A method, apparatus and device for renewing a service permission

CN115271640BActive Publication Date: 2026-09-25ANT SHENGXIN (SHANGHAI) INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210798830.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2019-12-27
Publication Date
2026-09-25
Estimated Expiration
2039-12-27

AI Technical Summary

Technical Problem

[0005]本说明书实施例提供一种业务权限的续签方法、装置以及设备,用于解决以下技术问题:业务权限续签过程中,操作繁琐的问题

Benefits of technology

[0023]本说明书实施例基于用户与用户权限紧密程度的特征数据,利用预先获得的业务权限模型,实现待续签业务的自动续签,能够减少业务权限系统对用户及权限管理者的干扰,提升工作效率。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115271640B_ABST
    Figure CN115271640B_ABST
Patent Text Reader

Abstract

The embodiment of the specification discloses a business authority renewal method, device and equipment. The method comprises the following steps: obtaining business authority data of a user to be renewed; obtaining an evaluation result of the user to be renewed based on the business authority data and a business authority model, wherein the evaluation result is the closeness of the user to be renewed to the business authority, and the business authority model is based on feature data of the relationship between the user and the business authority and a pre-obtained model; and renewing the business authority of the user to be renewed based on the evaluation result. The business authority renewal method provided by the embodiment of the specification can realize automatic renewal of the business authority, reduce the interference of the business authority system on the user and the authority manager, and improve the work efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This specification relates to the field of computer technology, and in particular to a method, apparatus, and device for renewing business permissions. Background Technology

[0002] With the development of the Internet, in companies or organizations with access control systems, in order to restrict users and / or user groups from accessing certain information items or from using certain functions, it is necessary to set different business permissions for different users and / or user groups to achieve access control for different businesses.

[0003] Currently, the common practice is for users to submit business permission applications, which then undergo approval processes such as supervisor review and authorization by the permission administrator before granting the corresponding business permissions. Since user and / or user group business permissions often have an expiration date, users need to resubmit their business permission applications before these expire to regain them. This business permission renewal method requires users to reapply, making the process cumbersome.

[0004] Therefore, in order to reduce the cumbersome operation during the renewal of business permissions, a more convenient and efficient method for renewing business permissions is needed. Summary of the Invention

[0005] This specification provides a method, apparatus, and device for renewing business permissions, which addresses the following technical problem: the cumbersome operation during the business permission renewal process.

[0006] To solve the above-mentioned technical problems, the embodiments in this specification are implemented as follows:

[0007] This specification provides an embodiment of a method for renewing business permissions, including:

[0008] Obtain the business permission data of users whose business permissions are pending renewal;

[0009] Based on the business permission data, and according to the business permission model, the evaluation result of the user whose business permission is to be renewed is obtained. The evaluation result is the degree of closeness between the user whose business permission is to be renewed and the business permission to be renewed. The business permission model is a model obtained in advance based on the feature data of the relationship between the user and the business permission.

[0010] Based on the evaluation results, the business permissions of the users whose business permissions are pending renewal are renewed.

[0011] This specification provides an embodiment of a business permission renewal device, comprising:

[0012] The module retrieves the business permission data of users whose business permissions are to be renewed.

[0013] The evaluation module, based on the business permission data and according to the business permission model, obtains the evaluation result of the user whose business permission is to be renewed. The evaluation result represents the closeness between the user whose business permission is to be renewed and the business permission to be renewed. The business permission model is a model obtained in advance based on the feature data of the relationship between the user and the business permission.

[0014] The renewal module renews the business permissions of the users whose business permissions are pending renewal based on the evaluation results.

[0015] An electronic device provided in the embodiments of this specification includes:

[0016] At least one processor; and,

[0017] A memory communicatively connected to the at least one processor; wherein,

[0018] The memory stores instructions executable by the at least one processor, which, when executed by the at least one processor, enable the at least one processor to:

[0019] Obtain the business permission data of users whose business permissions are pending renewal;

[0020] Based on the business permission data, and according to the business permission model, the evaluation result of the user whose business permission is to be renewed is obtained. The evaluation result is the degree of closeness between the user whose business permission is to be renewed and the business permission to be renewed. The business permission model is a model obtained in advance based on the feature data of the relationship between the user and the business permission.

