Unified account authority management platform based on cloud computing

Through a unified account permission management platform based on cloud computing, local outlier factors and support vector regression models are used to detect abnormalities, combine decision trees to analyze exception types, and dynamically adjust permissions, solving the problems of insensitive monitoring, imperfect permissions, single data, and poor adaptability of traditional account permission management systems, and achieving efficient and flexible security management.

CN120470622AInactive Publication Date: 2025-08-12DAJIAXIN (SHENZHEN) TECHNOLOGY SERVICE CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510556488.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-29
Publication Date
2025-08-12
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The traditional account permission management system is insensitive to the monitoring of abnormal account data, imperfect permission management, relying on outdated technology, and a single data source, making it difficult to adapt to rapidly changing business needs, resulting in insufficient security and flexibility, and being unable to work in concert with other IT systems, increasing management costs and risks.

Method used

The unified account permission management platform based on cloud computing obtains user, behavior and environment parameters through the data acquisition module, uses local outlier factors and support vector regression models to detect abnormalities, analyzes abnormal types in combination with decision trees, and responds to abnormal behavior through risk assessment and dynamic permission adjustment strategies.

Benefits of technology

It improves the accuracy and flexibility of abnormal detection, realizes multi-dimensional data analysis, enhances the system's adaptability and security, reduces management costs, and improves the system's response speed and collaborative work ability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120470622A_ABST
    Figure CN120470622A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of authority management, and discloses a unified account authority management platform based on cloud computing, and the platform comprises a data collection module which is used for collecting user parameter data, user behavior data, platform parameter data and cloud environment parameter data; the data processing module influences local reachable density by adjusting the number of nearest neighbor sample points and a sensitivity coefficient based on a local outlier factor, and further detects and rejects outliers of the user parameter data, the user behavior data, the platform parameter data and the cloud basic environment data; obtaining a parameter feature data set, a behavior feature data set, a platform feature data set and a cloud environment feature data set; performing correlation analysis and fusion on the parameter feature data set, the behavior feature data set, the platform feature data set and the cloud environment feature data set to obtain a comprehensive feature data set; the accuracy of risk assessment is improved, the account risk level is quickly judged, and measures can be taken in time.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of rights management, and more specifically, to a unified account rights management platform based on cloud computing. Background Art

[0002] The rapid development of cloud computing technology has provided enterprises with new approaches for efficient and secure account and permission management. The rapid advancement of cloud computing, particularly its remarkable achievements in resource virtualization, elastic scalability, and global data center deployment, has provided enterprises with unprecedented computing power and data storage services. The widespread adoption of these services has enabled enterprises to more flexibly respond to business growth and changes, but it has also placed higher demands on account and permission management. Traditional account and permission management models are becoming increasingly inadequate, and enterprises urgently need an account and permission management platform that centrally manages user identity information, flexibly configures permissions, and offers advanced security features.

[0003] Patent application publication number CN116167029A discloses a computer system account management method based on cloud computing, which relates to the field of account management technology. The management method includes the following steps: an administrator creates a new account for a user on the account management system of a cloud platform, sets account information and grants corresponding permissions based on the user category. Before accessing cloud platform resources, the user needs to authenticate through the account management system of the cloud platform. When different users operate on the cloud platform, the account management system obtains multiple data of the user in real time, comprehensively processes the multiple data to obtain anomaly coefficients, and generates a user management plan based on the comparison results of the anomaly coefficients and gradient thresholds. The present invention monitors the user's behavior during the user operation process, thereby ensuring the operational security of the cloud platform.

[0004] Traditional account permission management relies primarily on manual operations and rule-based decision-making, which has the following major problems:

[0005] The system is not sensitive to abnormal account data monitoring, unable to automatically and accurately identify abnormal account data, and unable to promptly detect potential abnormal behavior or system problems. The system is also not fully functional, which can easily lead to some users gaining access rights beyond their responsibilities. Traditional permission settings may allow users to retain unnecessary permissions for a long time, increasing the risk of insider threats. The system relies on outdated technology, cannot provide modern security measures, lacks integration and automation, and has difficulty working with other IT systems in the organization.

[0006] The data source is single and cannot provide a comprehensive and broad perspective and rich information for data analysis; it does not take into account the correlation between multi-channel and multi-factor data, and the data processing and analysis capabilities are weak, resulting in the system's poor risk perception; it is difficult to quickly adapt to business development and changes, resulting in the system's inability to meet new business needs. When the system needs to integrate new applications or services, traditional account permission management methods cannot provide sufficient support, thereby increasing the difficulty and cost of integration.

[0007] In view of this, the present invention proposes a unified account authority management platform based on cloud computing to solve the above problems. Summary of the Invention

[0008] In order to overcome the above-mentioned defects of the prior art and to achieve the above-mentioned objectives, the present invention provides the following technical solution: a unified account authority management platform based on cloud computing, comprising:

[0009] Data collection module, used to collect user parameter data, user behavior data, platform parameter data and cloud environment parameter data;

[0010] The data processing module, based on the local outlier factor, affects the local reachability density by adjusting the number of nearest neighbor sample points and the sensitivity coefficient, thereby detecting and removing outliers in user parameter data, user behavior data, platform parameter data, and cloud basic environment data, and thus obtaining parameter feature data sets, behavior feature data sets, platform feature data sets, and cloud environment feature data sets;

[0011] Perform correlation analysis and fusion on parameter feature datasets, behavior feature datasets, platform feature datasets, and cloud environment feature datasets to obtain a comprehensive feature dataset;

[0012] The account risk assessment module uses support vector regression and combines the silhouette coefficient to optimize the number of clusters to obtain the optimal hyperparameter combination. It analyzes the comprehensive feature data set and then predicts the account risk coefficient. The predicted account risk coefficient is compared with the preset account risk coefficient threshold to determine the account risk level.

