Method and electronic device for data security access control
By generating data access scenario types and fine-grained control domains, and combining real-time monitoring factors and policy factors, permissions are dynamically adjusted, solving the problems of single risk assessment and insufficient permission control in traditional data access control methods, and realizing multi-dimensional dynamic risk assessment and precise access control.
Patent Information
- Application Number
- CN202511848270.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-09
- Publication Date
- 2026-08-25
- Estimated Expiration
- 2045-12-09
AI Technical Summary
Traditional data access control methods are ill-suited to complex and ever-changing network environments. Their risk assessments are too simplistic and fail to accurately identify high-risk accesses. Furthermore, their access control lacks dynamic adjustment, leading to excessive data exposure and a high risk of failure.
By acquiring data access requests, scenario types are generated, fine-grained access control domains and evaluation dimension parameters are set, dynamic risk coefficients are calculated in conjunction with real-time monitoring factors, policy factors and permission transmission paths are generated, and dynamic access control operations are executed based on security evaluation coefficients.
It enables multi-dimensional dynamic risk assessment, accurately identifies high-risk access, dynamically adjusts permissions, improves data access security, reduces security risks, and adapts to complex access environments.
Smart Images

Figure CN121509059B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data security technology, and more specifically, to a method for data security access control. Background Technology
[0002] In the digital age, data has become a key production factor, making the need for secure data access increasingly urgent. Traditional data access control methods are ill-suited to the complex and ever-changing network environment and sophisticated data security requirements. Past solutions have been relatively singular in their risk assessment dimensions, often focusing on identity while neglecting the synergistic effects of multiple factors such as device status, network environment, and access time. This leads to inaccurate risk identification and an inability to accurately block high-risk access. Furthermore, access control lacks dynamic adjustment capabilities, and permission transmission fails to consider the correlation between policy factors and the actual frequency and overlap of interactions, making precise control difficult and resulting in excessive data exposure and high risk. Summary of the Invention
[0003] In view of the shortcomings of the existing technology, the purpose of this invention is to provide a method for data security access control.
[0004] To achieve the above objectives, the present invention provides the following technical solution: A method for data security access control, the method comprising the following steps: Obtain the data access request from the data access subject, and generate the data access scenario type based on the data access request; Set the control domain for fine-grained access, the corresponding evaluation dimension parameters for the control domain, and the risk weights corresponding to the evaluation dimension parameters based on the data access scenario type. Real-time monitoring factors for fine-grained access control domains are obtained based on evaluation dimension parameters. Dynamic risk coefficients for control domains are obtained based on real-time monitoring factors, evaluation dimension parameters, and risk weights. High-risk data access requests are obtained by comparing and analyzing the dynamic risk coefficients with preset risk thresholds. Strategy factors are generated based on the identity attributes of the data access subject and the data resource tags; Obtain the association mapping relationship of strategy factors, and generate the permission transmission path between strategy factors and the influence weight coefficient of the path based on the association mapping relationship; Obtain the high-risk policy factor corresponding to the high-risk data access request; process the policy factor and permission propagation path to obtain the restricted permission factor; Based on the high-risk strategy factor and the restricted access factor, a security assessment coefficient for the data access request is obtained, and the corresponding data access control operation is executed based on the security assessment coefficient.
[0005] Preferably, the restricted permission factor is obtained by processing the strategy factor and the permission propagation path, specifically including the following steps: A dynamic authorization model is constructed based on policy factors and permission propagation paths; The correlation influence factors of high-risk strategy factors are obtained based on the dynamic authorization model, and the authority decay coefficient of high-risk strategy factors on correlation influence factors is obtained based on the dynamic authorization model. The comprehensive permission coefficient of the related influence factor is obtained based on the permission decay coefficient and the basic permission coefficient corresponding to the related influence factor; the restricted permission factor is obtained by comparing and analyzing the comprehensive permission coefficient with the preset permission threshold.
[0006] Preferably, the evaluation dimension parameters include identity authentication strength, device security status, network environment trustworthiness, and access time characteristics.
[0007] Preferably, the dynamic risk coefficient of the control domain is obtained based on real-time monitoring factors, assessment dimension parameters, and risk weights, specifically including the following steps: The factor deviation value is calculated based on the benchmark values of the real-time monitoring factors and the evaluation dimension parameters; The dynamic risk coefficient of the control domain is obtained by weighting and summing the factor deviation values according to the risk weights.
