Secret data security management system and method based on role access control

By using a role-based access control-based confidential data security management system, combined with multi-factor authentication and access anomaly detection, access control policies are dynamically adjusted, solving the problem of access control policies being unable to adapt and improving data security and access flexibility.

CN121333740APending Publication Date: 2026-01-13SHANDONG YAZE INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511605947.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-05
Publication Date
2026-01-13

AI Technical Summary

Technical Problem

The lack of a joint modeling mechanism for user roles, access contexts, and data sensitivity in existing technologies results in access control policies being unable to adaptively adjust to dynamic environmental changes, affecting the ability to manage confidential data in a refined manner and provide real-time protection under a multi-level security system.

Method used

A role-based access control-based confidential data security management system is adopted. Through multi-factor authentication, RBAC model, real-time access anomaly detection and access anomaly detection graph construction, access control policies are dynamically adjusted, and an access control risk prediction model is used for multi-party optimization to achieve adaptive access control management.

Benefits of technology

It achieves improved access flexibility and system adaptive protection capabilities while ensuring data security, enabling refined management and real-time protection based on dynamic environmental changes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121333740A_ABST
    Figure CN121333740A_ABST
Patent Text Reader

Abstract

The invention provides a confidential data security management system and method based on role access control, and relates to the technical field of digital information transmission, and the system comprises a result generation module which generates a user identity authentication result through a multi-factor authentication mechanism; the strategy obtaining module carries out role access control analysis on the user; the graph construction module performs real-time access anomaly detection on the user; the space obtaining module dynamically adjusts the user access control strategy; the optimization domain obtaining module performs multi-party optimization on the access control adjustment space; and the result obtaining module guides the access control adjustment space to carry out variation collaborative optimization to obtain an access adjustment optimization result. According to the method and the device, the technical problem of relatively low security management quality of the confidential data in the prior art can be solved, and the technical effect of improving the security management quality of the confidential data is achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of digital information transmission technology, and in particular to a confidential data security management system and method based on role-based access control. Background Technology

[0002] With the continuous deepening of information technology construction and the accelerated advancement of enterprise digital transformation, more and more business data are being centrally stored and shared for access, resulting in a large amount of confidential information being transmitted and used in the network environment.

[0003] Currently, traditional access control methods mainly include discretionary access control and mandatory access control. Discretionary access control relies on users actively setting resource access permissions, while mandatory access control is based on security labels and security levels for systematic control. However, in complex real-world environments with multiple users, multiple systems, and multiple scenarios, these two methods often struggle to balance flexibility and security, leading to problems such as coarse permission division, insufficient access granularity, and delayed authorization updates, making them unsuitable for dynamic security requirements.

[0004] In summary, existing technologies suffer from a lack of a joint modeling mechanism for user roles, access contexts, and data sensitivity. This results in access control policies being unable to adaptively adjust to dynamic environmental changes, further impacting the refined management and real-time protection capabilities of confidential data within a multi-level security system. Summary of the Invention

[0005] The purpose of this application is to provide a role-based access control-based confidential data security management system and method to solve the technical problem in the prior art that the lack of a joint modeling mechanism for user roles, access context and data sensitivity leads to the inability of access control policies to adaptively adjust according to dynamic environmental changes, which further affects the fine-grained management and real-time protection capabilities of confidential data in a multi-level security system.

[0006] In view of the above problems, this application provides a confidential data security management system and method based on role-based access control.

[0007] Firstly, this application provides a role-based access control (RBAC)-based confidential data security management system, comprising: a result generation module, used to generate a user authentication result through a multi-factor authentication mechanism when a user sends an access request to the confidential data platform; a policy acquisition module, used to call the RBAC model to perform role-based access control parsing on the user based on the user authentication result, and obtain a user access control policy; a graph construction module, used to perform real-time access anomaly detection on the user based on the user access control policy and the access request, and construct an access anomaly detection graph; a space acquisition module, used to dynamically adjust the user access control policy according to the access anomaly detection graph, and obtain an access control adjustment space; an optimization domain acquisition module, used to perform multi-party optimization on the access control adjustment space according to an access control risk prediction model, and obtain an access adjustment multi-party optimization domain; and a result acquisition module, used to guide the access control adjustment space to perform variant collaborative optimization according to the access adjustment multi-party optimization domain, and obtain an access adjustment optimization result.

[0008] Preferably, the role-based access control-based confidential data security management system is further configured with: a real-time access log acquisition unit, configured to acquire the user's real-time access logs, the real-time access logs including data field access logs, functional module access logs, operation behavior logs, and access environment logs; a first access anomaly detection result acquisition unit, configured to perform multi-dimensional anomaly detection on the data field access logs based on the user access control policy and the access request, and obtain a first access anomaly detection result; and a second access anomaly detection result acquisition unit, configured to perform multi-dimensional anomaly detection on the functional module access logs based on the user access control policy and the access request, and obtain a second access anomaly detection result. The system includes a second access anomaly detection unit, a third access anomaly detection result acquisition unit, and a fourth access anomaly detection result acquisition unit. The third access anomaly detection result acquisition unit performs multi-dimensional anomaly detection on the operation behavior log based on the user access control policy and the access request, and obtains a fourth access anomaly detection result. The system also includes an access anomaly detection graph generation unit, which organizes the first access anomaly detection result, the second access anomaly detection result, the third access anomaly detection result, and the fourth access anomaly detection result to generate the access anomaly detection graph.

[0009] Preferably, the role-based access control-based confidential data security management system is further configured to: obtain a normal sample set of data access logs through a channel for retrieving normal samples from data field access logs based on the user access control policy and the access request, thereby obtaining a normal sample set of data access logs; establish a log sample confidence evaluation distribution channel for performing confidence evaluation based on the normal sample set of data access logs, thereby establishing a log sample confidence evaluation distribution; establish a normal and trustworthy data access space channel for performing confidence cleaning on the normal sample set of data access logs based on the log sample confidence evaluation distribution, thereby establishing a normal and trustworthy data access space; and obtain a first access anomaly detection result channel for performing anomaly parsing on the data field access logs based on the normal and trustworthy data access space, thereby obtaining the first access anomaly detection result.

