Electronic archive system dynamic access control method based on zero-trust architecture
By constructing access link disturbance sample sequences and analyzing the connection stability of communication nodes in the electronic archive system, the access control strategy is dynamically adjusted, which solves the problem of insufficient perception of link state changes in traditional access control methods and achieves more stable and secure access control.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- TONGLUE TECH CO LTD
- Filing Date
- 2026-03-24
- Publication Date
- 2026-04-21
AI Technical Summary
In existing technologies, the access control methods of traditional electronic record systems lack a mechanism for real-time capture of changes in link status, making it difficult to perceive the characteristics of link disturbances during the access process. This leads to a deviation between the permission allocation results and the actual link status, creating a blind spot in stability judgment and easily causing delays in permission configuration and the risk of resource exposure.
Based on a zero-trust architecture, by setting up continuous measurement nodes in the electronic archive access link, the difference in communication signal strength, the number of directional changes and the maximum jump amplitude are collected to construct an access link disturbance sample sequence, analyze the connection stability of communication nodes, generate access restriction classifications, and adjust the field masking method and access request interval to achieve dynamic access control.
It achieves precise matching between resource request status and restrictions, enhances the dynamic response capability and protection effect of access control, and improves the stability and security of access control.
Smart Images

Figure CN121907620A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of access control technology, and in particular to a dynamic access control method for electronic archive systems based on a zero-trust architecture. Background Technology
[0002] Access control technology involves managing and controlling access permissions for users, devices, or processes in information systems to prevent unauthorized access and data leakage. Its core aspects include authentication, permission allocation, access decisions, session management, and audit trails. This technology primarily studies how to judge and execute resource access requests based on preset policies and rules, ensuring that system resources are accessed only by authorized entities. It is widely used in traditional network environments, distributed systems, and cloud computing platforms. Common techniques include role-based access control, attribute-based access control, rule-based access control, and multi-factor authentication mechanisms. Traditional dynamic access control methods for electronic archive systems refer to the way permissions are dynamically adjusted and access controlled for electronic archives in information management systems. Access permissions are typically set based on user identity information, request content, and the current system state. Implementation methods mainly include setting static access control lists, using permission level models to divide user operation scopes, and matching user requests through access control policy files. The dynamism relies mainly on predefined policy refresh mechanisms or periodic permission review processes to implement permission changes.
[0003] Existing technologies primarily rely on static access strategies, depending on identity attributes and permission levels for access decisions. They lack a mechanism for real-time capture of changes in link status, making it difficult to detect link disturbances during the access process. Access control rules cannot be dynamically adjusted based on the actual fluctuations in the communication link, and there is a lack of effective criteria for judgment when faced with frequent jumps or signal anomalies. This leads to a discrepancy between permission allocation results and the actual link status. Furthermore, the lack of systematic analysis of node behavior consistency and connection maintenance during policy execution results in a stability blind spot in multi-node communication links, which can easily lead to problems such as delayed permission configuration, frequent miscontrols, and increased risk of resource exposure. Summary of the Invention
[0004] To achieve the above objectives, the present invention adopts the following technical solution: a dynamic access control method for electronic archive systems based on a zero-trust architecture, comprising the following steps: S1: Set up continuous measurement nodes in the electronic archive access link, collect the communication signal strength difference, direction change number and maximum jump amplitude per unit time, construct the access link disturbance sample sequence, calculate the fluctuation order in the access link disturbance sample sequence, and generate the access link fluctuation sequence. S2: Based on the access link fluctuation sequence, obtain the handshake response delay, path hop count change and connection hold period of the communication nodes in the path, analyze the downward trend of connection stability in the communication nodes, and generate access connection description content; S3: Call the access link fluctuation sequence and the access connection description, compare the disturbance frequency, connection interruption status and the number of inconsistent nodes, and generate an access restriction classification based on preset judgment rules; S4: Based on the restriction level in the access restriction category, filter the resource directory, adjust the field masking method, set the minimum access request interval, and generate access control processing content; S5: Invoke the resource directory filtering results, field masking methods, and request interval restriction methods in the access control processing content to determine whether the resources in the access request meet the restrictions of the access control processing content, and output the access permission control results.
[0005] As a further aspect of the present invention, the access link fluctuation sequence includes a signal strength difference sequence, direction change frequency, maximum jump amplitude value, and timing fluctuation pattern; the access connection description includes handshake delay distribution, path hop count fluctuation characteristics, connection hold period interval, and stability degradation index; the access restriction classification includes disturbance level category, connection anomaly level, and node consistency level; the access control processing includes resource directory filtering items, field masking rules, and minimum access interval setting; and the access permission control result includes resource request compliance status, access policy matching status, and permission judgment level.
[0006] As a further aspect of the present invention, the preset judgment rule refers to a standardized set of rules that compare and analyze the disturbance characteristics and connection status of the access link to determine the access restriction level.
