A dynamic permission management system, method, and multi-source heterogeneous message middleware

By monitoring user behavior in real time and using a multi-agent voting mechanism to generate permission adjustment schemes, the problem of slow response in existing permission management schemes is solved, achieving a balance between security and user experience, and ensuring the system's rapid response and security in high-risk situations.

CN121000532BActive Publication Date: 2026-01-30BEIJING XINQIAO INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511524722.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-10-24
Publication Date
2026-01-30
Estimated Expiration
2045-10-24

AI Technical Summary

Technical Problem

Existing access control solutions rely on static rules and lack intelligent and dynamic adjustment capabilities, resulting in slow system response when facing risks, and even information leakage and economic losses.

Method used

A dynamic permission management system is provided. By monitoring user behavior, multiple intelligent agents are used to conduct real-time risk assessment and voting to generate a final permission adjustment plan. The permission management system decides whether to implement the plan, and permissions are automatically restored after user behavior returns to normal.

Benefits of technology

It achieves dynamic and intelligent access control, which can effectively protect the security of information systems. User permissions are adjusted in real time according to the risk situation, ensuring that normal usage permissions are restored in a timely manner after the risk is eliminated, and significantly improving the user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121000532B_ABST
    Figure CN121000532B_ABST
Patent Text Reader

Abstract

This application discloses a dynamic permission management system, method, and multi-source heterogeneous message middleware, relating to the field of permission management. The system includes a monitoring system, a risk assessment system, an intelligent agent system, and a permission management system. The monitoring system monitors user behavior in real time, obtaining real-time user behavior data. The risk assessment system performs comprehensive risk analysis on the real-time user behavior data, generating real-time risk assessment results. The intelligent agent system includes multiple intelligent agents with different functions. Each intelligent agent individually evaluates the real-time user behavior data based on the real-time risk assessment results, generates voting results, and combines the voting results of each intelligent agent to generate a final permission adjustment scheme. The permission management system decides whether to execute the final permission adjustment scheme. If user behavior returns to normal after executing the final permission adjustment scheme, the user's permissions are automatically restored. This application can improve user experience while ensuring information system security.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of access control, and in particular to a dynamic access control system, method, and multi-source heterogeneous message middleware. Background Technology

[0002] In today's increasingly complex network environment, abnormal changes in user behavior pose a significant threat to the security of information systems. Existing access control solutions often rely on static rules, lacking intelligent and dynamic adjustment capabilities. This makes the system slow to react when faced with risks, and may even lead to information leaks and economic losses.

[0003] With the continuous development of technology, especially the rise of big data analytics and artificial intelligence, enterprises urgently need to build a dynamic and intelligent access control mechanism to cope with the security challenges brought about by the complex Internet environment. Summary of the Invention

[0004] The purpose of this application is to provide a dynamic permission management system, method, and multi-source heterogeneous message middleware, which can improve user experience while ensuring information system security.

[0005] To achieve the above objectives, this application provides the following solution.

[0006] Firstly, this application provides a dynamic access control system, comprising: a monitoring system, a risk assessment system, an agent system, and an access control system; the monitoring system is used to monitor user behavior in real time, obtain real-time user behavior data, and transmit the real-time user behavior data to the risk assessment system; the risk assessment system is used to perform comprehensive risk analysis on the real-time user behavior data and generate real-time risk assessment results; the agent system includes multiple agents with different functions, and the agent system uses each agent to individually evaluate the real-time user behavior data based on the real-time risk assessment results, generate voting results, and synthesize the voting results of each agent to generate a final access control adjustment scheme; the access control system is used to decide whether to execute the final access control adjustment scheme, and if the user behavior returns to normal after the final access control adjustment scheme is executed, the user's access is automatically restored.

[0007] Secondly, this application provides a dynamic permission management method, including: real-time monitoring of user behavior to obtain real-time user behavior data; comprehensive risk analysis of the real-time user behavior data to generate real-time risk assessment results; evaluation of the real-time user behavior data by each agent based on the real-time risk assessment results to generate voting results; synthesis of the voting results of each agent to generate a final permission adjustment scheme; and decision on whether to execute the final permission adjustment scheme. If user behavior returns to normal after executing the final permission adjustment scheme, user permissions are automatically restored.

[0008] Thirdly, this application provides a multi-source heterogeneous message middleware, including the aforementioned dynamic permission management system.

[0009] According to the specific embodiments provided in this application, this application has the following technical effects.