[0010] Preferably, the role-based access control-based confidential data security management system is further configured with: a first access control adjustment decision domain acquisition unit, configured to adaptively compensate and adjust the user access control policy based on a first access anomaly detection result to obtain a first access control adjustment decision domain; a second access control adjustment decision domain acquisition unit, configured to adaptively compensate and adjust the user access control policy based on a second access anomaly detection result to obtain a second access control adjustment decision domain; a third access control adjustment decision domain acquisition unit, configured to adaptively compensate and adjust the user access control policy based on a third access anomaly detection result to obtain a third access control adjustment decision domain; a fourth access control adjustment decision domain acquisition unit, configured to adaptively compensate and adjust the user access control policy based on a fourth access anomaly detection result to obtain a fourth access control adjustment decision domain; and an access control adjustment space generation unit, configured to combine the first access control adjustment decision domain, the second access control adjustment decision domain, the third access control adjustment decision domain, and the fourth access control adjustment decision domain to generate the access control adjustment space.

[0011] Preferably, the role-based access control-based confidential data security management system further comprises: an access control risk prediction model activation unit, used to activate the access control risk prediction model, the access control risk prediction model including multi-dimensional access control risk indicators, the multi-dimensional access control risk indicators including unauthorized access risk, privilege abuse risk, and access security risk; an access control risk map acquisition unit, used to perform access control risk prediction on each access control adjustment scheme in the access control adjustment space according to the access control risk prediction model, and obtain an access control risk map; and a first access adjustment optimization domain acquisition unit, used to adjust the access control risk based on the access control risk map and according to the unauthorized access risk threshold. The system employs a first access control optimization domain, which performs unauthorized access risk optimization on the access control adjustment space based on the access control risk map and a privilege abuse risk threshold. A second access control optimization domain acquisition unit is used to perform privilege abuse risk optimization on the access control adjustment space based on the access control risk map and an access security risk threshold, thereby obtaining a third access control optimization domain. A multi-party access control optimization domain incorporation unit is used to incorporate the first, second, and third access control optimization domains into the access control multi-party optimization domain.

[0012] Preferably, the role-based access control-based confidential data security management system is further configured as follows: a first access control optimization space acquisition unit, configured to guide the access control adjustment space to perform mutation optimization according to a first access adjustment optimization domain, to obtain a first access control optimization space; a second access control optimization space acquisition unit, configured to guide the access control adjustment space to perform mutation optimization according to a second access adjustment optimization domain, to obtain a second access control optimization space; a third access control optimization space acquisition unit, configured to guide the access control adjustment space to perform mutation optimization according to a third access adjustment optimization domain, to obtain a third access control optimization space; an access global risk analysis model acquisition unit, configured to perform weight allocation according to multi-dimensional access control risk indicators, to obtain an access global risk analysis model; and an access adjustment optimization result generation unit, configured to perform access global risk iterative optimization on the first access control optimization space, the second access control optimization space, and the third access control optimization space according to the access global risk analysis model, to generate the access adjustment optimization result.

[0013] Preferably, the role-based access control-based confidential data security management system is further configured to: a first access control difference distribution channel, used to perform difference feature analysis on the access control adjustment space according to the first access adjustment optimization domain to obtain a first access control difference distribution; a first access adjustment variation space channel, used to guide the access control adjustment space to mutate according to the first access control difference distribution to obtain a first access adjustment variation space; a risk sequence channel for each variation scheme, used to perform access control risk prediction on the first access adjustment variation space according to the access control risk prediction model to obtain a risk sequence for each variation scheme; and a first access control optimization space generation channel, used to use unauthorized access risk threshold, privilege abuse risk threshold, and access security risk threshold as access risk constraints, combined with the optimization of the risk sequence for each variation scheme to filter the first access adjustment variation space and generate the first access control optimization space.

[0014] Preferably, the role-based access control-based confidential data security management system is further configured to include: the multi-factor authentication mechanism including USB Key hardware authentication, PIN code authentication, and terminal binding authentication.

[0015] Preferably, the role-based access control confidential data security management system is further configured to: generate a Web Socket alarm signal based on the access anomaly detection map.

[0016] Secondly, this application also provides a method for managing confidential data security based on role-based access control, including: when a user sends an access request to a confidential data platform, generating a user authentication result through a multi-factor authentication mechanism; based on the user authentication result, calling an RBAC model to perform role-based access control parsing on the user to obtain a user access control policy; performing real-time access anomaly detection on the user based on the user access control policy and the access request, and constructing an access anomaly detection map; dynamically adjusting the user access control policy according to the access anomaly detection map to obtain an access control adjustment space; performing multi-party optimization on the access control adjustment space according to an access control risk prediction model to obtain an access control multi-party optimization domain; and guiding the access control adjustment space to perform variant collaborative optimization according to the access control multi-party optimization domain to obtain an access control optimization result.

[0017] The technical solution provided in this application has at least the following technical effects or advantages: by achieving the technical goal of intelligent access control management based on role-based hierarchical, context-aware and dynamic policy integration, it achieves the technical effect of improving access flexibility and system adaptive protection capabilities while ensuring data security.

[0018] The above description is merely an overview of the technical solution of this application. To enable a clearer understanding of the technical means of this application and to facilitate its implementation according to the description, and to make the above and other objects, features, and advantages of this application more apparent, specific embodiments of this application are described below. It should be understood that the content described in this section is not intended to identify key or important features of the embodiments of this application, nor is it intended to limit the scope of this application. Other features of this application will become readily apparent through the following description. Attached Figure Description

[0019] To more clearly illustrate the technical solutions in this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are merely exemplary. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.

[0020] Figure 1 This is a schematic diagram of the confidential data security management system based on role-based access control in this application.

[0021] Figure 2 This is a flowchart illustrating the confidential data security management method based on role-based access control proposed in this application.

[0022] Figure labeling: Result generation module 1, Strategy acquisition module 2, Graph construction module 3, Spatial acquisition module 4, Optimization domain acquisition module 5, Result acquisition module 6. Detailed Implementation

[0023] This application provides a role-based access control-based confidential data security management system and method. It addresses the technical problem in existing technologies where the lack of a joint modeling mechanism for user roles, access context, and data sensitivity prevents access control policies from adaptively adjusting to dynamic environmental changes, further impacting the refined management and real-time protection capabilities of confidential data within a multi-level security architecture. The application achieves the technical goal of intelligent access control management based on role-based hierarchical structure, context awareness, and dynamic policy integration, thereby enhancing access flexibility and the system's adaptive protection capabilities while ensuring data security.

