Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

183 results about "Data access control" patented technology

Data Access Control gives customers the ability to customize and control what areas their users can access within Zuora. Data Access Control allows you do the following: Restrict what products and accounts your users can see within Zuora​​. Data Access Control is ONLY enforced on UI users, not API users.

Linux access control system based on attributes

The invention provides a Linux access control system based on attributes, and relates to the technical field of data access control. The system comprises a system monitor module, a data interaction module and a decision unit. The system monitor module collects attributes from a kernel and a user space and writes the attributes into the data interaction module; the access decision unit compiles the access control strategy into an eBPF program and mounts the eBPF program to a corresponding hook; executing the kernel to the hook, and triggering an eBPF program; an eBPF program queries a Flow rule; matching the attribute with the Flow rule, and if the matching is successful, executing a corresponding action; if all the Flow rules fail to match, executing a default action; the system can be expanded during operation, and can be loaded or unloaded based on dynamic loading characteristics and strategies of the eBPF program and the eBPF program during operation of the system, so that the problem that a kernel needs to be compiled in a traditional LSM scheme is solved; the method does not intrude the kernel, is completely based on an eBPF program, does not modify a kernel source code, and can guarantee the stability and compatibility.
Owner:SICHUAN UNIV

Block chain-based trusted data space cross-domain access control method, system and device, and medium

The invention relates to the technical field of data cross-domain access control, in particular to a block chain-based trusted data space cross-domain access control method, system and device and a medium, comprising: receiving a data access request, and analyzing a target data identifier, a target heterogeneous system identifier and access scene information; obtaining the data attribute of the target data according to the target data identifier, generating a dynamic access strategy in combination with the access scene information, and deploying the dynamic access strategy into the block chain; mapping the dynamic access strategy into an equivalent access control rule, and converting the data access request into target compatible request data; verifying zero-knowledge proof provided by the user based on an equivalent access control rule and a user public key; after the verification is passed, routing the target compatible request data to the target heterogeneous system; and the target heterogeneous system generates original response data, converts the original response data into user-side compatible response data and returns the user-side compatible response data to the user. According to the invention, cross-system efficient cooperation is realized, and the real-time adaptability and privacy enhancement security of access control can be improved.
Owner:INSPUR YUNZHOU (SHANDONG) IND INTERNET CO LTD

Federal learning-based emergency rescue data privacy protection and collaborative analysis system

The invention discloses an emergency rescue data privacy protection and collaborative analysis system based on federated learning, and belongs to the technical field of emergency rescue data privacy protection and collaborative analysis. A dynamic trust evaluation module; the federated learning privacy protection engine module is used for realizing cross-domain data collaborative training by adopting a secure multi-party computing model; and the block chain intelligent contract module is used for deploying a data access control strategy and a credible auditing rule. According to the method, a global trusted environment is established through an end-side cloud three-level trust chain, the reliability of equipment is quantified through dynamic trust evaluation, data collaboration of privacy protection is realized through federated learning, an auditing strategy is automatically executed through an intelligent contract, an efficient encryption technology for guaranteeing safety and effectively reducing resource consumption is adopted, and the urban emergency data safety problem is solved.
Owner:INST OF URBAN SAFETY & ENVIRONMENTAL SCI BEIJING ACAD OF SCI & TECH

Data access control method and system based on zero knowledge proof

The invention provides a data access control method and system based on zero-knowledge proof, and relates to the technical field of data access control. According to the method, a root key of a unique hardware identity is generated through a physical unclonable function of a data request equipment chip, and meanwhile, real-time running state data of equipment is collected; the two are subjected to cryptographic binding to form an equipment credible state voucher; secondly, detecting capacitance field disturbance when data holding equipment approaches through a capacitive proximity sensor array, and generating an interactive response mode; then, the equipment credible state certificate and the interactive response mode serve as private input to generate a composite zero-knowledge proof, and identity authenticity and physical proximity are proved to data holding equipment at the same time on the premise that sensitive information is not leaked; and after the data holding device passes verification, the data access permission is authorized immediately, and a temporary encryption communication channel is established, so that the reliability and instantaneity of security authentication between IoT devices can be improved.
Owner:NANJING YISHENG SAFETY TECH RES INST CO LTD +1

