Data access control system in cloud environment
By accurately filtering and classifying data fields in the cloud environment, combined with access behavior monitoring and permission matching, the problem of insufficient user identity differentiation in the traditional cloud environment is solved, and precise control of data access and improved security are achieved.
Patent Information
- Application Number
- CN202511756179.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-27
- Publication Date
- 2026-02-27
AI Technical Summary
Existing technologies struggle to accurately distinguish user identities in traditional cloud environments, leading to unauthorized access and sensitive data leaks. Furthermore, access logs lack in-depth correlation analysis of information such as the source of operations, devices, and login locations, making it impossible to effectively identify potential security threats.
The data filtering module identifies and categorizes sensitive fields, the behavior tagging module monitors access behavior, and the permission review module matches user roles and security levels to ensure accurate access permission settings, including field content filtering, categorization, encryption, behavior monitoring, and permission control.
It improves the accuracy and security of data access, ensures compliance and information protection, and effectively prevents unauthorized access and leakage of sensitive data.
Smart Images

Figure CN121580419A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of smart campus construction, and in particular to a data access control system in a cloud environment. BACKGROUND
[0002] The technical field of smart campus construction covers many core matters such as campus basic information collection, identity verification, data hierarchical storage, data cross-terminal transmission, sensitive information protection, access permission configuration, log recording and auditing, etc. The overall technical field constitutes a collaborative architecture of multi-terminal access system, data management system, user identity system and security protection system. Each system constitutes a unified management environment through network access end, data exchange end and permission execution end.
[0003] Among them, the data access control system in the special cloud environment refers to the data management method of deploying access judgment rules in the cloud and performing permission verification when the terminal initiates a data request. The traditional data access control system in the cloud environment sets permission limits for user access behavior and data access range, usually performs identity verification based on account password comparison, lists accessible data items and prohibited access data items by generating a permission table, performs matching judgment on request path, request resource identifier and request timestamp when receiving an access request, and performs decryption process on sensitive data blocks through encryption key, and generates access logs by recording access behavior with fixed rules.
[0004] The prior art has deficiencies in identity verification and access control. The traditional scheme relies on account password and permission table for identity verification and access judgment, and cannot make fine processing for complex access scenarios. For example, for the case of multiple users sharing data, the traditional scheme cannot distinguish the user identity in detail, resulting in unauthorized access or sensitive data leakage. At the same time, the existing access log lacks in-depth correlation analysis of information such as operation source, device and login location, and cannot effectively identify potential security threats, which increases the risk of data leakage and permission management errors. SUMMARY
[0005] The purpose of the present application is to solve the shortcomings in the prior art and to provide a data access control system in a cloud environment.
[0006] In order to achieve the above purpose, the present application adopts the following technical scheme: a data access control system in a cloud environment, the system comprising:
[0007] A data filtering module acquires student data platform case record fields, distinguishes field names and information column attributes, checks whether the field content contains names, scores, and examination stem text content, reads field source identifiers and table positions, finds privacy identifier text and transmits it to the data processing area, and outputs a case registration field list.
[0008] The protection classification module extracts field classification tags based on the field names and their paths in the case registration field list, browses whether the field content is related to personnel or student status descriptions, finds field processing requirements and fills in the processing tab, and outputs a detailed list of encrypted field handling.
[0009] The behavior marking module calls the field content in the field encryption processing details, extracts all access behavior information associated with the field, lists the account, device and registration location description of the operation source, observes whether there are any differences between the above content and the title and information in the identity usage file, passes the differences to the access status page, and outputs the access abnormal behavior marking table.
[0010] The permission review module calls the access entries in the access abnormal behavior flag table, extracts the role name and user category description of the accesser, browses the connection content of user tags and data descriptive words, checks whether there is any inconsistency between the data and the permission scope, and after processing, it transfers to the permission operation page and outputs the permission conflict registration form.
[0011] The access confirmation module extracts the processing status and user identity information of the fields based on the access records in the permission conflict registration table, checks the compatibility between the security level description of the access field and the tag range of the user's usage category, completes the permission coverage check between the access description and the user status, and outputs the access control configuration table.
