A method and device for determining user permissions
By dividing and permission analysis of multiple users, the optimal permission set in similar users' concentrations is determined, which solves the problem of inaccurate permission automatic configuration in the existing technology, and improves the accuracy of permission configuration and system security.
Patent Information
- Application Number
- CN201911291930.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2019-12-16
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2039-12-16
AI Technical Summary
The existing automatic permission configuration method has increased the workload of manual permission sorting due to inaccurate configuration of the permission set, resulting in confusing permission configuration and excessive permission scope, which increases the risk of data leakage.
By dividing multiple users, obtaining a similar user set, and performing permission analysis for each user in each similar user set, we determine the optimal permission set for each user set in the similar user set. The method includes obtaining the key characteristics of the user, building a user behavior characteristic library, using the user similarity calculation model to obtain similar user sets, and determining the optimal permission set based on the principle of permission minimization.
This method can ensure the accuracy of the permission set, reduce the workload of manual permission sorting, reduce the risk of data leakage, and improve system security.
Smart Images

Figure CN112989402B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data security, and particularly to a method and device for determining user permissions. Background Art
[0002] In a system, the permissions of users or application programs (hereinafter collectively referred to as users) are generally manually configured by an administrator. The administrator configures corresponding operation permissions for them according to factors such as the level, category, department to which they belong, and business requirements of the user program. On the one hand, it is necessary to ensure that the configured permissions are large enough to ensure the normal business access behavior of users; on the other hand, it is necessary to prevent users from having excessive permissions, resulting in users being able to access data beyond their actual needs.
[0003] Permission control is a basic requirement for data security, and most systems provide a fine-grained authorization function. This allows the administrator to configure more refined permissions for users. However, as the business volume increases and the number and types of users increase, the workload of the administrator for configuring permissions also gradually increases. It is difficult to configure suitable permissions for each or every type of user, and in order to ensure the normal operation of the business, the administrator often configures relatively large permissions for users. Therefore, in a long-running system, it is very likely, or even common, that there are phenomena such as chaotic permission configuration and excessive permission scope for users (or application programs). This greatly increases the risk of data leakage and is a threat to system security.
[0004] However, the automatic permission configuration method has the problem of unreasonable permission set configuration, which increases the workload of manual permission sorting. Summary of the Invention
[0005] Embodiments of the present invention provide a method and device for determining user permissions to solve the problem that the existing automatic permission configuration method increases the workload of manual permission sorting due to inaccurate permission set configuration.
[0006] To solve the above technical problems, embodiments of the present invention provide a method for determining user permissions, including:
[0007] Dividing multiple users to obtain at least one set of similar users;
[0008] Performing permission analysis on each user in each set of similar users to determine the optimal permission set for each user in the set of similar users.
[0009] Optionally, the dividing multiple users to obtain at least one set of similar users includes:
[0010] Obtaining the key features of each user and constructing a user behavior feature library;
[0011] Based on the user behavior feature library, at least one set of similar users is obtained by using a user similarity calculation model;
[0012] Among them, the permissions of the users in each set of similar users are the same or similar.
[0013] Specifically, the key features include: the identity features of the user and / or the historical operation behavior features of the user.
[0014] Specifically, the historical operation behavior features of the user include at least one of the following:
[0015] The data range involved in the access behavior;
[0016] The operation type involved in the access behavior;
[0017] The data import and export behavior features involved in the operation behavior;
[0018] The operation behavior features for the system sensitive data;
[0019] The features reflecting the operation level.
[0020] Optionally, the acquisition method of the user similarity calculation model is:
[0021] Select at least one clustering algorithm to cluster the training set users into P clusters;
[0022] According to the clustering result, determine the optimal number of clusters n to obtain a clustering algorithm model;
[0023] Use the test set data to verify the clustering algorithm model, iterate and correct the algorithm model, and determine the model with the highest accuracy of user permission differentiation as the user similarity calculation model;
[0024] Among them, P is greater than or equal to 2 and less than or equal to the total number of training set users.
