A data security access control and privacy protection intelligent system in a cloud-native environment

CN122389057BActive Publication Date: 2026-09-11BEIJING GUOKE DATA SECURITY TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202610521309.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-04-20
Publication Date
2026-09-11
Estimated Expiration
2046-04-20

AI Technical Summary

Technical Problem

[0004]本发明的目的在于提供一种云原生环境下数据安全访问控制与隐私保护智能系统,以解决上述背景技术中提出的现有技术缺乏统一的风险驱动决策中枢,无法在隐私预算约束下将隐私消耗状态与风险度量深度融合、并基于融合后的风险等级同步驱动身份认证、数据隐私保护及审计合规策略动态适配,导致安全策略调整滞后于风险变化的问题

Benefits of technology

1.本发明通过安全感知与决策单元内置基于隐私预算约束的安全感知机制,由隐私预算管理模块设定隐私暴露上限阈值,数据采集模块根据实时风险等级在隐私暴露上限阈值约束下动态适配采集粒度,低风险状态采用最小化采集策略,中风险状态采用特征级采集策略,高风险状态在授权前提下采用增强采集策略,风险解除后自动回落采集粒度。同时,隐私预算管理模块对累计隐私消耗值进行实时监测,当累计隐私消耗值超过隐私暴露上限阈值时输出采集粒度抑制指令,确保数据采集行为始终处于隐私暴露上限约束范围内。由此建立了统一的风险驱动决策中枢,实现了隐私消耗状态与风险度量的深度融合,以及隐私保护约束下的风险自适应采集;

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122389057B_ABST
    Figure CN122389057B_ABST
Patent Text Reader

Abstract

This invention relates to the field of data security technology, specifically to an intelligent system for data security access control and privacy protection in a cloud-native environment. It includes: an identity authentication and access control unit; a data privacy protection unit; a security awareness and decision-making unit; and a security audit and compliance unit. This invention employs a security awareness mechanism with built-in privacy budget constraints, setting a privacy exposure upper limit threshold. Data collection dynamically adapts its granularity based on real-time risk levels within the threshold constraints. Low-risk data uses a minimal collection strategy, medium-risk data uses a feature-level collection strategy, and high-risk data uses an enhanced collection strategy under authorization. Once the risk is eliminated, the collection granularity automatically decreases. The system monitors the cumulative privacy consumption value in real time, outputting a collection granularity suppression command when the limit is exceeded, ensuring that data collection always remains within the privacy exposure upper limit constraint range. This achieves deep integration of privacy consumption status and risk measurement, and risk-adaptive collection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data security technology, and more specifically, to an intelligent system for data security access control and privacy protection in a cloud-native environment. Background Technology

[0002] In cloud-native environments, the widespread adoption of technologies such as microservices, containers, and dynamic orchestration has complicated data access paths, made access subjects dynamic, and blurred resource boundaries, rendering traditional static security strategies inadequate to cope with real-time changes in risk profiles. To ensure data security and user privacy, comprehensive security solutions combining identity authentication, access control, data encryption, privacy protection, and security auditing have emerged. These solutions typically employ a modular architecture, implementing identity authentication, permission control, data anonymization, and log auditing functions separately, attempting to build a security protection system covering the entire data lifecycle. However, in existing solutions, the various security function modules are relatively independent, and policy configurations are mostly statically preset, lacking a unified linkage mechanism based on real-time risk awareness. This makes it difficult to adaptively adjust the strength and granularity of security policies as risks dynamically change.

[0003] In existing cloud-native security solutions, authentication strength, access granularity, privacy protection policies, and audit scope all rely on pre-configured static rules. Each security module operates independently, lacking a core decision-making mechanism capable of real-time risk awareness and dynamically outputting risk levels under privacy budget constraints to uniformly drive collaborative adjustments across security modules. Specifically, existing technologies cannot establish privacy exposure limits during data collection while deeply integrating privacy consumption status with risk measurement. Furthermore, they struggle to dynamically adapt authentication, data privacy protection, and audit compliance policies based on the integrated risk level, resulting in security policy adjustments lagging behind risk changes and an inability to achieve a dynamic balance between protection capabilities and system efficiency. Therefore, we propose an intelligent system for data security access control and privacy protection in a cloud-native environment. Summary of the Invention

[0004] The purpose of this invention is to provide an intelligent system for data security access control and privacy protection in a cloud-native environment, in order to solve the problem mentioned in the background that the existing technology lacks a unified risk-driven decision-making center, cannot deeply integrate privacy consumption status with risk measurement under privacy budget constraints, and cannot synchronously drive identity authentication, data privacy protection and audit compliance strategies dynamically based on the integrated risk level, resulting in security policy adjustments lagging behind risk changes.

[0005] To address the aforementioned technical problems, the present invention aims to provide an intelligent system for data security access control and privacy protection in a cloud-native environment, comprising: The identity authentication and access control unit authenticates all access subjects in the cloud-native environment, performs fine-grained access control, implements the principle of least privilege, prevents unauthorized subjects from accessing data resources, and receives the risk level output by the security awareness and decision-making unit to dynamically adjust the identity authentication strength and access granularity. The data privacy protection unit implements privacy protection throughout the entire process of data collection, transmission, storage, processing, and destruction, controls access to and exposure of sensitive data, receives the risk level output by the security awareness and decision-making unit, and dynamically adjusts the data protection strategy. The security perception and decision-making unit has a built-in security perception mechanism based on privacy budget constraints. It dynamically adapts the data collection granularity according to the real-time risk level. In the low-risk state, it adopts a minimum collection strategy; in the medium-risk state, it adopts a feature-level collection strategy; and in the high-risk state, it adopts an enhanced collection strategy under the premise of authorization and simultaneously performs sensitive data privacy enhancement processing. After the risk is eliminated, it automatically reduces the collection granularity, collects security-related data of the cloud-native environment, identifies security anomalies and risks, dynamically adjusts the security strategy, and outputs the risk level to the identity authentication and access control unit, the data privacy protection unit, and the security audit and compliance unit. The security audit and compliance unit collects data access operation logs, performs compliance verification and behavior tracing, receives the risk level output by the security perception and decision-making unit, and dynamically adjusts the log collection scope and compliance verification strategy.

[0006] As a further improvement to this technical solution, the identity authentication and access control unit includes a risk data receiving module, an identity authentication module, an access control module, and an access interception module, wherein: The risk data receiving module is used to receive the risk level output by the security perception and decision-making unit, and synchronize the risk level to the identity authentication module and the access control module respectively. The identity authentication module is used to authenticate the identities of all access subjects in the cloud-native environment and dynamically adjust the identity authentication strength according to the received risk level. The access control module is used to perform fine-grained access control on access subjects that have completed identity authentication, implement the principle of least privilege, and dynamically adjust the granularity of access permissions according to the received risk level; The access interception module is used to intercept access by unauthenticated entities and access behaviors that exceed the scope of access permissions, thereby preventing unauthorized entities from accessing data resources.

[0007] As a further improvement to this technical solution, the data privacy protection unit includes a risk policy receiving module, a data classification and discovery module, a privacy policy execution module, and a privacy enhancement processing module, wherein: The risk policy receiving module is used to receive the risk level output by the security perception and decision-making unit, and synchronize the risk level to the privacy policy execution module and the privacy enhancement processing module. The data classification and discovery module is used to automatically scan, identify, and classify data in the cloud-native environment, and mark sensitive data levels. The privacy policy execution module dynamically adapts and executes corresponding data protection policies throughout the entire process of data collection, transmission, storage, processing, and destruction, based on the sensitive data level output by the data classification and discovery module and the risk level synchronized by the risk policy receiving module. The privacy enhancement processing module calls the corresponding privacy computing or de-identification technology to perform privacy enhancement processing on sensitive data based on the risk level synchronized by the risk policy receiving module, so as to control the access and exposure of sensitive data.

[0008] As a further improvement to this technical solution, the security perception and decision-making unit includes a privacy budget management module, a data acquisition module, a security anomaly identification module, a risk level determination module, a security policy adjustment module, and a risk level output module, wherein: The privacy budget management module is used to establish and maintain a privacy budget constraint mechanism, set a privacy exposure upper limit threshold, and provide a core constraint basis for adjusting the collection granularity of the data collection module. The data acquisition module is used to collect security-related data in the cloud-native environment. Based on the real-time risk level output by the risk level determination module, the acquisition granularity is dynamically adapted within the constraint threshold set by the privacy budget management module. The security anomaly identification module is used to analyze the cloud-native environment security-related data collected by the data acquisition module, identify security anomalies and potential risks, and output the anomaly identification results to the risk level determination module. The risk level determination module obtains the privacy budget usage information output by the privacy budget management module, and determines the real-time risk level based on the anomaly identification results output by the security anomaly identification module and the privacy budget usage information, and synchronizes the real-time risk level to the data acquisition module, security policy adjustment module and risk level output module. The security policy adjustment module dynamically adjusts the security policy based on the real-time risk level output by the risk level determination module, and synchronously adapts to the associated policies of data collection, privacy protection, identity authentication and audit compliance. The risk level output module is used to receive the real-time risk level output by the risk level determination module and output it synchronously to the identity authentication and access control unit, the data privacy protection unit, and the security audit and compliance unit.

[0009] As a further improvement to this technical solution, the privacy budget constraint execution process of the privacy budget management module includes the following steps: S31.1 Privacy Budget Initialization: Preset privacy exposure limits for data collection activities in cloud-native environments. And establish an initial allocation strategy for a privacy budget, which is used to quantify the degree of exposure of sensitive information during data collection; S31.2 Privacy Budget Consumption Monitoring: Under uniform discrete sampling time, the actual data acquisition behavior of the real-time data acquisition module at each acquisition granularity is monitored. Based on the unit privacy consumption coefficient and execution status of each type of data acquisition operation, the cumulative privacy consumption value is calculated. ; Accumulated privacy consumption value With privacy exposure limit threshold Compare data to generate a privacy budget usage status; S31.3, Privacy Budget Constraint Execution: Based on the privacy budget usage status generated in step S31.2, when the accumulated privacy consumption value... Exceeding the privacy exposure limit threshold Furthermore, when the excess reaches a preset hysteresis threshold, a data acquisition granularity suppression command is output to the data acquisition module, restricting the data acquisition module from switching to a higher acquisition granularity or forcibly maintaining the current acquisition granularity until the privacy budget reset cycle is reached or the accumulated privacy consumption value is reached. Fall back to below the privacy exposure limit threshold .