[0013] The account risk warning module continuously monitors changes in the account risk coefficient if the account is at low risk; if the account is at high risk, it issues a risk warning instruction through the cloud server management terminal, generates risk warning information, and collects abnormal account data;

[0014] The abnormality type analysis module analyzes account abnormal data and diagnoses abnormality types through a decision tree to obtain the corresponding account abnormality type;

[0015] The risk control processing module is used to execute the corresponding dynamic permission adjustment strategy according to the type of account abnormality until the account returns to normal; each module is connected via wired and / or wireless means.

[0016] Preferably, the user parameter data includes the user's name, ID number, mobile phone number and contact address; the user behavior data includes the user's login time and user login frequency; the platform parameter data includes the system version, service status, operation log, CPU usage and memory usage; the cloud environment parameter data includes resource usage, cloud service response time, fault records, security event logs, compliance check results and security policy execution.

[0017] Preferably, the method for acquiring the parameter feature dataset, the behavior feature dataset, the platform feature dataset, and the cloud environment feature dataset includes:

[0018] Perform data cleaning on user parameter data, user behavior data, platform parameter data, and cloud basic environment data, process missing values and noise, perform standardization and normalization, convert them into standard state distribution, and obtain normalized user parameter data, user behavior data, platform parameter data, and cloud basic environment data;

[0019] The normalized user parameter data, user behavior data, platform parameter data, and cloud infrastructure data are combined into a set X = {X1, X2, ..., Xn} containing n data samples, each of which contains d dimensions; where X n represents the nth data sample, X n =(x n1 ,x n2 ,...,x nd );x nd is the data of the dth dimension in the data sample Xn;

[0020] For each data sample Xi, calculate the distance between it and all other data samples. For each data sample, select K nearest neighbor sample points, which are recorded as the nearest neighbor sample set N. K (y); Calculate the local reachability density of each data sample, which is the inverse of the average reachability distance between the data sample and its K nearest neighbor sample points;

[0021] Dynamically adjust the number of nearest neighbor sample points through the nearest neighbor adjustment model Among them, K' is the adjusted number of nearest neighbor sample points; w1, w2 and w3 are weight coefficients; a is the proportion of abnormal samples in the total number of data samples; Q is the number of noise samples; M is the size of the data sample; ε is the coefficient for adjusting the sensitivity of outliers;

[0022] The size of ε is adjusted by the sensitivity coefficient adjustment formula, which is: Among them, δ is the gain coefficient for adjusting the influence of outliers, q is the noise ratio, η is the coefficient for adjusting the influence of noise, and θ is the equilibrium constant;

[0023] Calculate the local outlier factor of the data sample and compare it with the preset local outlier factor threshold. Mark the data samples whose local outlier factor is greater than or equal to the preset local outlier factor threshold as outliers. Select and remove all outliers in the set X, and finally obtain the parameter feature dataset, behavior feature dataset, platform feature dataset, and cloud environment feature dataset.

[0024] Preferably, the method for obtaining the comprehensive feature data set includes:

[0025] The parameter feature dataset, behavior feature dataset, platform feature dataset, and cloud environment feature dataset are fused through a weighted formula to obtain a comprehensive feature dataset; the parameter feature dataset is denoted as H1, the behavior feature dataset is denoted as H2, the platform feature dataset is denoted as H3, and the cloud environment feature dataset is denoted as H4;

[0026] The weighting formula is F = α1·H1+α2·H2+α3·H3+α4·H4; among them, α1 is the weight coefficient of the parameter feature dataset; α2 is the weight coefficient of the behavior feature dataset; α3 is the weight coefficient of the platform feature dataset; α4 is the weight coefficient of the cloud environment feature dataset.

[0027] Preferably, the method for obtaining the account risk coefficient includes:

[0028] The support vector regression model (SVR) is used to construct an account risk prediction model. The model's input data is a comprehensive feature dataset, and the output label is the account risk coefficient. The Gaussian kernel is selected as the kernel function of the model, and the model's hyperparameters are initialized. The model's hyperparameters are the penalty coefficient C and the kernel parameter.

[0029] The dataset is divided into training set, validation set and test set; the model is trained using the training set to minimize the objective function; the ε'-insensitive loss function is used as the loss function of the model to measure the difference between the model's predicted value and the actual value; the ε'-insensitive loss function is Among them, y' i is the actual value of account risk; f(s) is the predicted value of account risk; ε' is the width of the insensitive interval;

[0030] Tune the model hyperparameters to find the hyperparameters that minimize the loss function; use the test set to evaluate the model performance, and measure the model performance by observing the accuracy index of the model in the prediction task. When the model performance index reaches the preset model performance index threshold, stop the test and obtain the trained account risk prediction model; input the current comprehensive feature data set into the trained account risk prediction model to predict the account risk coefficient.