Data security protection method and system for large model training

The invention discloses a data security protection method and system for large model training. The core of the method is that a data safe box trusted application (TA application) is deployed in a trusted execution environment (TEE) and cooperatively works with a user-defined virtual file system driver at a host machine side, so that an end-to-end secret state data access control link is constructed. Before encryption protection of sensitive data, a measurement value (including code hash, configuration parameters and a runtime state) of a current TEE instance is submitted to a remote verification service through a data safe box TA application, and the verification service only sends the measurement value (including code hash, configuration parameters and a runtime state) of the current TEE instance to the remote verification service after confirming that the TEE environment meets a preset security policy (such as a kernel version, a software version and configuration parameter compliance). And generating a secret key encrypted by a custom virtual file system on a host machine side through derivation. And malicious copying of a system memory and a storage medium is prevented, so that the traditional attack defense capability is effectively improved.
Owner:PANOVASIC TECHNOLOGY CO LTD

Fault switching method and device, electronic equipment and storage medium

The invention discloses a failover method and device, electronic equipment and a storage medium, and relates to the technical field of distributed storage, and the failover method comprises the following steps: determining a first disk resource group corresponding to a first storage node and a second disk resource group corresponding to a second storage node; and establishing a double-control relationship between the first disk resource group and the second disk resource group. And after the establishment of the double-control relationship is completed, carrying out fault switching on different disk resource groups under the double-control relationship based on the first mechanism and the second mechanism. The technical problem that in a distributed storage system, efficient and safe disk resource management and data access control of a fault controller cannot be effectively achieved under a double-controller architecture is solved, and the technical effects of improving rapidness, smoothness and automatic back-switching of fault switching and remarkably improving the high availability of the distributed storage system are achieved.
Owner:JINAN INSPUR DATA TECH CO LTD

Power data access control method and device based on multi-level encryption strategy

The invention provides a power data access control method and device based on a multi-level encryption strategy. The method comprises the following steps: establishing a platform root key, a role key derived based on a role identifier and a homomorphic encryption public and private key pair bound with a sensitive field in an encryption engine, and mapping the keys to a corresponding power data field; performing first-layer encryption on the to-be-stored power data block by using the platform root key, performing second-layer encryption on the field set belonging to the corresponding role access level by using the role key, and performing third-layer encryption on the sensitive field by using the homomorphic encryption public key; distributing the data key set to a computing node, and enabling the computing node to execute decryption or secret state calculation on the encrypted power data to obtain target data; and re-encrypting the target data by using the role key, and providing the re-encrypted target data to the requester carrying the role identifier. According to the method and the device, data security access of fine-grained permission isolation and online secret state calculation can be considered.
Owner:INNER MONGOLIA ELECTRIC POWER (GRP) CO LTD DIGITAL RES BRANCH

Data access control method and device, storage medium and electronic equipment

The invention discloses a data access control method and device, a storage medium and electronic equipment, and relates to the field of computers.The data access control method comprises the steps that a target reading request is received, and the target reading request is used for requesting to read data corresponding to target time from a storage space in a memory according to target address information; in response to the target reading request, positioning a target cache region corresponding to the target address information in a cache space in a memory; and extracting the target data of the target snapshot version corresponding to the target time from the reference snapshot version and the reference data which are stored in the target cache region and have the corresponding relationship, thereby solving the technical problems of relatively low data access efficiency and the like caused by the fact that historical snapshot data reading needs to depend on a rear-end disk. The technical effects of cache acceleration of historical snapshot data reading and improvement of data access efficiency are achieved.
Owner:LANGCHAO ELECTRONIC INFORMATION IND CO LTD

Data distributed secure storage system and method based on computer science and technology

