End-to-end encrypted communication-based permission allocation method and system
By generating a multidimensional vector set and dynamically adjusting the permission level, the problem of rigid permission management in end-to-end encrypted communication is solved, and flexible and secure permission allocation is achieved.
Patent Information
- Application Number
- CN202510528520.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-25
- Publication Date
- 2025-07-25
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The existing end-to-end encrypted communication solutions lack flexibility in dynamic environments, resulting in rigid permission management or security vulnerabilities, making it difficult to take into account both flexibility and security.
By obtaining user permission identification encoding, access scope and behavioral trajectory, multidimensional vector sets are generated, matching scores are calculated, permission levels and access scope are dynamically adjusted, and permission allocation is combined with incremental update algorithms and encryption algorithms.
It realizes dynamic adjustment of permission allocation based on real-time user behavior and context, improves the flexibility and security of permission management, and avoids rigid permission management and security vulnerabilities.
Smart Images

Figure CN120378163A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of dynamic permission allocation, and particularly to a permission allocation method and system based on end-to-end encrypted communication. Background Art
[0002] With the rapid development of the digital society, communication security and privacy protection have become crucial research directions in the field of network technology. As the core means of protecting user data privacy, end-to-end encrypted communication plays an irreplaceable role in fields such as finance, healthcare, and social networking.
[0003] However, while existing methods achieve privacy protection, they often face the dilemma of being difficult to balance flexibility and security. Traditional encrypted communication schemes usually rely on static access control mechanisms, such as permission allocation based on fixed keys or identity authentication. Although these methods ensure data security to a certain extent, they lack adaptability in dynamic environments, especially in scenarios where user attributes are complex and changeable and access policies need to be adjusted in real time, which can easily lead to rigid permission management or security vulnerabilities. Overly strict control may restrict access by legitimate users, while loose policies may increase the risk of unauthorized access.
[0004] How to solve the above technical problems is a technical challenge that those skilled in the art need to overcome. Summary of the Invention
[0005] The present invention provides a permission allocation method and system based on end-to-end encrypted communication to at least partially solve the above technical problems.
[0006] In a first aspect, to solve the above technical problems, the present invention provides a permission allocation method based on end-to-end encrypted communication, including: Obtaining the permission identification code, permission access range, and behavior track of a user to obtain a user attribute set; Mapping the user attribute set into a multi-dimensional vector to generate a multi-dimensional vector set reflecting the dynamic characteristics of the user; Extracting a user vector and an access policy vector from the multi-dimensional vector set, and calculating the matching degree score between the two; If the matching degree score is higher than a first threshold, extracting the corresponding permission identification code and permission expiration period from the permission database to generate a preliminary permission allocation plan including permission level division and permission-related roles; According to the preliminary permission allocation plan, generating a final permission allocation plan based on the permission priority value, matching degree score, and verification rules; Based on the data updated in real time in the user attribute set, using an incremental update algorithm to adjust the dimension values of the permission access range and permission level division in the multi-dimensional vector set and calculate the updated matching degree score; If the updated matching score is lower than the second threshold, remove the corresponding permission identification code from the permission database and generate a dynamic permission allocation scheme.
[0007] In an alternative embodiment, obtaining the user's permission identification code, permission access range, and behavior track to obtain a user attribute set, including: Obtain the user identity identification, behavior track data, and context parameter set from the multi-source information system and perform data cleaning to obtain the initial user attribute set; Use a standardization processing method for the initial user attribute set to perform format conversion on the permission identification code and access range definition to generate a permission attribute set in a unified format; wherein, if there is a permission identification code with inconsistent format in the permission attribute set, correct it through a mapping rule to generate a permission data set; According to the permission data set and the behavior track data, use a clustering algorithm to extract behavior pattern features and generate a user behavior feature set; Through the user behavior feature set and the context parameter set, use an association rule mining method to determine the correspondence between the behavior pattern and the context, and obtain a behavior context association set; For the behavior context association set, use a data fusion method to integrate the permission identification code, access range definition, and behavior pattern features to generate a user attribute set.
[0008] In an alternative embodiment, map the user attribute set to a multi-dimensional vector to generate a multi-dimensional vector set reflecting the user's dynamic characteristics, including: Extract features from the user attribute set to generate an initial multi-dimensional vector; Assign an initial weight to the multi-dimensional vector according to the permission level and access range to obtain a weighted vector; Obtain context parameters. When the context parameters meet the preset threshold, adjust the weight value of the weighted vector through an iterative algorithm to determine the dynamic weight vector; the context parameters include: access time, device type, and the proportion of access during working hours; For the dynamic weight vector, use a clustering algorithm based on access frequency and module preference to divide user features; Extract significant attributes from the feature grouping. If the significant attributes match the permission level, generate the corresponding vector set; Combine the vector set with the context parameters to obtain a multi-dimensional vector set reflecting the user's dynamic characteristics.
[0009] In an alternative embodiment, extract the user vector and the access policy vector from the multi-dimensional vector set and calculate the matching score between the two, including: Extract the user vector and the access policy vector from the multi-dimensional vector set; wherein the user vector is generated based on user attributes; the access policy vector is generated based on permission rules; Generate a vector dimension description by obtaining the permission identification code and priority value of the user vector, as well as the permission identification code and priority value of the access policy vector; Perform normalization processing on each dimension of the vector based on the vector dimension description to ensure that the units of all dimensions are consistent; Calculate the distance between the user vector and the access policy vector using the Euclidean distance formula; if the distance result is less than the distance threshold, match the corresponding score data based on the distance; if the distance result is greater than or equal to the threshold, the score data is configured as a fixed basic score.
[0010] In an alternative implementation, according to the preliminary permission assignment scheme, if the matching degree score is higher than the first threshold, extract the corresponding permission identification code and permission expiration period from the permission database, and generate a preliminary permission assignment scheme including permission level division and permission associated roles, including: Compare the matching degree score between the user vector and the access policy vector with a preset first threshold; When the matching degree score is higher than the first threshold, extract the corresponding permission identification code and permission expiration period from the permission database based on the association information between the user vector and the access policy vector; where the permission identification code is a unique string used to clarify the specific permission type; the permission expiration period is used to specify the validity of the permission within the set time range; Based on the extracted permission identification code and combined with the permission level division rules, divide the permissions into levels; Determine the permission associated roles according to the user's role information and the association rules between permissions and roles; Integrate the extracted permission identification code, permission expiration period, the divided permission levels, and the determined permission associated roles to generate a preliminary permission assignment scheme including permission level division and permission associated roles.
[0011] In an alternative implementation, according to the preliminary permission assignment scheme, generate a final permission assignment scheme based on the permission priority value, matching degree score, and verification rules, including: Obtain a permission assignment request and parse the permission priority value and verification rules from the permission assignment request; where the permission priority value is converted into a numerical form and the verification rules are recorded to generate an initial permission assignment data set; the initial permission assignment data set includes permission identification, priority value, and association rules; Calculate the matching degree score for each permission to form a set of matching degree scores; Calculate the confidence level for each permission to obtain a set of confidence levels; if the confidence level of one permission is greater than the confidence level threshold, sort the permission assignment scheme according to the confidence interval of the permission's confidence level to obtain a candidate permission assignment scheme; if the confidence level is less than the confidence level threshold, record the abnormal status of the permission in the assignment log; Verify whether the candidate permission allocation scheme complies with the permission verification rules; if it complies with the rules, generate an optimized permission allocation scheme; if it does not comply with the rules, recalculate the confidence level; Generate a permission allocation log through the optimized permission allocation scheme, record the allocation time, permission identifier, and confidence level, and form an allocation log set; Extract the permission records that have not been completed from the allocation log set, and loop through the above steps until all permissions are allocated to obtain the final permission allocation scheme.