[0010] This application provides a dynamic permission management system, method, and multi-source heterogeneous message middleware. By monitoring user behavior and risk assessment in real time, and through voting by multiple intelligent agents, it decides whether to temporarily restrict the operation permissions of high-risk accounts, thereby achieving dynamic and intelligent permission management and effectively ensuring the security of information systems. User permissions can be adjusted in real time according to the risk situation, ensuring that users' normal usage permissions are restored in a timely manner after the risk is eliminated, significantly improving the user experience. Attached Figure Description

[0011] To more clearly illustrate the technical solutions in the embodiments of this application or related technologies, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0012] Figure 1 This is a schematic diagram of the structure of a dynamic permission management system provided in an embodiment of this application.

[0013] Figure 2 This is a schematic diagram illustrating the working principle of a dynamic permission management system provided in an embodiment of this application.

[0014] Figure 3 This is a flowchart illustrating a dynamic permission management method provided in an embodiment of this application. Detailed Implementation

[0015] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0016] To make the above-mentioned objectives, features and advantages of this application more apparent and understandable, the application will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0017] In one exemplary embodiment, such as Figure 1As shown, a dynamic access control system is provided, including: a monitoring system, a risk assessment system, an agent system, and an access control system. The monitoring system monitors user behavior in real time, obtains real-time user behavior data, and transmits the data to the risk assessment system. The risk assessment system performs comprehensive risk analysis on the real-time user behavior data and generates a real-time risk assessment result. The agent system includes multiple agents with different functions. Each agent individually evaluates the real-time user behavior data based on the real-time risk assessment result, generates a voting result, and combines the voting results of each agent to generate a final access control adjustment plan. The access control system decides whether to execute the final access control adjustment plan. If user behavior returns to normal after executing the final access control adjustment plan, the user's access is automatically restored.

[0018] This application utilizes real-time risk assessment (such as abnormal user behavior) and a vote by multiple intelligent agents to decide whether to temporarily restrict the operational permissions of high-risk accounts. This mechanism achieves a better balance between ensuring security and user experience, and improves the system's responsiveness and security level, especially in high-risk situations.

[0019] The following section provides a detailed introduction to each system within the dynamic permission management system.

[0020] (a) Monitoring system.

[0021] The monitoring system is responsible for monitoring user behavior in real time, providing a behavioral data interface, and transmitting the data to the risk assessment system.

[0022] The monitoring system includes a data acquisition module, a data processing module, and an interface module, which are connected sequentially. The data acquisition module captures raw user behavior data in real time. The data processing module performs structured transformation, time-series alignment, and feature extraction on the raw user behavior data to obtain processed user behavior data. The interface module pushes the processed user behavior data to the risk assessment system in real time.

[0023] Data Acquisition Module: Captures raw user behavior data through SDK tracking and API (Application Programming Interface) logs. User behavior data includes, but is not limited to: login timestamps, IP geographic information, operation frequency (such as the number of requests per second), and sensitive operation sequences (such as the sequence of "check balance → transfer → change password").

[0024] Data processing module: performs structured transformation, time-series alignment, and feature extraction on the raw user behavior data.

[0025] Structured transformation: Convert unstructured logs into JSON format, with fields including user_id, action_type, timestamp, and risk_flag.

[0026] Time-order alignment: Out-of-order data generated by a distributed system is reordered according to operation time. "Out-of-order data generated by a distributed system" corresponds to the "operation frequency (e.g., requests per second)" and "sensitive operation sequences (e.g., the time sequence of 'query balance → transfer → change password')" mentioned in the data acquisition module. Because different nodes may perform operations simultaneously in a distributed system, the records of these operations are not necessarily sequential in time; therefore, it is necessary to reorder this data according to operation time.

[0027] Feature extraction: Generate statistical features (such as the number of failed login attempts from the same IP address within 10 minutes).

[0028] Interface module: The processed data is pushed to the risk assessment system in real time via a RESTful API, and the transmission protocol uses TLS encryption.

[0029] (ii) Risk assessment system.

[0030] The risk assessment system analyzes user behavior using algorithms to generate real-time risk assessment results.

[0031] The risk assessment system includes a data input module, a risk assessment module, and an assessment result output module, which are connected sequentially.

[0032] The data input module receives real-time user behavior data. The risk assessment module uses threshold detection, statistical analysis, and machine learning algorithms to identify abnormal behaviors based on this data, obtaining the judgment results from each algorithm. The assessment result output module performs a comprehensive risk analysis on the judgment results from these algorithms, generating a real-time risk assessment result, which is then pushed to the intelligent agent system in real time.

[0033] The data input module receives and caches user behavior data from the monitoring system interface module.

[0034] Risk assessment module: Used to comprehensively assess the risk of input data. Specifically, it includes threshold detection algorithms, statistical analysis algorithms, and machine learning algorithms.

[0035] Threshold detection algorithm: A normal range for user behavior data is defined; when real-time user behavior data exceeds the upper limit of this normal range, it is marked as abnormal behavior. User behavior data includes metrics such as login failure count and access frequency.

