The invention discloses a fine-grained
access control method and
system based on
risk identification, and belongs to the technical field of
information security. According to the method, user subject attributes, behavior attributes and
system environment attribute information are collected in real time, a standardized
decision matrix is constructed, an interval type-2
fuzzy set (IT2FS) is used for conducting fuzzy modeling on the attributes, and an upper membership matrix and a lower membership matrix are generated. And calculating the dynamic weight of the attribute index in combination with a CRITIC method, introducing a time
decay factor to dynamically correct a risk
score through an improved
TOPSIS method, calculating the
Euclidean distance between an access request and a positive / negative
ideal solution, and generating a normalized risk closeness degree. And based on the risk
score and a preset threshold value, dynamically matching a hierarchical permission strategy, and adopting a static rule and a priority coverage mechanism to eliminate permission conflicts. According to the method, multi-dimensional
risk assessment and dynamic
weight adjustment are fused, the problems of insufficient real-time performance, subjective weight dependence and weak uncertainty
processing capability in a traditional method are solved, the accuracy and security of
access control are remarkably improved, and the method is suitable for scenes with
high security requirements such as
cloud computing and finance.