[0012] As a further embodiment of the present invention, the data filtering module includes field content, field naming, information bar attributes, name, score, exam question stem, field source, table location, privacy identifier, and case registration field list; the protection classification module includes field name, source path, data classification, personnel or student status description, field processing method, information processing tab, and field encryption handling details; the behavior marking module includes field content, access records, account name, device used, login location, identity profile, and access abnormal behavior marking table; the permission review module includes access entries, accessor role, user type, relationship between tags and data description, data classification table, and permission conflict registration table; the access confirmation module includes access records, field processing text, initiator role, field security level, tag range, and access control configuration table.
[0013] As a further aspect of the present invention, the data filtering module includes:
[0014] The field recognition submodule retrieves the field content from the case record table, detects the correspondence between field names and information column attributes, checks whether the fields contain keywords such as name, score, and exam question stem, determines the field classification based on field naming and content type, and obtains the field classification results.
[0015] The privacy label detection submodule analyzes the content of each field based on the field classification results, finds fields that contain privacy information, identifies fields involving privacy content, labels them, and outputs the privacy label fields.
[0016] The data transmission submodule, based on the privacy identifier field, transmits fields containing privacy information to the data processing area, verifies the source and location of the fields, and generates a list of case registration fields.
[0017] As a further aspect of the present invention, the protection classification module includes:
[0018] The field classification submodule obtains the field names and source paths from the case registration field list, extracts the classification information attached to the fields, browses the field content and detects whether it involves personnel or student status descriptions, determines the classification based on the field content, and obtains the field classification result.
[0019] The privacy judgment submodule checks whether any fields contain personnel or student status privacy information based on the field classification results, analyzes the field processing methods, determines the field processing steps according to the privacy category, and outputs the privacy processing method.
[0020] The information filling submodule, based on the privacy processing method, fills in the field processing method on the information processing tab to ensure that all privacy-related fields have been set with the correct processing method, and obtains the field encryption processing details.
[0021] As a further aspect of the present invention, the behavior tagging module includes:
[0022] The access record extraction submodule obtains the field content from the field encryption processing details, all access operation records associated with the fields, and lists the account name, device used, and login location description of the operation source to obtain the access operation record.
[0023] The identity comparison submodule extracts account name, device, and login location information based on the access operation record, and compares them with the titles and information in the identity usage profile to analyze the differences in usage before and after and obtain the differences in identity information.
[0024] The abnormal behavior marking submodule, based on the differences in the identity information, brings the data with differences into the access status registration area to complete the marking of abnormal behavior and obtain the access abnormal behavior marking table.
[0025] As a further aspect of the present invention, the permission review module includes:
[0026] The access entry extraction submodule obtains the access entries from the access abnormal behavior marker table, extracts the accesser role text and user type description corresponding to each access operation, and obtains the access entry content.
[0027] A user tag analysis submodule browses the connection content between the user tag and the data description word based on the access entry content, finds the association relationship entry in the data use classification table, and obtains a user tag analysis result;
[0028] A permission conflict identification submodule identifies the part inconsistent with the association relationship entry in the data use classification table according to the user tag analysis result, and transmits the part to an access permission processing page to obtain a permission conflict registration table.
[0029] As a further scheme of the application, the access confirmation module comprises:
[0030] An access record extraction submodule obtains the access record entry in the permission conflict registration table, extracts the processing text associated with the field and the role information of the access initiator, and obtains access record content;
[0031] A role and secret level comparison submodule finds the adaptation description between the secret level description of the access field and the label range of the current use category of the user based on the access record content, compares the role and secret level adaptation, and obtains a role and secret level adaptation result;
[0032] A permission coverage checking submodule completes the permission coverage check between the access description and the user state according to the role and secret level adaptation result, and outputs an access control configuration table.