[0024] The technical solutions of this application will now be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. It should be understood that this application is not limited to the exemplary embodiments described herein. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application. It should also be noted that, for ease of description, only the parts related to this application are shown in the accompanying drawings, not all of them.

[0025] Example 1, please refer to the appendix. Figure 1 This application provides a role-based access control-based confidential data security management system, specifically including: Result generation module 1 is used to generate user identity authentication results through a multi-factor authentication mechanism when a user sends an access request to the confidential data platform.

[0026] Furthermore, this application also includes: the multi-factor authentication mechanism includes USB Key hardware authentication, PIN code authentication, and terminal binding authentication.

[0027] Specifically, a user sending an access request to a confidential data platform means that the user wishes to access a system used to store and manage confidential information and submits access instructions to the confidential data platform via the network. A confidential data platform is a system used to store, manage, and protect sensitive data. An access request is a communication instruction sent by the user to the confidential data platform, indicating their intention to view, modify, or download certain specific data.

[0028] Multi-factor authentication generates user identity verification results by combining multiple authentication methods upon receiving an access request. This security measure comprises three verification elements: USB Key hardware authentication, PIN code authentication, and terminal binding authentication. USB Key hardware authentication requires the user to insert a physical security key device to verify their identity. A USB Key is a hardware device with a built-in encryption chip that generates a unique digital signature or encryption token upon login. The signature can only be generated using this key, so even if an attacker obtains the user's account information, they cannot complete authentication without the USB Key. PIN code authentication requires the user to enter a personally identifiable number (PIN) for further verification. The PIN code is typically set by the user and is between 6 and 12 characters long. It is encrypted on the server side and compared to a reference value stored in the system. If the PIN code matches correctly, the authentication is successful. Terminal binding authentication binds the user's access permissions to a hardware terminal device, ensuring that login is only possible on registered devices. This is achieved through device fingerprint, MAC address, or serial number identification, such as binding to a specific computer, mobile phone, or tablet. This prevents attackers from initiating access requests from unregistered devices, even if they have the user's account, password, and USB key, thereby further enhancing the level of protection.

[0029] When authentication is successful, the generated identity authentication result will be used as the input condition for subsequent access control policies, thereby providing a reliable basis for subsequent role-based access control and risk assessment.

[0030] The policy acquisition module 2 is used to perform role-based access control parsing on the user based on the user authentication result and call the RBAC model to obtain the user access control policy.

[0031] Specifically, user authentication results serve as the input for subsequent access control. The RBAC model is an access management mechanism that uses roles as intermediaries to control the access relationship between users and resources. The RBAC model is invoked to perform role-based access control parsing for users; that is, based on the user's authentication results, a role-based access control model is activated to analyze the user's permissions. For example, a user may be assigned one or more roles, each corresponding to a certain set of access permissions, such as data reading, file modification, or system administration. By parsing the user's corresponding role information, the system automatically determines the operations the user can perform or the data modules they can access, thereby obtaining the user access control policy and generating a set of control rules regarding the user's access behavior.

[0032] The graph construction module 3 is used to perform real-time access anomaly detection on the user based on the user access control policy and the access request, and to construct an access anomaly detection graph.

[0033] Furthermore, this application also includes: a real-time access log acquisition unit, configured to acquire the user's real-time access logs, the real-time access logs including data field access logs, functional module access logs, operation behavior logs, and access environment logs; a first access anomaly detection result acquisition unit, configured to perform multi-dimensional anomaly detection on the data field access logs based on the user access control policy and the access request, to obtain a first access anomaly detection result; a second access anomaly detection result acquisition unit, configured to perform multi-dimensional anomaly detection on the functional module access logs based on the user access control policy and the access request, to obtain a second access anomaly detection result; a third access anomaly detection result acquisition unit, configured to perform multi-dimensional anomaly detection on the operation behavior logs based on the user access control policy and the access request, to obtain a third access anomaly detection result; a fourth access anomaly detection result acquisition unit, configured to perform multi-dimensional anomaly detection on the access environment logs based on the user access control policy and the access request, to obtain a fourth access anomaly detection result; and an access anomaly detection graph generation unit, configured to organize the first access anomaly detection result, the second access anomaly detection result, the third access anomaly detection result, and the fourth access anomaly detection result to generate the access anomaly detection graph.

[0034] Furthermore, this application also includes: a channel for obtaining a normal sample set of data access logs, used to retrieve normal samples of data field access logs based on the user access control policy and the access request, to obtain a normal sample set of data access logs; a channel for establishing a log sample confidence evaluation distribution, used to evaluate confidence based on the normal sample set of data access logs, to establish a log sample confidence evaluation distribution; a channel for establishing a normal and trustworthy data access space, used to clean the normal sample set of data access logs with confidence based on the log sample confidence evaluation distribution, to establish a normal and trustworthy data access space; and a channel for obtaining a first access anomaly detection result, used to perform anomaly parsing on the data field access logs based on the normal and trustworthy data access space, to obtain the first access anomaly detection result.

[0035] Furthermore, this application also includes: generating a Web Socket alarm signal based on the access anomaly detection map.

[0036] Specifically, obtaining real-time user access logs refers to the real-time collection and recording of user access behavior data during interactions with the confidential data platform. Real-time access logs are dynamic data streams that reflect a user's operational trajectory and behavioral patterns within a specific time period. Real-time access logs include data field access logs, functional module access logs, operation behavior logs, and access environment logs. Specifically, data field access logs record the specific data items accessed by the user, such as accessing table fields or document attributes; functional module access logs reflect the user's use of system functions, such as whether the user entered the statistics module, export module, or permission management module; operation behavior logs describe the user's interactive actions, such as clicking, modifying, deleting, or downloading; and access environment logs record information about the user's terminal environment, including login location, device type, network source, and time characteristics.

[0037] Furthermore, based on user access control policies and access requests, normal sample retrieval of data field access logs refers to filtering data samples that conform to normal behavior patterns from users' past access logs under defined access control rules, thereby obtaining a normal sample set of data access logs. For example, if a user accesses certain fields of a business table during working hours every day, and the access frequency remains within a fixed range, this constitutes a normal sample of data access logs, which can be used as a baseline reference for subsequent analysis.