[0031] Preferably, the method for tuning the model hyperparameters includes:

[0032] Use grid search to tune the model's hyperparameters, define the range of hyperparameters, and create a parameter grid containing all hyperparameter combinations Divide the dataset into V subsets of equal size, use the first subset as the validation set, and the remaining V-1 subsets as the training set;

[0033] The method for dividing a dataset into V subsets of equal size is as follows: use the K-means clustering algorithm to subset the dataset; select V' initial cluster centers; calculate the distance between each data point in the dataset and each cluster center, and assign each data point to the cluster corresponding to the cluster center closest to it; calculate the mean of all data points in the cluster as the new cluster center; evaluate the clustering results by calculating the intra-cluster squared error; and adjust the number of initial cluster centers K' based on the evaluation results.

[0034] The method for optimizing the number of initial cluster centers is as follows: preset the range of the number of cluster centers K', adjust the number of cluster centers by maximizing the silhouette coefficient, and select the V' value that maximizes the silhouette coefficient as the optimal number of clusters V; the silhouette coefficient is: Where SI is the silhouette coefficient; I is the index of the sample in the data set; e(I) is the average distance between sample I and other samples in its cluster; z(I) is the minimum value of the average distance between sample I and samples in other clusters; M' is the adjustment parameter;

[0035] Use the training set to select any combination of hyperparameters The model is trained and the performance of the model is evaluated using the validation set to obtain performance indicators. The performance indicators of the obtained models corresponding to all hyperparameter combinations are calculated, and the hyperparameter combination that maximizes the performance indicator is selected as the optimal hyperparameter combination of the model. Use the best hyperparameter combination The model is trained on the training set and evaluated on the test set to confirm the generalization ability of the model.

[0036] Preferably, the method for determining the account risk level includes:

[0037] If the predicted account risk coefficient is less than the preset account risk coefficient threshold, the account is judged to be in a low-risk state;

[0038] If the predicted account risk coefficient is greater than or equal to the preset account risk coefficient threshold, the account is determined to be in a high-risk state.

[0039] Preferably, the abnormal account data includes:

[0040] Account abnormality data is collected from high-risk accounts, including transaction abnormal behavior data, user abnormal behavior data, account status abnormal data, device abnormal data, and security event data.

[0041] Preferably, the method for constructing the abnormality type diagnosis model includes:

[0042] The anomaly type diagnosis model is a decision tree model, including a root node, internal nodes, and leaf nodes. The CART algorithm is used to construct the decision tree model. The input data of the model is the account anomaly data within the historical period, and the output label is the account anomaly type. The pre-trained anomaly type diagnosis model is used to diagnose the current account anomaly data to obtain the corresponding account anomaly type.

[0043] Preferably, the method of executing a corresponding dynamic permission adjustment strategy according to the type of account abnormality until the account returns to normal includes:

[0044] Based on the type of account abnormality, dynamic adjustment strategies are implemented for user permissions until the account returns to normal; dynamic adjustment strategies include restricting account access rights, limiting account transaction amounts and frequency, enabling multi-factor authentication, requiring users to answer preset security questions when logging in, freezing accounts, and blocking transactions.

[0045] The technical effects and advantages of the unified account rights management platform based on cloud computing of the present invention are as follows:

[0046] Combining the KNN algorithm with local reachable density, the KNN algorithm is used to construct a sample set, and the degree of abnormality of each data point is evaluated by calculating the local reachable density. It not only considers the spatial distance between data points, but also introduces the density information of the surrounding environment of the data point through the local reachable density. It can effectively identify data points with local density abnormalities, that is, those isolated points or out-of-cluster points that are significantly different from the surrounding data points, thereby improving the accuracy of anomaly detection, which is of great significance for discovering potential abnormal behaviors or system problems.

[0047] By introducing a neighbor adjustment model and a sensitivity coefficient adjustment formula, the number of nearest neighbor sample points and outlier sensitivity are dynamically adjusted. This allows for automatic parameter adjustments based on the characteristics of different datasets and the needs of anomaly detection, improving the algorithm's robustness and generalization capabilities. Furthermore, adjusting the sensitivity coefficient allows for fine-grained control over the impact of outliers to adapt to different application scenarios, making the anomaly detection process more flexible and adaptive.

[0048] By fusing feature datasets from different fields, we achieve comprehensive integration of multi-dimensional features, providing a broader perspective and richer information for data analysis. During the fusion process, weight coefficients are introduced to balance the importance of different feature datasets. This weight distribution mechanism allows analysts to adjust the contribution of each dataset based on actual conditions, thereby more flexibly adapting to different analytical needs. The comprehensive feature dataset obtained through weighted fusion not only includes the feature information of each individual dataset, but also achieves an optimized combination of features through adjustment of the weight coefficients. This comprehensive feature dataset provides more comprehensive and powerful support for subsequent data analysis and modeling.

[0049] A clustering algorithm is introduced into the traditional grid search method to partition the dataset. Clustering brings similar data points together, resulting in a more representative data distribution on the validation set and improving the accuracy of model evaluation. By optimizing the number of cluster centers and hyperparameter combinations, the model can learn more generalized feature representations, improving its predictive ability on unseen data. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] Figure 1 This is a schematic diagram of the structure of a unified account authority management platform based on cloud computing of the present invention;

[0051] Figure 2 The figure is a flow chart of the unified account authority management method based on cloud computing of the present invention. DETAILED DESCRIPTION

[0052] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0053] Example 1

[0054] See also Figure 1 As shown, this embodiment further illustrates the unified account authority management platform based on cloud computing proposed by the present invention, including:

[0055] Traditional account and permission management systems rely primarily on manual operations and rule-based decision-making. These systems are often designed and implemented based on static policies, often failing to effectively address increasingly complex security threats and changes in the enterprise environment. Current traditional account and permission management systems have the following major issues:

[0056] Traditional systems are insensitive to abnormal account data monitoring. They lack the ability to detect abnormal account behavior and often rely on manual monitoring or simple rules to identify anomalies. They lack automated and accurate identification of abnormal account data. Many potential abnormal behaviors or system issues may not be discovered in a timely manner, leading to long-term security risks and even irreparable losses.