[0008] Preferably, the dynamic risk coefficient is compared and analyzed with a preset risk threshold to obtain high-risk data access requests, specifically including the following steps: If the dynamic risk coefficient is less than the preset risk threshold, the risk level of the data access request is judged to be normal. If the dynamic risk coefficient is greater than or equal to the preset risk threshold, the risk level of the data access request is judged to be abnormal, and the access request is recorded as a high-risk data access request.
[0009] Preferably, the generation of permission transmission paths and corresponding influence weight coefficients between strategy factors based on the association mapping relationship specifically includes the following steps: Based on the association mapping relationship, the associated factor set of the strategy factors, the permission dependency relationship between the strategy factors, the data interaction frequency and the degree of overlap of the access scope are obtained; Based on the permission dependency relationship, the permission pointing tags of the policy factors and the associated factor set are obtained. All policy factors have permission pointing tags, and the permission transmission path between policy factors is generated based on the permission pointing tags. Set frequency influence weights, and calculate the first transmission coefficient based on the frequency influence weights and data interaction frequency; Set the range influence weight, and calculate the second transmission coefficient based on the range influence weight and the overlap of the access range; Set a first weight coefficient and a second weight coefficient, and obtain the influence weight coefficient corresponding to the permission transmission path based on the weighted sum of the first weight coefficient and the first transmission coefficient, and the second weight coefficient and the second transmission coefficient.
[0010] Preferably, the correlation influence factors of high-risk strategy factors are obtained based on the dynamic authorization model, and the authority decay coefficient of high-risk strategy factors on correlation influence factors is obtained based on the dynamic authorization model. Specifically, this includes the following steps: Obtain the permission pointer markers for high-risk strategy factors, obtain the target transmission path of high-risk strategy factors based on the permission pointer markers, and obtain the corresponding related influencing factors based on the target transmission path; Obtain the permission transmission path between high-risk strategy factors and related influencing factors, and record the influence weight coefficients corresponding to the permission transmission path as the target weight coefficients; The authority decay coefficient is calculated based on the target weight coefficient and the dynamic risk coefficient corresponding to the high-risk strategy factor.
[0011] Preferably, the restricted permission factor is obtained by processing the strategy factor and the permission propagation path, specifically including the following steps: The comprehensive authority coefficient of the associated influence factor is obtained by multiplying the authority attenuation coefficient with the basic authority coefficient corresponding to the associated influence factor. If the overall permission coefficient is less than the preset permission threshold, the permission status of the associated influence factor is determined to be abnormal, and the associated influence factor is recorded as a restricted permission factor.
[0012] Preferably, based on the high-risk strategy factor and the restricted access factor, a security assessment coefficient for the data access request is obtained, and the corresponding data access control operation is performed based on the security assessment coefficient, specifically including the following steps: Obtain the first risk percentage corresponding to the high-risk strategy factor in the dynamic authorization model; Obtain the second risk percentage corresponding to the restricted permission factor in the dynamic authorization model; Set risk impact weights and authority impact weights, and obtain the security assessment coefficient based on the weighted sum of the risk impact weights and the proportion of the first risk, and the authority impact weights and the proportion of the second risk. When the security assessment coefficient is less than the preset security threshold, normal access authorization is performed; When the security assessment coefficient is greater than or equal to the preset security threshold, anonymization access or access denial operation will be performed.
[0013] An electronic device includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the method for secure data access control.
[0014] Compared with the prior art, the present invention has the following beneficial effects: This invention identifies high-risk data access requests by acquiring access request generation scenario types, then setting targeted control domains, evaluation dimension parameters, and risk weights, and calculating dynamic risk coefficients based on real-time monitoring factors. This allows risk assessment to move beyond relying on single static factors, comprehensively considering dynamic changes across multiple dimensions such as user, device, network, and time. This makes risk assessment more closely aligned with actual access scenarios, effectively improving the ability to perceive and identify potential threats and reducing security risks from high-risk access at the source. Policy factors are generated based on identity attributes and data tags, and related mapping relationships are mined to construct permission transmission paths and influence weights. Furthermore, restricted permission factors are obtained by processing high-risk factors, achieving fine-grained and dynamic permission control. Security assessment coefficients are calculated based on high-risk policy factors and restricted permission factors, and differentiated access control operations are then executed, providing a quantifiable and dynamic basis for security decisions. Different risk levels correspond to different processing methods, flexibly adapting to diverse business access needs while promptly implementing strict protective measures when risks exceed thresholds. This achieves a balance between data security and business efficiency, helping enterprises comprehensively protect data asset security in complex data access environments. Attached Figure Description
[0015] Figure 1 This is a schematic diagram illustrating the steps of a data security access control method proposed in this invention; Figure 2 This is a schematic diagram illustrating the steps of obtaining the restricted access factor in a data security access control method proposed in this invention; Figure 3 This is a schematic diagram of the structure of the electronic device provided in an embodiment of the present invention.