[0010] As a further improvement to this technical solution, the data acquisition module includes an acquisition granularity controller submodule, an acquisition actuator submodule, and a data preprocessing submodule, wherein: The data collection granularity controller submodule is used to receive the real-time risk level output by the risk level determination module, and dynamically select the current data collection strategy from the preset data collection strategy set under the privacy exposure upper limit threshold constraint set by the privacy budget management module. The preset data collection strategy set includes the minimum data collection strategy, the feature-level data collection strategy, and the enhanced data collection strategy. Different data collection strategies correspond to different sets of data collection fields and collection frequencies. The acquisition executor submodule is used to acquire security-related data from the cloud-native environment and generate raw acquisition data according to the current acquisition strategy selected by the acquisition granularity controller submodule. The data preprocessing submodule is used to normalize the format and filter sensitive information of the raw acquisition data output by the acquisition actuator submodule, and then send the processed data to the security anomaly identification module.

[0011] As a further improvement to this technical solution, the security anomaly identification and risk feature extraction process of the security anomaly identification module includes the following steps: S33.1, Establishment of Behavioral Baselines: Based on historical data collection, establish a normal behavioral baseline model in the cloud-native environment. The normal behavioral baseline model includes access behavior baseline, resource call baseline and network traffic baseline. Each baseline model is characterized by statistical distribution parameters, including the mean and standard deviation of each behavioral dimension. S33.2 Anomaly Detection: Compare the current security-related data collected by the data acquisition module with the normal behavior baseline model established in step S33.1, and calculate the deviation of each behavioral dimension. The deviation Used to quantify the degree of deviation between the current observation value and the baseline value; the deviation of each behavioral dimension is weighted and comprehensively judged to generate anomaly detection results, which include anomaly type, anomaly degree value and anomaly occurrence timestamp; S33.3 Risk Feature Extraction: Extract features from the anomaly detection results generated in step S33.2, aggregate the deviation of each behavioral dimension according to the time window, generate a structured risk feature vector, and output the structured risk feature vector to the risk level determination module.

[0012] As a further improvement to this technical solution, the risk level determination and output process of the risk level determination module includes the following steps: S34.1 Risk Feature Aggregation: Receives the structured risk feature vector output by the security anomaly identification module, weights and aggregates the deviations of each behavioral dimension, and generates a comprehensive risk metric. ; S34.2 Privacy Budget Integration: Obtain the privacy budget usage status output by the privacy budget management module and accumulate the privacy consumption value. With privacy exposure limit threshold The proportion is used as a constraint factor, and the comprehensive risk measure is adjusted based on this proportion. Perform amplification corrections to generate a corrected risk metric. ; S34.3, Risk Level Mapping: A built-in risk level mapping table defines the correspondence between multiple risk measurement threshold ranges and risk levels. The risk level mapping table is adjusted based on the risk measurement values. The threshold range into which the risk falls is output as a corresponding real-time risk level, which includes at least low risk, medium risk and high risk levels.

[0013] As a further improvement to this technical solution, the process of security policy linkage adjustment and distribution of the security policy adjustment module includes the following steps: S35.1, Policy Linkage Instruction Generation: Receives the real-time risk level output by the risk level determination module, and generates identity authentication policy adjustment instructions, access permission policy adjustment instructions, data protection policy adjustment instructions, and audit policy adjustment instructions that match the real-time risk level according to the preset policy linkage mapping relationship, forming a set of adjustment instructions; S35.2 Strategy Conflict Detection: Conflict detection is performed on the set of adjustment instructions generated in step S35.1. The conflict types include mutual exclusion conflict and parameter conflict. When a logical conflict is detected in the set of adjustment instructions, the adjustment instructions are corrected according to the preset conflict resolution rules to generate a set of conflict-free strategy adjustment instructions. S35.3 Policy Distribution: The set of conflict-free policy adjustment instructions generated in step S35.2 is distributed to the identity authentication and access control unit, the data privacy protection unit, and the security audit and compliance unit, respectively, triggering the identity authentication and access control unit, the data privacy protection unit, and the security audit and compliance unit to execute policy changes.

[0014] As a further improvement to this technical solution, the security audit and compliance unit includes a risk level receiving module, a log collection module, a compliance verification module, and a behavior tracing module, wherein: The risk level receiving module is used to receive the risk level output by the security perception and decision-making unit, and synchronize the risk level to the log collection module and the compliance verification module respectively. The log collection module is used to collect data access operation logs and dynamically adjusts the log collection range according to the risk level synchronized by the risk level receiving module. The compliance verification module is used to perform compliance verification on data access operations and dynamically adjusts the compliance verification strategy according to the risk level synchronized by the risk level receiving module. The behavior tracing module performs behavior tracing based on the data access operation logs collected by the log collection module and the compliance verification results of the compliance verification module, and generates tracing records.

[0015] Compared with the prior art, the beneficial effects of the present invention are as follows: 1. This invention establishes a privacy budget-constrained security awareness mechanism within the security awareness and decision-making unit. The privacy budget management module sets a privacy exposure cap threshold, and the data acquisition module dynamically adapts the acquisition granularity based on the real-time risk level within this threshold constraint. A minimal acquisition strategy is used in low-risk states, a feature-level acquisition strategy in medium-risk states, and an enhanced acquisition strategy in high-risk states with authorization. Once the risk is eliminated, the acquisition granularity automatically decreases. Simultaneously, the privacy budget management module monitors the cumulative privacy consumption value in real time. When the cumulative privacy consumption value exceeds the privacy exposure cap threshold, it outputs an acquisition granularity suppression command, ensuring that data acquisition always remains within the privacy exposure cap constraint range. This establishes a unified risk-driven decision-making center, achieving deep integration of privacy consumption status and risk measurement, as well as risk-adaptive acquisition under privacy protection constraints. 2. In this invention, the security perception and decision-making unit synchronously outputs the real-time risk level to the identity authentication and access control unit, the data privacy protection unit, and the security audit and compliance unit. The identity authentication and access control unit dynamically adjusts the authentication strength and access permission granularity based on the risk level; the data privacy protection unit dynamically adapts data protection strategies throughout the entire process of data collection, transmission, storage, processing, and destruction based on the risk level, and invokes privacy enhancement processing technology to control access to and exposure of sensitive data; the security audit and compliance unit dynamically adjusts the log collection scope and compliance verification strategies based on the risk level. This achieves collaborative linkage and dynamic adaptive adjustment of the four major security functions—identity authentication, access control, privacy protection, and audit compliance—based on a unified risk level, solving the problem of security policy adjustments lagging behind risk changes. Attached Figure Description

[0016] Figure 1 This is a schematic diagram of the system framework of the present invention; The meanings of the labels in the diagram are as follows: 1. Identity authentication and access control unit; 11. Risk data receiving module; 12. Identity authentication module; 13. Access control module; 14. Access interception module; 2. Data privacy protection unit; 21. Risk policy receiving module; 22. Data classification and discovery module; 23. Privacy policy enforcement module; 24. Privacy enhancement processing module; 3. Security Awareness and Decision-Making Unit; 31. Privacy Budget Management Module; 32. Data Acquisition Module; 33. Security Anomaly Identification Module; 34. Risk Level Determination Module; 35. Security Policy Adjustment Module; 36. Risk Level Output Module; 4. Security Audit and Compliance Unit; 41. Risk Level Receiving Module; 42. Log Collection Module; 43. Compliance Verification Module; 44. Behavior Traceability Module. Detailed Implementation

[0017] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present invention.

[0018] like Figure 1 As shown, this embodiment provides an intelligent system for data security access control and privacy protection in a cloud-native environment, including: Identity Authentication and Access Control Unit 1 authenticates all access subjects in the cloud-native environment, performs fine-grained access control, implements the principle of least privilege, prevents unauthorized subjects from accessing data resources, and receives the risk level output by Security Awareness and Decision Unit 3 to dynamically adjust the identity authentication strength and access granularity. In this embodiment, the identity authentication and access control unit 1 includes a risk data receiving module 11, an identity authentication module 12, an access control module 13, and an access interception module 14, wherein: The risk data receiving module 11 is used to receive the risk level output by the security perception and decision-making unit 3, and synchronize the risk level to the identity authentication module 12 and the access control module 13 respectively. Specifically, the input interface of the risk data receiving module 11 is connected to the security perception and decision-making unit 3, and receives the risk level output by the security perception and decision-making unit 3 in real time. The risk data receiving module 11 stores the current risk level status variable and synchronizes the received risk level to the identity authentication module 12 and the access control module 13 through the internal bus, respectively, to ensure that the identity authentication module 12 and the access control module 13 use the same risk level for policy adjustment.

[0019] The identity authentication module 12 is used to authenticate the identities of all access subjects in the cloud-native environment and dynamically adjust the identity authentication strength according to the received risk level. Specifically, the identity authentication module 12 is used to authenticate the identities of all access subjects in the cloud-native environment. The identity authentication module 12 has pre-defined multi-level authentication policies, including basic authentication policies, enhanced authentication policies, and strengthened authentication policies. Among them: The identity authentication module 12 dynamically adjusts the identity authentication strength according to the risk level synchronized by the risk data receiving module 11. When the risk level is low, a basic authentication strategy is adopted, requiring the access subject to provide a single authentication factor for authentication. When the risk level is medium, an enhanced authentication strategy is adopted, requiring the access subject to provide at least two different types of authentication factors for authentication. When the risk level is high, an enhanced authentication strategy is adopted, requiring the access subject to provide all preset authentication factors and additionally performing dynamic verification code verification or biometric verification.

