System permission allocation method and device based on user portrait

CN115455402BActive Publication Date: 2026-08-18INDUSTRIAL AND COMMERCIAL BANK OF CHINA +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211126549.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-16
Publication Date
2026-08-18
Estimated Expiration
2042-09-16

AI Technical Summary

Technical Problem

[0003]随着IT软硬件系统建设规模的增大,IT服务管理系统的用户数量增大,用户身份越来越复杂,影响用户权限的因素越来越多,以角色为载体管理用户权限,会造成角色划分成指数级增长,最终造成用户角色管理失控

Benefits of technology

[0029] This invention establishes user profiles, which include multiple profile feature dimensions and corresponding profile feature dimension values. Then, permissions are allocated and managed based on the user profiles. Since the profile feature dimensions in the user profiles are highly scalable and can be added at any time, the permission allocation scheme based on user profiles in this invention has high applicability and scalability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115455402B_ABST
    Figure CN115455402B_ABST
Patent Text Reader

Abstract

The application discloses a system permission allocation method and device based on user portrait, which can be applied to the financial field or other technical fields, and the method comprises the following steps: obtaining a user portrait of a target user, wherein the user portrait comprises portrait feature dimensions corresponding to the target user and portrait feature dimension values of the target user in each portrait feature dimension; comparing the user portrait with preset permission allocation conditions of each system permission to determine the permission allocation conditions met by the user portrait, wherein the permission allocation conditions comprise portrait feature dimensions and portrait feature dimension values that need to be met; and allocating system permissions corresponding to the permission allocation conditions met by the user portrait to the target user. The application improves the applicability and expandability of permission control.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of access control technology, and more specifically, to a system access control method and apparatus based on user profiles. Background Technology

[0002] Existing IT service management systems employ Role-Based Access Control (RBAC), managing user permissions through roles. Specifically, this involves adding a role information table to the access control design, associating roles with permissions, making roles a collection of permissions, and then assigning roles to users to achieve user access management. RBAC access control is as follows: Figure 4 As shown.

[0003] As the scale of IT hardware and software system construction increases, the number of users in IT service management systems grows, user identities become more complex, and more factors influence user permissions. Managing user permissions based on roles leads to an exponential increase in role division, ultimately resulting in a loss of control over user role management. How to improve the applicability and scalability of access control is a pressing technical problem that needs to be solved in this field. Summary of the Invention

[0004] In order to solve at least one of the technical problems in the background art, the present invention proposes a system permission allocation method and apparatus based on user profiles.

[0005] To achieve the above objectives, according to one aspect of the present invention, a system permission allocation method based on user profiles is provided, the method comprising:

[0006] Obtain a user profile of a target user, wherein the user profile includes: the profile feature dimension corresponding to the target user and the profile feature dimension value of the target user in each of the profile feature dimensions;

[0007] The user profile is compared with the preset permission allocation conditions of each system permission to determine the permission allocation conditions that the user profile meets. The permission allocation conditions include: the profile feature dimensions and profile feature dimension values ​​that need to be met.

[0008] The system permissions corresponding to the permission allocation conditions satisfied by the user profile are allocated to the target user.

[0009] Optionally, this user profile-based system permission allocation method also includes:

[0010] Determine whether a profile analysis model corresponding to the target user exists, wherein the profile analysis model includes: multiple preset profile feature dimensions;

[0011] If it exists, the user feature supplementary configuration information of the target user is obtained, and the user profile of the target user is generated according to the user feature supplementary configuration information and the profile analysis model. The user feature supplementary configuration information includes the profile feature dimension value of the target user in each profile feature dimension in the profile analysis model.

[0012] Optionally, this user profile-based system permission allocation method also includes:

[0013] If it does not exist, then a user profile of the target user is generated based on the profile feature dimension and profile feature dimension value corresponding to the selected target user.