[0025] Optionally, the acquisition method of the user similarity calculation model is:
[0026] Use m target user sets for classifier training;
[0027] Use the test set data to verify the classifier, iterate and correct the algorithm model, and determine the model with the highest accuracy of user permission differentiation as the user similarity calculation model.
[0028] Optionally, for each user in each set of similar users, perform permission analysis to determine the optimal permission set for each user in the set of similar users, including:
[0029] Compare the permissions among the users in the same set of similar users;
[0030] Based on the principle of minimizing permissions, determine the optimal permission set for each user in each similar user set.
[0031] Further, the determining the optimal permission set for each user in each similar user set based on the principle of minimizing permissions includes:
[0032] Determine the intersection of all user permissions in the same similar user set as the optimal permission set for each user in the same similar user set.
[0033] Specifically, the optimal permission set is the permission of the user with the smallest permission set or the lowest permission level in the same similar user set.
[0034] Optionally, after performing permission analysis on each user in each similar user set to determine the optimal permission set for each user in the similar user set, it further includes:
[0035] Generate recommendation content for the optimal permission set of each user or each similar user set.
[0036] Specifically, the recommendation content includes at least one of the following:
[0037] Username;
[0038] User's current permissions;
[0039] User's optimal permissions;
[0040] Marking information on whether there is a difference between the user's current permissions and the user's optimal permissions;
[0041] Difference permission set between the user's current permissions and the user's optimal permissions.
[0042] An embodiment of the present invention further provides a user permission determination device, including:
[0043] An acquisition module, configured to divide multiple users to obtain at least one similar user set;
[0044] A determination module, configured to perform permission analysis on each user in each similar user set to determine the optimal permission set for each user in the similar user set.
[0045] An embodiment of the present invention further provides a user permission determination device, including a transceiver and a processor;
[0046] The processor is configured to:
[0047] Divide multiple users to obtain at least one similar user set;
[0048] Perform permission analysis on each user in each similar user set to determine the optimal permission set for each user in the similar user set.
[0049] An embodiment of the present invention also provides a user permission determination device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the above-mentioned user permission determination method is implemented.
[0050] An embodiment of the present invention also provides a computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, the steps in the above-mentioned user permission determination method are implemented.
[0051] The beneficial effects of the present invention are:
[0052] In the above solution, by dividing multiple users, at least one similar user set is obtained, and then permission analysis is performed on each user in each similar user set to determine the optimal permission set for each user in the similar user set, so as to ensure that the configured permission set is relatively accurate and reduce the workload of manual permission sorting. BRIEF DESCRIPTION OF THE DRAWINGS
[0053] Figure 1 A flowchart showing the user permission determination method according to an embodiment of the present invention;
[0054] Figure 2 A flowchart showing the process of obtaining a similar user set;
[0055] Figure 3 A schematic diagram showing one of the divisions of a similar user set;
[0056] Figure 4 A schematic diagram showing another division of a similar user set;
[0057] Figure 5 A flowchart showing the process of determining the optimal number of clusters;
[0058] Figure 6 A flowchart showing the process of determining the optimal clustering model;
[0059] Figure 7 A flowchart showing the process of obtaining the optimal permission set;
[0060] Figure 8 A flowchart showing the process of recommending the optimal permission set to the administrator;
[0061] Figure 9 A schematic diagram showing the overall architecture of an embodiment of the present invention;
[0062] Figure 10 A schematic diagram showing the modules of the user permission determination device according to an embodiment of the present invention. Detailed implementation manners
[0063] To make the objectives, technical solutions and advantages of the present invention clearer, the present invention will be described in detail below with reference to the accompanying drawings and specific embodiments.
[0064] In view of the problem that in the existing method for automatically configuring permissions, inaccurate configuration of the permission set will increase the workload of manual permission sorting, the present invention provides a method and device for determining user permissions.