[0038] Confidence evaluation based on a normal sample set of data access logs involves assigning confidence scores to assess the consistency and reliability of behavioral patterns within this sample set, thereby establishing a confidence distribution for the log samples. Confidence evaluation is a statistical method used to measure the probability that a sample represents normal behavior. Confidence models can be built based on multi-dimensional features such as access time patterns, field access combinations, and access path consistency. For example, if a user accesses the same field in a fixed pattern for 25 out of 30 days, their behavioral confidence level could reach approximately 0.83. The confidence values ​​are then aggregated to form a confidence distribution curve, reflecting the credible range and degree of deviation of normal behavior samples.

[0039] Confidence cleaning is performed on the normal sample set of data access logs based on the confidence rating distribution of the log samples. This involves removing samples with low confidence or abnormal deviations to establish a normal confidence space for data access, ensuring the accuracy of the analytical basis. Confidence cleaning is the process of filtering or correcting samples with low confidence to avoid a small number of abnormal samples interfering with the overall model.

[0040] Anomaly analysis is performed on data field access logs based on the normal and trusted data access space. This involves analyzing the degree of deviation from the data field access logs and identifying anomalies to obtain the first access anomaly detection result. Anomaly analysis refers to calculating the deviation values ​​of access behavior in the data field access logs across dimensions such as time, field, and frequency. If the deviation exceeds the boundary of the normal and trusted data access space, it is determined to be abnormal behavior. The first access anomaly detection result describes the abnormal characteristics of the user's data field access.

[0041] Furthermore, based on user access control policies and access requests, multi-dimensional anomaly detection is performed on the access logs of functional modules. This involves security analysis of user access behavior across different functional modules to obtain a second access anomaly detection result. Multi-dimensional detection can determine whether a user has accessed a module that is inconsistent with their role's permissions. For example, an ordinary user attempting to access the system configuration module or export data module might be identified as privilege abuse or unauthorized operation. The second access anomaly detection result is used to indicate the degree of access anomaly at the functional level.

[0042] Based on user access control policies and access requests, multi-dimensional anomaly detection is performed on operation behavior logs. This demonstrates an analysis of potential risks from the user's operational perspective, comparing operations such as adding, modifying, downloading, and deleting with normal patterns to obtain third-dimensional access anomaly detection results. For example, if a user performs a large number of deletion operations or batch exports data outside of working hours, it will be judged as abnormal behavior, thus forming a third-dimensional access anomaly detection result, which reflects the degree of inconsistency between the operation behavior and the security policy.

[0043] Multidimensional anomaly detection based on user access control policies and access requests involves assessing potential security risks by observing changes in the access environment, thereby obtaining a fourth set of access anomaly detection results. For example, if the same user logs into the system from different regions within one hour, it may be determined as an account theft or proxy login anomaly.

[0044] The results of the first, second, third, and fourth access anomaly detections are collected and integrated from different dimensions. These results are then visualized and modeled to generate an access anomaly detection graph. The access anomaly detection graph is a structured graphical model that maps multidimensional anomaly information to nodes and relationships. Nodes represent anomaly types, and edges represent their mutual influence relationships.

[0045] Furthermore, when a WebSocket alarm signal is generated based on the access anomaly detection graph, it indicates that a real-time comprehensive analysis of multi-dimensional anomalies in user access behavior is performed, and alarm information is pushed to the front end or monitoring center via WebSocket communication. The access anomaly detection graph is a visualized risk distribution structure that records the anomaly characteristics and risk levels of different types of access behavior, such as unauthorized data fields, abnormal function calls, abnormal operation frequency, or abnormal access environment. Each node corresponds to a detection result and a risk weight. When the risk of certain nodes in the graph exceeds a set threshold, the alarm signal generation mechanism is triggered. WebSocket is a full-duplex communication mechanism based on the TCP protocol, enabling real-time, continuous connections between the server and client. It can push anomaly information to the client within milliseconds, thereby improving response speed and system interaction efficiency. The alarm signal is a security event notification, containing information such as the anomaly type, risk level, trigger time, and associated user information, used to notify security administrators or automatically trigger protection policies.

[0046] The space acquisition module 4 is used to dynamically adjust the user access control policy based on the access anomaly detection map to obtain the access control adjustment space.

[0047] Furthermore, this application also includes: a first access control adjustment decision domain acquisition unit, configured to adaptively compensate and adjust the user access control policy based on a first access anomaly detection result to obtain a first access control adjustment decision domain; a second access control adjustment decision domain acquisition unit, configured to adaptively compensate and adjust the user access control policy based on a second access anomaly detection result to obtain a second access control adjustment decision domain; a third access control adjustment decision domain acquisition unit, configured to adaptively compensate and adjust the user access control policy based on a third access anomaly detection result to obtain a third access control adjustment decision domain; a fourth access control adjustment decision domain acquisition unit, configured to adaptively compensate and adjust the user access control policy based on a fourth access anomaly detection result to obtain a fourth access control adjustment decision domain; and an access control adjustment space generation unit, configured to combine the first access control adjustment decision domain, the second access control adjustment decision domain, the third access control adjustment decision domain, and the fourth access control adjustment decision domain to generate the access control adjustment space.

[0048] Specifically, adaptive compensation adjustment of user access control policies based on the first access anomaly detection result means dynamically adjusting the corresponding access control parameters according to the user's abnormal behavior in accessing data fields, thereby forming the first access control adjustment decision domain. Adaptive compensation adjustment refers to the system's ability to automatically identify anomaly types and adjust permissions or access conditions. For example, when an abnormal frequency of a user's access to sensitive data is detected, the system can automatically tighten their access range.

[0049] Next, adaptive compensation adjustment is performed based on the second access anomaly detection results. This involves dynamically adjusting strategies to address abnormal access to functional modules, generating a second access control adjustment decision domain. When frequent access to a module or abnormal access periods are detected, adaptive adjustments are made according to the access control policy, such as temporarily freezing module permissions or increasing operation authentication strength, thereby maintaining the system's access security and stability.

[0050] Then, based on the results of the third access anomaly detection, the access control policy is adaptively adjusted. When unauthorized or frequently repeated operations are detected, the policy is adjusted to generate a third access control adjustment decision domain. For example, a secondary verification step may be added or the operation frequency may be limited to ensure that the operation behavior conforms to the normal usage pattern.