[0012] In an alternative embodiment, based on the real-time updated data in the user attribute set, an incremental update algorithm is used to adjust the dimension values of the permission access range and the permission level division in the multi-dimensional vector set and calculate the updated matching degree score, including: Obtain user behavior data and environmental parameters from the real-time data stream, parse the user behavior data and environmental parameters to identify the user's dynamic interaction pattern, and generate an initial behavior pattern vector set; the initial behavior pattern vector set includes operation frequency, time preference, and environmental characteristics; Allocate a context weight value for the environmental parameters according to their importance; adjust the initial behavior pattern vector set according to the allocated context weight value, and update the dimension value of the permission access range in the multi-dimensional vector set to obtain an adjusted vector set; Recalculate the distance between vectors in the permission level dimension to obtain an updated distance set; if any distance in the distance set is less than the confidence distance threshold, it indicates that the permission range needs to be re-divided; re-divide the permission access range according to the dynamic interaction pattern to obtain a candidate permission range set; For the candidate permission range set, verify whether the change in the behavior pattern complies with the context weight value constraint. If it does not comply, eliminate the candidate range to generate an optimized permission range set; extract the matching degree score of each permission range from the optimized permission range set, allocate weights to each dimension, and use the weighted average method to calculate the comprehensive matching degree score to obtain an updated matching degree score set.
[0013] In an alternative embodiment, if the updated matching degree score is lower than the second threshold, remove the corresponding permission identifier code from the permission database to generate a dynamic permission allocation scheme, including: Compare the updated matching degree score with the preset second threshold. When the updated matching degree score is lower than the second threshold, query and obtain the permission identifier code corresponding to the current user from the permission database; Remove the corresponding permission identifier code from the permission database and generate a permission change record; Use the log recording mechanism to write the permission adjustment time and trigger event into the permission allocation log according to the time stamp and event association method to obtain the permission adjustment log data; Extract the event trigger condition based on the permission adjustment log data; determine whether the event trigger condition meets the requirements of dynamic permission allocation; if the trigger condition indicates that the user behavior is abnormal, generate a corresponding dynamic allocation trigger signal; Call the permission management solution according to the dynamic allocation trigger signal to generate a dynamic permission allocation solution.
[0014] In an alternative embodiment, the method further includes: encrypting the permission identifier encoding based on the encryption algorithm type and the key distribution mechanism to generate an encrypted communication data stream including data stream shards and an encryption check code, specifically including: Adopt a sharded transmission mechanism, and divide the permission identifier encoding into different parts according to the MAC address or IP address of the communication module to obtain permission shard data; wherein, different parts are respectively used to identify the user identity and the permission type; Through the key distribution mechanism, select the corresponding encryption algorithm key from the key pool storing multiple algorithm keys according to the permission shard data type; Judge whether the encryption key set meets the matching conditions of the end-to-end encryption protocol; if the conditions are met, use the selected encryption algorithm to encrypt the permission shard data to obtain an encrypted permission data stream; Adopt the data stream sharding technology to divide the encrypted permission data stream into multiple shards, and attach a check identifier to each shard to form a sharded data packet set including the check identifier to obtain a sharded data packet set; After the communication module obtains the sharded data packet set, adopt an encryption check mechanism to compare the check identifier in the received sharded data packet with the preset check rule to judge whether the data is tampered with, and obtain a data packet that passes the check.
[0015] In a second aspect, the present invention provides a permission allocation system based on end-to-end encrypted communication, including: A first processing module, configured to: obtain the permission identifier encoding, permission access range and behavior track of the user to obtain a user attribute set; A second processing module, configured to: map the user attribute set into a multi-dimensional vector to generate a multi-dimensional vector set reflecting the dynamic characteristics of the user; A third processing module, configured to: extract the user vector and the access policy vector from the multi-dimensional vector set, and calculate the matching degree score between the two; A fourth processing module, configured to: if the matching degree score is higher than the first threshold, extract the corresponding permission identifier encoding and permission validity period from the permission database, and generate a preliminary permission allocation solution including permission level division and permission associated roles; A fifth processing module, configured to: generate a final permission allocation solution based on the preliminary permission allocation solution, based on the permission priority value, the matching degree score and the check rule; The sixth processing module is used to: based on the real-time updated data in the user attribute set, adopt an incremental update algorithm to adjust the dimension values of the permission access range and permission level division in the multi-dimensional vector set and calculate the updated matching degree score; The seventh processing module is used to: if the updated matching degree score is lower than the second threshold, remove the corresponding permission identification code from the permission database and generate a dynamic permission allocation scheme.
[0016] Compared with the prior art, the present invention has at least the following beneficial effects: extracting corresponding permission information from the permission database, generating a preliminary permission allocation scheme, and optimizing it through a fuzzy logic evaluation rule. In addition, the present invention can also dynamically adjust the permission allocation according to the real-time changing user behavior and context. Description of the Drawings
[0017] Figure 1 is a schematic flowchart of a permission allocation method based on end-to-end encrypted communication provided by the first embodiment of the present invention; Figure 2 is a block diagram of a permission allocation system based on end-to-end encrypted communication provided by the second embodiment of the present invention. Detailed Embodiments
[0018] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0019] Refer to Figure 1 , the first embodiment of the present invention provides a permission allocation method based on end-to-end encrypted communication, including the following steps: S101, obtaining the permission identification code, permission access range and behavior track of the user to obtain a user attribute set; S102, mapping the user attribute set into a multi-dimensional vector to generate a multi-dimensional vector set reflecting the dynamic characteristics of the user; S103, extracting the user vector and the access policy vector from the multi-dimensional vector set and calculating the matching degree score between the two; S104, if the matching degree score is higher than the first threshold, extracting the corresponding permission identification code and permission validity period from the permission database to generate a preliminary permission allocation scheme including permission level division and permission associated roles; S105, generating a final permission allocation scheme based on the preliminary permission allocation scheme, the permission priority value, the matching degree score and the verification rule; S106. Based on the data that is updated in real time in the user attribute set, use an incremental update algorithm to adjust the dimension values of the permission access scope and permission level division in the multi-dimensional vector set, and calculate the updated matching degree score. S107. If the updated matching degree score is lower than the second threshold, remove the corresponding permission identification code from the permission database and generate a dynamic permission allocation scheme.
[0020] In one implementation, obtaining the user attribute set by acquiring the user's permission identification code, permission access scope, and behavior track includes: Obtain the user identity identification, behavior track data, and context parameter set from the multi-source information system and perform data cleaning to obtain the initial user attribute set. Use a standardization processing method to perform format conversion on the permission identification code and access scope definition in the initial user attribute set to generate a permission attribute set in a unified format; among them, if there is a permission identification code with inconsistent format in the permission attribute set, it is corrected through a mapping rule to generate a permission data set. According to the permission data set and the behavior track data, use a clustering algorithm to extract behavior pattern features and generate a user behavior feature set. Through the user behavior feature set and the context parameter set, use an association rule mining method to determine the correspondence between the behavior pattern and the context, and obtain a behavior context association set. For the behavior context association set, use a data fusion method to integrate the permission identification code, access scope definition, and behavior pattern features to generate a user attribute set.
[0021] Specifically, the data acquisition of the multi-source information system is the basis for building a user portrait. For example, employee ID cards, access control records, VPN login logs, and application access logs all belong to the category of multi-source information systems. The user identity identification, behavior track data, and context parameter set obtained from these systems constitute the initial data source, but this data often has redundancy and noise. For example, the access control record of employee Zhang may contain duplicate card swiping records, which belong to redundant data; while incorrect timestamps belong to noise data. In order to obtain more effective data, a data cleaning method needs to be used. This method mainly retains valid records such as Zhang's first card swiping time every day and the actual VPN connection duration through deduplication and outlier filtering, so as to obtain the initial user attribute set.
[0022] The initial set of user attributes needs to be standardized. The permission identification code and access scope definition may exist in multiple formats in different scenarios. To facilitate unified processing by the system, they need to be converted into a unified format, and then a unified format of permission attributes set is generated. Taking the permission identification as an example, it may appear in the form of department code plus numbers. For example, DEV001 represents a certain permission of the development department, while the access scope may be expressed as "read and write in the code repository" or "read only". During the standardization process, DEV001 will be converted into a unified prefix format, such as PERM-DEV-001, and the access scope will be defined as an enumerated value. For example, RW represents read and write, and RO represents read only.