[0065] As Figure 1 shown, the method for determining user permissions according to an embodiment of the present invention includes:
[0066] Step 11: Divide multiple users to obtain at least one set of similar users;
[0067] It should be noted that the permissions of users in the same set of similar users are the same or similar. This step is to divide multiple users to obtain one or more sets of similar users.
[0068] It should be noted that the users mentioned in the embodiments of the present invention can be users in the system or application programs.
[0069] Step 12: Perform permission analysis on each user in each set of similar users to determine the optimal permission set for each user in the set of similar users;
[0070] In the above steps, by first determining the set of similar users and then determining the optimal permission set for each set of similar users, the optimal permission set for each user in the set of similar users can be obtained. In this way, the accuracy of permission set configuration can be improved.
[0071] The following specifically describes the specific implementation manners of the embodiments of the present invention as follows.
[0072] Specifically, the implementation manner of Step 11 is as follows:
[0073] Step 111: Obtain the key features of each user and construct a user behavior feature library;
[0074] It should be noted that this step is to perform feature processing on users. Finally, each user is converted into a feature set or feature matrix to establish a user feature library.
[0075] It should be noted that the key features include: the identity features of the user and / or the historical operation behavior features of the user.
[0076] Furthermore, the identity features may be features that can characterize the user's identity, such as the user's job rank, department, business scope, channel information, regional information, IP address, etc.
[0077] Furthermore, the historical operation behavior characteristics of the user include at least one of the following:
[0078] A11. The data range involved in the access behavior;
[0079] For example: database, table, column, path, etc.
[0080] A12. The operation type involved in the access behavior;
[0081] For example: rwx, DQL, DML, DDL, DCL, etc.
[0082] A13. The data import / export behavior characteristics involved in the operation behavior;
[0083] A14. The operation behavior characteristics for system sensitive data;
[0084] A15. The characteristics reflecting the operation level;
[0085] It should be noted that this characteristic can be the operation behavior itself or the statistical value of one or more operation behaviors.
[0086] Step 112: According to the user behavior feature library, use the user similarity calculation model to obtain at least one set of similar users;
[0087] It should be noted that this step is based on the user behavior feature library and uses the user similarity calculation model to complete the classification or clustering process of users, and finally obtains one or more sets of similar users. The specific implementation process is as Figure 2 shown.
[0088] It should be noted that the user similarity calculation model is based on the user feature library, adopts a machine learning algorithm model, aims to minimize the difference permission set between similar users, trains the user similarity calculation model, and finally the result output by the user similarity calculation model is multiple sets of similar users. Each user in each set of similar users is called a similar user. For example, as Figure 3 shown, "User 1" and "User 2" in "Similar User Set 1" are similar users to each other, and their permissions should be the same or similar. As Figure 4 shown, "User 3", "User 4" and "User 5" in "Similar User Set 2" are similar users to each other, and their permissions should be the same or similar.
[0089] In the embodiments of the present invention, two ways to obtain the user similarity calculation model are provided, which are described separately as follows.
[0090] Method 1: Select at least one clustering algorithm to cluster the training set users into P clusters;
[0091] According to the clustering results, determine the optimal number of clusters n to obtain a clustering algorithm model;
[0092] Use the test set data to verify the clustering algorithm model, iterate and correct the algorithm model, and determine the model with the highest accuracy rate of user permission differentiation as the user similarity calculation model;
[0093] Where P is greater than or equal to 2 and less than or equal to the total number of users in the training set.
[0094] It should be noted that this method obtains a similarity calculation model through a clustering algorithm. When the administrator is not clear about how many types of permissions should exist in the system and what permissions each user should adopt, the clustering algorithm can be used to obtain a similarity calculation model.
[0095] The following is a specific description of this implementation method:
[0096] First step, initially select one or more clustering algorithms (such as kmeans, EM, etc.), and cluster the training set users into p clusters (p >= 2 and p <= the number of users k in the training set). According to the clustering results, determine the optimal number of clusters n (or the best number of clusters).
[0097] The specific process is as Figure 5 shown.