[0016] 610. Processor; 620. Communication interface; 630. Memory; 640. Communication bus. Detailed Implementation
[0017] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings.
[0018] Many specific details are set forth in the following description in order to provide a full understanding of the invention. However, the invention may also be practiced in other ways different from those described herein, and those skilled in the art can make similar extensions without departing from the spirit of the invention. Therefore, the invention is not limited to the specific embodiments disclosed below.
[0019] Secondly, the term "an embodiment" or "embodiment" as used herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The phrase "in one embodiment" appearing in different places throughout this specification does not necessarily refer to the same embodiment, nor is it a single embodiment or an embodiment selectively excluded from other embodiments.
[0020] Reference Figures 1-3 As shown.
[0021] The embodiments further illustrate the data security access control method proposed in this invention.
[0022] A method for data security access control, the method comprising the following steps: Obtain the data access request from the data access subject, and generate the data access scenario type based on the data access request; Set the control domain for fine-grained access, the corresponding evaluation dimension parameters for the control domain, and the risk weights corresponding to the evaluation dimension parameters based on the data access scenario type. Real-time monitoring factors for fine-grained access control domains are obtained based on evaluation dimension parameters. Dynamic risk coefficients for control domains are obtained based on real-time monitoring factors, evaluation dimension parameters, and risk weights. High-risk data access requests are obtained by comparing and analyzing the dynamic risk coefficients with preset risk thresholds. Strategy factors are generated based on the identity attributes of the data access subject and the data resource tags; Obtain the association mapping relationship of strategy factors, and generate the permission transmission path between strategy factors and the influence weight coefficient of the path based on the association mapping relationship; Obtain the high-risk policy factor corresponding to the high-risk data access request; process the policy factor and permission propagation path to obtain the restricted permission factor; Based on the high-risk strategy factor and the restricted access factor, a security assessment coefficient for the data access request is obtained, and the corresponding data access control operation is executed based on the security assessment coefficient.
[0023] First, obtain the data access request issued by the data access subject. The data access request includes the access object and the access purpose. Based on the access object and the access purpose, generate the corresponding data access scenario type, such as the data query scenario of the internal office system or the data retrieval scenario of the external cooperation platform.
[0024] Based on the generated data access scenario type, fine-grained access control domains are set. The control domain defines the scope of data access control. At the same time, the corresponding evaluation dimension parameters are determined for the control domain, such as the authentication method of the access subject, the security status of the device used, the trustworthiness of the network environment, and the characteristics of the access time. Furthermore, corresponding risk weights are assigned to each evaluation dimension parameter. The degree of influence of each parameter on risk varies in different scenarios.
[0025] Based on the set evaluation dimension parameters, real-time monitoring factors for the fine-grained access control domain are obtained, which are the actual data performance of each evaluation dimension during actual access. Combining the evaluation dimension parameters and risk weights, a dynamic risk coefficient for the control domain is obtained. This dynamic risk coefficient reflects the risk level of the current access request. The dynamic risk coefficient is compared with a preset risk threshold to determine high-risk data access requests.
[0026] In terms of access control policies, policy factors are generated based on the identity attributes of the data access subject, such as ordinary employees, administrators, and external partners. The data resources themselves may be labeled as sensitive data or public data.
[0027] Obtain the correlation mapping relationship between strategy factors, understand the connection between different strategy factors, generate the permission transmission path between strategy factors based on this relationship, and determine the influence weight coefficient corresponding to the path to measure the degree of influence of this transmission.
[0028] Once a high-risk data access request is identified, its corresponding high-risk policy factor is located. Then, the policy factor and permission transmission path are processed to determine how permission transmission is restricted under high-risk conditions, thereby obtaining the restricted permission factor and clarifying which permissions are restricted due to risk.
[0029] By combining the risk level represented by the high-risk strategy factor and the permission restrictions reflected by the restricted permission factor, a security assessment coefficient for the data access request is obtained, and corresponding operations are performed based on the security assessment coefficient.
