A software access control method and device based on data security and a medium
Patent Information
- Application Number
- CN202511994398.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-26
- Publication Date
- 2026-09-15
- Estimated Expiration
- 2045-12-26
AI Technical Summary
[0005]因此,本发明提供了一种基于数据安全的软件访问控制方法无法实时响应环境变化和异常行为、且缺乏根据会话行为动态调整保护强度的问题
[0016]The beneficial effects of this invention are as follows: By recording user historical behavior logs in real time within a session and enhancing the initial risk profile to form the final risk decision, the process achieves continuous perception and response to dynamic access context and abnormal behavior. This compensates for the shortcomings of traditional role-based access control and attribute-based access control, which rely solely on initial authentication, effectively improving the defense capability against internal threats. Simultaneously, by adaptively selecting the perturbation strength in the final risk decision to perform masking, encryption, or pseudo-data replacement processing to generate a secure data copy, the session-level dynamic adjustment of data protection strength is achieved. This maintains high data availability in low-risk scenarios and provides strict protection in high-risk scenarios, avoiding the problems of over-masking or insufficient protection caused by the fixed-strength processing of existing query proxies and de-identification mechanisms, thus balancing business value and leakage risk.
Smart Images

Figure CN121786803B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of secure access technology, and in particular to a software access control method, device and medium based on data security. Background Technology
[0002] With the deepening of digital transformation and the widespread adoption of big data applications, data access control technology has become a core research direction in the field of information security. Early access control primarily relied on discretionary and mandatory access control. Subsequently, role-based access control (RBAC) developed, achieving relatively efficient permission management by binding permissions to roles, and has been widely applied in enterprises. Entering the cloud era and the zero-trust architecture stage, attribute-based access control has gradually emerged, dynamically deciding permissions based on multi-dimensional attributes such as subject, object, and environment, significantly improving the granularity and flexibility of control. Simultaneously, database proxies, query rewriting, and data masking technologies have been introduced to achieve row-level / column-level permission filtering and sensitive data protection. Furthermore, containerized isolation technology and session-level temporary execution environments are also being applied in the field of security sandboxes, aiming to limit the spread of malicious behavior.
[0003] However, existing data access control technologies still have some shortcomings. First, while traditional role-based access control and attribute-based access control can achieve static or attribute-based authorization, they lack awareness of dynamic context risks during access. They usually rely only on initial authentication and cannot respond to environmental changes and abnormal behavior in real time, resulting in limited defense capabilities against internal threats or abnormal behavior. Second, existing query proxies and data masking mechanisms mostly perform fixed-strength processing before data is returned to the client, lacking the ability to dynamically adjust the protection strength based on session behavior. This makes it difficult to balance data availability in low-risk scenarios with strict protection in high-risk scenarios, which can easily lead to excessive data masking that reduces business value or insufficient protection that leads to leakage risks. Summary of the Invention
[0004] In view of the aforementioned existing problems, the present invention is proposed.
[0005] Therefore, the present invention provides a software access control method based on data security that cannot respond to environmental changes and abnormal behavior in real time, and lacks the ability to dynamically adjust the protection strength according to session behavior.
[0006] To solve the above-mentioned technical problems, the present invention provides the following technical solution: In a first aspect, the present invention provides a software access control method based on data security, comprising, After a user initiates a data access request, their identity is verified. Once verified, a static business security tag is extracted from the unified identity management center. At the same time, real-time context signals are collected and used together with the static business security tag for judgment. After judgment, an initial risk profile is generated, and the user's identity, static business security tag, and initial risk profile are encapsulated into a dynamic access token. Receive dynamic access tokens, create independent temporary dynamic security containers based on the initial risk profile, parse query semantics based on data access requests, submit the query semantics and static business security tags to the production database for querying, inject the raw result dataset returned from the production database into the independent temporary dynamic security containers, and form the final risk decision after enhancing the initial risk profile. The independent temporary dynamic security container performs a forced comparison between the metadata tags in the original result dataset and the static business security tags to identify the user's static permission scope, and performs perturbation security processing to generate a secure data copy based on the final risk decision; A secure copy of the data is passed back to the client for display and high-risk operations are restricted. The independent, temporary, dynamic security container is destroyed after the session ends.
[0007] As a preferred embodiment of the data security-based software access control method of the present invention, the user initiates a data access request and undergoes identity verification. Upon successful verification, a static business security marker is extracted from the unified identity management center. Simultaneously, real-time context signals are collected and used in conjunction with the static business security marker to generate an initial risk profile. Specifically: Users initiate data access requests through client applications. The user's identity is confirmed through strong identity authentication. After successful authentication, the user's preset static business security tags are extracted from the unified identity management function. Collect geographic location, device health status, and access time period as real-time context signals; The extracted static business security markers and real-time context signals are analyzed using predefined logical rules to generate an initial risk profile.
[0008] As a preferred embodiment of the data security-based software access control method of the present invention, the steps of receiving a dynamic access token, creating an independent temporary dynamic security container based on an initial risk profile, parsing the query semantics according to the data access request, submitting the query semantics and static business security tags to the production database for querying, injecting the original result dataset returned from the production database into the independent temporary dynamic security container, and forming a final risk decision after enhancing the initial risk profile, are as follows: Upon receiving a dynamic access token, the initial risk profile is immediately parsed, and the container isolation level is determined based on the parsed initial risk profile, and an independent temporary dynamic security container is created. Perform SQL parsing on the original query statement in the data access request, extract table names, field names and query conditions, and generate query semantics; Rewrite the original query statement based on the query semantics and static business security tags, add permission filtering conditions, and obtain the rewritten query statement; The rewritten query statement is submitted to the production database proxy interface for execution, the original result dataset is returned, and an independent temporary dynamic security container is injected through a one-way channel. The frequency of operations and query patterns of this session are recorded in an independent temporary dynamic security container to form a user history behavior log, and a risk assessment score is calculated. The initial risk profile is enhanced and adjusted based on the risk assessment score to obtain the final risk decision.
