Data access control method and device, gateway end equipment and server end equipment
By extracting and evaluating multi-dimensional trust data of data access requests at the gateway, and combining authorization decision models and dynamic threshold control, the accuracy and consistency issues of data access control in microservice architecture are solved, thereby improving the security of data access.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-18
- Publication Date
- 2026-04-10
AI Technical Summary
In existing microservice architectures, the accuracy and consistency of authorization decisions during data access control are difficult to guarantee, resulting in poor data access security.
The gateway extracts multi-dimensional trust data from data access requests, scores it based on trust assessment rules, and sends the trust score and request content to the target server. It then uses an authorization decision model trained on historical authorization samples to determine the decision probability, and finally compares it with a preset dynamic threshold range for control.
It enables flexible and accurate distributed authorization decisions for data access requests in a microservice architecture, improving the effectiveness and security of data access control.
Smart Images

Figure CN121841697A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of data processing technology, and in particular to a data access control method and apparatus, a gateway device, and a server device. Background Technology
[0002] With the rapid popularization of big data applications in fields such as the internet, healthcare, and finance, these applications often involve large amounts of sensitive data, such as personal information, health information, financial records, and identity information. The security of this data is paramount; leakage or unauthorized access can lead to serious privacy and security issues and economic losses. Therefore, to protect sensitive data, application service providers typically employ strict data security management methods, such as access control, encryption, and auditing, to manage and control sensitive data.
[0003] Currently, existing microservice architectures typically control data access through authorization mechanisms. However, a single authorization mechanism is rather vague and can no longer meet increasingly complex security requirements. Furthermore, due to the distributed nature of microservices, requests generate multi-dimensional data as they pass through multiple service nodes. Different service nodes interpret and process this data differently, making it difficult to guarantee the accuracy and consistency of authorization decisions. This results in poor accuracy in data access control, significantly impacting data security. Summary of the Invention
[0004] This disclosure provides a data access control method and apparatus, a gateway device, and a server device. Its main purpose is to solve the problem of low security in data access control. According to a first aspect of this disclosure, a data access control method is provided, applied at a gateway, comprising: In response to a data access request, extract multi-dimensional trust data from the data access request; The multi-dimensional trust data is scored based on trust assessment rules to obtain a trust score. The trust score and the request content in the data access request are then sent to the target server so that the target server can determine the decision probability based on the authorization decision model, which is obtained by training the model based on historical authorization samples. The received decision probability is compared with a preset dynamic threshold range, and the data access request is controlled based on the comparison result.
[0005] According to a second aspect of this disclosure, another method for controlling data access is provided, comprising: Obtain the request content and trust score of the data access request sent by the gateway, wherein the trust score is obtained by scoring based on the multi-dimensional trust data of the data access request; The authorization decision model is used to process the request content, the trust score, and historical access data to obtain the decision probability. The authorization decision model is obtained by training the model based on historical authorization samples. The decision probability is fed back to the gateway.
[0006] According to a third aspect of this disclosure, a data access control device is provided, comprising: The extraction module is used to extract multi-dimensional trust data from the data access request in response to the data access request. The scoring module is used to score the multi-dimensional trust data based on trust assessment rules to obtain a trust score, and send the trust score and the request content in the data access request to the target server so that the target server can determine the decision probability based on the authorization decision model, which is obtained by model training based on historical authorization samples. The control module is used to compare the received decision probability with a preset dynamic threshold range, and control the data access request based on the comparison result.
[0007] According to a fourth aspect of this disclosure, another data access control device is provided, comprising: The acquisition module is used to acquire the request content and trust score of the data access request sent by the gateway. The trust score is obtained by scoring based on the multi-dimensional trust data of the data access request. The decision module is used to perform decision processing on the request content, the trust score, and historical access data based on the authorization decision model to obtain the decision probability. The authorization decision model is obtained by training the model based on historical authorization samples. The feedback module is used to feed back the decision probability to the gateway.
[0008] According to a fifth aspect of this disclosure, an electronic device is provided, comprising: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the data access control method described in the first aspect above.
[0009] According to a sixth aspect of this disclosure, a non-transitory computer-readable storage medium storing computer instructions is provided, wherein the computer instructions are used to cause the computer to perform the data access control method described in the first aspect above.
[0010] According to a seventh aspect of this disclosure, a computer program product is provided, including a computer program that, when executed by a processor, implements the data access control method as described in the first aspect above.
[0011] According to the eighth aspect of this disclosure, another electronic device is provided, comprising: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the data access control method described in the first aspect above.
[0012] According to a ninth aspect of this disclosure, another non-transitory computer-readable storage medium is provided, wherein the computer instructions are used to cause the computer to perform the data access control method described in the first aspect above.
[0013] According to the tenth aspect of this disclosure, another computer program product is provided, including a computer program that, when executed by a processor, implements the data access control method as described in the first aspect above.
[0014] According to the eleventh aspect of this disclosure, a data access control system is provided, which includes a gateway device as described above and a server device as described above.
[0015] The data access control method, apparatus, gateway device, and server device disclosed herein, upon responding to a data access request, extract multi-dimensional trust data from the data access request and score the multi-dimensional trust data based on trust evaluation rules to obtain a trust score. The trust score and the request content in the data access request are then sent to the target server, enabling the target server to determine a decision probability based on an authorization decision model, which is trained using historical authorization samples. When the gateway receives the decision probability, it compares it with a preset dynamic threshold range and controls the data access request based on the comparison result. This achieves flexible and accurate distributed authorization decision-making for data access request security, solving the problem of poor accuracy in fine-grained permission control under microservice architecture, thereby greatly improving the effectiveness of data access request control.
[0016] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of this disclosure, nor is it intended to limit the scope of this disclosure. Other features of this disclosure will become readily apparent from the following description. Attached Figure Description
[0017] The accompanying drawings are provided to better understand this solution and do not constitute a limitation of this disclosure. Wherein: Figure 1 A flowchart illustrating a data access control method provided in an embodiment of this disclosure; Figure 2 This is a schematic diagram of the control timing flow for data access provided in an embodiment of the present disclosure; Figure 3 A flowchart illustrating another data access control method provided in an embodiment of this disclosure; Figure 4 This is a schematic diagram of the structure of a text generation device provided in an embodiment of the present disclosure; Figure 5 A schematic diagram of another text generation apparatus provided in an embodiment of this disclosure; Figure 6 A schematic block diagram of an example electronic device 500 provided for embodiments of this disclosure; Figure 7 A schematic block diagram of an example electronic device 600 provided for embodiments of this disclosure. Detailed Implementation
[0018] The exemplary embodiments of this disclosure are described below with reference to the accompanying drawings, including various details of the embodiments to aid understanding, and should be considered merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of this disclosure. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description.
[0019] The following description, with reference to the accompanying drawings, outlines a data access control method and apparatus, a gateway device, and a server device according to embodiments of this disclosure.
[0020] Figure 1 This is a flowchart illustrating a data access control method provided in an embodiment of the present disclosure.
[0021] like Figure 1 As shown, when applied to the gateway, this method includes the following steps: Step 101: In response to the data access request, extract the multi-dimensional trust data from the data access request.
[0022] In this embodiment, the current execution end, acting as the primary entity for data security management in the microservice architecture, is the gateway, such as an API gateway. Upon receiving a data access request from a client, it performs a data security assessment on the request. This data access request is triggered by the client for the required application service. The request may carry authentication information (such as user credentials), device identifiers (such as device ID), address information (such as IP address), and time information (such as timestamp), from which multi-dimensional trust data can be extracted. This multi-dimensional trust data characterizes data that can be used for security trust assessment, including but not limited to user behavior characteristics and access frequency; this embodiment does not impose specific limitations on these characteristics.
[0023] It should be noted that the application service in this embodiment can be a microservice embedded in different applications, such as a payment service in a social application. This embodiment does not impose any specific limitations.
[0024] Step 102: Score the multi-dimensional trust data based on the trust assessment rules to obtain a trust score, and send the trust score and the request content in the data access request to the target server.