[0033] Compared with the prior art, the application has the advantages and positive effects that:
[0034] In the application, the data field content is accurately screened and classified. During field content screening, the fields containing sensitive information are identified and classified according to the field naming and information column attributes. Through detailed data classification, especially the distinction of personnel and school record information, the sensitive data is properly protected. In access behavior monitoring, the abnormal behavior is identified by combining the analysis of account, device and login location, and the access management and security review is strengthened. In the aspect of permission control, the access permission of different identity users is accurately set through the matching of secret level description and user label range, and the unauthorized access is effectively avoided. This series of technical means improves the accuracy and security of data processing, and ensures the compliance and information protection of data access. BRIEF DESCRIPTION OF DRAWINGS
[0035] Figure 1 The method flowchart of the application;
[0036] Figure 2 The acquisition flowchart of the data screening module of the application;
[0037] Figure 3Acquisition flowchart of the protection classification module of the present application;
[0038] Figure 4 Acquisition flowchart of the behavior marking module of the present application;
[0039] Figure 5 Acquisition flowchart of the authority review module of the present application;
[0040] Figure 6 Acquisition flowchart of the access confirmation module of the present application. DETAILED DESCRIPTION
[0041] The technical solutions in the present application will be described below in conjunction with the accompanying drawings.
[0042] In the embodiments of the present application, sometimes the subscript such as W1 is written in the form of non-subscript such as W1, and the meanings expressed thereby are consistent when no emphasis is placed on the difference.
[0043] To make the technical problems, technical solutions and advantages of the present application clearer, the following will be described in detail in conjunction with the accompanying drawings and specific embodiments.
[0044] Please refer to Figure 1 The present application provides a technical solution: a data access control system in a cloud environment, which comprises:
[0045] The data screening module acquires the field content of the case record table in the student data platform, distinguishes the naming and information column attributes of the fields, browses whether the fields contain text content such as names, scores and test stems, reads the field source identification and table position, finds the attached private identification text therein, transmits the involved content to the data processing area, and outputs the case registration field list.
[0046] The protection classification module uses the field name and source path in the case registration field list, extracts the data classification name attached to the field, browses whether the field content has personnel or school record description text, finds the field processing method indicated thereby, fills the text processing method into the information processing tab, and outputs the field encryption disposal details.
[0047] The behavior marking module calls the field content in the field encryption disposal details, extracts all access operation records in the case, lists the account name of the operation source, the used device, and the login location description, compares the above items with the name and information listed in the identity use archive, distinguishes the difference in usage before and after, brings the data with the difference into the access situation registration area, and outputs the access abnormal behavior marking table.
[0048] The permission review module calls the access entry in the access exception behavior marking table, extracts the corresponding access person role text and user type description, browses the connection content between the user label and the data description word involved, finds the associated relationship entry in the data use classification table, transmits the inconsistent part to the access permission processing page, and outputs the permission conflict registration table;
[0049] The access confirmation module extracts the processing text associated with the field and the role information of the access initiator by means of the access record entry in the permission conflict registration table, finds the adaptation description between the secret level description of the access field and the label range of the current use category of the user, completes the permission coverage check between the access description and the user state, and outputs the access control configuration table.
[0050] The data screening module includes field content, field naming, information column attribute, name, score, test stem, field source, table position, privacy identification, and case registration field list; the protection classification module includes field name, source path, data classification, personnel or academic record description, field processing method, information processing tab, and field encryption disposal details; the behavior marking module includes field content, access record, account name, use equipment, login location, identity file, and access exception behavior marking table; the permission review module includes access entry, access person role, user type, label and data description relationship, data classification table, and permission conflict registration table; the access confirmation module includes access record, field processing text, initiator role, field secret level, label range, and access control configuration table.
[0051] Please refer to Figure 2 , the data screening module includes:
[0052] The field recognition submodule obtains the field content in the case record table, detects the corresponding relationship between the field name and the information column attribute, checks whether the field contains keywords such as name, score, and test stem, determines the field classification according to the field naming and content type, and obtains the field classification result;
[0053] In the process of obtaining the field content in the case record table, all field information needs to be extracted from the case record table, and detailed checks are conducted for each field name to ensure that the content represented by the field can be clearly understood. For example, the system scans the name of each field and compares the content contained in the field one by one. For example, the field "name" represents the name information of an individual, the field "score" represents the test score, and the field "test stem" represents the specific content of the test question. According to the name and content type of the field, the specific classification of the field is determined. For example, if a field is named "name", the system will judge that the field content contains personal name information and classify it as a "personal information" field. If the field is "score", it will be judged that the field stores the test score of an individual and classified as a "test information" field. In addition, for cases where the field name has multiple meanings, such as "score and test stem", the system will further analyze the field content. If the field content contains a specific description of the test question, the field will be automatically classified as a "test content" category. The core of this process is that the system automatically analyzes the relationship between the field name and the content to ensure that each field is correctly classified, thereby providing clear and accurate field information for subsequent data processing and privacy analysis, and obtaining the field classification result.