[0030] The restricted permission factor is obtained by processing the policy factor and the permission propagation path, specifically including the following steps: A dynamic authorization model is constructed based on policy factors and permission propagation paths; The correlation influence factors of high-risk strategy factors are obtained based on the dynamic authorization model, and the authority decay coefficient of high-risk strategy factors on correlation influence factors is obtained based on the dynamic authorization model. The comprehensive permission coefficient of the related influence factor is obtained based on the permission decay coefficient and the basic permission coefficient corresponding to the related influence factor; the restricted permission factor is obtained by comparing and analyzing the comprehensive permission coefficient with the preset permission threshold.
[0031] First, a dynamic authorization model is constructed using policy factors and permission transmission paths. Policy factors cover key information such as the identity of the access subject and the attributes of data resources, while permission transmission paths clarify the relationship logic between different policy factors in the transfer of permissions. The combination of the two provides a basic framework for subsequent dynamic adjustment of permissions.
[0032] The dynamic authorization model identifies the associated influencing factors of high-risk strategy factors, thereby identifying other strategy factors that have permission relationships with high-risk strategy factors and are affected by their risk transmission. Simultaneously, the dynamic authorization model assesses the impact of high-risk strategy factors on these associated influencing factors, deriving a permission attenuation coefficient. This coefficient reflects the degree to which high-risk strategy factors weaken the permissions of associated influencing factors; the higher the risk, the larger the attenuation coefficient, and the more significant the impact on permissions.
[0033] By combining the permission decay coefficient with the original base permission coefficient of the related influencing factor, a comprehensive permission coefficient for the related influencing factor is obtained. The base permission coefficient represents the normal permission level of the related influencing factor under no-risk interference, while the decay coefficient reflects the actual permission situation after risk. The comprehensive permission coefficient is compared with a preset permission threshold. If the comprehensive permission coefficient is lower than the threshold, it indicates that the permission of the related influencing factor is restricted due to high risk, thus classifying it as a restricted permission factor. This achieves dynamic control of permissions in high-risk scenarios, avoiding data security risks caused by excessively high permissions.
[0034] The evaluation dimensions include authentication strength, device security status, network environment trustworthiness, and access time characteristics.
[0035] Assessment dimensions and parameters are key elements in constructing a dynamic risk assessment system, used to measure the risk level of data access requests. Among them, authentication strength focuses on the authentication method of the accessing entity. For example, using multi-factor authentication (combining passwords and SMS verification codes) results in high authentication strength, indicating good identity credibility; using only simple password authentication results in low strength and a relatively high risk of identity theft. Device security status focuses on the security status of the device used for access, checking whether the device has effective antivirus software installed, whether there are any unpatched high-risk vulnerabilities, and whether necessary security protection functions are enabled. Good device security status reduces the risk of data leakage due to device intrusion; if the device has many security vulnerabilities, the risk will be significantly increased. Network environment credibility focuses on the network environment in which the access originates, determining whether it is a trusted internal enterprise network, a verified secure office network, or an untrusted network such as public Wi-Fi. The more trustworthy the network environment, the lower the possibility of data hijacking or tampering during transmission. Access time characteristics are based on historical access patterns, considering whether the current access time is within the normal range. For example, business systems typically have high-frequency access during working hours; access during abnormal times, such as late at night, poses a risk.
[0036] The dynamic risk coefficient of the control domain is obtained based on real-time monitoring factors, assessment dimension parameters, and risk weights, specifically including the following steps: The factor deviation value is calculated based on the benchmark values of the real-time monitoring factors and the evaluation dimension parameters; The dynamic risk coefficient of the control domain is obtained by weighting and summing the factor deviation values according to the risk weights.
[0037] First, a baseline value is pre-set for each evaluation dimension parameter, representing the standard value when that dimension is in a safe and normal state. After obtaining the real-time monitoring factors, which are the actual data of each evaluation dimension in the actual access scenario, the real-time monitoring factors are compared with the baseline values of the corresponding evaluation dimension parameters to obtain the factor deviation value. The factor deviation value reflects the degree of deviation between the actual situation and the safety baseline. If the real-time value is better than the baseline value, the deviation value is negative; otherwise, it is positive.