[0021] Based on the evaluation results, the business permissions of the users whose business permissions are pending renewal are renewed.

[0022] The above-described at least one technical solution adopted in the embodiments of this specification can achieve the following beneficial effects:

[0023] The embodiments in this specification are based on the characteristic data of the closeness between users and user permissions. By using a pre-obtained business permission model, the automatic renewal of services to be renewed can be realized, which can reduce the interference of the business permission system on users and permission managers and improve work efficiency. Attached Figure Description

[0024] To more clearly illustrate the technical solutions in the embodiments or prior art of this specification, the drawings used in the description of the embodiments or prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0025] Figure 1 This is a schematic diagram of the existing technology for applying for and renewing business permissions.

[0026] Figure 2 A framework diagram of a business permission renewal method provided in the embodiments of this specification;

[0027] Figure 3 The construction principle of the business permission model provided in the embodiments of this specification;

[0028] Figure 4 A schematic diagram illustrating the application and renewal of business permissions as provided in the embodiments of this specification;

[0029] Figure 5 This is a schematic diagram of a business permission renewal device provided in an embodiment of this specification. Detailed Implementation

[0030] To enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this specification, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of this application.

[0031] In companies or organizations with access control systems, different business permissions need to be set for different users and / or user groups in order to implement access control for different business functions. Figure 1This diagram illustrates the existing process for applying for and renewing business permissions. When applying for new business permissions, the user submits an application, which undergoes approval by the supervisor and allocation of permissions by the permissions administrator, thus granting the user the corresponding permissions. The permissions administrator's allocation of permissions involves a secondary approval process based on the supervisor's initial approval, followed by direct allocation of permissions by the permissions administrator. Before a business permission expires, the user receives an email or system reminder that it is about to expire. The user decides whether to renew the business permission based on their specific needs. If renewal is required, the user submits a renewal application, which undergoes supervisor approval and permissions allocation by the permissions administrator, thus renewing the business permission.

[0032] The current technology for renewing business permissions is not suitable for situations with a large number of users. If the expiration reminder for a certain business permission in a certain year involves thousands of employees, each employee needs to apply for the permission more than twice on average. Therefore, the number of work orders for the corresponding business permission application and approval is large, and the approval process for employees, supervisors and permission managers is cumbersome, with a large workload and low efficiency.

[0033] To address the problems in business permission renewal in the prior art, this specification provides a business permission renewal method that is convenient and efficient.

[0034] Figure 2 This is a framework diagram of a business permission renewal method provided in the embodiments of this specification. Specifically, it includes:

[0035] Step S201: Obtain the business permission data of the user whose business permission is to be renewed.

[0036] In the embodiments of this specification, the user whose service permission is to be renewed is the user or corresponding user of the service that is about to expire within a preset period. The preset period is the period for reminding the user of the service expiration. It is a period set manually based on the characteristics of the service permission itself and / or the usage habits of the permission administrator. The preset period can be 1 month, 15 days, or 1 week. The length of the preset period does not constitute a limitation of this specification.

[0037] In the embodiments described in this specification, the business permissions to be renewed refer to a user's access permissions to the business system and / or a user's access permissions to reports. Specifically, a user's access permissions to the business system mean that the user and / or user group have access permissions to all platforms within their company or organization. A user's access permissions to reports mean that the user and / or user group have granular access permissions to each report on the reporting platform within their company or / or organization.

[0038] In the embodiments of this specification, the business permission data of the user whose business permission is to be renewed is the relevant business permission data of the user during a preset data collection period. This business permission data includes the business permission data to be renewed, and may also include other business permissions used by the user. The preset data collection period can be 3 months, 6 months, or 9 months, and the length of the preset data collection period does not constitute a limitation of this specification. It should be noted that the preset data collection period should be shorter than the total time the user uses the business permission to be renewed.

[0039] In the embodiments described in this specification, the obtained business permission data is the corresponding business permission data obtained after the user whose business permission is to be renewed receives the expiration reminder. The obtained business permission data can also be the corresponding business permission data obtained before the business permission expires. The timing and method of obtaining business permission data before the expiration of business permission do not constitute a limitation of this specification.