[0009] As a preferred embodiment of the software access control method based on data security described in this invention, the independent temporary dynamic security container performs a forced comparison between the metadata tags and static business security tags in the original result dataset to identify the user's static permission scope, and performs perturbation security processing to generate a secure data copy based on the final risk decision, specifically: An independent temporary dynamic security container receives the raw result dataset injected through a one-way channel, parses the structure of the raw result dataset, and extracts the row-level metadata tags for each record and the column-level metadata tags for each field. Compare the security level of the static business security tag in the dynamic access token with the row-level metadata tag to filter out inaccessible records; Compare the field permissions of static business security tags with column-level metadata tags to mask inaccessible fields; The original result dataset content, which retains the user's static permission range after row-level filtering and column-level masking, is combined into a permission-compliant dataset. Based on the final risk decision, risk level analysis is performed and the corresponding disturbance intensity is selected; Apply the selected perturbation strength to perform perturbation security processing on sensitive fields in the dataset that meet the permissions requirements; After the perturbation security processing is completed, the data content of the permission-compliant dataset after perturbation security processing is integrated into a secure data copy.
[0010] As a preferred embodiment of the software access control method based on data security described in this invention, the step of performing risk classification analysis and selecting the corresponding disturbance intensity based on the final risk decision specifically includes: The risk rating information in the final risk decision is analyzed. When the risk rating is low, a slight disturbance intensity is selected, and sensitive fields are masked. When the risk level is classified as medium, a moderate disturbance intensity is selected, and sensitive fields are encrypted. When the risk level is high, a high disturbance intensity is selected, and pseudo-data replacement is performed on sensitive fields.
[0011] As a preferred embodiment of the software access control method based on data security described in this invention, the step of transmitting a secure data copy back to the client as the control result of this data access and restricting high-risk operations specifically includes: The secure data copy is used as the sole control result of this data access and is transmitted unidirectionally to the client application through a pre-defined restricted output channel. The restricted output channel will apply high-risk operation restriction policies during the transmission process. After receiving a secure copy of the data, the client application will display the data on its local interface.
[0012] As a preferred embodiment of the software access control method based on data security described in this invention, the restricted output channel applies a high-risk operation restriction policy during transmission, which means prohibiting clients from downloading secure data copies in batches, prohibiting clients from copying secure data copy content via clipboard, and prohibiting clients from taking screenshots of the display interface.
[0013] As a preferred embodiment of the software access control method based on data security described in this invention, the step of performing predefined logical rule analysis on the extracted static business security markers and the collected real-time context signals specifically includes: When the predefined logical rules determine that the device health status is untrustworthy and the static business security label has a high security level, the initial risk profile is determined to be high risk. If the predefined logical rules determine that the geographical location is not on the whitelist and the access time is not during the user's usual active period, the initial risk profile is determined to be medium risk. Predefined logical rules determine the remaining cases and establish the initial risk profile as low risk.
[0014] In a second aspect, the present invention provides a computer device including a memory and a processor, wherein the memory stores a computer program, wherein when the computer program is executed by the processor, it implements any step of the software access control method based on data security as described in the first aspect of the present invention.
[0015] Thirdly, the present invention provides a computer-readable storage medium having a computer program stored thereon, wherein: when the computer program is executed by a processor, it implements any step of the software access control method based on data security as described in the first aspect of the present invention.
[0016] The beneficial effects of this invention are as follows: By recording user historical behavior logs in real time within a session and enhancing the initial risk profile to form the final risk decision, the process achieves continuous perception and response to dynamic access context and abnormal behavior. This compensates for the shortcomings of traditional role-based access control and attribute-based access control, which rely solely on initial authentication, effectively improving the defense capability against internal threats. Simultaneously, by adaptively selecting the perturbation strength in the final risk decision to perform masking, encryption, or pseudo-data replacement processing to generate a secure data copy, the session-level dynamic adjustment of data protection strength is achieved. This maintains high data availability in low-risk scenarios and provides strict protection in high-risk scenarios, avoiding the problems of over-masking or insufficient protection caused by the fixed-strength processing of existing query proxies and de-identification mechanisms, thus balancing business value and leakage risk. Attached Figure Description
[0017] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the following description of the embodiments will be briefly introduced. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0018] Figure 1 This is a flowchart of a software access control method based on data security.
[0019] Figure 2 A flowchart for creating and risk-making independent temporary dynamic safety containers.
[0020] Figure 3 This is a flowchart for permission comparison and disturbance security processing.
[0021] Figure 4 A flowchart for secure data copy transfer and container destruction. Detailed Implementation
[0022] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings.
[0023] Many specific details are set forth in the following description in order to provide a full understanding of the invention. However, the invention may also be practiced in other ways different from those described herein, and those skilled in the art can make similar extensions without departing from the spirit of the invention. Therefore, the invention is not limited to the specific embodiments disclosed below.
