Cross-department routing gateway and dynamic permission configuration method based on image recognition

By overlaying a context integrity watermark constellation onto the user interface and performing dynamic challenges, the routing gateway achieves real-time awareness of the user's screen context, solving the problem of information leakage in network access control and providing instant and reliable dynamic permission configuration.

CN121098635BActive Publication Date: 2026-02-03GUANGDONG HAUCI NETWORK TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202511640627.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-11-11
Publication Date
2026-02-03
Estimated Expiration
2045-11-11

AI Technical Summary

Technical Problem

Existing network access control mechanisms cannot perceive the user's screen context in real time, which leads to the risk of information leakage when data of different security levels are concurrently displayed in the same visual space, and existing technologies lack proactive prevention mechanisms.

Method used

By overlaying a contextual integrity watermark constellation onto the user interface, the routing gateway pauses access requests, generates a nature query code, the client encodes and presents the watermark, identifies the geometric relationship between the anchor point and the satellite watermark, and the routing gateway makes dynamic decisions based on permission rules.

Benefits of technology

It enables real-time awareness of network access control, prevents information leakage, ensures the immediacy and reliability of access decisions through multi-dimensional verification, resists screen image spoofing and partial occlusion, and provides dynamic permission configuration.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121098635B_ABST
    Figure CN121098635B_ABST
Patent Text Reader

Abstract

The application belongs to the technical field of electric digital data processing, and discloses a cross-department routing gateway and dynamic permission configuration method based on image recognition, which comprises the following steps: superimposedly displaying a watermark constellation on a user interface bearing first security bureau information; when receiving an access request for a second security bureau, the routing gateway suspends processing and sends an instruction containing a one-time challenge code; the client dynamically encodes the watermark according to the challenge code and collects a screen image; finally, the routing gateway makes a decision on the request according to the geometric relationship of the watermark constellation, the consistency of the decoded challenge code and the sent code, and a preset permission rule. The application associates the network access decision of the previous service permission verification in the background with the real-time and space-time dimension verified screen visual context of the user client by establishing a new linkage mechanism, and solves the security risk caused by the concurrent coexistence of different secret level information on the same screen.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application relates to an image recognition-based cross-department routing gateway and dynamic permission configuration method, and belongs to the technical field of electronic digital data processing. BACKGROUND

[0002] In the current networked digital information processing system, the core mechanism of permission management and access control technology is usually concentrated in the background or server, for example, verifying the identity of the access request, department signature and target resource strategy to decide to permit or refuse. This processing mode ensures the security of the call between the background microservice or departments, and has a clear effect on the security of single data exchange. However, with the application of graphical user interface and multi-task operating system, the user's work mode changes to parallel processing of information from different sources with different security levels in the same visual space. In the foregoing work mode, the inherent limitations of the data processing principle of isolating network requests are manifested. In this work mode, the inherent limitations of the data processing principle of isolating network requests begin to manifest when the user is processing a high-security local document while accessing another low-security local data through a network request. Even if each independent authorization verification meets the regulations, the coexistence of different security level information on the same screen provides a potential way for high-sensitive information leakage through screen capture or screen sharing.

[0003] To deal with such problems, the industry has adopted technologies such as comprehensive content monitoring or data leakage prevention for user terminals, but these solutions usually require the deployment of corresponding client software, occupy terminal computing resources, and determine risks through continuous analysis of screen display content. Their processing logic is relatively complex, and they do not solve the problem of separating access decisions from the real-time operation context in which they occur from the source of data processing, network access control. Analysis of existing technologies shows the following deficiencies: 1. The decision-making information dimension of data processing is single. When the network access control system makes authorization judgments, its basis is limited to the information carried by the network request, and there is a lack of data channel to obtain the actual work interface state of the user terminal in the mechanism; 2. The response to security risks is lagging. Existing security measures are mostly focused on tracing and blocking after the occurrence of information leakage behavior, and lack a data processing mechanism that actively prevents risks from the root of access authorization before the combination of operations that may lead to risks occurs.

[0004] Meanwhile, in the underlying image recognition technology used to achieve the aforementioned screen content monitoring, the research focus has deviated from the architecture-level linkage problem urgently needed for security control. For example, Chinese invention patent CN120339664A discloses a method and device for training an image recognition model, a vehicle, and electronic equipment. The core of this invention lies in configuring and calculating convolution kernels through dynamic generation functions. Its purpose is to optimize the model's ability to learn feature information in images, thereby improving the model's accuracy and robustness. However, such technological advancements are essentially about optimizing the feature extraction capability of image recognition algorithms, i.e., how to clearly see the image content. They do not and cannot solve the core problem that this invention aims to address, namely, how the network access control system (routing gateway) can perceive in real time whether there are visual contexts on the user's screen that should not be concurrent, and use this perception result as an immediate basis for access decisions. In other words, this type of technology improves the accuracy of recognition, but does not solve the architectural defect of separating access control decisions from real-time context. Therefore, the technical problem to be solved by this invention is how to establish a data processing linkage mechanism so that the network routing gateway can use the current screen visual context of the user terminal as a real-time judgment criterion when performing access decisions, so as to avoid potential information leakage caused by the concurrent data of cross-security bureaus at the visual level. Summary of the Invention

[0005] This invention provides a cross-departmental routing gateway and dynamic permission configuration method based on image recognition. Its main purpose is to solve the problem that existing network access control mechanisms cannot prevent the risk of visual concurrency of cross-security bureau data because they cannot perceive the real-time screen context of users.