[0054] The privacy identification detection submodule analyzes the content of each field according to the field classification result, finds the field containing privacy information, determines the field involving privacy content, and marks it, and outputs the privacy identification field;
[0055] According to the aforementioned field classification result, the specific content of each field is analyzed in depth to check whether it contains privacy information. According to the field classification result, it is identified which fields involve privacy information, such as "name", "ID number", "phone number" and other common privacy information fields. The content of these fields will be analyzed in depth, and the actual data in the field will be detected through rule matching or text analysis technology. For example, if the content of a field is "Zhang San", the system will determine whether the field is an individual's name through keyword matching, and mark it as a privacy information field. For the "score" field, the system will further analyze the score data in the field to determine whether it can be associated with a specific individual or identity. If the field contains the test score of a student, the field will also be determined as a privacy information field, especially when the score can be directly associated with an individual's identity. Through this process, the system can effectively identify which fields contain privacy information and mark them, ensuring that it can accurately distinguish which data needs special protection and output the privacy identification field.
[0056] The data transmission submodule transmits the field containing privacy information to the data processing area according to the privacy identification field, verifies the source and location of the field, and obtains the case registration field list.
[0057] According to the detection result of the privacy identification field, it is decided how to handle the field containing privacy information. The system will confirm the specific location and source of the identified privacy field in the case record table. Further verification is carried out on these fields to ensure that they come from the correct table or data source and the location meets the standards of privacy data transmission and protection. For example, the privacy information of a certain field comes from the "name" field in the case record table. The system will verify the source of the field and ensure the legality of the field location. The system will appropriately encrypt or desensitize the fields containing privacy information to ensure that these sensitive information will not be leaked during data transmission. Each step of the data transmission process is strictly checked and processed to ensure the safe transmission of privacy information and avoid unauthorized access. The fields marked as privacy information are transmitted to the data processing area, and a case registration field list is generated, which lists each field and its privacy label to ensure that the entire data transmission process meets the requirements of privacy protection, and the case registration field list is obtained.
[0058] Please refer to Figure 3 , the protection classification module includes:
[0059] The field classification submodule obtains the field name and source path in the case registration field list, extracts the classification information attached to the field, browses the field content and detects whether it involves personnel or academic description, determines the classification according to the field content, and obtains the field classification result;
[0060] After obtaining the field name and source path in the case registration field list, the classification information associated with each field is extracted. This process starts with reading the case registration field list, and the system will analyze the field name and source path one by one to determine the type and classification of the field. For example, when the system identifies a field name as "Name" and the field is from the "Personal Information" data source, it will be classified as the "Personal Information" category; if the field name is "Grade" and the field is from the "Test Record" table, the field will be classified as the "Test Information" category. The content of the field will be browsed and further analyzed to check if the field content involves "personnel" or "student status" description. This means that the system will analyze the text information of the field content to find keywords such as "position", "enrollment time", "student ID", etc. If the field contains these keywords or similar information, such as the content of the "student ID" field being a specific student ID or enrollment date, the system will determine that the field is a "student status" field; if the "position" field contains a description of a certain employee's position, it will be determined as a "personnel" field. Based on the field name and content, combined with the text analysis results, the fields are correctly classified into "personnel", "student status" or other categories, and the field classification results are obtained.
[0061] The privacy judgment submodule checks whether there are fields containing personnel or student status privacy information based on the field classification results, analyzes the processing method of the field, determines the processing steps of the field according to the privacy category, and outputs the privacy processing method.