[0051] Furthermore, adaptive compensation adjustments based on the fourth access anomaly detection results are a dynamic response to the access environment logs, generating a fourth access control adjustment decision domain. When a sudden change in the access source or a suspicious network environment is detected, a compensation mechanism is automatically triggered, such as restricting access from high-risk IP ranges or requiring users to re-authenticate via a USB key, thereby effectively preventing accounts from being remotely attacked or logged in by unauthorized devices.

[0052] Finally, the first, second, third, and fourth access control adjustment decision domains are combined to generate the access control adjustment space. The access control adjustment space refers to a set of strategies consisting of multiple adjustment schemes, reflecting the dynamic response patterns of the system under different abnormal scenarios, and achieving overall optimization of access control through multi-dimensional strategy fusion.

[0053] The optimization domain acquisition module 5 is used to perform multi-party optimization on the access control adjustment space according to the access control risk prediction model to obtain the multi-party optimization domain of access adjustment.

[0054] Furthermore, this application also includes: an access control risk prediction model activation unit, used to activate the access control risk prediction model, the access control risk prediction model including multi-dimensional access control risk indicators, the multi-dimensional access control risk indicators including unauthorized access risk, privilege abuse risk, and access security risk; an access control risk map acquisition unit, used to perform access control risk prediction on each access control adjustment scheme in the access control adjustment space according to the access control risk prediction model, and obtain an access control risk map; and a first access adjustment optimization domain acquisition unit, used to perform unauthorized access risk assessment on the access control adjustment space based on the access control risk map and according to an unauthorized access risk threshold. Access risk optimization is performed to obtain a first access regulation optimization domain; a second access regulation optimization domain acquisition unit is used to perform privilege abuse risk optimization on the access control regulation space based on the access control risk map and according to the privilege abuse risk threshold to obtain a second access regulation optimization domain; a third access regulation optimization domain acquisition unit is used to perform access security risk optimization on the access control regulation space based on the access control risk map and according to the access security risk threshold to obtain a third access regulation optimization domain; and an access regulation multi-party optimization domain incorporation unit is used to incorporate the first access regulation optimization domain, the second access regulation optimization domain, and the third access regulation optimization domain into the access regulation multi-party optimization domain.

[0055] Specifically, activating the access control risk prediction model means launching an intelligent analysis mechanism capable of assessing the potential risks of different access control schemes. The access control risk prediction model is a risk assessment framework built upon historical access behavior, anomaly detection results, and policy enforcement records, capable of predicting potential risk trends before policy adjustments. The model includes multi-dimensional access control risk indicators, including unauthorized access risk, privilege abuse risk, and access security risk. Unauthorized access risk refers to the security risks that may arise when a user attempts to access data or functions beyond their authorized scope; privilege abuse risk represents the risk of high-privilege users performing unauthorized operations on system resources; and access security risk focuses on the probability and impact of security threats such as external attacks, data breaches, or environmental anomalies.

[0056] Next, based on the access control risk prediction model, access control risk is predicted for each access control adjustment scheme within the access control adjustment space, thereby obtaining an access control risk map. The access control adjustment space contains multiple feasible combinations of access policies, while the access control risk map consists of three risk coefficients corresponding to each access control adjustment scheme. For example, a certain policy might have an unauthorized access risk of 0.2, a privilege abuse risk of 0.4, and an access security risk of 0.3, which are used for subsequent risk comparison and optimization analysis.

[0057] Then, the unauthorized access risk threshold is a system-defined upper limit of acceptable risk, set based on security level standards or regulatory requirements. Based on the access control risk map and combined with the unauthorized access risk threshold, the access control adjustment space is optimized for unauthorized access risk, resulting in the first access adjustment optimization domain. When the unauthorized access risk of a certain access scheme is found to be lower than the unauthorized access risk threshold, the scheme will be included in the first access adjustment optimization domain and considered a safe and feasible candidate scheme.

[0058] Next, the privilege abuse risk threshold is used to measure the acceptable level of risk associated with high-privilege operations, and can be customized by those skilled in the art based on actual circumstances. Based on the access control risk map and combined with the privilege abuse risk threshold, the access control regulation space is optimized for privilege abuse risk, resulting in a second access regulation optimization domain. If the risk of a particular solution in this dimension is less than the privilege abuse risk threshold, then the solution is considered safe and reliable in terms of privileged behavior.

[0059] Subsequently, the access security risk threshold reflects the system's tolerance level to threats such as external attacks and abnormal network connections, and can be customized by those skilled in the art based on actual conditions. Based on the access control risk map and combined with the access security risk threshold, the access control adjustment space is optimized for access security risks, thus forming a third access adjustment optimization domain. When the security risk of a certain strategy is less than the access security risk threshold, it indicates that the scheme is relatively robust in terms of external environment security and can be included in the third access adjustment optimization domain.

[0060] Finally, the first, second, and third access control optimization domains are integrated to form a multi-party access control optimization domain. This multi-party optimization domain is a set of multi-dimensional optimized strategies, encompassing all access control schemes that meet the threshold conditions across all three risk dimensions. It represents the final result that strikes a balance between security, flexibility, and controllability.

[0061] Result acquisition module 6 is used to guide the access control adjustment space to perform mutation collaborative optimization based on the access adjustment multi-party optimization domain, and obtain the access adjustment optimization result.

[0062] Furthermore, this application also includes: guiding the access control adjustment space to perform mutation optimization according to a first access adjustment optimization domain to obtain a first access control optimization space; guiding the access control adjustment space to perform mutation optimization according to a second access adjustment optimization domain to obtain a second access control optimization space; guiding the access control adjustment space to perform mutation optimization according to a third access adjustment optimization domain to obtain a third access control optimization space; performing weight allocation according to multi-dimensional access control risk indicators to obtain an access global risk analysis model; and performing access global risk iterative optimization on the first access control optimization space, the second access control optimization space, and the third access control optimization space according to the access global risk analysis model to generate the access adjustment optimization result.