[0014] Optionally, the user feature supplementary configuration information further includes: the portrait feature dimension corresponding to the target user other than the portrait feature dimension in the portrait analysis model, and the portrait feature dimension value of the target user on the portrait feature dimension other than the portrait feature dimension in the portrait analysis model.

[0015] Optionally, this user profile-based system permission allocation method also includes:

[0016] Build a portrait analysis model for each role based on its characteristics;

[0017] Obtain the mapping relationship between users and roles;

[0018] Establish a correspondence between users and the user profile analysis model based on the aforementioned correspondence.

[0019] Optionally, determining whether a profile analysis model corresponding to the target user exists specifically includes:

[0020] By querying the correspondence between users and profile analysis models, it can be determined whether a profile analysis model corresponding to the target user exists.

[0021] To achieve the above objectives, according to another aspect of the present invention, a system permission allocation device based on user profiles is provided, the device comprising:

[0022] The user profile acquisition unit is used to acquire a user profile of a target user, wherein the user profile includes: the profile feature dimension corresponding to the target user and the profile feature dimension value of the target user in each of the profile feature dimensions;

[0023] The condition comparison unit is used to compare the user profile with the preset permission allocation conditions of each system permission to determine the permission allocation conditions that the user profile meets. The permission allocation conditions include: the profile feature dimensions and profile feature dimension values ​​that need to be met.

[0024] The permission allocation unit is used to allocate the system permissions corresponding to the permission allocation conditions satisfied by the user profile to the target user.

[0025] To achieve the above objectives, according to another aspect of the present invention, a computer device is also provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the above-described system permission allocation method based on user profile.

[0026] To achieve the above objectives, according to another aspect of the present invention, a computer-readable storage medium is also provided, on which a computer program / instruction is stored, which, when executed by a processor, implements the steps of the above-described system permission allocation method based on user profile.

[0027] To achieve the above objectives, according to another aspect of the present invention, a computer program product is also provided, comprising a computer program / instruction that, when executed by a processor, implements the steps of the above-described system permission allocation method based on user profile.

[0028] The beneficial effects of this invention are as follows:

[0029] This invention establishes user profiles, which include multiple profile feature dimensions and corresponding profile feature dimension values. Then, permissions are allocated and managed based on the user profiles. Since the profile feature dimensions in the user profiles are highly scalable and can be added at any time, the permission allocation scheme based on user profiles in this invention has high applicability and scalability. Attached Figure Description

[0030] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort. In the drawings:

[0031] Figure 1 This is the first flowchart of the system permission allocation method based on user profile in an embodiment of the present invention;

[0032] Figure 2 This is the second flowchart of the system permission allocation method based on user profile in an embodiment of the present invention;

[0033] Figure 3 This is the third flowchart of the system permission allocation method based on user profiles in an embodiment of the present invention;

[0034] Figure 4 This is a diagram illustrating RBAC (Right-Based Access Control) permissions management.

[0035] Figure 5 This is a system configuration diagram of the present invention;

[0036] Figure 6 This is a data relationship diagram of the present invention;

[0037] Figure 7 This is a schematic diagram of the portrait analysis model constructed by the present invention;

[0038] Figure 8 This is a schematic diagram of the user profile building process;

[0039] Figure 9 This is a structural block diagram of a system permission allocation device based on user profiles according to an embodiment of the present invention;

[0040] Figure 10 This is a schematic diagram of a computer device according to an embodiment of the present invention. Detailed Implementation

[0041] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.

[0042] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0043] It should be noted that the terms "comprising" and "having" and any variations thereof in the specification, claims and accompanying drawings of this invention are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units that are explicitly listed, but may include other steps or units that are not explicitly listed or that are inherent to such processes, methods, products or devices.

[0044] It should be noted that, unless otherwise specified, the embodiments and features described in the present invention can be combined with each other. The present invention will now be described in detail with reference to the accompanying drawings and embodiments.

[0045] It should be noted that the acquisition, storage, use, and processing of data in the technical solution of this application all comply with the relevant provisions of national laws and regulations.