[0006] To achieve the above objectives, the present invention provides a cross-departmental routing gateway and dynamic permission configuration method based on image recognition, the method comprising:

[0007] Step a, when a user interface element associated with the First Security Bureau is activated on a display device, a client agent overlays a first context integrity watermark constellation within the visible area of ​​the user interface element. The first context integrity watermark constellation includes an anchor watermark and one or more satellite watermarks, and the satellite watermarks and anchor watermarks have a preset geometric spatial relationship.

[0008] Step b: A routing gateway device receives a user's access request for a target resource associated with the second security bureau;

[0009] In step c, in response to the access request, the routing gateway does not immediately process the request based on the background credentials, but suspends the processing of the access request and generates a first-order nature query code, and then sends a context challenge instruction containing the first-order nature query code to the client agent.

[0010] In step d, the client agent responds to the context challenge instruction, dynamically encodes the information of the challenge code based on the received first nature challenge code, and presents it in the first context integrity watermark constellation. Then, it performs an image acquisition of the current display content of the display device to obtain the current screen image.

[0011] Step e: In the current screen image, simultaneously identify anchor watermark and one or more satellite watermarks, verify whether the geometric spatial relationship between satellite watermark and anchor watermark conforms to the preset, and decode the challenge code information encoded in the first context integrity watermark constellation.

[0012] Step f: After confirming that the decoded challenge code information is consistent with the first challenge code and that the geometric spatial relationship conforms to the preset, the routing gateway makes a final dynamic decision on the suspended access request based on a preset permission rule that defines the compatibility relationship between the first security bureau and the second security bureau.

[0013] Preferably, the preset geometric spatial relationship is dynamically defined relative to one or more logical structure anchor points of the user interface element; and the method further includes: when a change in the layout or size of the user interface element is detected, in response to the change, recalculating and adjusting the display position of the anchor watermark and one or more satellite watermarks on the screen to maintain the dynamically defined geometric spatial relationship with one or more logical structure anchor points.

[0014] Preferably, the first context integrity watermark constellation is a structured cursor pattern that encodes information from the corresponding first security bureau.

[0015] Preferably, the method further includes: starting a debouncing timer after receiving an event indicating a change in the layout or size of a user interface element; and triggering recalculation and adjustment only if no new layout or size change event is received within a preset debouncing timeout period.

[0016] Preferably, the client agent displays the first context integrity watermark constellation overlaid within the visible area of ​​the user interface element by displaying it in a semi-transparent manner.

[0017] Preferably, the first security bureau and the second security bureau are two different security bureaus; the preset permission rules define the first security bureau and the second security bureau as incompatible.

[0018] Preferably, the rule for determining the image stabilization timeout is as follows: in, Anti-shake timeout period; It is a basic timeout constant; The frequency of layout or size change events received per unit time; This is a sensitivity coefficient, the value of which is determined according to a preset rule that maps the level of the first security bureau to the corresponding coefficient.

[0019] Preferably, in step a, the client agent is a program that runs at the operating system level, which displays the first context integrity watermark constellation by overlaying it on the top-level window of the user interface element. This display process does not change the content of the user interface element itself.

[0020] Preferably, after the routing gateway performs dynamic decision-making in step f, if the decision result is rejection, it returns a warning message to the user. The warning message contains conflict information between the first security bureau and the second security bureau that caused the rejection.

[0021] Compared with the prior art, the beneficial effects of the present invention are:

[0022] 1. The present invention establishes a data processing method in which the network routing gateway's access decision for target resources no longer relies solely on the static correspondence between user identity and requested resources. Instead, it establishes a direct and immediate logical association with the current screen image content of the user client. When an access request is received, the gateway does not process it immediately but actively sends a contextual challenge instruction to the client. Based on the result of the client's collection and recognition of the current screen image and the presence or absence of a specific contextual integrity watermark, the gateway ultimately decides whether to grant or deny the access request. This processing flow transforms an isolated network access event into a closed-loop data processing process that must be verified by the user's real-time working interface status, enabling the configuration of access permissions to have real-time awareness of the user's operating environment.

[0023] 2. By designing the context integrity watermark as a constellation containing anchor watermarks and one or more satellite watermarks, and establishing a preset geometric spatial relationship between these watermarks, the client's task when responding to queries and performing identification is no longer to determine the presence or absence of a single watermark, but to simultaneously identify the complete constellation structure and verify whether its geometric relationship conforms to the preset. This deepens the verification of screen context from a single-point Boolean judgment to a verification of the integrity of the spatial structure. Any partial occlusion or cropping of the user interface carrying the watermark will directly destroy the preset geometric relationship, leading to verification failure. Thus, the context verification process itself has the ability to resist the physical incompleteness of user interface elements, and the reliability of its judgment result is no longer limited to the visibility state of a single visual mark.

