A data security access method and system
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- GUANGZHOU XIAOCHI TECH CO LTD
- Filing Date
- 2025-12-16
- Publication Date
- 2026-08-07
AI Technical Summary
[0004]本发明的目的在于克服现有技术的不足,本发明提供了一种数据安全访问方法及系统,能够实现对用户访问权限的动态、智能调整,有效解决了传统静态权限控制无法应对复杂多变访问环境的难题,显著提升了数据访问的安全性
[0015] In this embodiment of the invention, authentication is performed based on identity credentials, and a target session is created based on the authentication results of each user to determine the data access permissions of each user in the target session. Access terminal status information and access behavior characteristic information of each user during access to the target session are obtained. Vulnerability exposure risk analysis is performed based on the vulnerability behavior feature library and access terminal status information, which can more comprehensively identify and assess potential vulnerabilities of the access terminal, providing more accurate data support for subsequent risk analysis. Access risk analysis is performed based on access terminal status information, access behavior characteristic information, and vulnerability exposure risk information to obtain the initial access risk coefficient of each user. Business task information of each user during access to the target session is obtained, and emergency task judgment is performed based on the business task information. A business exemption factor is generated based on the emergency task judgment result, and the initial access risk coefficient is adjusted based on the business exemption factor to obtain a more context-aware target access risk coefficient. Permission adjustment conflict detection is performed based on the target access risk coefficient of each user, and data access permissions are adjusted based on the permission adjustment conflict detection result and the target access risk coefficient. This enables dynamic and intelligent adjustment of user access permissions, effectively solving the problem that traditional static permission control cannot cope with complex and ever-changing access environments, and significantly improving the security of data access.
Smart Images

Figure CN121441637B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data security technology, and in particular to a data security access method and system. Background Technology
[0002] In today's increasingly mobile and remote work environment, user data access scenarios are no longer static but are fraught with dynamic and changing risk factors. Existing methods often only perform one-time authentication and permission granting upon initial login, failing to continuously monitor environmental changes or abnormal user behavior during the access process. This makes the system inadequate in dealing with dynamic risks, easily leading to over-authorization and thus creating potential data leaks. Traditional access control methods involve users submitting identity credentials through access terminals, which, after verification, grant access to data resources within their preset permission scope. However, in today's complex network environment where mobile work and remote access are commonplace, permission control relying solely on static identities has shown significant limitations.
[0003] Meanwhile, traditional access control methods neglect the environmental risks at the time of access. For example, even if the user's identity is legitimate, the terminal they are using may be in an insecure network environment, infected with malware, or exhibit abnormal access behavior patterns. These dynamic risk factors are not taken into account in permission decisions. This leads to two security risks: first, it may result in over-authorization, where legitimate users still possess excessive privileges in insecure access scenarios, easily leading to data leaks; second, it lacks dynamic adjustment capabilities, failing to downgrade or restrict access permissions in real time when risks are detected, thus making it difficult to effectively deal with dynamic security threats such as internal threats and credential misuse. Summary of the Invention
[0004] The purpose of this invention is to overcome the shortcomings of the prior art. This invention provides a data security access method and system that can dynamically and intelligently adjust user access permissions, effectively solving the problem that traditional static permission control cannot cope with complex and ever-changing access environments, and significantly improving the security of data access.
[0005] To address the aforementioned technical problems, this invention provides a data security access method, the method comprising: Obtain the identity credentials of each user, perform identity verification based on the identity credentials, obtain the identity verification result, create a target session based on the identity verification result of each user, and determine the data access permissions of each user in the target session; Acquire the access terminal status information and access behavior characteristic information of each user during the access to the target session, construct a vulnerability behavior feature library, and perform vulnerability exposure risk analysis based on the vulnerability behavior feature library and access terminal status information to obtain vulnerability exposure risk information. Based on the access terminal status information, access behavior characteristic information and vulnerability exposure risk information, an access risk analysis is performed to obtain the initial access risk coefficient for each user. Obtain the business task information of each user during the access to the target session, and make an emergency task judgment based on the business task information to obtain the emergency task judgment result; Based on the emergency task judgment result, a business exemption factor is generated, and the initial access risk coefficient is adjusted based on the business exemption factor to obtain the target access risk coefficient for each user. Based on the target access risk coefficient of each user, permission adjustment conflict detection is performed to obtain the permission adjustment conflict detection result, and the data access permissions are adjusted based on the permission adjustment conflict detection result and the target access risk coefficient.
[0006] Optionally, the step of constructing a vulnerability behavior feature library and performing vulnerability exposure risk analysis based on the vulnerability behavior feature library and access terminal status information to obtain vulnerability exposure risk information includes: Obtain security test information of the network stack, and extract vulnerability identifiers, trigger condition descriptions, vulnerability behavior characteristics, and vulnerability risk levels based on the security test information; A vulnerability behavior feature library is constructed based on the vulnerability identifier, trigger condition description information, vulnerability behavior characteristics, and vulnerability risk level. Based on the access terminal status information, perform instantaneous network encryption weakening analysis to obtain instantaneous network encryption weakening information; and perform electromagnetic interference analysis based on the access terminal status information to obtain electromagnetic interference information. Based on the network instantaneous encryption weakening information and electromagnetic interference information, network stack behavior analysis is performed to obtain network stack behavior information; Based on the vulnerability behavior feature library, the network stack behavior information is used to perform vulnerability exposure risk analysis to obtain vulnerability exposure risk information.
[0007] Optionally, the step of performing network stack behavior analysis based on the network instantaneous encryption weakening information and electromagnetic interference information to obtain network stack behavior information includes: Based on the network's instantaneous encryption weakening information and electromagnetic interference information, a probe data packet is generated and transmitted to each user's access terminal; Obtain the CPU utilization, memory usage changes, protocol state machine, and system logs of each user's access terminal when processing the probe data packets; Network stack behavior analysis is performed based on the CPU utilization, memory usage changes, protocol state machine, and system logs to obtain network stack behavior information.
[0008] Optionally, the step of determining the urgency of a task based on the business task information and obtaining the urgency determination result includes: Obtain the task identifier based on the aforementioned business task information; Based on the business task information, a business impact level analysis is performed to obtain the target business impact level; Based on the task identifier and the target business impact level, an emergency task determination is made to obtain the emergency task determination result.
[0009] Optionally, generating the business exemption factor based on the emergency task determination result includes: Identify whether the result of the emergency task determination indicates that an emergency task exists; If the emergency task assessment result indicates that an emergency task exists, obtain the priority and potential business impact of the emergency task. A business exemption factor is generated based on the priority of the emergency task and the degree of its potential business impact.
[0010] Optionally, the step of performing permission adjustment conflict detection based on the target access risk coefficient of each user to obtain permission adjustment conflict detection results includes: The risk assessment coefficient for each user's access to the same shared data in the target session is determined based on the target access risk coefficient of each user. The suggested adjustment permissions for each user are determined based on the aforementioned risk assessment coefficient; Perform permission adjustment conflict detection on the suggested permission adjustments for each user, and obtain the permission adjustment conflict detection results.
