A method and system for reconstructing permissions of enterprise-level information systems

By sorting out the relationships between enterprise positions and personnel and information system permissions, and using the K-means algorithm to generate the optimal permission set and verify it, the problem of inconsistent information system permissions in group enterprises is solved, and automated permission management and scientific permission governance are achieved.

CN114491492BActive Publication Date: 2025-09-09INFORMATION CENT OF YUNNAN POWER GRID CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111502088.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-09
Publication Date
2025-09-09
Estimated Expiration
2041-12-09

AI Technical Summary

Technical Problem

In group enterprises, the information system authority systems of various business departments are not unified, resulting in heavy operation and maintenance workload, high security risks, and difficulty in ensuring compliance with role permissions.

Method used

By sorting out the standardized human resources job settings within the enterprise, forming a standard relationship database of job positions and personnel, automatically matching information system permission configuration information, using the K-means algorithm for cluster analysis, generating the optimal permission set, and performing permission rationality verification, it automatically generates a permission reconstruction analysis report.

Benefits of technology

It realizes the automated verification and scientific management of enterprise-level information system permissions, reduces the operation and maintenance workload, improves the rationality and security of permission configuration, and supports dynamic permission governance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure FT_1
    Figure FT_1
  • Figure FT_2
    Figure FT_2
Patent Text Reader

Abstract

The present invention relates to a method and system for reconstructing the authority of an enterprise-level information system. The method is based on establishing a standard relationship database for enterprise position personnel and a service pool for full extraction and information deconstruction of enterprise-level information system authority configuration information. The method automatically matches and starts services according to the enterprise name, extracts information related to information system authority configuration in full from the enterprise-level information system, and automatically deconstructs the authority configuration information. This triggers the start of an optimal authority self-identification algorithm for position personnel and a rationality verification algorithm for position personnel authority in an enterprise-level information system authority reconstruction analysis model. Based on enterprise-level information system authority reconstruction analysis result report generation rules and templates, an enterprise-level information system authority reconstruction analysis result report is automatically generated, providing a scientific reference basis for enterprise-level information system authority review and authority governance. The method assists in the automated review of the enterprise-level information system authority system, effectively solving the problem of the inconsistency of the existing enterprise information system authority system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of information management, and in particular relates to a method and system for reconstructing permissions of an enterprise-level information system. Background Art

[0002] In group enterprises, each business department has built a large number of information systems. These information systems are complex and mutually coordinated. Since the system construction is not based on a unified development platform, the authority system of each information system is not unified. This will lead to inconsistent and diverse authority management of different information systems, increasing the investment in operation and maintenance.

[0003] The overly complex configuration of roles and processes has caused three major problems. First, there is no direct correlation between personnel permissions and positions. One position requires multiple roles to be configured to meet the requirements. Many users have more than 50 roles. There is no clear reference for grassroots employees to apply for role permissions, and the workload of operation and maintenance personnel in allocating role permissions is large; second, the permissions of personnel in the same position are not unified, and the compliance of personnel permissions is poor, resulting in high business security and audit risks; third, there is a lack of a role permission verification model. The rationality of newly applied roles mainly relies on manual review, which requires a large workload and makes it difficult to ensure the compliance of role applications. Summary of the Invention

[0004] In order to overcome the problems existing in the background technology, the present invention provides a method and system for reconstructing enterprise-level information system permissions, which assists in the automated review of the enterprise-level information system permission system and effectively solves the problem of inconsistent permission systems in existing enterprise information systems.

[0005] To achieve the above object, the present invention is implemented through the following technical solutions:

[0006] The method for reconstructing permissions of an enterprise-level information system includes:

[0007] Obtaining enterprise personnel position information, wherein the personnel position information includes position-personnel relationships, forming enterprise position-personnel standard relationship data, and forming an enterprise position-personnel standard relationship database;

[0008] Obtain enterprise-level information system permission configuration information; the enterprise-level information system permission configuration information includes role-function relationship, process-role relationship, and personnel-role relationship, forming a full-scale extraction and information deconstruction service pool for enterprise-level information system permission configuration information.