[0024] 3. Based on the constellation verification mentioned above, a primary challenge code is generated by the gateway when issuing a challenge command. The client dynamically encodes this challenge code and displays its information in the watermark. This requires the client to decode the challenge code from the watermark and compare it with the original challenge code issued by the gateway when performing image recognition. This mechanism binds the gateway's challenge action with the client's screen image evidence in the time dimension. Any attempt to deceive with outdated screen images will fail because the dynamically encoded information corresponding to the current challenge command cannot be presented. Ultimately, a multi-dimensional access adjudication system integrating user identity, target resources, screen content spatial integrity, and temporal authenticity is formed. When processing each data request, it completes a comprehensive confirmation of the authenticity, integrity, and timeliness of the user's current working status. Attached Figure Description

[0025] Fig. 1 This is a flowchart illustrating the closed-loop processing of dynamic access control and contextual challenge in this invention.

[0026] Fig. 2 This is a comparison chart showing the recognition accuracy of constellation verification and single-point watermark under interface occlusion in this invention.

[0027] Fig. 3 This is a diagram of the architecture of the strategy-driven dynamic access control system of the present invention. Detailed Implementation

[0028] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this invention, not all embodiments. Based on the embodiments of this invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this invention.

[0029] The cross-departmental routing gateway and dynamic permission configuration method based on image recognition claimed in this invention comprises a data processing architecture consisting of a client agent program deployed on the user terminal device and a routing management device deployed at the network boundary. This method establishes a closed-loop data processing flow including in-transit request pause, contextual challenge, dynamic beacon response, and multi-dimensional verification and adjudication. It expands the decision-making basis for network access control from a single network request information to include the real-time, spatiotemporally verified screen visual context of the user terminal. Its operation includes the generation and dynamic injection of contextual integrity watermark constellations and the encryption of in-transit requests by the routing gateway. The process involves stages such as inquiry, real-time acquisition and spatiotemporal feature verification of screen images by the client, and final dynamic adjudication by the routing gateway based on multi-dimensional verification results. In one application scenario, to mitigate the risk of cross-security bureau data visual concurrency caused by multi-tasking operations, a mechanism is needed to enable the network access control system to obtain the screen state of the user terminal. Therefore, the method of this invention first classifies information assets, i.e., defines security bureaus. For example, the core terms document of the A project merger case belongs to the first security bureau and is set to a high security level, while the public market financial database belongs to the second security bureau. Based on the security policy, a rule is preset in the rule base of the routing gateway. The restriction rule is used to define an incompatible relationship between the first security bureau and the second security bureau. When a user interface element associated with the first security bureau, such as an application window displaying Project A's document, is activated on the display device, a client agent running at the operating system level is triggered accordingly. This client agent, according to a preset configuration, displays a first context integrity watermark constellation within the visible area of ​​the user interface element by overlaying it semi-transparently in a top-level window. This process does not change the content of the user interface element itself. The first context integrity watermark constellation is a structured cursor pattern optimized for machine vision. The system encodes the information of the corresponding first security bureau through pixel arrangement. To cope with possible partial occlusion or cropping operations in the user interface, the first context integrity watermark constellation is designed to include a main anchor watermark and one or more satellite watermarks. There is a preset geometric spatial relationship between the satellite watermark and the anchor watermark. For example, the center coordinates of the satellite watermark are defined as a fixed vector offset of the center coordinates of the anchor watermark in the screen coordinate system, such as (X+100 pixels, Y-50 pixels). In this way, the verification of the screen context changes from judging the presence or absence of a single mark to verifying the integrity of the preset geometric configuration of the entire constellation.

[0030] With the watermarked Project A document window open, when a user initiates a data access request that requires passage through the routing gateway—for example, attempting to access a financial database belonging to the Second Security Bureau—the routing gateway device, upon receiving the request, pauses its processing to allow time for data interaction to acquire the screen context information needed for decision-making. To ensure the temporal authenticity of the acquired screen context information and defend against evidence replay attacks using outdated screenshots, the routing gateway generates a one-time challenge code after pausing the request. This challenge code can be implemented using a pseudo-random number generation algorithm seeded by the current high-precision timestamp and the request session ID, for example, generating a 128-bit random string. Subsequently, the routing gateway sends this information to the client proxy on the user's terminal that initiated the request. The program sends a context challenge command containing the first-order challenge code. After receiving and parsing the context challenge command, the client agent program, in order to time-bind the current screen snapshot with the gateway's challenge action, first dynamically encodes the information of the challenge code based on the received first-order challenge code and presents it in the first context integrity watermark constellation. This encoding process is a deterministic mapping procedure. For example, the 128-bit challenge code is divided into 16 8-bit bytes. The value of each byte (0-255) is used to assign a color to the corresponding pixel block of a 16-pixel core area inside the anchor watermark from a preset 256-color lookup table. After the dynamic encoding and rendering of the watermark is completed, the client agent program performs an image capture of the current display content of the display device to obtain the current screen image.