[0046] It should be noted that the system permission allocation method and device based on user profiles of the present invention can be used in the financial field, or in any field other than the financial field. The application field of the system permission allocation method and device based on user profiles of the present invention is not limited.

[0047] It should be noted that the following embodiments of the present invention use an IT service management system as an example, but the system of the present invention is not limited thereto.

[0048] This invention analyzes the characteristics of system users and finds that factors affecting system user permissions include, but are not limited to, the user's system role, the level of organization the user belongs to, the role of the support group the user belongs to, the products the user supports, and the operations provided by the user. These factors are abstracted into feature dimensions of user profiles. Combined with reality, these feature dimensions are integrated into a profile analysis model. Based on the model, user profiles are constructed, and a permission management system based on user profiles is built.

[0049] This solution is applicable to the access control module of an IT service management system. Its common components include a database, a user profile analysis model building engine, a user profile building engine, and a user profile authorization engine. The system structure diagram is shown below. Figure 5 As shown.

[0050] The overall process of this plan is as follows:

[0051] 1. Based on the user characteristics of the IT service management system, analyze the feature points that affect user permissions (i.e., profile feature dimensions).

[0052] 2. Based on user feature points (i.e. profile feature dimensions), abstract the user profile feature dimensions.

[0053] 3. Establish a user profile analysis model based on the user profile feature dimensions.

[0054] 4. Build user profiles for system users.

[0055] 5. System permissions for building user profiles.

[0056] This solution involves a profile feature dimension table, a profile analysis model table, and a user profile table. The relationships between these tables are as follows: Figure 6 exhibit.

[0057] Before building user profiles for an IT service management system, it's necessary to analyze the feature points affecting system permissions and abstract the profile feature dimensions. To facilitate user profile building, a user profile analysis model needs to be constructed based on system module permissions. This solution uses an IT service management system in a specific scenario as an example, defining relevant table data.

[0058] In one embodiment of the present invention, the portrait feature dimension table can be as shown in Table 1 below:

[0059]

[0060]

[0061] Table 1. Portrait Feature Dimensions

[0062] As shown in Table 1 above, the present invention establishes a portrait feature dimension table to record the abstracted portrait feature dimensions. The portrait feature dimension table records the code and name of each portrait feature dimension.

[0063] In one embodiment of the present invention, the image feature dimension value table can be as shown in Table 2 below:

[0064]

[0065]

[0066] Table 2. Portrait Feature Dimension Values

[0067] As shown in Table 2 above, the portrait feature dimension value table records all portrait feature dimension values ​​corresponding to each portrait feature dimension, as well as the name of each portrait feature dimension value.

[0068] In one embodiment of the present invention, the portrait analysis model table can be as shown in Table 3 below:

[0069]

[0070] Table 3. Portrait Analysis Model

[0071] As shown in Table 3 above, the portrait analysis model table records the information of each portrait analysis model, specifically including the model code, model name, and all portrait feature dimensions contained in the model.

[0072] In this invention, user profiles can be represented by a user profile table. In one embodiment of this invention, the user profile table can be as shown in Table 4 below:

[0073]

[0074]

[0075] Table 4 User Profile Table

[0076] As shown in Table 4 above, the user profile table records the profile feature dimensions corresponding to the user, as well as the profile feature dimension values ​​of the user in each corresponding profile feature dimension.

[0077] Figure 1 This is a first flowchart of the system permission allocation method based on user profiles according to an embodiment of the present invention, as follows: Figure 1 As shown, in one embodiment of the present invention, the system permission allocation method based on user profile of the present invention includes steps S101 to S103.

[0078] Step S101: Obtain the user profile of the target user, wherein the user profile includes: the profile feature dimension corresponding to the target user and the profile feature dimension value of the target user in each of the profile feature dimensions.

[0079] This invention analyzes the characteristics of users in the system to identify the factors that affect user permissions, abstracts these factors into feature dimensions of user profiles, and defines the value range for these feature dimensions.