[0023] If there are permission identification codes with inconsistent formats in the permission attributes set, such as some permissions still in the old format DEV-001, it is necessary to correct them to the unified format, that is, PERM-DEV-001, through the preset mapping rules, so as to ensure a unified and standardized permission data set. Based on the obtained permission data set and behavior trace data, a clustering algorithm is used to extract behavior pattern features. The clustering algorithm is an algorithm that groups data points into sets of similar objects. For example, the commonly used K-means clustering algorithm. Taking Zhang as an example, his permission is PERM-DEV-001, and the behavior trace shows that he submits code 5 times a week and the proportion of accessing the code repository at night is 30%. Through the K-means clustering algorithm, users can be divided into different groups such as "high-frequency submitters" and "regular developers". Due to characteristics such as high submission frequency and night-time activity, Zhang will be classified as a high-frequency submitter, and these characteristics constitute the user behavior feature set.
[0024] Combining the user behavior feature set with the context parameter set (including information such as time, location, and device type), and using the association rule mining method, the corresponding relationship between the behavior pattern and the context can be determined. Association rule mining is a process of discovering interesting associations between item sets from a large amount of data. For example, Zhang often submits code using the company's laptop in the R & D building from Monday to Friday. Through association rule mining, a strong association such as "high-frequency submitter → R & D building on weekdays → laptop" may be discovered. This result is the behavior context association set. This association set shows that Zhang's active behavior is closely related to the work environment, providing a basis for dynamically adjusting permissions.
[0025] For the behavior context association set, the data fusion method is used to integrate the permission identification code, access scope definition and behavior pattern characteristics to generate a user attribute set. For example, Zhang's structured user attribute set may include: permission code PERM-DEV-001, access scope RW, behavior pattern high frequency submitter, context workday R&D building. Such a user attribute set clearly describes the user's full picture, allowing the permission management system to flexibly and dynamically adjust the access scope based on the user's behavior and context. For example, during non-working hours, the system can limit its RW permissions to RO to improve the security of the system.
[0026] The technical effects brought by the above method include improved data consistency, accurate description of behavior patterns, and intelligent permission management. The user attribute set provides a unified decision-making basis for the system, avoiding permission allocation errors caused by inconsistent data formats or misjudgment of behavior, and realizing refined management through context association, taking into account both efficiency and security.
[0027] In one implementation, a user attribute set is mapped into a multidimensional vector to generate a multidimensional vector set reflecting the user's dynamic characteristics, including: Extract features from the user attribute set to generate an initial multi-dimensional vector; Assigning initial weights to the multidimensional vectors according to the permission level and access scope to obtain a weighted vector; Obtaining context parameters, and when the context parameters meet a preset threshold, adjusting the weight value of the weighted vector through an iterative algorithm to determine a dynamic weight vector; the context parameters include: access time, device type, and access ratio during working hours; For the dynamic weight vector, a clustering algorithm based on access frequency and module preference is used to divide user characteristics; Extract salient attributes from the feature groupings. If the salient attributes match the permission level, generate the corresponding vector set. The vector set is combined with the context parameters to obtain a multidimensional vector set that reflects the dynamic characteristics of the user.
[0028] Specifically, extracting features from the user attribute set is the basis for constructing the initial multidimensional vector. The user attribute set contains rich information, such as the employee's ID, department, historical access records, etc. Through statistical analysis methods, key features can be obtained from this information, such as the average access frequency of employees, the type of modules they mainly access, etc. Taking an internal system of an enterprise as an example, if you want to analyze the access behavior of employees, the vector of one of the employees may contain dimensional information such as the access frequency of 5 times a week and the main access to the financial module. This multidimensional vector constructed based on user basic information and behavior data can intuitively reflect the characteristics of user behavior.
[0029] To enable the multi-dimensional vector to more accurately reflect user privilege-related features, it is necessary to assign initial weights to it according to the privilege level and access scope. The privilege level is usually divided into different levels in the system. Suppose the system defines three levels of privileges, namely high, medium, and low privileges, and the corresponding weights are set as 0.8, 0.5, and 0.3 respectively. The access scope is measured by the number of modules accessed by the employee. For example, the weight of an employee who accesses 3 modules increases by 10%. If a high-privilege employee accesses 2 modules, according to the above rules, the initial weight of its vector is calculated as 0.8×1.1 = 0.88. This weighting method can highlight the contribution degrees of the privilege level and the access scope to the features, thereby enhancing the discrimination of the vector expression.
[0030] The context parameters mainly include information such as access time, device type, and the proportion of access during working hours. The system will preset thresholds. When the obtained context parameters meet these preset thresholds, an iterative algorithm will be started to adjust the weight values of the weighted vector. For example, if the threshold for the proportion of access during working hours is set at 80%, when 90% of an employee's accesses occur during working hours, the threshold condition is met, and at this time, it enters the weight adjustment stage. The iterative algorithm optimizes the weights by analyzing historical data. For example, for an employee who frequently accesses at night, their weight may be reduced by 10% to generate a dynamic weight vector. This dynamic adjustment mechanism can better adapt to the changes in user behavior and make the vector more accurately reflect the current behavior characteristics of the user. It should be noted that when obtaining context parameters and determining whether they meet the preset thresholds, parameters such as access time and device type can be set.
[0031] For the generated dynamic weight vector, a clustering algorithm based on access frequency and module preference is used to divide user features. The clustering algorithm is a technique that groups data points into sets of similar objects. Through this algorithm, users with similar behavior patterns can be grouped into one group. For example, the system performs clustering based on access frequency and module preference. If an employee's vector shows that they frequently access the finance module, then this employee will be classified into the "finance active group". Through such a grouping method, the system can identify groups of employees with similar behavior patterns, which helps to discover common features among users.
[0032] After completing the grouping of user characteristics, significant attributes are extracted from each characteristic group. A significant attribute refers to an attribute that is representative in the group and can highlight the characteristics of the group. When extracting significant attributes from the characteristic group and matching the permission levels, the high-frequency behaviors within the group can be focused on. For example, the significant attribute of the "financially active group" may be that the access proportion to the financial module exceeds 70%. Then, these significant attributes are matched with the permission levels. If a significant attribute matches a certain permission level, a corresponding vector set is generated. For example, when the significant attribute of the group where an employee belongs matches the high permission level, the generated vector set will highlight the employee's characteristics in the financial module and correspond to the high permission, ensuring the consistency between the vector set and the permission system.
[0033] Through the preset mapping rules, the generated vector set is combined with the context parameters. For example, the system can design a mapping table to associate different behaviors and scenarios. Suppose the mapping rule stipulates that accessing during working hours corresponds to the "high credibility" label. When an employee's vector set is combined with its context parameters (such as accessing during working hours), the final feature vector will be generated and labeled as "high credibility and financially active". This combination method can comprehensively depict the user characteristics, fully considering the relationship between user behavior, permissions, and context, providing a more reliable and multi-dimensional vector set that can reflect the dynamic characteristics of users for the system.
[0034] The above method forms the final user feature vector set step by step through steps such as multi-dimensional vectors, dynamic weights, and feature grouping. Each step focuses on user behavior and permissions, with a strict logic and mutual support. In the example, the behavior characteristics of the employee are refined step by step from extraction to optimization, and finally a precise feature representation is formed. This method helps to improve the accuracy and applicability of the user portrait in the enterprise internal system.
[0035] In one implementation, the user vector and the access policy vector are extracted from the multi-dimensional vector set, and the matching degree score between the two is calculated, including: Extract the user vector and the access policy vector from the multi-dimensional vector set; where the user vector is generated based on user attributes; the access policy vector is generated based on permission rules; Obtain the permission identification code and priority value of the user vector and the permission identification code and priority value of the access policy vector to generate a vector dimension description; Based on the vector dimension description, standardize each dimension of the vector to ensure that the units of all dimensions are consistent; Use the Euclidean distance formula to calculate the distance between the user vector and the access policy vector; if the distance result is less than the distance threshold, match the corresponding score data based on the distance; if the distance result is greater than or equal to the threshold, the score data is configured as a fixed base score.
[0036] Specifically, the multi-dimensional vector set is obtained after a series of processes on the user attribute set. Among them, the user vector is generated based on user attributes, which contains multi-dimensional information such as age, department, role, etc. These information comprehensively reflect the characteristics of the user. For example, a user vector may be [25, "Technical Department", "Engineer"], representing that the user is 25 years old, from the Technical Department, and holds the role of an engineer.
[0037] The access policy vector is generated according to the permission rules, covering information such as resource type and operation permissions. For example, the access policy vector is ["Document", "Read / Write"], indicating the read / write operation policy for document resources. By extracting these two types of vectors from the multi-dimensional vector set, it provides the basic data for subsequent matching degree calculation.