[0040] Step S203: Based on the business permission data, according to the business permission model, obtain the evaluation result of the user whose business permission is to be renewed, wherein the evaluation result is the degree of closeness between the user whose business permission is to be renewed and the business permission to be renewed, and the business permission model is a model obtained in advance based on the feature data of the relationship between the user and the business permission.

[0041] In this embodiment of the specification, the business permission data obtained in step S201 is input into the business permission model to obtain the evaluation result of the user whose business permission is to be renewed. This evaluation result indicates the closeness between the user and the business permission to be renewed. The higher the evaluation result of the user, the more frequently the user uses the business permission to be renewed, and the higher the probability of renewing the business permission.

[0042] In the embodiments of this specification, the business permission model used to evaluate users whose business permissions are pending renewal is a pre-obtained model based on feature data of the relationship between users and business permissions. To facilitate understanding of the process of obtaining the business permission model, Figure 3 This document explains the construction principle of the business permission model provided in the embodiments of this specification, in order to describe in detail the construction of the business permission model.

[0043] In the embodiments of this specification, the business permission model is a model obtained by training a regression model based on the feature data of the relationship between users and business permissions.

[0044] In the embodiments of this specification, the feature data of the relationship between users and business permissions includes: feature data of the relationship between users and business permissions based on the user's first-degree relationship circle.

[0045] and / or

[0046] Based on feature data related to business permissions and relationships among all users

[0047] and / or

[0048] Based on feature data of the relationship between users and business permission administrators

[0049] and / or

[0050] Feature data based on the relationship between users and other permissions of business permission managers.

[0051] It should be noted that the feature data provided in the embodiments of this specification are significant and strong features. When constructing a business permission model, feature data from other dimensions can be added for training. The feature data provided in the embodiments of this specification does not constitute a limitation of this application.

[0052] In the embodiments of this specification, the feature data based on the relationship between users and business permissions within a user's first-degree relationship circle is obtained by calculating the highest, lowest, and average scores corresponding to business permissions for other users within the user's first-degree relationship circle. In this specification, a user's first-degree relationship circle refers to their adjacent users; specifically, it includes the user's superiors, subordinates, and other users in the same department / group. It should be noted that the highest, lowest, and average scores corresponding to business permissions for other users within the user's first-degree relationship circle are pre-set scores based on the user's access frequency to business permissions over a certain period.

[0053] During the construction of the business permission model, the highest, lowest, and average scores of other users within the user's first-degree relationship circle corresponding to business permissions are input into the business permission model for its construction.

[0054] In the embodiments of this specification, the feature data of the relationship between business permissions and all users is based on the highest, lowest, and average scores of the closeness between the owner and the business permission. These scores represent the characteristics of the business permission itself. Using this feature data in the business permission model can improve the generalization ability of the model's predictions. It should be noted that the highest, lowest, and average scores based on the closeness between the owner and the business permission are pre-set scores based on the frequency of user access to the business permission within a certain period.

[0055] During the construction of the business permission model, the characteristic data of the obtained business permissions and the relationship between all users are input into the business permission model for its construction.

[0056] In the embodiments of this specification, the feature data based on the relationship between the user and the business permission manager is obtained by determining the relationship between the user and the permission manager based on the user's first-degree relationship circle and the user's second-degree relationship circle.

[0057] In the embodiments of this specification, if the business permission manager belongs to the user's first-degree relationship circle, the relationship between the user and the permission manager is defined as 1 point;

[0058] If the business permission manager belongs to the user's second-degree relationship circle, then the relationship between the user and the permission manager is defined as 0.5 points;

[0059] Otherwise, the relationship between the user and the permission administrator will be defined as 0 points.

[0060] It should be noted that a user's second-degree relationship circle is derived from the user's first-degree relationship circle through permutations and combinations. Specifically, a user's second-degree relationship circle consists of the leaders of leaders and the subordinates of subordinates.

[0061] During the construction of the business permission model, the characteristic data of the relationship between users and permission administrators are obtained and input into the business permission model for its construction.

[0062] In the embodiments of this specification, the relationship between the user and the permission manager is determined by whether the user and the business permission manager are within a first-degree relationship circle and / or a second-degree relationship circle, which is a strong feature characterizing the user and business permissions.