[0080] Step S102: Compare the user profile with the preset permission allocation conditions of each system permission to determine the permission allocation conditions that the user profile meets. The permission allocation conditions include: the profile feature dimensions and profile feature dimension values ​​that need to be met.

[0081] Step S103: Assign the system permissions corresponding to the permission allocation conditions satisfied by the user profile to the target user.

[0082] This invention uses user profiles instead of system roles as a bridge to communicate between users and permissions. It requires defining a set of user profile feature dimensions that meet the permission granting conditions and defining the value range for these feature dimensions.

[0083] In one embodiment of the present invention, taking event handling permissions as an example, the permission allocation conditions that meet the requirements for granting database-related emergency issue event handling permissions are:

[0084] 1. The system role is equivalent to "Event User";

[0085] 2. The company name is equal to "DATA_XX";

[0086] 3. The support group role is equivalent to "Event Manager";

[0087] 4. The supported product primary category is "SOFT" (software products);

[0088] 5. The supported product secondary category is equal to "APPLY_SYS" (application software);

[0089] 6. Supported event urgency range: "Medium" and "High";

[0090] 7. The supported events have a "high" impact.

[0091] 8. Supported event priority is "high".

[0092] When an event occurs that falls within the range of the above profile feature dimensions, it will be assigned to a user who meets the above permission allocation conditions to resolve the issue, thereby completing the granting of user profile permissions.

[0093] like Figure 2 As shown, in one embodiment of the present invention, the system permission allocation method based on user profile of the present invention further includes steps S201 to S202.

[0094] Step S201: Determine whether there is a profile analysis model corresponding to the target user. The profile analysis model includes multiple preset profile feature dimensions.

[0095] Step S202: If it exists, obtain the user feature supplementary configuration information of the target user, and generate the user profile of the target user according to the user feature supplementary configuration information and the profile analysis model. The user feature supplementary configuration information includes: the profile feature dimension value of the target user in each profile feature dimension in the profile analysis model.

[0096] In one embodiment of the present invention, the system permission allocation method based on user profiles of the present invention further includes the following steps:

[0097] If it does not exist, then a user profile of the target user is generated based on the profile feature dimension and profile feature dimension value corresponding to the selected target user.

[0098] In one embodiment of the present invention, the user feature supplementary configuration information further includes: the portrait feature dimension corresponding to the target user other than the portrait feature dimension in the portrait analysis model, and the portrait feature dimension value of the target user on the portrait feature dimension other than the portrait feature dimension in the portrait analysis model.

[0099] In this invention, to quickly build a user profile, a profile analysis model matching the user can be selected, the feature dimensions contained in the profile analysis model can be matched to the user, and values ​​can be assigned to the user's feature dimensions to complete the user profile. If no profile analysis model matching the user exists, the profile feature dimensions and feature values ​​can be directly selected to build the user profile.

[0100] In one embodiment of the present invention, the specific process for constructing a user profile can be as follows: Figure 8 As shown, the specific steps are as follows:

[0101] To create a user profile, you can directly select the profile feature dimensions and feature values.

[0102] 1. Select a user profile analysis model that matches the user;

[0103] 2. If applicable, assign feature values ​​to the user feature dimensions; otherwise, choose whether to create a new model.

[0104] 3. If a new model is created, rebuild it from step 1; if no new model is created, use feature dimensions to build the user profile.

[0105] 4. Supplement feature dimensions for users in the selected user profile analysis model;

[0106] 5. Assign feature values ​​to the feature dimensions of the user profile.

[0107] like Figure 3 As shown, in one embodiment of the present invention, the system permission allocation method based on user profile of the present invention further includes steps S301 to S303.

[0108] Step S301: Construct a portrait analysis model for each character based on their respective character characteristics.

[0109] Step S302: Obtain the correspondence between users and roles.

[0110] Step S303: Establish the correspondence between users and the profile analysis model based on the correspondence.