[0062] Based on the field classification results, it is checked whether there are fields involving personnel or student status privacy information. According to the field classification results, all fields containing privacy information are filtered out, which usually involves personal identity, student record or personnel data. For example, the system will first focus on the "name", "student ID", "ID number" and other fields. Then, the system checks the specific content of these fields to determine whether they contain sensitive privacy information. The system will determine whether the field can be directly associated with the identity information of a person according to the actual content of the field. For example, if the "name" field contains a specific personal name, the system determines that the field involves privacy information. Similarly, if the "student ID" or "grade" field can be associated with the information of a specific student, the system will determine that the field involves privacy. According to the category of privacy information, the corresponding processing steps are determined. For example, for the "name" field containing personal identity information, encryption storage is selected; while for the "grade" field, desensitization processing is selected to ensure that the grade data is not directly exposed. The system will also select different protection strategies according to the different privacy categories, for example, for "student status" information, more stringent privacy protection measures will be taken, and the privacy processing method of each field is output.
[0063] The information filling sub-module fills in the processing method of each field according to the privacy processing mode, and ensures that all fields related to privacy have been set with correct processing methods, and obtains a field encryption treatment detail.
[0064] The information filling sub-module fills in the processing method of each field according to the privacy processing mode. The system will arrange the processing scheme of each field according to the output of the privacy judgment module, and ensure that all fields related to privacy have been set with correct processing methods. At the beginning of this process, the system will check the privacy processing mode of each field one by one, and confirm the specific operation required. For example, for the "name" field marked as involving personal identity information, the system will fill in the "encryption" processing method; for the "student number" field related to student information, the system will fill in the "desensitization" processing method. The system will also select appropriate processing methods according to the type and privacy level of the field, for example, for the more sensitive "ID number" field, a more rigorous encryption processing is selected. Fill in the processing method of all privacy fields into the information processing tab, ensure that each field has clear processing steps, and avoid any leakage of privacy information. A field encryption treatment detail is generated.
[0065] Please refer to Figure 4 , the behavior marking module includes:
[0066] The access record extraction sub-module obtains the field content in the field encryption treatment detail, extracts all access operation records associated with the field, lists the account name of the operation source, the device used, the login location description, and obtains the access operation record.
[0067] After obtaining the field content in the field encryption handling details, the system further extracts all access operation records related to each field. These access records include several key data: the account of the operation source, the device used, and the login location description. According to the field identification in the field encryption handling details, the access operation records related to the field are retrieved one by one. For example, assuming that a field "Name" is accessed, the system records the account names that access this field, such as "Account A" or "Account B", which correspond to different users. The device information used in the operation is extracted, such as "Device 1: Windows PC", "Device 2: MacBook Pro", "Device 3: iPhone", etc., indicating different access behaviors. In addition, the system also records the login location information, such as "IP address: 192.168.1.1, location: Beijing" or "IP address: 10.0.0.2, location: Shanghai", which provides geographical and device background data for subsequent analysis. Throughout the process, the system ensures that all access records of the fields are captured and listed, helping to conduct subsequent behavior analysis and audit. By extracting and listing these information, complete access operation records are generated.
[0068] The identity comparison sub-module extracts account names, devices, and login location information based on access operation records, and compares them with the titles and information in the identity usage archives, analyzes the differences in usage before and after, and obtains the differences in identity information;
[0069] The account names, devices, and login location information extracted based on access operation records are compared with the titles and information in the identity usage archives. The specific information in each access record is extracted, including account names, devices, and login locations. Taking a user "Zhang San" as an example, assuming that the system records that the user "Zhang San" used a "Windows PC" device in a certain access, and the login location was "Shanghai". At this time, the system compares these information with the identity archives of "Zhang San", and checks whether there is matching device information and historical login location in the archives. If the historical archives show that "Zhang San" usually logs in through "MacBook" device in "Beijing", then it will be found that there is an inconsistency between the device type and the login location. The specific comparison process includes: the system checks whether the device is consistent, if the device in the access record does not match the device in the archives, the system will mark it as a difference; secondly, the system compares the login location, if the actual login location does not match the historical login location in the archives, the system will mark it as a difference. Through this process, the system can accurately identify the abnormal access behavior of the user, such as using an unusual device or logging in at an unusual location. Through these comparisons, the differences in identity information are obtained.