[0011] Optionally, the step of performing permission adjustment conflict detection on the suggested permission adjustments for each user and obtaining permission adjustment conflict detection results includes: The timestamp verification is performed on the suggested permission adjustments for each user, and the timestamp verification results are obtained. The suggested permission adjustments for each user are compared using serial numbers to obtain the serial number comparison results. Based on the timestamp verification result and the serial number comparison result, a false conflict detection is performed to obtain the first false conflict detection result; Obtain the permission status and network environment quality indicators corresponding to the same shared data in the target session; Based on the permission status and network environment quality indicators corresponding to the same shared data, combined with the suggestions of each user, permissions are adjusted to perform false conflict detection and obtain a second false conflict detection result. The permission adjustment conflict detection result is determined based on the first false conflict detection result and the second false conflict detection result.
[0012] Optionally, adjusting the data access permissions based on the permission adjustment conflict detection results and the target access risk coefficient includes: Based on the conflict detection results of the aforementioned permission adjustment, a conflict resolution strategy is determined. Based on the target access risk coefficient, risk jump analysis is performed using past access risk records to obtain risk jump information; Based on the aforementioned risk jump information, a permission adjustment smoother and a gradual permission adjustment path are determined; The data access permissions of each user are adjusted based on the aforementioned conflict resolution strategy, permission adjustment smoother, and progressive permission adjustment path.
[0013] Optionally, determining the permission adjustment smoother and the gradual permission adjustment path based on the risk transition information includes: Based on the risk jump information, the degree and frequency of risk change are determined, and based on the degree and frequency of risk change, a permission adjustment smoother is determined. Based on the risk jump information and the permission adjustment rate parameter, a gradual permission adjustment path is determined.
[0014] In addition, the present invention also provides a data security access system, the system comprising: Initial permission allocation module: used to obtain the identity credentials of each user, perform identity verification based on the identity credentials, obtain the identity verification result, create a target session based on the identity verification result of each user, and determine the data access permissions of each user in the target session; Vulnerability risk analysis module: used to obtain access terminal status information and access behavior characteristic information of each user during access to the target session, build a vulnerability behavior feature library, and perform vulnerability exposure risk analysis based on the vulnerability behavior feature library and access terminal status information to obtain vulnerability exposure risk information; Access risk analysis module: used to perform access risk analysis based on the access terminal status information, access behavior characteristic information and vulnerability exposure risk information, and obtain the initial access risk coefficient for each user; Emergency Task Judgment Module: Used to obtain the business task information of each user during the access to the target session, and to make an emergency task judgment based on the business task information to obtain the emergency task judgment result; Coefficient adjustment module: used to generate a business exemption factor based on the emergency task judgment result, and adjust the initial access risk coefficient based on the business exemption factor to obtain the target access risk coefficient for each user; Permission adjustment module: used to perform permission adjustment conflict detection based on the target access risk coefficient of each user, obtain permission adjustment conflict detection results, and adjust the data access permissions based on the permission adjustment conflict detection results and the target access risk coefficient.
[0015] In this embodiment of the invention, authentication is performed based on identity credentials, and a target session is created based on the authentication results of each user to determine the data access permissions of each user in the target session. Access terminal status information and access behavior characteristic information of each user during access to the target session are obtained. Vulnerability exposure risk analysis is performed based on the vulnerability behavior feature library and access terminal status information, which can more comprehensively identify and assess potential vulnerabilities of the access terminal, providing more accurate data support for subsequent risk analysis. Access risk analysis is performed based on access terminal status information, access behavior characteristic information, and vulnerability exposure risk information to obtain the initial access risk coefficient of each user. Business task information of each user during access to the target session is obtained, and emergency task judgment is performed based on the business task information. A business exemption factor is generated based on the emergency task judgment result, and the initial access risk coefficient is adjusted based on the business exemption factor to obtain a more context-aware target access risk coefficient. Permission adjustment conflict detection is performed based on the target access risk coefficient of each user, and data access permissions are adjusted based on the permission adjustment conflict detection result and the target access risk coefficient. This enables dynamic and intelligent adjustment of user access permissions, effectively solving the problem that traditional static permission control cannot cope with complex and ever-changing access environments, and significantly improving the security of data access. Attached Figure Description
[0016] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0017] Figure 1 This is a flowchart illustrating the data security access method in an embodiment of the present invention; Figure 2 This is a flowchart illustrating a data security access method according to another embodiment of the present invention; Figure 3 This is a schematic diagram of the structural composition of the data security access system in an embodiment of the present invention. Detailed Implementation
[0018] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0019] Example 1 Please see Figure 1 , Figure 1 This is a flowchart illustrating a data security access method according to an embodiment of the present invention. The method includes: S11: Obtain the identity credentials of each user, perform identity verification based on the identity credentials, obtain the identity verification result, create a target session based on the identity verification result of each user, and determine the data access permissions of each user in the target session; In the specific implementation of this invention, the identity credentials of each user are obtained, identity verification is performed based on the identity credentials, the identity verification result is obtained, and a target session is created based on the identity verification result of each user. The data access permissions of each user in the target session are determined, which ensures that legitimate users can initially access the system, and at the same time provides operable permission objects for subsequent permission adjustments.
[0020] S12: Obtain the access terminal status information and access behavior characteristic information of each user during the access to the target session, construct a vulnerability behavior characteristic library, and perform vulnerability exposure risk analysis based on the vulnerability behavior characteristic library and access terminal status information to obtain vulnerability exposure risk information. In the specific implementation of this invention, the access terminal status information and access behavior characteristic information of each user during the access to the target session are obtained, and the security test information of the network stack is obtained. Based on the security test information, vulnerability identifiers, trigger condition description information, vulnerability behavior characteristics, and vulnerability risk levels are extracted. A vulnerability behavior feature library is constructed based on the vulnerability identifiers, trigger condition description information, vulnerability behavior characteristics, and vulnerability risk levels. Based on the access terminal status information, instantaneous network encryption weakening analysis is performed to obtain instantaneous network encryption weakening information. Based on the access terminal status information, electromagnetic interference analysis is performed to obtain electromagnetic interference information. Based on the instantaneous network encryption weakening information and electromagnetic interference information, network stack behavior analysis is performed to obtain network stack behavior information. Based on the vulnerability behavior feature library, the network stack behavior information is used to perform vulnerability exposure risk analysis, which can more comprehensively identify and evaluate the potential vulnerabilities of the access terminal, providing more accurate data support for subsequent risk analysis, thereby improving the accuracy of risk assessment.
[0021] S13: Based on the access terminal status information, access behavior characteristic information and vulnerability exposure risk information, perform access risk analysis to obtain the initial access risk coefficient for each user; In the specific implementation of this invention, access risk analysis is performed based on the access terminal status information, access behavior characteristic information, and vulnerability exposure risk information to obtain the initial access risk coefficient of each user. This enables more accurate identification of deep threats hidden behind a single risk signal, resulting in a quantitative risk assessment result. This provides an intelligent and accurate decision-making basis for subsequent dynamic adjustment of permissions.
[0022] S14: Obtain the business task information of each user during the access to the target session, and make an emergency task judgment based on the business task information to obtain the emergency task judgment result. In the specific implementation of this invention, business task information of each user during the access to the target session is obtained, and a task identifier is obtained based on the business task information; business impact level analysis is performed based on the business task information to obtain the target business impact level; and emergency task judgment is made based on the task identifier and the target business impact level, incorporating the urgency of business tasks into the risk assessment system, so that permission adjustments can better adapt to business needs and avoid affecting normal business operations due to excessive security restrictions.