[0063] In the embodiments of this specification, the feature data based on the relationship between the user and the other permissions of the business permission manager is obtained based on the access relationship between the user and the permission manager for other permissions. This yields the highest score, lowest score, average score, and number of other permissions possessed by the user and the business permission manager, further characterizing the relationship between the user and the business permission manager. It should be noted that the highest score, lowest score, average score, and number of other permissions possessed by the user and the business permission manager are based on the frequency of the user's access to business permissions within a certain period and are pre-set scores.

[0064] During the construction of the business permission model, the highest score, lowest score, average score, and number of other permissions corresponding to the user and the business permission manager are input into the business permission model for its construction.

[0065] It should be noted that, in the embodiments of this specification, the feature data describing the relationship between users and business permissions is set manually based on business permissions and the frequency of user access to business permissions within a certain period of time, and the way the scores are expressed does not constitute a limitation of this specification.

[0066] Based on the feature data of the relationship between users and business permissions, a regression model is used for training to obtain a business permission model. In the embodiments of this specification, the regression model includes GBDT, PS-SMART, or linear regression.

[0067] GBDT (Gradient Boosting Decision Tree) is a regression algorithm that uses an additive model (i.e., a linear combination of basis functions) and continuously reduces the residuals generated during training to classify or regress data. In the embodiments of this specification, when constructing the business permission model, GBDT uses a CART regression tree to regress the target data.

[0068] PS-SMART is a regression algorithm based on a parameter server. Using this regression algorithm to construct a business permission model can save resources and meet various needs.

[0069] Linear regression refers to using a straight line to describe the relationship between data more accurately. By using a cost function, a linear regression model that most accurately describes the relationship between data can be obtained, thereby constructing a business permission model.

[0070] The business permission model obtained based on the above GBDT, PS-SMART, or linear regression can realize the renewal of business permissions. However, since the evaluation results obtained by the above methods may contain errors, in order to ensure further accuracy of the evaluation results and reduce errors, in the embodiments of this specification, the regression model further includes:

[0071] Model fusion is performed using a stacking fusion method.

[0072] STACKING fusion is a model fusion method with a hierarchical structure. It outputs prediction results through K-fold cross-validation, then merges the prediction results from each model into a new feature, and uses the new model for training. In the embodiments of this specification, prediction results based on GBDT, PS-SMART, or linear regression are merged into a new feature and trained using the new model to construct a business permission model.

[0073] It should be noted that the GBDT, PS-SMART, or linear regression regression models in the embodiments of this specification are merely illustrative examples and do not constitute a limitation of this application. Other regression models can also be used to construct business permission models, such as deep learning-based models.

[0074] Step S205: Based on the evaluation results, renew the business permissions of the users whose business permissions are pending renewal.

[0075] In this embodiment of the specification, the renewal of the service permissions to be renewed is based on the evaluation result obtained in the aforementioned step S203. Specifically, the evaluation result is a score, and the user's service permissions to be renewed are renewed according to a preset threshold.

[0076] If the evaluation result is greater than or equal to the preset threshold, then the user's pending renewal service permissions will be renewed.

[0077] If the evaluation result is less than the preset threshold, the user's pending service permissions will not be renewed.

[0078] In the embodiments of this specification, the evaluation result obtained in the aforementioned step S203 is a score and whether to recommend renewal. Based on a preset threshold, the user's pending renewal service permissions are renewed.

[0079] In the embodiments of this specification, based on the evaluation results obtained in the aforementioned step S203, the renewal of the business to be renewed is automatically realized according to the preset settings.

[0080] In the embodiments of this specification, the renewal of the business permission to be renewed is realized based on the evaluation result obtained in the aforementioned step S203. The specific implementation method does not constitute a limitation of this specification.

[0081] To facilitate a further understanding of the business permission renewal method provided in the embodiments of this specification, Figure 4 This diagram illustrates the application and renewal of business permissions as provided in the embodiments of this specification. The business permission renewal method provided in the embodiments of this specification enables automatic renewal of business permissions.