[0025] In this embodiment, since different application services or different access purposes have different characteristics, the current execution end pre-configures trust evaluation rules for scoring, retrieves the trust evaluation rules corresponding to the data access request, scores the multi-dimensional trust data to obtain a trust score, and sends the trust score and the request content in the data access request to the target server, so that the target server can determine the decision probability based on the authorization decision model. The target server is selected by the current execution end from multiple servers, which can be selected based on a weighted round-robin algorithm or a random round-robin method. Different servers can provide application services. After the target server is determined, the trust score and the request content in the data access request are sent to the target server via routing. Furthermore, the request content in the data access request represents the content requested by the client to access the application service, including but not limited to data download, video playback, etc., which are not specifically limited in this embodiment.
[0026] In this embodiment of the disclosure, the trust assessment rule, as a rule for scoring multi-dimensional trust data, may include, but is not limited to, weighted scoring of different trust data. For example, the trust assessment rule may assign 30% to the source IP trustworthiness, 50% to the authentication token validity, and 20% to the access time reasonableness. When the source IP in the multi-dimensional trust data is 192.168.1.100, the authentication token is "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9", and the access time is 2024-09-24 14:30:00, according to the preset rules, the source IP trustworthiness is 0.8 (out of 1.0), the authentication token validity is 1.0, and the access time reasonableness is 0.9. Then, applying the weighted average algorithm, the trust score is calculated as 0.8*0.3 + 1.0*0.5 + 0.9*0.2 = 0.92. In addition, if a resource sensitivity coefficient is set in the trust assessment rules, then if the resource sensitivity is 0.7, the final trust score will be 0.92 * 0.7 = 0.644.
[0027] It should be noted that different servers will pre-customize and adapt authorization decision models based on the differences in their own data resources. After receiving multi-dimensional trust data, they will use the authorization decision model to make a decision on whether to authorize data access. The authorization decision model is trained based on historical authorization samples. At this time, the historical authorization samples may include, but are not limited to, historical access counts and historical access authorization results, etc., to train the authorization decision model. Moreover, the authorization decision model is preferably a random forest tree model, but this embodiment does not make specific limitations.
[0028] Step 103: The received decision probability is compared with a preset dynamic threshold range, and the data access request is controlled based on the comparison result.
[0029] In this embodiment, after the target server receives the decision probability, it compares it against a preset dynamic threshold range to determine one of authorized, unauthorized, or suspicious permissions. If it is an authorized permission, it means the target server's decision on the data access request is to authorize it. Therefore, the current execution terminal, acting as the gateway, sends the data access request to the target application service. At this time, the target application service can be a standalone server or embedded within a server. Furthermore, when sending the data access request to the target application service, the data access request can carry a token issued by the authentication service.
[0030] In some embodiments, when authorization is determined based on the comparison result, the gateway sends a token request instruction to the authentication service. This instruction includes the requested identity information and authorization scope to obtain an access token returned by the authentication service. The access token contains expiration time and authorization scope information. The gateway verifies the signature and validity period of the access token. If the access token is valid, it appends it to the request header of the original data access request. Simultaneously, it can obtain a list of target application service addresses from the server, select a service instance from the list using a weighted round-robin algorithm, and finally forward the data access request carrying the access token to the selected service instance to complete the transmission of the authorized data access request.
[0031] In other embodiments, an authorization decision log can also be generated. In this case, the authorization decision log contains request information, decision results, and token information. The authorization decision log is then sent to the log collection service via a message queue. The log collection service parses and standardizes the received log.
[0032] For example, after receiving the output of the authorization decision model, the API gateway determines whether the request meets the access threshold. If not, it generates a standard format response with detailed descriptions based on different rejection reasons (such as authentication failure, insufficient permissions, resource limitations), returns it to the request initiator via HTTP status code 403, and records the rejection event in a local log file. For data access requests that meet the access threshold, the API gateway initiates a token request to the authentication service. The authentication service generates an access token containing information such as expiration time and permission scope using the JWT (JSON Web Token) specification, based on the request's identity information and authorization scope, and returns it to the API gateway via a TLS encrypted channel. If the token request fails, the API gateway generates an error response containing the reason for the failure and returns it to the requester. The API gateway verifies the received token signature and validity period, appends a valid token to the header of the original request, obtains the address list of the target business logic service through the service discovery mechanism, selects a specific service instance using a weighted round-robin algorithm, and then forwards the request carrying the token to the selected application service, such as the business logic instance, via HTTPS. If a network timeout or service unavailability is encountered during forwarding, other instances can be tried or an error response can be returned.
[0033] In some embodiments, the API gateway asynchronously sends the complete authorization decision log, including request information (IP address, timestamp, request path), decision result (allow / deny, reason code), and token information (token ID, expiration time, permission scope), to a unified log collection service via a message queue. The log collection service parses and standardizes the received logs, storing the structured data in the relational database of the auditing platform and the time-series database of the risk control platform, respectively. The risk control platform uses this data for real-time anomaly detection, such as frequent failed login attempts and abnormal access pattern identification, and triggers corresponding risk control measures, such as temporarily blocking IPs or requiring additional verification. For example, if the API gateway receives an authorization decision model output of 0.65, which is below the 0.75 threshold, it determines that access is denied. The API gateway can also generate a standard format response and return it via an HTTP 403 status code. Simultaneously, it logs the request; for requests that pass the access test, such as a trust score of 0.85, the API gateway requests a token from the authentication service. The authentication service generates a JWT format token containing an expiration timestamp of 1632553800 and the permission scope "read:profile,write:data". The API gateway receives the token via a TLS 1.3 encrypted channel and verifies its signature and validity period. Upon successful verification, the token is added to the request header. Service discovery returns the addresses of three instance locations for the target service. The API gateway uses a weighted round-robin algorithm to select instance 2 (weight 0.4) and forwards the request to https: / / service2.example.com / api / v1 / resource via HTTPS. The log collection service receives JSON-formatted logs. The risk control platform analyzes the data and finds that the request frequency from IP 192.168.1.100 within the last 5 minutes is 30 requests / minute, exceeding the preset threshold of 20 requests / minute. This triggers the risk control rule, sending a temporary rate-limiting instruction to the API gateway, limiting the request rate from that IP to 10 requests / minute for 30 minutes.
[0034] In this embodiment of the disclosure, step 102, which scores the multi-dimensional trust data based on trust assessment rules to obtain a trust score, includes: Retrieve trust assessment rules from the trust assessment rule base that match the user operation type of the data access request; The multi-dimensional trust data is scored based on the trust assessment rules to obtain multi-dimensional scoring results. The multi-dimensional scoring results are then weighted based on a dynamic weighted threshold to obtain a trust score.
[0035] To achieve integrated control between the gateway and the server, the gateway, acting as the current execution end, first retrieves a trust assessment rule from the trust assessment rule base that matches the user operation type of the data access request when scoring multi-dimensional trust data. The trust assessment rule base stores at least one trust assessment rule corresponding to different user operation types. Since trust assessment rules are used to characterize the scoring of multi-dimensional trust data, they can be configured according to different user operation types. Furthermore, different dynamic weighting thresholds can be matched to different user operation types. User operation types include, but are not limited to, data loading and data browsing. Therefore, as the gateway, the current execution end pre-configures trust assessment rules matching different user operation types and stores them in the trust assessment rule base. This embodiment does not impose specific limitations. Then, the multi-dimensional trust data is scored based on the trust assessment rules to obtain multi-dimensional scoring results. These results are then weighted using dynamic weighting thresholds to obtain a trust score. Different user operation types match different dynamic weighting thresholds, which can be adjusted using an adaptive weighting algorithm to improve the calculation effectiveness of the trust score.
[0036] In some embodiments, after querying the trust assessment rules that match the user operation type of the current request for a dynamically weighted threshold, the user operation type can be further distinguished between sensitive operations and ordinary operations. Sensitive operations require stricter authentication and lower behavioral anomaly thresholds. Therefore, for the extracted multidimensional trust data (such as source IP address, authentication token, access timestamp), scores for identity trustworthiness, device trustworthiness, and behavioral anomaly are calculated respectively. Then, an adaptive weight adjustment algorithm based on request type and historical trust is used to dynamically calculate the weight coefficients of each sub-item score, that is, to combine the sub-item scores into a vector form of the final trust score. The score vector is then normalized to obtain a multidimensional trust score vector (i.e., trust score) representing the trustworthiness of the request. Simultaneously, the isolated forest algorithm can be used to detect anomalies in the operation sequence; if anomalies are detected, the trust score of the corresponding dimension is reduced.