[0023] S15: Generate a business exemption factor based on the emergency task judgment result, and adjust the initial access risk coefficient based on the business exemption factor to obtain the target access risk coefficient for each user; In the specific implementation of this invention, it is determined whether the emergency task judgment result indicates the existence of an emergency task; if the emergency task judgment result indicates the existence of an emergency task, the priority and potential business impact of the emergency task are obtained; a business exemption factor is generated based on the priority and potential business impact of the emergency task; the initial access risk coefficient is adjusted based on the business exemption factor to obtain the target access risk coefficient for each user. This allows for flexible adjustment of the risk coefficient according to the actual situation of the emergency task, ensuring smooth business operation in emergency situations while also taking security into account.
[0024] S16: Perform permission adjustment conflict detection based on the target access risk coefficient of each user, obtain the permission adjustment conflict detection result, and adjust the data access permission based on the permission adjustment conflict detection result and the target access risk coefficient.
[0025] In the specific implementation of this invention, a risk assessment coefficient for the same shared data of each user in the target session is determined based on the target access risk coefficient of each user; a suggested adjustment permission for each user is determined based on the risk assessment coefficient; permission adjustment conflict detection is performed on the suggested adjustment permissions of each user to obtain permission adjustment conflict detection results, which can effectively avoid conflicts caused by multiple users simultaneously adjusting permissions and ensure the coordination and consistency of permission adjustments. A conflict resolution strategy is determined based on the permission adjustment conflict detection results; risk jump analysis is performed using past access risk records based on the target access risk coefficient to obtain risk jump information; a permission adjustment smoother and a gradual permission adjustment path are determined based on the risk jump information; and data access permissions of each user are adjusted based on the conflict resolution strategy, permission adjustment smoother, and gradual permission adjustment path, which can achieve smooth and gradual permission adjustment, avoid negative impacts on user experience and business continuity caused by sudden permission changes, and effectively solve the conflict problem in permission adjustment.
[0026] In this embodiment of the invention, authentication is performed based on identity credentials, and a target session is created based on the authentication results of each user to determine the data access permissions of each user in the target session. Access terminal status information and access behavior characteristic information of each user during access to the target session are obtained. Vulnerability exposure risk analysis is performed based on the vulnerability behavior feature library and access terminal status information, which can more comprehensively identify and assess potential vulnerabilities of the access terminal, providing more accurate data support for subsequent risk analysis. Access risk analysis is performed based on access terminal status information, access behavior characteristic information, and vulnerability exposure risk information to obtain the initial access risk coefficient of each user. Business task information of each user during access to the target session is obtained, and emergency task judgment is performed based on the business task information. A business exemption factor is generated based on the emergency task judgment result, and the initial access risk coefficient is adjusted based on the business exemption factor to obtain a more context-aware target access risk coefficient. Permission adjustment conflict detection is performed based on the target access risk coefficient of each user, and data access permissions are adjusted based on the permission adjustment conflict detection result and the target access risk coefficient. This enables dynamic and intelligent adjustment of user access permissions, effectively solving the problem that traditional static permission control cannot cope with complex and ever-changing access environments, and significantly improving the security of data access.
[0027] Example 2 Please see Figure 2 , Figure 2 This is a flowchart illustrating a data security access method according to another embodiment of the present invention, the method comprising: S201: Obtain the identity credentials of each user, perform identity verification based on the identity credentials, obtain the identity verification result, create a target session based on the identity verification result of each user, and determine the data access permissions of each user in the target session; In the specific implementation of this invention, the system acquires the identity credentials of each user. Identity credentials can be understood as any form of information used by a user to prove their identity, such as username and password, digital certificate, biometric information, etc. Identity verification is performed based on these credentials to obtain the verification result. A target session is created based on the verification results of each user. A target session refers to the logical connection established between a user and the data access system after successful identity verification for data interaction, and the system determines the data access permissions for each user within the target session. Data access permissions refer to specific operations that a user is allowed to perform in the target session, such as reading, writing, modifying, and deleting. Based on the acquired identity credentials, the system performs identity verification to confirm the user's legitimacy. After successful identity verification, the system obtains the verification result and creates a target session for each user based on this result. Simultaneously with creating the target session, the system determines the initial data access permissions for each user within the target session based on preset information such as the user's identity and role. For example, ordinary employees may be granted read-only permissions, while department managers may have read and write permissions.
[0028] S202: Obtain the access terminal status information and access behavior characteristic information of each user during the access to the target session, construct a vulnerability behavior characteristic library, and perform vulnerability exposure risk analysis based on the vulnerability behavior characteristic library and access terminal status information to obtain vulnerability exposure risk information. In the specific implementation of this invention, the construction of a vulnerability behavior feature library and the vulnerability exposure risk analysis based on the vulnerability behavior feature library and access terminal status information to obtain vulnerability exposure risk information include: acquiring security test information of the network stack and extracting vulnerability identifiers, trigger condition description information, vulnerability behavior features, and vulnerability risk levels based on the security test information; constructing a vulnerability behavior feature library based on the vulnerability identifiers, trigger condition description information, vulnerability behavior features, and vulnerability risk levels; performing network instantaneous encryption weakening analysis based on the access terminal status information to obtain network instantaneous encryption weakening information; performing electromagnetic interference analysis based on the access terminal status information to obtain electromagnetic interference information; performing network stack behavior analysis based on the network instantaneous encryption weakening information and electromagnetic interference information to obtain network stack behavior information; and performing vulnerability exposure risk analysis based on the vulnerability behavior feature library and the network stack behavior information to obtain vulnerability exposure risk information.
[0029] Specifically, the system acquires the access terminal status information and access behavior characteristic information of each user during the target access session. The access terminal status information includes the hardware and software environment information of the device used by the user when accessing data, such as operating system version, security patch status, installed applications, network connection type, IP address, etc. Access behavior characteristic information refers to the behavioral patterns exhibited by the user during the data access process, such as access time, access frequency, data type accessed, and operation command sequence, etc.
[0030] Obtaining security testing information for the network stack refers to the security auditing, vulnerability scanning, or penetration testing performed on the network protocol stack (e.g., TCP / IP protocol stack) used by the accessing terminal, thereby obtaining relevant security testing reports or data. Based on this security testing information, vulnerability identifiers, trigger condition descriptions, vulnerability behavior characteristics, and vulnerability risk levels are extracted. A vulnerability identifier is a unique code or name used to identify a specific vulnerability, such as a common CVE number. Trigger condition descriptions detail the environmental configuration, operational steps, or input data required for successful exploitation of the vulnerability. Vulnerability behavior characteristics refer to abnormal behavior patterns that the system or network may exhibit when a vulnerability is exploited, such as specific network traffic patterns, abnormal resource usage, or error logs. The vulnerability risk level is an assessment of the vulnerability's severity, exploitability, and potential impact, typically categorized as high, medium, or low. The purpose is to extract structured, key vulnerability information from the raw security testing data that can be used for subsequent analysis.
[0031] Constructing a vulnerability behavior feature database based on the vulnerability identifier, trigger condition description information, vulnerability behavior characteristics, and vulnerability risk level refers to integrating the extracted structured vulnerability information into a centrally stored and managed database, forming a comprehensive vulnerability knowledge base. This vulnerability behavior feature database serves as the foundational data source for subsequent vulnerability exposure risk analysis, providing a basis for matching and identifying potential vulnerabilities.