[0031] After acquiring the current screen image containing the dynamically encoded watermark, the client agent processes the image data to extract structured contextual evidence. To reduce computational resource consumption, this processing and recognition process is limited to matching the preset pattern of the first context integrity watermark constellation, rather than performing content recognition on the entire current screen image. This recognition process is implemented through a two-stage algorithmic path. The first step, anchor point localization, uses a template matching algorithm based on normalized cross-correlation coefficients to search for and locate the anchor watermark's position coordinates in the current screen image. The second step, constellation and encoding verification, involves the algorithm verifying the simultaneous presence of all satellite watermarks at the expected relative coordinate positions based on preset geometric spatial relationships. If the constellation structure is complete, the encoded challenge code information is further decoded from the 16-pixel core region of the anchor watermark and then... The decoded security bureau ID, challenge code information, and constellation geometric relationship verification status are packaged into a response data packet and sent back to the routing gateway. Upon receiving the response data packet, the routing gateway enters the final dynamic adjudication stage. Its adjudication logic is a multi-AND logic gate with a strict order. First, the routing gateway confirms that the decoded challenge code information is consistent with the challenge code it issued and temporarily stored to verify the timeliness of the evidence, and confirms that the geometric spatial relationship conforms to the preset to verify the spatial integrity of the evidence. After both of these preconditions are met, the gateway then makes a final dynamic adjudication on the suspended access request based on the rule in the preset permission rule base that defines the relationship between the first security bureau and the second security bureau as incompatible. Since the first security bureau on the screen conflicts with the requested second security bureau, the adjudication result is rejection, and the gateway then returns a warning message to the user containing the conflict domain information that caused the rejection.

[0032] To adapt to dynamic changes in window size and layout within the graphical user interface (GUI), and to prevent the default rigid geometric relationships from failing due to normal user scaling or reflow operations, the default geometric spatial relationships are dynamically defined relative to one or more logical structure anchor points of user interface elements. These logical structure anchor points are not absolute pixel coordinates, but rather refer to interface logical objects that can be identified through the UI automation interface, such as the close button in the window title bar or the lower right page number area of ​​a document. When the client agent detects an event from the operating system indicating a change in the layout or size of a user interface element, it responds by re-querying the latest screen coordinates of each logical structure anchor point and recalculating and adjusting the display positions of the anchor watermark and one or more satellite watermarks on the screen to dynamically maintain... The method maintains a dynamically defined geometric spatial relationship with one or more logical structure anchor points. Furthermore, to address the UI event storm that may be triggered when users perform continuous and rapid window dragging operations, and to avoid system performance issues caused by high-frequency triggering of the aforementioned recalculation and adjustment logic, this method also introduces a throttling mechanism. Upon receiving an event indicating a change in the layout or size of a user interface element, the client agent does not immediately perform a recalculation. Instead, it starts or resets a debouncing timer with a preset debouncing timeout, such as 100ms. A recalculation and adjustment is only triggered if no new layout or size change event is received within this timeout. The specific value of this debouncing timeout can be configured using a dynamic calculation formula. ,in, Anti-shake timeout period; Set a basic timeout constant, such as 50ms; The frequency of layout or size change events received per unit time; This is a sensitivity coefficient, the value of which is determined according to a preset rule that maps the security level of the first security bureau to a corresponding coefficient. The higher the security level, the higher the coefficient. The smaller the value, the more it ensures that the watermark reconstruction operation is performed only once after the user interface layout is stable.

[0033] Example 1: This example is a specific operational instance of the method described above. In a clinical setting of a large teaching hospital, an attending physician with high-level data access reviews a highly sensitive electronic medical record (EHR) and gene sequencing report for a specific patient, belonging to the First Security Bureau, on their terminal device. According to a specific implementation, the client agent program displays a first contextual integrity watermark constellation corresponding to the First Security Bureau in a semi-transparent manner overlaid within the visible area of ​​the medical record window. For clinical research comparison, the physician needs to refer to an anonymized clinical research database stored on the hospital's internal server, which belongs to the Second Security Bureau. Although the data has been anonymized, access remains strictly controlled due to the large-scale population statistics involved. While keeping the medical records of highly sensitive patients open, the physician initiated an access request to the research database. This request was intercepted by the routing gateway device. According to the data processing flow of the present invention, the routing gateway recognized that this request required context verification, so it suspended the processing of the access request and generated a one-time challenge code, such as Ax78B-9vK2c. Subsequently, it sent a context challenge instruction containing this challenge code to the physician's client agent program. This intervention of the suspension challenge mechanism shifted the decision-making basis for data processing from static identity permissions to dynamic operational context.