[0020] Meanwhile, the identity authentication module 12 verifies the authentication credentials submitted by the access subject. If the authentication is successful, the access subject's identity information is transmitted to the access control module 13. If the authentication fails, an interception command is output to the access interception module 14.

[0021] Access control module 13 is used to perform fine-grained access control on access subjects that have completed identity authentication, implement the principle of least privilege, and dynamically adjust the granularity of access permissions according to the received risk level; Specifically, the access control module 13 has a built-in role-based access control policy library and dynamically adjusts the granularity of access permissions based on the risk level synchronized by the risk data receiving module 11. When the risk level is low, the access control module 13 adopts the conventional permission granularity and grants the access subject the corresponding data access permission according to the preset role permission table. When the risk level is medium risk, the access control module 13 adopts a reduced permission granularity, restricting the access subject's access to sensitive data fields based on the preset role permission table; When the risk level is high, the access control module 13 adopts the minimum permission granularity, granting only the access subject the minimum operation permissions necessary to perform core business.

[0022] Furthermore, after receiving the access subject's identity information from the identity authentication module 12, the access control module 13 determines the actual set of permissions for the access subject based on the risk level, generates a permission determination result, and synchronizes it to the access interception module 14.

[0023] The access interception module 14 is used to intercept access actions by unauthenticated subjects or those exceeding the scope of access permissions, thereby preventing unauthorized subjects from accessing data resources.

[0024] Specifically, the access interception module 14 is deployed in the data access request processing chain to intercept access actions by unauthenticated subjects or those exceeding the scope of access permissions, preventing unauthorized subjects from accessing data resources. The access interception module 14 receives authentication failure interception instructions output by the authentication module 12 and permission determination results output by the access permission control module 13.

[0025] Furthermore, when the authentication failure interception command is triggered, the access interception module 14 blocks the access request and returns an authentication failure response; when authentication is successful but the operation requested by the access subject exceeds the actual permission set determined by the access control module 13, the access interception module 14 blocks the access operation and records the unauthorized access log.

[0026] Data privacy protection unit 2 implements privacy protection throughout the entire process of data collection, transmission, storage, processing and destruction, controls access to and exposure of sensitive data, and receives the risk level output by security awareness and decision-making unit 3 to dynamically adjust data protection strategies. In this embodiment, the data privacy protection unit 2 includes a risk policy receiving module 21, a data classification and discovery module 22, a privacy policy execution module 23, and a privacy enhancement processing module 24, wherein: The risk policy receiving module 21 is used to receive the risk level output by the security perception and decision-making unit 3, and synchronize the risk level to the privacy policy execution module 23 and the privacy enhancement processing module 24. Specifically, the input interface of the risk policy receiving module 21 is connected to the security perception and decision-making unit 3, and receives the risk level output by the security perception and decision-making unit 3 in real time. The risk policy receiving module 21 synchronizes the received risk level to the privacy policy execution module 23 and the privacy enhancement processing module 24 respectively, ensuring that the privacy policy execution module 23 and the privacy enhancement processing module 24 use the same risk level to adjust the data protection policy.

[0027] The data classification and discovery module 22 is used to automatically scan, identify and classify data in the cloud-native environment, and mark sensitive data levels; Specifically, the data classification and discovery module 22 periodically scans storage resources in the cloud-native environment to identify sensitive information in structured and unstructured data, including personal identification information, account credentials, and key business data. The data classification and discovery module 22 divides the data into different sensitive data levels according to preset classification rules, including public level, internal level, sensitive level, and highly sensitive level, and outputs the marked sensitive data levels to the privacy policy execution module 23.

[0028] The privacy policy execution module 23 dynamically adapts and executes corresponding data protection policies throughout the entire process of data collection, transmission, storage, processing, and destruction, based on the sensitive data level output by the data classification and discovery module 22 and the risk level synchronized by the risk policy receiving module 21. Specifically, the privacy policy execution module 23 has built-in policy matching logic. Based on the combination of sensitive data level and risk level, it selects the corresponding protection policy combination from the preset data protection policy set. The specific implementation is as follows: When the sensitive data is classified as public, the privacy policy enforcement module 23 adopts a basic protection policy and does not perform additional encryption or desensitization processing on the data. When the sensitive data level is internal, the privacy policy execution module 23 adopts a transmission encryption strategy and enables transport layer security protocol encryption for the data transmission channel. When the sensitive data is at the sensitive level, the privacy policy execution module 23 adopts a storage encryption strategy to enable field-level encryption or file-level encryption on the data storage medium. When the sensitive data is classified as highly sensitive, the privacy policy execution module 23 adopts a full-link encryption strategy, enabling encryption protection in all stages of data collection, transmission, storage, and processing, and performing a secure erasure operation when the data is destroyed.

[0029] Meanwhile, the privacy policy enforcement module 23 dynamically adjusts the strength of the protection policy based on the risk level synchronized by the risk policy receiving module 21, as specifically implemented as follows: When the risk level is medium risk, the privacy policy enforcement module 23 adds access frequency restrictions and abnormal behavior monitoring on the basis of the protection policy corresponding to the established sensitive data level. When the risk level is high, the privacy policy enforcement module 23 additionally enables the data access approval process and real-time blocking mechanism on the basis of the protection policy corresponding to the established sensitive data level.

[0030] Based on the risk level synchronized by the risk policy receiving module 21, the privacy enhancement processing module 24 invokes the corresponding privacy computing or de-identification technology to perform privacy enhancement processing on sensitive data in order to control access to and exposure of sensitive data.

[0031] Specifically, the privacy enhancement processing module 24 has a built-in set of privacy enhancement processing strategies. It dynamically selects the corresponding processing method based on the risk level synchronized by the risk strategy receiving module 21. The specific implementation is as follows: When the risk level is low, the privacy enhancement processing module 24 adopts static desensitization processing, performs fixed rule desensitization operation on sensitive data in non-production environment, replaces or masks sensitive fields according to preset desensitization rules, and generates desensitized datasets for non-production scenarios. When the risk level is medium risk, the privacy enhancement processing module 24 adopts dynamic desensitization processing, performs real-time desensitization operation in the data access response stage of the production environment, dynamically desensitizes sensitive fields in the returned data according to the access subject's permission level, and outputs masking symbols or null values ​​for sensitive fields that are not authorized to be accessed. When the risk level is high, the privacy enhancement processing module 24 uses differential privacy processing or homomorphic encryption processing to add random noise that meets the requirements of differential privacy budget to the data query results, or to perform homomorphic encryption calculation on the encrypted data, so as to prevent the leakage of sensitive information while ensuring data availability.

[0032] Furthermore, the privacy enhancement processing module 24 returns the privacy-enhanced data to the data access requester or transmits it to other processing stages within the data privacy protection unit 2, thereby achieving refined control over access to and exposure of sensitive data.

[0033] Security Awareness and Decision-Making Unit 3 has a built-in security awareness mechanism based on privacy budget constraints. It dynamically adapts the data collection granularity according to the real-time risk level. In low-risk situations, it employs a minimal collection strategy; in medium-risk situations, it uses a feature-level collection strategy; and in high-risk situations, under authorized conditions, it employs an enhanced collection strategy and simultaneously performs sensitive data privacy enhancement processing. After the risk is eliminated, the collection granularity automatically reverts. It collects security-related data for the cloud-native environment, identifies security anomalies and risks, dynamically adjusts security policies, and outputs the risk level to the Identity Authentication and Access Control Unit 1, Data Privacy Protection Unit 2, and Security Audit and Compliance Unit 4. Security Awareness and Decision-Making Unit 3 includes a privacy budget management module 31, a data collection module 32, a security anomaly identification module 33, a risk level determination module 34, a security policy adjustment module 35, and a risk level output module 36, among which: In this embodiment, the privacy budget management module 31 is used to establish and maintain a privacy budget constraint mechanism, set a privacy exposure upper limit threshold, and provide a core constraint basis for adjusting the collection granularity of the data collection module 32; the privacy budget constraint execution process of the privacy budget management module 31 includes the following steps: S31.1 Privacy Budget Initialization: Preset privacy exposure limits for data collection activities in cloud-native environments. And establish an initial allocation strategy for the privacy budget, which is used to quantify the degree of exposure of sensitive information during the data collection process; Specifically, the privacy budget management module 31 performs the privacy budget initialization as follows: The privacy budget management module 31 loads preset privacy exposure limit thresholds from the configuration center when the system starts up. Privacy exposure limit threshold A positive number indicates the maximum allowed total privacy consumption within a privacy budget reset cycle. The privacy budget reset cycle is a preset fixed time period, such as 24 hours, or dynamically configured by the administrator based on the system's operational phase, used to periodically reset the accumulated privacy consumption value. This is to avoid the privacy budget being overrun for an extended period, which could negatively impact data collection capabilities.

[0034] Meanwhile, the privacy budget management module 31 configures corresponding initial values ​​for unit privacy consumption coefficients for various data collection operations based on the data collection service type in the cloud-native environment. The unit privacy consumption coefficient characterizes the degree of privacy budget consumption in a single execution of this type of data collection operation; where the unit privacy consumption coefficient (i.e., in S31.2) The setting of privacy consumption coefficient is based on the following: it is positively correlated with the number of sensitive data fields, the level of sensitive data and the number of data subjects involved in a single data collection operation. For collection operations that do not involve sensitive data, the unit privacy consumption coefficient is set to 0. For collection operations that involve sensitive data, the unit privacy consumption coefficient is determined by a preset privacy sensitivity mapping table. This mapping table maps different levels of sensitive data to corresponding privacy consumption weight values ​​according to the level of sensitive data output by the data classification and discovery module 22.

[0035] Finally, the privacy budget management module 31 initializes the privacy exposure cap threshold. The unit privacy consumption coefficients for each type of data collection operation are stored in memory as a basis for subsequent privacy budget consumption monitoring.