[0032] Based on the access terminal status information, a momentary network encryption weakening analysis is performed to obtain network momentary encryption weakening information. This refers to assessing the potential temporary decrease or failure of the access terminal's encrypted communication capability at a certain point in time or under a specific network environment. Examples include reduced encryption strength or interrupted encrypted connections due to network congestion, protocol degradation attacks, or configuration errors. Electromagnetic interference analysis is also performed based on the access terminal status information to obtain electromagnetic interference information. This assesses whether the physical environment in which the access terminal is located contains electromagnetic interference that may affect its normal communication or hardware operation, such as strong electromagnetic radiation from nearby devices, which may lead to data transmission errors or system instability. The network momentary encryption weakening information and electromagnetic interference information are the results of these analyses, reflecting the non-traditional security risks faced by the terminal at a certain moment. Their purpose is to identify potential security vulnerabilities caused by environmental or momentary network conditions that may be overlooked by traditional security protections.
[0033] Network stack behavior analysis based on the aforementioned transient encryption weakening information and electromagnetic interference information, to obtain network stack behavior information, refers to an in-depth analysis of the behavior of the access terminal's network protocol stack when processing network traffic, taking into account transient encryption weakening and electromagnetic interference. This may include monitoring changes in the protocol state machine, packet processing latency, and abnormal connection attempts. The network stack behavior information is the output of this analysis, revealing the actual operating status and potential anomalies of the network stack under adverse environments. Its purpose is to dynamically evaluate the robustness and security of network communication of access terminals in complex or interfered environments.
[0034] Based on the vulnerability behavior feature library, vulnerability exposure risk analysis is performed using the network stack behavior information to obtain vulnerability exposure risk information. This involves matching and comparing the pre-built vulnerability behavior feature library with real-time or near-real-time network stack behavior information. By associating the network stack behavior of a terminal in a certain environment with the vulnerability behavior features and trigger condition descriptions of known vulnerabilities, it is possible to more accurately determine whether the current terminal is at risk of vulnerability exposure. Vulnerability exposure risk information is the final analysis result, which quantifies or describes the probability and potential impact of the vulnerability currently faced by the terminal being exploited. Its purpose is to provide a dynamic, real-time vulnerability exposure risk assessment, providing a basis for subsequent permission adjustments. It avoids misjudgments or omissions caused by environmental factors. Therefore, the obtained vulnerability exposure risk information is closer to reality, making risk assessment no longer solely dependent on static vulnerability features, but able to reflect in real time the degree of matching between the terminal's network stack behavior and known vulnerability behavior features in the current network environment and operating state, thereby more accurately identifying the actual exposure risk of vulnerabilities.
[0035] Furthermore, the step of performing network stack behavior analysis based on the network instantaneous encryption weakening information and electromagnetic interference information to obtain network stack behavior information includes: generating probe data packets based on the network instantaneous encryption weakening information and electromagnetic interference information, and transmitting the probe data packets to the access terminals of each user; obtaining the CPU utilization rate, memory usage changes, protocol state machine, and system logs of each user's access terminal when processing the probe data packets; and performing network stack behavior analysis based on the CPU utilization rate, memory usage changes, protocol state machine, and system logs to obtain network stack behavior information.
[0036] Specifically, probing data packets are generated based on the network's instantaneous encryption weakening information and electromagnetic interference information. These probing data packets are then transmitted to the access terminals of each user. Generating probing data packets means constructing data packets with specific characteristics based on the network's instantaneous encryption weakening information and electromagnetic interference information. For example, these data packets can simulate common attack traffic patterns in weak encryption environments, or simulate abnormal data packets that may cause data packet corruption or delays in electromagnetic interference environments. The purpose is to actively inject these data packets to induce observable responses in the network stack of the access terminal, thereby revealing its behavior patterns in non-ideal environments. The transmission of these probing data packets to the access terminals of each user aims to simulate real network attack or interference scenarios to assess the actual risk resistance capabilities of the terminals.
[0037] Obtaining CPU utilization, memory usage changes, protocol state machine data, and system logs for each user's access terminal during the processing of the probe packets can be understood as real-time monitoring of the access terminal's internal resource consumption and system behavior. CPU utilization and memory usage changes reflect the resource overhead and performance pressure on the network stack when processing abnormal packets; the protocol state machine reveals whether the network protocol stack's state transitions and processing logic under abnormal conditions meet expectations, and whether there are abnormal states or deadlocks; the system log records system-level events and error information, providing deeper fault diagnosis and clues to behavioral anomalies. Obtaining these metrics aims to comprehensively characterize the internal operating state of the network stack from multiple dimensions.
[0038] Network stack behavior analysis is performed based on CPU utilization, memory usage changes, protocol state machines, and system logs to obtain network stack behavior information. Specifically, this involves a comprehensive evaluation of these real-time acquired metrics. For example, analyzing CPU utilization and memory usage changes can determine if the network stack is experiencing resource exhaustion or performance bottlenecks; examining the protocol state machine can identify protocol vulnerabilities or abnormal state transitions; and parsing system logs can uncover potential attack traces or system errors. The aim is to accurately identify abnormal behavior patterns and potential vulnerabilities of the network stack under the influence of momentary encryption weakening and electromagnetic interference through multi-dimensional data correlation analysis, thereby obtaining more precise network stack behavior information. The combination of proactive detection and multi-dimensional metric analysis significantly improves the accuracy and depth of vulnerability exposure risk analysis, enabling in-depth revelation of network stack resource consumption, protocol processing logic, and system stability under risk conditions. This overcomes the limitations of relying solely on passive monitoring, which may not be able to fully capture dynamic behavior, resulting in more accurate and in-depth acquisition of network stack behavior information.
[0039] S203: Based on the access terminal status information, access behavior characteristic information and vulnerability exposure risk information, perform access risk analysis to obtain the initial access risk coefficient for each user; In the specific implementation of this invention, access risk analysis is performed based on the access terminal status information, access behavior characteristic information, and vulnerability exposure risk information to obtain the initial access risk coefficient for each user. The initial access risk coefficient is a quantitative value of user access risk initially assessed based on multi-dimensional information. For example, if a user's terminal has a high-risk vulnerability, its behavior pattern is abnormal (such as frequently accessing sensitive data outside of working hours), and the vulnerability exposure risk is high, its initial access risk coefficient will increase accordingly.
[0040] S204: Obtain the business task information of each user during the access to the target session, and make an emergency task judgment based on the business task information to obtain the emergency task judgment result; In a specific implementation of the present invention, the step of determining an emergency task based on the business task information and obtaining an emergency task determination result includes: obtaining a task identifier based on the business task information; performing a business impact level analysis based on the business task information to obtain a target business impact level; and determining an emergency task based on the task identifier and the target business impact level to obtain an emergency task determination result.
[0041] Specifically, the process involves acquiring business task information for each user during their access to the target session, and then obtaining a task identifier based on this information. Business task information refers to a set of data associated with a specific business activity performed by a user in the target session. This information may include a task description, task type, task priority, expected completion time, data sensitivity, and any other contextual data related to the task. The task identifier is a unique or quasi-unique string, number, or code extracted from the business task information, used to identify and distinguish different business tasks. The process of obtaining the task identifier may involve parsing the business task information, pattern matching, or obtaining it from the business system through a predefined interface. For example, the task identifier may be a work order number, project number, or specific operation code.