[0038] Because different assessment dimensions have varying importance in the overall risk assessment, a corresponding risk weight is assigned to each dimension. The factor deviation values calculated for each dimension are then weighted and summed according to their risk weights. For example, the factor deviation value for the identity authentication strength dimension is multiplied by its risk weight, the factor deviation value for the device security status dimension is multiplied by its risk weight, and so on, until the weighted results for all dimensions are summed to obtain the dynamic risk coefficient for the control domain. This dynamic risk coefficient comprehensively considers the differences between the actual situation and the security benchmark across multiple dimensions, as well as the risk weights of each dimension, reflecting the risk level of the current data access request within this control domain.
[0039] Through calculation formula The dynamic risk coefficient R is calculated. Assign weights to the evaluation dimension parameters, where i represents the evaluation dimension. in, To monitor factors in real time, This serves as the benchmark value for real-time monitoring factors and evaluation dimension parameters.
[0040] ; Thus, through the calculation formula The calculated dynamic risk coefficient R = 2.3.
[0041] The process of comparing and analyzing dynamic risk coefficients with preset risk thresholds to identify high-risk data access requests includes the following steps: If the dynamic risk coefficient is less than the preset risk threshold, the risk level of the data access request is judged to be normal. If the dynamic risk coefficient is greater than or equal to the preset risk threshold, the risk level of the data access request is judged to be abnormal, and the access request is recorded as a high-risk data access request.
[0042] If the value of the dynamic risk coefficient is less than the preset risk threshold, it indicates that the deviation of the current data access request from the security benchmark is small under the comprehensive evaluation of identity authentication strength, device security status, and network environment credibility. Therefore, the overall risk is within an acceptable range, and the risk level of the data access request is determined to be normal, allowing it to perform data access operations within a reasonable scope of permissions.
[0043] If the dynamic risk coefficient is greater than or equal to the preset risk threshold, it indicates that the deviation from the security baseline in multiple dimensions has exceeded the acceptable security range, posing a high security risk. In this case, the risk level of the data access request is determined to be abnormal, and the request is marked as a high-risk data access request. Stricter security control measures are triggered for high-risk data access requests, such as further identity verification, restricting access permissions, performing data anonymization, or directly denying access, thereby ensuring the security of data access and preventing data leakage security incidents caused by high-risk access.
[0044] Based on the association mapping relationship, the permission transmission path between strategy factors and the corresponding influence weight coefficient of the path are generated, which specifically includes the following steps: Based on the association mapping relationship, the associated factor set of the strategy factors, the permission dependency relationship between the strategy factors, the data interaction frequency and the degree of overlap of the access scope are obtained; Based on the permission dependency relationship, the permission pointing tags of the policy factors and the associated factor set are obtained. All policy factors have permission pointing tags, and the permission transmission path between policy factors is generated based on the permission pointing tags. Set frequency influence weights, and calculate the first transmission coefficient based on the frequency influence weights and data interaction frequency; Set the range influence weight, and calculate the second transmission coefficient based on the range influence weight and the overlap of the access range; Set a first weight coefficient and a second weight coefficient, and obtain the influence weight coefficient corresponding to the permission transmission path based on the weighted sum of the first weight coefficient and the first transmission coefficient, and the second weight coefficient and the second transmission coefficient.
[0045] In the process of constructing and analyzing permission policies for data security access, this application is used to sort out the relationship between policy factors. First, the association factor set of policy factors is mined by the association mapping relationship to clarify the permission dependency relationship between policy factors. At the same time, the data interaction frequency and access scope overlap are statistically analyzed. The data interaction frequency is the frequency of data exchange between policy factors, and the access scope overlap is the overlap ratio of policy factors accessing data resources.
[0046] Based on the permission dependency relationship, the policy factors and associated factor sets are marked with permission pointers. Each policy factor has a corresponding permission pointer marker. Based on these markers, the permission transmission path between policy factors can be identified, and how permissions are transferred between different factors can be clearly presented.
[0047] To quantify the impact of permission transmission, a frequency influence weight is set, and a first transmission coefficient is obtained by combining the data interaction frequency, which reflects the impact of the frequency of data interaction on permission transmission; a range influence weight is set, and a second transmission coefficient is obtained based on the degree of overlap of access ranges, which reflects the effect of the overlap of access ranges on permission transmission.