[0098] Second step, determine the similarity calculation model
[0099] Verify the clustering algorithm model obtained in the first step on the test set data, and cluster the test set users into n classes, that is, obtain n similar user sets.
[0100] Conduct permission analysis on the n similar user sets (which can be manually analyzed by the administrator). When the similar users in the clustered similar user sets should indeed have the same permissions and should have different permissions from the users in other similar user sets (which can be manually confirmed by the administrator), the differentiation of user permissions is achieved.
[0101] Iterate and correct the algorithm model, and select the model with the highest accuracy rate of user permission differentiation as the best clustering model and use it as the similarity calculation model; the specific process is as Figure 6 shown.
[0102] Method 2: Use m target user sets for classifier training; use the test set data to verify the classifier
[0103] Iterate and correct the algorithm model, and determine the model with the highest accuracy rate of user permission differentiation as the user similarity calculation model.
[0104] It should be noted that this method obtains a similarity calculation model through a classification algorithm. When the administrator has determined that there should actually be n types of users with different permissions in the system, but is not sure which category each user belongs to, the classification algorithm can be used.
[0105] The following is a specific description of this implementation method:
[0106] The first step is to train a classifier;
[0107] Prepare m (m > 1) target user sets, where it is known that the users in each user set have the same (or similar) permissions; the permissions of the users in each user set are different from those of the users in other user sets. Use these m user sets as classification targets to train the classifier.
[0108] The second step is to determine the similarity calculation model;
[0109] Verify the classifier on the test set data. When the classifier can assign the test set users to the user sets that match their expected permissions, the differentiation of user permissions is achieved. Iteratively correct the algorithm model. Finally, use the classifier with the highest accuracy in differentiating users as the similarity calculation model.
[0110] It should be further noted that after obtaining one or more similar user sets, it is necessary to determine the optimal permission set for each user in each similar user set. The specific implementation method is as follows:
[0111] Compare the permissions among the users in the same similar user set;
[0112] Based on the principle of minimizing permissions, determine the optimal permission set for each user in each similar user set.
[0113] Specifically, based on the principle of minimizing permissions, the specific implementation method for determining the optimal permission set for each user in each similar user set is: determine the intersection of the permissions of all users in the same similar user set as the optimal permission set for each user in the same similar user set.
[0114] Specifically, when there is a user whose permission set is the intersection of the permissions of all users in the same similar user set, then the optimal permission set for each user in the same similar user set is the permission set of this user, that is, the permission of the user with the smallest permission set or the lowest permission level is the optimal permission set for each user in the same similar user set. The specific process is as Figure 7 shown.
[0115] Take Figure 4Taking the similar user set 2 as an example, the specific process of obtaining the optimal permission set for each user in the same similar user set is as follows: First, compare the permissions of user 3, user 4, and user 5 to obtain the permission differences among the three users. If, in the "similar user set 2", the permission set of user 4 is the smallest (or the permission level is the lowest), then the current permission set of user 4 should be the optimal permission set for all users in the similar user set 2. That is, the permission set of user 4 is the optimal permission set for user 3 and user 5. It should be noted that when there is no user's permission set in the permission sets of user 3, user 4, and user 5 that is a subset of the permission sets of the other two users, the intersection of the three permission sets is used as the optimal permission set for all users in the similar user set 2.
[0116] It should also be noted that there is a special case here, that is, when there is no intersection of all users in the same similar user set, the intersection of the users' permission sets cannot be obtained. In this case, the optimal permission set for each user in this similar user set cannot be obtained, and the result of not obtaining the optimal permission set is obtained and pushed to the administrator.
[0117] Furthermore, it should be noted that in order to clearly facilitate the administrator to obtain the optimal permission set for each user, after step 12, the embodiments of the present invention further include: generating recommended content for the optimal permission set of each user or each similar user set.
[0118] The recommended content includes at least one of the following:
[0119] B11. User name;
[0120] B12. User's current permission;
[0121] B13. User's optimal permission;
[0122] B14. Marking information on whether there is a difference between the user's current permission and the user's optimal permission;
[0123] B15. Difference permission set between the user's current permission and the user's optimal permission.