The invention relates to the technical field of data distributed storage, in particular to a data distributed secure storage system and method based on computer science and technology. The system comprises a data fragmentation and strategy binding module, a strategy declaration evidence storage and state tracking module, a strategy execution voucher generation module and a voucher verification and data assembly module. The system carries out fragmentation processing on original service data through a dynamic fragmentation algorithm to generate encrypted data fragments and a strategy binding statement; storing the strategy binding declaration to a distributed account book and maintaining a strategy state table; generating a policy execution voucher including an access qualification proof, a digital signature response, a policy hash value and a timestamp based on the system real-time state and the access request; and the distributed storage node implements decentralized data access control by verifying the policy execution credential. According to the method, the single-point fault and strategy tampering risk of centralized authority management are effectively solved, and a reliable data security sharing scheme is provided for a supply chain financial service scene.
Owner:刘震

Data access control

Methods, systems, and apparatus, including computer programs encoded on computer storage media, for controlling data access. One of the methods includes receiving, from a user device associated with an account, a request for data; accessing data from one or more data sources that includes, for each of a plurality of data types, corresponding data values; selecting, from the plurality of data types and using permissions data for the account, one or more data types that the account has permission to access; and providing, to the user device and for each of the one or more data types that the account has permission to access, the corresponding data values.
Owner:CHEN TECH LLC

Medical data access control method based on block chain

The invention relates to the technical field of medical data access control, in particular to a medical data access control method based on a block chain. The method comprises the following steps: S1, a health bureau is used as a management and operation main body of a block chain system; according to the method, the access information entropy is calculated for the data volume accessed by the user, the risk of the access request is dynamically calculated, and then the trust degree is calculated through risk assessment, so that sufficient risk verification and trust degree confirmation are ensured for each data access; the decentralization, transparency and data tampering resistance of the system are further improved, so that the access control of the medical data is safer and more reliable; compared with the prior art, the risk can be evaluated and controlled more accurately, higher adaptability is achieved, complex medical data sharing requirements and potential security threats can be effectively dealt with, and the access throughput and delay of the medical data are also remarkably improved.
Owner:LIMING VOCATIONAL UNIV +1

Advanced semantic caching with CDN for rag-based LLM applications

A Content Distribution Network (CDN) may implemented as a front door to a RAG-based LLM for the purpose of semantically caching LLM responses to natural language prompts. More specifically, the CDN may also cache document citation(s) and / or user tag(s) along with the LLM response for purposes of ensuring that access permission constraints of the RAG are observed when providing cached LLM response as direct responses to semantically similar natural language prompts. Additionally, the CDN may be configured to modify and / or purge cached data from the CDN's cached memory database based on instructions received from a data access control (DAC) entity of the organization or enterprise client. This may ensure that the CDN observes any changes to the access permission constraints that might be made by the DAC entity.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Data access control method based on smart contract

The invention provides a data access control method based on a smart contract. Constructing a hierarchical domain organization tree according to the cooperation relationship of partners under multi-party cooperation and the internal organization structure relationship of the partners; each block chain node establishes a client-role mapping table, an on-chain node-role mapping table, a role-permission mapping table, a permission-data-operation mapping table and a permission-contract mapping table to form an access control strategy library; the client carries client role information to a block chain node of a domain to which the client belongs for registration; the client role information is composed of an upstream path in the hierarchical domain organization tree and a position role; after a client carries an initiating transaction request, before a contract is executed and before the contract is executed and accesses data, a constraint condition checker is called to verify identity, authority and execution behaviors. According to the invention, support is provided for realizing access control requirements of traditional data management by using a block chain system in an enterprise organization.
Owner:BEIJING INST OF TECH

Cloud disk data access control and authority management method and system based on zero-trust architecture

The invention provides a cloud disk data access control and authority management method and system based on a zero-trust architecture, and relates to the technical field of cloud computing, and the method comprises the steps: generating a real-time risk score through calculating a user access behavior deviation degree, a geographic position and a device fingerprint; reading the distributed permission strategy library in parallel by adopting a consistent Hash algorithm, and obtaining dynamic permission configuration; based on an attribute access control strategy, constructing a multi-dimensional permission decision matrix in combination with a data sensitivity label and an access environment context; and finally executing fine-grained access control and recording a verification process. According to the method, dynamic and continuous identity verification and refined authority control are realized, and the cloud disk data access security is remarkably improved.
Owner:BEIJING XINXUN XINAN TECH CO LTD