[0057] Imperfect permissions management. Traditional permission management systems suffer from irrational permissions allocation, which can result in some users gaining access rights beyond their responsibilities. More seriously, certain permissions may persist even after a user's responsibilities change, leading to users holding unnecessary permissions for extended periods of time, significantly increasing the risk of insider threats. For example, some users may retain access to sensitive data even after completing a project assignment, even exceeding their responsibilities.

[0058] Traditional access management systems often rely on outdated technology and lack modern security measures. These systems often lack integration and automation, making them difficult to effectively collaborate with other IT systems within an organization. This results in lagging security measures and making them unable to adapt to rapidly evolving security threats and technological developments.

[0059] Traditional account and permission management systems rely on limited data sources, such as logs and user behavior records, and lack analytical capabilities. These systems often fail to consider the interconnectedness of data from multiple channels and factors, resulting in an incomplete analysis of the actual situation. Consequently, traditional systems lack sufficient sensitivity and accuracy in risk perception and response, easily overlooking potential security risks.

[0060] Traditional account and permission management methods struggle to adapt to rapidly evolving business needs. When the enterprise environment or technical architecture changes, or when new applications and services are integrated, traditional systems often fail to provide adequate support, increasing integration difficulty and costs. This often presents significant challenges for organizations responding to business changes, hindering their ability to adjust permission management strategies in a timely manner to meet new demands.

[0061] Therefore, the limitations and shortcomings of traditional account and permission management systems no longer meet the security, flexibility, automation, and interoperability requirements of modern enterprises. These issues not only increase management costs but can also significantly reduce system security and impact the overall operational efficiency of enterprises.

[0062] In order to effectively solve the above problems, the present invention proposes a unified account rights management platform based on cloud computing, including:

[0063] Data collection module, used to collect user parameter data, user behavior data, platform parameter data and cloud environment parameter data;

[0064] The data processing module, based on the local outlier factor, affects the local reachability density by adjusting the number of nearest neighbor sample points and the sensitivity coefficient, thereby detecting and removing outliers in user parameter data, user behavior data, platform parameter data, and cloud basic environment data, and thus obtaining parameter feature data sets, behavior feature data sets, platform feature data sets, and cloud environment feature data sets;

[0065] Perform correlation analysis and fusion on parameter feature datasets, behavior feature datasets, platform feature datasets, and cloud environment feature datasets to obtain a comprehensive feature dataset;

[0066] The account risk assessment module uses support vector regression and combines the silhouette coefficient to optimize the number of clusters to obtain the optimal hyperparameter combination. It analyzes the comprehensive feature data set and then predicts the account risk coefficient. The predicted account risk coefficient is compared with the preset account risk coefficient threshold to determine the account risk level.

[0067] The account risk warning module continuously monitors changes in the account risk coefficient if the account is at low risk; if the account is at high risk, it issues a risk warning instruction through the cloud server management terminal, generates risk warning information, and collects abnormal account data;

[0068] The abnormality type analysis module analyzes account abnormal data and diagnoses abnormality types through a decision tree to obtain the corresponding account abnormality type;

[0069] The risk control processing module is used to execute the corresponding dynamic permission adjustment strategy according to the type of account abnormality until the account returns to normal; each module is connected via wired and / or wireless means.

[0070] User parameter data includes the user's name, ID number, mobile phone number and contact address; user behavior data includes user login time and user login frequency; platform parameter data includes system version, service status, operation log, CPU usage and memory usage; cloud environment parameter data includes resource usage, cloud service response time, fault records, security event logs, compliance check results and security policy implementation; user parameter data, user behavior data, platform parameter data and cloud basic environment data are all collected through the data monitoring platform of the unified account authority management platform.

[0071] Methods for obtaining parameter feature datasets, behavior feature datasets, platform feature datasets, and cloud environment feature datasets include:

[0072] Perform data cleaning on user parameter data, user behavior data, platform parameter data, and cloud basic environment data, process missing values and noise, perform standardization and normalization, convert them into standard state distribution, and obtain normalized user parameter data, user behavior data, platform parameter data, and cloud basic environment data;

[0073] The normalized user parameter data, user behavior data, platform parameter data, and cloud infrastructure data are combined into a set X = {X1, X2, ..., Xn} containing n data samples, each of which contains d dimensions. Xn represents the nth data sample, Xn = (xn1, xn2, ..., xnd), and xnd is the data of the dth dimension in the data sample Xn.