[0048] A first weighting coefficient and a second weighting coefficient are set. The first weighting coefficient is multiplied by the first transmission coefficient, and the second weighting coefficient is multiplied by the second transmission coefficient to obtain the influence weighting coefficient corresponding to the permission transmission path. The influence weighting coefficient comprehensively considers the impact of data interaction frequency and access scope overlap in permission transmission, and measures the magnitude of the effect of different permission transmission paths on the overall permission policy. It provides key quantitative basis for subsequent dynamic authorization models such as permission decay and determination of restricted permission factors, making permission control more refined and more closely aligned with actual data access scenarios.
[0049] Through the first calculation formula The first conduction coefficient was calculated. ,in, Frequency affects weights, Set to 0.5. For data interaction frequency, This represents the highest interaction frequency in history.
[0050] Through the second calculation formula The second conduction coefficient was calculated. , To influence the weights based on the range, Set to 0.5. For the degree of overlap in the access range.
[0051] ; Thus, through the first calculation formula The first conduction coefficient was calculated. =0.25.
[0052] Thus, through the second calculation formula The second conduction coefficient was calculated. =0.15.
[0053] The dynamic authorization model is used to obtain the associated influence factors of high-risk strategy factors, and the dynamic authorization model is also used to obtain the authority decay coefficient of high-risk strategy factors on associated influence factors. The specific steps include: Obtain the permission pointer markers for high-risk strategy factors, obtain the target transmission path of high-risk strategy factors based on the permission pointer markers, and obtain the corresponding related influencing factors based on the target transmission path; Obtain the permission transmission path between high-risk strategy factors and related influencing factors, and record the influence weight coefficients corresponding to the permission transmission path as the target weight coefficients; The authority decay coefficient is calculated based on the target weight coefficient and the dynamic risk coefficient corresponding to the high-risk strategy factor.
[0054] First, obtain the permission pointers for high-risk strategy factors to guide the identification of the target transmission path of high-risk strategy factors. By following the path, the corresponding related influencing factors can be located, and it can be determined which factors will be affected by the permission transmission of high-risk strategy factors.
[0055] Find the specific permission transmission path between high-risk strategy factors and related influencing factors, and determine the influence weight coefficient corresponding to this path as the target weight coefficient. This coefficient reflects the original degree of influence of this transmission path when the permission is transferred.
[0056] By combining the dynamic risk coefficients corresponding to high-risk strategy factors, a permission decay coefficient is obtained using the target weight coefficient and the dynamic risk coefficient. The permission decay coefficient can accurately measure the degree to which the permission transmission of related influencing factors is weakened due to the risk of the high-risk strategy factor itself. The higher the risk and the larger the target weight coefficient, the larger the permission decay coefficient tends to be. This enables dynamic adjustment of permission transmission in high-risk scenarios, allowing the permissions of related influencing factors to adapt to the current risk level. This ensures that data access permissions can still be accurately controlled under high-risk conditions, avoiding security issues caused by over-authorization.
[0057] The restricted permission factor is obtained by processing the policy factor and the permission propagation path, specifically including the following steps: The comprehensive authority coefficient of the associated influence factor is obtained by multiplying the authority attenuation coefficient with the basic authority coefficient corresponding to the associated influence factor. If the overall permission coefficient is less than the preset permission threshold, the permission status of the associated influence factor is determined to be abnormal, and the associated influence factor is recorded as a restricted permission factor.
[0058] First, obtain the permission decay coefficient, which reflects the degree to which the high-risk strategy factor weakens the permissions of the related influencing factor. Simultaneously, obtain the basic permission coefficient corresponding to the related influencing factor, which represents the normal permission level that the factor should have under no risk influence. Multiply these two coefficients to obtain the comprehensive permission coefficient, which reflects the actual permissions possessed by the related influencing factor under the influence of the high-risk strategy factor.
[0059] The overall permission coefficient is compared with the preset permission threshold. If the overall permission coefficient is less than the preset permission threshold, it indicates that the actual permission of the associated influencing factor has fallen below the normal acceptable permission level due to the influence of the high-risk strategy factor. In this case, the permission status of the associated influencing factor can be judged as abnormal. Associated influencing factors with abnormal permission status are marked as restricted permission factors. Subsequently, corresponding permission restriction measures are implemented for these factors, such as further narrowing their data access scope and reducing access depth. This ensures that data access permissions are always within a safe and controllable range in high-risk scenarios, avoiding data leakage and unauthorized access security issues caused by abnormal permissions.
