and storage medium
CN110569657A
Information access control method and device, computer equipment and medium
CN115203672A
Data access control method and device, equipment and storage medium
CN117216748A
Access control method and system for data security protection
CN119109614A
User authority management method and device
CN119760743A