Data access management method, device and storage medium

This application provides a data access control method, device, and storage medium, relating to the field of smart home technology. It can perceive dynamic social relationships between users, bridge the semantic interaction gap, and thus improve the interactive experience of permission configuration in multi-user home scenarios. The method includes: receiving a data access request initiated by a third user, the data access request being used to request authorization for a second user to access target data created by a first user, the data access request including target social relationships, including at least two of the following: social relationships between the first and second users, social relationships between the second and third users, and social relationships between the first and third users; determining the second user's target access permission for the target data in a pre-constructed knowledge graph; and controlling the second user's access to the target data according to the target access permission.
Owner:ZTE CORP

Data leakage protection and monitoring system

The invention discloses a data leakage protection and monitoring system, and relates to the technical field of data security supervision. The system specifically comprises a data classification and marking module, a data access control module, a data encryption module, a data monitoring and analysis module, a data auditing and reporting module, a data shielding and desensitization module and a threat intelligence and vulnerability management module. The data access control module sets different access permissions according to data classification and marks, the data encryption module carries out encryption protection on sensitive data, the data detection and analysis module monitors the flow and access conditions of the data, and the data auditing and reporting module records access and operation logs of the data. According to the method, an enterprise is helped to quickly deal with and solve security problems, the flow direction of the data is tracked, the source and the destination of the data are known, security holes and risk points in a data transmission path can be identified, and the enterprise is helped to enhance the security of data transmission.
Owner:STATE GRID HUBEI ELECTRIC POWER INFORMATION & TELECOMMUNICATION COMPANY +1

Cross-component metadata access control method and device for credential big data platform

The invention relates to the technical field of big data access control, and discloses a cross-component metadata access control method and device for a credential big data platform, and the method comprises the steps: firstly constructing a metadata virtualization layer used for mapping a plurality of metadata databases, and enabling the metadata virtualization layer to map the plurality of metadata databases; subsequent cross-database field mapping and result aggregation operation can be realized on the metadata virtualization layer, so that each database does not need to be accessed independently, and efficient cross-component access operation is realized. According to the method, the authentication key is designed into the retrieval segment and the key segment, the retrieval segment is only used for retrieving and distinguishing the key, the user side and the metadatabase respectively send the respective key segment to the metadata virtualization layer, and unified authentication of the user side authority is realized through matching of the authentication key in the virtual mapping layer. And the user side does not need to perform independent authentication with each metadatabase, so that the metadata access control efficiency is improved.
Owner:HUAAN SECURITIES CO LTD

Security management system for data access control

The invention relates to the technical field of data security management, and discloses a security management system for data access control. The system comprises an access request receiving unit, a hierarchical analysis unit, a space mapping unit, a permission decision unit and a permission execution unit. The access request receiving unit obtains a data access request of a user, and analyzes a request main body identifier and a request resource identifier. The layering analysis unit carries out layering processing on the resource identification and extracts resource level feature information. And the space mapping unit retrieves the historical access log according to the main body identifier, and constructs an access behavior space distribution model. And the authority decision-making unit generates a dynamic access authority strategy in combination with the resource level characteristics and the access behavior space model. And the permission execution unit controls the access operation of the user to the resources according to the strategy. The system can adapt to a complex data resource structure and realize fine-grained dynamic access control.
Owner:BEIJING ZHONGCHUANG HAISHENG TECHNOLOGY CO LTD

Data access control method and device, storage medium and electronic equipment

The application discloses a data access control method and device, a storage medium and an electronic equipment, relates to the field of computers, and comprises the following steps: receiving a target reading request, the target reading request being used for requesting reading data corresponding to a target time from a storage space in a memory according to target address information; in response to the target reading request, locating a target cache area corresponding to the target address information in a cache space in the memory; and extracting target data of a target snapshot version corresponding to the target time from a reference snapshot version and reference data stored in the target cache area and having a corresponding relationship, so as to solve the technical problems that historical snapshot data reading needs to depend on a rear-end disk and causes low data access efficiency, and achieve the technical effects of realizing cache acceleration of historical snapshot data reading and improving data access efficiency.
Owner:LANGCHAO ELECTRONIC INFORMATION IND CO LTD