[0036] Statistical analysis algorithms: By modeling the behavioral distribution of a user group, these algorithms detect whether individual behaviors deviate from the overall pattern. The data processed by statistical analysis algorithms is the behavioral distribution of the user group. Statistical analysis algorithms identify abnormal behavior, specifically including: establishing a baseline behavioral model based on historical behavioral data of the user group using statistical methods; establishing a standard distribution curve for the user group's behavior based on the baseline behavioral model; determining confidence intervals for user behavior from the standard distribution curve; establishing a normal range for user behavior based on the confidence intervals; and marking real-time user behavior data as abnormal if it exceeds the upper limit of the normal range.

[0037] For example, the historical behavior data of the aforementioned user group can include login time, operation frequency, etc. The statistical methods used can be, for example, normal distribution, Poisson distribution, etc. By calculating the mean, variance, and other statistical measures of the group's behavior, a standard distribution curve of the group's behavior can be formed, such as a standard normal distribution curve. Confidence intervals for typical behavioral patterns can be determined, such as configuring them as 95% confidence intervals.

[0038] The standard calculation method for detecting individual behavior deviating from the overall pattern:

[0039] Group benchmark model: Calculates the distribution of behavioral parameters of a user group (such as mean μ, standard deviation σ) using historical data.

[0040] Threshold setting:

[0041] Use static thresholds: directly set a fixed range (e.g., login failures > 5 times / hour).

[0042] Dynamic thresholds are used: based on confidence intervals (e.g., 80% corresponds to ±1.28σ, 95% corresponds to ±1.96σ), and values ​​outside the range are considered deviations.

[0043] Example:

[0044] If the average user access frequency μ = 10 times / minute and σ = 2, then:

[0045] 80% confidence interval: 10 ± 2.56 → 7.44 beats / minute to 12.56 beats / minute is considered normal.

[0046] A user accessed the site 15 times per minute → triggering an exception.

[0047] Machine learning models (such as the Isolation Forest algorithm) are trained based on existing normal behavior data to automatically identify individual behaviors that deviate from the group's patterns. They are suitable for detecting sudden and combined anomalies. The data processed by these machine learning models is existing normal behavior data used to identify individual behaviors that deviate from the group's patterns. By inputting real-time user behavior data into a pre-trained machine learning model, behavioral anomalies can be identified.

[0048] Evaluation result output module: It integrates the judgment results output by the threshold detection algorithm, statistical analysis algorithm and machine learning algorithm to generate a risk score ranging from 0 to 100, and attaches abnormal behavior labels (such as "abnormal login", "high frequency access" etc.) as input to the intelligent agent system.

[0049] In terms of comprehensively analyzing the risk results of threshold detection algorithms, statistical analysis algorithms, and machine learning algorithms to generate real-time risk assessment results, the assessment result output module specifically includes: obtaining the corresponding values ​​of the judgment results of threshold detection algorithms, statistical analysis algorithms, and machine learning algorithms respectively; weighting the corresponding values ​​of threshold detection algorithms, statistical analysis algorithms, and machine learning algorithms to obtain a risk score; establishing abnormal behavior labels based on the abnormal behaviors in the real-time user behavior data identified by threshold detection algorithms, statistical analysis algorithms, and machine learning algorithms respectively; and combining the risk score and abnormal behavior labels to constitute the real-time risk assessment result.

[0050] The specific values ​​for the judgment results of the threshold detection algorithm, statistical analysis algorithm, and machine learning algorithm are as follows.

[0051] For the threshold detection algorithm: A normal data range for user behavior is set (e.g., login failures ≤ 5 times / hour). When real-time data exceeds the upper limit of the normal data range, it is marked as abnormal, and the corresponding value is 1; otherwise, the value is 0. Example: When 7 failed logins are detected per hour, the value is 1.

[0052] For statistical analysis algorithms: Establish a standard distribution curve based on user group behavior (e.g., μ = 10 times / minute, σ = 2), calculate the deviation of individual behavior from the group mean, and assign values ​​according to confidence intervals (e.g., 0.2 within the 80% confidence interval, 0.8 beyond). Example: User visits 15 times / minute (beyond the 95% confidence interval), value = 0.95.

[0053] For machine learning algorithms: real-time data is input into a pre-trained model (such as Isolation Forest), and the model directly outputs anomaly probability values ​​(in the range of 0-1). Example: a pre-trained model outputting 0.83 indicates an 83% anomaly probability.

[0054] (III) Intelligent agent system.

[0055] The intelligent agent system is responsible for voting and feeding the results back to the access control system.

[0056] The intelligent agent system can be replaced by the following steps S1 to S9 in terms of using each intelligent agent to evaluate real-time user behavior data based on real-time risk assessment results, generating voting results, and combining the voting results of each intelligent agent to generate a final permission adjustment plan.