[0037] For example, when processing a request from IP address 192.168.1.100, the authentication token "BearereyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9" is extracted from the data access request header using the regular expression "^Bearer\s[\w-.]+$". The device ID "D123456" is verified using the pattern "^D\d{6}$". The user operation type "fund_transfer" and the target resource " / api / accounts / 12345" are extracted from the data access request body using a JSON parser. At this point, the device's geographical location information is missing, which can be filled in using the user's historical average "39.9042°N, 116.4074°E". Furthermore, 200 user operation records from the past 24 hours were retrieved from the behavior log database, and the average request frequency was calculated to be 8 times / hour. The common operation sequence was "login-check balance-transfer", and resource access was concentrated in " / api / accounts / *". The autoregressive ensemble moving average model predicted the request frequency for the next hour to be 10±2 times, and the current frequency of 9 times / hour is within the normal range. In the trust assessment rule base, "fund_transfer" is a sensitive operation, requiring two-factor authentication and a behavior anomaly threshold of 0.1. The calculated identity trustworthiness was 0.9 (token valid), device trustworthiness was 0.8 (common device), and behavior anomaly was 0.05 (normal frequency, sequence matching). The adaptive weighting algorithm dynamically adjusted the weighting threshold to [0.4, 0.3, 0.3] based on the operation sensitivity and the user's historical trustworthiness of 0.95, and combined them to obtain the trust score vector [0.36, 0.24, 0.285], which was normalized to [0.407, 0.271, 0.322]. The Isolation Forest algorithm detected anomalies in the last 100 operations, with an anomaly score of 0.03, which is below the anomaly threshold of 0.05. Therefore, the original trust score was maintained and the request was sent to the server. Finally, the server determined that the request was highly trustworthy and allowed the transfer operation to proceed.
[0038] In this embodiment of the disclosure, step 101, extracting the multi-dimensional trust data from the data access request, includes: Extract authentication information, device identifier, address information, and time information from the request header of the data access request, and extract user operation type and behavior pattern from the request body of the data access request; The identity authentication information, the device identifier, the address information, and the time information are cleaned, and the importance features are extracted from the cleaned information to obtain multi-dimensional trust data.
[0039] To extract effective multi-dimensional trust data and improve the accuracy of trust score calculation, the current gateway first extracts authentication information, device identifier, address information, and time information from the request header of the data access request. Simultaneously, it extracts user operation type and behavior pattern from the request body. The behavior pattern characterizes whether user behavior is normal. For example, if the average online time of a user's last three requests is x, it falls under a normal behavior pattern. In this case, the behavior pattern judgment can be based on the user's historical behavior statistics. For instance, a sequence pattern mining algorithm can be used to analyze the user's historical operation sequences, extract typical behavior pattern features, and obtain a user behavior pattern library. This embodiment does not impose specific limitations. Furthermore, the extracted authentication information, device identifier, address information, and time information are cleaned, and importance features are extracted from the cleaned information to obtain multi-dimensional trust data. Data cleaning may include data format standardization and deduplication. Importance feature extraction can employ feature engineering techniques on the cleaned information to obtain the derived multi-dimensional trust data used for trust scoring.
[0040] In some embodiments, feature engineering is performed on the cleaned information. A feature importance evaluation method based on decision trees is used to filter features, retaining the top 80% of features by importance score to obtain a representative feature vector. For example, when processing a request from IP address 192.168.1.100, the user ID "user123", device identifier "device456", geographic coordinates "39.9042,116.4074", and timestamp "2024-09-24 15:30:00" are extracted from the header of the data access request. The validity of the user ID is verified using the regular expression "^[a-zA-Z0-9]{6,}$", the device identifier is hashed using MD5, the geographic coordinates are converted to the standard format "latitude, longitude", and the timestamp is unified to UTC format. If the device online duration data is missing, the nearest neighbor interpolation method is used to fill the missing data with the average online duration of the user's three most recent requests, which is 7200 seconds. During the feature engineering phase, after calculating that the user's request frequency in the past 24 hours was 10 times / hour, the device's online time was 7200 seconds, and the geographical location changed at a rate of 5 km / h in the past hour, a feature importance evaluation method based on decision trees was used, with scores of 0.4, 0.3, and 0.2, all higher than the threshold of 0.1, so all were retained. Finally, combined with a dynamic weight adjustment mechanism based on the current time 15:30 being within the working hours, the dynamic weighted thresholds used were 40% for identity authentication strength, 30% for device trustworthiness, and 30% for abnormal behavior patterns, resulting in a normalized trust score vector of [0.8, 0.7, 0.9].
[0041] In this embodiment of the disclosure, the steps further include: Obtain the user behavior pattern library; Upon receiving user operation behavior feedback from the server, a trust classification is performed based on the similarity between the historical operation behavior and the user operation behavior, and the trust score, to obtain a trust classification result. The dynamic weighted threshold is adjusted based on the trust classification result; or, The dynamic weighted threshold is adjusted based on the request type and request time of the data access request.
[0042] To dynamically adjust the weighted threshold and improve the accuracy and effectiveness of trust scoring, the gateway first acquires a user behavior pattern library containing historical user actions. Since behavior patterns characterize whether user behavior is normal, the behavior model of a user after authorized access can be determined based on the user's actions reported by the server. Then, trust classification is performed based on the similarity between the historical actions and the current user actions, and the trust score, yielding a trust classification result. During trust classification, algorithms such as Support Vector Machines can be used to determine the level of trust at the gateway, such as medium or high trust, and adjust the dynamic weighted threshold accordingly.
[0043] For example, by analyzing 100 historical user operation behavior sequences using a sequence pattern mining algorithm, the typical pattern "login-query-place order" is extracted. The similarity between this pattern and the current user operation behavior sequence "login-query-modify" is calculated to be 0.67. Then, based on the support vector machine algorithm, the trust score vector and the behavior pattern similarity are classified, and the trust classification result of the data access request is "medium trust". The user behavior pattern library is updated, and the new operation sequence "login-query-modify" and its frequency of occurrence are recorded. At this time, the dynamic weighted threshold can be directly adjusted based on the trust classification result, such as increasing or decreasing. Alternatively, the dynamic weighted threshold can be adjusted based on the request type and request time of the data access request, such as increasing or decreasing. The value of increasing or decreasing can be configured based on different business scenarios, and this embodiment does not impose specific limitations.
[0044] In this embodiment of the disclosure, step 103, which compares the received decision probability with a preset dynamic threshold range and controls the data access request based on the comparison result, includes: If the decision probability is within the first preset evaluation range, it is determined to be unauthorized permission, and an access denial response is output for the data access request; If the decision probability matches the second preset evaluation range, it is determined to be a suspicious permission, and a verification request instruction is sent to perform secondary security verification. If the decision probability matches the third preset evaluation range, then the authorization is determined, and the data access request is sent to the target application service.
[0045] To achieve joint control over data access between the gateway and the server, the gateway pre-sets a dynamic threshold range. This dynamic threshold range may include a first preset evaluation range, a second preset evaluation range, and a third preset evaluation range to classify permissions. For example, the first preset evaluation range is 0-0.4, the second preset evaluation range is 0.4-0.8, and the third preset evaluation range is 0.8-1. This embodiment does not impose specific limitations. Specifically, if the decision probability falls within the first preset evaluation range, it is determined to be unauthorized permission, and the gateway outputs a denied access response to the client. If the decision probability matches the second preset evaluation range, it is determined to be suspicious permission, and the gateway can send a verification request command for secondary security verification. If the decision probability matches the third preset evaluation range, it is determined to be authorized permission, and the gateway sends the data access request to the target application service. Figure 2 As shown.