[0024] Secondly, the term "one embodiment" or "embodiment" as used herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The phrase "in one embodiment" appearing in different places in this specification does not necessarily refer to the same embodiment, nor is it a single or selective embodiment that is mutually exclusive with other embodiments.
[0025] Reference Figures 1-4 This is one embodiment of the present invention, which provides a software access control method based on data security, including the following steps: S1: After a user initiates a data access request, identity verification is performed. Once verified, a static business security tag is extracted from the unified identity management center. Simultaneously, real-time context signals are collected and used together with the static business security tag for judgment. After judgment, an initial risk profile is generated, and the user identity, static business security tag, and initial risk profile are encapsulated into a dynamic access token. S1.1: After a user initiates a data access request through the client application, strong authentication is performed on the user's identity. The specific process is as follows: After the user initiates a data access request through the client application, an identity authentication interface is provided to the user, requiring the user to input basic authentication information for identity verification. Basic authentication information includes a user account identifier and authentication credentials bound to the user account identifier. Authentication credentials can be at least one of password information, biometric information, or a one-time authentication code. After receiving the basic authentication information submitted by the user, a consistency check is performed between the basic authentication information and the identity verification information pre-stored in the unified identity management function to confirm the matching relationship between the user account identifier and the authentication credentials. When the basic authentication information verification passes... Upon further verification, an additional authentication process is triggered. This process is used to confirm the user's identity a second time. The additional authentication verification can be based on pre-bound terminal device features, pre-registered biometric features, or pre-configured dynamic authentication codes. When both the basic authentication verification result and the additional authentication verification result meet the preset identity confirmation conditions (i.e., both the basic authentication verification result and the additional authentication verification result pass), the strong identity authentication is deemed successful, confirming that the user initiating the data access request's identity matches the preset identity verification information recorded in the unified identity management function. When any authentication verification fails to meet the preset identity confirmation conditions, the strong identity authentication is deemed unsuccessful, and the subsequent static business security tag extraction and real-time context signal acquisition processes are terminated. After successful strong identity authentication, the static business security tag corresponding to the user's identity is read from the unified identity management function. The static business security tag is used to characterize the user's security attributes at the business level and includes at least the security level, business department information, or business project identification information. At the same time, the real-time context signal of this data access request is collected. The real-time context signal includes geographical location, device health status and access time period. Geographical location is used to indicate the physical or network location where the user initiates the data access request. Device health status is used to indicate whether the access device currently used by the user meets the preset security conditions. Access time period is used to indicate the time range in which the data access request occurs.
[0026] It should also be noted that the preset security conditions are used to limit the minimum security requirements that the accessing device must meet in terms of software and hardware operation and security protection status. Specifically, these include: whether the accessing device has a terminal security management client installed and in normal operating condition, to ensure that the accessing device has basic security control capabilities; whether the accessing device's operating version is within the allowed version range (set according to known vulnerability intelligence, such as Android-12 and above, iOS-15 and above), to prevent known high-risk vulnerability versions from participating in data access; whether the accessing device has completed necessary security patch updates, to reduce the risks caused by publicly disclosed security flaws; whether the accessing device is in an operating state that has not been modified or damaged without authorization, to confirm that the accessing device is not in jailbroken, cracked, or debug mode; and whether the accessing device has enabled necessary local security protection mechanisms, such as whether the accessing device has enabled local storage encryption or secure boot mechanisms. All of the above security conditions are defined by the unified identity management function. When the accessing device meets all preset security conditions, its health status is determined to be trustworthy; when the accessing device has any preset security condition that is not met, its health status is determined to be untrustworthy.
[0027] S1.2: After completing the extraction of static business security tags and the acquisition of real-time context signals, the static business security tags and real-time context signals are input into predefined logical rules for analysis. The predefined logical rules determine access risks based on the combination of security levels and real-time context signals. When the predefined logical rules determine that the device health status is untrustworthy and the security level of the static business security tag reaches level three or above, an initial risk profile with a high-risk rating is generated. Security levels are represented using a discrete level method, reflecting the sensitivity of data and the level of operational risk that users are allowed to access at the business level. Security levels are defined using an ordered set of levels, including level one, level two, level three, and level four, where level three or above indicates high business security sensitivity. In the predefined logical rules, if the security level of the static business security tag reaches level three or above, the static business security tag is determined to have a high security level. When the predefined logical rules determine that the geographical location is not on the whitelist and the access time is not during the user's regular active period, an initial risk profile with a medium-risk rating is generated. When the predefined logical rules determine that the conditions for high-risk and medium-risk ratings are not met, an initial risk profile with a low-risk rating is generated. After the initial risk profile is generated, the user identity, static business security marker, and initial risk profile are encapsulated to form a dynamic access token for this data access request. The dynamic access token serves as the access credential carrying identity information, business security marker information, and risk level information in the subsequent access control process.
[0028] It should also be noted that predefined logical rules are a set of deterministic judgment rules pre-configured according to business security management requirements before the data access control process is initiated. These predefined logical rules use the security level information in static business security tags and the geographical location, device health status, and access time period in real-time context signals as input, and the risk rating result of the initial risk profile as output. Predefined logical rules are defined using explicit condition matching. Each predefined logical rule clearly specifies the combination of triggering conditions and the corresponding risk rating result. There is no probability judgment or learning process between predefined logical rules; instead, they are matched sequentially according to the configuration order. When the triggering condition of a predefined logical rule completely matches the currently collected static business security tags and real-time context signals, the corresponding initial risk profile risk rating is determined, and the subsequent rule matching process ends. When no predefined logical rule meets the triggering condition, a preset default risk rating is used to generate the initial risk profile. Predefined logical rules are configured based on data sensitivity requirements, user role security requirements, and access environment risk requirements, and are stored and maintained in the unified identity management function and access control policy configuration environment.