[0111] In this invention, the user profile analysis model building engine is the foundation for convenient and rapid user profile construction. A common method for building a user profile analysis model is to use roles as a basis and then combine and overlay the user profile feature dimensions extracted during the analysis phase as needed. This involves combining the profile feature dimension table data to generate a user profile analysis model table. For example... Figure 7 As shown, taking the IT service management system incident handling user profile analysis model as an example, the role of the incident handling user is the incident handling role. In addition, the feature dimensions that determine the operation permissions of the incident handling user include support group role, the support group to which they belong, the company they belong to, the product they are responsible for, and the urgency, impact, and priority of the incident they are responsible for. These feature dimensions are used to construct a profile analysis model for user profile building and authorization.

[0112] In one embodiment of the present invention, determining whether a profile analysis model corresponding to the target user exists in step S201 specifically includes:

[0113] By querying the correspondence between users and profile analysis models, it can be determined whether a profile analysis model corresponding to the target user exists.

[0114] As can be seen from the above embodiments, the system permission allocation method based on user profiles of the present invention achieves at least the following beneficial effects:

[0115] 1. This invention is based on the user profile management IT service management system permissions. The user profile feature dimensions can be added and combined arbitrarily, and the configuration is flexible.

[0116] 2. This invention can be used to manage various permission control needs, such as menu access permissions, data access permissions, and operation control permissions.

[0117] 3. Adding new feature dimensions and feature values ​​will not affect the preset function permissions, and user profile feature dimensions can be expanded at will.

[0118] 4. For precise matching of user profile permissions, the present invention can use data digest method for permission matching, which can improve the efficiency of permission matching.

[0119] It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases the steps shown or described may be executed in a different order than that shown here.

[0120] Based on the same inventive concept, embodiments of the present invention also provide a system permission allocation device based on user profiles, which can be used to implement the system permission allocation method based on user profiles described in the above embodiments, as described in the following embodiments. Since the principle of the system permission allocation device based on user profiles is similar to that of the system permission allocation method based on user profiles, embodiments of the system permission allocation device based on user profiles can be found in embodiments of the system permission allocation method based on user profiles, and repeated details will not be repeated. As used below, the terms "unit" or "module" can refer to a combination of software and / or hardware that implements a predetermined function. Although the device described in the following embodiments is preferably implemented in software, hardware implementation, or a combination of software and hardware, is also possible and contemplated.

[0121] Figure 9 This is a structural block diagram of a system permission allocation device based on user profiles according to an embodiment of the present invention, as shown below. Figure 9 As shown, in one embodiment of the present invention, the system permission allocation device based on user profiles of the present invention specifically includes:

[0122] User profile acquisition unit 1 is used to acquire a user profile of a target user, wherein the user profile includes: the profile feature dimension corresponding to the target user and the profile feature dimension value of the target user in each of the profile feature dimensions;

[0123] The condition comparison unit 2 is used to compare the user profile with the preset permission allocation conditions of each system permission to determine the permission allocation conditions that the user profile meets. The permission allocation conditions include: the profile feature dimensions and profile feature dimension values ​​that need to be met.

[0124] The permission allocation unit 3 is used to allocate the system permissions corresponding to the permission allocation conditions satisfied by the user profile to the target user.

[0125] In one embodiment of the present invention, the system permission allocation device based on user profile of the present invention further includes:

[0126] A matching profile analysis model lookup unit is used to determine whether a profile analysis model corresponding to the target user exists. The profile analysis model includes multiple preset profile feature dimensions.

[0127] The first user profile generation unit is configured to, if present, acquire supplementary user feature configuration information of the target user, and generate a user profile of the target user based on the supplementary user feature configuration information and the profile analysis model, wherein the supplementary user feature configuration information includes: the profile feature dimension value of the target user in each profile feature dimension of the profile analysis model.