[0074] For each data sample Xi, calculate the distance between it and all other data samples. For each data sample, select K nearest neighbor sample points, which are recorded as the nearest neighbor sample set N. K (y); Calculate the local reachability density of each data sample, which is the inverse of the average reachable distance between the data sample and its K nearest neighbor sample points;

[0075] Dynamically adjust the number of nearest neighbor sample points through the nearest neighbor adjustment model Among them, K' is the adjusted number of nearest neighbor sample points; w1, w2 and w3 are weight coefficients; a is the proportion of abnormal samples in the total number of data samples; Q is the number of noise samples; M is the size of the data sample; ε is the coefficient for adjusting the sensitivity of outliers;

[0076] The size of ε is adjusted by the sensitivity coefficient adjustment formula, which is: Among them, δ is the gain coefficient for adjusting the influence of outliers, q is the noise ratio, η is the coefficient for adjusting the influence of noise, and θ is the equilibrium constant;

[0077] Calculate the local outlier factor of the data sample and compare it with the preset local outlier factor threshold. Mark the data samples whose local outlier factor is greater than or equal to the preset local outlier factor threshold as outliers. Select and remove all outliers in the set X, and finally obtain the parameter feature dataset, behavior feature dataset, platform feature dataset, and cloud environment feature dataset.

[0078] For example: suppose there is a set of 10 data samples, each of which contains 4 dimensions; take data sample X1: [0.1, 0.5, 0.3, 0.8] as an example, and calculate the distance with data sample X2: [0.2, 0.4, 0.6, 0.2]; use the Euclidean distance formula to calculate the distance between data point 1 and data point 2,

[0079]

[0080] Select K nearest neighbors, assuming ω1 = 0.5, ω2 = 0.3, ω2 = 0.2, a = 0.2, Q = 2, ε = 0.01, then adjust the model based on the nearest neighbor points to obtain:

[0081] So we select 2 nearest neighbor sample points.

[0082] Methods for obtaining comprehensive feature datasets include:

[0083] The parameter feature dataset, behavior feature dataset, platform feature dataset, and cloud environment feature dataset are fused through a weighted formula to obtain a comprehensive feature dataset; the parameter feature dataset is denoted as H1, the behavior feature dataset is denoted as H2, the platform feature dataset is denoted as H3, and the cloud environment feature dataset is denoted as H4;

[0084] The weighting formula is F = α1·H1+α2·H2+α3·H3+α4·H4; among them, α1 is the weight coefficient of the parameter feature dataset; α2 is the weight coefficient of the behavior feature dataset; α3 is the weight coefficient of the platform feature dataset; α4 is the weight coefficient of the cloud environment feature dataset.

[0085] Methods for obtaining account risk coefficients include:

[0086] The support vector regression model (SVR) is used to construct an account risk prediction model. The model's input data is a comprehensive feature dataset, and the output label is the account risk coefficient. The Gaussian kernel is selected as the kernel function of the model, and the model's hyperparameters are initialized. The model's hyperparameters are the penalty coefficient C and the kernel parameter γ.

[0087] The dataset is divided into training set, validation set and test set; the model is trained using the training set to minimize the objective function; the ε'-insensitive loss function is used as the loss function of the model to measure the difference between the model's predicted value and the actual value; the ε'-insensitive loss function is Among them, y' i is the actual value of account risk; f(s) is the predicted value of account risk; ε' is the width of the insensitive interval;

[0088] Tune the model hyperparameters to find the hyperparameters that minimize the loss function; use the test set to evaluate the model performance, and measure the model performance by observing the accuracy index of the model in the prediction task. When the model performance index reaches the preset model performance index threshold, stop the test and obtain the trained account risk prediction model; input the current comprehensive feature data set into the trained account risk prediction model to predict the account risk coefficient.

[0089] Methods for tuning model hyperparameters include:

[0090] Use grid search to tune the model's hyperparameters, define the range of hyperparameters, and create a parameter grid containing all hyperparameter combinations Divide the dataset into V subsets of equal size, use the first subset as the validation set, and the remaining V-1 subsets as the training set;

[0091] The method for dividing a dataset into V subsets of equal size is as follows: use the K-means clustering algorithm to subset the dataset; select V' initial cluster centers; calculate the distance between each data point in the dataset and each cluster center, and assign each data point to the cluster corresponding to the cluster center closest to it; calculate the mean of all data points in the cluster as the new cluster center; evaluate the clustering results by calculating the intra-cluster squared error; and adjust the number of initial cluster centers K' based on the evaluation results.

[0092] The method for optimizing the number of initial cluster centers is as follows: preset the range of the number of cluster centers K', adjust the number of cluster centers by maximizing the silhouette coefficient, and select the V' value that maximizes the silhouette coefficient as the optimal number of clusters V; the silhouette coefficient is: Where SI is the silhouette coefficient; I is the index of the sample in the data set; e(I) is the average distance between sample I and other samples in its cluster; z(I) is the minimum value of the average distance between sample I and samples in other clusters; M' is the adjustment parameter;

[0093] Use the training set to select any combination of hyperparameters The model is trained and the performance of the model is evaluated using the validation set to obtain performance indicators. The performance indicators of the obtained models corresponding to all hyperparameter combinations are calculated, and the hyperparameter combination that maximizes the performance indicator is selected as the optimal hyperparameter combination of the model. Use the best hyperparameter combination The model is trained on the training set and evaluated on the test set to confirm the generalization ability of the model.

[0094] For example, there is a data set containing 1000 samples, which needs to be divided into several subsets of equal size. The number of cluster centers is preset to range from 3 to 7, the average distance between sample 1 and other samples in its cluster is 3, and the minimum average distance between sample 1 and samples in other clusters is 1. The cluster adjustment formula is used to adjust the number of cluster centers. For example, if the number of cluster centers is 5, the silhouette coefficient is Calculate the silhouette coefficients for all cluster center numbers, and select the number of cluster centers V' corresponding to the largest silhouette coefficient as the optimal number of clusters V finally selected.