[0063] Furthermore, this application also includes: performing differential feature analysis on the access control adjustment space based on the first access adjustment optimization domain to obtain a first access control differential distribution; guiding the access control adjustment space to mutate based on the first access control differential distribution to obtain a first access adjustment mutation space; performing access control risk prediction on the first access adjustment mutation space based on the access control risk prediction model to obtain a risk sequence of each mutation scheme; using unauthorized access risk threshold, privilege abuse risk threshold, and access security risk threshold as access risk constraints, and combining the risk sequences of each mutation scheme to optimize and screen the first access adjustment mutation space to generate the first access control optimization space.

[0064] Specifically, when performing difference feature analysis on the access control adjustment space based on the first access adjustment optimization domain, it means comparing the difference features between each scheme in the current access control adjustment space and the optimal scheme in the first access adjustment optimization domain, and quantitatively analyzing the differences of different strategies in terms of risk level, access permission configuration, execution conditions, etc., thereby identifying the dimensions that can be optimized.

[0065] Next, mutation is an optimization technique that introduces subtle random adjustments to the original scheme to explore potentially better policy combinations. The access control adjustment space is guided by the first access control difference distribution to obtain the first access control adjustment mutation space. Guided mutation is a targeted optimization based on the difference distribution, focusing on adjusting risks that differ significantly from the first access control optimization domain.

[0066] Then, based on the access control risk prediction model, access control risks are predicted for the first access regulation variation space to obtain the risk sequence for each variation scheme. The risk sequence is a set of three risk values ​​corresponding to each variation scheme, including unauthorized access risk, privilege abuse risk, and access security risk. For example, the risk sequence of one scheme may be (0.25, 0.3, 0.35), and another scheme may be (0.15, 0.45, 0.4).

[0067] Finally, using the unauthorized access risk threshold, privilege abuse risk threshold, and access security risk threshold as access risk constraints, and combining the risk sequences of each variant scheme, an optimization screening is performed to generate a first access control optimization space from the first access adjustment variant space. This means selecting all schemes whose risks are all below the corresponding thresholds for the three risk indicators. For example, if the unauthorized access risk threshold, privilege abuse risk threshold, and access security risk threshold are 0.3, 0.4, and 0.5 respectively, then the scheme with the risk sequence (0.25, 0.35, 0.4) will be retained, while the scheme with the risk sequence (0.25, 0.45, 0.35) will be eliminated. The filtered first access control optimization space consists of the optimal schemes that satisfy the triple risk constraints.

[0068] Furthermore, based on the second access regulation optimization domain, the access control regulation space is guided to perform mutation optimization. With the control of privilege abuse risk as the core, the scheme with lower risk in the second access regulation optimization domain is used for guided mutation, thereby reducing violations while maintaining the flexibility of high-privilege operations and obtaining the second access control optimization space.

[0069] Then, based on the third access regulation optimization domain, the access control regulation space is mutated and optimized. That is, in view of access security risks, the main considerations are network security, authentication and external attack protection. The schemes with lower risks in the third access regulation optimization domain are referenced, and the optimization is carried out by adjusting parameters such as network access policy, communication encryption strength or device trust level to obtain the third access control optimization space.

[0070] Subsequently, a global access risk analysis model is constructed by weighting multi-dimensional access control risk indicators. These indicators include unauthorized access risk, privilege abuse risk, and access security risk. Weighting involves assigning different importance coefficients to each risk type, ensuring the global access risk analysis model balances the impact of different risk dimensions during overall optimization. For example, unauthorized access risk can be weighted 0.4, privilege abuse risk 0.35, and access security risk 0.25. The global access risk analysis model includes a global access risk analysis function. This function is: Global Access Risk Value = Unauthorized Access Risk Coefficient × Unauthorized Access Risk Weight + Privilege Abuse Risk Coefficient × Privilege Risk Weight + Access Security Risk Coefficient × Security Risk Weight.

[0071] Finally, based on the global access risk analysis model, iterative optimization of the first, second, and third access control optimization spaces is performed to minimize global access risk. Iterative optimization refers to gradually updating the strategy in multiple rounds of calculation until the comprehensive risk value reaches the optimal state, i.e., the comprehensive risk value reaches the lowest level and a stable state where further adjustments in subsequent iterations cannot significantly reduce it. The resulting access adjustment optimization result is the optimal access control scheme that minimizes global risk. Specifically, based on the current access control policy, the unauthorized access risk value, privilege abuse risk value, and access security risk value corresponding to each access scheme are calculated. Based on the risk values, the policy parameters such as access thresholds, role permission ranges, or context weights are adjusted. The adjusted policy is then input into the next round of calculation to re-evaluate the new risk values. By continuously learning from the errors and results of the previous round in each round, the optimal solution with the minimum risk is gradually approached.

[0072] In summary, the role-based access control-based confidential data security management system provided in this application has the following technical effects: by achieving the technical goal of intelligent access control management based on role hierarchy, context awareness and dynamic policy integration, it achieves the technical effect of improving access flexibility and system adaptive protection capabilities while ensuring data security.

[0073] Example 2: Based on the same inventive concept as the role-based access control-based confidential data security management system in the preceding examples, this application also provides a role-based access control-based confidential data security management method. Please refer to the appendix. Figure 2 The process includes: when a user sends an access request to the confidential data platform, generating a user authentication result through a multi-factor authentication mechanism; based on the user authentication result, calling the RBAC model to perform role-based access control parsing on the user to obtain a user access control policy; performing real-time access anomaly detection on the user based on the user access control policy and the access request, and constructing an access anomaly detection map; dynamically adjusting the user access control policy according to the access anomaly detection map to obtain an access control adjustment space; performing multi-party optimization on the access control adjustment space according to an access control risk prediction model to obtain an access control adjustment multi-party optimization domain; and guiding the access control adjustment space to perform variant collaborative optimization according to the access control adjustment multi-party optimization domain to obtain an access control optimization result.

[0074] Furthermore, the role-based access control-based confidential data security management method further includes: obtaining the user's real-time access logs, the real-time access logs including data field access logs, functional module access logs, operation behavior logs, and access environment logs; performing multi-dimensional anomaly detection on the data field access logs based on the user access control policy and the access request to obtain a first access anomaly detection result; performing multi-dimensional anomaly detection on the functional module access logs based on the user access control policy and the access request to obtain a second access anomaly detection result; performing multi-dimensional anomaly detection on the operation behavior logs based on the user access control policy and the access request to obtain a third access anomaly detection result; performing multi-dimensional anomaly detection on the access environment logs based on the user access control policy and the access request to obtain a fourth access anomaly detection result; and organizing the first access anomaly detection result, the second access anomaly detection result, the third access anomaly detection result, and the fourth access anomaly detection result to generate the access anomaly detection map.