[0034] Upon receiving the context challenge instruction, the client agent does not immediately perform screen capture. Instead, it first dynamically encodes the challenge code Ax78B-9vK2c contained in the instruction using a deterministic mapping procedure and presents it on the already displayed first context integrity watermark constellation on the screen. For example, it changes the color combination of specific pixel blocks within the anchor watermark. Only after completing the real-time rendering of this dynamic beacon does the client agent perform screen image capture. Subsequently, in the captured screen image, the client agent not only needs to verify the integrity of the preset geometric spatial relationship between the anchor watermark and the satellite watermark of the first context integrity watermark constellation, but also needs to successfully decode the encoded challenge code information from the constellation. This dual-dimensional verification mechanism of space and time works synergistically. The geometric integrity check of the watermark constellation is used to address the problem that single-point watermark recognition may fail due to unintentional user occlusion of the window, while the dynamic encoding and decoding comparison of the first-order challenge code ensures the immediacy of the screen image evidence. The system uses real-time data processing to eliminate the possibility of bypassing permissions using outdated screenshots. Finally, the client proxy returns the structured result—generating a valid geometric relationship, a security bureau ID of the first security bureau, and a decoded challenge code of Ax78B-9vK2c—to the routing gateway. The routing gateway, after confirming that the decoded challenge code matches its own and that the geometric relationship is valid, proceeds with the permission decision. Based on the pre-defined rule in its rulebase that the first security bureau (highly sensitive identifiable patient data) and the second security bureau (anonymized research data) are incompatible, it dynamically rejects the access request and sends a message to the user that the operation is prohibited. Through this closed-loop data processing, a potential information leakage or data compliance risk arising from the coexistence of highly identifiable sensitive patient information and large-scale anonymized data in a single visual space is proactively prevented at the source of data access authorization. The system no longer passively audits already occurring operations but prevents a risky combination of operations from forming by altering the data processing flow.

[0035] Example 2: To objectively verify the effectiveness of the method of the present invention in dynamically adjudicating cross-security bureau access requests under different operating scenarios, this example designed and executed a set of comparative experiments. The experimental platform consisted of a user terminal configured with an Intel Core i7 processor, 16GB of memory, and running the Windows 10 operating system, and a server acting as a routing gateway device. The two were connected via a 1Gbps Ethernet. A client agent program was deployed on the user terminal, and the corresponding access control and challenge logic was deployed on the routing gateway device. In the experiment, a first security bureau and a second security bureau were defined, and incompatible permission rules were preset in the routing gateway. The experiment set up a control group and an experimental group. The control group adopted a simplified verification method, that is, the client only identified whether there was a static ordinary watermark associated with the first security bureau on the screen, without performing the watermark constellation geometric relationship verification and one property query code verification of the present invention. The experimental group adopted the method of the present invention in its entirety. The experiment simulated four operating or attack scenarios and recorded the final adjudication result of the routing gateway for the request to access the second security bureau. The specific experimental conditions and data are shown in Table 1.

[0036] Table 1: Comparison of adjudication results under different scenarios.

[0037]

[0038] Analysis of Table 1 shows that in Scenario 1, both test groups were able to identify incompatible contexts and reject access requests. In Scenario 2, when the window carrying the watermark was partially obscured, the static watermark recognition algorithm of the control group could still match the visible part of the watermark, thus determining the context was valid and granting access. However, the experimental group rejected the request because the satellite watermark was obscured, disrupting the preset geometric spatial relationship and causing the geometric relationship verification to fail. In Scenario 3, the control group granted access to a forged security screenshot because it did not contain a watermark, while the experimental group's routing gateway issued a single-propagation query code that could not obtain the correct encoded response in the forged screenshot, leading to... The client returned an inconsistent challenge code verification result, and the access request was therefore rejected. The results of scenario four show that the method of the present invention will not hinder the user's normal access under normal operation without security conflicts. Experimental data shows that the experimental group using the method of the present invention can handle the situation where the user interface elements are physically incomplete through the geometric relationship verification of the first scenario integrity watermark constellation, and can identify and prevent deceptive behavior based on old image evidence through the timeliness verification mechanism of a single property challenge code. Compared with the control group that only relies on static watermark recognition, the method of the present invention has higher adjudication accuracy in complex and adversarial scenarios.

[0039] To further verify, from the system architecture level, the closed-loop data processing flow of in-transit request pause, context challenge, dynamic beacon response, and multi-dimensional verification decision adopted in this invention, and its non-obvious technical advantages in security and reliability compared to a conventional technical path in the field that relies on the client to actively report the status, the following comparative example 1 is set up.