[0057] S1: Set real-time risk assessment results to include risk scores and abnormal behavior labels.

[0058] S2: Each agent adjusts its risk score individually based on abnormal behavior labels and real-time user behavior data, thus obtaining the adjusted risk score for each agent.

[0059] S3: When the adjusted risk score of each agent is greater than its own preset score threshold, the voting result is to restrict permissions.

[0060] S4: When the risk score adjusted by each agent is less than or equal to its respective preset score threshold, the voting result is to maintain the permission.

[0061] S5: Set the vote result for restricting permissions to 1, and set the vote result for maintaining permissions to 0.

[0062] S6: Generate a weighted comprehensive decision value based on the voting results.

[0063] S7: If the overall decision value is greater than the decision threshold, the final permission adjustment plan is determined to be a restriction of permissions.

[0064] S8: If the overall decision value is less than the decision threshold, the final permission adjustment plan is determined to be no permission restriction.

[0065] S9: If the comprehensive decision value equals the decision threshold, a secondary verification is triggered; if the secondary verification passes, the final permission adjustment scheme is determined to be unrestricted permissions; if the secondary verification fails, the final permission adjustment scheme is determined to be restricted permissions; the secondary verification includes SMS verification and biometric identification.

[0066] Based on steps S1 to S9, the intelligent agent system can be divided into an agent module, a decision-making module, and a voting result aggregation module according to their functions. The agent module, decision-making module, and voting result aggregation module are connected in sequence.

[0067] The agent module contains multiple agents with different functions. Each agent acts as an independent evaluation unit, processing data from different dimensions.

[0068] For example, multiple intelligent agents with different functions include a historical behavior intelligent agent, a geographic location intelligent agent, a time pattern intelligent agent, a transaction sensitivity intelligent agent, and a group behavior comparison intelligent agent, each with the following functions.

[0069] The historical behavior agent compares real-time user behavior data with the user's baseline behavior model; if the real-time user behavior data matches the user's baseline behavior model, the risk score is reduced; if the real-time user behavior data deviates from the user's baseline behavior model, the risk score is increased.

[0070] The user's baseline behavior model is established by analyzing the user's historical operation data (digital profile of user habits), and the main process of establishing it is as follows.

[0071] (1) Data collection

[0072] Data types: login time, operating device, frequently used functions, access frequency, geographical location, etc.

[0073] Time range: Typically, the system collects normal operation records of users over the past 3 to 6 months.

[0074] (2) Feature extraction

[0075] Statistical characteristics: such as average daily login frequency, high-frequency operation periods, and commonly used IP ranges;

[0076] Behavioral patterns: For example, "Export reports every Monday morning" or "Access only via mobile device".

[0077] (3) Model training

[0078] Statistical models (such as mean / standard deviation): quantify the normal fluctuation range of user behavior;

[0079] Machine learning (such as clustering / classification): distinguishing between user personalized habits and anomalies.

[0080] Output: Generate user-specific behavioral baselines (e.g., "90% of logins occur between 9:00 and 18:00").

[0081] (4) Dynamic updates

[0082] Adjust the model regularly (e.g., monthly) with new data to adapt to changes in behavior;

[0083] The specific form of the baseline behavior model is a combination of structured rules and probability distributions, for example:

[0084] (1) Regularization features

[0085] Time rule: Allowed login period = weekdays 8:00–20:00 (95% confidence level);

[0086] Device rule: Commonly used devices = [MacBook Pro, iPhone 13] (historical percentage 85%).

[0087] (2) Statistical threshold

[0088] Operation frequency: Average number of queries per day = 20 ± 5 times (more than 3σ is considered abnormal);

[0089] Geographic location: Commonly used IP cities; other cities require secondary verification.

[0090] (3) Machine learning output

[0091] Anomaly detection model:

[0092] Input: User's current behavioral characteristics (e.g., login time + device + action);

[0093] Output: Anomaly probability value (e.g., 0.8 → high risk).

[0094] The geolocation agent monitors real-time user behavior data for anomalies in IP geolocation changes. When anomalies are detected, a high-risk assessment is immediately established, and the risk score is set to the highest level. Anomalies in IP geolocation include sudden IP changes without a reasonable explanation (e.g., IPs from different locations).

[0095] The time-pattern agent determines whether the login time in real-time user behavior data belongs to a high-risk time period. If the login time belongs to a high-risk time period, the weighting coefficient of the time-pattern agent is increased. The high-risk time period is an abnormal gap period dynamically calculated based on historical traffic baseline, such as the early morning.

[0096] The transaction sensitivity agent analyzes real-time user behavior data to determine if it constitutes a high-risk operation. If so, the risk score is set to the highest possible level. High-risk operations include data deletion and large-scale data export.