[0075] Furthermore, the role-based access control-based confidential data security management method further includes: retrieving normal samples from data field access logs based on the user access control policy and the access request to obtain a normal sample set of data access logs; evaluating the confidence level of the normal sample set of data access logs to establish a log sample confidence evaluation distribution; cleaning the normal sample set of data access logs based on the log sample confidence evaluation distribution to establish a normal and trustworthy data access space; and performing anomaly analysis on the data field access logs based on the normal and trustworthy data access space to obtain the first access anomaly detection result.

[0076] Furthermore, the role-based access control-based confidential data security management method further includes: adaptively compensating and adjusting the user access control policy based on a first access anomaly detection result to obtain a first access control adjustment decision domain; adaptively compensating and adjusting the user access control policy based on a second access anomaly detection result to obtain a second access control adjustment decision domain; adaptively compensating and adjusting the user access control policy based on a third access anomaly detection result to obtain a third access control adjustment decision domain; adaptively compensating and adjusting the user access control policy based on a fourth access anomaly detection result to obtain a fourth access control adjustment decision domain; and combining the first access control adjustment decision domain, the second access control adjustment decision domain, the third access control adjustment decision domain, and the fourth access control adjustment decision domain to generate the access control adjustment space.

[0077] Furthermore, the role-based access control-based confidential data security management method further includes: activating the access control risk prediction model, which includes multi-dimensional access control risk indicators, including unauthorized access risk, privilege abuse risk, and access security risk; predicting access control risks for each access control adjustment scheme within the access control adjustment space based on the access control risk prediction model to obtain an access control risk map; optimizing the access control adjustment space for unauthorized access risk based on the access control risk map and an unauthorized access risk threshold to obtain a first access adjustment optimization domain; optimizing the access control adjustment space for privilege abuse risk based on the access control risk map and an privilege abuse risk threshold to obtain a second access adjustment optimization domain; optimizing the access control adjustment space for access security risk based on the access control risk map and an access security risk threshold to obtain a third access adjustment optimization domain; and merging the first, second, and third access adjustment optimization domains into the access adjustment multi-party optimization domain.

[0078] Furthermore, the role-based access control-based confidential data security management method further includes: guiding the access control adjustment space to perform mutation optimization according to a first access adjustment optimization domain to obtain a first access control optimization space; guiding the access control adjustment space to perform mutation optimization according to a second access adjustment optimization domain to obtain a second access control optimization space; guiding the access control adjustment space to perform mutation optimization according to a third access adjustment optimization domain to obtain a third access control optimization space; performing weight allocation according to multi-dimensional access control risk indicators to obtain an access global risk analysis model; and performing access global risk iterative optimization on the first access control optimization space, the second access control optimization space, and the third access control optimization space according to the access global risk analysis model to generate the access adjustment optimization result.

[0079] Furthermore, the role-based access control-based confidential data security management method further includes: performing difference feature analysis on the access control adjustment space according to the first access adjustment optimization domain to obtain a first access control difference distribution; guiding the access control adjustment space to mutate according to the first access control difference distribution to obtain a first access adjustment mutation space; performing access control risk prediction on the first access adjustment mutation space according to the access control risk prediction model to obtain a risk sequence of each mutation scheme; using unauthorized access risk threshold, privilege abuse risk threshold, and access security risk threshold as access risk constraints, and combining the risk sequences of each mutation scheme to optimize and filter the first access adjustment mutation space to generate the first access control optimization space.

[0080] Furthermore, the role-based access control-based confidential data security management method also includes: the multi-factor authentication mechanism includes USB Key hardware authentication, PIN code authentication, and terminal binding authentication.

[0081] Furthermore, the role-based access control-based confidential data security management method also includes: generating a Web Socket alarm signal based on the access anomaly detection map.

[0082] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The role-based access control-based confidential data security management system and specific examples in the foregoing embodiment one are also applicable to the role-based access control-based confidential data security management method in this embodiment. Through the foregoing detailed description of the role-based access control-based confidential data security management system, those skilled in the art can clearly understand the role-based access control-based confidential data security management method in this embodiment. Therefore, for the sake of brevity, it will not be described in detail here.

[0083] The above description of the disclosed embodiments enables those skilled in the art to make or use this application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

[0084] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of this application and its equivalents, this application also intends to include such modifications and variations.

Claims

1. A role-based access control-based confidential data security management system, characterized in that, include: The result generation module is used to generate user authentication results through a multi-factor authentication mechanism when a user sends an access request to the confidential data platform. The policy acquisition module is used to perform role-based access control parsing on the user based on the user authentication result and to obtain the user access control policy by calling the RBAC model. The graph construction module is used to perform real-time access anomaly detection on the user based on the user access control policy and the access request, and to construct an access anomaly detection graph. The space acquisition module is used to dynamically adjust the user access control policy based on the access anomaly detection map to obtain the access control adjustment space; The optimization domain acquisition module is used to perform multi-party optimization on the access control adjustment space according to the access control risk prediction model to obtain the multi-party optimization domain of access adjustment. The result acquisition module is used to guide the access control regulation space to perform mutation collaborative optimization based on the access regulation multi-party optimization domain, and obtain the access regulation optimization result.

2. The role-based access control-based confidential data security management system as described in claim 1, characterized in that, The map construction module includes: The real-time access log acquisition unit is used to acquire the user's real-time access log, which includes data field access log, functional module access log, operation behavior log and access environment log; The first access anomaly detection result acquisition unit is used to perform multi-dimensional anomaly detection on the data field access log based on the user access control policy and the access request, and obtain the first access anomaly detection result. The second access anomaly detection result acquisition unit is used to perform multi-dimensional anomaly detection on the access log of the functional module based on the user access control policy and the access request, and obtain the second access anomaly detection result. The third access anomaly detection result acquisition unit is used to perform multi-dimensional anomaly detection on the operation behavior log based on the user access control policy and the access request, and obtain the third access anomaly detection result. The fourth access anomaly detection result acquisition unit is used to perform multi-dimensional anomaly detection on the access environment log based on the user access control policy and the access request, and obtain the fourth access anomaly detection result. The access anomaly detection map generation unit is used to organize the first access anomaly detection result, the second access anomaly detection result, the third access anomaly detection result, and the fourth access anomaly detection result to generate the access anomaly detection map.

