A flexible permission decision method and device for multiple resources

By building and training the permission decision model, the problem of complex role management and insufficient permission division in the RBAC model is solved, and fine permission control and dynamic adjustment are realized, which improves the security and flexibility of the system.

CN118114275BActive Publication Date: 2025-09-02CHINESE PEOPLES LIBERATION ARMY UNIT 91977 +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410244446.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-03-04
Publication Date
2025-09-02
Estimated Expiration
2044-03-04

AI Technical Summary

Technical Problem

The traditional role-based access control (RBAC) model has complex role management and insufficient permission division, which makes permission control difficult, and depends on the administrator's professional knowledge and experience, and lacks flexibility and security.

Method used

By obtaining business system data information, preprocessing it, and building a permission decision model, and using the cross entropy loss model to train and optimize the permission decision model to achieve fine permission division and dynamic permission control.

Benefits of technology

It realizes fine permission division and dynamic permission allocation, improves the security and flexibility of the system, reduces human configuration errors, improves management efficiency, and enhances the transparency of decisions by outputting probability values, simplifying the permission update process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118114275B_ABST
    Figure CN118114275B_ABST
Patent Text Reader

Abstract

The present invention discloses a multi-resource flexible permission decision-making method and device, which includes: obtaining business system data information and permission attribute information of the business system; the business system data information includes basic information of the user, operation behavior information, operation content information, environmental factor information and historical behavior information; preprocessing the business system data information to obtain preprocessed business system data information; constructing a permission decision model based on the preprocessed business system data information and the permission attribute information of the business system; training the permission decision model to obtain an optimized permission decision model; using the trained permission decision model to process the actual operating business system data information to obtain the user's flexible permission decision result. The integration of the method of the present invention with the existing security framework not only improves the adaptability and security of the system, but also provides an efficient, scalable and easy-to-maintain permission management solution.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer security technology, and in particular to a multi-resource oriented flexible permission decision method and device. Background Art

[0002] With the development of computer application systems, permission control plays a vital role in ensuring system security. The traditional role-based access control (RBAC) model controls permissions by associating roles and permissions with objects. This model relies on administrators' expertise and experience to correctly configure roles and permissions. However, this model suffers from complex role management, insufficiently refined permission division, and high maintenance difficulties. Therefore, a new approach is needed to achieve more flexible and secure permission control. Summary of the Invention

[0003] The technical problem to be solved by the present invention is to provide a flexible permission decision method and device for multiple resources to solve the problems existing in the traditional RBAC model and achieve more fine-grained and dynamic permission control.

[0004] In order to solve the above technical problems, the first aspect of the embodiment of the present invention discloses a flexible permission decision method for multiple resources, the method comprising:

[0005] S1, obtain business system data information and business system authority attribute information;

[0006] The business system data information includes user basic information, operation behavior information, operation content information, environmental factor information and historical behavior information;

[0007] S2, preprocessing the business system data information to obtain preprocessed business system data information;

[0008] S3, constructing an authority decision model based on the pre-processed business system data information and the authority attribute information of the business system;

[0009] S4, training the permission decision model to obtain an optimized permission decision model;

[0010] S5, using the optimized authority decision model, processing the actual operating business system data information to obtain the user's flexible authority decision result.

[0011] As an optional implementation manner, in the first aspect of the embodiment of the present invention, preprocessing the business system data information to obtain preprocessed business system data information includes:

[0012] S21, performing data cleaning on the business system data information to obtain first business system data information;

[0013] S22, performing deduplication processing on the first business system data information to obtain second business system data information;

[0014] S23, performing missing value processing on the second business system data information to obtain third business system data information;

[0015] S24, encoding the third business system data information to obtain pre-processing business system data information.

[0016] As an optional implementation manner, in the first aspect of the embodiment of the present invention, the step of performing data cleaning on the business system data information to obtain the first business system data information includes:

[0017] S211, correcting the business system data information, removing erroneous information and incomplete information, and obtaining corrected business system data information;

[0018] S212: De-noise the modified business system data information to obtain first business system data information.

[0019] As an optional implementation manner, in the first aspect of the embodiment of the present invention, encoding the third business system data information to obtain pre-processed business system data information includes:

[0020] S241, converting the data information of the third business system in chronological order to obtain a time step sequence; the time step sequence includes non-numeric data and numeric data; the non-numeric data includes text data and category data;

[0021] S242, processing the time step sequence to obtain a preprocessed time step sequence;

[0022] S243, segmenting the preprocessing time step sequence to obtain segmentation data information;

[0023] S244: Encode the segmented data information to obtain pre-processing business system data information.