[0124] Specifically, the administrator can obtain the recommended content through at least one of the following ways including but not limited to:
[0125] C11. Outputting documents such as reports and tables;
[0126] C12. Page display, when the administrator queries or selects a user on the system management page, a recommended display is performed;
[0127] C13. Outputting to a specified database, email, work order, etc.
[0128] Specifically, the implementation process of the optimal permission set recommendation is as Figure 8as shown
[0129] In summary, the embodiments of the present invention are mainly divided into an algorithm module, a permission analysis module, and a permission recommendation module in terms of realized functions. The overall architecture diagram is as Figure 9 shown. The algorithm module completes the training of the user similarity model to obtain a set of similar users; the permission analysis module analyzes and calculates the optimal permission set for each user based on the set of similar users obtained by the algorithm module; the permission recommendation module recommends the optimal permission set to the administrator.
[0130] It should be noted that the intelligent user permission determination method proposed in the embodiments of the present invention has the following advantages:
[0131] It can be realized only based on the user characteristics (user information, historical behaviors, etc.) in the system, regardless of the authorization model and authorization mechanism adopted by the system, and has strong versatility, being applicable to the permission sorting and recommendation of users in various systems;
[0132] It can intelligently sort out the permissions of users in the system, obtain the optimal permission set for each user (or each type of user), and recommend the optimal permission set of the user to the system administrator; it solves the problems such as the great difficulty and large workload in sorting out user permissions in the system, and the difficulty in judging whether the user permissions are too large, can effectively avoid the risk of data leakage caused by excessive user permissions, and reduce the system security threat.
[0133] As Figure 10 shown, the user permission determination device 100 of the embodiments of the present invention includes:
[0134] An acquisition module 101, configured to divide multiple users and acquire at least one set of similar users;
[0135] A determination module 102, configured to perform permission analysis on each user in each set of similar users to determine the optimal permission set for each user in the set of similar users.
[0136] Optionally, the acquisition module 101 includes:
[0137] A construction unit, configured to acquire the key features of each user and construct a user behavior feature library;
[0138] An acquisition unit, configured to acquire at least one set of similar users according to the user behavior feature library by using a user similarity calculation model;
[0139] Among them, the permissions of the users in each set of similar users are the same or similar.
[0140] Specifically, the key features include: the identity features of the user and / or the historical operation behavior features of the user.
[0141] Specifically, the historical operation behavior characteristics of the user include at least one of the following:
[0142] The data range involved in the access behavior;
[0143] The operation type involved in the access behavior;
[0144] The data import and export behavior characteristics involved in the operation behavior;
[0145] The operation behavior characteristics for the system sensitive data;
[0146] The characteristics reflecting the operation level.
[0147] Optionally, the acquisition method of the user similarity calculation model is as follows:
[0148] Select at least one clustering algorithm to cluster the training set users into P clusters;
[0149] According to the clustering result, determine the optimal number of clusters n to obtain the clustering algorithm model;
[0150] Use the test set data to verify the clustering algorithm model, iterate and correct the algorithm model, and determine the model with the highest accuracy rate of user permission differentiation as the user similarity calculation model;
[0151] Wherein, P is greater than or equal to 2 and less than or equal to the total number of training set users.
[0152] Optionally, the acquisition method of the user similarity calculation model is as follows:
[0153] Use m target user sets to train the classifier;
[0154] Use the test set data to verify the classifier, iterate and correct the algorithm model, and determine the model with the highest accuracy rate of user permission differentiation as the user similarity calculation model.
[0155] Optionally, the determination module 102 includes:
[0156] A comparison unit for comparing the permissions among users in the same similar user set;
[0157] A determination unit for determining the optimal permission set of each user in each similar user set based on the principle of minimizing permissions.
[0158] Specifically, the determination unit is used to implement:
[0159] Determine the intersection of all user permissions in the same similar user set as the optimal permission set of each user in the same similar user set.