[0046] In some embodiments, if the decision probability obtained based on the trust score falls within the suspicious range, the gateway can also select other verification methods from the security measure library, such as manual verification, based on the trust score, request type, and resource sensitivity, to generate response information containing additional verification methods and return it to the client. In this case, the response information includes the verification type, verification token, and verification interface URL. The verification token is in JWT format and includes a timestamp and a random nonce value. The gateway receives the verification information obtained by the client based on the verification interface URL. The verification information includes the verification result and the original request information. The verification information is encrypted using TLS 1.3 and uses HMAC for message integrity verification. Based on the verification type, the corresponding verification logic is invoked. If the verification passes, the trust score is recalculated, and the verification result is sent to the gateway as a new feature for decision-making, resulting in an updated decision probability. If the updated trust score exceeds the admission threshold, the original authorization process continues.
[0047] For example, after receiving the output of the authorization decision model, the API gateway compares the results with a preset dynamic threshold range to determine suspicious permissions. If a permission is deemed suspicious, it selects an appropriate additional verification method from the security measure library, such as SMS verification code, email verification link, or image CAPTCHA, based on factors such as score, request type, and resource sensitivity. The API gateway generates a response containing the selected verification method and returns it to the client via HTTP status code 303 (See Other). The response body includes the verification type, verification token, and verification interface URL. Simultaneously, a verification session timer is started, setting the verification timeout to 300 seconds. The verification token uses JWT format and includes a timestamp and a random nonce value to prevent replay attacks. The client obtains the verification information from the URL in the response, completes the verification steps, and submits the verification result along with the original request information to the verification interface. All transmitted data is encrypted using TLS 1.3 and message integrity is verified using HMAC. The API gateway receives the verification data and calls the corresponding verification logic based on the verification type, such as verifying the correctness of the SMS verification code, checking the validity of the email verification link, or recognizing the image CAPTCHA. If verification passes, the API gateway recalculates the trust score and sends the verification result as a new feature to the server to obtain an updated decision probability. If the updated score exceeds the access threshold, the original authorization process continues; if it remains in the suspicious range, a higher level of verification is required. If verification fails or times out, the access request is directly rejected. Three consecutive verification failures will trigger a temporary blocking mechanism, with the blocking duration increasing with the number of failures. At this time, performance metrics and abnormal patterns of the entire verification process can be recorded in real time through a time-series database. When the verification time exceeds a preset threshold or an abnormal pattern occurs, an alarm is triggered and the verification strategy is automatically adjusted. For example, the API gateway receives a decision probability of 0.65, and the server falls into the dynamically calculated suspicious range [0.6, 0.75]. This range is calculated based on 99.9% of the request distribution over the past 24 hours and the current CPU utilization of 85%. The decision tree model selects SMS verification as an additional verification method, considering that the request involves sensitive financial operations. The API gateway generates an HTTP 303 response. The body contains {"verification_type":"sms","token":"eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...","url":"https: / / api.example.com / verify / sms"}. The JWT token contains exp:1632468300, nonce:"a1b2c3". The client obtains the verification code and submits it: {"code":"123456","token":"eyJhbGci..."}, encrypted using TLS 1.3 and signed with HMAC-SHA256 to ensure integrity.The API gateway verifies the SMS code's correctness and recalculates the trust score: The random forest model takes [original features, verification passed: 1] as input and outputs a new score of 0.78. Since the score exceeds the 0.75 threshold, the authorization process continues. The entire verification process takes 280ms, below the 300ms threshold, and is recorded in InfluxDB: {time:1632468000,request_id:"req123",verification_type:"sms",duration:280,score_before:0.65,score_after:0.78}. If consecutive failures occur, such as IP192.168.1.100 failing verification three times, the exponential backoff algorithm is triggered: a 5-minute ban for the first time, 15 minutes for the second, and 45 minutes for the third. An anomaly detection algorithm detects a sudden increase in verification time to 500ms, triggering a Prometheus alert and automatically adjusting the verification timeout from 300 seconds to 450 seconds.
[0048] This disclosure provides a data access control method. Upon responding to a data access request, a gateway extracts multi-dimensional trust data from the request and scores it based on trust evaluation rules to obtain a trust score. The trust score, along with the request content, is then sent to a target server. The target server determines a decision probability based on an authorization decision model trained on historical authorization samples. When the gateway receives the decision probability, it compares it with a preset dynamic threshold range and controls the data access request based on the comparison result. This achieves flexible and accurate distributed authorization decision-making for data access request security, solving the problem of poor accuracy in fine-grained permission control under microservice architectures, thereby significantly improving the effectiveness of data access request control.
[0049] Figure 3 This is a schematic diagram illustrating another data access control process provided in an embodiment of this disclosure.
[0050] like Figure 3 As shown, when applied to the server side, this method includes the following steps: Step 201: Obtain the request content and trust score of the data access request sent by the gateway.
[0051] In this embodiment, the current execution end, acting as the second execution entity for data security management in the microservice architecture, is a server, such as an application server. It receives the data access request content and trust score from the gateway and makes decisions regarding whether it has the right to request data. The data access request is triggered by the client for the required application service. This request may carry authentication information (such as user credentials), device identifiers (such as device ID), address information (such as IP address), and time information (such as timestamp) to extract multi-dimensional trust data. This multi-dimensional trust data characterizes data that can be used for security trust judgment, including but not limited to user behavior characteristics and access frequency; this embodiment does not specifically limit these characteristics.
[0052] It should be noted that the trust score is obtained by the gateway based on the multi-dimensional trust data of the data access request. Since the multi-dimensional trust data is multi-dimensional, a multi-dimensional trust score vector can be obtained when scoring, which can be used as the input of the authorization decision model.
[0053] Step 202: Based on the authorization decision model, perform decision processing on the request content, the trust score, and historical access data to obtain the decision probability.
[0054] In this embodiment, the current execution terminal invokes a pre-trained authorization decision model to process the request content, the trust score, and historical access data to obtain a decision probability. The authorization decision model is trained based on historical authorization samples, which may include, but are not limited to, historical access counts and authorization results, for training the authorization decision model. Preferably, the authorization decision model is a random forest tree model; however, this embodiment does not impose specific limitations. Furthermore, the input to the authorization decision model is a probability value to represent the likelihood of authorization trust.
[0055] Step 203: Feed back the decision probability to the gateway.
[0056] In this embodiment of the disclosure, after obtaining the decision probability, the current execution end feeds the decision probability back to the gateway end so that the gateway end can compare it with the preset dynamic threshold range to determine the access permissions of authorized permissions, unauthorized permissions or suspicious permissions, thereby enabling the gateway end to control whether the request is approved.
[0057] It should be noted that the gateway's preset dynamic threshold range can be pre-set with three default value ranges to distinguish between authorized permissions, unauthorized permissions, or suspicious permissions. At the same time, it can also be adjusted in real time based on the results of data access to improve the accuracy of data access control.
[0058] In this embodiment of the disclosure, before step 202, which involves processing the request content, the trust score, and historical access data based on an authorization decision model to obtain the decision probability, the method further includes: An authorization decision model is constructed based on the random forest algorithm, and historical authorization samples are obtained to represent the current historical authorization situation. The authorization decision model is trained using the historical authorization samples, and the model parameters in the authorization decision model are optimized using grid search to obtain the completed authorization decision model.
[0059] To further assess the trust score calculated at the gateway on the server side, the current server pre-constructs an authorization decision model based on the random forest algorithm and obtains historical authorization samples to represent the current server's historical authorization status. These historical authorization samples are then used to train the authorization decision model. Here, the current server's historical authorization status represents the server's historical decisions on whether to authorize data access requests based on resource conditions. Different servers manage data access requests differently due to their varying resource characteristics. For example, historical authorization decision records are retrieved from the microservice log database and categorized according to their resource types to obtain categorized authorization decision data. This categorized authorization decision data can then be cleaned to remove outliers and duplicates. A stratified random sampling method can be used to select a training sample set, resulting in a cleaned training sample set, which serves as the historical authorization sample. Furthermore, when performing feature engineering on the cleaned training sample set, the feature engineering process includes one-hot encoding of categorical features and normalization of numerical features, resulting in a processed feature dataset. This embodiment does not impose specific limitations on this process.