System and method for managing access control of data across a distributed system

Methods and systems for managing access and control of data are disclosed. To manage access and control, data management system may require registration and verification of devices associated with an individual or other individuals to which control over access may be granted. Data management system may vest control over access to data to the device associated with the individual for which data is stored, and progressively vest control over access to data to other devices associated with other individuals as an increasing amount of information indicating the lack of capacity of the individual to authorize access to data. When access to data is granted by the individuals, the data may be scrutinized with respect to other types of restrictions on distribution of the data.
Owner:DELL PROD LP

Controlling access to data in a cloud-based software platform based on application authorization

Aspects of the present disclosure relate to systems and methods for managing access to data in a cloud-based software platform. A first cloud-based software application generates first data associated with a user account on the cloud-based software platform. A second cloud-based software application may also be connected to the user account and request access to the first data generated by the first application. The user account sets a collection of access permissions on the first data, where the second cloud-based software application is granted access to the first data subject to the collection of access permissions.
Owner:STRIPE LLC

Access permission control method and device, computer storage medium and electronic equipment

The invention discloses an access permission control method and device, a computer storage medium and electronic equipment, and relates to the field of block chain technology and information security. The method comprises the following steps: acquiring biological characteristic information and access event information of a target object; the access event information is written into a public chain, and the public chain is used for recording data access information; performing Hash operation on the biological characteristic information to obtain a characteristic Hash value; the feature hash value is stored in a private chain, and the private chain is used for verifying the identity of the target object and performing authority management under the condition that the object information of the target object is not exposed; and adjusting the access authority of the target object according to the feature hash value on the private chain and the access event information on the public chain. According to the method and the device, the technical problem of poor information security caused by static management of authority in traditional data access control is solved.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

User-generated content sharing system with fine-grained permission control

This invention discloses a user-generated content sharing system with fine-grained access control, specifically relating to the field of user-generated content sharing and data access control. It includes an end-to-end sharing module for writing published user-generated content into fragment identifiers based on text segments, image objects, and attachment objects, attaching the initial receiving scope and initial re-sharing action to the fragment identifiers, and generating an original shared copy. This invention solves the problem in existing technologies where, when receiving user-generated content, it is impossible to limit the content segments that can be brought out, the receiving object scope, and the re-sharing action based on the current shared copy by splitting user-generated content into fragments and generating an original shared copy.
Owner:SHANGHAI XIANGYUE JIANGFENG DIGITAL TECHNOLOGY CO LTD

Data accessing with a virtual sandbox database

Various embodiments of the present technology generally relate to management of big data storage and data access control systems. In some embodiments, a data access system for use in multiple application service and multiple storage service environments comprises a sandbox database for users, wherein the sandbox database is a virtual database environment via which a user may access datasets according to one or more access policies. In some embodiments, the data access system receives a user request to access a dataset stored in a database into the sandbox environment, wherein the database is associated with the data access system. In response to the request, the data access system may retrieve the corresponding data from the database, determine any associated sandbox access policies, and generate an anonymized data table in the sandbox environment.
Owner:DATABRICKS INC

Data access control method and device, equipment, storage medium and program product

The embodiment of the invention provides a data access control method and device, equipment, a storage medium and a program product, and relates to the field of financial science and technology. According to the method, each asset table in data assets is pre-registered according to a plurality of pre-divided logic isolation units, an isolated asset list is generated, then a data access request issued by a target user is responded, and if a target asset table exists in the isolated asset list, the data access request is sent to the target user based on the role and the service attribute of the target user. According to the method and the device, the data access request is subjected to permission decision making according to the preset access control strategy, the access control instruction is generated, and the access result of the target user is obtained from the isolation asset list based on the access control instruction, so that the technical effect of dynamically adjusting the access permission based on roles and service attributes is realized; and the access control strategies comprise table-level, row-level, column-level and other granularity access control strategies, so that multi-department fine granularity data authority management requirements under different service scenes are met.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Method and apparatus for data access control