[0160] Further, the optimal permission set is the permission of the user with the smallest permission set or the lowest permission level in the same similar user set.
[0161] Optionally, after the determining module 102 performs permission analysis on each user in each similar user set to determine the optimal permission set of each user in the similar user set, the method further includes:
[0162] A generating module, configured to generate recommendation content for the optimal permission set of each user or each similar user set.
[0163] Specifically, the recommendation content includes at least one of the following:
[0164] Username;
[0165] The current permissions of the user;
[0166] The optimal permissions of the user;
[0167] Marking information indicating whether there is a difference between the current permissions of the user and the optimal permissions of the user;
[0168] The set of different permissions between the current permissions of the user and the optimal permissions of the user.
[0169] It should be noted that the device provided in the embodiments of the present invention is a device capable of executing the above user permission determination method. Therefore, all implementation manners in the embodiments of the above user permission determination method are applicable to this device, and all can achieve the same or similar beneficial effects.
[0170] The embodiments of the present invention further provide a user permission determination device, including a transceiver and a processor;
[0171] The processor is configured to:
[0172] Divide multiple users to obtain at least one similar user set;
[0173] Perform permission analysis on each user in each similar user set to determine the optimal permission set of each user in the similar user set.
[0174] Optionally, when the processor executes the dividing of multiple users to obtain at least one similar user set, it is configured to:
[0175] Obtain the key features of each user and construct a user behavior feature library;
[0176] According to the user behavior feature library, use a user similarity calculation model to obtain at least one similar user set;
[0177] Wherein, the permissions of the users in each similar user set are the same or similar.
[0178] Specifically, the key features include: the identity features of the user and / or the historical operation behavior features of the user.
[0179] Specifically, the historical operation behavior features of the user include at least one of the following:
[0180] The data range involved in the access behavior;
[0181] The operation type involved in the access behavior;
[0182] The data import and export behavior features involved in the operation behavior;
[0183] The operation behavior features for the system sensitive data;
[0184] The features reflecting the operation level.
[0185] Optionally, when the processor executes to obtain the user similarity calculation model, the specific implementation is as follows:
[0186] Select at least one clustering algorithm to cluster the training set users into P clusters;
[0187] According to the clustering result, determine the optimal number of clusters n to obtain the clustering algorithm model;
[0188] Use the test set data to verify the clustering algorithm model, iterate and correct the algorithm model, and determine the model with the highest accuracy rate of user permission differentiation as the user similarity calculation model;
[0189] Wherein, P is greater than or equal to 2 and less than or equal to the total number of training set users.
[0190] Optionally, when the processor executes to obtain the user similarity calculation model, the specific implementation is as follows:
[0191] Use m target user sets for classifier training;
[0192] Use the test set data to verify the classifier, iterate and correct the algorithm model, and determine the model with the highest accuracy rate of user permission differentiation as the user similarity calculation model.
[0193] Optionally, when the processor executes to perform permission analysis on each user in each similar user set and determine the optimal permission set for each user in the similar user set, the implementation is as follows:
[0194] Compare the permissions among users in the same similar user set;
[0195] Based on the principle of minimizing permissions, determine the optimal permission set for each user in each similar user set.
[0196] Specifically, when the processor determines the optimal permission set for each user in each similar user set based on the principle of minimizing permissions, it is used to implement:
[0197] The intersection of all user permissions in the same similar user set is determined as the optimal permission set for each user in the same similar user set.
[0198] Furthermore, the optimal permission set is the permission of the user with the smallest permission set or the lowest permission level in the same similar user set.
[0199] Optionally, after the processor performs permission analysis on each user in each similar user set to determine the optimal permission set for each user in the similar user set, it is also used to implement:
[0200] Generate recommended content for the optimal permission set of each user or each similar user set.