[0007] As a further aspect of the present invention, the access control processing content is limited to resource access conditions set based on the access restriction level, including restriction measures such as resource filtering, field masking, and minimum request interval.
[0008] As a further aspect of the present invention, the specific steps of S1 are as follows: S101: Obtain continuous measurement nodes in the electronic archive access link, record the communication signal strength of the nodes per unit time, calculate the strength difference between adjacent nodes, and combine it with the node sequence to generate a communication signal strength difference sequence. S102: Based on the communication signal strength difference sequence, determine the direction of node signal change, count the number of directional changes per unit time, and generate a sequence of directional change count indicators by combining the node time index; S103: Based on the communication signal strength difference sequence and the direction change number index sequence, extract the maximum jump amplitude of the node, aggregate them into a disturbance sample sequence, analyze the time-series fluctuation characteristics, and generate an access link fluctuation sequence.
[0009] As a further aspect of the present invention, the specific steps of S2 are as follows: S201: Based on the access link fluctuation sequence, call the handshake request and response delay records of the communication nodes in the path, measure the interval of the request and response time within the same access period, extract the response time difference between nodes, and aggregate it with the corresponding node index to generate a handshake response delay sequence. S202: Based on the handshake response delay sequence, call the path hop count change record in each access cycle, extract the hop count fluctuation value in consecutive access cycles, compare whether the hop count change trend is continuously offset, and generate a structured data frame by combining the access time index to obtain the path hop count change trend sequence. S203: Call the path hop count change trend sequence and the handshake response delay sequence, retrieve the connection hold time parameter within the corresponding period, perform a pairing judgment on the correlation between the connection hold period and the hop count fluctuation trend, if the connection hold time decreases and the hop count changes frequently within a continuous period, then aggregate the corresponding period and link identifier to generate access connection description content.
[0010] As a further aspect of the present invention, the specific steps of S3 are as follows: S301: Call the access link fluctuation sequence and the access connection description content, extract the number of disturbance events recorded by each access link in a unit time, calculate the frequency of disturbance events during the access process, and aggregate the frequency results with the link identifier to generate a disturbance frequency index set; S302: Based on the access connection description, retrieve connection interruption records within the continuous access period, extract the number of connection interruptions and the duration of interruptions, determine whether there is a situation that exceeds the preset connection interruption threshold, extract the number of periodic node differences in combination with node distribution information, and generate a connection anomaly feature matrix. S303: Based on the disturbance frequency index set and the connection anomaly feature matrix, set the disturbance frequency threshold, connection interruption threshold and node difference number threshold as preset conditions, perform condition matching on the index combination of each access link, and perform classification marking on access links that meet the differentiation level standard to establish access restriction classification.
[0011] As a further aspect of the present invention, the specific steps of S4 are as follows: S401: Based on the restriction level information in the access restriction classification, filter target resource directories with restriction levels not lower than the access classification threshold, bind the resource identifier of the corresponding directory with the restriction level, and establish a target resource mapping set; S402: Call the target resource mapping set, retrieve the associated field details, compare and judge the field type and restriction level, and perform field masking policy rule matching according to the masking policy parameters set by the field sensitivity level to obtain the field masking configuration parameter group. S403: Based on the field masking configuration parameter group and the target resource mapping set, set an access request interval control strategy for each resource record, extract the access interval threshold parameter corresponding to the restriction level, establish an access restriction control frame by combining the masking configuration and the directory mapping, and summarize the access control processing content.
[0012] As a further aspect of the present invention, the specific steps of S5 are as follows: S501: Call the directory filtering results in the access control processing content, parse the resource path identifier contained in the access request, match it with the filtered directory path, if the path exists in the filtering results, mark it as an accessible directory, otherwise mark it as a prohibited access path, and generate a path access judgment result set. S502: Based on the path access judgment result set and the field masking method in the access control processing content, extract the field content in the request, and match and judge whether the corresponding field is a masked field. If the access field is a masked field, mark it as a sensitive field access behavior and generate a field access compliance identification frame. S503: Invoke the access compliance identification frame of the field and the access frequency limitation method in the access control handling content, extract the timestamp of the access request and the record time interval, determine whether the access frequency is lower than the minimum interval threshold, and jointly compare the access frequency, field access status and path judgment result to establish access control result.
[0013] As a further aspect of the present invention, the minimum interval threshold refers to the shortest time interval between consecutive requests to access the same resource.