[0040] Comparative Example 1: This comparative example uses the same test platform as the aforementioned embodiments, including a user terminal and a routing gateway device. The core difference is that Comparative Example 1 adopts a conventional technical path that is easily conceived by those skilled in the art and has a simpler architecture, namely, a client-initiated reporting mechanism, to replace the gateway-initiated challenge mechanism of this invention. In this conventional technical path, the processing logic is modified as follows: the client agent is configured to continuously monitor the window at the operating system level. When it detects that an application window belonging to the First Security Bureau is activated, it sets a high-security context state flag locally. When the user initiates any network access request through the routing gateway, the client agent (not the gateway) proactively appends a custom static header to the HTTP request. For example, X-Context-Security:Domain-1-Active; the access control logic on the routing gateway device is simplified accordingly. It no longer has the function of actively initiating context challenges or verifying one-time nature queries. Its permission rule base is configured as a passive trust logic: when an access request for the second security bureau is received, it checks whether the request contains the X-Context-Security header. If it contains the header and the rule is defined as incompatible, access is denied; if it does not contain the header, it is considered that the client context is secure and permission is granted. To verify the effectiveness of this conventional technical path in adversarial scenarios, a test sequence containing 5,000 access requests was designed to simulate three operating scenarios. The adjudication results are shown in Table 2.

[0041] Table 2: Adjudication results of conventional technical approaches (client-initiated reporting) in different scenarios.

[0042]

[0043] Table 2 clearly shows that under normal operation in Scenario 1 and Scenario 2, the client-initiated reporting of the conventional technical path can correctly execute the preset access control. However, in Scenario 3 (local header tampering attack), because the adjudication basis of this architecture relies entirely on a static information (HTTP header) provided unilaterally by the client and easily tampered with, its systemic security flaws are completely exposed. The routing gateway, failing to receive the X-Context-Security header, incorrectly treats this high-risk cross-domain access request as a normal compatible access and grants permission based on its passive trust rules, leading to the adjudication... The accuracy rate dropped to 0%; the experimental results of this comparative model objectively confirm that any access control architecture that relies on the client to actively report the context state has a fundamental flaw in terms of security and trustworthiness. It cannot resist man-in-the-middle tampering from the user terminal side (even if the report is genuine). In contrast, the closed-loop challenge mechanism adopted by this invention, which is initiated by the routing gateway as the trusted party, contains a single nature query code, and requires the client to dynamically encode the response, has a non-obvious design principle in that it establishes a time-bound verification channel that cannot be statically tampered with or replayed, thereby avoiding passive dependence on untrusted clients in terms of mechanism.

[0044] Example 3: This example combines Figs. 1 to 3 This section describes the cross-departmental routing gateway and dynamic permission configuration method based on image recognition, such as... Fig. 1 As shown, after the access request is received by the routing gateway, a parallel closed-loop challenge and adjudication process is triggered. The routing gateway performs in-transit request pause and context challenge, actively probing the client's state by generating a nature query code and sending a challenge command. The client responds by dynamically encoding a watermark and capturing the screen, displaying the challenge information in the watermark in real time. Subsequently, screen image analysis and spatiotemporal feature verification are performed to check the constellation geometric relationship and decode the challenge code. The verification result is returned to the routing gateway. After receiving the verification result, the routing gateway enters the multi-dimensional verification and dynamic adjudication stage, which comprehensively judges the time, space, and permission rules. If the verification passes and there is no incompatibility, permission is requested. If the verification fails or there is incompatibility, permission is requested. At the same time, to cope with the dynamic changes of the user interface, an interface dynamic adaptation module responds to UI layout changes, recalculates and adjusts the watermark position, and uses a debouncing timer to avoid performance issues caused by high-frequency UI events.

[0045] like Fig. 2As shown in the figure, the horizontal axis represents the interface occlusion ratio, ranging from 0% to 60%, and the vertical axis represents the recognition accuracy, ranging from 0% to 100%. The figure shows a comparison of three curves. The solid curve representing the constellation verification method of this invention can maintain a recognition accuracy of about 80% even when the occlusion ratio reaches 50%, which is significantly higher than the dotted-line curve representing the single-point watermark recognition method. The latter's accuracy drops below 30% under the same occlusion ratio, and both are better than the theoretical lower limit shown by the dashed line. This data shows that by verifying the geometric integrity of the watermark constellation, it is possible to resist recognition failure caused by partial occlusion of interface elements.

[0046] like Fig. 3 As shown, the architecture consists of four core entities: a policy management server, user terminal devices, a routing gateway device, and a target resource server. The policy management console within the policy management server is responsible for generating policies and distributing incompatible rules to the permission rule base of the routing gateway device via the policy distribution path. Simultaneously, it distributes client configurations to the client configuration files on the user terminal devices. The client agent program deployed on the user terminal devices injects watermarks based on the configuration when it detects the activation of a high-security application. When a user initiates an access request, the request is intercepted by the routing gateway device. Its internal access control and challenge logic module interacts with the client agent program through contextual challenge / response interactions, and adjudicates the request based on the permission rule base. Finally, the adjudicated access request is forwarded to the target resource server, such as a database storing financial data.