[0201] Specifically, the recommended content includes at least one of the following:
[0202] Username;
[0203] User's current permissions;
[0204] User's optimal permissions;
[0205] Marking information on whether there is a difference between the user's current permissions and the user's optimal permissions;
[0206] The set of different permissions between the user's current permissions and the user's optimal permissions.
[0207] An embodiment of the present invention also provides a user permission determination device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements each process in the above-mentioned embodiment of the user permission determination method and can achieve the same technical effect. To avoid repetition, it will not be elaborated here.
[0208] An embodiment of the present invention also provides a computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, it implements each process in the above-mentioned embodiment of the user permission determination method and can achieve the same technical effect. To avoid repetition, it will not be elaborated here. Among them, the computer-readable storage medium is, for example, a read-only memory (Read-Only Memory, abbreviated as ROM), a random access memory (Random Access Memory, abbreviated as RAM), a magnetic disk, or an optical disc, etc.
[0209] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-readable storage media (including but not limited to disk storage and optical storage, etc.) that contain computer-usable program code.
[0210] The present application is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one or more of the processes or multiple processes and / or one or more of the blocks.
[0211] These computer program instructions can also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable storage medium generate a paper product including an instruction device, and the instruction device implements the functions specified in Figure 1 one or more of the processes or multiple processes and / or blocks Figure 1 one or more of the blocks.
[0212] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in Figure 1 one or more of the processes or multiple processes and / or blocks Figure 1 one or more of the blocks.
[0213] The above is the preferred embodiment of the present invention. It should be noted that for those of ordinary skill in the art, several improvements and refinements can be made without departing from the principle described in the present invention, and these improvements and refinements are also within the protection scope of the present invention.
Claims
1. A method for determining user permissions, characterized in that, it includes: Dividing multiple users to obtain at least one set of similar users; Performing permission analysis on each user in each set of similar users to determine the optimal permission set for each user in the set of similar users; Among them, the performing permission analysis on each user in each set of similar users to determine the optimal permission set for each user in the set of similar users includes: Comparing the permissions among users in the same set of similar users; Based on the principle of minimizing permissions, determining the optimal permission set for each user in each set of similar users; Among them, the based on the principle of minimizing permissions, determining the optimal permission set for each user in each set of similar users includes: Taking the intersection of the permissions of all users in the same set of similar users as the optimal permission set for each user in the same set of similar users; Among them, the dividing multiple users to obtain at least one set of similar users includes: Obtaining the key features of each user and constructing a user behavior feature library; According to the user behavior feature library, using a user similarity calculation model to obtain at least one set of similar users; where the permissions of users in each set of similar users are the same or similar; Among them, the way to obtain the user similarity calculation model is: Selecting at least one clustering algorithm to cluster the training set users into P clusters; where P is greater than or equal to 2 and less than or equal to the total number of training set users; According to the clustering result, determining the optimal number of clusters n to obtain a clustering algorithm model; Using the test set data to verify the clustering algorithm model, iteratively modifying the algorithm model, and determining the model with the highest accuracy in distinguishing user permissions as the user similarity calculation model; Among them, the way to obtain the user similarity calculation model is: Using m target user sets for classifier training; Using the test set data to verify the classifier, iteratively modifying the algorithm model, and determining the model with the highest accuracy in distinguishing user permissions as the user similarity calculation model.
2. The method for determining user permissions according to claim 1, characterized in that, the key features include: the identity features of the user and / or the historical operation behavior features of the user.
3. The method for determining user permissions according to claim 2, characterized in that, the historical operation behavior features of the user include at least one of the following: The data range involved in the access behavior; The operation type involved in the access behavior; The data import / export behavior features involved in the operation behavior; The operation behavior features for system sensitive data; The features reflecting the operation level.
4. The method for determining user permissions according to claim 1, characterized in that, the optimal permission set is the permission of the user with the smallest permission set or the lowest permission level in the same set of similar users.
5. The method for determining user permissions according to claim 1, characterized in that, after the performing permission analysis on each user in each set of similar users to determine the optimal permission set for each user in the set of similar users, it further includes: Generating recommended content for the optimal permission set of each user or each set of similar users.