[0036] S31.2 Privacy Budget Consumption Monitoring: Under uniform discrete sampling time, the actual data acquisition behavior of the real-time data acquisition module 32 at each acquisition granularity is collected. Based on the unit privacy consumption coefficient and execution status of each type of data acquisition operation, the cumulative privacy consumption value is calculated. ; Accumulated privacy consumption value With privacy exposure limit threshold Compare data to generate a privacy budget usage status; Specifically, the privacy budget management module 31 performs privacy budget consumption monitoring as follows: The privacy budget management module 31 proactively requests execution status logs for various data acquisition operations from the data acquisition module 32 via the internal data bus at a fixed sampling period, or the data acquisition module 32 asynchronously pushes the execution logs to the privacy budget management module 31 after each acquisition operation. The execution logs include at least the operation type identifier, execution timestamp, and acquisition granularity information. Based on the received logs, the privacy budget management module 31 identifies the execution status of data acquisition operations at each sampling moment within the current privacy budget reset period. The cumulative privacy consumption value is then calculated. The calculation formula is: ; in, This represents the total number of sampling moments within the privacy budget reset period, with the sampling interval set to 1. The privacy budget reset cycle length is ,but ; Indicates the sampling time index; Indicates the total number of data acquisition operation types; Indicates the index of the data acquisition operation type; Indicates the first The unit privacy consumption coefficient corresponding to the data collection operation; Indicates at the sampling time Within the sampling interval, the first The actual number of times a data collection operation is executed is a non-negative integer. When an operation of a certain type is executed multiple times within the sampling interval, the number of executions is accumulated and included in the privacy consumption.

[0037] Furthermore, the privacy budget management module 31 iterates through the execution records at each sampling time within the current privacy budget reset cycle, and checks the execution status... The data collection operations accumulate their corresponding unit privacy consumption coefficients. Receive cumulative privacy consumption value .

[0038] Finally, the privacy budget management module 31 records the cumulative privacy consumption value in real time. With privacy exposure limit threshold The comparison results generate a privacy budget usage status, which includes an unexceeded status and an exceeded status.

[0039] The calculation example is as follows: Assuming the total number of sampling times within the privacy budget reset period Total number of data acquisition operation types The unit privacy consumption coefficients for the three types of operations are respectively At a certain sampling time The execution states of the three types of operations are as follows: The privacy cost at that sampling time is... The privacy consumption values ​​at all 10 sampling times are summed to obtain the cumulative privacy consumption value. ; If privacy exposure upper limit threshold Then the privacy budget management module 31 continuously compares The relationship between the size of 15 and 15, when When the privacy budget usage status is not exceeded, The privacy budget usage status is currently in the over-limit state.

[0040] S31.3, Privacy Budget Constraint Execution: Based on the privacy budget usage status generated in step S31.2, when the accumulated privacy consumption value... Exceeding the privacy exposure limit threshold Furthermore, when the excess reaches a preset hysteresis threshold, a data acquisition granularity suppression command is output to the data acquisition module 32, restricting the data acquisition module 32 from switching to a higher acquisition granularity or forcibly maintaining the current acquisition granularity until the privacy budget reset cycle is reached or the accumulated privacy consumption value is reached. Fall back to below the privacy exposure limit threshold .

[0041] Specifically, the implementation of privacy budget constraint execution in privacy budget management module 31 is as follows: Privacy Budget Management Module 31: Setting a Lag Threshold hysteresis threshold This value is non-negative and is used to implement a hysteresis comparator mechanism, avoiding oscillations in the collection granularity caused by frequent fluctuations in the accumulated privacy consumption value around the privacy exposure upper limit threshold. The privacy budget management module 31 defines three constraint states: Not exceeding limits: Cumulative privacy consumption value This allows the data acquisition module 32 to switch the acquisition granularity normally according to the risk level; Excessive suppression status: Cumulative privacy consumption value Output a data acquisition granularity suppression command to the data acquisition module 32 to prevent switching to a higher acquisition granularity; Restore to the original state: The cumulative privacy consumption value meets the requirement. The constraint state from the previous moment remains unchanged.

[0042] The state transition rules are as follows: when the system is in a non-over-limit state and When the system is in an over-limit suppression state, it transitions to the over-limit suppression state; when the system is in the over-limit suppression state and When the limit is exceeded, the state transitions to the non-exceeded state; otherwise, the state remains unchanged.

[0043] Meanwhile, after receiving the acquisition granularity suppression command, the data acquisition module 32 prohibits the switching operation to a higher acquisition granularity; if the current acquisition granularity is higher than the minimum acquisition granularity, it forcibly maintains the current acquisition granularity unchanged until the acquisition granularity suppression is lifted.

[0044] Furthermore, the privacy budget management module 31 continuously monitors the cumulative privacy consumption value. When the privacy budget reset cycle arrives, the privacy budget management module 31 will accumulate the privacy consumption value. Reset to zero, restart the next cycle of privacy budget consumption monitoring, and remove the suppression of collection granularity; when the cumulative privacy consumption value... Falling back to At this time, the privacy budget management module 31 removes the suppression of collection granularity, allowing the data collection module 32 to switch the collection granularity normally according to the risk level.

[0045] The calculation example is as follows: Following the calculation example in S31.2, let's assume a privacy exposure cap threshold. hysteresis threshold When the cumulative privacy consumption value When it reaches 18, it meets the requirements. The privacy budget management module 31 outputs a collection granularity suppression command to the data collection module 32, prohibiting the data collection module 32 from switching to a higher collection granularity. In subsequent privacy consumption monitoring, if the privacy budget reset cycle is reached, the privacy budget management module 31 will accumulate the privacy consumption value. Resetting to zero will automatically release the suppression; if the accumulated privacy consumption value... When the data collection activity decreases and the value drops below 15, the privacy budget management module 31 also releases the suppression, allowing the data collection module 32 to resume normal collection granularity switching.

[0046] Finally, the privacy budget management module 31 will accumulate the privacy consumption value. Privacy exposure limit threshold The privacy budget usage status is also synchronized in real time to the risk level assessment module 34, serving as a constraint factor for risk level assessment.

[0047] In this embodiment, the data acquisition module 32 is used to collect security-related data of the cloud-native environment. Based on the real-time risk level output by the risk level determination module 34, and within the constraint threshold set by the privacy budget management module 31, the data acquisition granularity is dynamically adapted. The data acquisition module 32 includes a data acquisition granularity controller submodule, a data acquisition executor submodule, and a data preprocessing submodule, wherein: The data collection granularity controller submodule is used to receive the real-time risk level output by the risk level determination module 34, and under the privacy exposure upper limit threshold constraint set by the privacy budget management module 31, dynamically select the current data collection strategy from the preset data collection strategy set. The preset data collection strategy set includes the minimum data collection strategy, the feature-level data collection strategy, and the enhanced data collection strategy. Different data collection strategies correspond to different data collection field sets and collection frequencies. Specifically, the data collection granularity controller submodule acquires the real-time risk level output by the risk level determination module 34 and the privacy budget usage status output by the privacy budget management module 31. The data collection granularity controller submodule has built-in strategy selection logic that selects the corresponding data collection strategy from a preset set based on the combination of the real-time risk level and the privacy budget usage status. The specific implementation is as follows: When the real-time risk level is low and the privacy budget usage status is not exceeded, the collection granularity controller submodule selects the minimum collection strategy. The data collection field set corresponding to the minimum collection strategy only includes the core fields necessary for security monitoring, and the collection frequency is set to the lowest preset frequency value. When the real-time risk level is medium risk and the privacy budget usage status is not exceeded, the collection granularity controller submodule selects the feature-level collection strategy. The data collection field set corresponding to the feature-level collection strategy includes the core fields required for security monitoring and the key fields required for feature extraction. The collection frequency is set to a medium preset frequency value. When the real-time risk level is high and the privacy budget usage status is within limits, the collection granularity controller submodule first initiates an authorization verification request to the authorization management service to confirm that the current cloud-native environment or data subject has been granted high-risk collection permissions. If the authorization verification passes, an enhanced collection strategy is selected; if it fails, the current collection strategy remains unchanged, and an authorization failure log is recorded. The data collection field set corresponding to the enhanced collection strategy includes a complete set of security monitoring fields, and the collection frequency is set to the highest preset frequency value. When the privacy budget usage status is in the over-limit state, the collection granularity controller submodule receives the collection granularity suppression instruction output by the privacy budget management module 31, prohibiting the selection of a collection strategy with a higher granularity than the current collection strategy. If the current collection strategy is a feature-level collection strategy, then switching to an enhanced collection strategy is prohibited; if the current collection strategy is a minimal collection strategy, then the minimal collection strategy is maintained unchanged.

[0048] Finally, the acquisition granularity controller submodule passes the selected current acquisition strategy identifier to the acquisition executor submodule.

[0049] The data acquisition executor submodule is used to acquire security-related data from the cloud-native environment and generate raw data based on the current acquisition strategy selected by the data acquisition granularity controller submodule. Specifically, the acquisition executor submodule receives the current acquisition strategy identifier from the acquisition granularity controller submodule, and loads the data acquisition field set and acquisition frequency configuration corresponding to the acquisition strategy from the local configuration library. The specific implementation is as follows: The data collection executor submodule is configured according to the collection frequency and periodically collects security-related data from the cloud-native environment, including container runtime metrics, microservice call chain data, network traffic metadata, system call logs, access request records, etc.

[0050] For the minimal collection strategy, the collection executor submodule only collects data from the preset core field set, such as only collecting core security fields such as access subject identifier, operation type, timestamp, and operation result, while discarding extended fields and detailed payload content; For feature-level collection strategies, the collection executor submodule adds key fields required for feature extraction on the basis of core fields, such as request path, response status code, resource consumption indicators, user agent information and other feature fields; For the enhanced data collection strategy, the data collection executor submodule collects a complete set of security monitoring fields, including core fields, feature fields, detailed load content, complete request parameters, stack trace information, and other detailed data.

[0051] The data acquisition executor submodule packages the acquired data into raw data, adds a data acquisition timestamp and acquisition strategy identifier, and then passes it to the data preprocessing submodule.

[0052] The data preprocessing submodule is used to normalize the format and filter sensitive information of the raw acquisition data output by the acquisition actuator submodule, and then send the processed data to the security anomaly identification module 33.