3. The role-based access control-based confidential data security management system as described in claim 2, characterized in that, The first access anomaly detection result acquisition unit includes: A normal sample set acquisition channel for data access logs is used to retrieve normal samples of data field access logs based on the user access control policy and the access request, and to obtain a normal sample set of data access logs. A log sample confidence evaluation distribution establishment channel is used to access the normal log sample set based on the data to evaluate confidence and establish the log sample confidence evaluation distribution. A channel for establishing a normal and reliable data access space is used to perform confidence cleaning on the normal sample set of data access logs based on the confidence evaluation distribution of the log samples, thereby establishing a normal and reliable data access space. The first access anomaly detection result acquisition channel is used to perform anomaly parsing on the data field access logs based on the data access to the normal trusted space, and obtain the first access anomaly detection result.

4. The role-based access control-based confidential data security management system as described in claim 1, characterized in that, The space acquisition module includes: The first access control adjustment decision domain acquisition unit is used to adaptively compensate and adjust the user access control policy based on the first access anomaly detection result, and obtain the first access control adjustment decision domain. The second access control adjustment decision domain acquisition unit is used to adaptively compensate and adjust the user access control policy based on the second access anomaly detection result, and obtain the second access control adjustment decision domain. The third access control adjustment decision domain acquisition unit is used to adaptively compensate and adjust the user access control policy based on the third access anomaly detection result, and obtain the third access control adjustment decision domain. The fourth access control adjustment decision domain acquisition unit is used to adaptively compensate and adjust the user access control policy based on the fourth access anomaly detection result, and obtain the fourth access control adjustment decision domain. The access control adjustment space generation unit is used to generate the access control adjustment space by combining decisions based on the first access control adjustment decision domain, the second access control adjustment decision domain, the third access control adjustment decision domain, and the fourth access control adjustment decision domain.

5. The role-based access control-based confidential data security management system as described in claim 1, characterized in that, The optimization domain acquisition module includes: An access control risk prediction model activation unit is used to activate the access control risk prediction model, which includes multi-dimensional access control risk indicators, including unauthorized access risk, privilege abuse risk, and access security risk. The access control risk map acquisition unit is used to perform access control risk prediction on each access control adjustment scheme in the access control adjustment space according to the access control risk prediction model, and obtain the access control risk map. The first access control adjustment optimization domain acquisition unit is used to perform unauthorized access risk optimization on the access control adjustment space based on the access control risk map and according to the unauthorized access risk threshold to obtain the first access control adjustment optimization domain. The second access control adjustment optimization domain acquisition unit is used to perform privilege abuse risk optimization on the access control adjustment space based on the access control risk map and according to the privilege abuse risk threshold to obtain the second access control adjustment optimization domain. The third access control adjustment optimization domain acquisition unit is used to perform access security risk optimization on the access control adjustment space based on the access control risk map and according to the access security risk threshold to obtain the third access control adjustment optimization domain. The access regulation multi-party optimization domain incorporation unit is used to incorporate the first access regulation optimization domain, the second access regulation optimization domain, and the third access regulation optimization domain into the access regulation multi-party optimization domain.

6. The role-based access control-based confidential data security management system as described in claim 1, characterized in that, The result acquisition module includes: The first access control optimization space acquisition unit is used to guide the access control adjustment space to perform mutation optimization according to the first access adjustment optimization domain to obtain the first access control optimization space. The second access control optimization space acquisition unit is used to guide the access control adjustment space to perform mutation optimization according to the second access adjustment optimization domain, and obtain the second access control optimization space. The third access control optimization space acquisition unit is used to guide the access control adjustment space to perform mutation optimization according to the third access adjustment optimization domain to obtain the third access control optimization space. The access global risk analysis model acquisition unit is used to allocate weights based on multi-dimensional access control risk indicators to obtain the access global risk analysis model. The access regulation optimization result generation unit is used to perform access global risk iterative optimization on the first access control optimization space, the second access control optimization space, and the third access control optimization space according to the access global risk analysis model, and generate the access regulation optimization result.

7. The role-based access control-based confidential data security management system as described in claim 6, characterized in that, The first access control optimization space acquisition unit includes: The first access control difference distribution channel is used to perform difference feature analysis on the access control adjustment space according to the first access adjustment optimization domain to obtain the first access control difference distribution. The first access regulation variation space channel is used to guide the access control regulation space to mutate according to the first access control difference distribution to obtain the first access regulation variation space. Each mutation scheme risk sequence channel is used to predict access control risks in the first access regulation mutation space according to the access control risk prediction model, and obtain the risk sequence of each mutation scheme. The first access control optimization space generation channel is used to optimize and filter the first access adjustment variation space by combining the risk sequences of each variation scheme with access risk constraints such as unauthorized access risk threshold, privilege abuse risk threshold and access security risk threshold, and to generate the first access control optimization space.

8. The role-based access control-based confidential data security management system as described in claim 1, characterized in that, The multi-factor authentication mechanism includes USB Key hardware authentication, PIN code authentication, and terminal binding authentication.

9. The role-based access control-based confidential data security management system as described in claim 1, characterized in that, Based on the access anomaly detection map, a Web Socket alarm signal is generated.

10. A method for managing confidential data security based on role-based access control, characterized in that, Executed by the role-based access control-based confidential data security management system as described in any one of claims 1 to 9, including: When a user sends an access request to the confidential data platform, a user identity authentication result is generated through a multi-factor authentication mechanism; Based on the user authentication result, the RBAC model is invoked to perform role access control parsing on the user and obtain the user access control policy. Based on the user access control policy and the access request, perform real-time access anomaly detection on the user and construct an access anomaly detection map. The user access control policy is dynamically adjusted based on the access anomaly detection map to obtain the access control adjustment space. Based on the access control risk prediction model, the access control adjustment space is optimized in multiple ways to obtain the access adjustment multi-party optimization domain. The access control regulation space is guided by the access regulation multi-party optimization domain to perform variant collaborative optimization and obtain the access regulation optimization result.