[0047] Example 4: This example provides a standardized calibration procedure for key parameters in the first context integrity watermark constellation recognition process. In a pre-deployment calibration scenario, a technical challenge is determining a unified template matching threshold and geometric tolerance for a client agent program to be deployed to various display resolutions and color settings, in order to ensure recognition rate while controlling the false positive rate within a preset level. To address this challenge, the system employs an offline, procedural calibration process executed in a standardized test environment. This environment includes a reference-grade display capable of displaying 24-bit true color and calibration software for automating the process. The calibration software first loads all predefined template images of the first context integrity watermark constellation, initially defined as uncompressed bitmap images. After calibration... The first step in the process is data acquisition. The calibration software performs 1000 iterations in a loop. In each iteration, it randomly selects a background color and an overlay transparency within a preset range (e.g., 70% to 95%). Then, it renders a randomly selected watermark constellation image on this background and immediately performs a screen image acquisition, thus obtaining 1000 sample images with different visual interferences, but all of which are valid watermarks. After data acquisition, the calibration process enters the parameter calculation stage. First, regarding the determination of the template matching threshold, the program executes a template matching algorithm based on normalized cross-correlation coefficients on each of these 1000 sample images to locate the anchor watermark and records the normalized cross-correlation value of each successful match, thereby obtaining a sample dataset containing 1000 matching scores. Subsequently, the mean of this dataset is calculated. with standard deviation In this embodiment, the mean is calculated. The standard deviation is 0.92. The final template matching threshold is 0.03. It is set as the mean minus three standard deviations, i.e. .

[0048] Secondly, regarding the determination of geometric relationship tolerance, when processing these 1000 sample images, the program determines the anchor point watermark coordinates each time. At the same time, it will also locate the coordinates of all satellite watermarks. And calculate the actual relative coordinate vector. The program will compare the actual vector with the theoretical vector defined by the preset geometric spatial relationship. By comparing the two, the Euclidean distance between them, i.e., the positional deviation, is calculated. After completing the calculations for all samples, a dataset containing 1000 positional deviation values ​​is obtained. This dataset is sorted, and the value of the 999th percentile (3.7 pixels in this embodiment) is taken as the tolerance radius for geometric relationship verification. This value is then rounded down to 4 pixels. Through this procedure, the client agent program, during actual runtime, can determine that the geometric spatial relationship conforms to the preset value as long as the relative positional deviation between the detected satellite watermark and the anchor watermark is no greater than 4 pixels. The final output of this calibration process is a value containing the template matching threshold. Geometric relationship tolerance radius A configuration file for key parameters such as pixels; this file is then distributed and applied to all client agents to be deployed. This process provides a method for setting parameters in the recognition algorithm that were previously set based on experience through standardized experiments and statistical analysis, so that the recognition performance of the method of the present invention is consistent and reproducible in different hardware and software environments.

[0049] Example 5: This example aims to provide a specific engineering procedure for the establishment and deployment of security bureaus and preset permission rules. In a scenario where an enterprise is deploying the method of this invention for the first time, the enterprise's existing information security level classification and departmental access policies need to be transformed into a policy set executable by the method of this invention, consisting of a routing gateway rule base and client configuration files. To this end, the system administrator configures the policy through a policy management control panel deployed on the server. In the interface provided by the control panel, the administrator first creates and names each security bureau, such as the first security bureau - R&D core and the second security bureau - market data. Subsequently, the system displays all created security bureaus in the form of a matrix. The administrator defines whether any two security bureaus are incompatible by checking the checkboxes at the intersection of rows and columns in the matrix. The configuration results of this series of operations are saved in the rule base of the routing gateway as the basis for executing the final dynamic decision.

[0050] After defining the incompatibility rules at the routing gateway level, the administrator also needs to specify which user interface elements should be watermarked for the client agent. To do this, in the same interface of the policy management console, the administrator needs to associate one or more application or document identifiers with each created security bureau. These identifiers can be the process name of an application, the storage path pattern of a specific document, or the window title of a user interface element. When the administrator completes all configurations and confirms deployment, the policy management console generates two independent configuration files. One contains an incompatibility relationship matrix, which is distributed to the routing gateway device. The other contains a list of mappings between security bureaus and application identifiers, which is distributed to all user terminals in the network and loaded by the client agent. This procedure ensures that the logic of network access adjudication and the visual beacon injection on the terminal side originate from the same centrally managed and synchronously updated security policy, thereby providing a consistent and maintainable data foundation for the operation of the entire system.

[0051] Example 6: This example aims to provide a specific parameter calibration and fault-tolerant handling procedure for the dejitter timeout parameters related to dynamic changes in user interface elements, as well as for abnormal situations during contextual challenge communication. During system deployment, to balance the timeliness of the client agent's response to interface changes with the terminal's computational resource consumption, the dejitter timeout formula needs to be adjusted. The basic timeout constant in and sensitivity coefficient For calibration, in a benchmark environment, an automated script simulated a user continuously dragging and resizing a window within 5 seconds, recording the timestamps of all layout change events. Analyzing this dataset, the 95th percentile of the continuous event time interval was calculated to be 45ms. To allow for processing margins, the base timeout constant was... The sensitivity coefficient was set to 50ms. The value is determined according to a preset rule that maps security bureau levels to response priorities. For high-security bureaus, a smaller value is set. A value is set to reduce the effect of high-frequency events on extending the timeout period; conversely, a larger value is set for low-frequency events. value.