[0029] S2: Receive dynamic access token, create independent temporary dynamic security container based on initial risk profile, parse query semantics based on data access request, submit query semantics and static business security tags to production database query, inject the raw result dataset returned from production database into independent temporary dynamic security container, enhance initial risk profile to form final risk decision; S2.1: Upon receiving the dynamic access token, immediately deseal and verify it, extracting the initial risk profile encapsulated within. The initial risk profile contains risk classification information. Based on this information, determine the isolation level of the independent temporary dynamic security container, expressed as: ; in, Indicates the isolation level. This represents the base isolation level value, with a fixed initial value of 1, indicating the lowest isolation baseline for all sessions. This indicates the amount of isolation level adjustment, representing the additional isolation intensity value added based on the risk level (e.g., 0 for low risk, 1 for medium risk, and 2 for high risk).
[0030] High-risk classification corresponds to the highest level of isolation, medium-risk classification corresponds to the medium level of isolation, and low-risk classification corresponds to the basic level of isolation.
[0031] The process of creating an independent, temporary, dynamic, secure container instantiates a temporary virtual runtime space in an isolated execution environment. It is implemented using operating system-level virtualization technology (such as Linux namespace and cgroups mechanisms or equivalent kernel isolation technologies). The independent, temporary, dynamic, secure container has independent memory allocation, process space, and resource limits. Container boundary policies are configured according to the determined isolation level, including restricting external network access, restricting file access scope, and limiting resource consumption limits, to ensure that the independent, temporary, dynamic, secure container is completely isolated from the production environment and other sessions. For example: When the isolation level corresponds to a high-risk classification, the container boundary policy completely prohibits external network access, prohibits all file write operations, restricts file access to reading only necessary query temporary files, and sets resource usage limits to, for example, 20% CPU share and a memory limit of 512MB, ensuring that high-risk sessions cannot leak data or consume excessive host resources. When the isolation level corresponds to a medium-risk classification, the container boundary policy prohibits external network access but allows limited file access, including reading query-related temporary files, and sets resource usage limits to, for example, 50% CPU share and a memory limit of 1GB, providing medium protection while supporting normal query execution. When the isolation level corresponds to a low-risk classification, the container boundary policy allows controlled external network access limited to the production database proxy interface, allows standard file access to read and write query temporary files, and sets resource usage limits to, for example, 80% CPU share and a memory limit of 2GB, balancing security and performance requirements. The container boundary policy takes effect throughout the entire lifecycle of the independent, temporary, dynamically secure container, ensuring that subsequent injection and processing of raw result datasets are performed within the controlled boundary.
[0032] S2.2: Perform SQL parsing on the original query statement contained in the data access request. The original query statement is a standard SQL format string carried by the user when initiating the data access request. The SQL parsing operation extracts the table name list, field name list, and query condition expression from the original query statement through lexical and syntactic analysis, generating structured query semantics. The query semantics stores the extracted table names, field names, and query conditions in a data structure for easy processing of subsequent access control.
[0033] The original query statement is rewritten based on the generated query semantics and the static business security marker carried in the dynamic access token. The rewriting process adds row-level and column-level permission filtering conditions to the query semantics. The row-level permission filtering conditions generate a WHERE clause based on the security level of the static business security marker and department information to limit the record range. For example, if the static business security marker's security level is level three and the department information is "R&D Department", the generated WHERE clause would be: WHERE data_level<=3 AND dept='R&D Department', which restricts the original result dataset to only returning records with a security level not exceeding level three and belonging to the R&D Department. The column-level permission filtering conditions generate a SELECT clause based on the field permissions of the static business security marker to limit the returned fields, resulting in a rewritten query statement with access control.
[0034] S2.3: Submit the rewritten query statement to the production database proxy interface. The production database proxy interface executes the rewritten query statement in the real production database environment and returns the original result dataset. The original result dataset is a collection of query records that meet the permission filtering conditions. After being returned, it is directly injected into the created independent temporary dynamic security container through a preset one-way channel. The one-way channel only allows data to be transmitted from the production database proxy to the independent temporary dynamic security container, and prohibits reverse or external access, ensuring that the original result dataset is not directly exposed to the client application.
[0035] It should also be noted that the production database is the core business database of the enterprise or organization, built using a relational database (such as MySQL, Oracle, or PostgreSQL), deployed on a dedicated server or cloud database instance, isolated from the external network, and provided with controlled access only through the production database proxy interface. The production database contains business-related structured data tables, such as user personal information tables, order record tables, financial data tables, and log tables. Each table defines fields, indexes, and constraints, and is tagged with metadata, including row-level metadata tags (used to identify the department, security level, or project to which the record belongs) and column-level metadata tags (used to identify field sensitivity attributes, such as normal, sensitive, or highly sensitive). Metadata tags are added by data governance tools when the database is created or data is ingested, to support subsequent permission filtering. The unidirectional channel is implemented during the deployment phase through network security and proxy configuration, built using a database firewall or dedicated proxy service (such as database proxy middleware). The channel configuration rules explicitly define that data flow is only from the production database proxy to the execution environment of the independent, temporary, dynamic security container, prohibiting reverse traffic.