[0097] The group behavior comparison agent calculates the deviation between real-time user behavior data and the average behavior of the user group, assesses the degree of anomaly, and improves the risk score based on the deviation. If user behavior deviates significantly from the group mean, the score is adjusted.

[0098] Decision Module: Each agent determines whether its risk score exceeds a set threshold based on its own policy model. If it does, it votes to "restrict access"; if not, it votes to "maintain access." The voting process is independent, and the system assigns different weights to each agent (e.g., 0.2 weight for geographic location agents and 0.4 weight for historical behavior agents). A weighted voting mechanism is used to calculate the final decision value; if the result is to restrict access, it is immediately pushed to the access management system.

[0099] Voting Results Summary Module: Summarizes the voting results of all agents, generates the final permission adjustment scheme ("restricted permissions" or "unrestricted permissions") according to the predetermined weighted calculation method, and submits it to the permission management system for execution.

[0100] Calculate the overall decision value: In the formula, This represents the comprehensive decision value. Indicates the first The voting results of each agent can be represented as follows: Indicates the first The weights of each agent.

[0101] If the overall decision value is greater than 0.6 (a configurable threshold), it is determined as "restricting permissions"; in the event of a tie, secondary verification is triggered first rather than direct restriction. The criteria for determining a tie: In an agent voting system, a tie means that the overall decision value is exactly equal to the decision threshold (e.g., 0.6).

[0102] Example of a draw:

[0103] The historical behavior agent (weight 0.4) votes "Restrict Permissions" (1×0.4=0.4); the geolocation agent (weight 0.2) votes "Maintain Permissions" (0×0.2=0); the time pattern agent (weight 0.1) votes "Restrict Permissions" (1×0.1=0.1); the overall decision value is: 0.4+0+0.1 = 0.5, overall decision value < 0.6 → Maintain Permissions. If the weight of the time pattern agent is changed to 0.2, the overall decision value is 0.6 → a draw.

[0104] Tie-breaking approach: Trigger secondary verification (such as SMS verification code, biometric identification) instead of directly restricting permissions. Permissions are maintained after successful secondary verification; otherwise, restrictions are imposed. The design intent of this tie-breaking approach is to avoid misjudging high-risk users due to minor score differences, achieving a balance between security and user experience.

[0105] (iv) Access control system.

[0106] The access control system dynamically adjusts user permissions based on the voting results of the intelligent agents, and provides management and recovery interfaces.

[0107] The access control system includes three modules: a access control adjustment module, an audit log module, and an access control recovery module. The access control adjustment module prevents the final access control adjustment from being executed when the administrator has pre-set user access permissions. When the administrator has not pre-set user permissions, it dynamically adjusts user permissions according to the final access control adjustment plan, restricting sensitive operations (such as exporting, deleting, and modifying), sending risk warnings to users, and setting access freeze times or conditional recovery mechanisms. The audit log module records detailed information on all access control adjustments, maintaining the system's audit trail. The access control recovery module automatically restores user permissions if user behavior returns to normal after an access control adjustment. For example, the criteria for normal user behavior recovery are: the user performs a certain number of consecutive normal operations; no system-preset risk behavior patterns are triggered for a period of time; operation type weighting is differentiated (e.g., the proportion of critical and sensitive operations is reduced); and manual review and confirmation (secondary verification by the system administrator or a trusted intelligent agent).

[0108] The permission restoration module automatically restores user permissions based on subsequent risk assessment results. If the subsequent risk assessment results show a significant decrease, the system will automatically trigger the restoration process. A secondary voting mechanism can also be set to confirm the lifting of permission restrictions. The criteria for a significant decrease in risk assessment results are: a drop in risk assessment score exceeding a certain threshold (e.g., 50); risk score below the warning line for multiple consecutive assessment cycles (e.g., 3 times); agent voting approval rate reaching a specific percentage (e.g., 80%); and time window restrictions (e.g., a continuous decline in risk score within the last 7 days).

[0109] The monitoring system and risk assessment system in this application communicate via an interface, transmitting user behavior data (such as login time, login IP, accessed files, operation frequency, etc.) to the risk assessment system. Based on the received data, the risk assessment system uses a built-in assessment algorithm model (such as a machine learning-based anomaly detection model) to perform a risk score, outputting a risk value (range 0–100). This risk score is then transmitted to an intelligent agent system, where multiple agents analyze and judge the score, and vote on whether to restrict user permissions. The intelligent agent system submits the weighted voting results to the permission management system, which ultimately decides whether to execute the permission adjustment operation and records the result in the audit module. If the user's behavior returns to normal, the system can automatically restore their permissions based on the latest assessment value. These modules are connected sequentially to form a closed-loop control system. After receiving the voting results, the permission management system does not directly modify permissions according to the voting results, but rather combines the system administrator's pre-set settings for users and user groups to determine the final permissions. The system administrator's pre-set settings for users and user groups are manual settings, which have the highest priority. This mechanism ensures the controllability of automated permission management.