[0014] Compared with the prior art, the advantages and positive effects of the present invention are as follows: In this invention, a link disturbance sample sequence is constructed and communication fluctuation characteristics are extracted. A connection behavior description is generated by combining node response delay and hop count changes. Access classification rules are established by utilizing disturbance frequency and node inconsistency. Resource filtering, field masking and access interval setting are integrated to form unified handling content, thereby achieving accurate matching of resource request status and restriction conditions. Access judgment is driven by link status and behavior characteristics, enhancing the dynamic response capability and protection effect of access control. Attached Figure Description
[0015] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0016] Figure 1 This is a schematic diagram of the steps of the present invention; Figure 2 This is a detailed schematic diagram of S1 of the present invention; Figure 3 This is a detailed schematic diagram of S2 of the present invention; Figure 4 This is a detailed schematic diagram of S3 of the present invention; Figure 5 This is a detailed schematic diagram of S4 of the present invention; Figure 6 This is a detailed schematic diagram of S5 of the present invention. Detailed Implementation
[0017] The technical solution of the present invention will now be described with reference to the accompanying drawings.
[0018] In embodiments of the present invention, words such as "exemplarily," "for example," etc., are used to indicate that something is an example, illustration, or description. Any embodiment or design described as "exemplary" in the present invention should not be construed as being more preferred or advantageous than other embodiments or designs. Specifically, the use of the word "exemplary" is intended to present the concept in a concrete manner. Furthermore, in embodiments of the present invention, the meaning expressed by "and / or" can be both, or either one.
[0019] In the embodiments of this invention, the terms "image" and "picture" may sometimes be used interchangeably. It should be noted that, without emphasizing the distinction between them, they convey the same meaning. Similarly, the terms "of," "corresponding (relevant)," and "corresponding" may sometimes be used interchangeably. It should be noted that, without emphasizing the distinction between them, they convey the same meaning.
[0020] In this embodiment of the invention, sometimes a subscript such as W1 may be written in a non-subscript form such as W1. When the difference is not emphasized, the meaning they express is the same.
[0021] To make the technical problems, technical solutions and advantages of the present invention clearer, a detailed description will be given below in conjunction with the accompanying drawings and specific embodiments.
[0022] Please see Figure 1 This invention provides a dynamic access control method for electronic archives systems based on a zero-trust architecture, comprising the following steps: S1: By setting up continuous measurement nodes in the electronic archive access link, the difference in communication signal strength, the number of directional changes and the maximum jump amplitude per unit time are collected to construct the access link disturbance sample sequence, calculate the time-series fluctuation law in the disturbance sample sequence and generate the access link fluctuation sequence. S2: Based on the access link fluctuation sequence, obtain the handshake response delay of communication nodes in the path, the changes in the number of path hops and the connection maintenance period, analyze whether there is a trend of stability decline in the communication link during continuous access, and generate access connection description content. S3: Call the access link fluctuation sequence and access connection description, compare the disturbance frequency, connection interruption status and the number of inconsistent nodes, establish access classification rules and generate access restriction categories based on preset conditions; S4: Based on the restriction level information in the access restriction category, filter the target resource directory, adjust the field masking method, and set the minimum interval time for access requests. Summarize the three types of processing content to form access control processing content. S5: Invoke the directory filtering results, field masking method and access frequency limitation method in the access control handling content, determine whether the resource requests included in the access request conform to the current access control handling content, and output the access permission control result.
[0023] The access link fluctuation sequence includes signal strength difference sequence, frequency of directional changes, maximum jump amplitude value, and timing fluctuation pattern. The access connection description includes handshake delay distribution, path hop count fluctuation characteristics, connection hold period interval, and stability degradation index. The access restriction classification includes disturbance level category, connection anomaly level, and node consistency level. The access control handling content includes resource catalog filtering items, field masking rules, and minimum access interval settings. The access permission control results include resource request compliance status, access policy matching status, and permission judgment level.
[0024] Please see Figure 2 The specific steps of S1 are as follows: S101: Obtain continuous measurement nodes in the electronic archive access link, record the communication signal strength of the nodes per unit time, calculate the strength difference between adjacent nodes, and combine it with the node sequence to generate a communication signal strength difference sequence. By deploying detection components at key nodes in the network architecture, various measurement nodes in the current data transmission path are identified and connected in real time. These nodes cover the entire path from user terminal access switches and aggregation layer backbone routers to the core database server. With a monitoring accuracy set at the millisecond level, the communication signal strength of each node is recorded per unit time by continuously parsing the physical descriptors of the network packet flow. In actual execution, for real-time monitoring of nodes A, B, and C, the raw power level values collected by the link detectors are retrieved, and the initial signal strength of node A within the current observation second is recorded as -62dBm, node B as -65dBm, and node C as -70dBm.
[0025] During execution, the intensity values of nodes A and B at the same time step are extracted, and a difference operation is performed to obtain the absolute magnitude of their intensity loss. The intensity difference between nodes A and B is calculated to be 3 dBm. Then, the same operation is performed on node B and its downstream node C, and the intensity difference between the adjacent nodes is calculated to be 5 dBm. The calculated difference results [3, 5] are bound and mapped to the physical topology location sequence identifiers of each node to ensure that each difference can be traced back to a specific physical link interval. By sequentially arranging all the difference data within 60 consecutive sampling periods, a communication signal intensity difference sequence is generated. Each value in this sequence accurately records the dynamic attenuation characteristics of the signal during transmission between nodes in the link, reflecting the real-time loss of the signal transmission by the physical medium.