[0038] After extracting the user vector and the access policy vector, it is necessary to obtain their respective permission identification codes and priority values, and generate vector dimension descriptions. The permission identification code is used to uniquely determine the permission category corresponding to the user or policy. For example, "USER_ADMIN" represents the administrator user permission, and "READ_ONLY" represents the read-only permission. The priority value represents the priority level of the permission in integer form. Usually, 1 is set as the highest priority and 5 as the lowest. The vector dimension description is a detailed explanation of the semantics and numerical range of each dimension of the vector. For example, the age dimension of the user vector may be in the integer range of 18 to 60, and the department dimension is a predefined set of strings; the resource type of the access policy vector may be "Document", "Database", etc. Through the dimension description, it can ensure that the units of each dimension are consistent when calculating the distance.
[0039] To ensure that the units of each dimension are consistent when calculating the distance, it is necessary to perform standardization processing on each dimension of the vector based on the vector dimension description. The data types and numerical ranges of different dimensions vary greatly. Without standardization processing, it will lead to inaccurate calculation results. For example, the numerical range of the age dimension is relatively large and needs to be normalized to the range of 0 to 1 to make it comparable with other dimensions in calculation; the department dimension is usually in string form and needs to be converted to discrete coding to accurately reflect the differences between dimensions when calculating the distance. Through this standardization processing, the impact of the differences in data of different dimensions on the calculation results is eliminated, and the accuracy of distance calculation is improved.
[0040] The Euclidean distance formula d = √(∑(x_i - y_i)^2) is used to calculate the distance between the user vector and the access policy vector. Here, x_i is the value of the i-th dimension of the user vector, and y_i is the value of the i-th dimension of the access policy vector. During the calculation process, the dimension differences are quantified one by one. For example, assume that the normalized difference in the age dimension between the user vector and the access policy vector is 0.1, the difference in the department dimension match is 0, and the difference in the role dimension is 0.2. These differences are calculated according to the Euclidean distance formula, and the square root is taken after accumulation to obtain the distance result.
[0041] The system will preset a distance threshold. If the calculated distance result is less than this threshold, it indicates that the fit between the user vector and the access policy vector is relatively high. At this time, based on the preset corresponding relationship, the corresponding score data is matched for this distance, and this score data can intuitively reflect the matching degree between the user and the policy; if the distance result is greater than or equal to the threshold, it indicates that the fit between the two is relatively low. At this time, the score data is configured as a fixed basic score, which is a unified score preset in advance and is used as the default score when the matching degree between the two is not good. For example, it is set to 50 points.
[0042] After the matching degree score is generated, the permission identification code associated with the access policy vector can be further extracted. Assume that a score of 90 corresponds to "DOC_RW", and based on this, the basis for the permission allocation for the user to read and write documents can be determined. If the score is only 50 points, then only the "DOC_READ" permission may be allocated. Such a mapping ensures the rationality of permission allocation.
[0043] When extracting the priority value from the permission allocation basis, the access condition can be set as the priority value being less than or equal to 3. For example, the priority value of "DOC_RW" is 2, which meets the condition, and the verification result is passed; if the priority value is 4, the verification fails, and only low-level access is allowed. This hierarchical verification improves the flexibility of permission management.
[0044] In one embodiment, when sorting the matching degree scores, the quicksort algorithm can be used. For example, the scores of multiple user vectors are 90, 75, and 50 respectively. After sorting, the sequence is [90, 75, 50], and the corresponding users obtain the priority to allocate permissions in turn. This sorting facilitates optimizing the allocation efficiency when resources are limited.
[0045] The above implementation method ensures the dynamics and consistency of permission allocation through clear vector extraction, distance calculation, and sorting logic. The combination of priority verification and score sorting can quickly screen eligible users in high-load scenarios, significantly improving the response speed of permission management.
[0046] In one implementation, according to the preliminary permission allocation scheme, if the matching degree score is higher than the first threshold, the corresponding permission identification code and permission validity period are extracted from the permission database, and a preliminary permission allocation scheme including permission level division and permission-related roles is generated, including: Compare the matching degree score of the user vector and the access policy vector with a preset first threshold; When the matching degree score is higher than the first threshold, according to the association information between the user vector and the access policy vector, extract the corresponding permission identification code and permission validity period from the permission database; among them, the permission identification code is a unique string, used to clarify the specific permission type; the permission validity period is used to specify the validity of the permission within the set time range; Based on the extracted permission identification code and combined with the permission level division rules, divide the permissions into levels; Determine the permission-related roles according to the user's role information and the association rules between permissions and roles; Integrate the extracted permission identification code, permission validity period, the divided permission levels and the determined permission-related roles to generate a preliminary permission allocation scheme including permission level division and permission-related roles.
[0047] Specifically, after obtaining the matching degree score of the user vector and the access policy vector, it is necessary to compare this score with a preset first threshold. The setting of the first threshold is determined comprehensively based on various factors such as the security requirements of the system and business needs. For example, in the permission management scenario of an enterprise, for resource access involving sensitive data, in order to ensure data security, a relatively high first threshold will be set; while for the access to general resources, the first threshold may be relatively low. The method of setting different thresholds according to different business scenarios makes the permission allocation more in line with the actual needs.
[0048] When the matching degree score is higher than the first threshold, the system will extract the corresponding permission identification code and permission validity period from the permission database according to the association information between the user vector and the access policy vector. The permission identification code is a unique string, which is like the "ID card" of the permission and is used to clarify the specific permission type. For example, "MKT_RW" can represent the read and write permissions of the marketing department, and different permissions can be accurately identified through such codes. The permission validity period specifies the validity of the permission within a specific time range. For example, "2025-12-31" means that this permission is valid before this date and will not be available after expiration.
[0049] Based on the extracted permission identification code, the system will classify permissions according to the pre-established permission hierarchy division rules. The permission hierarchy division rules are formulated based on factors such as the importance, sensitivity level, and operation scope of permissions. Suppose the system divides permissions into three levels: high, medium, and low. Permissions involving core business operations and capable of accessing sensitive data, such as the read and write permissions of the key database by the system administrator, may be classified as high-level permissions; while some general business operation permissions, like the viewing permissions of some public documents by ordinary employees, may be classified as low-level permissions.
[0050] The system determines the permission-associated roles based on the user's role information and the pre-set association rules between permissions and roles. The user's role information can include the user's position, department, etc., such as "Marketing Manager", "Technical Engineer", etc. The association rules between permissions and roles clarify the permission scope corresponding to different roles. For example, in an enterprise, it is stipulated that the role corresponding to medium-level permissions is "Department Manager". Then, when a certain user is assigned medium-level permissions, according to this association rule, this user will be determined as the "Department Manager" role. The setting of this association rule ensures the consistency between permission allocation and user roles.
[0051] The system integrates the extracted permission identification code, permission expiration date, the divided permission hierarchy, and the determined permission-associated roles to generate a preliminary permission allocation plan including permission hierarchy division and permission-associated roles. For example, for the user "Zhang Wei", whose matching score is higher than the first threshold, the permission identification code extracted from the permission database is "MKT_RW", the permission expiration date is "2025-12-31", it is determined as medium-level permission after permission hierarchy division, and according to the association rules between permissions and roles, its associated role is determined as "Department Manager". Then the generated preliminary permission allocation plan includes medium-level permission, the role of "Department Manager", the permission identification code "MKT_RW", and the expiration date "2025-12-31".
[0052] It provides clear permission information for users, enhancing the traceability and transparency of permission management; through this series of steps, the process of generating a preliminary permission allocation plan based on the matching score is achieved, providing a basis for further optimizing permission allocation in the future, ensuring the rationality and effectiveness of permission allocation, and ensuring that the system can achieve secure permission management in different user and business scenarios.