[0070] Anomaly behavior marking submodule, according to the identity information difference, brings the data with the difference into the access situation registration area, completes the marking of the abnormal behavior, and obtains an access anomaly behavior marking table.
[0071] According to the aforementioned identity information difference, the differences are brought into the access situation registration area, and the abnormal behavior is marked. All access records marked as abnormal are screened out, and these records usually show that there are differences in aspects such as account, device or login location. For example, if the system finds that an account is switched between two geographic locations within a short period of time, or an access is made using a device that is not in the user's commonly used device list, the system will mark the record as abnormal behavior. These abnormal access records are imported into the access situation registration area, and each record is specifically marked, and the marking items include “device inconsistency”, “location anomaly”, “frequent account switching” and the like. These marks can help the security team quickly locate potential security risks or abnormal access behaviors. The system marks each abnormal behavior in detail to ensure that the abnormal behavior is effectively tracked and identified. An access anomaly behavior marking table is generated.
[0072] Please refer to Figure 5 , the permission review module includes:
[0073] An access entry extraction submodule obtains access entries in the access anomaly behavior marking table, extracts access person role text and user type description corresponding to each access operation, and obtains access entry content.
[0074] All access entries in the access anomaly behavior marking table are obtained, and access person role text and user type description corresponding to each access operation are extracted. Each access record in the access anomaly behavior marking table is scanned, and the operation role of each access operation and the user type corresponding thereto are identified. For example, assuming that a record shows that “user A” accesses a field “name”, the role of the user is “administrator”, and the type description of the user is “company management personnel”, the system will mark the access person role of this record as “administrator”, and the user type description as “company management personnel”. In the extraction process, the system will not only capture the user role and type information, but also pay attention to the access record of the related field, for example, the access of the “position” field will be associated with the user role of the “personnel” category, and the “score” field will be associated with the user type of the “student” category. The system will extract the role and user type in all access records one by one, and compare them with the actual access data, to ensure that each access entry is clearly associated with the operation role and user type. Access entry content is generated.
[0075] A user label analysis submodule, based on the access entry content, browses the connection content between the user label and the data description word involved, finds the association relationship item in the data use classification table, and obtains a user label analysis result.
[0076] Based on the content of access entries, the system browses the connections between user tags and related data descriptors, searching for related entries in the data usage category table. It extracts user-related tag information from the access entries, such as user type and role, and obtains descriptors related to the accessed fields, such as "personal information" and "exam scores." The system analyzes the relationships between these tags and descriptors one by one to determine if the user tags match the data descriptors. For example, if the user tag is "administrator" and the accessed field is "scores," the system will search the data usage category table for a relationship between "administrator" and the "scores" field. The system will further compare entries in the data usage category table to find all tag-descriptor associations that meet this condition. For instance, if the data usage category table explicitly states that "administrators" can only access "company data" and not the "student scores" field, the system will mark this access record as potentially non-compliant. Through this process, the system can analyze the accurate connections between user tags and data descriptors and identify potential permission issues. The system then generates user tag analysis results.
[0077] The permission conflict identification submodule identifies, based on the user tag analysis results, parts that are inconsistent with the related entries in the data usage classification table, and transmits them to the access permission processing page to obtain the permission conflict registration form.
[0078] Based on the user tag analysis results, inconsistencies with the related entries in the data usage classification table are identified and sent to the access permission processing page. By comparing the user tag analysis results with the related entries in the data usage classification table, access records with permission conflicts are identified. For example, suppose the system identifies that an "administrator" role has accessed the "student grades" field, but according to the data usage classification table, the "administrator" does not have permission to access this data; the system then marks this as a permission conflict. These access records with permission conflicts are sent to the access permission processing page for further processing. During processing, the system adjusts user access permissions according to predefined permission policies, such as restricting access permissions for certain roles or conducting temporary authorization reviews. The system generates a permission conflict registration table, which details all access records with permission conflicts, including the conflicting user role, the accessed field, and the type of conflict, ensuring that all permission issues are reviewed and processed promptly. A complete permission conflict registration table is output.