[0009] The method for reconstructing permissions of an enterprise-level information system comprises the following steps:

[0010] S1. Sort out the standardized HR job settings within the enterprise, sort out the job-personnel relationships, form a job-personnel correspondence table, and import it into the system to generate the enterprise job-personnel standard relationship database;

[0011] S2. Based on the enterprise-level system name, automatically match and call the enterprise-level information system permission configuration information full extraction and information deconstruction service pool through scheduled or unscheduled tasks to fully extract the role function relationship, process role relationship, and personnel role relationship in the specified enterprise-level information system;

[0012] S3. Based on the full extraction of enterprise-level information system authority configuration information and the deconstruction service in the information deconstruction service pool, the extracted role-function relationship, process-role relationship, and personnel-role relationship are structured to generate an enterprise-level information system position authority relationship standard configuration library and the current system personnel authority configuration information;

[0013] S4. Triggering the start of the optimal self-identification algorithm for position personnel permissions in the enterprise-level information system permission reconstruction analysis model, automatically identifying and generating the optimal set of enterprise-level information system permission configurations for each position personnel based on the position personnel standard relationship database;

[0014] S5. Triggering and starting the personnel authority rationality verification algorithm in the enterprise-level information system authority reconstruction analysis model to automatically verify the rationality of the current enterprise-level information system personnel authority configuration and generate a verification result;

[0015] S6. Based on the enterprise-level information system permission reconstruction analysis result report generation rules and templates, the system automatically generates an enterprise-level information system permission reconstruction analysis result report, providing a scientific reference basis for enterprise-level information system permission review and permission governance.

[0016] Furthermore, the enterprise-level information system authority reconstruction analysis model described in step S4 is used to automatically identify and generate the optimal set of enterprise-level information system authority configurations for personnel in various positions, and automatically verify the rationality of the authority configurations of various personnel in the current enterprise-level information system, and output the verification results.

[0017] Furthermore, the enterprise-level information system permission reconstruction model is configured with a standardized service pool for extracting and deconstructing the full amount of enterprise-level information system permission configuration information. The services in the service pool are configured in accordance with JAVA specifications and are adaptable to standard interfaces for connecting to data exchange between different enterprise-level information systems. The model periodically or irregularly obtains data such as role-function relationships and process-role relationships within the enterprise-level information system. The role-function relationship data includes at least role ID, role name, function ID, and function name; and the process-role data includes at least process ID, process version, process name, link ID, link name, and role ID.

[0018] Furthermore, the enterprise-level information system permission reconstruction analysis model includes an optimal permission self-identification algorithm for job positions and an algorithm for verifying the rationality of personnel permissions. The current system personnel permission configuration information is the input of the model, and the output of the model is the optimal set of enterprise-level information system permission configurations for each position and the verification results of the rationality of personnel permission configurations.

[0019] Furthermore, the optimal permissions self-identification algorithm for job positions in the enterprise-level information system permissions reconstruction analysis model is integrated with the K-means algorithm. The enterprise job position standard relationship database and the standard configuration database of each enterprise-level information system job permission relationship are used as input for cluster analysis, and the optimal set of enterprise-level information system permission configurations for each job position is output.

[0020] Furthermore, the job personnel authority rationality verification algorithm in the enterprise-level information system authority reconstruction analysis model is constructed in the form of a verification rule set, which includes mutually exclusive verification rules, super-large authority verification rules, sensitive authority verification rules, and authority rationality verification rules. The algorithm input is the enterprise job personnel standard relationship library, the standard configuration library of job authority relationships of each enterprise-level information system, and the current system personnel authority configuration information, and the output is the rationality verification result of the current system personnel authority configuration.

[0021] Beneficial effects of the present invention:

[0022] The present invention can automatically verify and analyze the rationality and scientificity of the enterprise-level information system personnel authority configuration, provide more scientific auxiliary data support for the enterprise-level information system authority management, and when personnel positions change, it is only necessary to update the position-personnel standard relationship library without large-scale adjustment of the model to meet the personnel authority reconstruction analysis needs, which can effectively adapt to the needs of dynamic review, management and control of enterprise-level information system permissions, and assist in promoting the improvement of quality and efficiency of enterprise-level information system authority review and management work. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] Figure 1 It is a schematic diagram of the process of the present invention.

[0024] Figure 2 This is a schematic diagram of the present invention. DETAILED DESCRIPTION

[0025] In order to make the purpose, technical solutions and beneficial effects of the present invention clearer, the preferred embodiments of the present invention will be described in detail below to facilitate understanding by technicians.