[0053] In one implementation, a final permission allocation plan is generated based on the permission priority value, matching score, and verification rules, including: Obtain a permission assignment request and parse the permission priority value and verification rules from the permission assignment request; among them, convert the permission priority value into a numerical form and record the verification rules to generate an initial permission assignment dataset; the initial permission assignment dataset includes a permission identifier, a priority value, and an association rule; Calculate the matching degree score for each permission to form a set of matching degree scores; Calculate the confidence level of each permission to obtain a set of confidence levels; if the confidence level of one permission is greater than the confidence level threshold, then sort the permission assignment plan according to the confidence interval of the permission's confidence level to obtain a candidate permission assignment plan; if the confidence level is less than the confidence level threshold, record the abnormal status of this permission in the assignment log; Verify whether the candidate permission assignment plan complies with the permission verification rules; if it complies with the rules, generate an optimized permission assignment plan; if it does not comply with the rules, recalculate the confidence level; Generate a permission assignment log through the optimized permission assignment plan, record the assignment time, permission identifier, and confidence level, and form a set of assignment logs; Extract the permission records that have not been completed for assignment from the set of assignment logs, and loop through the above steps until all permissions are assigned to obtain the final permission assignment plan.
[0054] Specifically, the permission assignment request contains a lot of information that plays a key role in permission assignment. Among them, the permission priority value is used to reflect the difference in the importance of different permissions, and is commonly distinguished as high, medium, and low. For the convenience of subsequent calculation and comparison, the system will convert these priority values into specific numerical forms. For example, it is set that the high priority corresponds to the numerical value 3, the medium priority corresponds to 2, and the low priority corresponds to 1. The verification rules are used to ensure that the permission assignment process complies with the established security policies and business rules, such as "only administrators can assign high-level permissions".
[0055] After extracting this information from the permission assignment request, the system integrates the permission identifier, the converted priority value, and the associated verification rules to generate an initial permission assignment dataset. For example, assume there are 3 permission requests: permission A has a high priority, permission B has a medium priority, and permission C has a low priority. The system will generate a dataset that includes the permission identifiers of permissions A, B, and C respectively, the corresponding priority numerical values (such as permission A corresponding to 3, permission B corresponding to 2, and permission C corresponding to 1), and the verification rules associated with them.
[0056] After obtaining the initial permission allocation dataset, the matching degree score of each permission is calculated with the help of fuzzy logic rules. Fuzzy logic rules are a method that can effectively handle the uncertainty in permission allocation. In actual application scenarios, permission allocation is often affected by various complex factors and is difficult to judge with simple precise logic, while fuzzy logic rules can exactly handle this situation. The system will pre-define a series of fuzzy rules, such as "if the priority is high and it conforms to the rules, then the matching degree is high". Taking permission A as an example, assuming its priority is high and it conforms to the administrator rules, according to this fuzzy rule, its matching degree score may be judged as 0.9; permission B partially conforms to the rules, and its score may be 0.6; permission C has a low priority, and its score may be only 0.3. By applying these fuzzy rules to each permission in the dataset, the system obtains a set of matching degree scores.
[0057] The weighted average method is adopted. Combining the pre-set weight w_i and the calculated matching degree score s_i, the confidence level P of each permission is calculated according to the formula P = ∑(w_i * s_i) / ∑w_i, where w_i represents the weight of the i-th dimension, and s_i is the score of the i-th dimension. The setting of the weight w_i is determined according to the importance of different dimensions of the permission in the entire permission system. For example, for the permission dimension involving access to core business data, a relatively high weight may be assigned to highlight its importance in permission evaluation; while for some relatively minor permission dimensions, a lower weight is assigned.
[0058] Assume that the weights of permissions A, B, and C are 0.5, 0.3, and 0.2 respectively. Combining the previously calculated matching degree scores (permission A is 0.9, permission B is 0.6, and permission C is 0.3), through weighted average calculation, it can be obtained that: the confidence level of permission A is 0.85, the confidence level of permission B is 0.65, and the confidence level of permission C is 0.45. The confidence levels of all permissions form a confidence level set.
[0059] The system will preset a confidence level threshold, which is set according to the system's requirements for the accuracy and security of permission allocation. If the confidence level of a certain permission is greater than this threshold, it means that the allocation of this permission has a relatively high reliability. The system will sort the permission allocation schemes according to the confidence interval of the permission confidence level to obtain a candidate permission allocation scheme. The confidence interval is a range representing the reliability degree of the confidence level. A narrower confidence interval means that the fluctuation of the confidence level is smaller and its reliability is higher. On the contrary, if the confidence level of a certain permission is less than the confidence level threshold, it indicates that there is a certain risk in the permission allocation. The system will record the abnormal status of this permission in the allocation log, and the allocation log is used to detail the abnormal situations in the permission allocation process.
[0060] For the obtained candidate permission allocation scheme, the system will perform verification based on the previously recorded verification rules. For example, if there is a verification rule that "permission A requires administrator approval", the system will check whether the allocation of permission A in the candidate scheme has been approved by the administrator. If the candidate scheme meets all permission verification rules, it indicates that the scheme is reliable in terms of the compliance of permission allocation, and the system will determine it as the optimized permission allocation scheme; if it does not meet the rules, the system will adjust the weight w_i and recalculate the confidence level. This is because the adjustment of the weight may change the confidence level of the permission, thereby affecting the rationality of the permission allocation scheme. By recalculating the confidence level and performing screening and verification again until an optimized scheme that meets the rules is obtained, the security risks caused by unreasonable permission allocation are avoided.
[0061] After determining the optimized permission allocation scheme, the system will generate a permission allocation log. The log details key information such as the allocation time, permission identifier, and confidence level. For example, the log records that permission A was allocated at "2025-04-14 10:00" with a confidence level of 0.85. These logs are stored indexed by time order and permission identifier, forming an allocation log set. The allocation log set provides a strong basis for the monitoring and auditing of the system, facilitating managers to view the historical records of permission allocation at any time.
[0062] The system will extract the permission records with uncompleted allocation from the allocation log set, and for these records, the above steps of calculating the matching degree score, confidence level, and verifying the scheme will be executed again in a loop. For example, assume that permission B was not completed in the initial allocation due to non-compliance with the rules. The system will adjust its weight and recalculate the confidence level, and perform verification and screening again. After multiple loop processes, until all permissions are allocated, a complete final permission allocation scheme is finally obtained.
[0063] In summary, through the application of fuzzy logic and confidence level calculation, the present invention enables the system to flexibly and dynamically adapt to complex permission scenarios. At the same time, through detailed log records and loop processing mechanisms, the transparency and completeness of permission allocation are improved, effectively ensuring the security and stability of the system.
[0064] In one implementation manner, based on the real-time updated data in the user attribute set, an incremental update algorithm is used to adjust the dimension values of the permission access range and permission level division in the multi-dimensional vector set and calculate the updated matching degree score, including: Obtain user behavior data and environmental parameters from the real-time data stream, parse the user behavior data and environmental parameters to identify the dynamic interaction patterns of the user, and generate an initial behavior pattern vector set; the initial behavior pattern vector set includes operation frequency, time preference, and environmental characteristics; Assign context weight values to environmental parameters according to their importance; adjust the initial set of behavior pattern vectors based on the assigned context weight values, update the dimension values of the access scope in the multi-dimensional vector set, and obtain the adjusted vector set; Recalculate the distances between vectors in the permission level dimension to obtain an updated set of distances; if any distance in the distance set is less than the confidence distance threshold, it indicates that the permission scope needs to be re-divided; re-divide the permission access scope according to the dynamic interaction pattern to obtain a candidate permission scope set; For the candidate permission scope set, verify whether the change in the behavior pattern conforms to the context weight value constraint. If not, eliminate the candidate scope to generate an optimized permission scope set; extract the matching degree scores of each permission scope from the optimized permission scope set, assign weights to each dimension, and calculate the comprehensive matching degree score using the weighted average method to obtain the updated set of matching degree scores.
[0065] Specifically, obtaining user behavior data and environmental parameters from the real-time data stream is a key link for the permission management system to capture the dynamic interaction characteristics of users. User behavior data includes login time, operation type (such as view, edit, etc.), and environmental parameters cover device type, IP address, etc. The system parses these data to identify the dynamic interaction pattern of users, and then generates an initial set of behavior pattern vectors. The pattern vector set includes dimensions such as operation frequency, time preference, and environmental characteristics, which can reflect the interaction habits of users in a specific scenario. For example, if a user frequently views reports during working hours (such as 9:00 - 17:00), and the environmental parameters show a fixed office IP, the system will record their behavior as high-frequency query and generate an initial set of behavior pattern vectors including dimensions such as operation frequency (high frequency), time preference (9:00 - 17:00), and environmental characteristics (fixed office IP). Suppose a user logs in to the system daily from 9:00 - 17:00, the operation type is query, and uses an office computer. The generated vector set includes the time dimension value 9:00 - 17:00, the operation dimension value query, and the environmental dimension value fixed device.