[0082] In the embodiments of this specification, the business permission renewal method provided in the embodiments of this specification can be used in companies or organizations with permission management systems. It can be used within the company or organization or in the cloud, such as financial cloud, to improve user stickiness between external merchants and their users.

[0083] The business permission renewal method provided in the embodiments of this specification takes into account the relationship between users and business permissions when constructing the business permission model. Based on the business permission model, it realizes the automatic renewal of business permissions to be renewed, which can reduce the interference of the business permission system on users and permission administrators and improve work efficiency.

[0084] The above describes in detail a method for renewing business permissions. Correspondingly, this specification also provides a device for renewing business permissions, such as... Figure 5 As shown. Figure 5 This is a schematic diagram of a business permission renewal device provided in an embodiment of this specification. The renewal device includes:

[0085] Module 501 retrieves the business permission data of users whose business permissions are to be renewed.

[0086] The scoring module 503, based on the business permission data and according to the business permission model, obtains the evaluation result of the user whose business permission is to be renewed, wherein the evaluation result is the degree of closeness between the user whose business permission is to be renewed and the business permission to be renewed, and the business permission model is a model obtained in advance based on the feature data of the relationship between the user and the business permission;

[0087] The renewal module 505 renews the business permissions of the user whose business permissions are to be renewed based on the evaluation results.

[0088] The scoring module 503 specifically includes:

[0089] The characteristic data of the relationship between users and service permissions includes:

[0090] Feature data based on the relationship between users and business permissions within a user's first-degree social circle.

[0091] and / or

[0092] Based on feature data related to business permissions and relationships among all users

[0093] and / or

[0094] Based on feature data of the relationship between users and business permission administrators

[0095] and / or

[0096] Feature data based on the relationship between users and other permissions of business permission managers.

[0097] The feature data on the relationship between users and business permissions based on a user's first-degree relationship circle is obtained by obtaining the highest score, lowest score, and average score of other users and business permissions within the user's first-degree relationship circle based on their relationships with other users and business permissions.

[0098] The characteristic data of the relationship between the business permissions and all users is based on the highest, lowest, and average scores of the closeness between the owner of the business permission and the business permission.

[0099] The feature data based on business permissions and relationships with all users is obtained by determining the relationship between the user and the permission administrator based on the user's first-degree relationship circle and the user's second-degree relationship circle.

[0100] The feature data based on the relationship between the user and the other permissions of the business permission manager is based on the access relationship between the user and the permission manager's other permissions, to obtain the highest score, lowest score, average score and number of other permissions corresponding to the user and the business permission manager's other permissions.

[0101] The regression model includes GBDT, PS-SMART, or linear regression.

[0102] The regression model further includes:

[0103] Model fusion is performed using a stacking fusion method.

[0104] This specification also provides an electronic device, including:

[0105] At least one processor; and,

[0106] A memory communicatively connected to the at least one processor; wherein,

[0107] The memory stores instructions executable by the at least one processor, which, when executed by the at least one processor, enable the at least one processor to:

[0108] Obtain the business permission data of users whose business permissions are pending renewal;

[0109] Based on the business permission data, and according to the business permission model, the evaluation result of the user whose business permission is to be renewed is obtained. The evaluation result is the degree of closeness between the user whose business permission is to be renewed and the business permission to be renewed. The business permission model is a model obtained in advance based on the feature data of the relationship between the user and the business permission.

[0110] Based on the evaluation results, the business permissions of the users whose business permissions are pending renewal are renewed.

[0111] The foregoing has described specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than that shown in the embodiments and may still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require the specific or sequential order shown to achieve the desired result. In some embodiments, multitasking and parallel processing are possible or may be advantageous.

[0112] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to interchangeably. Each embodiment focuses on describing the differences from other embodiments. In particular, the embodiments for apparatus, electronic devices, and non-volatile computer storage media are basically similar to the method embodiments, so the descriptions are relatively simple; relevant parts can be referred to the descriptions of the method embodiments.

[0113] The apparatus, electronic device, and non-volatile computer storage medium and method provided in the embodiments of this specification are corresponding. Therefore, the apparatus, electronic device, and non-volatile computer storage medium also have similar beneficial technical effects as the corresponding method. Since the beneficial technical effects of the method have been described in detail above, the beneficial technical effects of the corresponding apparatus, electronic device, and non-volatile computer storage medium will not be repeated here.