[0095] Methods for determining account risk level include:

[0096] If the predicted account risk coefficient is less than the preset account risk coefficient threshold, the account is judged to be in a low-risk state;

[0097] If the predicted account risk coefficient is greater than or equal to the preset account risk coefficient threshold, the account is determined to be in a high-risk state.

[0098] Abnormal account data includes:

[0099] Account abnormality data is collected from high-risk accounts, including transaction abnormal behavior data, user abnormal behavior data, account status abnormal data, device abnormal data, and security event data.

[0100] Abnormal transaction behavior data includes: abnormal transaction frequency or volume changes, large or unusual transfers, unusual geographic locations or IP addresses where transactions occurred, and unusual transaction times;

[0101] Abnormal user behavior data includes: abnormal number of user logins, login locations and times, excessive number of failed password attempts, and abnormal changes to account settings and permissions;

[0102] Abnormal account status data includes: abnormal inflows and outflows of account funds, account freezes or restrictions, and sudden or unexplained changes in account balances;

[0103] Device abnormal data includes: changes in commonly used login devices or operating systems, and changes in device fingerprint information;

[0104] Security incident data includes: attacks by malware or networks, exploitation of security vulnerabilities, data leaks, and illegal use of personal information.

[0105] The construction method of the abnormal type diagnosis model includes:

[0106] The anomaly type diagnosis model is a decision tree model, including a root node, internal nodes, and leaf nodes. The CART algorithm is used to construct the decision tree model. The input data of the model is the account anomaly data within the historical period, and the output label is the account anomaly type. The pre-trained anomaly type diagnosis model is used to diagnose the current account anomaly data to obtain the corresponding account anomaly type.

[0107] Methods for implementing corresponding dynamic permission adjustment policies based on the type of account anomaly until the account returns to normal include:

[0108] Based on the type of account abnormality, dynamic adjustment strategies are implemented for user permissions until the account returns to normal; dynamic adjustment strategies include restricting account access rights, limiting account transaction amounts and frequency, enabling multi-factor authentication, requiring users to answer preset security questions when logging in, freezing accounts, and blocking transactions.

[0109] This embodiment combines the KNN algorithm with the local reachable density, uses the KNN algorithm to construct a sample set, and evaluates the degree of abnormality of each data point by calculating its local reachable density. It not only considers the spatial distance between data points, but also introduces the density information of the surrounding environment of the data point through the local reachable density. It can effectively identify data points with local density abnormalities, that is, those isolated points or out-of-cluster points that are significantly different from the surrounding data points, thereby improving the accuracy of anomaly detection, which is of great significance for discovering potential abnormal behaviors or system problems.

[0110] By introducing a neighbor adjustment model and a sensitivity coefficient adjustment formula, the number of nearest neighbor sample points and outlier sensitivity are dynamically adjusted. This allows for automatic parameter adjustments based on the characteristics of different datasets and the needs of anomaly detection, improving the algorithm's robustness and generalization capabilities. Furthermore, adjusting the sensitivity coefficient allows for fine-grained control over the impact of outliers to adapt to different application scenarios, making the anomaly detection process more flexible and adaptive.

[0111] By fusing feature datasets from different fields, we achieve comprehensive integration of multi-dimensional features, providing a broader perspective and richer information for data analysis. During the fusion process, weight coefficients are introduced to balance the importance of different feature datasets. This weight distribution mechanism allows analysts to adjust the contribution of each dataset based on actual conditions, thereby more flexibly adapting to different analytical needs. The comprehensive feature dataset obtained through weighted fusion not only incorporates the feature information of each individual dataset, but also achieves an optimized combination of features through adjustment of the weight coefficients. This comprehensive feature dataset provides more comprehensive and powerful support for subsequent data analysis and modeling.

[0112] A clustering algorithm is introduced into the traditional grid search method to partition the dataset. Clustering brings similar data points together, resulting in a more representative data distribution on the validation set and improving the accuracy of model evaluation. By optimizing the number of cluster centers and hyperparameter combinations, the model can learn more generalized feature representations, improving its predictive ability on unseen data.

[0113] Example 2

[0114] See also Figure 2 As shown, for the parts not described in detail in this embodiment, please refer to the description of Example 1. A unified account authority management method based on cloud computing is provided, including:

[0115] S1, used to collect user parameter data, user behavior data, platform parameter data and cloud environment parameter data;

[0116] S2. Based on the local outlier factor, the number of nearest neighbor sample points and the sensitivity coefficient are adjusted to influence the local reachability density, thereby detecting and removing outliers in user parameter data, user behavior data, platform parameter data, and cloud basic environment data, thereby obtaining parameter feature data sets, behavior feature data sets, platform feature data sets, and cloud environment feature data sets;

[0117] Perform correlation analysis and fusion on parameter feature datasets, behavior feature datasets, platform feature datasets, and cloud environment feature datasets to obtain a comprehensive feature dataset;

[0118] S3. Use support vector regression and optimize the number of clusters using the silhouette coefficient to obtain the optimal hyperparameter combination. Analyze the comprehensive feature data set and predict the account risk coefficient. Compare the predicted account risk coefficient with the preset account risk coefficient threshold to determine the account risk level.