[0066] The system assigns context weight values to environmental parameters according to their importance. The context weight value reflects the relative importance of different environmental parameters in permission evaluation. For example, the weight of the office IP is set to 0.6, and the weight of the device type is 0.4. Based on the assigned context weight values, the system adjusts the initial set of behavior pattern vectors, thereby updating the dimension values of the access scope in the multi-dimensional vector set to obtain the adjusted vector set. This adjustment mechanism can dynamically adapt to changes in user behavior. For example, if a user logs in from a non-office IP, the system will reduce the value of the environmental dimension, so that the adjusted vector set reflects a higher risk feature. If a user logs in from an unknown device at night, the system updates the dimension values of the access scope in the vector set through weight adjustment to restrict their access to sensitive data.
[0067] The system recalculates the distance between vectors of the permission level dimension to obtain an updated distance set. The distance between vectors reflects the differences between permission levels. For example, the vector distance of the query operation is 0.8. When the user switches from query to edit operation, the system incrementally updates the operation dimension value, and the recalculated vector distance is updated to 0.5. The system pre-sets a confidence distance threshold. If any distance in the distance set is less than this threshold (such as 0.6), it indicates that the permission scope needs to be re-divided. At this time, the system re-divides the permission access scope according to the dynamic interaction mode to obtain a set of candidate permission scopes. For example, if the user frequently edits data, the system adjusts the user's permission scope to a higher level according to the distance set.
[0068] For the set of candidate permission scopes, the system needs to verify whether the change in the behavior pattern conforms to the context weight value constraint. For example, the system will verify whether the user's night-time edit operation conforms to the high-weight office IP constraint. If not, the candidate scope will be excluded, thereby generating an optimized set of permission scopes. The optimized set of permission scopes better fits the actual needs of the user. For example, when the user queries reports in the office scenario, the optimized scope allows access to all report data, while in non-office scenarios, it is restricted to partial data.
[0069] The system extracts the matching degree scores of each permission scope from the optimized set of permission scopes. For example, the score for report query in the office scenario is 0.9, and the score in the non-office scenario is 0.4. After assigning weights to each dimension (such as time, operation, etc.), the system uses the weighted average method to calculate the comprehensive matching degree score to obtain an updated set of matching degree scores. For example, the comprehensive score for the office scenario is 0.85, and the non-office scenario is 0.45. The final set of matching degree scores reflects the priority of the permission scope, ensuring that the permission allocation is more in line with the user's behavior characteristics.
[0070] Through the above steps, the permission management system of the present invention can dynamically adjust the permission access scope and the permission level division according to the real-time changes of user behavior data and environmental parameters, calculate a matching degree score that better fits the actual situation of the user, so as to achieve accurate permission allocation.
[0071] In one implementation, if the updated matching degree score is lower than the second threshold, the corresponding permission identification code is removed from the permission database to generate a dynamic permission allocation scheme, including: Compare the updated matching degree score with the preset second threshold. When the updated matching degree score is lower than the second threshold, query and obtain the permission identification code corresponding to the current user from the permission database; Remove the corresponding permission identification code from the permission database and generate a permission change record; The log recording mechanism is adopted to write the permission adjustment time and the triggering event into the permission allocation log according to the time stamp and the event association method, so as to obtain the permission adjustment log data; Extract the event triggering conditions based on the permission adjustment log data; determine whether the event triggering conditions meet the requirements of dynamic permission allocation; if the triggering conditions indicate that the user behavior is abnormal, generate the corresponding dynamic allocation trigger signal; Call the permission management solution according to the dynamic allocation trigger signal to generate a dynamic permission allocation solution.
[0072] Specifically, the system continuously monitors the updated matching score and compares it with a preset second threshold. The second threshold is a key indicator set according to the system's requirements for the security and stability of permission allocation, and this threshold will vary under different application scenarios and security policies. When the updated matching score is lower than the second threshold, it indicates that the user behavior or context parameters fail to meet the standards set by the current permission allocation.
[0073] Taking an enterprise internal permission management system as an example, if the second threshold is set to 0.75 and the matching score of an employee is 0.6, this means that the employee's recent operation behavior deviates from the normal mode. The system will query and obtain the permission identification code corresponding to the current user from the permission database. The permission identification code is a specific code used to uniquely determine the permissions owned by the user. For example, "EMP_001_RW", where "EMP_001" represents the employee number and "RW" represents read and write permissions. By obtaining this code, the system can clarify the current permissions of the user.
[0074] After obtaining the corresponding permission identification code, the system will remove the permissions corresponding to this code from the permission database to adjust the user's permission configuration. The permission removal operation is completed through a database transaction. The database transaction ensures the atomicity, consistency, isolation, and durability of data operations, ensuring that the data integrity of the database will not be damaged during the permission removal process.
[0075] After the permission is removed, the system will generate a permission change record. This record details the key information related to the permission change, including the employee ID, the removed permission identification, and the change time, etc. For example, the generated record may show "EMP_001, remove write permission, 2025-04-14 10:30". These records facilitate tracing the historical information of permission changes.
[0076] The system adopts a log recording mechanism to write the permission adjustment time and the triggering event into the permission allocation log according to the time stamp and the event association method. The time stamp accurately records the specific moment when the permission adjustment occurs, and the event association method closely links the permission adjustment with the specific event that triggers the adjustment, such as "frequently attempting to access unauthorized resources".
[0077] Based on the generated permission adjustment log data, the system extracts the event trigger conditions therein. These trigger conditions are important bases for judging whether user behavior conforms to the permission allocation rules. For example, "accessing restricted resources 3 times in a row" is a typical event trigger condition. The system analyzes these conditions to determine whether they meet the requirements of dynamic permission allocation. If the trigger conditions indicate that there are abnormalities in user behavior, the system generates corresponding dynamic allocation trigger signals to guide the system to perform subsequent permission adjustment operations. For example, when an employee attempts to access sensitive data multiple times, the system generates a trigger signal marked as "high risk". In some special cases, such as when an employee temporarily needs to access new project data due to a business trip, although the matching score is lower than the second threshold and triggers permission removal, but the log analysis shows that their operation conforms to the business trip scenario, at this time the trigger signal will be changed to "temporary allocation".
[0078] According to the generated dynamic allocation trigger signal, the system calls the permission management solution to generate a dynamic permission allocation plan. The permission management solution is a set of pre-set rules and algorithms. It comprehensively considers various factors such as user positions and historical behaviors to ensure that the generated permission allocation plan not only meets the security requirements of the system but also adapts to the actual needs of different users. For example, when the trigger signal is "high risk", the generated dynamic permission allocation plan may adjust the employee's permission to "read-only for 72 hours" and require supervisor approval to reduce potential risks; when the trigger signal is "temporary allocation", the final plan may be "grant read-only permission for the project for 24 hours", which not only meets the temporary work needs of the employee but also ensures the minimum allocation of permissions.
[0079] After the dynamic allocation plan is generated, the system also notifies the user of the permission adjustment result by email or other means, informing the employee of the details of the permission change. For example, when an employee triggers permission removal due to an operation error, after the system records their behavior pattern in the log and analyzes and confirms that it is a misoperation rather than a malicious behavior, the dynamic plan will restore their permission and attach a training prompt. Through this complete process from removal to restoration, with the synergistic effect of the trigger signal and the log, the system realizes fine-grained permission management and dynamic adjustment, taking into account both security and flexibility.