[0026] Reference Figure 1 The workflow diagram shown in the figure is combined with Figure 2System implementation principle diagram, the present invention provides a method for reconstructing the permissions of an enterprise-level information system, which is applied to the reconstruction of the permissions of an enterprise-level information system. The system includes: a unified permission interface, a permission reconstruction model, an optimal permission identification component, and a position permission verification component.

[0027] The method comprises the following steps:

[0028] Step S1: sort out the standardized human resources job settings within the enterprise, sort out the job-personnel relationships, form a job-personnel correspondence table, and import it into the system to generate a job-personnel standard relationship library.

[0029] In this step, combined with the characteristics of group enterprises, the human resources job settings at the provincial, municipal, district and county levels are sorted out. The job information includes: job ID, organizational level, department name, job title, personnel ID, and personnel name.

[0030] Step S2, based on the enterprise-level system name, automatically matches and calls the extraction service in the enterprise-level information system permission configuration information full extraction and information deconstruction service pool through scheduled or irregular tasks, and fully extracts the role function relationship, process role relationship, and personnel role relationship in the specified enterprise-level information system.

[0031] In this step, the system architecture information is as follows:

[0032] Front-end framework: Use vue technology to implement the client interface, vue-router for routing, vuex for state management, axios for sending network requests, and echarts for drawing front-end charts.

[0033] Backend service: SpringBoot builds a single microservice and adopts Netflix's eureka registration center and gateway to implement the microservice architecture. The scheduled task platform uses the distributed scheduled task scheduling platform XXL-JOB for asynchronous scheduling. The data access layer uses mybatis-plus for object-relational mapping. The service security implementation uses the SpringSecurity framework for security authentication.

[0034] Desktop client: A winform application developed based on .net-core, with Google browser CEF and selenium webdriver embedded for automation.

[0035] Establish a service pool for the complete extraction and deconstruction of enterprise-level information system permission configuration information. The services in the service pool follow Java specifications and can adapt to standard interfaces for data exchange between different enterprise-level information systems. This allows for regular or irregular acquisition of data such as role-function relationships and process-role relationships within enterprise-level information systems. Role-function relationship data includes at least role ID, role name, function ID, and function name; process-role data includes at least process ID, process version, process name, link ID, link name, and role ID.

[0036] Step S3, based on the full extraction of enterprise-level information system authority configuration information and the deconstruction service in the information deconstruction service pool, the extracted role function relationship, process role relationship, and personnel role relationship are structured to generate an enterprise-level information system position authority relationship standard configuration library and the current system personnel authority configuration information.

[0037] In this step, based on the extracted system role function relationship, process role relationship and other data, and based on the format requirements of the input data of the optimal authority self-identification algorithm for job positions in the enterprise-level information system authority reconstruction analysis model, the corresponding enterprise-level information system job authority relationship standard configuration library table and the current system personnel authority configuration information table are created in the database, and the role function relationship data, process role relationship data, personnel role relationship data, etc. obtained in step S2 are split and deconstructed based on the data table format to form unified and standard deconstructed data and written into the database table.

[0038] Step S4 triggers the self-identification algorithm for optimal permissions of job positions in the enterprise-level information system permission reconstruction analysis model, and automatically identifies and generates the optimal set of enterprise-level information system permission configurations for each job position based on the job position standard relationship database.

[0039] In this step, the K-means algorithm is integrated for cluster analysis. K-means is an unsupervised learning method that classifies unlabeled data (that is, data without defined categories or groups). The goal of this algorithm is to find groups in the data, labeled by a variable K. The algorithm works iteratively, assigning each data point to one of K groups based on the provided features. Data points are clustered based on feature similarity.

[0040] In this step, the optimal authority self-identification algorithm for job personnel is integrated with the K-means algorithm for cluster analysis. The objects of analysis are mainly divided into two categories. One is cluster analysis of role-function relationship, which associates the personnel IDs in the sorted HR positions with the personnel IDs in the original business system, and groups the personnel in the same position; the optimal authority self-identification algorithm for job personnel performs K-means cluster analysis on the same function under the same position, and for each point in the data set and each centroid, calculates the distance between the centroid and the data point, and assigns the data point to the cluster closest to it. For each cluster, calculates the mean of all points in the cluster and uses the mean as the centroid to obtain the optimal function setting for each position; the other category is clustering of process role relationship, and the clustering principle is the same as the first category.