[0053] Specifically, the data preprocessing submodule receives the raw acquired data output by the acquisition executor submodule. First, it performs format normalization processing, converting heterogeneous data from different data sources into a preset standard data format. Format normalization includes: converting different time formats to Unix timestamp format, converting different encoding methods to UTF-8 encoding, mapping different field naming conventions to preset field names, and flattening nested data structures into key-value pair structures.

[0054] Furthermore, after format normalization, the data preprocessing submodule performs sensitive information filtering. This submodule has a built-in sensitive information identification rule base to identify sensitive information that may be contained in the raw data, such as personal identification information, account credentials, and key materials. For the identified sensitive information, the data preprocessing submodule processes it according to preset filtering rules, as detailed below: When the sensitive information type is personal identity information, the data preprocessing submodule uses hash desensitization to replace the original sensitive value with an irreversible hash value. When the sensitive information type is account credentials or key materials, the data preprocessing submodule performs direct discard processing, removing the field from the collected data; When the sensitive information type is business sensitive data, the data preprocessing submodule uses masking to retain the first two and last two characters, and replaces the middle character with an asterisk.

[0055] Finally, the data preprocessing submodule encapsulates the data after format normalization and sensitive information filtering according to the data interface format preset by the security anomaly identification module 33, and transmits it to the security anomaly identification module 33 through the data channel as the input data source for security anomaly identification and risk feature extraction.

[0056] In this embodiment, the security anomaly identification module 33 is used to analyze the cloud-native environment security-related data collected by the data acquisition module 32, identify security anomalies and potential risks, and output the anomaly identification results to the risk level determination module 34; the security anomaly identification and risk feature extraction process of the security anomaly identification module 33 includes the following steps: S33.1, Establishing Behavioral Baselines: Based on historical data collection, establish normal behavioral baseline models in the cloud-native environment. The normal behavioral baseline models include access behavior baselines, resource call baselines, and network traffic baselines. Each baseline model is characterized by statistical distribution parameters, including the mean and standard deviation of each behavioral dimension. Specifically, the security anomaly identification module 33 retrieves historical data collected within a preset time window from the data storage. This historical data consists of security-related data collected during normal operation of the cloud-native environment, including access behavior data, resource call data, and network traffic data. The security anomaly identification module 33 performs statistical analysis on each behavioral dimension, calculating the mean and standard deviation of each dimension; the specific implementation is as follows: Let the first The set of historical observations for each behavioral dimension is ,in This represents the total number of historical observations. The mean of this behavioral dimension is then... and standard deviation The calculation formula is: ; ; in, Indicates the first The first behavioral dimension One historical observation value, Indicates the first The mean of each behavioral dimension, Indicates the first The standard deviation of each behavioral dimension.

[0057] Finally, the security anomaly identification module 33 calculates the mean values ​​of each behavioral dimension. and standard deviation The data is stored in the baseline model and used as a comparison benchmark for subsequent anomaly detection. After the behavioral baseline is established, the security anomaly identification module 33 enters the anomaly detection phase.

[0058] S33.2 Anomaly Detection: Compare the current security-related data collected by the data acquisition module 32 with the normal behavior baseline model established in step S33.1, and calculate the deviation of each behavioral dimension. , deviation degree Used to quantify the degree of deviation between the current observation and the baseline value; the deviation of each behavioral dimension is weighted and comprehensively judged to generate anomaly detection results, which include anomaly type, anomaly degree value and anomaly occurrence timestamp; Specifically, the anomaly detection implementation of the security anomaly identification module 33 is as follows: The security anomaly identification module 33 acquires the current security-related data output by the data acquisition module 32 in real time and extracts the current observation values ​​of each behavioral dimension. For each behavioral dimension, the security anomaly identification module 33 calculates the deviation between the current observation and the baseline mean. The formula for calculating the deviation is: ; in, Indicates the first Current observations for each behavioral dimension Indicates the first The mean of each behavioral dimension, Indicates the first Standard deviation of each behavioral dimension; As a smoothing factor, This is used to prevent the denominator from being zero when the standard deviation is zero. The rule for selecting the value is: take an extremely small positive number whose value is less than all others. The smallest possible non-zero value is one-thousandth; a typical value can be set to... Ensure that When the smoothing factor is non-zero, it has no substantial impact on the calculation of the deviation.

[0059] Meanwhile, deviation The range of values ​​is , The larger the value, the greater the deviation of the current observation from the baseline mean, and the higher the probability of an anomaly.

[0060] Furthermore, the security anomaly identification module 33 performs a weighted comprehensive judgment on the deviation of each behavioral dimension, employing a binary weighted voting method. This involves first determining whether each dimension exceeds a threshold, and then weighted summing of the exceeding results. The purpose of this design is to avoid false alarms caused by drastic fluctuations in a single dimension, while ensuring that minor anomalies across multiple dimensions can be effectively identified when they accumulate to a threshold, thus improving the robustness of anomaly detection. The specific implementation is as follows: First, the security anomaly identification module 33 presets a deviation threshold for each behavioral dimension. Deviation threshold Determined based on the distribution characteristics of historical data, it is usually set to... This corresponds to the three-standard-deviation principle. The safety anomaly identification module 33 performs deviation judgment on each behavioral dimension. When this happens, an anomaly is determined to exist in that dimension.

[0061] Subsequently, the security anomaly identification module 33 performs a weighted synthesis of the anomaly judgment results from each dimension. The calculation formula for the weighted synthesis judgment is as follows: ; in, This represents the total number of behavioral dimensions. Indicates the first The voting weight coefficients for each behavioral dimension satisfy the following conditions: and , This is an indicator function; it takes the value 1 when the condition within the parentheses is true, and 0 otherwise. The weighted anomaly score has a value range of [0,1].

[0062] Next, the security anomaly detection module 33 presets a voting threshold. , When weighted outlier scores When abnormal behavior is detected, an anomaly detection result is generated.

[0063] The calculation example is as follows: Assuming the total number of behavioral dimensions The voting weight coefficients for the three dimensions are as follows: Preset voting threshold The current comparison results of the deviation degree and deviation threshold for each dimension are as follows: Dimension 1 satisfies... Dimension 2 does not satisfy Dimension 3 satisfies Then the weighted outlier score. .because The security anomaly identification module 33 determines that there is abnormal behavior.

[0064] Finally, anomaly detection results are generated, including the anomaly type, anomaly severity value, and anomaly occurrence timestamp. The anomaly type is determined based on the combination of behavioral dimensions that triggered the anomaly determination. For example, when the access behavior baseline dimension is triggered, the anomaly type is access anomaly; when the resource call baseline dimension is triggered, the anomaly type is resource anomaly; and when the network traffic baseline dimension is triggered, the anomaly type is network anomaly. The anomaly severity value uses a weighted anomaly score. Quantification is performed. The timestamp of the exception occurrence is the current system time.

[0065] S33.3 Risk Feature Extraction: Extract features from the anomaly detection results generated in step S33.2, aggregate the deviation of each behavioral dimension according to the time window, generate a structured risk feature vector, and output the structured risk feature vector to the risk level determination module 34.

[0066] Specifically, the risk feature extraction implementation of the security anomaly identification module 33 is as follows: The security anomaly detection module 33 employs a sliding time window mechanism. The time window length is preset to a fixed duration, such as 5 minutes, 10 minutes, or 30 minutes, and can be dynamically configured according to system response speed requirements. The sliding time window slides forward with a preset sliding step size, which can be set to half the time window length. For example, when the time window length is 10 minutes, the sliding step size is set to 5 minutes, achieving window overlap and ensuring the continuity of anomaly detection.

[0067] The safety anomaly identification module 33 extracts and aggregates the deviation records of each behavioral dimension within the current time window at each sliding step, calculating the statistical characteristics of each behavioral dimension within the time window, specifically including the maximum deviation, mean deviation, variance of deviation, and number of deviation exceedances. The safety anomaly identification module 33 uses the aggregated statistical characteristics as the structured risk feature vector for the current time window and outputs the structured risk feature vector to the risk level determination module 34.

[0068] For the For each behavioral dimension, the security anomaly identification module 33 calculates the maximum deviation within a time window. Mean deviation Deviation and the number of times the deviation exceeded the limit The number of deviations exceeding the limit is defined as the deviation within the time window. Exceeding the preset deviation threshold The number of times.

[0069] The security anomaly identification module 33 combines the aggregated features of each behavioral dimension to generate a structured risk feature vector. The structured risk feature vector takes the following form: ; in, This represents the total number of behavioral dimensions.

[0070] Finally, the security anomaly identification module 33 encapsulates the generated structured risk feature vector according to the data interface format preset by the risk level determination module 34, and transmits it to the risk level determination module 34 through the data channel as the input data source for risk level determination. This structured risk feature vector is also stored as risk feature data in the risk feature library for risk trend analysis and post-event auditing. The security anomaly identification module 33 also stores the current deviation at the latest sampling time. The data is output in real time to the risk level determination module 34 for real-time risk level determination.

[0071] The calculation example is as follows: Assuming a time window length of 5 minutes, the total number of behavioral dimensions The deviation thresholds for the two dimensions are respectively Within a 5-minute time window, Dimension 1 recorded 10 deviation values: Dimension 2 records 10 deviation values: .

[0072] At this point, the security anomaly identification module 33 calculates the aggregated feature of dimension 1: the maximum value. mean ,variance Exceeding the limit (Number of times the deviation exceeds 3.0); Calculate the aggregated features of dimension 2: maximum value mean ,variance Exceeding the limit .

[0073] The generated structured risk feature vector is: The security anomaly identification module 33 outputs the vector to the risk level determination module 34.

[0074] In this embodiment, the risk level determination module 34 obtains the privacy budget usage information output by the privacy budget management module 31, and determines the real-time risk level based on the anomaly identification results output by the security anomaly identification module 33 and the privacy budget usage information. The real-time risk level is then synchronized to the data acquisition module 32, the security policy adjustment module 35, and the risk level output module 36. The risk level determination and output process of the risk level determination module 34 includes the following steps: S34.1 Risk Feature Aggregation: Receive the structured risk feature vector output by the security anomaly identification module 33, weight and aggregate the deviations of each behavioral dimension, and generate a comprehensive risk metric. ; Specifically, the risk level determination module 34 performs risk feature aggregation as follows: The risk level determination module 34 receives the structured risk feature vector output by the security anomaly identification module 33 in real time. The structured risk feature vector contains the current deviation of each behavioral dimension. And the statistical characteristics of each behavioral dimension within the sliding time window, including the maximum deviation. Mean deviation and the number of times the deviation exceeded the limit .