[0060] It should be noted that during model training, the server can optimize the model parameters of the authorization decision model using grid search to obtain a completed authorization decision model. At this point, the model parameters include the number of decision trees (e.g., the number of trees), the maximum tree depth (e.g., the number of layers), and feature selection criteria (e.g., the number of features or the number of feature categories). Incremental training of the authorization decision model includes: incorporating new authorization decision samples as historical authorization samples, updating feature weights and decision rules to obtain an updated authorization decision model. If the accuracy of the updated authorization decision model is lower than a preset threshold or the trust score is lower than a preset score, a model retraining process is triggered.
[0061] In some embodiments, historical authorization decision records can be extracted from the microservice log database on the server side. The data is categorized according to resource type (e.g., sensitive data, public interfaces, internal services), including request trust characteristics (e.g., user identity, device information, access time) and business-related characteristics (e.g., operation type, resource sensitivity). Outliers and duplicates are removed through data cleaning. A stratified random sampling method is used to select a representative training sample set based on resource type and authorization result ratio, which serves as the historical authorization sample. When performing feature engineering on the selected sample set, a correlation-based feature selection method can be used to calculate the correlation coefficient between features and authorization results, selecting a subset of features with an absolute correlation coefficient greater than 0.3. Furthermore, when optimizing model parameters using the grid search method, hierarchical 5-fold cross-validation can be used to evaluate model performance. For imbalanced classes, synthetic minority oversampling (SMOTE) can be used to balance the sample distribution. For example, a sliding window technique can be used to incrementally train the model every 24 hours, incorporating new authorization decision samples, updating feature weights and decision rules, and improving the model's adaptability to new authorization scenarios. At the same time, model performance monitoring metrics can be set. When the accuracy is below 95% or the F1 score is below 0.9, the model retraining process can be triggered, and the local anomaly factor algorithm can be used to detect new abnormal authorization patterns. The detected abnormal samples can be added to the training set to adapt to the new authorization scenarios.
[0062] For example, in a microservice authorization decision system, 1 million authorization records from the past 30 days were extracted from the log database. These records included 40% sensitive data access, 35% public interface calls, and 25% internal service requests. After data cleaning, 500,000 samples were selected using stratified random sampling to maintain the original proportions. During feature engineering, 10 categorical features, such as "user role," were one-hot encoded and expanded into 50 binary features; 5 numerical features, such as "access frequency," underwent min-max normalization. Using Pearson correlation coefficient calculations, 35 features with an absolute correlation coefficient greater than 0.3 with the authorization results were selected. The constructed random forest model was trained using 300 decision trees with a maximum depth of 15, and the feature selection criterion was the Gini coefficient. Furthermore, for cases where the rejection rate in the sensitive data access category was only 5%, the SMOTE algorithm was used to generate 7,500 synthetic samples, increasing the rejection rate to 15%. The random forest model achieved an average accuracy of 97.2% and an F1 score of 0.943 in 5-fold cross-validation. The server currently uses approximately 230,000 newly added samples from the last 7 days for incremental training every 24 hours, updating feature weights accordingly. In the most recent update, the "device fingerprint" feature weight increased from 0.08 to 0.12, reflecting its increased importance. Random forest model performance monitoring shows that the lowest accuracy in the past 30 days was 96.1%, and the lowest F1 score was 0.935, neither of which triggered the retraining threshold. The Local Anomaly Factor algorithm detected 200 new authorization patterns with an anomaly rate of 0.01, 80% of which came from access requests from newly launched IoT devices. These samples were labeled and added to the next round of training to adapt to the new authorization scenarios.
[0063] In this embodiment of the disclosure, before step 202, which involves processing the request content, the trust score, and historical access data based on an authorization decision model to obtain the decision probability, the method further includes: The system retrieves a pre-defined rule engine and determines whether there are any hard violations in the request content based on the pre-defined rule engine. If there is no hard violation, the weighted average of the trust score is determined, and if the weighted average is less than a preset evaluation threshold, the authorization decision model that has completed model training is retrieved.
[0064] To meet the need for flexible control over data access requests and thus improve the accuracy of data access request control, the current server can manage hard rules by configuring a rule engine. In this case, the preset rule engine is configured with multiple hard violations, including at least one of access blacklists and access to sensitive content, so as to invoke the preset rule engine and determine whether hard violations exist in the request content. In some embodiments, the preset rule engine, Drools rule engine, performs initial filtering. The Drools rule engine determines whether the request violates the preset hard rules. If no hard violations exist, a weighted average trust score can be determined based on the trust score vector (i.e., vector weighting calculation). When the weighted average is less than a preset evaluation threshold, the trained authorization decision model is invoked. Here, the first preset evaluation range is used to characterize the numerical conditions that trigger the authorization decision model to make a trust score decision. This range can be configured based on different application services, and this embodiment does not impose specific limitations.
[0065] It should be noted that when the weighted average value is greater than the preset evaluation threshold, access can be directly determined as allowed and feedback can be sent to the gateway.
[0066] In some embodiments, the current server can use a weighted round-robin algorithm at the gateway to select the target service. It encapsulates the trust score vector and request content into a JSON message and sends it to a message queue. Upon receiving the JSON message, the message queue routes it based on the target service identifier. Then, the Drools rule engine is invoked for initial filtering. The Drools rule engine determines whether the request violates predefined hard rules. If no hard violations are found, a weighted average of the trust score vector is calculated. If the weighted average is lower than a predefined threshold, a deeper evaluation is triggered, using a random forest algorithm. The algorithm outputs a trust probability value, which is then used to determine if it matches different dynamic threshold ranges. For example, if the probability is greater, access is allowed; if less, access is denied. The evaluation result is fed back to the API gateway via the message queue. The API gateway executes access control based on the evaluation result. New authorization decision samples are obtained, consisting of the evaluation result and related information, and used to update the training set of the random forest model.
[0067] For example, after calculating the trust score, the API gateway obtains a list of target microservice instances through the service discovery mechanism, selects a specific server using a weighted round-robin algorithm, and encapsulates the data access request content and trust score vector into a JSON message containing fields such as request ID, timestamp, target resource, operation type, and trust score. This message is then sent to the server corresponding to the selected microservice instance via a message queue. Upon receiving the message, the message queue routes it based on the target microservice identifier in the message, ensuring the message is correctly delivered to the specified microservice instance's server. The target microservice's server consumes the message from the message queue, parses the request content and trust score vector, and first calls the built-in Drools rule engine. This engine filters obviously violating requests based on preset hard rules, such as access from blacklisted IPs or during sensitive time periods. The rule engine's output includes whether a violation occurred and the reason for the violation. Once no hard violations are found, the authorization decision module receives the output from the pre-built rule engine and calculates a weighted average of the trust scores for data access requests not rejected by hard rules. The weights can be dynamically adjusted based on resource sensitivity. If the weighted average is greater than a preset threshold (e.g., greater than 0.8), access is directly granted. If it is less than 0.8, a deeper evaluation process is triggered. This deeper evaluation phase uses an authorization decision model trained using a random forest algorithm. The authorization decision model is trained on historical authorization data. Input features include trust score vectors, request context information, user historical behavior statistics, and current system load. The output is a trust probability value between 0 and 1. When this value falls within the dynamically calculated threshold range, access is granted; otherwise, access is denied. Finally, the decision result is fed back to the API gateway via a message queue for access control. New authorization decision samples can also be added to the training set, and the system automatically retrains the random forest model every 24 hours to continuously optimize the accuracy of authorization decisions.