[0079] Please see Figure 6 The access confirmation module includes:
[0080] The access record extraction submodule retrieves access record entries from the permission conflict registration table, extracts the processing text associated with the fields and the role information of the access initiator, and obtains the access record content.
[0081] The access record entries in the permission conflict registration table are obtained, and the processing text associated with each access operation and the role information of the access initiator are extracted. The system extracts the processing text associated with each field and the user role performing the access operation by scanning each record in the permission conflict registration table. For example, assume that the processing text associated with a field "exam score" is "encryption processing", and the role initiating the access operation is "teacher". The system marks the field processing text of this record as "encryption processing" and the role information as "teacher". Each record in this process is compared and the processing text and role information of the field are extracted to ensure that each access record clearly associates the role and the corresponding processing method of the field. All extracted access records are listed one by one, and it is ensured that the field processing text matches the role of the access initiator. For example, if the role is "administrator" and the field involves personal sensitive data, the processing text is "encryption" or "desensitization", and based on this information the system generates complete access record content.
[0082] The role and classification comparison submodule compares the role and classification adaptation based on the access record content, finds the adaptation description between the classification description of the access field and the label range of the user's current use category, and obtains the role and classification adaptation result.
[0083] Based on the access record content, the adaptation description between the classification description of the access field and the label range of the user's current use category is found, and the role and classification adaptation comparison is performed. According to the field description in the access record, the classification information of the field is judged, such as "confidential", "public" or "restricted access", and then according to the role of the user and the label range, the adaptation description of the field classification is found. For example, if a field "personal identity information" is marked as "confidential", and the user role is "external auditor", the system will check whether the user role has the right to access "confidential" level data. Specifically, the system will compare the classification description of the access field and the label range of the user's current role to determine whether the role has the right to access the field. For example, if the role "external auditor" is limited to "public" level information, and the accessed field is "confidential" level content, the system will mark it as role and classification mismatch. This process is achieved by comparing the intersection of field classification and role access permission to ensure that the user can only access data within the scope of his / her permission. According to these comparisons, the role and classification adaptation result is obtained.
[0084] The permission override checking submodule completes the permission override check between the access description and the user state according to the role and classification adaptation result, and outputs the access control configuration table.
[0085] According to the role secret level adaptation result, the permission coverage check between the access description and the user state is completed. According to the comparison result of the role secret level adaptation, it is checked whether the user has sufficient permission to access a certain field. The system compares the access records one by one to ensure that the secret level permission of the user role covers the requirements of the field. For example, if a certain field "employee salary" is marked as "secret" level, and the user role is "human resources manager", and the label range of the role includes "secret" level data access permission, the permission of the user is considered to be covered, and the system will consider the access record as legal. Permission coverage check will be performed on all access records to check whether the user role and the secret level of each record match. If there is a mismatch, the system will be marked as "insufficient permission". For example, if a user role is "visitor", but the user tries to access a "secret" level field, the system will judge that the access request is not in compliance, and record it as a permission conflict. The entire permission check process will be completed, and an access control configuration table will be generated.
[0086] The above is only a specific embodiment of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical scope disclosed by the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A data access control system in a cloud environment, characterized in that, The system includes: The data filtering module retrieves case record fields from the student data platform, distinguishes field names and information column attributes, checks whether the field content contains names, grades, and exam question text, reads field source identifiers and table positions, finds privacy-identifying text and sends it to the data processing area, and outputs a list of case registration fields. The protection classification module extracts field classification tags based on the field names and their paths in the case registration field list, browses whether the field content is related to personnel or student status descriptions, finds field processing requirements and fills in the processing tab, and outputs a detailed list of encrypted field handling. The behavior marking module calls the field content in the field encryption processing details, extracts all access behavior information associated with the field, lists the account, device and registration location description of the operation source, observes whether there are any differences between the above content and the title and information in the identity usage file, passes the differences to the access status page, and outputs the access abnormal behavior marking table. The permission review module calls the access entries in the access abnormal behavior flag table, extracts the accessor's role name and user category description, browses the connection content of user tags and data descriptive words, checks whether there are inconsistencies between the data and the permission scope, and after processing, redirects to the permission operation page and outputs the permission conflict registration form.