[0026] S102: Based on the communication signal strength difference sequence, determine the direction of node signal change, count the number of directional changes per unit time, and generate a sequence of directional change count indicators by combining the node time index; The direction of change in the node signal is determined by comparing the increase or decrease of values between adjacent sampling points. The judgment criterion is set as follows: if the difference value at the current moment is higher than the value at the previous moment, the direction of change at that moment is recorded as "enhancing disturbance"; conversely, if the value decreases, it is recorded as "decreasing trend". Through a preset 60-second statistical window, the extreme switching points where the direction changes from enhancement to decay or from decay to enhancement within the window are accumulated and counted to count the number of directional changes per unit time, aiming to identify whether there is high-frequency noise interference in the signal environment.
[0027] In a specific implementation scenario, the difference sequence [3, 5, 2, 6, 4] and its subsequent extended data are retrieved. First, the first two values are compared, indicating a positive change; then, values 5 and 2 are compared, indicating a negative change, triggering a directional mutation count. If 14 such reversal behaviors are accumulated through a traversal algorithm within the entire 60-second observation period, the count value 14 is extracted as a key mutation indicator. Subsequently, the time index information of each mutation is retrieved, such as extracting specific timestamps like 10.5 seconds or 12.2 seconds. These time indices are then structurally correlated with the total number of mutations to generate a directional mutation count indicator sequence. This sequence reflects the degree of environmental interference through numerical range divisions: 0 to 5 indicates a stable signal, 6 to 15 indicates moderate fluctuation, and more than 15 indicates high disturbance, accurately revealing the noise activity patterns of the link's physical environment.
[0028] S103: Based on the communication signal strength difference sequence and the direction change number index sequence, extract the maximum jump amplitude of the node, aggregate it into a disturbance sample sequence, analyze the time-series fluctuation characteristics, and generate the access link fluctuation sequence. A peak retrieval operation is performed to extract the maximum jump amplitude of the node. All sampling points are traversed in the difference sequence. If a signal strength difference at a sampling point is detected to suddenly increase from the baseline of 3dBm to 28dBm, a value extraction operation is performed to define it as the maximum jump amplitude of 28dBm within that period. This amplitude value of 28 is logically aggregated with the number of directional abrupt changes (14) within the same period and stored in the perturbation sample sequence, forming a sample set containing both fluctuation intensity and fluctuation frequency dimensions.
[0029] Subsequently, time-series fluctuation characteristic analysis was performed on the disturbed sample sequence. Specifically, the sample mean was first calculated. Assuming the five amplitude data sets recorded in the sample set were 28, 25, 30, 26, and 21 dBm, the arithmetic mean was calculated to yield a mean of 26 dBm. Next, the standard deviation of the sample set was calculated. This was done by summing the squares of the differences between each sample value and the mean of 26, dividing by the number of samples, and then taking the square root, resulting in a standard deviation of approximately 3.03 dBm. Finally, the standard deviation of 3.03 was divided by the mean of 26, yielding a coefficient of variation of approximately 0.116. This coefficient of variation was used as a core parameter for link stability, and combined with the time-series characteristics of each node for aggregation analysis, ultimately generating an access link fluctuation sequence. This sequence quantifies the comprehensive physical fluctuation situation of the link during the observation period, providing a fluctuation background reference for subsequent transport layer analysis.
[0030] Please see Figure 3 The specific steps of S2 are as follows: S201: Based on the access link fluctuation sequence, call the handshake request and response delay records of communication nodes in the path, measure the interval of request and response time within the same access period, extract the response time difference between nodes, and aggregate it with the corresponding node index to generate a handshake response delay sequence. Entering the transport layer performance monitoring phase, the handshake request and response latency records of communication nodes in the path are invoked. The probe sends TCP handshake request synchronization signals to the nodes in the path through the network protocol stack, recording the nanosecond-level timestamp of the sending time. In actual execution, the probe record initiated against node A shows a sending timestamp of 14:00:00.100, and when the response signal is received from node A, the timestamp of the response is recorded as 14:00:00.125.
[0031] An interval measurement operation is performed, calculating the single-point response latency of node A within this period to be 25 milliseconds. Similarly, the response latency of downstream node B is measured to be 48 milliseconds. The response time difference between two consecutive nodes is extracted, and a subtraction operation is performed to obtain a node response time difference of 23 milliseconds. This difference value of 23 milliseconds is then subjected to structured aggregation with the corresponding node indices A and B. By iteratively measuring and extracting the difference in the request response times of all path nodes within the same access period, a handshake response latency sequence is finally generated. This sequence serves as the core basis for evaluating network congestion and transmission performance, reflecting the deviation in the processing capabilities of each node during data transmission.