[0075] The risk level assessment module 34 calculates a comprehensive risk metric by combining the current deviation with window statistical characteristics. Comprehensive risk metric The calculation formula is: ; in, This represents the total number of behavioral dimensions. Indicates a behavioral dimension index; Indicates the frequency exceeding the limit; ; This indicates the total number of samples taken within the time window.

[0076] Overall risk level The range of is [0, +∞), and the larger the value, the higher the overall risk level of the current system.

[0077] The calculation example is as follows: Assuming the total number of behavioral dimensions The weight coefficients for each feature are set as follows: Dimension 1: ; Dimension 2: .

[0078] The structured risk feature vector output by the security anomaly identification module 33 is: Current deviation: ; Window statistical characteristics: ; Total number of samples within the time window .

[0079] Then the comprehensive risk measurement value The calculation is as follows: Dimension 1 contribution value: ; Dimension 2 contribution value: ; Comprehensive risk measurement .

[0080] S34.2 Privacy Budget Integration: Obtain the privacy budget usage status output by the privacy budget management module 31, and accumulate the privacy consumption value. With privacy exposure limit threshold The proportion is used as a constraint factor, and the proportion is used to measure the comprehensive risk value. Perform amplification corrections to generate a corrected risk metric. ; Specifically, the implementation of privacy budget fusion in the risk level determination module 34 is as follows: The risk level assessment module 34 obtains the cumulative privacy consumption value output by the privacy budget management module 31 in real time. and privacy exposure limits Calculate the privacy consumption ratio Considering that the system enters an over-limit suppression state when the cumulative privacy consumption value exceeds the privacy exposure limit threshold, the privacy consumption ratio should not continue to increase at this point. Therefore, an upper limit truncation is applied to the privacy consumption ratio, taking... This process ensures that the privacy consumption ratio remains within the range of [0,1].

[0081] Furthermore, the risk metric was revised. The calculation formula is: ; in, This is the privacy budget fusion coefficient, used to regulate the amplification of privacy consumption on risk measurement. The rules for determining the value are as follows: This is an empirical parameter, and its value range is... The default value is set to 0.5, and this value can be adjusted according to the system's sensitivity to privacy consumption. The higher the system's sensitivity to privacy consumption, the better. The larger the value, the larger the maximum value that can be set to is 1.

[0082] When the proportion of privacy consumption is high, adjust the risk metric. compared to This is amplified, reflecting the increased risk level when privacy budgets are tight.

[0083] Adjust risk metric The range of is [0, +∞), and .

[0084] The calculation example is as follows: Assuming a comprehensive risk metric Cumulative privacy consumption value Privacy exposure limit threshold Privacy Budget Integration Coefficient The privacy consumption ratio Correct risk metrics .

[0085] S34.3, Risk Level Mapping: A built-in risk level mapping table defines the correspondence between multiple risk measurement threshold ranges and risk levels. The table is adjusted based on the risk measurement values. The threshold range into which the risk falls is output, and the corresponding real-time risk level is output. The real-time risk level includes at least low risk level, medium risk level and high risk level.

[0086] Specifically, the risk level determination module 34 performs the level mapping as follows: The risk level determination module 34 has a pre-set risk level mapping table, which defines and modifies risk measurement values. The mapping table shows the correspondence between threshold ranges and risk levels. The table format is as follows: in, The low-risk threshold The high-risk threshold The threshold can be determined based on historical system data or dynamically configured by the administrator according to security requirements.

[0087] Risk level determination module 34 obtains the current corrected risk metric. The risk level is compared with the threshold range in the mapping table to determine the range it falls into and output the corresponding real-time risk level. The real-time risk level is synchronized to the data acquisition module 32, the security policy adjustment module 35, and the risk level output module 36 in the form of enumerated values ​​(low risk level, medium risk level, high risk level), respectively.

[0088] The calculation example is as follows: Following on from the example in S34.2, let's assume the risk metric is adjusted. Preset low-risk threshold High risk threshold .because Correct risk metrics If the risk level falls within the threshold range corresponding to the medium-risk level, the risk level determination module 34 outputs a medium-risk level. This medium-risk level is synchronized to the data acquisition module 32 to adjust the acquisition granularity, synchronized to the security policy adjustment module 35 to generate corresponding security policy adjustment instructions, and synchronized to the risk level output module 36 to output to other units.

[0089] In this embodiment, the security policy adjustment module 35 dynamically adjusts the security policy based on the real-time risk level output by the risk level determination module 34, and synchronously adapts to the associated policies for data collection, privacy protection, identity authentication, and audit compliance. The process of security policy linkage adjustment and distribution by the security policy adjustment module 35 includes the following steps: S35.1, Policy Linkage Instruction Generation: Receive the real-time risk level output by the risk level determination module 34, and generate identity authentication policy adjustment instructions, access permission policy adjustment instructions, data protection policy adjustment instructions, and audit policy adjustment instructions that match the real-time risk level according to the preset policy linkage mapping relationship, forming a set of adjustment instructions; Specifically, the implementation of the security policy adjustment module 35 in generating policy linkage instructions is as follows: The security policy adjustment module 35 receives the real-time risk level output by the risk level determination module 34. The real-time risk levels include low risk, medium risk, and high risk. The security policy adjustment module 35 has pre-set policy linkage mapping relationships, which define the correspondence between different real-time risk levels and various security policy adjustment commands, as follows: When the real-time risk level is low, the identity authentication policy adjustment instruction generated by the security policy adjustment module 35 indicates that the basic authentication strength is used, the access permission policy adjustment instruction indicates that the regular permission granularity is used, the data protection policy adjustment instruction indicates that the basic protection policy is used, and the audit policy adjustment instruction indicates that the regular audit scope is used. When the real-time risk level is medium risk, the identity authentication policy adjustment instruction generated by the security policy adjustment module 35 indicates that enhanced authentication strength is adopted, the access permission policy adjustment instruction indicates that the granularity of permissions is narrowed, the data protection policy adjustment instruction indicates that the transmission encryption policy is adopted, and the audit policy adjustment instruction indicates that the audit scope is enhanced. When the real-time risk level is high, the security policy adjustment module 35 generates an identity authentication policy adjustment instruction that indicates enhanced authentication strength, an access permission policy adjustment instruction that indicates minimized permission granularity, a data protection policy adjustment instruction that indicates end-to-end encryption, and an audit policy adjustment instruction that indicates full audit scope.

[0090] Furthermore, the security policy adjustment module 35 encapsulates the generated four types of policy adjustment instructions into an adjustment instruction set. The adjustment instruction set adopts a key-value pair structure, with each instruction containing an instruction type identifier and a target unit identifier. The form of the adjustment instruction set is as follows: ; in, This indicates an instruction to adjust the identity authentication policy. This indicates an instruction to adjust access control policies. This indicates a data protection policy adjustment instruction. This indicates an instruction to adjust the audit strategy.

[0091] S35.2 Strategy Conflict Detection: Perform conflict detection on the set of adjustment instructions generated in step S35.1. Conflict types include mutual exclusion conflict and parameter conflict. When a logical conflict is detected in the set of adjustment instructions, the adjustment instructions are corrected according to the preset conflict resolution rules to generate a set of conflict-free strategy adjustment instructions. Specifically, the implementation of policy conflict detection in the security policy adjustment module 35 is as follows: The security policy adjustment module 35 performs conflict detection on the set of adjustment instructions generated in step S35.1, checking whether there are mutual exclusion conflicts or parameter conflicts in the set of adjustment instructions. Specifically: Mutual exclusion conflict refers to two or more policy adjustment instructions that logically cannot take effect simultaneously. For example, when an identity authentication policy adjustment instruction requires the use of a basic authentication policy (single authentication factor), while an audit policy adjustment instruction requires enabling full audit scope, if system resources are insufficient to support both basic authentication and full audit simultaneously, a mutual exclusion conflict is determined to exist. The security policy adjustment module 35 has a built-in mutual exclusion conflict rule base, which records mutually exclusive instruction combinations. Parameter conflict refers to two or more policy adjustment instructions assigning different values ​​to the same configuration parameter. For example, if a data protection policy adjustment instruction requires the use of a transmission encryption policy, while an identity authentication policy adjustment instruction requires the use of a strengthened authentication policy, and both set different values ​​for the same session timeout parameter, a parameter conflict is determined to exist. The security policy adjustment module 35 has built-in parameter conflict detection logic to identify whether there are multiple definitions for the same configuration parameter in the instruction set.

[0092] Furthermore, when a logical conflict is detected in the set of adjustment instructions, the security policy adjustment module 35 corrects the adjustment instructions according to preset conflict resolution rules. The priority order of the conflict resolution rules is: high-risk policies take precedence over low-risk policies, authentication policies take precedence over access permission policies, and data protection policies take precedence over auditing policies. The specific implementation is as follows: When a mutual exclusion conflict occurs, the security policy adjustment module 35 retains the higher priority instruction, removes the lower priority instruction, or merges the instructions. When a parameter conflict occurs, the security policy adjustment module 35 retains the parameter value of the higher priority instruction and overwrites the parameter value of the lower priority instruction to ensure that the same configuration parameter has a unique and definite value.

[0093] Finally, the security policy adjustment module 35 recombines the revised adjustment instructions to generate a conflict-free set of policy adjustment instructions. .

[0094] S35.3 Policy Distribution: The set of conflict-free policy adjustment instructions generated in step S35.2 is distributed to the Identity Authentication and Access Control Unit 1, Data Privacy Protection Unit 2, and Security Audit and Compliance Unit 4 respectively, triggering the Identity Authentication and Access Control Unit 1, Data Privacy Protection Unit 2, and Security Audit and Compliance Unit 4 to execute policy changes.