[0024] As an optional implementation manner, in the first aspect of the embodiment of the present invention, processing the time step sequence to obtain a preprocessed time step sequence includes:

[0025] S2421, performing data conversion on the text data to obtain word embedding data information;

[0026] S2422, converting the category data to obtain one-hot encoded data information;

[0027] S2423, performing normalization processing on the non-numeric data to obtain normalized data information;

[0028] S2424: Integrate the word embedding data information, the one-hot encoded data information, and the normalized data information to obtain a preprocessing time step sequence.

[0029] As an optional implementation manner, in the first aspect of the embodiment of the present invention, performing data conversion on the text data to obtain word embedding data information includes:

[0030] S24211, extracting keywords from the text data to obtain text keyword information;

[0031] S24212, converting the text keyword information to obtain word vector information;

[0032] S24213, performing cluster analysis on the word vector information to obtain word embedding data information.

[0033] As an optional implementation manner, in the first aspect of the embodiment of the present invention, the training of the permission decision model to obtain the optimized permission decision model includes:

[0034] S41, using the cross entropy loss model, sums the cross entropy losses of all samples to obtain the cross entropy loss function;

[0035] The cross entropy loss expression is:

[0036]

[0037] Where Loss is the cross entropy loss, p is a probability distribution, and y is the binary encoding representation of the sample permission label. For the k-th category resource, when the sample permission belongs to the c-th category, y kc =1, otherwise y kc =0; M is the total number of resources, C is the total number of categories;

[0038] The cross entropy loss model is:

[0039]

[0040] Where N is the number of samples, y ikc is the true label of the cth category of the kth category resource of the i-th sample, p ikc is the probability that the i-th sample has the c-th type of permission in the k-th type of resource, Loss i is the cross entropy loss of the i-th sample, and L is the total loss value;

[0041] S42, calculating the gradient of the cross entropy loss function with respect to the parameters of the authority decision model;

[0042] S43, processing the gradient to obtain a first-order moment and a second-order moment;

[0043] S44, correcting the first-order moment and the second-order moment to obtain a corrected first-order moment and a corrected second-order moment;

[0044] S45, processing the modified first-order moment and the modified second-order moment to obtain parameter update information of the authority decision model;

[0045] S46, when the total loss value converges or reaches the preset number of training times, the parameter update information is processed to obtain an optimized authority decision model; otherwise, execute S42.

[0046] A second aspect of an embodiment of the present invention discloses a multi-resource flexible permission decision-making device, the device comprising:

[0047] Information acquisition module, used to obtain business system data information and business system authority attribute information;

[0048] The business system data information includes user basic information, operation behavior information, operation content information, environmental factor information and historical behavior information;

[0049] An information preprocessing module, configured to preprocess the business system data information to obtain preprocessed business system data information;

[0050] A model building module, configured to build a permission decision model based on the pre-processed business system data information and the permission attribute information of the business system;

[0051] A model training module, used to train the permission decision model to obtain an optimized permission decision model;

[0052] The elastic authority decision module uses the optimized authority decision model to process the data information of the actual running business system to obtain the user's elastic authority decision result.

[0053] As an optional implementation manner, in the second aspect of the embodiment of the present invention, preprocessing the business system data information to obtain preprocessed business system data information includes:

[0054] S21, performing data cleaning on the business system data information to obtain first business system data information;

[0055] S22, performing deduplication processing on the first business system data information to obtain second business system data information;

[0056] S23, performing missing value processing on the second business system data information to obtain third business system data information;

[0057] S24, encoding the third business system data information to obtain pre-processing business system data information.

[0058] As an optional implementation manner, in the second aspect of the embodiment of the present invention, the step of performing data cleaning on the business system data information to obtain the first business system data information includes:

[0059] S211, correcting the business system data information, removing erroneous information and incomplete information, and obtaining corrected business system data information;

[0060] S212: De-noise the modified business system data information to obtain first business system data information.

[0061] As an optional implementation manner, in the second aspect of the embodiment of the present invention, encoding the third business system data information to obtain pre-processed business system data information includes:

[0062] S241, converting the data information of the third business system in chronological order to obtain a time step sequence; the time step sequence includes non-numeric data and numeric data; the non-numeric data includes text data and category data;

[0063] S242, processing the time step sequence to obtain a preprocessed time step sequence;

[0064] S243, segmenting the preprocessing time step sequence to obtain segmentation data information;

[0065] S244: Encode the segmented data information to obtain pre-processing business system data information.