A method, device, equipment and storage medium for data access control are provided. The method described herein comprises: receiving a data query request for characterizing a first user's request for target data; obtaining a business data access capability attribute corresponding to the first user and obtaining a business security attribute corresponding to the target data; calling a data access security model to determine a data query processing strategy corresponding to the data query request according to the business data access capability attribute of the first user and the business security attribute of the target data; and calling the data query processing strategy to process the target data and generating a response message for feedback. According to the fact of the present disclosure, by providing a response to the request based on the business data access capability attribute of the user and the business security attribute of the target data, the access of the user to the data can be effectively controlled.
Owner:DOUYIN VISION CO LTD

Multi-modal data processing method and device

The invention provides a multi-modal data processing method and device, and the method comprises the steps: setting an independent centralized configuration center for each business module for a data labeling system comprising a plurality of business modules; when the data annotation system receives a data annotation task, according to a task type corresponding to the data annotation task, requesting and obtaining a corresponding task execution configuration from the centralized configuration center; according to the obtained task execution configuration, processing the multi-modal data associated with the data labeling task; the task execution configuration comprises label system configuration of a data labeling task, large model template configuration of a data reasoning task and role permission configuration of data access control. According to the method and the device, the problems of high module coupling degree, process solidification and difficulty in flexibly and efficiently responding to diversified and frequently-changed multi-modal task requirements of a data annotation platform are solved, and the efficient and flexible delivery capability oriented to various modal data and customization requirements is accelerated.
Owner:SHANGHAI LINKE ZHIHUA DIGITAL TECHNOLOGY CO LTD

Data processing method and device, equipment and storage medium

The embodiment of the invention provides a data processing method and device, equipment and a storage medium. The method comprises the following steps: in response to a received data access request, determining a target data resource related to the data access request and a group of attribute information about the data access request, the group of attribute information at least comprises at least one piece of first attribute information associated with an initiator of the data access request, at least one piece of second attribute information associated with the target data resource and at least one piece of third attribute information associated with the data access operation; determining a matching relationship between the group of attribute information and at least one predetermined access control policy; and processing the data access operation based on the matching relationship. Therefore, finer data access control can be realized.
Owner:XIAN TONGXING HENGYAO INFORMATION TECHNOLOGY CO LTD

Dynamic User Impersonation for Enhanced Data Security and Access Control

The present disclosure relates to dynamic user impersonation to enhance data security and access control in computing environments, such as to allow the configuration and operation of data access controls for one user to be verified by another user. A first identifier value of a user to be impersonated is received and is assigned to a user impersonation variable in a data store. A query associated with a second identifier value of a different user is received, accessing data objects subject to data access controls. The query is executed using the first identifier value to filter requests according to the specified data access controls, and filtered query results are returned. In some cases, the first identifier value is provided as an input parameter to a data object subject to data access controls. In other cases, the first identifier value is set as a session variable for a data store session.
Owner:SAP SE

Block chain-oriented attribute-based fine-grained data access control method and system

The invention belongs to the field of block chain system access control, and discloses a block chain-oriented attribute-based fine-grained data access control method and model, and the method comprises the steps: carrying out the preliminary encryption of business data through employing an AES-128 symmetric encryption algorithm; the encrypted original data is stored in the IPFS; and a CP-ABE algorithm is introduced, a secret key generated by the AES-128 algorithm is subjected to secondary encryption, and the secret key is uploaded to the block chain. According to the method, the access control tree and the corresponding core algorithm are constructed, so that the block chain-based fine-grained access control model is realized. Through contrast experiments, the feasibility and stability of the method are fully verified.
Owner:WUHAN VOCATIONAL COLLEGE OF SOFTWARE & ENG (WUHAN OPEN UNIV)