[0114] In the 1990s, improvements to a technology could be clearly distinguished as either hardware improvements (e.g., improvements to the circuit structure of diodes, transistors, switches, etc.) or software improvements (improvements to the methodology). However, with technological advancements, many methodological improvements today can be considered direct improvements to the hardware circuit structure. Designers almost always obtain the corresponding hardware circuit structure by programming the improved methodology into the hardware circuit. Therefore, it cannot be said that a methodological improvement cannot be implemented using hardware physical modules. For example, a Programmable Logic Device (PLD) (such as a Field Programmable Gate Array (FPGA)) is such an integrated circuit whose logic function is determined by the user programming the device. Designers can program and "integrate" a digital system onto a PLD themselves, without needing chip manufacturers to design and manufacture dedicated integrated circuit chips. Furthermore, nowadays, instead of manually manufacturing integrated circuit chips, this programming is mostly implemented using "logic compiler" software. Similar to the software compiler used in program development, the original code before compilation must be written in a specific programming language, called a Hardware Description Language (HDL). There are many HDLs, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, and RHDL (Ruby Hardware Description Language). Currently, the most commonly used are VHDL (Very-High-Speed ​​Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should understand that by simply performing some logic programming on the method flow using one of these hardware description languages ​​and programming it into an integrated circuit, the hardware circuit implementing the logical method flow can be easily obtained.

[0115] The controller can be implemented in any suitable manner. For example, it can take the form of a microprocessor or processor and a computer-readable medium storing computer-readable program code (e.g., software or firmware) executable by the (micro)processor, logic gates, switches, application-specific integrated circuits (ASICs), programmable logic controllers, and embedded microcontrollers. Examples of controllers include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicon Labs C8051F320. A memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art will also recognize that, in addition to implementing the controller in purely computer-readable program code form, the same functionality can be achieved by logically programming the method steps to make the controller take the form of logic gates, switches, application-specific integrated circuits, programmable logic controllers, and embedded microcontrollers. Therefore, such a controller can be considered a hardware component, and the means included therein for implementing various functions can also be considered as structures within the hardware component. Alternatively, the means for implementing various functions can be considered as both software modules implementing the method and structures within the hardware component.

[0116] The systems, devices, modules, or units described in the above embodiments can be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, a computer can be, for example, a personal computer, laptop computer, cellular phone, camera phone, smartphone, personal digital assistant, media player, navigation device, email device, game console, tablet computer, wearable device, or any combination of these devices.

[0117] For ease of description, the above apparatus is described by dividing it into various functional units. Of course, when implementing one or more embodiments of this specification, the functions of each unit can be implemented in one or more software and / or hardware.

[0118] Those skilled in the art will understand that the embodiments of this specification can be provided as methods, systems, or computer program products. Therefore, the embodiments of this specification can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the embodiments of this specification can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0119] This specification is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this specification. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create a machine for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0120] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0121] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0122] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0123] Memory may include non-persistent storage in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.

[0124] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.

[0125] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0126] This specification can be described in the general context of computer-executable instructions that are executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform a specific task or implement a specific abstract data type. This specification can also be practiced in distributed computing environments, where tasks are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside on local and remote computer storage media, including storage devices.

[0127] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to interchangeably. Each embodiment focuses on describing the differences from other embodiments. In particular, the system embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions in the method embodiments.

[0128] The above description is merely an embodiment of this specification and is not intended to limit this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principle of this application should be included within the scope of the claims of this application.

Claims

1. A method for renewing business permissions, comprising: Obtain the business permission data of users whose business permissions are pending renewal; Based on the business permission data, and according to the business permission model, the evaluation result of the user whose business permission is to be renewed is obtained. The evaluation result is the degree of closeness between the user whose business permission is to be renewed and the business permission to be renewed. The business permission model is a model obtained in advance based on the feature data of the relationship between the user and the business permission. The feature data is obtained by judging the relationship between the user and the permission manager based on the user's first-degree relationship circle and the user's second-degree relationship circle. The second-degree relationship circle is a relationship derived by permuting and combining the user's first-degree relationship circle. Based on the evaluation results, the business permissions of the users whose business permissions are pending renewal are renewed.