[0066] As an optional implementation manner, in the second aspect of the embodiment of the present invention, processing the time step sequence to obtain a preprocessed time step sequence includes:

[0067] S2421, performing data conversion on the text data to obtain word embedding data information;

[0068] S2422, converting the category data to obtain one-hot encoded data information;

[0069] S2423, performing normalization processing on the non-numeric data to obtain normalized data information;

[0070] S2424: Integrate the word embedding data information, the one-hot encoded data information, and the normalized data information to obtain a preprocessing time step sequence.

[0071] As an optional implementation manner, in the second aspect of the embodiment of the present invention, performing data conversion on the text data to obtain word embedding data information includes:

[0072] S24211, extracting keywords from the text data to obtain text keyword information;

[0073] S24212, converting the text keyword information to obtain word vector information;

[0074] S24213, performing cluster analysis on the word vector information to obtain word embedding data information.

[0075] As an optional implementation manner, in the second aspect of the embodiment of the present invention, the training of the permission decision model to obtain the optimized permission decision model includes:

[0076] S41, using the cross entropy loss model, sums the cross entropy losses of all samples to obtain the cross entropy loss function;

[0077] The cross entropy loss expression is:

[0078]

[0079] Where Loss is the cross entropy loss, p is a probability distribution, and y is the binary encoding representation of the sample permission label. For the k-th category resource, when the sample permission belongs to the c-th category, y kc =1, otherwise y kc =0; M is the total number of resources, C is the total number of categories;

[0080] The cross entropy loss model is:

[0081]

[0082] Where N is the number of samples, y ikc is the true label of the cth category of the kth category resource of the i-th sample, p ikc is the probability that the i-th sample has the c-th type of permission in the k-th type of resource, Loss i is the cross entropy loss of the i-th sample, and L is the total loss value;

[0083] S42, calculating the gradient of the cross entropy loss function with respect to the parameters of the authority decision model;

[0084] S43, processing the gradient to obtain a first-order moment and a second-order moment;

[0085] S44, correcting the first-order moment and the second-order moment to obtain a corrected first-order moment and a corrected second-order moment;

[0086] S45, processing the modified first-order moment and the modified second-order moment to obtain parameter update information of the authority decision model;

[0087] S46, when the total loss value converges or reaches the preset number of training times, the parameter update information is processed to obtain an optimized authority decision model; otherwise, execute S42.

[0088] A third aspect of the present invention discloses another flexible permission decision device for multiple resources, the device comprising:

[0089] a memory storing executable program code;

[0090] a processor coupled to the memory;

[0091] The processor calls the executable program code stored in the memory to execute part or all of the steps in the multi-resource flexible permission decision method disclosed in the first aspect of the embodiment of the present invention.

[0092] The fourth aspect of the present invention discloses a computer-storable medium, which stores computer instructions. When the computer instructions are called, they are used to execute some or all of the steps in the multi-resource elastic permission decision method disclosed in the first aspect of an embodiment of the present invention.

[0093] Compared with the prior art, the embodiments of the present invention have the following beneficial effects:

[0094] The present invention utilizes an optimized permission decision model to achieve refined permission division and dynamic permission allocation, significantly improving the security and flexibility of the system. The method of the present invention can effectively analyze and accumulate the evolution of user behavior over time and environmental factors, thereby accurately adjusting and granting permissions. This mechanism significantly reduces human configuration errors, improves management efficiency, and enhances the transparency of decisions by outputting probability values. The dynamic permission control function allows real-time response to changes in business needs and simplifies the permission update process without the need for complex code modifications or system redeployment. Integration with existing security frameworks not only improves the adaptability and security of the system, but also provides an efficient, scalable and easy-to-maintain permission management solution. BRIEF DESCRIPTION OF THE DRAWINGS

[0095] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0096] Figure 1 This is a flow chart of a method for flexible permission decision-making for multiple resources disclosed in an embodiment of the present invention;

[0097] Figure 2 This is a flow chart of another method for flexible permission decision-making for multiple resources disclosed in an embodiment of the present invention;

[0098] Figure 3 Schematic diagram of a flexible permission decision model based on a multi-layer long short-term memory network disclosed in an embodiment of the present invention;

[0099] Figure 4 Schematic diagram of the hidden layer of the long short-term memory network disclosed in an embodiment of the present invention;

[0100] Figure 5 This is a schematic diagram of the structure of a multi-resource flexible permission decision-making device disclosed in an embodiment of the present invention;

[0101] Figure 6 This is a structural diagram of another multi-resource oriented flexible permission decision device disclosed in an embodiment of the present invention. DETAILED DESCRIPTION

[0102] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making any creative efforts shall fall within the scope of protection of the present invention.