[0110] The working principle of the dynamic permission management system in this application is as follows: Figure 2 As shown.

[0111] This application also suggests using a centralized decision-making system for risk assessment, but this approach often requires significant resources and is prone to becoming a single point of failure. Furthermore, the results of centralized decision-making may be affected by insufficient judgment equilibrium and inadequate self-defense mechanisms.

[0112] The advantages of this application are as follows.

[0113] 1. High efficiency: Through a multi-agent voting mechanism, risk assessment and permission adjustment can be completed in a very short time, reducing the need for manual intervention.

[0114] 2. Improved accuracy: Risk assessment combines the voting results of multiple agents, reducing the error caused by a single judgment, and can more accurately decide whether to restrict the operation permissions of high-risk accounts based on the actual risk.

[0115] 3. High flexibility: User permissions can be adjusted in real time according to the risk situation, ensuring that the user's normal usage permissions are restored in a timely manner after the risk is resolved, which significantly improves the user experience.

[0116] 4. High transparency: Every permission adjustment has a detailed audit record, which facilitates subsequent analysis and improvement.

[0117] These advantages mainly stem from the following technical aspects.

[0118] This application employs an intelligent agent voting mechanism to improve the accuracy of decision-making and the ability to respond quickly.

[0119] Through real-time risk monitoring and assessment, we ensure that every permission adjustment is based on the latest data analysis results.

[0120] The combined use of multiple agents makes decision-making more diversified, reduces the bias caused by a single decision, and improves the system's fault tolerance.

[0121] Based on the same inventive concept, this application also provides a dynamic permission management method applied to the aforementioned dynamic permission management system. The solution provided by this method is similar to the implementation scheme described in the above system; therefore, the specific limitations in one or more embodiments of the dynamic permission management method provided below can be found in the limitations of the dynamic permission management system described above, and will not be repeated here.

[0122] In one exemplary embodiment, such as Figure 3 As shown, a dynamic permission management method is provided, including the following steps 101 to 105.

[0123] Step 101: Monitor user behavior in real time and obtain real-time user behavior data.

[0124] Step 102: Conduct a comprehensive risk analysis on real-time user behavior data to generate real-time risk assessment results.

[0125] Step 103: Utilize each agent individually to evaluate real-time user behavior data based on the real-time risk assessment results, and generate voting results.

[0126] Step 104: Combine the voting results of each agent to generate the final permission adjustment plan.

[0127] Step 105: Decide whether to implement the final permission adjustment plan. If the user's behavior returns to normal after the final permission adjustment plan is implemented, the user's permissions will be automatically restored.

[0128] Steps 101 and 102 above involve real-time risk assessment, executed by the monitoring system and the risk assessment system. The specific process is as follows: The monitoring system collects various user behavioral data, including login time, IP address, and operational behaviors (such as file access and message sending). Using preset rules and models (such as anomaly detection algorithms), the system analyzes the data to determine behavioral patterns. Once abnormal behavior is detected (such as frequent incorrect logins or abnormal login locations), the system records it immediately and generates a corresponding risk assessment value. This assessment value is converted into a specific score, which describes whether the current user behavior is abnormal and its severity. The output risk assessment value typically ranges from 0 to 100, with higher values ​​indicating greater risk.

[0129] Steps 103-104 above employ an agent voting mechanism, executed by multiple agents (AI proxies) within the agent system. The specific process is as follows: The system generates several agents (multiple proxies), each participating in the voting according to its own set rules and weights. For example, one agent might make a judgment based on historical user behavior data, while another might rely more on real-time data analysis. Each agent receives input data including real-time risk assessment results and the user's current state information, and performs an evaluation based on this information. They each make judgments and vote, with voting results categorized as "restrict permissions" or "maintain permissions." Each agent's voting result generates different weights, which are then combined to form the final voting result. The final voting result is output; for example, if the vast majority of agents vote to restrict permissions, this result will be given priority.

[0130] Rule-based static access control still exists, and while this approach can be effective in certain situations, it often struggles to adapt to complex and ever-changing internal and external threats. Therefore, this application incorporates a diversified evaluation method using intelligent agents, enabling more efficient and dynamic access control.

[0131] Step 105 above involves dynamic permission adjustment, executed by the permission management system. The specific process is as follows: Based on the voting results of the intelligent agents, corresponding permission adjustments are performed. If the system decides to restrict permissions, high-risk accounts will have certain critical operations suspended (such as exporting, deleting, and modifying), and a record will be generated. The system will continue to monitor the account's subsequent behavior; if the assessment results improve, the system will conduct a second vote for adjustment. If the assessment determines that the risk has been eliminated, the user's full operational privileges are automatically restored. The system outputs the operation permission adjustment results, permission status change records, etc.