[0032] S202: Based on the handshake response delay sequence, call the path hop count change record in each access cycle, extract the hop count fluctuation value in consecutive access cycles, compare whether the hop count change trend is continuously offset, and generate a structured data frame by combining the access time index to obtain the path hop count change trend sequence. The system retrieves the path hop count change records for each access period. It extracts the real-time path hop count by parsing the Time-to-Live (TTL) field in the packet header and calculating its decrease during transmission. For example, in access period T, the recorded path hop count is 6 hops; in the subsequent T1 period, due to path reselection triggered by the network's dynamic routing protocol, the path hop count changes to 9 hops. A subtraction operation is performed to extract the hop count fluctuation value of 3 within consecutive access periods.
[0033] Next, a determination is made as to whether the hop count trend is continuously shifting. The criteria for continuous trend shift are: the direction of hop count change remains consistent over three consecutive access cycles, and the sum of the absolute values of the cumulative fluctuations exceeds 4 hops. If the hop count is observed to increase from 6 to 9, and then to 12, satisfying the above shift condition, it is determined to be a continuous trend shift. Subsequently, combined with the access time index 14:00:05, the current hop count of 12, the fluctuation value of 3, and the shift determination status are encapsulated into a structured data frame. By sequentially summarizing multiple sets of data frames, a path hop count change trend sequence is obtained. This sequence records the dynamic evolution characteristics of the network topology and is used to analyze the impact of lower-level routing changes on upper-level access.
[0034] S203: Call the path hop count change trend sequence and handshake response delay sequence, retrieve the connection hold time parameter within the corresponding period, perform a pairing judgment on the correlation between the connection hold time and the hop count fluctuation trend, if the connection hold time decreases and the hop count changes frequently within a continuous period, then aggregate the corresponding period and link identifier to generate access connection description content. Retrieve the connection hold-up time parameter within the corresponding period. Perform a pairwise judgment on the correlation between the connection hold-up time and the hop count fluctuation trend. During execution, two pre-set trigger logics are used: first, the connection hold-up time decreases by more than 60 milliseconds; second, the path hop count changes frequently and the cumulative fluctuation value exceeds 4 hops.
[0035] In practice, if it is detected that the connection hold time rapidly decreases from 1800 milliseconds to 1710 milliseconds within the current period, a decrease of 90 milliseconds, the first condition is met; simultaneously, the path hop count changes from 5 hops to 10 hops within a short period, a change of 5 hops, satisfying the second condition. When both parameters trigger the preset conditions simultaneously within the same time window, pairing confirmation logic is executed, aggregating the abnormal time period, the affected link identifier ID, and the specific hop count fluctuation data. Through this process, access connection description content is generated, which records in detail the causal mapping relationship between connection quality degradation and drastic network topology changes.
[0036] Please see Figure 4 The specific steps of S3 are as follows: S301: Call the access link fluctuation sequence and access connection description, extract the number of disturbance events recorded for each access link in a unit of time, calculate the frequency of disturbance events during the access process, and aggregate the frequency results with the link identifier to generate a disturbance frequency index set; Perform frequency quantization calculations for disturbance events. Extract the total number of disturbance events recorded for each access link within a 60-second time unit. A disturbance event is defined as an extreme record where the signal transition amplitude exceeds 20dBm or the single-hop delay fluctuation exceeds 100ms. If Link_01 records 18 such disturbance events within 60 seconds, the calculated frequency of disturbance events during the access process is 0.3 times per second.
[0037] The calculated frequency result of 0.3 is mapped to the corresponding link identifier Link_01 using a key-value pair aggregation method. Similarly, if the total number of disturbance events for link Link_02 is 6, its frequency is calculated as 0.1 times per second and recorded. By summarizing the frequency data of all access links within the monitoring range, a disturbance frequency index set is finally generated. This index set provides a quantitative ranking of the links affected by physical and transport layer interference; higher values indicate more unstable link quality, laying the data foundation for subsequent risk classification.
[0038] S302: Based on the access connection description, retrieve connection interruption records within the continuous access period, extract the number of connection interruptions and the duration of interruptions, determine whether there is a situation that exceeds the preset connection interruption threshold, extract the number of periodic node differences in combination with node distribution information, and generate a connection anomaly feature matrix. Retrieve connection interruption records within a continuous access period. Extract all abnormal interruption data for Link_01 within a specific time window. The records show that a total of 4 connection interruptions occurred. Extract the duration of each interruption, which is 3 seconds, 6 seconds, 12 seconds, and 4 seconds, respectively.