[0041] Step S5: trigger and start the post personnel authority rationality verification algorithm in the enterprise-level information system authority reconstruction analysis model, automatically verify the rationality of the current enterprise-level information system personnel authority configuration and generate a verification result

[0042] In this step, the job personnel authority rationality verification algorithm is mainly constructed in the form of a verification rule set, which includes mutually exclusive verification rules, super-large authority verification rules, sensitive authority verification rules, authority rationality verification rules, etc. The algorithm input is the enterprise job personnel standard relationship library, the job authority relationship standard configuration library of each enterprise-level information system and the current system personnel authority configuration information, and the output is the rationality verification result of the current system personnel authority configuration.

[0043] In step S6, the system automatically generates an enterprise-level information system authority reconstruction analysis result report, providing a scientific reference basis for enterprise-level information system authority review and authority governance.

[0044] In this step, the enterprise-level information system permission reconstruction analysis result report generation rules and templates are applied. The generation rules clearly define the report content data range, report content speech template library, report content generation process and other information extracted from the analysis report, and automatically complete the filling of the analysis report content based on the given analysis report template format to generate an enterprise-level information system permission reconstruction analysis result report.

[0045] The present invention provides a method and system for reconstructing enterprise-level information system permissions through steps S1 to S6, which can automatically verify and analyze the rationality and scientificity of the permission configuration of enterprise-level information system personnel, provide more scientific auxiliary data support for enterprise-level information system permission management, and when personnel positions change, it is only necessary to update the position-personnel standard relationship library without large-scale adjustment of the model to meet the personnel permission reconstruction analysis needs, and can effectively adapt to the needs of dynamic review, management, and control of enterprise-level information system permissions, and assist in promoting the improvement of quality and efficiency of enterprise-level information system permission review and management work.

[0046] Reference Figure 2 The system implementation schematic diagram shows an application scenario. The system includes: an enterprise-level information system permission configuration information full extraction and information deconstruction service pool 10, an enterprise-level information system permission reconstruction analysis model 20, an optimal position and personnel permission self-identification algorithm 30, a position and personnel permission rationality verification algorithm 40, and an enterprise-level information system permission reconstruction analysis result report 50. The optimal position and personnel permission self-identification algorithm 30 and the position and personnel permission rationality verification algorithm 40 together constitute the enterprise-level information system permission reconstruction analysis model 20. The enterprise-level information system permission configuration information full extraction and information deconstruction service pool 10 serves as a data exchange link between the existing enterprise-level information system and the enterprise-level information system permission reconstruction system, providing input data support for the enterprise-level information system permission reconstruction analysis model 20. The optimal position and personnel permission self-identification algorithm 30 provides input data for the position and personnel permission rationality verification algorithm 40. The output data of the enterprise-level information system permission reconstruction analysis model 20 will be uniformly written into the enterprise-level information system permission reconstruction analysis result report 50 as the content of the enterprise-level information system permission reconstruction analysis result report.

[0047] Those skilled in the art will clearly understand that the techniques in the embodiments of the present invention can be implemented using software and a necessary general-purpose hardware platform. Based on this understanding, the technical solutions in the embodiments of the present invention, or the portion that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a storage medium such as ROM / RAM, a magnetic disk, or an optical disk, and includes instructions for enabling a computer device (such as a personal computer, server, or network device) to execute the methods described in various embodiments of the present invention, or portions thereof.

[0048] In this specification, the same or similar parts between the various embodiments can be referred to each other. In particular, for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the description in the method embodiment.

[0049] The present invention has been described in detail above with reference to specific embodiments and exemplary examples. However, these descriptions should not be construed as limiting the present invention. Those skilled in the art will appreciate that various equivalent substitutions, modifications, or improvements may be made to the technical solutions and implementations of the present invention without departing from the spirit and scope of the present invention, all of which fall within the scope of the present invention. The scope of protection of the present invention shall be determined by the appended claims.

[0050] Finally, it should be noted that the above preferred embodiments are only used to illustrate the technical solutions of the present invention and are not limiting. Although the present invention has been described in detail through the above preferred embodiments, those skilled in the art should understand that various changes can be made in form and details without departing from the scope defined by the claims of the present invention.