[0095] Specifically, the implementation of the security policy adjustment module 35 in issuing the policy is as follows: The security policy adjustment module 35 will generate the set of conflict-free policy adjustment instructions in step S35.2. The instructions are categorized according to the target unit and encapsulated into a format that the corresponding unit can recognize.

[0096] The security policy adjustment module 35 sends the identity authentication policy adjustment instruction to the risk data receiving module 11 of the identity authentication and access control unit 1 through the internal communication bus. After receiving the instruction, the identity authentication and access control unit 1 performs dynamic adjustment of the identity authentication strength and access permission granularity. The security policy adjustment module 35 sends the data protection policy adjustment instruction to the risk policy receiving module 21 of the data privacy protection unit 2. After receiving the instruction, the data privacy protection unit 2 performs dynamic adaptation of the data protection policy. The security policy adjustment module 35 sends the audit policy adjustment instruction to the risk level receiving module 41 of the security audit and compliance unit 4. After receiving the instruction, the security audit and compliance unit 4 performs dynamic adjustment of the log collection scope and compliance verification policy.

[0097] The security policy adjustment module 35 records a log after the instruction is issued, including the issuance time, instruction content, target unit, and execution status, for subsequent auditing and tracing.

[0098] In this embodiment, the risk level output module 36 is used to receive the real-time risk level output by the risk level determination module 34 and output it synchronously to the identity authentication and access control unit 1, the data privacy protection unit 2, and the security audit and compliance unit 4.

[0099] Specifically, the input interface of the risk level output module 36 is connected to the risk level determination module 34, and it receives the real-time risk level output by the risk level determination module 34 in real time. The risk level output module 36 stores the received real-time risk level as the current risk level for subsequent synchronous distribution.

[0100] Furthermore, the risk level output module 36 is connected to the identity authentication and access control unit 1, the data privacy protection unit 2, and the security audit and compliance unit 4 through three independent output channels. Upon receiving the real-time risk level, the risk level output module 36 immediately distributes the currently stored real-time risk level synchronously to each target unit through the three output channels, as follows: The risk level output module 36 sends the real-time risk level to the risk data receiving module 11 of the identity authentication and access control unit 1. The identity authentication and access control unit 1 dynamically adjusts the identity authentication strength and access permission granularity according to the received real-time risk level. The risk level output module 36 sends the real-time risk level to the risk policy receiving module 21 of the data privacy protection unit 2. The data privacy protection unit 2 dynamically adjusts the data protection policy according to the received real-time risk level. The risk level output module 36 sends the real-time risk level to the risk level receiving module 41 of the security audit and compliance unit 4. The security audit and compliance unit 4 dynamically adjusts the log collection scope and compliance verification strategy according to the received real-time risk level.

[0101] Finally, the risk level output module 36 uses a message queue mechanism to ensure reliable transmission of real-time risk levels. When any output channel fails to transmit, the risk level output module 36 records the transmission failure log and attempts to retransmit, ensuring that each target unit can obtain the latest real-time risk level in a timely manner.

[0102] Security Audit and Compliance Unit 4 collects data access operation logs, implements compliance verification and behavior tracing, and receives the risk level output by Security Awareness and Decision Unit 3, dynamically adjusting the log collection scope and compliance verification strategy.

[0103] In this embodiment, the security audit and compliance unit 4 includes a risk level receiving module 41, a log collection module 42, a compliance verification module 43, and a behavior tracing module 44, wherein: The risk level receiving module 41 is used to receive the risk level output by the security perception and decision-making unit 3, and synchronize the risk level to the log collection module 42 and the compliance verification module 43 respectively. Log collection module 42 is used to collect data access operation logs and dynamically adjusts the log collection range according to the risk level synchronized by risk level receiving module 41. Specifically, the log collection module 42 incorporates multi-level log collection strategies, including a regular collection strategy, an enhanced collection strategy, and a comprehensive collection strategy. The log collection module 42 dynamically adjusts the log collection scope based on the risk level synchronized by the risk level receiving module 41, as implemented below: When the risk level is low, the log collection module 42 adopts a conventional collection strategy, collecting only the core fields of the data access operation, including the access subject identifier, access time, operation type, operation result, and access object identifier, while discarding detailed request parameters and response content. When the risk level is medium risk, the log collection module 42 adopts an enhanced collection strategy, adding key fields such as collection request path, response status code, resource consumption indicators, and session identifier on the basis of core fields, while increasing the log sampling frequency. When the risk level is high, the log collection module 42 adopts a comprehensive collection strategy to collect complete data access operation logs, including all request parameters, complete response content, stack trace information, network connection information, and enables a real-time log reporting mechanism.

[0104] Finally, the log collection module 42 encapsulates the collected logs in a unified format, adds a collection timestamp and risk level identifier, and then sends them to the compliance verification module 43 and the behavior traceability module 44, respectively.

[0105] The compliance verification module 43 is used to perform compliance verification on data access operations and dynamically adjusts the compliance verification strategy according to the risk level synchronized by the risk level receiving module 41. Specifically, the compliance verification module 43 has a built-in compliance verification rule library, which pre-configures multiple verification rules based on data security regulations, industry standards, and enterprise security policies. The compliance verification module 43 dynamically adjusts the compliance verification strategy based on the risk level synchronized by the risk level receiving module 41, as implemented below: When the risk level is low, the compliance verification module 43 adopts a conventional verification strategy, and only performs key rule verification on data access operations, including access permission verification, sensitive data access verification, and operation type compliance verification. When the risk level is medium risk, the compliance verification module 43 adopts an enhanced verification strategy, which adds cross-border data transmission verification, data retention period verification, and sensitive data de-identification verification on the basis of regular verification, and provides real-time alarms on the verification results. When the risk level is high, the compliance verification module 43 adopts a comprehensive verification strategy, enables all compliance verification rules, performs in-depth verification on data access operations, including access context association verification, operation behavior pattern verification, data flow compliance verification, and triggers real-time blocking for illegal operations.

[0106] Finally, the compliance verification module 43 sends the compliance verification results (including whether it is compliant, the type of violation, the degree of violation, and the verification timestamp) to the behavior traceability module 44.

[0107] The behavior tracing module 44 implements behavior tracing based on the data access operation logs collected by the log collection module 42 and the compliance verification results of the compliance verification module 43, and generates tracing records.

[0108] Specifically, the behavior tracing module 44 receives data access operation logs from the log collection module 42 and compliance verification results from the compliance verification module 43 in real time. The behavior tracing module 44 uses the access subject identifier and session identifier as association keys to aggregate data access operation logs and compliance verification results for the same access subject within the same session period.

[0109] Furthermore, when a violation record is found in the compliance verification result output by the compliance verification module 43, the behavior tracing module 44 triggers the tracing process to perform a retrospective query on the historical operations of the accessing subject. The behavior tracing module 44 retrieves all data access operation logs of the accessing subject within a specified time range from the historical log storage of the log collection module 42, and combines this with the violation judgment result of the compliance verification module 43 to construct a complete operation behavior chain.

[0110] Meanwhile, the traceability records generated by the behavior traceability module 44 include traceability identifiers, access subject identifiers, traceability time ranges, operational behavior chains, details of violations, compliance verification results, and risk level identifiers. These traceability records are stored in a structured format in the audit database for subsequent security audits, compliance report generation, and security incident investigations.

[0111] Finally, the behavior tracing module 44 synchronizes the generated tracing records to the output interface of the security audit and compliance unit 4 for use by external audit systems or security management platforms.

[0112] Those skilled in the art will understand that the process of implementing all or part of the steps of the above embodiments can be carried out by hardware or by a program instructing the relevant hardware.

[0113] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The embodiments and descriptions in the specification are merely preferred examples and are not intended to limit the invention. Various changes and modifications can be made to the invention without departing from its spirit and scope, and all such changes and modifications fall within the scope of the claimed invention.

Claims

1. A smart system for data security access control and privacy protection in a cloud-native environment, characterized in that, include: Identity authentication and access control unit (1) performs identity authentication on all access subjects in the cloud-native environment, executes fine-grained access control, implements the principle of least privilege, prevents unauthorized subjects from accessing data resources, and receives the risk level output by the security perception and decision unit (3), and dynamically adjusts the identity authentication strength and access granularity. The data privacy protection unit (2) implements privacy protection for the entire process of data collection, transmission, storage, processing and destruction, controls access to and exposure of sensitive data, and receives the risk level output by the security perception and decision-making unit (3) to dynamically adjust the data protection strategy. Security perception and decision-making unit (3) has a built-in security perception mechanism based on privacy budget constraints. The privacy budget is used to quantify the degree of exposure of sensitive information during data collection. The security perception mechanism constrains data collection behavior by setting a privacy exposure upper limit threshold and integrates privacy consumption status with risk measurement. It dynamically adapts the data collection granularity according to the real-time risk level. In the low-risk state, it adopts a minimal collection strategy that only includes the core fields of security monitoring. In the medium-risk state, it adopts a feature-level collection strategy that includes the core fields of security monitoring and key fields of feature extraction. In the high-risk state, it adopts an enhanced collection strategy that includes complete security monitoring fields under the premise of authorization and performs sensitive data privacy enhancement processing simultaneously. After the risk is eliminated, it automatically falls back to the collection granularity, collects security-related data of cloud-native environment, identifies security anomalies and risks, dynamically adjusts security strategies and outputs the risk level to the identity authentication and access control unit (1), the data privacy protection unit (2) and the security audit and compliance unit (4). The security audit and compliance unit (4) collects data access operation logs, performs compliance verification and behavior tracing, and receives the risk level output by the security perception and decision-making unit (3), and dynamically adjusts the log collection scope and compliance verification strategy.