[0119] S4. If the account is at low risk, the account risk factor changes are continuously monitored; if the account is at high risk, a risk warning instruction is issued through the cloud server management terminal, risk warning information is generated, and abnormal account data is collected;

[0120] S5. Analyze the account abnormal data and diagnose the abnormality type through the decision tree to obtain the corresponding account abnormality type;

[0121] S6 is used to execute the corresponding permission dynamic adjustment strategy according to the account abnormality type until the account returns to normal.

[0122] Since the electronic device described in this embodiment is an electronic device used to implement the unified account and authority management platform based on cloud computing in the embodiments of this application, those skilled in the art will be able to understand the specific implementation methods and various variations of the electronic device of this embodiment based on the unified account and authority management platform based on cloud computing described in the embodiments of this application. Therefore, how the electronic device implements the method in the embodiments of this application will not be described in detail here. As long as those skilled in the art implement the unified account and authority management platform based on cloud computing in the embodiments of this application, it falls within the scope of protection of this application.

[0123] The above formulas are all dimensionless and numerical calculations. The formulas are obtained by collecting a large amount of data and performing software simulation to obtain the most recent real situation. The preset parameters and thresholds in the formulas are set by technicians in this field according to actual conditions.

[0124] The above description is merely a preferred embodiment of the present invention. The scope of protection of the present invention is not limited to the above embodiment. All technical solutions based on the principles of the present invention are within the scope of protection of the present invention. It should be noted that for users of ordinary skill in the art, various improvements and modifications that do not depart from the principles of the present invention should also be considered within the scope of protection of the present invention.

Claims

1. A unified account authority management platform based on cloud computing, characterized by: include: Data collection module, used to collect user parameter data, user behavior data, platform parameter data and cloud environment parameter data; The data processing module, based on the local outlier factor, affects the local reachability density by adjusting the number of nearest neighbor sample points and the sensitivity coefficient, thereby detecting and removing outliers in user parameter data, user behavior data, platform parameter data, and cloud basic environment data, and thus obtaining parameter feature data sets, behavior feature data sets, platform feature data sets, and cloud environment feature data sets; Perform correlation analysis and fusion on parameter feature datasets, behavior feature datasets, platform feature datasets, and cloud environment feature datasets to obtain a comprehensive feature dataset; The account risk assessment module uses support vector regression and combines the silhouette coefficient to optimize the number of clusters to obtain the optimal hyperparameter combination. It analyzes the comprehensive feature data set and then predicts the account risk coefficient. The predicted account risk coefficient is compared with the preset account risk coefficient threshold to determine the account risk level. Account risk warning module: if the account is at low risk, it will continuously monitor the changes in the account risk coefficient; If the account is at high risk, a risk warning instruction will be issued through the cloud server management terminal, risk warning information will be generated, and abnormal account data will be collected; The abnormality type analysis module uses a decision tree to analyze account abnormal data and diagnose abnormality types to obtain the corresponding account abnormality types; The risk control processing module is used to execute the corresponding dynamic permission adjustment strategy according to the type of account abnormality until the account returns to normal; each module is connected via wired and / or wireless means.

2. The unified account authority management platform based on cloud computing according to claim 1, characterized in that: The user parameter data includes the user's name, ID number, mobile phone number and contact address; the user behavior data includes the user's login time and user login frequency; the platform parameter data includes the system version, service status, operation log, CPU usage and memory usage; the cloud environment parameter data includes resource usage, cloud service response time, fault records, security event logs, compliance check results and security policy execution.

3. The unified account authority management platform based on cloud computing according to claim 2, characterized in that: The method for obtaining the parameter feature data set, the behavior feature data set, the platform feature data set, and the cloud environment feature data set includes: Perform data cleaning on user parameter data, user behavior data, platform parameter data, and cloud basic environment data, process missing values and noise, perform standardization and normalization, convert them into standard state distribution, and obtain normalized user parameter data, user behavior data, platform parameter data, and cloud basic environment data; The normalized user parameter data, user behavior data, platform parameter data, and cloud infrastructure data are combined into a set X = {X1, X2, ..., Xn} containing n data samples, each of which contains d dimensions. Xn represents the nth data sample, Xn = (xn1, xn2, ..., xnd), and xnd is the data of the dth dimension in the data sample Xn. For each data sample Xi, calculate the distance between it and all other data samples. For each data sample, select K nearest neighbor sample points, which are recorded as the nearest neighbor sample set N. K (y); Calculate the local reachability density of each data sample, which is the inverse of the average reachability distance between the data sample and its K nearest neighbor sample points; Dynamically adjust the number of nearest neighbor sample points through the nearest neighbor adjustment model Among them, K' is the adjusted number of nearest neighbor sample points; w1, w2 and w3 are weight coefficients; a is the proportion of abnormal samples in the total number of data samples; Q is the number of noise samples; M is the size of the data sample; ε is the coefficient for adjusting the sensitivity of outliers; The size of ε is adjusted by the sensitivity coefficient adjustment formula, which is: Among them, δ is the gain coefficient for adjusting the influence of outliers, q is the noise ratio, η is the coefficient for adjusting the influence of noise, and θ is the equilibrium constant; Calculate the local outlier factor of the data sample and compare it with the preset local outlier factor threshold. Mark the data samples whose local outlier factor is greater than or equal to the preset local outlier factor threshold as outliers. Select and remove all outliers in the set X, and finally obtain the parameter feature dataset, behavior feature dataset, platform feature dataset, and cloud environment feature dataset.