[0060] Based on the high-risk strategy factor and the restricted access factor, a security assessment coefficient for the data access request is obtained. The corresponding data access control operation is then executed based on this security assessment coefficient, specifically including the following steps: Obtain the first risk percentage corresponding to the high-risk strategy factor in the dynamic authorization model; Obtain the second risk percentage corresponding to the restricted permission factor in the dynamic authorization model; Set risk impact weights and authority impact weights, and obtain the security assessment coefficient based on the weighted sum of the risk impact weights and the proportion of the first risk, and the authority impact weights and the proportion of the second risk. When the security assessment coefficient is less than the preset security threshold, normal access authorization is performed; When the security assessment coefficient is greater than or equal to the preset security threshold, anonymization access or access denial operation will be performed.
[0061] First, key risk indicators are extracted from the dynamic authorization model. The first is the proportion of risk associated with high-risk strategy factors, which reflects the proportion of risk brought by high-risk strategy factors in the overall strategy factors. The second is the proportion of risk associated with restricted authority factors, which reflects the proportion of risk associated with factors with restricted authority in the overall system.
[0062] To reasonably balance the impact of risk and access restrictions on security assessment, risk impact weights and access restriction impact weights are set. The magnitude of these weights is determined based on actual security needs and scenario characteristics; for example, the risk impact weight can be increased in highly sensitive data scenarios. Then, the risk impact weight is multiplied by the first risk percentage, and the access restriction weight is multiplied by the second risk percentage. The sum of these two products yields the security assessment coefficient, which comprehensively considers the impact of risk and access restrictions on data access security.
[0063] The security assessment coefficient is compared with the preset security threshold. If the security assessment coefficient is less than the security threshold, it means that the overall risk of the current access request is within an acceptable range, and normal access authorization is granted, allowing the access subject to obtain data within reasonable permissions. If the security assessment coefficient is greater than or equal to the security threshold, it indicates that the access has a high security risk, and the access operation is directly denied to ensure data security. This approach controls the overall security risk of data access and achieves dynamic and precise access control.
[0064] An electronic device includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement a method for secure data access control.
[0065] like Figure 3 As shown, the electronic device may include a processor 610, a communication interface 620, a memory 630, and a communication bus 640, wherein the processor 610, the communication interface 620, and the memory 630 communicate with each other through the communication bus 640. The processor 610 can call logical instructions in the memory 630 to execute a data security access control method.
[0066] Furthermore, the logical instructions in the aforementioned memory 630 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory, random access memory, magnetic disks, or optical disks.
[0067] On the other hand, the present invention also provides a computer program product, the computer program product including a computer program that can be stored on a non-transitory computer-readable storage medium, and when the computer program is executed by a processor, the computer is able to execute a data security access control method.
[0068] In another aspect, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, is implemented to perform a method for data security access control.
[0069] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.
[0070] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.
[0071] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A method for data security access control, characterized in that, The method includes the following steps: Obtain the data access request from the data access subject, and generate the data access scenario type based on the data access request; Based on the data access scenario type, set the control domain for fine-grained access, the corresponding evaluation dimension parameters for the control domain, and the risk weights corresponding to the evaluation dimension parameters; Real-time monitoring factors for fine-grained access control domains are obtained based on evaluation dimension parameters. Dynamic risk coefficients for control domains are obtained based on real-time monitoring factors, evaluation dimension parameters, and risk weights. High-risk data access requests are obtained by comparing and analyzing the dynamic risk coefficients with preset risk thresholds. Strategy factors are generated based on the identity attributes of the data access subject and the data resource tags; Obtain the association mapping relationship of strategy factors, and generate the permission transmission path between strategy factors and the influence weight coefficient of the path based on the association mapping relationship; Obtain the high-risk policy factor corresponding to the high-risk data access request; process the policy factor and permission propagation path to obtain the restricted permission factor; Based on the high-risk strategy factor and the restricted access factor, a security assessment coefficient for the data access request is obtained, and the corresponding data access control operation is executed based on the security assessment coefficient.
2. The data security access control method according to claim 1, characterized in that, The restricted permission factor is obtained by processing the policy factor and the permission propagation path, specifically including the following steps: A dynamic authorization model is constructed based on policy factors and permission propagation paths; The correlation influence factors of high-risk strategy factors are obtained based on the dynamic authorization model, and the authority decay coefficient of high-risk strategy factors on correlation influence factors is obtained based on the dynamic authorization model. The comprehensive permission coefficient of the related influence factor is obtained based on the permission decay coefficient and the basic permission coefficient corresponding to the related influence factor; the comprehensive permission coefficient is compared and analyzed with the preset permission threshold to obtain the restricted permission factor.