[0128] In one embodiment of the present invention, the system permission allocation device based on user profile of the present invention further includes:

[0129] The second user profile generation unit is used to generate a user profile of the target user based on the profile feature dimension and profile feature dimension value corresponding to the selected target user if the target user does not exist.

[0130] In one embodiment of the present invention, the user feature supplementary configuration information further includes: the portrait feature dimension corresponding to the target user other than the portrait feature dimension in the portrait analysis model, and the portrait feature dimension value of the target user on the portrait feature dimension other than the portrait feature dimension in the portrait analysis model.

[0131] In one embodiment of the present invention, the system permission allocation device based on user profile of the present invention further includes:

[0132] The portrait analysis model building unit is used to build a portrait analysis model for each character based on their respective character characteristics.

[0133] The mapping relationship acquisition unit is used to acquire the mapping relationship between users and roles;

[0134] The correspondence establishment unit is used to establish a correspondence between users and the profile analysis model based on the correspondence.

[0135] In one embodiment of the present invention, the matching profile analysis model lookup unit is specifically used to determine whether there is a profile analysis model corresponding to the target user by querying the correspondence between the user and the profile analysis model.

[0136] To achieve the above objectives, according to another aspect of this application, a computer device is also provided. For example... Figure 10 As shown, the computer device includes a memory, a processor, a communication interface, and a communication bus. The memory stores a computer program that can run on the processor. When the processor executes the computer program, it implements the steps in the method of the above embodiments.

[0137] The processor can be a central processing unit (CPU). The processor can also be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, or combinations of the above types of chips.

[0138] Memory, as a non-transitory computer-readable storage medium, can be used to store non-transitory software programs, non-transitory computer-executable programs, and units, such as the program units corresponding to the above-described method embodiments of the present invention. The processor executes various functional applications and data processing of the processor by running the non-transitory software programs, instructions, and modules stored in the memory, thereby implementing the methods described in the above-described method embodiments.

[0139] The memory may include a program storage area and a data storage area. The program storage area may store the operating system and applications required for at least one function; the data storage area may store data created by the processor, etc. Furthermore, the memory may include high-speed random access memory and non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some embodiments, the memory may optionally include memory remotely located relative to the processor, which can be connected to the processor via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0140] The one or more units are stored in the memory and, when executed by the processor, perform the methods described in the above embodiments.

[0141] The specific details of the aforementioned computer equipment can be understood by referring to the relevant descriptions and effects in the above embodiments, and will not be repeated here.

[0142] To achieve the above objectives, according to another aspect of this application, a computer-readable storage medium is also provided, which stores a computer program that, when executed in a computer processor, implements the steps in the above-described system permission allocation method based on user profiles. Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. The storage medium can be a magnetic disk, optical disk, read-only memory (ROM), random access memory (RAM), flash memory, hard disk drive (HDD), or solid-state drive (SSD), etc.; the storage medium may also include combinations of the above types of memory.

[0143] To achieve the above objectives, according to another aspect of this application, a computer program product is also provided, including a computer program / instructions that, when executed by a processor, implement the steps of the above-described system permission allocation method based on user profile.

[0144] Obviously, those skilled in the art will understand that the modules or steps of the present invention described above can be implemented using general-purpose computing devices. They can be centralized on a single computing device or distributed across a network of multiple computing devices. Optionally, they can be implemented using computer-executable program code, thereby storing them in a storage device for execution by a computing device, or fabricating them separately as individual integrated circuit modules, or fabricating multiple modules or steps as a single integrated circuit module. Thus, the present invention is not limited to any particular hardware and software combination.