[0132] This application is proposed based on an analysis of the shortcomings of existing technologies. By introducing intelligent agent technology and dynamic risk monitoring, it aims to improve the user experience while ensuring the security of large-scale systems.

[0133] In one exemplary embodiment, this application provides a multi-source heterogeneous message middleware, which includes the aforementioned dynamic permission management system. Therefore, this application provides an efficient permission management solution for multi-source heterogeneous message middleware based on the dynamic permission adjustment technology of the intelligent agent voting mechanism.

[0134] Multi-source heterogeneous message middleware refers to a message middleware system used to connect, transmit, and integrate data from different sources (multi-source) and different structures (heterogeneous). In modern distributed architectures, it acts as a "data bus," resolving inconsistencies in protocols, formats, and speeds between different systems. Multi-source: Data comes from different systems, such as databases, sensors, APIs, logs, and IoT (Internet of Things) devices. Heterogeneous: Data has different formats, such as JSON, XML, CSV, binary, and structured / unstructured data. Message middleware: Acts as an "intermediary" to asynchronously transmit data, decoupling upstream and downstream systems and improving system resilience and scalability.

[0135] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0136] This document uses specific examples to illustrate the principles and implementation methods of this application. The descriptions of the above embodiments are only for the purpose of helping to understand the methods and core ideas of this application. Furthermore, those skilled in the art will recognize that, based on the ideas of this application, there will be changes in the specific implementation methods and application scope. Therefore, the content of this specification should not be construed as a limitation of this application.

Claims

1. A dynamic permission management system, characterized in that, Comprise: A monitoring system, a risk assessment system, an agent system and a permission management system; The monitoring system is used for monitoring user behavior in real time, obtaining real-time user behavior data, and transmitting the real-time user behavior data to the risk assessment system; The risk assessment system is used for comprehensive risk analysis on the real-time user behavior data to generate real-time risk assessment results; The agent system comprises a plurality of agents with different functions, and the agent system uses each agent to evaluate the real-time user behavior data according to the real-time risk assessment results to generate a voting result, and combines the voting results of each agent to generate a final permission adjustment scheme; The permission management system is used for determining whether to execute the final permission adjustment scheme, and automatically restoring user permissions if the user behavior returns to normal after executing the final permission adjustment scheme; The monitoring system comprises a data acquisition module, a data processing module and an interface module; The data acquisition module is used for real-time acquisition of original user behavior data; The data processing module is used for structural conversion, time sequence alignment and feature extraction on the original user behavior data to obtain processed user behavior data; The interface module is used for real-time pushing of the processed user behavior data to the risk assessment system; The risk assessment system comprises a data input module, a risk assessment module and an evaluation result output module; The data input module is used for receiving real-time user behavior data; The risk assessment module is used for identifying abnormal behaviors by using a threshold detection algorithm, a statistical analysis algorithm and a machine learning algorithm according to the real-time user behavior data to obtain the judgment results of the threshold detection algorithm, the statistical analysis algorithm and the machine learning algorithm; The evaluation result output module is used for comprehensive risk analysis on the judgment results of the threshold detection algorithm, the statistical analysis algorithm and the machine learning algorithm to generate real-time risk assessment results, and real-time pushing of the real-time risk assessment results to the agent system.

2. The dynamic rights management system of claim 1, wherein, The threshold detection algorithm identifies abnormal behaviors, specifically comprising: setting a normal data range of user behavior; when the real-time user behavior data is greater than the upper limit value of the set normal data range, marking as behavior abnormal; The statistical analysis algorithm identifies abnormal behaviors, specifically comprising: based on historical behavior data of a user group, using a statistical method to establish a benchmark behavior model; according to the benchmark behavior model, establishing a standard distribution curve of user group behavior; determining a confidence interval of user behavior from the standard distribution curve; according to the confidence interval of user behavior, establishing a normal range of user behavior; if the real-time user behavior data is greater than the upper limit value of the normal range of user behavior, marking as behavior abnormal; The machine learning algorithm identifies abnormal behaviors, specifically comprising: inputting the real-time user behavior data into a trained machine learning model to identify behavior abnormalities.

3. The dynamic rights management system of claim 1, wherein, The evaluation result output module in the comprehensive risk analysis on the judgment results of the threshold detection algorithm, the statistical analysis algorithm and the machine learning algorithm to generate real-time risk assessment results, specifically comprises: Respectively obtaining the corresponding values of the judgment results of the threshold detection algorithm, the statistical analysis algorithm and the machine learning algorithm; Weighting the corresponding values of the threshold detection algorithm, the statistical analysis algorithm and the machine learning algorithm to obtain a risk score; According to the abnormal behaviors in the real-time user behavior data identified by the threshold detection algorithm, the statistical analysis algorithm and the machine learning algorithm, an abnormal behavior label is established; The risk score and the abnormal behavior label together constitute a real-time risk assessment result.