3. The data security access control method according to claim 2, characterized in that, The evaluation dimensions include authentication strength, device security status, network environment credibility, and access time characteristics.
4. The data security access control method according to claim 3, characterized in that, The dynamic risk coefficient of the control domain is obtained based on real-time monitoring factors, assessment dimension parameters, and risk weights, specifically including the following steps: The factor deviation value is calculated based on the benchmark values of the real-time monitoring factors and the evaluation dimension parameters; The dynamic risk coefficient of the control domain is obtained by weighting and summing the factor deviation values according to the risk weights.
5. The data security access control method according to claim 4, characterized in that, The process of comparing and analyzing dynamic risk coefficients with preset risk thresholds to identify high-risk data access requests includes the following steps: If the dynamic risk coefficient is less than the preset risk threshold, the risk level of the data access request is judged to be normal. If the dynamic risk coefficient is greater than or equal to the preset risk threshold, the risk level of the data access request is judged to be abnormal, and the access request is recorded as a high-risk data access request.
6. The data security access control method according to claim 5, characterized in that, Based on the association mapping relationship, the permission transmission path between strategy factors and the corresponding influence weight coefficient of the path are generated, which specifically includes the following steps: Based on the association mapping relationship, the associated factor set of the strategy factors, the permission dependency relationship between the strategy factors, the data interaction frequency and the degree of overlap of the access scope are obtained; Based on the permission dependency relationship, the permission pointing tags of the policy factors and the associated factor set are obtained. All policy factors have permission pointing tags, and the permission transmission path between policy factors is generated based on the permission pointing tags. Set frequency influence weights, and calculate the first transmission coefficient based on the frequency influence weights and data interaction frequency; Set the range influence weight, and calculate the second transmission coefficient based on the range influence weight and the overlap of the access range; Set a first weight coefficient and a second weight coefficient, and obtain the influence weight coefficient corresponding to the permission transmission path based on the weighted sum of the first weight coefficient and the first transmission coefficient, and the second weight coefficient and the second transmission coefficient.
7. A method for data security access control according to claim 6, characterized in that, The dynamic authorization model is used to obtain the associated influence factors of high-risk strategy factors, and the dynamic authorization model is also used to obtain the authority decay coefficient of high-risk strategy factors on associated influence factors. The specific steps include: Obtain the permission pointer markers for high-risk strategy factors, obtain the target transmission path of high-risk strategy factors based on the permission pointer markers, and obtain the corresponding related influencing factors based on the target transmission path; Obtain the permission transmission path between high-risk strategy factors and related influencing factors, and record the influence weight coefficients corresponding to the permission transmission path as the target weight coefficients; The authority decay coefficient is calculated based on the target weight coefficient and the dynamic risk coefficient corresponding to the high-risk strategy factor.
8. A method for data security access control according to claim 7, characterized in that, The restricted permission factor is obtained by processing the policy factor and the permission propagation path, specifically including the following steps: The comprehensive authority coefficient of the associated influence factor is obtained by multiplying the authority attenuation coefficient with the basic authority coefficient corresponding to the associated influence factor. If the overall permission coefficient is less than the preset permission threshold, the permission status of the associated influence factor is determined to be abnormal, and the associated influence factor is recorded as a restricted permission factor.
9. A method for data security access control according to claim 8, characterized in that, Based on the high-risk strategy factor and the restricted access factor, a security assessment coefficient for the data access request is obtained. The corresponding data access control operation is then executed based on this security assessment coefficient, specifically including the following steps: Obtain the first risk percentage corresponding to the high-risk strategy factor in the dynamic authorization model; Obtain the second risk percentage corresponding to the restricted permission factor in the dynamic authorization model; Set risk impact weights and authority impact weights, and obtain the security assessment coefficient based on the weighted sum of the risk impact weights and the proportion of the first risk, and the authority impact weights and the proportion of the second risk. When the security assessment coefficient is less than the preset security threshold, normal access authorization is performed; When the security assessment coefficient is greater than or equal to the preset security threshold, anonymization access or access denial operation will be performed.
10. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements a data security access control method as described in any one of claims 1 to 9.
Citation Information
Patent Citations
Access anomaly analysis method and system based on multi-dimensional features and user behaviors
CN120378207A
Intelligent data management system based on behavior path analysis
CN120524484A