[0036] S2.4: Within a separate, temporary, dynamic security container, user actions during the current session are recorded in real time. This includes counting operation frequency (e.g., the user has submitted 12 query requests in this session), identifying query patterns (e.g., the query pattern for this session is identified as a continuous high-frequency field query pattern, specifically, 8 consecutive queries targeting the same sensitive fields "ID number" and "mobile phone number" in the same table), and recording data access volume (e.g., the cumulative number of accessed records for this session is 4500), forming a user historical behavior log. This user historical behavior log is stored in the memory of the separate, temporary, dynamic security container in structured log format. The degree of abnormal behavior is assessed based on the recorded user historical behavior logs. Specifically, this involves: checking whether the operation frequency exceeds a preset frequency threshold. If the operation frequency exceeds the threshold, it is identified as a high-frequency operation and the risk assessment score is increased accordingly. The initial risk assessment score is 0. For example, based on historical audit data, high-frequency operations account for about 40% of abnormal behaviors, but about 30% of these are legitimate sudden business transactions. Therefore, a score of 20 is added for high-frequency operation anomalies to appropriately increase the risk assessment score while avoiding excessive false alarms, thus obtaining the abnormal operation frequency score; checking whether there are abnormal changes in query patterns. Abnormal changes include the query table or field suddenly switching from a normal business field to a sensitive field (such as personal privacy information, financial information, etc.), or the query conditions changing from single-record queries to multi-batch queries. If abnormal changes in query patterns are identified, the risk assessment score will be increased. Frequent jumps in query patterns are identified as abnormal and the risk assessment score is increased accordingly. For example, based on risk event backtracking analysis, in sessions where the query pattern suddenly switches to sensitive fields or batch queries, approximately 70% are ultimately associated with data breaches or internal threats. Therefore, an abnormal pattern score is increased by 30 points to highlight the severity of abnormal query pattern behavior and prioritize triggering stronger protection, thus obtaining an abnormal query pattern score. At the same time, it is checked whether the data access volume exceeds the preset query ratio. If the data access volume exceeds the query ratio, it is identified as batch access abnormal and the risk assessment score is increased accordingly. For example, based on data breach case statistics, abnormal batch access accounts for approximately 50% of violations, but some are legitimate reporting requirements. Therefore, an abnormal batch access score is increased by 25 points to balance detection sensitivity and business availability, thus obtaining an abnormal data access volume score.
[0037] The risk assessment score is obtained based on the anomalies, expressed as follows: ; in, Indicates the risk assessment score. This indicates the score for abnormal operation frequency. Indicates the query pattern anomaly score. This indicates an abnormal score for data access volume.
[0038] A higher risk assessment score indicates a greater degree of behavioral abnormality. The risk assessment score is integrated with the risk level of the initial risk profile. Specifically, the cumulative risk assessment score is mapped to the risk level adjustment range. Based on the statistical analysis of historical user behavior logs and actual risk events, a range is set: when the risk assessment score is below 30, the risk level of the initial risk profile remains unchanged; when the score is between 30 and 60, the risk level of the initial risk profile is increased by one level; and when the score is above 60, the risk level of the initial risk profile is increased by two levels. This generates a final risk decision that includes a higher or the same risk level, ensuring that the degree of behavioral abnormality directly affects the strength of subsequent disturbance security handling. The final risk decision is formed based on the initial risk profile and includes risk level information adjusted from the user's historical behavior logs. The risk level information is used to select the strength of subsequent disturbances.
[0039] It should also be noted that the frequency threshold is set based on normal user business access habits, aiming to identify potential bulk export or attack behaviors. For example, a frequency threshold of no more than 5 query requests per minute is based on the frequency of manual operations by ordinary users or legitimate application interface calls in typical enterprise database applications. The query ratio is set according to data security compliance requirements and sensitive data access monitoring specifications to prevent the risk of leakage due to excessive accumulation of sensitive information within a session. For example, a query ratio set to no more than 30% of the total number of records accessed for sensitive fields in a session is based on data classification and grading standards; 30% can balance normal analysis needs with risk control.
[0040] Ideally, by dynamically creating independent temporary dynamic security containers and configuring isolation levels in real time based on initial risk profiles, complete isolation between query execution and data processing is achieved. This prevents the raw result dataset from being directly exposed to client applications, effectively preventing data leakage. A mechanism for real-time evaluation of user historical behavior logs and fusion with risk profiles dynamically enhances the accuracy of risk decisions and supports adaptive adjustment of perturbation intensity based on the degree of behavioral anomalies, improving defense against internal threats and abnormal access. Simultaneously, the combination of query rewriting and one-way channel injection ensures that permission filtering is enforced in the production environment without trusting the client, significantly improving the granularity and security of data access control, meeting compliance requirements in highly sensitive business scenarios, and balancing security protection with query performance.