[0042] Based on the business task information, a business impact level analysis is performed to obtain the target business impact level. Business impact level analysis refers to the process of assessing the potential impact of a business task on organizational operations, data security, or compliance. This analysis can be based on a pre-defined rule base, historical data, expert systems, or machine learning models. For example, the business impact level can be determined based on the data sensitivity involved in the task, the impact of the task on key business processes, the urgency of the task, and potential financial or reputational losses. The target business impact level is the result of the business impact level analysis; it quantifies or categorizes the importance or potential risk of a specific business task. For example, the target business impact level can be classified as low, medium, high, or a specific numerical value.
[0043] Based on the task identifier and the target business impact level, an emergency task judgment is performed to obtain an emergency task judgment result. Emergency task judgment refers to the process of determining whether a business task is urgent by comprehensively utilizing the task identifier and the target business impact level. This judgment can be based on preset logical rules; for example, if the task identifier belongs to a specific category and the target business impact level is high or very high, the task is judged as an emergency task. The emergency task judgment result is the output of this judgment process, typically a Boolean value (e.g., "Is it an emergency task" or "Not an emergency task") or a classification label. By refining the emergency task judgment into steps of obtaining the task identifier, performing business impact level analysis, and making a comprehensive judgment based on both, the process of identifying emergency tasks becomes more refined and intelligent. The task identifier provides the uniqueness and type information of the task, while the business impact level analysis assesses the importance of the task from a business perspective. By combining these two aspects of information, misjudgments that may be caused by single-dimensional judgment can be avoided, thereby more accurately identifying business tasks that truly require urgent handling. This ensures that when dynamically adjusting data access permissions, the actual needs and potential risks of the business are fully considered.
[0044] S205: Generate a business exemption factor based on the emergency task judgment result, and adjust the initial access risk coefficient based on the business exemption factor to obtain the target access risk coefficient for each user; In a specific implementation of the present invention, generating a business exemption factor based on the emergency task judgment result includes: identifying whether the emergency task judgment result indicates the existence of an emergency task; if the emergency task judgment result indicates the existence of an emergency task, obtaining the priority and potential business impact of the emergency task; and generating a business exemption factor based on the priority and potential business impact of the emergency task.
[0045] Specifically, the system identifies whether an urgent task exists based on the emergency task judgment result. The output of the emergency task judgment module is analyzed to determine if any urgent business tasks require special handling. For example, if the emergency task judgment result indicates that a business task is marked as urgent, the system will further trigger the subsequent business exemption factor generation process. If the emergency task judgment result indicates that no urgent task exists, there is no need to adjust the initial access risk coefficient; this initial access risk coefficient can be directly used as the final target access risk coefficient.
[0046] If an emergency task is identified as urgent, its priority and potential business impact are determined. The priority of an emergency task can be categorized based on factors such as its importance and timeliness, for example, into high, medium, and low levels. The potential business impact assesses the potential losses or risks to the business if the emergency task is not completed in a timely manner, which can be quantified as economic losses, reputational damage, or compliance risks. This information can be extracted from business task information or obtained through interaction with the business system.
[0047] A business exemption factor is generated based on the priority and potential business impact of the emergency task. This factor is a quantifiable value used to adjust the initial access risk coefficient in subsequent risk coefficient adjustments. For example, an emergency task with a higher priority and greater potential business impact may have a larger business exemption factor, thus receiving greater exemption weight during risk adjustment to ensure the smooth execution of the emergency task. By comprehensively considering these indicators, the system can generate a reasonable business exemption factor that quantifies the corrective effect of the emergency task on the access risk assessment. This mechanism ensures that in emergency business scenarios, the system can flexibly adjust user access permissions, avoiding the obstruction of critical business execution due to strict risk control. The initial access risk coefficient is adjusted based on the business exemption factor to obtain the target access risk coefficient for each user. For example, for a user with a high initial risk coefficient, if they are performing an urgent task, the business exemption factor may appropriately lower their target access risk coefficient to ensure the smooth execution of the urgent task. The generated business exemption factor can more reasonably adjust the initial access risk coefficient, thereby effectively improving the execution efficiency and flexibility of urgent business tasks while ensuring data security, and avoiding impact on business continuity due to excessive security restrictions.
[0048] S206: Perform permission adjustment conflict detection based on the target access risk coefficient of each user, obtain permission adjustment conflict detection results, and determine conflict resolution strategy based on the permission adjustment conflict detection results; In the specific implementation of this invention, the step of performing permission adjustment conflict detection based on the target access risk coefficient of each user and obtaining permission adjustment conflict detection results includes: determining the risk assessment coefficient of each user for the same shared data of the target session based on the target access risk coefficient of each user; determining the suggested adjustment permissions of each user based on the risk assessment coefficient; and performing permission adjustment conflict detection on the suggested adjustment permissions of each user to obtain permission adjustment conflict detection results.
[0049] Specifically, based on the target access risk coefficient of each user, the risk assessment coefficient of each user for the same shared data in the target session is determined. This risk assessment coefficient can quantify the potential risk level of a user accessing shared data in a context where the target access risk coefficient is in effect. For example, it can be calculated comprehensively based on factors such as user history, data sensitivity, and access terminal status.
[0050] Based on the aforementioned risk assessment coefficient, the system determines recommended adjustment permissions for each user. Recommended permission adjustments refer to data access permissions suggested by the system to better suit the current risk situation, based on the risk assessment results. For example, if the risk assessment coefficient is high, the recommended permission adjustment might be to reduce the user's access permissions to mitigate potential risks; conversely, if the risk assessment coefficient is low, the system might recommend maintaining or increasing the user's access permissions to improve work efficiency.
[0051] The system performs conflict detection on suggested permission adjustments for each user, obtaining the conflict detection results. This detection aims to identify potential conflicts that may arise when multiple users simultaneously or sequentially adjust permissions. For example, different users may submit contradictory permission adjustment requests for the same shared data, or a user's permission adjustment may affect other users' normal access. This detection ensures the rationality, consistency, and security of permission adjustments, enabling refined management of the data access permission adjustment process. By introducing a risk assessment coefficient, the basis for permission adjustments becomes more objective and quantifiable, avoiding biases caused by subjective judgment. Furthermore, conflict detection on suggested permission adjustments effectively prevents potential conflicts and security vulnerabilities that may arise from permission adjustments in a multi-user environment, thereby significantly improving the accuracy, security, and system stability of data access permission adjustments, ensuring that data access permissions are always in an optimal configuration state even in a dynamically changing risk environment.
[0052] Based on the detection results of permission adjustment conflicts, a conflict resolution strategy is determined. This strategy refers to a series of predefined rules or algorithms used by the system to resolve conflicts when they are detected. For example, when multiple users submit conflicting permission adjustment requests for the same shared data, the conflict resolution strategy can specify priority levels (e.g., downgrading high-risk users, maintaining permissions for users with urgent tasks), adhere to the majority rule, or resolve the conflict through administrator approval. The aim is to ensure logical consistency and system stability in permission adjustments.