[0068] For example, the API gateway receives an access request from IP 192.168.1.100, parses out a trust score vector [0.85, 0.92, 0.78], representing identity trustworthiness, device trustworthiness, and behavior normality, respectively. The service discovery mechanism returns three instances of the target microservice "User Profile Service," selecting instance 2 through a weighted round-robin algorithm. The request is encapsulated as a JSON message and sent to the "user-profile-service" topic in the RabbitMQ message queue. The message queue routes the message to instance 2, where the microservice receives and parses the message. The Drools rule engine executes 10 preset rules, such as "IF accessTimeNOTBETWEEN08:00AND22:00THENDENY," and this request passes all hard rules. The authorization decision module calculates the weighted average trust score: 0.85 * 0.4 + 0.92 * 0.3 + 0.78 * 0.3 = 0.851, which falls within the preset threshold range of 0.8-1, and is therefore deemed acceptable for access. If the score is less than the preset threshold of 0.8, the random forest model (containing 100 decision trees with a maximum depth of 15) will conduct an in-depth evaluation. The input features include 20 features such as trust score, access time at 15:30, and average access frequency over the past 7 days (3.5 times per day). The output decision probability is 0.89.
[0069] In this embodiment of the disclosure, the steps further include: When the target application service executes the data access request, the user's operation behavior is recorded and fed back to the gateway so that the gateway can recalculate the trust score. The historical authorization samples are updated based on the user's actions and the recalculated trust score, so as to retrain the authorization decision model.
[0070] To improve the accuracy of the authorization decision model, after a data access request is authorized, when the current execution end performs the access behavior of the data access request on the target application service, it first records the user's operation behavior and feeds it back to the gateway. The gateway then recalculates the trust score based on the updated user operation behavior and receives the feedback trust score. Subsequently, based on the user operation behavior and the recalculated trust score, the historical authorization samples are updated to retrain the authorization decision model.
[0071] In some embodiments of the control system, an authentication service may also be included. This service can be embedded in the server or a standalone server. The server generates authorization log information, which includes fields such as request time, resource type, trust score, and authorization result. Based on the authorization log information, the authorization logs are cleaned and structured in real time to obtain structured authorization data. Furthermore, after collecting authorization log information through a distributed log collection tool, the authentication service applies a statistical anomaly detection method combined with a long short-term memory network to the structured authorization data to identify authorization behaviors significantly different from historical patterns, thus obtaining abnormal authorization behavior data. Simultaneously, the gateway can automatically generate and optimize new trust assessment rules using a genetic algorithm based on the acquired abnormal authorization behavior data. The evaluation criteria for the trust assessment rules include rule coverage, accuracy, and complexity. If the new trust assessment rules pass the rule engine's verification and conflict detection, an online learning algorithm is used to continuously optimize the authorization decision model in the server. The online learning algorithm triggers incremental training and updates the parameters of the authorization decision model when it receives a preset number of new samples.
[0072] For example, the authentication service collects authorization logs in real time from various microservice applications using a distributed log collection tool. It uses a unified log format standard and version control mechanism to handle log differences between microservices, including fields such as request time, resource type, trust score, and authorization result. The collected raw logs are stored in a distributed file system, and Apache Flink is used for real-time cleaning and structuring. The processed structured data is then processed using a statistical anomaly detection method combined with Long Short-Term Memory (LSTM) networks to identify authorization behaviors significantly different from historical patterns. Simultaneously, association rule mining algorithms are used to analyze the correlations between anomalous authorization events, discovering potential new threat patterns. The gateway can then automatically generate and optimize new trust assessment rules based on the discovered new threat patterns using a genetic algorithm. Evaluation criteria include rule coverage, accuracy, and complexity. The generated rules are submitted to the rule engine for verification and conflict detection. Semantic analysis and decision tree comparison are used to detect conflicts between rules. Approved new rules undergo A / B testing and incremental deployment, gradually updating the rule cache of each microservice. In addition, the server can continuously optimize the authorization decision model using online learning algorithms. Incremental training is triggered every time a certain number of new samples are received, updating model parameters. Model performance is evaluated through cross-validation, and a rollback trigger threshold is set. Automatic rollback occurs when model performance degrades beyond a preset value. When the gateway uses an adaptive weight adjustment algorithm to dynamically update the trust score, the weights of each factor can be adjusted based on real-time threat intelligence. Simultaneously, a service mesh can be deployed to monitor microservice topology changes, automatically detecting newly added or changed service nodes and adjusting authorization policies to adapt to architectural evolution. The authentication service uses a Filebeat collector to collect logs from 50 microservice nodes in a unified JSON format, with fields including {timestamp, service_id, resource_type, trust_score, auth_result}, and the version number v1.2 stored in the log header. Logs are written to a Kafka cluster at a rate of 1000 records per second. Apache Flink processes the data stream with a 5-second sliding window, and the cleaned structured data is stored in ClickHouse. The anomaly detection module uses the Z-score method to identify outliers in trust scores, with a threshold of 3. Simultaneously, an LSTM network (64 hidden units, 2 layers) predicts normal authorization patterns; deviations exceeding 20% are considered anomalies. The FP-Growth algorithm mines association rules, with a minimum support of 0.01 and a confidence level of 0.8, discovering new threat patterns such as "frequent password resets + abnormal IP access." A genetic algorithm generates rules with a population size of 100 and 500 iterations, using a fitness function f = 0.6 coverage + 0.3 accuracy - 0.1 complexity. The server-side rule engine, Drools, validates new rules, detecting conflicts through decision tree comparisons, with a conflict threshold of 0.85.The new rules involve A / B testing on 10% of the traffic, increasing by 5% per hour until reaching 100%. Simultaneously, the online learning algorithm triggers incremental training every 1000 new samples, and a rollback is triggered if the cross-validation F1 score falls below 0.95. In the gateway, an adaptive weight adjustment algorithm updates the trust matrix hourly, adjusting weights based on the threat intelligence API, such as increasing the network factor weight from 0.3 to 0.4. When the Istio service mesh detects a new order service node, it automatically generates a default authorization policy, limiting requests per second to 100, and then optimizes the policy based on actual traffic characteristics after a 24-hour observation period.
[0073] Another data access control method provided in this disclosure involves a gateway responding to a data access request, extracting multi-dimensional trust data from the request, and scoring the multi-dimensional trust data based on trust evaluation rules to obtain a trust score. The trust score, along with the request content from the data access request, is then sent to a target server. The target server then determines a decision probability based on an authorization decision model, which is trained using historical authorization samples. When the gateway receives the decision probability, it compares it with a preset dynamic threshold range and controls the data access request based on the comparison result. This achieves flexible and accurate distributed authorization decision-making for data access request security, solving the problem of poor accuracy in fine-grained permission control under a microservice architecture, thereby significantly improving the effectiveness of data access request control.
[0074] Corresponding to the data access control method described above, the present invention also proposes a data access control device. Since the device embodiments of the present invention correspond to the method embodiments described above, details not disclosed in the device embodiments can be referred to in the method embodiments described above, and will not be repeated here.
[0075] Figure 4 A schematic diagram of a data access control device provided in this disclosure embodiment includes: Extraction module 31 is used to extract multi-dimensional trust data from the data access request in response to the data access request; The scoring module 32 is used to score the multi-dimensional trust data based on trust evaluation rules to obtain a trust score, and send the trust score and the request content in the data access request to the target server so that the target server can determine the decision probability based on the authorization decision model, wherein the authorization decision model is obtained by model training based on historical authorization samples. The control module 33 is used to compare the received decision probability with a preset dynamic threshold range, and control the data access request based on the comparison result.
[0076] Furthermore, The scoring module is specifically used to retrieve trust assessment rules that match the user operation type of the data access request from the trust assessment rule base. The trust assessment rule base stores at least one trust assessment rule corresponding to different user operation types. The module scores the multi-dimensional trust data based on the trust assessment rules to obtain multi-dimensional scoring results, and performs a weighted calculation on the multi-dimensional scoring results based on a dynamic weighted threshold to obtain a trust score. Different user operation types are matched with different dynamic weighted thresholds.
[0077] Furthermore, The extraction module is specifically used to extract authentication information, device identifier, address information, and time information from the request header of the data access request, and to extract user operation type and behavior pattern from the request body of the data access request; to perform data cleaning on the authentication information, device identifier, address information, and time information, and to extract importance features from the cleaned information to obtain multi-dimensional trust data.