2. The intelligent system for data security access control and privacy protection in a cloud-native environment according to claim 1, characterized in that, The identity authentication and access control unit (1) includes a risk data receiving module (11), an identity authentication module (12), an access control module (13), and an access interception module (14), wherein: The risk data receiving module (11) is used to receive the risk level output by the security perception and decision-making unit (3) and synchronize the risk level to the identity authentication module (12) and the access control module (13) respectively. The identity authentication module (12) is used to authenticate the identities of all access subjects in the cloud-native environment and dynamically adjust the identity authentication strength according to the received risk level. The access control module (13) is used to perform fine-grained access control on the access subject that has completed identity authentication, implement the principle of least privilege, and dynamically adjust the granularity of access permissions according to the received risk level; The access interception module (14) is used to intercept access subjects that have not passed identity authentication and access behaviors that exceed the scope of access permissions, thereby preventing unauthorized subjects from accessing data resources.

3. The intelligent system for data security access control and privacy protection in a cloud-native environment according to claim 1, characterized in that, The data privacy protection unit (2) includes a risk policy receiving module (21), a data classification and discovery module (22), a privacy policy execution module (23), and a privacy enhancement processing module (24), wherein: The risk policy receiving module (21) is used to receive the risk level output by the security perception and decision-making unit (3) and synchronize the risk level to the privacy policy execution module (23) and the privacy enhancement processing module (24). The data classification and discovery module (22) is used to automatically scan, identify and classify data in the cloud-native environment and mark sensitive data levels; The privacy policy execution module (23) dynamically adapts and executes the corresponding data protection policy throughout the entire process of data collection, transmission, storage, processing, and destruction, based on the sensitive data level output by the data classification and discovery module (22) and the risk level synchronized by the risk policy receiving module (21). The privacy enhancement processing module (24) calls the corresponding privacy computing or de-identification technology to perform privacy enhancement processing on sensitive data according to the risk level synchronized by the risk policy receiving module (21) in order to control the access and exposure of sensitive data.

4. The intelligent system for data security access control and privacy protection in a cloud-native environment according to claim 1, characterized in that, The security perception and decision-making unit (3) includes a privacy budget management module (31), a data acquisition module (32), a security anomaly identification module (33), a risk level determination module (34), a security policy adjustment module (35), and a risk level output module (36), wherein: The privacy budget management module (31) is used to establish and maintain a privacy budget constraint mechanism, set a privacy exposure upper limit threshold, and provide a core constraint basis for adjusting the collection granularity of the data collection module (32). The data acquisition module (32) is used to collect cloud-native environment security-related data. Based on the real-time risk level output by the risk level judgment module (34), the acquisition granularity is dynamically adapted within the constraint threshold set by the privacy budget management module (31). The security anomaly identification module (33) is used to analyze the cloud-native environment security-related data collected by the data acquisition module (32), identify security anomalies and potential risks, and output the anomaly identification results to the risk level determination module (34). The risk level determination module (34) obtains the privacy budget usage information output by the privacy budget management module (31), and determines the real-time risk level based on the anomaly identification results output by the security anomaly identification module (33) and the privacy budget usage information, and synchronizes the real-time risk level to the data acquisition module (32), the security policy adjustment module (35), and the risk level output module (36). The security policy adjustment module (35) dynamically adjusts the security policy based on the real-time risk level output by the risk level determination module (34), and synchronously adapts to the associated policies of data collection, privacy protection, identity authentication and audit compliance. The risk level output module (36) is used to receive the real-time risk level output by the risk level determination module (34) and output it synchronously to the identity authentication and access control unit (1), the data privacy protection unit (2) and the security audit and compliance unit (4).

5. The intelligent system for data security access control and privacy protection in a cloud-native environment according to claim 4, characterized in that, The privacy budget constraint execution process of the privacy budget management module (31) includes the following steps: S31.1 Privacy Budget Initialization: Preset privacy exposure limits for data collection activities in cloud-native environments. And establish an initial allocation strategy for a privacy budget, which is used to quantify the degree of exposure of sensitive information during the data collection process; S31.2 Privacy Budget Consumption Monitoring: Under uniform discrete sampling time, the actual data acquisition behavior of the real-time data acquisition module (32) at each acquisition granularity is collected. Based on the unit privacy consumption coefficient and execution status of each type of data acquisition operation, the cumulative privacy consumption value is calculated. ; Accumulated privacy consumption value With privacy exposure limit threshold Compare data to generate a privacy budget usage status; S31.3, Privacy Budget Constraint Execution: Based on the privacy budget usage status generated in step S31.2, when the accumulated privacy consumption value... Exceeding the privacy exposure limit threshold Furthermore, when the excess reaches the preset hysteresis threshold, a collection granularity suppression command is output to the data collection module (32) to restrict the data collection module (32) from switching to a higher collection granularity or to forcibly maintain the current collection granularity until the privacy budget reset cycle is reached or the accumulated privacy consumption value is reached. Fall back to below the privacy exposure limit threshold .

6. The intelligent system for data security access control and privacy protection in a cloud-native environment according to claim 5, characterized in that, The data acquisition module (32) includes an acquisition granularity controller submodule, an acquisition actuator submodule, and a data preprocessing submodule, wherein: The collection granularity controller submodule is used to receive the real-time risk level output by the risk level determination module (34), and under the privacy exposure upper limit threshold constraint set by the privacy budget management module (31), dynamically select the current collection strategy from the preset collection strategy set. The preset collection strategy set includes the minimum collection strategy, the feature-level collection strategy and the enhanced collection strategy. Different collection strategies correspond to different data collection field sets and collection frequencies. The acquisition executor submodule is used to acquire security-related data from the cloud-native environment and generate raw acquisition data according to the current acquisition strategy selected by the acquisition granularity controller submodule. The data preprocessing submodule is used to normalize the format and filter sensitive information of the raw acquisition data output by the acquisition actuator submodule, and then send the processed data to the security anomaly identification module (33).

7. The intelligent system for data security access control and privacy protection in a cloud-native environment according to claim 6, characterized in that, The process of security anomaly identification and risk feature extraction by the security anomaly identification module (33) includes the following steps: S33.1, Establishment of Behavioral Baselines: Based on historical data collection, establish a normal behavioral baseline model in the cloud-native environment. The normal behavioral baseline model includes access behavior baseline, resource call baseline and network traffic baseline. Each baseline model is characterized by statistical distribution parameters, including the mean and standard deviation of each behavioral dimension. S33.2 Anomaly Detection: Compare the current security-related data collected by the data acquisition module (32) with the normal behavior baseline model established in step S33.1, and calculate the deviation of each behavioral dimension. The deviation Used to quantify the degree of deviation between the current observation value and the baseline value; the deviation of each behavioral dimension is weighted and comprehensively judged to generate anomaly detection results, which include anomaly type, anomaly degree value and anomaly occurrence timestamp; S33.3 Risk Feature Extraction: Extract features from the anomaly detection results generated in step S33.2, aggregate the deviation of each behavioral dimension according to the time window, generate a structured risk feature vector, and output the structured risk feature vector to the risk level determination module (34).

8. The intelligent system for data security access control and privacy protection in a cloud-native environment according to claim 7, characterized in that, The risk level determination and output process of the risk level determination module (34) includes the following steps: S34.1 Risk Feature Aggregation: Receive the structured risk feature vector output by the security anomaly identification module (33), weight and aggregate the deviation of each behavioral dimension to generate a comprehensive risk metric. ; S34.2, Privacy Budget Integration: Obtain the privacy budget usage status output by the privacy budget management module (31), and accumulate the privacy consumption value. With privacy exposure limit threshold The proportion is used as a constraint factor, and the comprehensive risk measure is adjusted based on this proportion. Perform amplification corrections to generate a corrected risk metric. ; S34.3, Risk Level Mapping: A built-in risk level mapping table defines the correspondence between multiple risk measurement threshold ranges and risk levels. The risk level mapping table is adjusted based on the risk measurement values. The threshold range into which the risk falls is output as a corresponding real-time risk level, which includes at least low risk, medium risk and high risk levels.

9. The intelligent system for data security access control and privacy protection in a cloud-native environment according to claim 8, characterized in that, The process of security policy linkage adjustment and distribution by the security policy adjustment module (35) includes the following steps: S35.1, Strategy linkage instruction generation: Receive the real-time risk level output by the risk level determination module (34), and generate identity authentication strategy adjustment instructions, access permission strategy adjustment instructions, data protection strategy adjustment instructions and audit strategy adjustment instructions that match the real-time risk level according to the preset strategy linkage mapping relationship, forming a set of adjustment instructions; S35.2 Strategy Conflict Detection: Perform conflict detection on the set of adjustment instructions generated in step S35.

1. Conflict types include mutual exclusion conflict and parameter conflict. When a logical conflict is detected in the set of adjustment instructions, the adjustment instructions are corrected according to the preset conflict resolution rules to generate a set of conflict-free strategy adjustment instructions. S35.3 Policy Distribution: The set of conflict-free policy adjustment instructions generated in step S35.2 is distributed to the identity authentication and access control unit (1), the data privacy protection unit (2), and the security audit and compliance unit (4) respectively, triggering the identity authentication and access control unit (1), the data privacy protection unit (2), and the security audit and compliance unit (4) to execute policy changes.

10. The intelligent system for data security access control and privacy protection in a cloud-native environment according to claim 1, characterized in that, The security audit and compliance unit (4) includes a risk level receiving module (41), a log collection module (42), a compliance verification module (43), and a behavior tracing module (44), wherein: The risk level receiving module (41) is used to receive the risk level output by the security perception and decision-making unit (3) and synchronize the risk level to the log collection module (42) and the compliance verification module (43) respectively. The log collection module (42) is used to collect data access operation logs and dynamically adjust the log collection range according to the risk level synchronized by the risk level receiving module (41). The compliance verification module (43) is used to perform compliance verification on data access operations and dynamically adjust the compliance verification strategy according to the risk level synchronized by the risk level receiving module (41). The behavior tracing module (44) implements behavior tracing based on the data access operation logs collected by the log collection module (42) and the compliance verification results of the compliance verification module (43), and generates tracing records.

Citation Information

Patent Citations

  • Cross-platform education data privacy protection analysis system

    CN120781380A

  • Data desensitization and sensitive information dynamic risk assessment method based on privacy calculation

    CN121145260A