[0041] S3: The independent temporary dynamic security container performs a forced comparison between the metadata tags in the original result dataset and the static business security tags, identifies the user's static permission scope, and performs perturbation security processing to generate a secure data copy based on the final risk decision; S3.1: After receiving the original result dataset injected through the one-way channel, the independent temporary dynamic security container performs structural parsing on the original result dataset. The parsing process is used to identify the data record structure and field structure contained in the original result dataset, and extract metadata tags related to data security control. The extracted metadata tags include row-level metadata tags associated with each data record and column-level metadata tags associated with each data field. The row-level metadata tags are used to characterize the security level, business department or business project attribute corresponding to the data record, and the column-level metadata tags are used to characterize the sensitive attribute type corresponding to the data field. After extracting the metadata tags, the security level information of the static business security tags encapsulated in the dynamic access token is compared line by line with the row-level metadata tags. Both the security level of the static business security tags and the record security level in the row-level metadata tags adopt a unified security level grading standard. The security level grading standard is a preset numerical range of 1-10 (level 1 is the lowest sensitivity, and level 10 is the highest sensitivity). The level values are pre-assigned by the unified identity management center based on the record's sensitivity attributes when the data is entered into the database. For example, the security level of ordinary business data records is level 3, the security level of records involving personal privacy is level 7, and the security level of records involving core trade secrets is level 10. The security levels in the static business security tags and the record security levels in the row-level metadata tags are then compared. The system determines that when the security level in the static business security tag is greater than or equal to the record security level in the row-level metadata tag, the corresponding data record is within the user's static permission range and is retained. When the security level in the static business security tag is less than the record security level in the row-level metadata tag, the corresponding data record is determined to be outside the user's static permission range (the user's static permission range is entirely determined by the user's preset role and is unrelated to real-time behavior, ensuring that information beyond the authorization will not be leaked even in low-risk sessions. For example, after the current user passes strong authentication, the security level of the static business security tag extracted from the unified identity management function is level 7 (meaning that the current user has permission to access records and fields at the highest level 7 and below)) and performs filtering processing on the current data record. Simultaneously, the field access permissions defined in the static business security tag are compared with the column-level metadata tag: the list of allowed fields is read from the static business security tag, and the list of allowed fields is matched one by one with the field identifiers identified in the column-level metadata tag. When the field identifier corresponding to the column-level metadata tag is not included in the list of allowed fields, it is determined that the current field does not meet the field access permission requirements. The data field that does not meet the field access permission requirements is masked. Specifically, for data fields that are marked as inaccessible by the column-level metadata tag, the corresponding field content is replaced with an empty value or an unrecognizable placeholder when generating the permission-compliant dataset, so that only the data content that conforms to the user's static permission range is retained in the original result dataset, forming the permission-compliant dataset.
[0042] It should also be noted that the permission conformance dataset, as a subset of the original result dataset, is directly used for subsequent perturbation security processing to generate a secure data copy. The difference between the permission conformance dataset and the secure data copy is that the permission conformance dataset only performs static permission filtering and masking, while the secure data copy further applies dynamic perturbations (such as noise addition, generalization, or suppression) based on the final risk decision to sensitive fields.
[0043] S3.2: After generating the permission compliance dataset, the risk rating information is parsed based on the final risk decision. This risk rating information reflects the risk level of the data access request after comprehensively considering the access environment and access behavior. The parsing process is as follows: Based on the access risk level determined by the final risk decision, the access risk level is matched with pre-defined risk rating enumeration values to determine the risk rating result corresponding to the final risk decision. The risk rating enumeration values are a pre-defined set of ordered risk levels defined before the deployment of the data access control process, based on business data security management requirements and access risk classification rules. These values are set based on the comprehensive management needs of data sensitivity, access environment risk, and access behavior risk. The risk rating enumeration values include at least three levels: low risk, medium risk, and high risk. Each risk rating enumeration value corresponds to a clear risk meaning and is used as the judgment benchmark during risk rating parsing. When the risk level is low, a mild perturbation intensity is selected. This intensity masks sensitive fields in the dataset that match the user's permissions, hiding some content while preserving the field format characteristics. When the risk level is medium, a moderate perturbation intensity is selected. This intensity encrypts sensitive fields in the dataset that match the user's permissions, preventing direct identification without authorization. When the risk level is high, a high perturbation intensity is selected. This intensity performs pseudo-data replacement on sensitive fields in the dataset that match the user's permissions. This replacement eliminates the identifiability of genuine sensitive information. Specifically, sensitive fields in the dataset that match the user's permissions (such as names, ID numbers, mobile phone numbers, addresses, account balances, etc., pre-marked as sensitive) are replaced with pseudo-data. This pseudo-data comes from a centrally managed pseudo-data pool or is dynamically generated based on field type. For example, for the name field, a fake name generated from a common surname and given name combination is used, such as replacing "Zhang Wei" with "Li Ming". The correspondence between risk level and perturbation intensity ensures that the data security processing intensity is consistent with the access risk level.
[0044] S3.3: After selecting the perturbation strength, perform perturbation security processing corresponding to the perturbation strength on sensitive fields in the permission-compliant dataset. This perturbation security processing only affects data content within the permission-compliant dataset and does not change the storage state of the original dataset in the production database. After the perturbation security processing is complete, the data fields that have undergone masking, encryption, or pseudo-data replacement processing are integrated with the unaffected data fields to generate a data access result for external provision. This generated data access result is the secure data copy. The secure data copy exists only in a controlled environment within an independent, temporary, dynamic secure container and is used for subsequent data display and access control processes, thereby reducing the risk of sensitive information leakage while ensuring data availability.
[0045] Preferably, compared to traditional methods, this invention processes the original result dataset within an independent, temporary, dynamic security container, extending data access control from traditional static permission verification to a multi-dimensional control mechanism that combines static business security tags, data metadata tags, and access risk decisions. Through mandatory comparison of row-level and column-level metadata tags, the static permission range of users can be accurately identified before data is returned, preventing the exposure of data exceeding permissions. Simultaneously, combined with the final risk decision, different levels of perturbation security processing are applied to sensitive fields, causing the data presentation to dynamically change according to access risks. This effectively reduces the risk of sensitive information leakage while ensuring data availability, thereby achieving a more refined and reliable software access control effect based on data security.