2. The method as described in claim 1, wherein the feature data of the user-business permission relationship further includes: Based on the feature data of the relationship between users and business permissions in a user's first-degree relationship circle, the user's first-degree relationship circle is the user's neighboring users; and / or Based on feature data related to business permissions and relationships among all users and / or Based on feature data of the relationship between users and business permission administrators and / or Feature data based on the relationship between users and other permissions of business permission managers.

3. The method as described in claim 2, wherein the feature data of the relationship between users and business permissions based on the user's first-degree relationship circle is obtained by obtaining the highest score, lowest score and average score of other users and business permissions within the user's first-degree relationship circle based on the relationship between other users and business permissions within the user's first-degree relationship circle.

4. The method as described in claim 2, wherein the feature data of the relationship between the business permissions and all users is based on the highest score, lowest score, and average score of the closeness between the owner of the business permissions and the business permissions.

5. The method as described in claim 2, wherein the feature data based on the relationship between the user and other permissions of the business permission manager is based on the access relationship between the user and other permissions of the permission manager, to obtain the highest score, lowest score, average score and number of other permissions corresponding to the user and other permissions of the business permission manager.

6. The method as described in claim 1, wherein the business permission model is a model obtained based on a regression model, wherein, The regression model includes GBDT or PS. SMART or linear regression.

7. The method of claim 6, wherein the regression model further comprises: Model fusion is performed using a stacking fusion method.

8. The method according to any one of claims 1 to 7, wherein the business permission model is a model obtained in advance based on feature data of the relationship between users and business permissions.

9. The method as described in any one of claims 1 to 7, wherein the business permissions to be renewed are user access permissions to the business system and / or user access permissions to reports; wherein, User access permissions to business systems include user and / or user group access permissions to all platforms within their company or organization; user access permissions to reports include user and / or user group access permissions to every report in the reporting platform within their company or / or organization.

10. The method according to any one of claims 1 to 7, wherein the business permission data of the user whose business permission is to be renewed includes the relevant business permission data of the user whose business permission is to be renewed during a preset data collection period.

11. The method as described in claim 10, wherein the preset data collection time period is shorter than the total time the user uses the pending renewal service permission.

12. The method as described in claim 1, wherein the evaluation result is a score, and the step of renewing the pending business permissions of the user based on the evaluation result specifically includes: If the evaluation result is greater than or equal to the preset threshold, the user's pending renewal service permissions will be renewed. If the evaluation result is less than the preset threshold, the user's pending service permissions will not be renewed.

13. A device for renewing business permissions, comprising: The module retrieves the business permission data of users whose business permissions are to be renewed. The evaluation module, based on the business permission data and according to the business permission model, obtains the evaluation result of the user whose business permission is to be renewed. The evaluation result represents the closeness between the user and the business permission to be renewed. The business permission model is a model pre-obtained based on the feature data of the relationship between the user and the business permission. The feature data is obtained by judging the relationship between the user and the permission manager based on the user's first-degree relationship circle and the user's second-degree relationship circle. The second-degree relationship circle is a relationship derived by permuting and combining the user's first-degree relationship circle. The renewal module renews the business permissions of the users whose business permissions are pending renewal based on the evaluation results.

14. An electronic device comprising: At least one processor; as well as, A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, which, when executed by the at least one processor, enable the at least one processor to: Obtain the business permission data of users whose business permissions are pending renewal; Based on the business permission data, and according to the business permission model, the evaluation result of the user whose business permission is to be renewed is obtained. The evaluation result is the degree of closeness between the user whose business permission is to be renewed and the business permission to be renewed. The business permission model is a model obtained in advance based on the feature data of the relationship between the user and the business permission. The feature data is obtained by judging the relationship between the user and the permission manager based on the user's first-degree relationship circle and the user's second-degree relationship circle. The second-degree relationship circle is a relationship derived by permuting and combining the user's first-degree relationship circle. Based on the evaluation results, the business permissions of the users whose business permissions are pending renewal are renewed.

Citation Information

Patent Citations

  • Permission dispatching method and device

    CN104598778A

  • Authorization method and device for intelligent equipment

    CN105119875A