[0145] The above description is merely a preferred embodiment of the present invention and is not intended to limit the invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A system permission allocation method based on user profiles, characterized in that, include: Obtain a user profile of a target user, wherein the user profile includes: the profile feature dimension corresponding to the target user and the profile feature dimension value of the target user in each of the profile feature dimensions; Determine whether a profile analysis model corresponding to the target user exists. The profile analysis model includes: multiple preset profile feature dimensions; the profile analysis model is configured and stored in the form of a data table. If present, the user feature supplementary configuration information of the target user is obtained, and a user profile of the target user is generated based on the user feature supplementary configuration information and the profile analysis model. The user feature supplementary configuration information includes: the profile feature dimension value of the target user on each profile feature dimension in the profile analysis model; the user feature supplementary configuration information also includes: the profile feature dimension corresponding to the target user other than the profile feature dimensions in the profile analysis model, and the profile feature dimension value of the target user on the profile feature dimensions other than the profile feature dimensions in the profile analysis model; the feature dimensions and feature dimension values ​​of the user profile are supplemented by configuring all the profile feature dimensions and all the profile feature dimension values; the configuration includes at least: combining the profile feature dimensions and combining the profile feature dimension values. The user profile is compared with the preset permission allocation conditions of each system permission to determine the permission allocation conditions that the user profile meets. The permission allocation conditions include: the profile feature dimensions and profile feature dimension values ​​that need to be met. The system permissions corresponding to the permission allocation conditions that the user profile meets are allocated to the target user.

2. The system permission allocation method based on user profiles according to claim 1, characterized in that, Also includes: If it does not exist, then a user profile of the target user is generated based on the profile feature dimension and profile feature dimension value corresponding to the selected target user.

3. The system permission allocation method based on user profiles according to claim 1, characterized in that, Also includes: Build a portrait analysis model for each role based on its characteristics; Obtain the mapping relationship between users and roles; Establish a correspondence between users and the user profile analysis model based on the aforementioned correspondence.

4. The system permission allocation method based on user profiles according to claim 3, characterized in that, The determination of whether a profile analysis model corresponding to the target user exists specifically includes: By querying the correspondence between users and profile analysis models, it can be determined whether a profile analysis model corresponding to the target user exists.

5. A system permission allocation device based on user profiles, characterized in that, include: The user profile acquisition unit is used to acquire a user profile of a target user, wherein the user profile includes: the profile feature dimension corresponding to the target user and the profile feature dimension value of the target user in each of the profile feature dimensions; A matching profile analysis model lookup unit is used to determine whether a profile analysis model corresponding to the target user exists. The profile analysis model includes: multiple preset profile feature dimensions; the profile analysis model is configured and stored in the form of a data table. A first user profile generation unit is configured to, if present, acquire supplementary user feature configuration information for the target user, and generate a user profile for the target user based on the supplementary user feature configuration information and the profile analysis model. The supplementary user feature configuration information includes: the profile feature dimension value of the target user on each profile feature dimension in the profile analysis model; the supplementary user feature configuration information also includes: the profile feature dimension corresponding to the target user excluding the profile feature dimensions in the profile analysis model, and the profile feature dimension value of the target user on the profile feature dimensions excluding the profile feature dimensions in the profile analysis model; the user profile's feature dimensions and feature dimension values ​​are supplemented by configuring all the profile feature dimensions and all the profile feature dimension values; the configuration includes at least: combining the profile feature dimensions and combining the profile feature dimension values. The condition comparison unit is used to compare the user profile with the preset permission allocation conditions of each system permission to determine the permission allocation conditions that the user profile meets. The permission allocation conditions include: the profile feature dimensions and profile feature dimension values ​​that need to be met. The permission allocation unit is used to allocate the system permissions corresponding to the permission allocation conditions that the user profile meets to the target user.

6. A computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 4.

7. A computer-readable storage medium having a computer program / instructions stored thereon, characterized in that, When the computer program / instructions are executed by the processor, they implement the steps of the method according to any one of claims 1 to 4.

8. A computer program product comprising a computer program / instructions, characterized in that, When the computer program / instructions are executed by the processor, they implement the steps of the method according to any one of claims 1 to 4.

Citation Information

Patent Citations

  • User authority dynamic management and control method and device based on user behaviors and equipment

    CN111966995A

  • User portrait generation method

    CN112035532A