[0046] S4: Pass a copy of the secure data back to the client for display and restrict high-risk operations. Destroy the independent temporary dynamic security container after the session ends.
[0047] S4.1: Once the secure data copy is generated, it serves as the sole control result for this data access and is unidirectionally transmitted to the client application via a pre-defined restricted output channel. This pre-defined restricted output channel is configured during the deployment phase and is built using a dedicated communication interface between the client application and the independent temporary dynamic secure container. This communication interface only supports data transmission from the independent temporary dynamic secure container to the client application; sending any data or commands from the client application to the independent temporary dynamic secure container is prohibited. When transmitting the secure data copy via the pre-defined restricted output channel, the data content is packaged in encrypted stream form to ensure data integrity and confidentiality during transmission.
[0048] Upon receiving the secure data copy, the client application immediately loads the data records on the local interface and displays the data. During the display process, a read-only view is used to render the secure data copy content, and multiple records cannot be selected or the export function is disabled in the view controls. A pre-defined restricted output channel enforces a high-risk operation restriction policy while transmitting the secure data copy. This policy includes three specific measures: First, it prohibits clients from batch downloading the secure data copy; the client application interface hides all download buttons and export options, and the client application intercepts any batch save requests and returns a rejection response. Second, it prohibits clients from copying the secure data copy content via the clipboard; the client application disables text selection and copy functions on the display interface, monitors clipboard operations, and clears any content related to the secure data copy that attempts to copy. Third, it prohibits clients from taking screenshots of the display interface; for example, the client application registers a screenshot interception hook with the operation function at runtime, and upon detecting a screenshot event, immediately overwrites the display interface with a black screen or warning screen and records the interception event.
[0049] S4.2: When the current data access session terminates due to timeout or user-initiated termination, the independent temporary dynamic security container immediately initiates a destruction process. The destruction process first clears all temporary data in the independent temporary dynamic security container's memory, including the original result dataset, permission-compliant dataset, security data copies, user historical behavior logs, and intermediate computation states. The clearing operation employs multiple overwrite operations to ensure data is unrecoverable. Then, the process space, memory allocation, and resource limits occupied by the independent temporary dynamic security container are released. After the destruction process is complete, the independent temporary dynamic security container instance completely disappears, and subsequent sessions cannot access any residual data, thus completing this software access control process.
[0050] Preferably, this invention implements one-way encrypted transmission of secure data copies and enforces high-risk operation restrictions through a pre-defined restricted output channel. Client applications can only perform read-only display and cannot perform batch downloads, clipboard copying, or screenshots, ensuring that sensitive data is not leaked or misused on the client side. Simultaneously, at the end of the session, an independent temporary dynamic secure container is automatically destroyed and all temporary data is completely cleared, eliminating residual risks and avoiding persistent data leakage problems caused by client caching or temporary files in existing methods. This significantly improves the security and compliance of access control while ensuring data availability, making it particularly suitable for highly sensitive business scenarios and providing more reliable end-to-end data protection.
[0051] This embodiment also provides a computer device applicable to the software access control method based on data security, comprising: a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions to implement the software access control method based on data security as proposed in the above embodiment.
[0052] The computer device can be a terminal, comprising a processor, memory, communication interface, display screen, and input devices connected via a system bus. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The communication interface is used for wired or wireless communication with external terminals; wireless communication can be achieved through Wi-Fi, carrier networks, NFC (Near Field Communication), or other technologies. The display screen can be an LCD screen or an e-ink screen. The input devices can be a touch layer covering the display screen, buttons, a trackball, or a touchpad on the computer device's casing, or an external keyboard, touchpad, or mouse.
[0053] This embodiment also provides a storage medium storing a computer program thereon. When the program is executed by a processor, it implements the software access control method based on data security as proposed in the above embodiments. The storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as Static Random Access Memory (SRAM), Electrically Erasable Programmable Read-Only Memory (EEPROM), Erasable Programmable Read Only Memory (EPROM), Programmable Red-Only Memory (PROM), Read-Only Memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk.
[0054] In summary, this invention achieves continuous awareness and response to dynamic access context and abnormal behavior by recording user historical behavior logs in real time within a session and enhancing the initial risk profile to form the final risk decision. This overcomes the shortcomings of traditional role-based access control and attribute-based access control, which rely solely on initial authentication, effectively improving the defense capability against internal threats. Simultaneously, by adaptively selecting the perturbation strength in the final risk decision to perform masking, encryption, or pseudo-data replacement processing to generate a secure data copy, it achieves session-level dynamic adjustment of data protection strength. This maintains high data availability in low-risk scenarios and provides strict protection in high-risk scenarios, avoiding the problems of over-masking or insufficient protection caused by the fixed-strength processing of existing query proxies and de-identification mechanisms, thus balancing business value and leakage risk.
[0055] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.