[0052] To address potential network latency or communication interruptions between the routing gateway and client agent during actual operation, the data processing flow of this invention incorporates a timeout-based fault tolerance mechanism. When the routing gateway sends a context challenge command containing a challenge code to the client agent, it simultaneously starts an independent challenge timer. The timeout threshold of this timer, i.e., the challenge timeout, is set to a fixed value, 500ms in this embodiment. This value is set because it is greater than the total time required for a challenge response data round trip and client processing under normal network conditions. If, within this challenge timeout period, the routing gateway fails to receive a valid response containing a decoded challenge code consistent with the sent code, regardless of the cause—network packet loss, client agent non-response, or any other anomaly—the challenge timer will trigger a default failure security decision. This automatically rejects the suspended access request and returns a specific warning message to the user indicating client status verification failure. This procedure ensures that the system's access control behavior remains secure even when the communication link is unreliable.

[0053] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention.

[0054] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention.

Claims

1. A cross-departmental routing gateway and dynamic permission configuration method based on image recognition, characterized in that, The method includes: Step a, when a user interface element associated with the First Security Bureau is activated on a display device, a client agent overlays a first context integrity watermark constellation within the visible area of ​​the user interface element. The first context integrity watermark constellation includes an anchor watermark and one or more satellite watermarks, and the satellite watermarks and anchor watermarks have a preset geometric spatial relationship. Step b: A routing gateway device receives a user's access request for a target resource associated with the second security bureau; In step c, in response to the access request, the routing gateway does not immediately process the request based on the background credentials, but suspends the processing of the access request and generates a first-order nature query code, and then sends a context challenge instruction containing the first-order nature query code to the client agent. In step d, the client agent responds to the context challenge instruction, dynamically encodes the information of the challenge code based on the received first nature challenge code, and presents it in the first context integrity watermark constellation. Then, it performs an image acquisition of the current display content of the display device to obtain the current screen image. Step e: In the current screen image, simultaneously identify anchor watermark and one or more satellite watermarks, verify whether the geometric spatial relationship between satellite watermark and anchor watermark conforms to the preset, and decode the challenge code information encoded in the first context integrity watermark constellation. Step f: After confirming that the decoded challenge code information is consistent with the first challenge code and that the geometric spatial relationship conforms to the preset, the routing gateway makes a final dynamic decision on the suspended access request based on a preset permission rule that defines the compatibility relationship between the first security bureau and the second security bureau.

2. The method for cross-departmental routing gateway and dynamic permission configuration based on image recognition according to claim 1, characterized in that, The preset geometric spatial relationships are dynamically defined relative to one or more logical structural anchor points of the user interface elements; and the method also includes: when a change in the layout or size of a user interface element is detected, in response to the change, recalculating and adjusting the display positions of the anchor watermark and one or more satellite watermarks on the screen.

3. The method for cross-departmental routing gateway and dynamic permission configuration based on image recognition according to claim 1, characterized in that, The First Context Integrity Watermark Constellation is a structured cursor pattern that encodes information from the First Security Bureau it corresponds to.

4. The method for cross-departmental routing gateway and dynamic permission configuration based on image recognition according to claim 2, characterized in that, The method also includes: starting a debouncing timer after receiving an event that the layout or size of a user interface element has changed; and triggering recalculation and adjustment only if no new layout or size change event is received within a preset debouncing timeout period.

5. The method for cross-departmental routing gateway and dynamic permission configuration based on image recognition according to claim 1, characterized in that, The client agent overlays the first context integrity watermark constellation within the visible area of ​​the user interface element by displaying it in a semi-transparent manner.

6. The method for cross-departmental routing gateway and dynamic permission configuration based on image recognition according to claim 1, characterized in that, The First Security Bureau and the Second Security Bureau are two different security bureaus; the default permission rules define the First Security Bureau and the Second Security Bureau as incompatible.

7. The method for cross-departmental routing gateway and dynamic permission configuration based on image recognition according to claim 4, characterized in that, The rules for determining the image stabilization timeout period are as follows: in, Anti-shake timeout period; It is a basic timeout constant; The frequency of layout or size change events received per unit time; This is a sensitivity coefficient, the value of which is determined according to a preset rule that maps the level of the first security bureau to the corresponding coefficient.

8. The method for cross-departmental routing gateway and dynamic permission configuration based on image recognition according to claim 1, characterized in that, In step a, the client agent is a program that runs at the operating system level and displays the first context integrity watermark constellation by overlaying it on the top-level window of the user interface element.

9. The method for cross-departmental routing gateway and dynamic permission configuration based on image recognition according to claim 1, characterized in that, After the routing gateway makes a dynamic decision in step f, if the decision result is a rejection, it returns a warning message to the user. The warning message contains conflict information between the first security bureau and the second security bureau that caused the rejection.

Citation Information

Patent Citations

  • Image recognition model training method and device, vehicle and electronic equipment

    CN120339664A

  • Role-and-attribute-based cross-domain secure switch access control method of integrated network

    CN106572116A

  • Multi-dimensional data authority management and privacy protection method for electric power information network

    CN119538276A