[0080] In one implementation, based on the encryption algorithm type and the key distribution mechanism, the permission identifier encoding is encrypted to generate an encrypted communication data stream including data stream sharding and an encryption check code, specifically including: Adopt a sharding transmission mechanism. According to the MAC address or IP address of the communication module, the permission identifier encoding is divided into different parts to obtain permission shard data; among them, different parts are respectively used to identify the user identity and the permission type; Through the key distribution mechanism, select the corresponding encryption algorithm key from the key pool storing multiple algorithm keys according to the permission sharded data type; Determine whether the encryption key set meets the matching conditions of the end-to-end encryption protocol; if the conditions are met, use the selected encryption algorithm to encrypt the permission sharded data to obtain the encrypted permission data stream; Adopt the data stream sharding technology to divide the encrypted permission data stream into multiple shards, and attach a verification identifier to each shard to form a shard data packet containing the verification identifier to obtain a set of shard data packets; After the communication module obtains the set of shard data packets, adopt the encryption verification mechanism to compare the verification identifier in the received shard data packet with the preset verification rule to determine whether the data has been tampered with, and obtain the data packet that passes the verification.
[0081] Specifically, when the system adopts the sharding transmission mechanism, the permission identifier code is split according to the MAC address or IP address of the communication module. The permission identifier code is a code used to uniquely determine the user's permission. For example, "EMP_001_RW", where "EMP_001" is used to identify the user identity, and "RW" indicates that the user has read and write permissions. The system splits such a code into different parts to obtain the permission sharded data.
[0082] In practical applications, when an employee logs in to the system, the part of "EMP_001" will be transmitted to the identity verification server to verify the employee's identity information; the part of "RW" will be transmitted to the permission verification server to confirm the employee's access scope. Through this separated transmission method, the risk of single-point leakage can be effectively reduced.
[0083] The system obtains the key of the encryption algorithm from the key pool through the key distribution mechanism. The key pool stores multiple algorithm keys, such as the commonly used AES-256 and RSA, etc. The system will select the corresponding encryption algorithm key according to the permission sharded data type. For example, for the sharded data used to identify the user identity, the AES-256 algorithm key may be selected for encryption; for the sharded data identifying the permission type, the RSA algorithm key may be selected for encryption.
[0084] In a possible implementation manner, the system will generate a key pair for each employee (such as EMP_001), where the public key is used to encrypt the permission data, and the private key is stored in the security module to ensure the security of the key. During key distribution, the system sends the public key to the target node through a secure channel to avoid the key being stolen during transmission, thus ensuring the efficiency and security of the encryption process.
[0085] After obtaining the encrypted key set, the system will determine whether the key set meets the matching conditions of the end-to-end encryption protocol. The end-to-end encryption protocol is an important mechanism to ensure the security of data during transmission, which requires that the key length, algorithm version, etc. must be consistent. For example, for the AES-256 encryption algorithm, the system will check whether the obtained key is 256 bits. If the encrypted key set meets the matching conditions, the system will use the selected encryption algorithm to encrypt the permission shard data to obtain the encrypted permission data stream. Only the target node with the corresponding private key can decrypt the encrypted data. For example, after the permission data stream of employee EMP_001 is transmitted to the project server, the project server uses the private key to decrypt it to confirm the employee's permissions (such as read-only permissions), effectively ensuring the integrity of data transmission.
[0086] To further ensure the reliability of data transmission, the system adopts the data stream sharding technology to divide the encrypted permission data stream into multiple shards. For example, in one embodiment, the data stream is divided into 4 shards. At the same time, an authentication identifier is attached to each shard, such as the SHA-256 checksum, to form a sharded data packet containing the authentication identifier, and then a set of sharded data packets is obtained. For example, shard 1 contains the permission identifier EMP_001 and also attaches the checksum hash1. In this way, during data transmission, even if a certain shard has a problem, it can be quickly detected through the authentication identifier.
[0087] After the communication module obtains the sharded data packet, it uses an encryption verification mechanism to verify the data. Specifically, the communication module will compare the authentication identifier (such as hash1) in the received sharded data packet with the preset verification rules to determine whether the data has been tampered with. For example, after the target node receives shard 1, it will calculate the hash value of this shard and compare it with the received hash1. If the two are the same, it means that the data has not been tampered with during transmission and the data packet passes the verification; if they are different, it indicates that the data may have been tampered with and needs to be retransmitted or other measures need to be taken.
[0088] Through the above series of rigorous steps, the present invention realizes the encryption processing of the permission identifier encoding and generates an encrypted communication data stream containing data stream sharding and encryption checksum, effectively ensuring the security and integrity of permission data during transmission, and improving the security and reliability of the entire dynamic permission allocation system.
[0089] Refer to Figure 2 , the second embodiment of the present invention provides a permission allocation system based on end-to-end encrypted communication, including: The first processing module is used to: obtain the user's permission identifier encoding, permission access range and behavior track to obtain the user attribute set; The second processing module is used to: map the user attribute set into a multi-dimensional vector, and generate a multi-dimensional vector set reflecting the dynamic characteristics of the user; The third processing module is used to: extract the user vector and the access policy vector from the multi-dimensional vector set, and calculate the matching degree score between the two; The fourth processing module is used to: if the matching degree score is higher than the first threshold, extract the corresponding permission identification code and permission validity period from the permission database, and generate a preliminary permission allocation scheme including permission level division and permission-related roles; The fifth processing module is used to: generate a final permission allocation scheme based on the preliminary permission allocation scheme, the permission priority value, the matching degree score and the verification rule; The sixth processing module is used to: based on the data updated in real time in the user attribute set, adopt an incremental update algorithm to adjust the dimension values of the permission access range and the permission level division in the multi-dimensional vector set, and calculate the updated matching degree score; The seventh processing module is used to: if the updated matching degree score is lower than the second threshold, remove the corresponding permission identification code from the permission database, and generate a dynamic permission allocation scheme.
[0090] It should be noted that a permission allocation system based on end-to-end encrypted communication provided by an embodiment of the present invention is used to execute all the process steps of a permission allocation method based on end-to-end encrypted communication in the above embodiment. The working principles and beneficial effects of the two correspond one by one, so they will not be repeated here.
[0091] The specific embodiments described above further elaborate on the purpose, technical solution and beneficial effects of the present invention. It should be understood that the above description is only specific embodiments of the present invention and is not used to limit the protection scope of the present invention. In particular, for those skilled in the art, any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. A permission allocation method based on end-to-end encrypted communication, characterized in that, Including: Obtain the user's permission identification code, permission access scope, and behavior track to obtain the user attribute set; Map the user attribute set to multi-dimensional vectors to generate a multi-dimensional vector set reflecting the user's dynamic characteristics; Extract the user vector and access policy vector from the multi-dimensional vector set, and calculate the matching degree score between the two; If the matching degree score is higher than the first threshold, extract the corresponding permission identification code and permission expiration period from the permission database, and generate a preliminary permission allocation plan including permission level division and permission-related roles; According to the preliminary permission allocation plan, generate the final permission allocation plan based on the permission priority value, matching degree score, and verification rules; Based on the data updated in real time in the user attribute set, use the incremental update algorithm to adjust the dimension values of the permission access scope and permission level division in the multi-dimensional vector set and calculate the updated matching degree score; If the updated matching degree score is lower than the second threshold, remove the corresponding permission identification code from the permission database to generate a dynamic permission allocation plan.
2. The permission allocation method based on end-to-end encrypted communication according to claim 1, wherein Obtain the user's permission identification code, permission access scope, and behavior track to obtain the user attribute set, including: Obtain the user identity identification, behavior track data, and context parameter set from the multi-source information system, and perform data cleaning to obtain the initial user attribute set; Use the standardization processing method on the initial user attribute set to perform format conversion on the permission identification code and access scope definition to generate a unified format permission attribute set; among them, if there are permission identification codes with inconsistent formats in the permission attribute set, they are corrected through the mapping rule, and then a permission data set is generated; According to the permission data set and behavior track data, use the clustering algorithm to extract behavior pattern features to generate a user behavior feature set; Through the user behavior feature set and context parameter set, use the association rule mining method to determine the corresponding relationship between the behavior pattern and the context to obtain the behavior context association set; For the behavior context association set, use the data fusion method to integrate the permission identification code, access scope definition, and behavior pattern features to generate the user attribute set.