Claims
1. A software access control method based on data security, characterized in that: include, After a user initiates a data access request, their identity is verified. Once verified, a static business security tag is extracted from the unified identity management center. Simultaneously, real-time context signals are collected and used together with the static business security tag for judgment. After judgment, an initial risk profile is generated, and the user's identity, static business security tag, and initial risk profile are encapsulated into a dynamic access token. Receive dynamic access tokens, create independent temporary dynamic security containers based on the initial risk profile, parse query semantics based on data access requests, submit the query semantics and static business security tags to the production database for querying, inject the raw result dataset returned from the production database into the independent temporary dynamic security containers, and form the final risk decision after enhancing the initial risk profile. The creation of the independent temporary dynamic security container specifically involves: Upon receiving a dynamic access token, the initial risk profile is immediately parsed, and the container isolation level is determined based on the parsed initial risk profile, and an independent temporary dynamic security container is created. The formation of the final risk decision specifically involves: The frequency of operations and query patterns of this session are recorded in an independent temporary dynamic security container to form a user history behavior log, and a risk assessment score is calculated. The initial risk profile is enhanced and adjusted based on the risk assessment score to obtain the final risk decision. The independent temporary dynamic security container performs a forced comparison between the metadata tags in the original result dataset and the static business security tags to identify the user's static permission scope, and performs perturbation security processing to generate a secure data copy based on the final risk decision; A secure copy of the data is passed back to the client for display and high-risk operations are restricted. The independent, temporary, dynamic security container is destroyed after the session ends.
2. The software access control method based on data security as described in claim 1, characterized in that: After a user initiates a data access request, their identity is verified. Upon successful verification, a static business security tag is extracted from the unified identity management center. Simultaneously, real-time context signals are collected and used in conjunction with the static business security tag to generate an initial risk profile, specifically: Users initiate data access requests through client applications. The user's identity is confirmed through strong identity authentication. After successful authentication, the user's preset static business security tags are extracted from the unified identity management function. Collect geographic location, device health status, and access time period as real-time context signals; The extracted static business security markers and real-time context signals are analyzed using predefined logical rules to generate an initial risk profile.
3. The software access control method based on data security as described in claim 1, characterized in that: The process involves receiving a dynamic access token, creating an independent temporary dynamic security container based on the initial risk profile, parsing the query semantics according to the data access request, submitting the query semantics and static business security tags to the production database, injecting the raw result dataset returned from the production database into the independent temporary dynamic security container, and enhancing the initial risk profile to form the final risk decision. Specifically: Perform SQL parsing on the original query statement in the data access request, extract table names, field names and query conditions, and generate query semantics; Rewrite the original query statement based on the query semantics and static business security tags, add permission filtering conditions, and obtain the rewritten query statement; The rewritten query statement is submitted to the production database proxy interface for execution, the original result dataset is returned, and an independent temporary dynamic security container is injected through a one-way channel.
4. The software access control method based on data security as described in claim 1, characterized in that: The independent temporary dynamic security container performs a forced comparison between the metadata tags in the original result dataset and the static business security tags to identify the user's static permission scope, and performs perturbation security processing to generate a secure data copy based on the final risk decision. Specifically: An independent temporary dynamic security container receives the raw result dataset injected through a one-way channel, parses the structure of the raw result dataset, and extracts the row-level metadata tags for each record and the column-level metadata tags for each field. Compare the security level of the static business security tag in the dynamic access token with the row-level metadata tag to filter out inaccessible records; Compare the field permissions of static business security tags with column-level metadata tags to mask inaccessible fields; The original result dataset content, which retains the user's static permission range after row-level filtering and column-level masking, is combined into a permission-compliant dataset. Based on the final risk decision, risk level analysis is performed and the corresponding disturbance intensity is selected; Apply the selected perturbation strength to perform perturbation security processing on sensitive fields in the dataset that meet the permissions requirements; After the perturbation security processing is completed, the data content of the permission-compliant dataset after perturbation security processing is integrated into a secure data copy.
5. The software access control method based on data security as described in claim 4, characterized in that: The process of risk rating analysis and selection of corresponding disturbance strength based on the final risk decision is as follows: Analyze the risk rating information in the final risk decision, select a mild disturbance intensity when the risk rating is low, and mask sensitive fields; When the risk level is classified as medium, a moderate disturbance intensity is selected, and sensitive fields are encrypted. When the risk level is high, a high disturbance intensity is selected, and pseudo-data replacement is performed on sensitive fields.
6. The software access control method based on data security as described in claim 1, characterized in that: The step of passing a secure data copy back to the client as the control result of this data access for display and restricting high-risk operations specifically involves: The secure data copy is used as the sole control result of this data access and is transmitted unidirectionally to the client application through a pre-defined restricted output channel. The restricted output channel will apply high-risk operation restriction policies during the transmission process. After receiving a secure copy of the data, the client application will display the data on its local interface.
7. The software access control method based on data security as described in claim 6, characterized in that: The restricted output channel will apply high-risk operation restriction policies during transmission, which means prohibiting clients from downloading security data copies in batches, prohibiting clients from copying security data copy content via clipboard, and prohibiting clients from taking screenshots of the display interface.
8. The software access control method based on data security as described in claim 2, characterized in that: The process of analyzing the extracted static business security markers and the collected real-time context signals using predefined logical rules specifically involves: When the predefined logical rules determine that the device health status is untrustworthy and the static business security label has a high security level, the initial risk profile is determined to be high risk. If the predefined logical rules determine that the geographical location is not on the whitelist and the access time is not during the user's usual active period, the initial risk profile is determined to be medium risk. Predefined logical rules determine the remaining cases and establish the initial risk profile as low risk.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that: When the processor executes the computer program, it implements the steps of the software access control method based on data security as described in any one of claims 1 to 8.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by the processor, it implements the steps of the software access control method based on data security as described in any one of claims 1 to 8.
Citation Information
Patent Citations
Access control method and system for data security protection
CN119109614A
Systems and methods for enforcing policy based on assigned user risk scores in a cloud-based system
US20250227110A1