4. The dynamic rights management system of claim 1, wherein, In terms of using each agent to evaluate the real-time user behavior data according to the real-time risk assessment result, generating a voting result, and synthesizing the voting result of each agent to generate the final permission adjustment scheme, the intelligent agent system specifically includes: Setting the real-time risk assessment result to include the risk score and the abnormal behavior label; Each agent adjusts the risk score according to the abnormal behavior label and the real-time user behavior data, and obtains the adjusted risk score of each agent; When the adjusted risk score of each agent is greater than the respective preset score threshold, the voting result is to limit the permission; When the adjusted risk score of each agent is less than or equal to the respective preset score threshold, the voting result is to maintain the permission; The voting result of limiting the permission is valued as 1, and the voting result of maintaining the permission is valued as 0; According to the voting result value, a comprehensive decision value is generated by weighting; If the comprehensive decision value is greater than the decision threshold, it is determined that the final permission adjustment scheme is to limit the permission; If the comprehensive decision value is less than the decision threshold, it is determined that the final permission adjustment scheme is not to limit the permission; If the comprehensive decision value is equal to the decision threshold, a secondary verification is triggered; after the secondary verification passes, it is determined that the final permission adjustment scheme is not to limit the permission; after the secondary verification fails, it is determined that the final permission adjustment scheme is to limit the permission; the secondary verification includes SMS verification and biometric identification.

5. The dynamic rights management system of claim 4, wherein, When the multiple different-function agents include a historical behavior agent, a geographic location agent, a time pattern agent, a transaction sensitivity agent and a group behavior comparison agent, each agent adjusts the risk score according to the abnormal behavior label and the real-time user behavior data, specifically including: The historical behavior agent compares the real-time user behavior data with the user's baseline behavior model; if the real-time user behavior data conforms to the user's baseline behavior model, the risk score is reduced; if the real-time user behavior data deviates from the user's baseline behavior model, the risk score is increased; The geographic location agent monitors whether the IP geographic location change in the real-time user behavior data is abnormal, and sets the risk score to the highest score when it is determined that the IP geographic location change is abnormal; The time pattern agent determines whether the login time in the real-time user behavior data belongs to a high-risk time period, and increases the weighting coefficient of the time pattern agent if the login time belongs to a high-risk time period; The transaction sensitivity agent analyzes whether the real-time user behavior data belongs to a high-risk operation, and sets the risk score to the highest score if the real-time user behavior data belongs to a high-risk operation; The group behavior comparison agent calculates the deviation of the real-time user behavior data from the average behavior of the user group, and increases the risk score according to the deviation.

6. The dynamic rights management system of claim 1, wherein, The permission management system includes a permission adjustment module, an audit record module and a permission recovery module; The permission adjustment module is configured to not execute the most stringent permission adjustment scheme when the administrator has previously set the user's permissions, and to dynamically adjust the user's permissions according to the most stringent permission adjustment scheme, limit sensitive operations, send a risk prompt to the user, and set a permission freezing time or a condition-triggered recovery mechanism when the administrator has not previously set the user's permissions. The audit record module is configured to record detailed information of all permission adjustments. The recovery permission module is configured to automatically recover the user's permissions when the user's behavior returns to normal after the user's permissions are adjusted.

7. A dynamic permission management method, characterized by, The method comprises: real-time monitoring of user behavior to obtain real-time user behavior data, specifically including: real-time capture of original user behavior data; and structural conversion, time alignment and feature extraction of the original user behavior data to obtain processed user behavior data; comprehensive risk analysis of the real-time user behavior data to generate real-time risk assessment results, specifically including: receiving real-time user behavior data; identifying abnormal behavior using threshold detection algorithms, statistical analysis algorithms and machine learning algorithms according to the real-time user behavior data to obtain the judgment results of the threshold detection algorithms, statistical analysis algorithms and machine learning algorithms; and comprehensive risk analysis of the judgment results of the threshold detection algorithms, statistical analysis algorithms and machine learning algorithms to generate real-time risk assessment results; using each agent to evaluate the real-time user behavior data according to the real-time risk assessment results to generate voting results; integrating the voting results of each agent to generate a most stringent permission adjustment scheme; determining whether to execute the most stringent permission adjustment scheme, and automatically recovering the user's permissions when the user's behavior returns to normal after the most stringent permission adjustment scheme is executed.

8. A multi-source heterogeneous message middleware, characterized in that, The multi-source heterogeneous message middleware comprises the dynamic permission management system of any one of claims 1-6.

Citation Information

Patent Citations

  • Dynamic authority management system for database

    CN118886061A

  • Access authority management method and system of industrial internet

    CN120474843A