[0078] Furthermore, the device also includes: The acquisition module is used to acquire a user behavior pattern library, which stores the historical operation behaviors of historical users. The classification module is used to perform trust classification based on the similarity between the historical operation behavior and the user operation behavior and the trust score after receiving the user operation behavior feedback from the server, and obtain the trust classification result. An adjustment module is used to adjust the dynamic weighted threshold based on the trust classification result; or, to adjust the dynamic weighted threshold based on the request type and request time of the data access request.
[0079] Furthermore, The control module is specifically configured to: if the decision probability is within a first preset evaluation range, determine it as unauthorized permission and output a denial response for the data access request; if the decision probability matches a second preset evaluation range, determine it as suspicious permission and send a verification request command for secondary security verification; if the decision probability matches a third preset evaluation range, determine it as authorized permission and send the data access request to the target application service.
[0080] This disclosure provides a data access control device that, upon responding to a data access request, extracts multi-dimensional trust data from the request and scores the data based on trust evaluation rules to obtain a trust score. The trust score, along with the request content, is then sent to a target server. The target server determines a decision probability based on an authorization decision model trained on historical authorization samples. When the gateway receives the decision probability, it compares it with a preset dynamic threshold range and controls the data access request based on the comparison result. This achieves flexible and accurate distributed authorization decision-making for data access request security, solving the problem of poor accuracy in fine-grained permission control under microservice architectures, thereby significantly improving the effectiveness of data access request control.
[0081] Figure 5 A schematic diagram of another data access control device provided in an embodiment of this disclosure includes: The acquisition module 41 is used to acquire the request content and trust score of the data access request sent by the gateway. The trust score is obtained by scoring based on the multi-dimensional trust data of the data access request. Decision module 42 is used to perform decision processing on the request content, the trust score, and historical access data based on the authorization decision model to obtain the decision probability. The authorization decision model is obtained by training the model based on historical authorization samples. Feedback module 43 is used to feed back the decision probability to the gateway.
[0082] Furthermore, the device also includes: The module is used to build an authorization decision model based on the random forest algorithm and obtain historical authorization samples to represent the current historical authorization situation. The training module is used to train the authorization decision model using the historical authorization samples, and after optimizing the model parameters in the authorization decision model through grid search, obtain the authorization decision model that has completed model training. The model parameters include the number of decision trees, the maximum tree depth, and the feature selection criteria.
[0083] Furthermore, the device also includes: The retrieval module is used to retrieve a preset rule engine and determine whether there is any hard violation content in the request content based on the preset rule engine. The preset rule engine is configured with multiple hard violation content, including at least one of access blacklist and access sensitive content. If there is no hard violation content, the weighted average of the trust score is determined, and if the weighted average is less than a preset evaluation threshold, the authorization decision model that has completed model training is retrieved.
[0084] Furthermore, the device also includes: The recording module is used to record user operation behavior when the target application service executes the data access request, and feed it back to the gateway so that the gateway can recalculate the trust score. An update module is used to update the historical authorization samples based on the user's operation behavior and the recalculated trust score, so as to retrain the authorization decision model.
[0085] Another data access control device provided in this disclosure, after responding to a data access request at the gateway end, extracts multi-dimensional trust data from the data access request, scores the multi-dimensional trust data based on trust evaluation rules to obtain a trust score, and sends the trust score and the request content in the data access request to the target server end, so that the target server end determines the decision probability based on an authorization decision model, which is obtained by model training based on historical authorization samples; when the gateway end receives the decision probability, it compares it with a preset dynamic threshold range, and controls the data access request based on the comparison result, realizing flexible and accurate distributed authorization decision-making for data access request security, solving the problem of poor accuracy of fine-grained permission control under microservice architecture, thereby greatly improving the effectiveness of data access request control.
[0086] It should be noted that the foregoing explanation of the method embodiments also applies to the apparatus of the embodiments of this disclosure, and the principle is the same. Therefore, the embodiments of this disclosure are not limited thereto.
[0087] According to embodiments of this disclosure, this disclosure also provides a gateway device, a readable storage medium, and a computer program product.
[0088] Figure 6 A schematic block diagram of an example electronic device 500 that can be used to implement embodiments of the present disclosure is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present disclosure described and / or claimed herein.
[0089] like Figure 5As shown, the electronic device 500 includes a computing unit 501, which can perform various appropriate actions and processes based on a computer program stored in ROM (Read-Only Memory) 502 or a computer program loaded from storage unit 508 into RAM (Random Access Memory) 503. The RAM 503 can also store various programs and data required for the operation of the electronic device 500. The computing unit 501, ROM 502, and RAM 503 are interconnected via a bus 504. An I / O (Input / Output) interface 505 is also connected to the bus 504.
[0090] Multiple components in electronic device 500 are connected to I / O interface 505, including: input unit 505, such as keyboard, mouse, etc.; output unit 507, such as various types of monitors, speakers, etc.; storage unit 508, such as disk, optical disk, etc.; and communication unit 509, such as network card, modem, wireless transceiver, etc. Communication unit 509 allows electronic device 500 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0091] The computing unit 501 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 501 include, but are not limited to, CPUs (Central Processing Units), GPUs (Graphics Processing Units), various special-purpose AI (Artificial Intelligence) computing chips, various computing units running machine learning model algorithms, DSPs (Digital Signal Processors), and any suitable processor, controller, microcontroller, etc. The computing unit 501 performs the various methods and processes described above, such as data access control methods. For example, in some embodiments, the data access control methods may be implemented as computer software programs tangibly contained in a machine-readable medium, such as storage unit 508. In some embodiments, part or all of the computer program may be loaded and / or installed on the electronic device 500 via ROM 502 and / or communication unit 509. When the computer program is loaded into RAM 503 and executed by the computing unit 501, one or more steps of the methods described above may be performed. Alternatively, in other embodiments, the computing unit 501 may be configured to perform the aforementioned data access control method by any other suitable means (e.g., by means of firmware).
[0092] According to embodiments of this disclosure, this disclosure also provides a server device, a readable storage medium, and a computer program product.
[0093] Figure 7 A schematic block diagram of an example electronic device 600 that can be used to implement embodiments of the present disclosure is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present disclosure described and / or claimed herein.
[0094] like Figure 7 As shown, the electronic device 600 includes a computing unit 601, which can perform various appropriate actions and processes based on a computer program stored in ROM (Read-Only Memory) 602 or loaded from storage unit 608 into RAM (Random Access Memory) 603. The RAM 603 may also store various programs and data required for the operation of the electronic device 600. The computing unit 601, ROM 602, and RAM 603 are interconnected via a bus 604. An I / O (Input / Output) interface 605 is also connected to the bus 604.
[0095] Multiple components in electronic device 600 are connected to I / O interface 605, including: input unit 606, such as keyboard, mouse, etc.; output unit 607, such as various types of displays, speakers, etc.; storage unit 608, such as disk, optical disk, etc.; and communication unit 609, such as network card, modem, wireless transceiver, etc. Communication unit 609 allows electronic device 600 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0096] The computing unit 601 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 601 include, but are not limited to, CPUs (Central Processing Units), GPUs (Graphics Processing Units), various special-purpose AI (Artificial Intelligence) computing chips, various computing units running machine learning model algorithms, DSPs (Digital Signal Processors), and any suitable processor, controller, microcontroller, etc. The computing unit 601 performs the various methods and processes described above, such as data access control methods. For example, in some embodiments, the data access control methods may be implemented as computer software programs tangibly contained in a machine-readable medium, such as storage unit 608. In some embodiments, part or all of the computer program may be loaded and / or installed on the electronic device 600 via ROM 602 and / or communication unit 609. When the computer program is loaded into RAM 603 and executed by the computing unit 601, one or more steps of the methods described above may be performed. Alternatively, in other embodiments, the computing unit 601 may be configured to perform the aforementioned data access control method by any other suitable means (e.g., by means of firmware).
[0097] According to embodiments of this disclosure, this disclosure also provides a data access control system, including a gateway device and a server device.