[0053] Furthermore, the step of performing permission adjustment conflict detection on the suggested adjustment permissions of each user and obtaining permission adjustment conflict detection results includes: performing timestamp verification on the suggested adjustment permissions of each user and obtaining timestamp verification results; performing sequence number comparison on the suggested adjustment permissions of each user and obtaining sequence number comparison results; performing false conflict detection based on the timestamp verification results and sequence number comparison results to obtain a first false conflict detection result; obtaining the permission status and network environment quality indicators corresponding to the same shared data in the target session; performing false conflict detection based on the permission status and network environment quality indicators corresponding to the same shared data and the suggested adjustment permissions of each user to obtain a second false conflict detection result; and determining the permission adjustment conflict detection result based on the first false conflict detection result and the second false conflict detection result.
[0054] Specifically, timestamp verification is performed on each user's suggested permission adjustments. This verification aims to validate the timeliness and validity of permission adjustment requests. For example, if the timestamp of a permission adjustment request is significantly delayed or advanced compared to the current system time, it may indicate that the request is invalid, expired, or at risk of malicious tampering. Timestamp verification effectively filters out such abnormal requests, ensuring that subsequent permission adjustment requests are timely.
[0055] The suggested permission adjustment requests for each user are compared using sequence numbers. The purpose of obtaining the sequence number comparison results is to identify and handle potentially duplicate or out-of-order permission adjustment requests. In distributed or high-concurrency environments, permission adjustment requests may become out of order due to network latency or system processing sequence. By comparing sequence numbers, it can be ensured that each request is uniquely identified and processed in the correct order, thereby avoiding false conflicts caused by duplicate or out-of-order requests.
[0056] Based on the timestamp verification result and the sequence number comparison result, a false conflict detection is performed to obtain the first false conflict detection result. This step mainly focuses on potential conflicts caused by time or sequence issues. For example, two seemingly conflicting permission adjustment requests may be identified as false conflicts after verification of timestamps and sequence numbers, and it may be found that one of the requests has expired or is a duplicate request.
[0057] Obtain the permission status and network environment quality indicators corresponding to the same shared data in the target session. The permission status refers to the access permission configuration of the current shared data, while the network environment quality indicators can include parameters such as network latency, packet loss rate, and bandwidth. These indicators can reflect the reliability and efficiency of the current network communication.
[0058] Based on the permission status and network environment quality indicators corresponding to the same shared data, combined with user suggestions, a false conflict detection is performed to obtain a second false conflict detection result. This detection aims to consider the impact of external environmental factors on the judgment of permission adjustment conflicts. For example, in the case of poor network environment quality, the transmission of permission adjustment requests may be delayed, causing the system to receive multiple seemingly conflicting requests that are actually different stages of the same adjustment process within a short period of time. By combining permission status and network environment quality indicators, the system can more accurately determine whether these situations are genuine conflicts, rather than temporary inconsistencies caused by environmental factors.
[0059] Based on the first and second false conflict detection results, the permission adjustment conflict detection results are determined, providing a comprehensive basis for accurate conflict judgment in subsequent permission adjustments. By introducing timestamp verification and sequence number comparison mechanisms, false conflicts caused by request timeliness or sequence issues can be effectively identified and eliminated. Simultaneously, considering shared data permission status and network environment quality indicators, the accuracy and robustness of conflict detection are further enhanced, enabling the system to distinguish between genuine permission conflicts and temporary inconsistencies caused by external environmental factors. This avoids invalid operations or wasted system resources due to misjudged conflicts. It helps ensure a smoother, more efficient, and reliable data access permission adjustment process, thereby improving the stability and user experience of the entire data security access system. The system can more accurately identify genuine conflicts requiring manual intervention or special handling, while automatically handling or ignoring non-substantive conflicts, thus optimizing the efficiency of permission management.
[0060] S207: Based on the target access risk coefficient, perform risk jump analysis using past access risk records to obtain risk jump information; In the specific implementation of this invention, risk jump analysis is performed based on the target access risk coefficient using past access risk records to obtain risk jump information. Risk jump analysis can be understood as identifying situations where the risk coefficient changes significantly within a short period by comparing and analyzing trends between the target access risk coefficient and past access risk records. Past access risk records refer to the data set of users' historical access risk coefficients accumulated by the system over a long period. Risk jump information is the result of risk jump analysis, which specifically includes the magnitude, direction, frequency, and duration of risk changes. Its purpose is to quantify the dynamic characteristics of risk changes, providing a more refined basis for subsequent permission adjustments.
[0061] S208: Determine the permission adjustment smoother and the gradual permission adjustment path based on the risk jump information; In a specific implementation of the present invention, determining the permission adjustment smoother and the gradual permission adjustment path based on the risk jump information includes: determining the degree of risk change and the frequency of risk change based on the risk jump information, and determining the permission adjustment smoother based on the degree of risk change and the frequency of risk change; and determining the gradual permission adjustment path based on the risk jump information combined with the permission adjustment rate parameter.
[0062] Specifically, based on the risk jump information, the degree and frequency of risk change are determined. The degree of risk change refers to the magnitude of the change in the risk coefficient, such as the quantitative difference between a low-risk and high-risk jump. The frequency of risk change refers to the number or rate at which the risk coefficient jumps within a certain period of time. These indicators can be obtained through statistical analysis, trend prediction, or anomaly detection algorithms on historical access risk records. Based on the degree and frequency of risk change, a permission adjustment smoother is determined. The permission adjustment smoother can be understood as a mechanism or parameter used to adjust the rate and magnitude of permission adjustments. Its purpose is to avoid sudden changes in permissions, making the permission adjustment process smoother and more gradual. For example, the permission adjustment smoother can be a damping coefficient, a time delay parameter, or a piecewise function, used to gradually, rather than immediately, adjust the user's access permissions when a risk jump occurs. In practical applications, the permission adjustment rate parameter refers to a preset parameter used to control the speed of permission adjustment. For example, when the risk increases, permissions can be adjusted at a rate of decreasing by 5% per minute; when the risk decreases, permissions can be adjusted at a rate of increasing by 2% per minute.
[0063] Based on the aforementioned risk jump information and the permission adjustment rate parameter, a progressive permission adjustment path is determined. This path refers to the specific trajectory or sequence by which permission values gradually transition from the current state to the target state during the permission adjustment process. The determination of this path aims to ensure the continuity and predictability of the permission adjustment process, avoiding service interruptions or user confusion caused by sudden permission changes. The refined identification of risk jump characteristics enables the permission adjustment smoother to adaptively adjust according to the specific circumstances of risk changes, avoiding the inadequacies that may arise from a single fixed smoother. Furthermore, by combining this with the permission adjustment rate parameter, the construction of the progressive permission adjustment path is further refined, ensuring that permission adjustments are not only smooth but also have a controllable speed and direction. This mechanism effectively avoids sudden drops or increases in permissions due to risk mutations, ensuring that permissions can be adjusted in an acceptable, gradual, and progressive manner when risks change dynamically. This significantly improves the flexibility, stability, and user satisfaction of secure data access, thereby guaranteeing user access continuity and system stability in risk-changing environments.
[0064] S209: Adjust the data access permissions of each user based on the conflict resolution strategy, permission adjustment smoother, and progressive permission adjustment path.