4. The unified account authority management platform based on cloud computing according to claim 3, characterized in that: The method for obtaining the comprehensive feature data set includes: The parameter feature dataset, behavior feature dataset, platform feature dataset, and cloud environment feature dataset are fused through a weighted formula to obtain a comprehensive feature dataset; the parameter feature dataset is denoted as H1, the behavior feature dataset is denoted as H2, the platform feature dataset is denoted as H3, and the cloud environment feature dataset is denoted as H4; The weighting formula is F = α1·H1+α2·H2+α3·H3+α4·H4; among them, α1 is the weight coefficient of the parameter feature dataset; α2 is the weight coefficient of the behavior feature dataset; α3 is the weight coefficient of the platform feature dataset; α4 is the weight coefficient of the cloud environment feature dataset.

5. The unified account authority management platform based on cloud computing according to claim 4, characterized in that: The method for obtaining the account risk coefficient includes: The support vector regression model (SVR) is used to construct an account risk prediction model. The model's input data is a comprehensive feature dataset, and the output label is the account risk coefficient. The Gaussian kernel is selected as the kernel function of the model, and the model's hyperparameters are initialized. The model's hyperparameters are the penalty coefficient C and the kernel parameter γ. The dataset is divided into training set, validation set and test set; the model is trained using the training set to minimize the objective function; the ε'-insensitive loss function is used as the loss function of the model to measure the difference between the model's predicted value and the actual value; the ε'-insensitive loss function is Among them, y' i is the actual value of account risk; f(s) is the predicted value of account risk; ε' is the width of the insensitive interval; Tune the model hyperparameters to find the hyperparameters that minimize the loss function; use the test set to evaluate the model performance, and measure the model performance by observing the accuracy index of the model in the prediction task. When the model performance index reaches the preset model performance index threshold, stop the test and obtain the trained account risk prediction model; input the current comprehensive feature data set into the trained account risk prediction model to predict the account risk coefficient.

6. The unified account authority management platform based on cloud computing according to claim 5, characterized in that: The method for tuning the model hyperparameters includes: Use grid search to tune the model's hyperparameters, define the range of hyperparameters, and create a parameter grid containing all hyperparameter combinations Divide the dataset into V subsets of equal size, use the first subset as the validation set, and the remaining V-1 subsets as the training set; The method for dividing a dataset into V subsets of equal size is as follows: use the K-means clustering algorithm to subset the dataset; select V' initial cluster centers; calculate the distance between each data point in the dataset and each cluster center, and assign each data point to the cluster corresponding to the cluster center closest to it; calculate the mean of all data points in the cluster as the new cluster center; evaluate the clustering results by calculating the intra-cluster squared error; and adjust the number of initial cluster centers K' based on the evaluation results. The method for optimizing the number of initial cluster centers is as follows: preset the range of the number of cluster centers K', adjust the number of cluster centers by maximizing the silhouette coefficient, and select the V' value that maximizes the silhouette coefficient as the optimal number of clusters V; the silhouette coefficient is: Where SI is the silhouette coefficient; I is the index of the sample in the data set; e(I) is the average distance between sample I and other samples in its cluster; z(I) is the minimum value of the average distance between sample I and samples in other clusters; M' is the adjustment parameter; Use the training set to select any combination of hyperparameters The model is trained and the performance of the model is evaluated using the validation set to obtain performance indicators. The performance indicators of the obtained models corresponding to all hyperparameter combinations are calculated, and the hyperparameter combination that maximizes the performance indicator is selected as the optimal hyperparameter combination of the model. Use the best hyperparameter combination The model is trained on the training set and evaluated on the test set to confirm the generalization ability of the model.

7. The unified account authority management platform based on cloud computing according to claim 6, characterized in that: The method for determining the account risk level includes: If the predicted account risk coefficient is less than the preset account risk coefficient threshold, the account is judged to be in a low-risk state; If the predicted account risk coefficient is greater than or equal to the preset account risk coefficient threshold, the account is determined to be in a high-risk state.

8. The unified account authority management platform based on cloud computing according to claim 7, characterized in that: The abnormal account data includes: Account abnormality data is collected from high-risk accounts, including transaction abnormal behavior data, user abnormal behavior data, account status abnormal data, device abnormal data, and security event data.

9. The unified account authority management platform based on cloud computing according to claim 8, characterized in that: The method for constructing the abnormality type diagnosis model includes: The anomaly type diagnosis model is a decision tree model, including a root node, internal nodes, and leaf nodes. The CART algorithm is used to construct the decision tree model. The input data of the model is the account anomaly data within the historical period, and the output label is the account anomaly type. The pre-trained anomaly type diagnosis model is used to diagnose the current account anomaly data to obtain the corresponding account anomaly type.

10. The unified account authority management platform based on cloud computing according to claim 9, characterized in that: The method of executing a corresponding dynamic permission adjustment strategy according to the type of account abnormality until the account returns to normal includes: Based on the type of account abnormality, dynamic adjustment strategies are implemented for user permissions until the account returns to normal; dynamic adjustment strategies include restricting account access rights, limiting account transaction amounts and frequency, enabling multi-factor authentication, requiring users to answer preset security questions when logging in, freezing accounts, and blocking transactions.

Citation Information

Patent Citations

  • Computer system account management method based on cloud computing

    CN116167029A