[0103] The terms "first," "second," and so on, in the description and claims of the present invention and the accompanying drawings are used to distinguish between different objects, not to describe a specific order. Furthermore, the terms "including," "having," and any variations thereof, are intended to cover non-exclusive inclusions. For example, a process, method, apparatus, product, or device comprising a series of steps or elements is not limited to the listed steps or elements but may optionally include steps or elements not listed, or may optionally include other steps or elements inherent to the process, method, product, or device.

[0104] References herein to "embodiments" mean that a particular feature, structure, or characteristic described in connection with the embodiments may be included in at least one embodiment of the present invention. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor does it constitute a separate or alternative embodiment that is mutually exclusive of other embodiments. It is understood, both explicitly and implicitly, by those skilled in the art that the embodiments described herein may be combined with other embodiments.

[0105] The present invention discloses a flexible permission decision method and device for multiple resources, the method comprising: obtaining business system data information and permission attribute information of the business system; the business system data information comprises basic information of the user, operation behavior information, operation content information, environmental factor information and historical behavior information; preprocessing the business system data information to obtain preprocessed business system data information; constructing a permission decision model based on the preprocessed business system data information and the permission attribute information of the business system; training the permission decision model to obtain an optimized permission decision model; using the trained permission decision model to process the actual running business system data information to obtain the user's flexible permission decision result. The integration of the method of the present invention with the existing security framework not only improves the adaptability and security of the system, but also provides an efficient, scalable and easy-to-maintain permission management solution. The following are detailed descriptions.

[0106] Example 1

[0107] See also Figure 1 , Figure 1 This is a flow chart of a multi-resource elastic permission decision method disclosed in an embodiment of the present invention. Figure 1 The described multi-resource oriented flexible permission decision method is applied to the field of computer security to implement permission control, which is not limited in the embodiments of the present invention. Figure 1 As shown, the multi-resource oriented elastic permission decision method may include the following operations:

[0108] S1, obtain business system data information and business system authority attribute information;

[0109] The business system data information includes user basic information, operation behavior information, operation content information, environmental factor information and historical behavior information;

[0110] S2, preprocessing the business system data information to obtain preprocessed business system data information;

[0111] S3, constructing an authority decision model based on the pre-processed business system data information and the authority attribute information of the business system;

[0112] S4, training the permission decision model to obtain an optimized permission decision model;

[0113] S5, using the optimized authority decision model, processing the actual operating business system data information to obtain the user's flexible authority decision result.

[0114] Optionally, preprocessing the business system data information to obtain preprocessed business system data information includes:

[0115] S21, performing data cleaning on the business system data information to obtain first business system data information;

[0116] S22, performing deduplication processing on the first business system data information to obtain second business system data information;

[0117] S23, performing missing value processing on the second business system data information to obtain third business system data information;

[0118] S24, encoding the third business system data information to obtain pre-processing business system data information.

[0119] Optionally, performing data cleaning on the business system data information to obtain the first business system data information includes:

[0120] S211, correcting the business system data information, removing erroneous information and incomplete information, and obtaining corrected business system data information;

[0121] The correction is the existing technology in this field and is not limited in this embodiment.

[0122] S212: De-noise the modified business system data information to obtain first business system data information.

[0123] Denoising the correction business system data information includes:

[0124] Perform time-frequency analysis on the data information of the correction business system, and the formula is:

[0125]

[0126] Where S(m,n) is the time-spectrum graph, x(t) represents the time domain signal, g(t) represents the window function, T represents the sliding window length, N represents the discrete Fourier transform length, m and n represent the frequency point and time of the time-spectrum graph respectively, L represents the signal length, i represents the signal sample point, and M represents the discrete Fourier transform length.

[0127] Set the initial threshold δ thThe target interval is [α, β], where 0≤α<β≤max{S(m,n)}, S(m,n) is the time-frequency spectrum;

[0128] Divide the target interval [α, β] into L equal parts;

[0129] The initial threshold δ th Set to α, according to The step size is incremented and iterated to obtain the threshold

[0130] Utilizing Thresholds Calculate the time-frequency spectrum after each iteration

[0131]

[0132] Among them, S(m,n) represents the original time spectrum, represents the time-frequency spectrum after filtering, a and b represent the time and frequency parameters in the threshold;

[0133] Calculate the difference ε between each iteration and the time spectrum obtained in the previous iteration i ,i=1,2,… is the number of iterations;

[0134] The difference ε i Perform curve fitting to obtain curve C. When curve C has an inflection point, the corresponding threshold is the optimal threshold;

[0135] The optimal threshold is used to perform optimal threshold filtering on the time-frequency spectrum S(m,n) to obtain a denoised time-frequency spectrum.