[0065] In the specific implementation of this invention, data access permissions for each user are adjusted based on the conflict resolution strategy, permission adjustment smoother, and gradual permission adjustment path. By introducing the conflict resolution strategy, risk jump analysis, permission adjustment smoother, and gradual permission adjustment path, the problems of abruptness, instability, and impact on business processes that may exist in the basic solution regarding permission adjustment are effectively solved. Specifically, when the system needs to adjust data access permissions based on the permission adjustment conflict detection results and the target access risk coefficient, firstly, the potential permission adjustment conflicts are handled through the conflict resolution strategy to ensure the logical rationality of the adjustment. Secondly, risk jump analysis is performed on the target access risk coefficient to identify the dynamic change characteristics of the risk, which enables the system to more accurately understand the urgency and persistence of the risk. On this basis, the permission adjustment smoother is determined using the risk jump information. This smoother can buffer the magnitude of permission adjustment, avoiding sudden drops or increases in permissions due to sudden changes in risk. At the same time, a gradual permission adjustment path is determined in conjunction with the risk jump information, decomposing the permission adjustment into multiple small steps, making the change of permissions a gradual transition process. Ultimately, based on the aforementioned conflict resolution strategies, permission adjustment smoother, and gradual permission adjustment path, the data access permissions for each user are adjusted to achieve a smooth, orderly, and secure permission adjustment process.
[0066] By adjusting users' data access permissions through conflict resolution strategies, permission adjustment smoothers, and progressive permission adjustment paths, more refined and user-friendly data access permission adjustments can be achieved. Conflict resolution strategies effectively handle complex permission conflict scenarios, avoiding contradictory system decisions. The combination of risk jump analysis, permission adjustment smoothers, and progressive permission adjustment paths ensures that permission adjustment is no longer a rigid, one-size-fits-all approach, but rather carried out in a smooth and gradual manner based on the dynamic changes in risk trends. This not only significantly reduces the interference of permission adjustments on users' normal business operations and improves the user experience, but also enhances the system's adaptability and robustness in the face of dynamic risks, effectively avoiding new security risks or business interruptions caused by improper permission adjustments, thereby improving the overall reliability of secure data access.
[0067] In this embodiment of the invention, authentication is performed based on identity credentials, and a target session is created based on the authentication results of each user to determine the data access permissions of each user in the target session. Access terminal status information and access behavior characteristic information of each user during access to the target session are obtained. Vulnerability exposure risk analysis is performed based on the vulnerability behavior feature library and access terminal status information, which can more comprehensively identify and assess potential vulnerabilities of the access terminal, providing more accurate data support for subsequent risk analysis. Access risk analysis is performed based on access terminal status information, access behavior characteristic information, and vulnerability exposure risk information to obtain the initial access risk coefficient of each user. Business task information of each user during access to the target session is obtained, and emergency task judgment is performed based on the business task information. A business exemption factor is generated based on the emergency task judgment result, and the initial access risk coefficient is adjusted based on the business exemption factor to obtain a more context-aware target access risk coefficient. Permission adjustment conflict detection is performed based on the target access risk coefficient of each user, and data access permissions are adjusted based on the permission adjustment conflict detection result and the target access risk coefficient. This enables dynamic and intelligent adjustment of user access permissions, effectively solving the problem that traditional static permission control cannot cope with complex and ever-changing access environments, and significantly improving the security of data access.
[0068] Example 3 Please see Figure 3 , Figure 3 This is a schematic diagram of the structural composition of a data security access system according to an embodiment of the present invention. The system includes: Initial permission allocation module 31: used to obtain the identity credentials of each user, perform identity verification based on the identity credentials, obtain the identity verification result, create a target session based on the identity verification result of each user, and determine the data access permissions of each user in the target session; Vulnerability risk analysis module 32: used to obtain access terminal status information and access behavior characteristic information of each user during access to the target session, construct a vulnerability behavior feature library, and perform vulnerability exposure risk analysis based on the vulnerability behavior feature library and access terminal status information to obtain vulnerability exposure risk information; Access risk analysis module 33: used to perform access risk analysis based on the access terminal status information, access behavior characteristic information and vulnerability exposure risk information, and obtain the initial access risk coefficient of each user; Emergency task judgment module 34: used to obtain the business task information of each user during the access to the target session, and to make an emergency task judgment based on the business task information to obtain the emergency task judgment result; Coefficient adjustment module 35: used to generate a business exemption factor based on the emergency task judgment result, and adjust the initial access risk coefficient based on the business exemption factor to obtain the target access risk coefficient for each user; Permission adjustment module 36: is used to perform permission adjustment conflict detection based on the target access risk coefficient of each user, obtain permission adjustment conflict detection results, and adjust the data access permissions based on the permission adjustment conflict detection results and the target access risk coefficient.
[0069] In the specific implementation of this invention, the specific implementation methods of the system items can be referred to the implementation methods of the above-mentioned method items, and will not be repeated here.
[0070] In this embodiment of the invention, authentication is performed based on identity credentials, and a target session is created based on the authentication results of each user to determine the data access permissions of each user in the target session. Access terminal status information and access behavior characteristic information of each user during access to the target session are obtained. Vulnerability exposure risk analysis is performed based on the vulnerability behavior feature library and access terminal status information, which can more comprehensively identify and assess potential vulnerabilities of the access terminal, providing more accurate data support for subsequent risk analysis. Access risk analysis is performed based on access terminal status information, access behavior characteristic information, and vulnerability exposure risk information to obtain the initial access risk coefficient of each user. Business task information of each user during access to the target session is obtained, and emergency task judgment is performed based on the business task information. A business exemption factor is generated based on the emergency task judgment result, and the initial access risk coefficient is adjusted based on the business exemption factor to obtain a more context-aware target access risk coefficient. Permission adjustment conflict detection is performed based on the target access risk coefficient of each user, and data access permissions are adjusted based on the permission adjustment conflict detection result and the target access risk coefficient. This enables dynamic and intelligent adjustment of user access permissions, effectively solving the problem that traditional static permission control cannot cope with complex and ever-changing access environments, and significantly improving the security of data access.
[0071] Those skilled in the art will understand that all or part of the steps in the various methods of the above embodiments can be implemented by a program instructing related hardware. The program can be stored in a computer-readable storage medium, which may include: read-only memory (ROM), random access memory (RAM), magnetic disk or optical disk, etc.
[0072] Furthermore, the above provides a detailed description of the data security access method and system provided by the embodiments of the present invention. Specific examples have been used to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only for the purpose of helping to understand the method and core ideas of the present invention. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of the present invention. Therefore, the content of this specification should not be construed as a limitation of the present invention.