Claims

1. A method for reconstructing permissions of an enterprise-level information system, characterized in that: include: Obtain enterprise personnel position information, including position-personnel relationships, to form enterprise position-personnel standard relationship data and an enterprise position-personnel standard relationship database; obtain enterprise-level information system permission configuration information; the enterprise-level information system permission configuration information includes role-function relationships, process-role relationships, and personnel-role relationships, to form a full-scale extraction and information deconstruction service pool for enterprise-level information system permission configuration information; The method comprises the following steps: S1. Sort out the standardized HR job settings within the enterprise, sort out the job-personnel relationships, form a job-personnel correspondence table, and import it into the system to generate the enterprise job-personnel standard relationship database; S2. Based on the enterprise-level system name, automatically match and call the enterprise-level information system permission configuration information full extraction and information deconstruction service pool through scheduled or unscheduled tasks to fully extract the role function relationship, process role relationship, and personnel role relationship in the specified enterprise-level information system; S3. Based on the full extraction of enterprise-level information system authority configuration information and the deconstruction service in the information deconstruction service pool, the extracted role-function relationship, process-role relationship, and personnel-role relationship are structured to generate an enterprise-level information system position authority relationship standard configuration library and the current system personnel authority configuration information; S4. Triggering the start of the optimal self-identification algorithm for position personnel permissions in the enterprise-level information system permission reconstruction analysis model, automatically identifying and generating the optimal set of enterprise-level information system permission configurations for each position personnel based on the position personnel standard relationship database; S5. Triggering and starting the personnel authority rationality verification algorithm in the enterprise-level information system authority reconstruction analysis model to automatically verify the rationality of the current enterprise-level information system personnel authority configuration and generate a verification result; S6. Based on the enterprise-level information system authority reconstruction analysis result report generation rules and templates, the system automatically generates an enterprise-level information system authority reconstruction analysis result report, providing a scientific reference basis for enterprise-level information system authority review and authority governance; The enterprise-level information system authority reconstruction analysis model described in step S4 is used to automatically identify and generate the optimal set of enterprise-level information system authority configurations for personnel in various positions, and automatically verify the rationality of the authority configurations of various personnel in the current enterprise-level information system, and output the verification results; The enterprise-level information system authority reconstruction model sets up a standardized enterprise-level information system authority configuration information full-volume extraction and information deconstruction service pool. The services in the service pool follow the JAVA specification settings and can adapt to the standard interface for connecting to different enterprise-level information systems for data exchange. It can obtain data such as role-function relationships, process-role relationships, etc. of the enterprise-level information system on a regular or irregular basis. The role-function relationship data includes at least the role ID, role name, function ID, and function name; the process role data includes at least the process ID, process version, process name, link ID, link name, and role ID; The enterprise-level information system authority reconstruction analysis model includes an optimal authority self-identification algorithm for job personnel and an algorithm for verifying the rationality of job personnel authority. The current system personnel authority configuration information is the input of the model, and the output of the model is the optimal set of enterprise-level information system authority configurations for each position personnel and the rationality verification results of personnel authority configurations. The job personnel authority rationality verification algorithm in the enterprise-level information system authority reconstruction analysis model is constructed in the form of a verification rule set, which includes mutually exclusive verification rules, super-large authority verification rules, sensitive authority verification rules, and authority rationality verification rules. The algorithm input is the enterprise job personnel standard relationship library, the standard configuration library of job authority relationships of each enterprise-level information system, and the current system personnel authority configuration information, and the output is the rationality verification result of the current system personnel authority configuration.

2. The method for reconstructing permissions of an enterprise-level information system according to claim 1, characterized in that: The optimal permissions self-identification algorithm for job positions in the enterprise-level information system permissions reconstruction analysis model is integrated with the K-means algorithm. It uses the enterprise job position standard relationship database and the standard configuration database of each enterprise-level information system's job permissions as input to perform cluster analysis and output the optimal set of enterprise-level information system permissions configuration for each job position.

3. A permission reconstruction system for enterprise-level information systems obtained using the method described in claim 1 or 2.

Citation Information

Patent Citations

  • Service permission recommendation method and device

    CN110825929A

  • User permission determination method and device

    CN112989402A