[0039] The extracted maximum interruption duration of 12 seconds was compared with the preset connection interruption threshold of 10 seconds. Since 12 is greater than 10, the link was determined to have a serious risk of interruption. Simultaneously, the node distribution information of the link was retrieved, and the initial set of normal path nodes was compared with the set of nodes at the current abnormal moment to identify newly added or failed nodes in the path, calculating the number of node differences to be 7. The interruption count (4), maximum interruption duration (12 seconds), and number of node differences (7) were then matrix-filled to generate a connection anomaly feature matrix. This matrix characterizes the degree of link failure and topological heterogeneity at the connection layer.
[0040] S303: Based on the disturbance frequency index set and the connection anomaly feature matrix, set the disturbance frequency threshold, connection interruption threshold and node difference number threshold as preset conditions, perform condition matching on the index combination of each access link, and perform classification marking on access links that meet the differentiation level standard to establish access restriction classification. Set multiple threshold conditions to perform matching. The preset judgment conditions are: disturbance frequency threshold is set to 0.25 times per second, connection interruption threshold is set to 10 seconds, and node difference number threshold is set to 5.
[0041] For the feature combination [0.3, 12, 7] of link_01, conditional matching logic is executed: First, the disturbance frequency 0.3 is greater than 0.25, which is considered excessive; second, the interruption duration 12 is greater than 10, which is also considered excessive; finally, the number of node differences 7 is greater than 5, which is also considered excessive. Since all indicators of this link meet the preset differentiated high-level standard, it is classified as "high-risk restricted". By performing similar conditional matching and classification on all access links, an access restriction classification is finally established. This classification provides a mandatory policy basis for subsequent differentiated access control of resources with different security levels.
[0042] Please see Figure 5 The specific steps of S4 are as follows: S401: Based on the restriction level information in the access restriction classification, filter the target resource directories with a restriction level not lower than the access level threshold, bind the resource identifier of the corresponding directory with the restriction level, and establish a target resource mapping set; Perform targeted resource catalog filtering. Set the access level threshold to "Level 2 Moderately Restricted" and automatically retrieve all target resources with a restriction level not lower than this threshold. For example, if Link_01 is identified as having a restriction level of "Level 3 Highly Restricted" and the resource it carries is a financial audit catalog with the resource identifier Res_Finance_001.
[0043] During execution, the resource identifier Res_Finance_001 is bound to the "Level 3" restriction level. By traversing the resource index database of the electronic records management system, all sensitive directories accessed through high-risk links are selected, and their resource identifiers are mapped one-to-one with their corresponding restriction levels to establish a target resource mapping set. This mapping set clarifies which resource directories need to enter a state of mandatory security control under the current network environment, defining the execution boundaries for subsequent fine-grained control at the field level.
[0044] S402: Call the target resource mapping set, retrieve the associated field details, compare and judge the field type and restriction level, and perform field masking policy rule matching according to the masking policy parameters set by the field sensitivity level to obtain the field masking configuration parameter group. Further retrieve the field details associated with the controlled resource directory. In the search for resource Res_Finance_001, extract a list of fields including employee name, contact number, bank account number, and monthly salary. Obtain the original sensitivity attributes of each field and compare them with the current restriction level.
[0045] Based on preset masking strategy parameters, rule matching is performed for different fields. For the "Bank Account Number" field, due to its association link restriction level of level three and the field's inherent high sensitivity, the "mask masking" strategy is applied; for the "Employee Name" field, the "partial masking" strategy is applied. After the judgment is executed, the specific masking parameters corresponding to each field are extracted, such as retaining the first four and last three digits of the account number. Finally, the processing methods for all controlled fields are summarized to obtain the field masking configuration parameter group, which serves as a direct instruction for data desensitization, preventing sensitive information from being leaked under insecure links.
[0046] S403: Based on the field masking configuration parameter group and the target resource mapping set, set the access request interval control policy for each resource record, extract the access interval threshold parameter corresponding to the restriction level, establish an access restriction control frame by combining the masking configuration and the directory mapping, and summarize the access control processing content. Set access request interval control policies for each resource record. Extract the access interval threshold parameters corresponding to the restriction level. For the "Level 3 Highly Restricted" level, set the minimum access frequency interval threshold to 5000 milliseconds to combat malicious high-frequency crawling behavior that may be caused by unstable links.
[0047] During execution, the 5000-millisecond access interval threshold, masking rules for each field, and resource directory path are jointly encapsulated to establish an access restriction control frame. This control frame contains complete resource access control metadata. By uniformly managing and summarizing these control frames, the access control processing content is obtained. This content serves as the execution standard for the security gateway, guiding the real-time interception and dynamic processing of every subsequent access request to the restricted resource.