6. The method for determining user permissions according to claim 5, It is characterized in that the recommended content includes at least one of the following: username; the current user permission; the optimal permission of the user; marking information on whether there is a difference between the current user permission and the optimal permission of the user; the set of different permissions between the current user permission and the optimal permission of the user.
7. A user permission determination device It is characterized in that it includes: an acquisition module, configured to divide multiple users and acquire at least one set of similar users; a determination module, configured to perform permission analysis on each user in each set of similar users to determine the optimal permission set of each user in the set of similar users; wherein, the determination module includes: a comparison unit, configured to compare the permissions between users in the same set of similar users; a determination unit, configured to determine the optimal permission set of each user in each set of similar users based on the principle of minimizing permissions; wherein, the determination unit is configured to implement: determining the intersection of all user permissions in the same set of similar users as the optimal permission set of each user in the same set of similar users; wherein, the acquisition module includes: a construction unit, configured to acquire the key features of each user and construct a user behavior feature library; an acquisition unit, configured to acquire at least one set of similar users according to the user behavior feature library by using a user similarity calculation model; wherein, the permissions of users in each set of similar users are the same or similar; wherein, the acquisition method of the user similarity calculation model is: selecting at least one clustering algorithm to cluster the training set users into P clusters; where P is greater than or equal to 2 and less than or equal to the total number of training set users; determining the optimal number of clusters n according to the clustering result to obtain a clustering algorithm model; validating the clustering algorithm model by using the test set data, iteratively correcting the algorithm model, and determining the model with the highest accuracy of differentiating user permissions as the user similarity calculation model; wherein, the acquisition method of the user similarity calculation model is: using m target user sets for classifier training; validating the classifier by using the test set data, iteratively correcting the algorithm model, and determining the model with the highest accuracy of differentiating user permissions as the user similarity calculation model.
8. A user permission determination device It is characterized in that it includes a transceiver and a processor; the processor is configured to: divide multiple users and acquire at least one set of similar users; perform permission analysis on each user in each set of similar users to determine the optimal permission set of each user in the set of similar users; wherein, when the processor performs permission analysis on each user in each set of similar users to determine the optimal permission set of each user in the set of similar users, it is configured to implement: compare the permissions between users in the same set of similar users; determine the optimal permission set of each user in each set of similar users based on the principle of minimizing permissions; specifically, when the processor determines the optimal permission set of each user in each set of similar users based on the principle of minimizing permissions, it is configured to implement: determine the intersection of all user permissions in the same set of similar users as the optimal permission set of each user in the same set of similar users; When the processor executes the division of multiple users to obtain at least one set of similar users, it is used to implement: Obtain the key features of each user and construct a user behavior feature library; According to the user behavior feature library, use the user similarity calculation model to obtain at least one set of similar users; wherein, the permissions of the users in each set of similar users are the same or similar; Wherein, when the processor executes the acquisition of the user similarity calculation model, the specific implementation is: Select at least one clustering algorithm to cluster the training set users into P clusters; wherein, P is greater than or equal to 2 and less than or equal to the total number of training set users; According to the clustering result, determine the optimal number of clusters n to obtain a clustering algorithm model; Use the test set data to verify the clustering algorithm model, iterate and correct the algorithm model, and determine the model with the highest accuracy of user permission differentiation as the user similarity calculation model; Wherein, when the processor executes the acquisition of the user similarity calculation model, the specific implementation is: Use m target user sets for classifier training; Use the test set data to verify the classifier, iterate and correct the algorithm model, and determine the model with the highest accuracy of user permission differentiation as the user similarity calculation model.
9. A user permission determination device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the user permission determination method according to any one of claims 1-6.
10. A computer-readable storage medium, on which a computer program is stored, characterized in that, When the program is executed by the processor, it implements the steps in the user permission determination method according to any one of claims 1-6.
Citation Information
Patent Citations
User authority management method and device, electronic device and readable storage medium
CN109815685A