2. The data access control system in a cloud environment according to claim 1, characterized in that: The data filtering module includes field content, field naming, information column attributes, name, score, exam question stem, field source, table location, privacy identifier, and case registration field list; the protection classification module includes field name, source path, data classification, personnel or student status description, field processing method, information processing tab, and field encryption handling details; the behavior marking module includes field content, access records, account name, device used, login location, identity profile, and access abnormal behavior marking table; the permission review module includes access entries, accesser role, user type, relationship between tags and data description, data classification table, and permission conflict registration table.
3. The data access control system in a cloud environment according to claim 1, characterized in that, The data filtering module includes: The field recognition submodule retrieves the field content from the case record table, detects the correspondence between field names and information column attributes, checks whether the fields contain keywords such as name, score, and exam question stem, determines the field classification based on field naming and content type, and obtains the field classification results. The privacy label detection submodule analyzes the content of each field based on the field classification results, finds fields that contain privacy information, identifies fields involving privacy content, labels them, and outputs the privacy label fields. The data transmission submodule, based on the privacy identifier field, transmits fields containing privacy information to the data processing area, verifies the source and location of the fields, and generates a list of case registration fields.
4. The data access control system in a cloud environment according to claim 1, characterized in that, The protection classification module includes: The field classification submodule obtains the field names and source paths from the case registration field list, extracts the classification information attached to the fields, browses the field content and detects whether it involves personnel or student status descriptions, determines the classification based on the field content, and obtains the field classification result. The privacy judgment submodule checks whether any fields contain personnel or student status privacy information based on the field classification results, analyzes the field processing methods, determines the field processing steps according to the privacy category, and outputs the privacy processing method. The information filling submodule, based on the privacy processing method, fills in the field processing method on the information processing tab to ensure that all privacy-related fields have been set with the correct processing method, and obtains the field encryption processing details.
5. The data access control system in a cloud environment according to claim 1, characterized in that, The behavior tagging module includes: The access record extraction submodule obtains the field content from the field encryption processing details, extracts all access operation records associated with the fields, and lists the account name, device used, and login location description of the operation source to obtain the access operation records. The identity comparison submodule extracts account name, device, and login location information based on the access operation record, and compares them with the titles and information in the identity usage profile to analyze the differences in usage before and after and obtain the differences in identity information. The abnormal behavior marking submodule, based on the differences in the identity information, brings the data with differences into the access status registration area to complete the marking of abnormal behavior and obtain the access abnormal behavior marking table.
6. The data access control system in a cloud environment according to claim 1, characterized in that, The permission review module includes: The access entry extraction submodule obtains the access entries from the access abnormal behavior marker table, extracts the accesser role text and user type description corresponding to each access operation, and obtains the access entry content. The user tag analysis submodule, based on the access entry content, browses the connection content between user tags and the relevant data descriptive words, searches for the association entries in the data usage classification table, and obtains the user tag analysis results. The permission conflict identification submodule identifies, based on the user tag analysis results, parts that are inconsistent with the related entries in the data usage classification table, and transmits them to the access permission processing page to obtain the permission conflict registration table.
7. The data access control system in a cloud environment according to claim 1, characterized in that, Also includes: The access confirmation module extracts the processing status and user identity information of the fields based on the access records in the permission conflict registration table, checks the adaptation between the security level description of the access field and the tag range of the user's usage category, completes the permission coverage check between the access description and the user status, and outputs the access control configuration table. The access confirmation module includes access records, field processing text, initiator role, field security level, tag range, and access control configuration table.
8. The data access control system in a cloud environment according to claim 7, characterized in that, The access confirmation module includes: The access record extraction submodule retrieves access record entries from the permission conflict registration table, extracts the processing text associated with the fields and the role information of the access initiator, and obtains the access record content. The role and security level comparison submodule, based on the access record content, searches for the compatibility description between the security level description of the access field and the tag range of the user's current usage category, performs a comparison of role and security level compatibility, and obtains the role and security level compatibility result. The permission overlay check submodule performs a permission overlay check between the access description and the user status based on the role security level adaptation result, and outputs an access control configuration table.