[0048] Please see Figure 6 The specific steps of S5 are as follows: S501: Call the directory filtering results in the access control handling content, parse the resource path identifier contained in the access request, match it with the filtered directory path, if the path exists in the filtering results, mark it as an accessible directory, otherwise mark it as a prohibited path, and generate a path access judgment result set; The system retrieves the directory filtering results from the access control handling content. It parses the resource path identifier carried in the access request message, for example, extracting the request path as a specific financial report file. It then executes a path matching algorithm, comparing the path with the controlled directory paths in the handling content using prefix comparison.
[0049] If the path is included in the controlled directory list, it is marked as an accessible directory and associated with the corresponding security level policy; if the path is not in the filtering results, it is marked as a prohibited path according to the default security rules. This initial filtering at the path level generates a path access judgment result set. This step ensures that the access behavior first conforms to the security management boundary at the resource path level, providing a legality prerequisite for subsequent field content checks.
[0050] S502: Based on the path access judgment result set and the field masking method in the access control handling content, extract the field content in the request, and match and judge whether the corresponding field is a masked field. If the accessed field is a masked field, mark it as a sensitive field access behavior and generate a field access compliance identification frame. Further extract the field content contained in the request. Scan the data request body of the user request in real time to determine whether it contains controlled sensitive fields.
[0051] In practice, if a user requests to read the "bank account number" field, the masking parameter group generated in S402 is used as a reference. Since "bank account number" is explicitly defined as a masked field, this access behavior is immediately marked as a "sensitive field access behavior." Subsequently, this judgment result is bound to the request serial number to generate a field access compliance identification frame. This frame records the compliance status bit of the request. If a sensitive field is involved, the identification bit is activated, indicating that the access behavior must undergo mandatory desensitization and frequency verification before a response can be given.
[0052] S503: Invoke the access frequency limitation method in the field access compliance identification frame and access control handling content, extract the timestamp of the access request and the record time interval, determine whether the access frequency is lower than the minimum interval threshold, and jointly compare the access frequency, field access status and path judgment result to establish access control result; The final decision is made in conjunction with the access frequency limitation method in the access control handling content. The arrival timestamp of the current access request is extracted, and the time of the user's last successful request for this resource is retrieved from the cache.
[0053] The time interval between two accesses is calculated, and the absolute difference is extracted to be 1500 milliseconds. The minimum interval threshold of 5000 milliseconds set in S403 is used for judgment: since 1500 is less than 5000, the current access frequency is determined to be too high, constituting a frequency violation. The access frequency judgment result, field sensitivity flag, and path judgment result are jointly compared logically. Due to path restriction, field sensitivity, and frequency violation, an access control result is finally established, blocking this request and returning a frequency restriction response. This result achieves dynamic, multi-dimensional, and closed-loop control of electronic document access permissions, ensuring data security under unstable links.
[0054] The above description is merely a specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the technical scope disclosed in the present invention should be included within the scope of protection of the present invention. Therefore, the scope of protection of the present invention should be determined by the scope of the claims.
Claims
1. A dynamic access control method for electronic archive systems based on a zero-trust architecture, characterized in that, Includes the following steps: S1: Set up continuous measurement nodes in the electronic archive access link, collect the communication signal strength difference, direction change number and maximum jump amplitude per unit time, construct the access link disturbance sample sequence, calculate the fluctuation order in the access link disturbance sample sequence, and generate the access link fluctuation sequence. S2: Based on the access link fluctuation sequence, obtain the handshake response delay, path hop count change and connection hold period of the communication nodes in the path, analyze the downward trend of connection stability in the communication nodes, and generate access connection description content; S3: Call the access link fluctuation sequence and the access connection description, compare the disturbance frequency, connection interruption status and the number of inconsistent nodes, and generate an access restriction classification based on preset judgment rules; S4: Based on the restriction level in the access restriction category, filter the resource directory, adjust the field masking method, set the minimum access request interval, and generate access control processing content; S5: Invoke the resource directory filtering results, field masking methods, and request interval restriction methods in the access control processing content to determine whether the resources in the access request meet the restrictions of the access control processing content, and output the access permission control results.
2. The dynamic access control method for an electronic archive system based on a zero-trust architecture according to claim 1, characterized in that, The access link fluctuation sequence includes signal strength difference sequence, direction change frequency, maximum jump amplitude value, and timing fluctuation pattern. The access connection description includes handshake delay distribution, path hop count fluctuation characteristics, connection hold period interval, and stability degradation index. The access restriction classification includes disturbance level category, connection anomaly level, and node consistency level. The access control processing content includes resource directory filtering items, field masking rules, and minimum access interval setting. The access permission control result includes resource request compliance status, access policy matching status, and permission judgment level.
3. The dynamic access control method for an electronic archive system based on a zero-trust architecture according to claim 1, characterized in that, The preset judgment rule refers to a set of standardized rules that compare and analyze the disturbance characteristics and connection status of the access link to determine the access restriction level.