[0098] Various implementations of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, FPGAs (Field Programmable Gate Arrays), ASICs (Application-Specific Integrated Circuits), ASSPs (Application-Specific Standard Products), SOCs (System-on-Chips), CPLDs (Complex Programmable Logic Devices), computer hardware, firmware, software, and / or combinations thereof. These various implementations may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0099] The program code used to implement the methods of this disclosure may be written in any combination of one or more programming languages. This program code may be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus, such that when executed by the processor or controller, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may be executed entirely on a machine, partially on a machine, as a standalone software package partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0100] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, RAM, ROM, EPROM (Electrically Programmable Read-Only Memory) or flash memory, optical fiber, CD-ROM (Compact Disc Read-Only Memory), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0101] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device for displaying information to the user (e.g., a CRT (Cathode-Ray Tube) or LCD (Liquid Crystal Display) monitor); and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the computer. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0102] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or computing systems that include middleware components (e.g., application servers), or computing systems that include frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include LANs (Local Area Networks), WANs (Wide Area Networks), the Internet, and blockchain networks.
[0103] Computer systems can include clients and servers. Clients and servers are generally geographically separated and typically interact via communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. A server can be a cloud server, also known as a cloud computing server or cloud host, a hosting product within the cloud computing service system that addresses the shortcomings of traditional physical hosts and VPS (Virtual Private Server) services, such as high management difficulty and weak business scalability. Servers can also be servers for distributed systems or servers incorporating blockchain technology.
[0104] It's important to note that artificial intelligence (AI) is the study of enabling computers to simulate certain human thought processes and intelligent behaviors (such as learning, reasoning, thinking, and planning). It encompasses both hardware and software technologies. AI hardware technologies generally include sensors, dedicated AI chips, cloud computing, distributed storage, and big data processing. AI software technologies primarily include computer vision, speech recognition, natural language processing, machine learning / deep learning, big data processing, and knowledge graph technologies.
[0105] It should be understood that the various forms of processes shown above can be used to rearrange, add, or delete steps. For example, the steps described in this disclosure can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution disclosed in this disclosure can be achieved, and this is not limited herein.
[0106] The specific embodiments described above do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure should be included within the scope of protection of this disclosure.
Claims
1. A data access control method, applied at a gateway, characterized in that, include: In response to a data access request, extract multi-dimensional trust data from the data access request; The multi-dimensional trust data is scored based on trust assessment rules to obtain a trust score. The trust score and the request content in the data access request are then sent to the target server so that the target server can determine the decision probability based on the authorization decision model, which is obtained by training the model based on historical authorization samples. The received decision probability is compared with a preset dynamic threshold range, and the data access request is controlled based on the comparison result.
2. The method according to claim 1, characterized in that, The trust score obtained by scoring the multi-dimensional trust data based on trust assessment rules includes: Retrieve a trust assessment rule from the trust assessment rule base that matches the user operation type of the data access request. The trust assessment rule base stores at least one trust assessment rule corresponding to different user operation types. The multi-dimensional trust data is scored based on the trust assessment rules to obtain multi-dimensional scoring results. The multi-dimensional scoring results are then weighted based on dynamic weighting thresholds to obtain a trust score. Different user operation types are matched with different dynamic weighting thresholds.
3. The method according to claim 2, characterized in that, The extraction of multi-dimensional trust data from the data access request includes: Extract authentication information, device identifier, address information, and time information from the request header of the data access request, and extract user operation type and behavior pattern from the request body of the data access request; The identity authentication information, the device identifier, the address information, and the time information are cleaned, and the importance features are extracted from the cleaned information to obtain multi-dimensional trust data.
4. The method according to claim 3, characterized in that, The method further includes: Obtain a user behavior pattern library, which stores the historical operation behaviors of historical users; Upon receiving user operation behavior feedback from the server, a trust classification is performed based on the similarity between the historical operation behavior and the user operation behavior, and the trust score, to obtain a trust classification result. The dynamic weighted threshold is adjusted based on the trust classification result; or, The dynamic weighted threshold is adjusted based on the request type and request time of the data access request.
5. The method according to claim 1, characterized in that, The step of comparing the received decision probability with a preset dynamic threshold range and controlling the data access request based on the comparison result includes: If the decision probability is within the first preset evaluation range, it is determined to be unauthorized permission, and an access denial response is output for the data access request; If the decision probability matches the second preset evaluation range, it is determined to be a suspicious permission, and a verification request instruction is sent to perform secondary security verification. If the decision probability matches the third preset evaluation range, then the authorization is determined, and the data access request is sent to the target application service.
6. A data access control method, applied to a server, characterized in that, include: Obtain the request content and trust score of the data access request sent by the gateway, wherein the trust score is obtained by scoring based on the multi-dimensional trust data of the data access request; The authorization decision model is used to process the request content, the trust score, and historical access data to obtain the decision probability. The authorization decision model is obtained by training the model based on historical authorization samples. The decision probability is fed back to the gateway.
7. The method according to claim 6, characterized in that, Before performing decision processing on the request content, the trust score, and historical access data based on the authorization decision model to obtain the decision probability, the method further includes: An authorization decision model is constructed based on the random forest algorithm, and historical authorization samples are obtained to represent the current historical authorization situation. The authorization decision model is trained using the historical authorization samples, and the model parameters are optimized using grid search to obtain the completed authorization decision model. The model parameters include the number of decision trees, the maximum tree depth, and the feature selection criteria.
8. The method according to claim 7, characterized in that, Before performing decision processing on the request content, the trust score, and historical access data based on the authorization decision model to obtain the decision probability, the method further includes: The system retrieves a pre-configured rule engine and determines whether there are any hard violations in the request content based on the pre-configured rule engine. The pre-configured rule engine is configured with multiple hard violations, including at least one of accessing a blacklist or accessing sensitive content. If there is no hard violation, the weighted average of the trust score is determined, and if the weighted average is less than a preset evaluation threshold, the authorization decision model that has completed model training is retrieved.
9. The method according to claim 8, characterized in that, The method further includes: When the target application service executes the data access request, the user's operation behavior is recorded and fed back to the gateway so that the gateway can recalculate the trust score. The historical authorization samples are updated based on the user's actions and the recalculated trust score, so as to retrain the authorization decision model.
10. A data access control device, applied at a gateway, characterized in that, include: The extraction module is used to extract multi-dimensional trust data from the data access request in response to the data access request. The scoring module is used to score the multi-dimensional trust data based on trust assessment rules to obtain a trust score, and send the trust score and the request content in the data access request to the target server so that the target server can determine the decision probability based on the authorization decision model, which is obtained by model training based on historical authorization samples. The control module is used to compare the received decision probability with a preset dynamic threshold range, and control the data access request based on the comparison result.
11. A data access control device, applied to a server, characterized in that, include: The acquisition module is used to acquire the request content and trust score of the data access request sent by the gateway. The trust score is obtained by scoring based on the multi-dimensional trust data of the data access request. The decision module is used to perform decision processing on the request content, the trust score, and historical access data based on the authorization decision model to obtain the decision probability. The authorization decision model is obtained by training the model based on historical authorization samples. The feedback module is used to feed back the decision probability to the gateway.
12. A gateway device, characterized in that, include: At least one processor; as well as A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, which, when executed by the at least one processor, enables the at least one processor to perform the data access control method according to any one of claims 1-5.
13. A non-transitory computer-readable storage medium storing computer instructions, characterized in that, The computer instructions are used to cause the computer to execute the data access control method according to any one of claims 1-5.
14. A computer program product, characterized in that, It includes a computer program that, when executed by a processor, implements the data access control method according to any one of claims 1-5.
15. A server-side device, characterized in that, include: At least one processor; as well as A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, which, when executed by the at least one processor, enables the at least one processor to perform the data access control method according to any one of claims 6-9.
16. A non-transitory computer-readable storage medium storing computer instructions, characterized in that, The computer instructions are used to cause the computer to execute the data access control method according to any one of claims 6-9.
17. A computer program product, characterized in that, It includes a computer program that, when executed by a processor, implements the data access control method according to any one of claims 6-9.
18. A data access control system, characterized in that, This includes the gateway device as described in claim 12 and the server device as described in claim 15.