3. The method for permission allocation based on end-to-end encrypted communication according to claim 2, wherein Map the user attribute set to multi-dimensional vectors to generate a multi-dimensional vector set reflecting the user's dynamic characteristics, including: Extract features from the user attribute set to generate the initial multi-dimensional vector; Allocate initial weights to the multi-dimensional vectors according to the permission level and access scope to obtain the weighted vector; Obtain the context parameters. When the context parameters meet the preset threshold, adjust the weight value of the weighted vector through the iterative algorithm to determine the dynamic weight vector; the context parameters include: access time, device type, and proportion of access during working hours; For the dynamic weight vector, use the clustering algorithm based on access frequency and module preference to divide the user features; Extract significant attributes from the feature grouping. If the significant attributes match the permission level, generate the corresponding vector set; Combine the vector set with the context parameters to obtain a multi-dimensional vector set reflecting the user's dynamic characteristics.
4. The privilege distribution method based on end-to-end encrypted communication according to claim 3, wherein, Extract the user vector and access policy vector from the multi-dimensional vector set, and calculate the matching degree score between the two, including: Extract the user vector and access policy vector from the multi-dimensional vector set; among them, the user vector is generated based on the user attributes; the access policy vector is generated based on the permission rules; Generate a vector dimension description by obtaining the permission identification code and priority value of the user vector, as well as the permission identification code and priority value of the access policy vector; Perform normalization processing on each dimension of the vector based on the vector dimension description to ensure that the units of all dimensions are consistent; Calculate the distance between the user vector and the access policy vector using the Euclidean distance formula; if the distance result is less than the distance threshold, match the corresponding score data based on the distance; if the distance result is greater than or equal to the threshold, configure the score data as a fixed base score.
5. The permission allocation method based on end-to-end encrypted communication according to claim 4, characterized in that According to the preliminary permission allocation plan, if the matching degree score is higher than the first threshold, extract the corresponding permission identification code and permission validity period from the permission database, and generate a preliminary permission allocation plan including permission level division and permission associated roles, including: Compare the matching degree score between the user vector and the access policy vector with a preset first threshold; When the matching degree score is higher than the first threshold, extract the corresponding permission identification code and permission validity period from the permission database according to the association information between the user vector and the access policy vector; among them, the permission identification code is a unique string used to clarify the specific permission type; the permission validity period is used to specify the validity of the permission within the set time range; Perform level division on the permissions based on the extracted permission identification code in combination with the permission level division rules; Determine the permission associated roles according to the user's role information and the association rules between permissions and roles; Integrate the extracted permission identification code, permission validity period, the divided permission levels, and the determined permission associated roles to generate a preliminary permission allocation plan including permission level division and permission associated roles.
6. The method for permission allocation based on end-to-end encrypted communication according to claim 5, characterized in that, According to the preliminary permission allocation plan, generate a final permission allocation plan based on the permission priority value, matching degree score, and verification rules, including: Obtain a permission allocation request and parse the permission priority value and verification rules from the permission allocation request; among them, convert the permission priority value into a numerical form and record the verification rules to generate an initial permission allocation data set; the initial permission allocation data set includes permission identification, priority value, and association rules; Calculate the matching degree score for each permission to form a set of matching degree scores; Calculate the confidence level for each permission to obtain a set of confidence levels; if the confidence level of one permission is greater than the confidence level threshold, sort the permission allocation plan according to the confidence interval of the permission's confidence level to obtain a candidate permission allocation plan; if the confidence level is less than the confidence level threshold, record the abnormal status of the permission in the allocation log; Verify whether the candidate permission allocation plan complies with the permission verification rules; if it complies with the rules, generate an optimized permission allocation plan; if it does not comply with the rules, recalculate the confidence level; Generate a permission allocation log through the optimized permission allocation plan, record the allocation time, permission identification, and confidence level to form a set of allocation logs; Extract the permission records that have not been allocated from the set of allocation logs, and loop through the above steps until all permissions are allocated to obtain the final permission allocation plan.
7. A permission allocation method based on end-to-end encrypted communication according to claim 6, characterized in that, Adjust the dimension values of the permission access range and the permission level division in the multi-dimensional vector set using an incremental update algorithm based on the real-time updated data in the user attribute set, and calculate the updated matching degree score, including: Obtain user behavior data and environmental parameters from the real-time data stream, parse the user behavior data and environmental parameters to identify the user's dynamic interaction pattern, and generate an initial behavior pattern vector set; the initial behavior pattern vector set includes operation frequency, time preference, and environmental characteristics; Assign context weight values to the environmental parameters according to their importance; adjust the initial behavior pattern vector set based on the assigned context weight values, and update the dimension values of the permission access range in the multi-dimensional vector set to obtain an adjusted vector set; Recalculate the distance between vectors in the permission level dimension to obtain an updated distance set; if any distance in the distance set is less than the confidence distance threshold, it indicates that the permission range needs to be re-divided; re-divide the permission access range according to the dynamic interaction pattern to obtain a candidate permission range set; For the candidate permission range set, verify whether the change in the behavior pattern meets the context weight value constraint, and if not, remove the candidate range to generate an optimized permission range set; extract the matching degree score of each permission range from the optimized permission range set, assign weights to each dimension, and use the weighted average method to calculate the comprehensive matching degree score to obtain an updated matching degree score set.
8. The method for permission allocation based on end-to-end encrypted communication according to claim 7, characterized in that, If the updated matching degree score is lower than the second threshold, remove the corresponding permission identification code from the permission database to generate a dynamic permission allocation plan, including: Compare the updated matching degree score with the preset second threshold. When the updated matching degree score is lower than the second threshold, query and obtain the permission identification code corresponding to the current user from the permission database; Remove the corresponding permission identification code from the permission database and generate a permission change record; Use the log recording mechanism to write the permission adjustment time and trigger event into the permission allocation log according to the time stamp and event association method to obtain permission adjustment log data; Extract the event trigger condition based on the permission adjustment log data; determine whether the event trigger condition meets the dynamic permission allocation requirements; if the trigger condition indicates that the user behavior is abnormal, generate a corresponding dynamic allocation trigger signal; Call the permission management plan according to the dynamic allocation trigger signal to generate a dynamic permission allocation plan.
9. The permission allocation method based on end-to-end encrypted communication according to claim 8, wherein, The method further includes: encrypting the permission identification code based on the encryption algorithm type and the key distribution mechanism to generate an encrypted communication data stream including data stream shards and encrypted verification codes, specifically including: Adopt a sharding transmission mechanism to divide the permission identification code into different parts according to the MAC address or IP address of the communication module to obtain permission shard data; among them, different parts are used to identify the user identity and permission type respectively; Through the key distribution mechanism, select the corresponding encryption algorithm key from the key pool storing multiple algorithm keys according to the permission shard data type; Judge whether the encryption key set meets the matching conditions of the end-to-end encryption protocol; if it meets the conditions, use the selected encryption algorithm to encrypt the permission shard data to obtain an encrypted permission data stream; Using the data stream sharding technology, the encrypted permission data stream is divided into multiple shards, and a verification identifier is attached to each shard to form a sharded data packet containing the verification identifier to obtain a set of sharded data packets; After the communication module obtains the set of sharded data packets, it adopts an encryption verification mechanism to compare the verification identifier in the received sharded data packet with the preset verification rules to determine whether the data has been tampered with, and obtains the data packet that passes the verification.
10. A permission allocation system based on end-to-end encrypted communication, characterized in that, It includes: The first processing module is used to: obtain the permission identifier code, permission access range, and behavior track of the user to obtain the user attribute set; The second processing module is used to: map the user attribute set into a multi-dimensional vector to generate a multi-dimensional vector set reflecting the dynamic characteristics of the user; The third processing module is used to: extract the user vector and the access policy vector from the multi-dimensional vector set and calculate the matching degree score between the two; The fourth processing module is used to: if the matching degree score is higher than the first threshold, extract the corresponding permission identifier code and permission validity period from the permission database, and generate a preliminary permission allocation plan including the permission level division and the permission associated role; The fifth processing module is used to: based on the preliminary permission allocation plan, generate a final permission allocation plan based on the permission priority value, the matching degree score, and the verification rules; The sixth processing module is used to: based on the data updated in real time in the user attribute set, use the incremental update algorithm to adjust the dimension values of the permission access range and the permission level division in the multi-dimensional vector set and calculate the updated matching degree score; The seventh processing module is used to: if the updated matching degree score is lower than the second threshold, remove the corresponding permission identifier code from the permission database and generate a dynamic permission allocation plan.
Citation Information
Cited By
Multi-authority management method for access control system
CN121482914A
Role-based knowledge base authority management and data access control method and system
CN121723500A