4. The dynamic access control method for an electronic archive system based on a zero-trust architecture according to claim 1, characterized in that, The access control measures mentioned refer to the resource access conditions set based on the access restriction level, including restrictions such as resource filtering, field masking, and minimum request interval.
5. The dynamic access control method for an electronic archive system based on a zero-trust architecture according to claim 1, characterized in that, The specific steps of S1 are as follows: S101: Obtain continuous measurement nodes in the electronic archive access link, record the communication signal strength of the nodes per unit time, calculate the strength difference between adjacent nodes, and combine it with the node sequence to generate a communication signal strength difference sequence. S102: Based on the communication signal strength difference sequence, determine the direction of node signal change, count the number of directional changes per unit time, and generate a sequence of directional change count indicators by combining the node time index; S103: Based on the communication signal strength difference sequence and the direction change number index sequence, extract the maximum jump amplitude of the node, aggregate them into a disturbance sample sequence, analyze the time-series fluctuation characteristics, and generate an access link fluctuation sequence.
6. The dynamic access control method for an electronic archive system based on a zero-trust architecture according to claim 1, characterized in that, The specific steps of S2 are as follows: S201: Based on the access link fluctuation sequence, call the handshake request and response delay records of the communication nodes in the path, measure the interval of the request and response time within the same access period, extract the response time difference between nodes, and aggregate it with the corresponding node index to generate a handshake response delay sequence. S202: Based on the handshake response delay sequence, call the path hop count change record in each access cycle, extract the hop count fluctuation value in consecutive access cycles, compare whether the hop count change trend is continuously offset, and generate a structured data frame by combining the access time index to obtain the path hop count change trend sequence. S203: Call the path hop count change trend sequence and the handshake response delay sequence, retrieve the connection hold time parameter within the corresponding period, perform a pairing judgment on the correlation between the connection hold period and the hop count fluctuation trend, if the connection hold time decreases and the hop count changes frequently within a continuous period, then aggregate the corresponding period and link identifier to generate access connection description content.
7. The dynamic access control method for an electronic archive system based on a zero-trust architecture according to claim 1, characterized in that, The specific steps for S3 are as follows: S301: Call the access link fluctuation sequence and the access connection description content, extract the number of disturbance events recorded by each access link in a unit time, calculate the frequency of disturbance events during the access process, and aggregate the frequency results with the link identifier to generate a disturbance frequency index set; S302: Based on the access connection description, retrieve connection interruption records within the continuous access period, extract the number of connection interruptions and the duration of interruptions, determine whether there is a situation that exceeds the preset connection interruption threshold, extract the number of periodic node differences in combination with node distribution information, and generate a connection anomaly feature matrix. S303: Based on the disturbance frequency index set and the connection anomaly feature matrix, set the disturbance frequency threshold, connection interruption threshold and node difference number threshold as preset conditions, perform condition matching on the index combination of each access link, and perform classification marking on the access links that meet the differentiation level standard to establish access restriction classification.
8. The dynamic access control method for an electronic archive system based on a zero-trust architecture according to claim 1, characterized in that, The specific steps of S4 are as follows: S401: Based on the restriction level information in the access restriction classification, filter target resource directories with restriction levels not lower than the access classification threshold, bind the resource identifier of the corresponding directory with the restriction level, and establish a target resource mapping set; S402: Call the target resource mapping set, retrieve the associated field details, compare and judge the field type and restriction level, and perform field masking policy rule matching according to the masking policy parameters set by the field sensitivity level to obtain the field masking configuration parameter group. S403: Based on the field masking configuration parameter group and the target resource mapping set, set an access request interval control strategy for each resource record, extract the access interval threshold parameter corresponding to the restriction level, establish an access restriction control frame by combining the masking configuration and the directory mapping, and summarize the access control processing content.
9. The dynamic access control method for an electronic archive system based on a zero-trust architecture according to claim 1, characterized in that, The specific steps of S5 are as follows: S501: Call the directory filtering results in the access control processing content, parse the resource path identifier contained in the access request, match it with the filtered directory path, if the path exists in the filtering results, mark it as an accessible directory, otherwise mark it as a prohibited access path, and generate a path access judgment result set. S502: Based on the path access judgment result set and the field masking method in the access control processing content, extract the field content in the request, and match and judge whether the corresponding field is a masked field. If the access field is a masked field, mark it as a sensitive field access behavior and generate a field access compliance identification frame. S503: Invoke the access compliance identification frame of the field and the access frequency limitation method in the access control handling content, extract the timestamp of the access request and the record time interval, determine whether the access frequency is lower than the minimum interval threshold, and jointly compare the access frequency, field access status and path judgment result to establish access control result.
10. The dynamic access control method for an electronic archive system based on a zero-trust architecture according to claim 1, characterized in that, The minimum interval threshold refers to the shortest time interval between consecutive requests to access the same resource.