Claims
1. A method for secure data access, characterized in that, The method includes: Obtain the identity credentials of each user, perform identity verification based on the identity credentials, obtain the identity verification result, create a target session based on the identity verification result of each user, and determine the data access permissions of each user in the target session; Acquire the access terminal status information and access behavior characteristic information of each user during the access to the target session, construct a vulnerability behavior feature library, and perform vulnerability exposure risk analysis based on the vulnerability behavior feature library and access terminal status information to obtain vulnerability exposure risk information. Based on the access terminal status information, access behavior characteristic information and vulnerability exposure risk information, an access risk analysis is performed to obtain the initial access risk coefficient for each user. Obtain the business task information of each user during the access to the target session, and make an emergency task judgment based on the business task information to obtain the emergency task judgment result; Based on the emergency task judgment result, a business exemption factor is generated, and the initial access risk coefficient is adjusted based on the business exemption factor to obtain the target access risk coefficient for each user. Based on the target access risk coefficient of each user, permission adjustment conflict detection is performed to obtain the permission adjustment conflict detection result, and the data access permission is adjusted based on the permission adjustment conflict detection result and the target access risk coefficient; The process of constructing a vulnerability behavior feature library and performing vulnerability exposure risk analysis based on the vulnerability behavior feature library and access terminal status information to obtain vulnerability exposure risk information includes: acquiring security test information of the network stack and extracting vulnerability identifiers, trigger condition descriptions, vulnerability behavior features, and vulnerability risk levels based on the security test information; constructing a vulnerability behavior feature library based on the vulnerability identifiers, trigger condition descriptions, vulnerability behavior features, and vulnerability risk levels; performing network instantaneous encryption weakening analysis based on the access terminal status information to obtain network instantaneous encryption weakening information; performing electromagnetic interference analysis based on the access terminal status information to obtain electromagnetic interference information; performing network stack behavior analysis based on the network instantaneous encryption weakening information and electromagnetic interference information to obtain network stack behavior information; and performing vulnerability exposure risk analysis using the network stack behavior information based on the vulnerability behavior feature library to obtain vulnerability exposure risk information. The step of adjusting the data access permissions based on the permission adjustment conflict detection results and the target access risk coefficient includes: determining a conflict resolution strategy based on the permission adjustment conflict detection results; performing risk jump analysis using past access risk records based on the target access risk coefficient to obtain risk jump information; determining a permission adjustment smoother and a gradual permission adjustment path based on the risk jump information; and adjusting the data access permissions of each user based on the conflict resolution strategy, the permission adjustment smoother, and the gradual permission adjustment path.
2. The data security access method according to claim 1, characterized in that, The network stack behavior analysis based on the instantaneous encryption weakening information and electromagnetic interference information to obtain network stack behavior information includes: Based on the network's instantaneous encryption weakening information and electromagnetic interference information, a probe data packet is generated and transmitted to each user's access terminal; Obtain the CPU utilization, memory usage changes, protocol state machine, and system logs of each user's access terminal when processing the probe data packets; Network stack behavior analysis is performed based on the CPU utilization, memory usage changes, protocol state machine, and system logs to obtain network stack behavior information.
3. The data security access method according to claim 1, characterized in that, The step of determining the urgency of a task based on the business task information and obtaining the urgency determination result includes: Obtain the task identifier based on the aforementioned business task information; Based on the business task information, a business impact level analysis is performed to obtain the target business impact level; Based on the task identifier and the target business impact level, an emergency task determination is made to obtain the emergency task determination result.
4. The data security access method according to claim 1, characterized in that, The generation of the business exemption factor based on the emergency task assessment result includes: Identify whether the result of the emergency task determination indicates that an emergency task exists; If the emergency task assessment result indicates that an emergency task exists, obtain the priority and potential business impact of the emergency task. A business exemption factor is generated based on the priority of the emergency task and the degree of its potential business impact.
5. The data security access method according to claim 1, characterized in that, The permission adjustment conflict detection based on the target access risk coefficient of each user, and the resulting permission adjustment conflict detection results, include: The risk assessment coefficient for each user's access to the same shared data in the target session is determined based on the target access risk coefficient of each user. The suggested adjustment permissions for each user are determined based on the aforementioned risk assessment coefficient; Perform permission adjustment conflict detection on the suggested permission adjustments for each user, and obtain the permission adjustment conflict detection results.
6. The data security access method according to claim 5, characterized in that, The proposed permission adjustment for each user is used to perform permission adjustment conflict detection, and the resulting conflict detection results are as follows: The timestamp verification is performed on the suggested permission adjustments for each user, and the timestamp verification results are obtained. The suggested permission adjustments for each user are compared using serial numbers to obtain the serial number comparison results. Based on the timestamp verification result and the serial number comparison result, a false conflict detection is performed to obtain the first false conflict detection result; Obtain the permission status and network environment quality indicators corresponding to the same shared data in the target session; Based on the permission status and network environment quality indicators corresponding to the same shared data, combined with the suggestions of each user, permissions are adjusted to perform false conflict detection and obtain a second false conflict detection result. The permission adjustment conflict detection result is determined based on the first false conflict detection result and the second false conflict detection result.
7. The data security access method according to claim 1, characterized in that, The process of determining the permission adjustment smoother and the gradual permission adjustment path based on the risk jump information includes: Based on the risk jump information, the degree and frequency of risk change are determined, and based on the degree and frequency of risk change, a permission adjustment smoother is determined. Based on the risk jump information and the permission adjustment rate parameter, a gradual permission adjustment path is determined.
8. A data security access system, characterized in that, The system includes: Initial permission allocation module: used to obtain the identity credentials of each user, perform identity verification based on the identity credentials, obtain the identity verification result, create a target session based on the identity verification result of each user, and determine the data access permissions of each user in the target session; Vulnerability risk analysis module: used to obtain access terminal status information and access behavior characteristic information of each user during access to the target session, build a vulnerability behavior feature library, and perform vulnerability exposure risk analysis based on the vulnerability behavior feature library and access terminal status information to obtain vulnerability exposure risk information; Access risk analysis module: used to perform access risk analysis based on the access terminal status information, access behavior characteristic information and vulnerability exposure risk information, and obtain the initial access risk coefficient for each user; Emergency Task Judgment Module: Used to obtain the business task information of each user during the access to the target session, and to make an emergency task judgment based on the business task information to obtain the emergency task judgment result; Coefficient adjustment module: used to generate a business exemption factor based on the emergency task judgment result, and adjust the initial access risk coefficient based on the business exemption factor to obtain the target access risk coefficient for each user; Permission adjustment module: used to perform permission adjustment conflict detection based on the target access risk coefficient of each user, obtain permission adjustment conflict detection results, and adjust the data access permissions based on the permission adjustment conflict detection results and the target access risk coefficient; The process of constructing a vulnerability behavior feature library and performing vulnerability exposure risk analysis based on the vulnerability behavior feature library and access terminal status information to obtain vulnerability exposure risk information includes: acquiring security test information of the network stack and extracting vulnerability identifiers, trigger condition descriptions, vulnerability behavior features, and vulnerability risk levels based on the security test information; constructing a vulnerability behavior feature library based on the vulnerability identifiers, trigger condition descriptions, vulnerability behavior features, and vulnerability risk levels; performing network instantaneous encryption weakening analysis based on the access terminal status information to obtain network instantaneous encryption weakening information; performing electromagnetic interference analysis based on the access terminal status information to obtain electromagnetic interference information; performing network stack behavior analysis based on the network instantaneous encryption weakening information and electromagnetic interference information to obtain network stack behavior information; and performing vulnerability exposure risk analysis using the network stack behavior information based on the vulnerability behavior feature library to obtain vulnerability exposure risk information. The step of adjusting the data access permissions based on the permission adjustment conflict detection results and the target access risk coefficient includes: determining a conflict resolution strategy based on the permission adjustment conflict detection results; performing risk jump analysis using past access risk records based on the target access risk coefficient to obtain risk jump information; determining a permission adjustment smoother and a gradual permission adjustment path based on the risk jump information; and adjusting the data access permissions of each user based on the conflict resolution strategy, the permission adjustment smoother, and the gradual permission adjustment path.
Citation Information
Patent Citations
General surgery department medical information sharing method and system based on medical big data
CN119380917A
Block chain-based shopping mall supply chain management method and system
CN120197897A
Multi-level dynamic data access control method and device based on credential environment
CN120729631A