[0136] Performing an inverse time-frequency transform on the noise-reduced time-frequency spectrum to obtain first business system data information.

[0137] Optionally, encoding the third business system data information to obtain pre-processed business system data information includes:

[0138] S241, converting the data information of the third business system in chronological order to obtain a time step sequence; the time step sequence includes non-numeric data and numeric data; the non-numeric data includes text data and category data;

[0139] S242, processing the time step sequence to obtain a preprocessed time step sequence;

[0140] S243, segmenting the preprocessing time step sequence to obtain segmentation data information;

[0141] S244: Encode the segmented data information to obtain pre-processing business system data information.

[0142] Optionally, processing the time step sequence to obtain a preprocessed time step sequence includes:

[0143] S2421, performing data conversion on the text data to obtain word embedding data information;

[0144] S2422, converting the category data to obtain one-hot encoded data information;

[0145] S2423, performing normalization processing on the non-numeric data to obtain normalized data information;

[0146] S2424: Integrate the word embedding data information, the one-hot encoded data information, and the normalized data information to obtain a preprocessing time step sequence.

[0147] Optionally, performing data conversion on the text data to obtain word embedding data information includes:

[0148] S24211, extracting keywords from the text data to obtain text keyword information;

[0149] S24212, converting the text keyword information to obtain word vector information;

[0150] The method used to convert the text keyword information is a word embedding method, which is achieved by using the BERT model. The BERT model is a natural language processing model based on the Transformer architecture and was proposed by Google in 2018.

[0151] S24213, performing cluster analysis on the word vector information to obtain word embedding data information.

[0152] Optionally, the clustering analysis method is: using the VGG19 network to extract the features of the word vector information, and then using the agglomerative hierarchical clustering method to cluster the features output by each layer of the VGG19 network to obtain the clustering feature parameters of each word vector information. Agglomerative Hierarchical Clustering (AHC) has a bottom-up hierarchical tree structure. The algorithm first puts all the data on the first layer, and each data object is regarded as a minimum cluster. The similarity between different clusters is then calculated, and the two clusters with the greatest similarity are merged into a large cluster and placed on the second layer. As the number of layers continues to increase, the number of clusters continues to decrease until all the data is merged into one cluster or the number of clusters reaches a preset value.

[0153] Optional keyword extraction method is:

[0154] The text data is subjected to a lattice network construction, which is a prior art in the field. The node set of the lattice network is N = {n0, n1, ...}, the arc set is E = {e0, e1, ...}, and each node n i ∈N contains a time tag t(ni), arc e u→v represents the arc connecting node u to node v. Let the nodes in the keyword network be NS = {N0, N1, ...}, Represents the node N in the keyword network i Connect to node N j A set of arcs.

[0155] 1. Any n i ∈N i , n j ∈N i , by t(n i )<t(n j ) we can get i≤j.

[0156] 2. Any n i ∈N i , n j ∈N i , by t(n i )=t(n j ) we can get i=j.

[0157] 3. Any e u→v ∈E, if for u∈N i and v∈N j , e u→v Equivalent to a group Then i≤m≤n≤j. (Here n=m+1, e u→v The two endpoints belong to N m and N n . )

[0158] The word grid network is converted into a keyword network, and the generation algorithm is:

[0159] 1. Convert keywords into corresponding syllable strings: K1…K M (M is the number of syllables of the keyword.) Traverse all nodes N in the Lattice network and find node n that matches K1. k , set as

[0160] 2. As the end point, search for the nearest node n in reverse time order. k-1If n k-1 and There is no arc between them, then n k-1 Also belongs to Continue to search k-1 Otherwise, the search stops.

[0161] 3. As the starting point, search for similar nodes n in chronological order k+1 If n k+1 and There is no arc between them, then n k+1 belong Continue to search k+1 Otherwise, the search stops.

[0162] 4. For e k→k+1 belong n k+1 belong

[0163] 5. All included in Arc e in k→k+1 Form a keyword confusion network.

[0164] 6. For each arc If u belongs to N s , n i Belongs to N t When t=s+1, belong otherwise, belong (s+1≤n≤t).

[0165]

[0166]

[0167] Where w(l) and w(e) are the words corresponding to arcs l and e, sim(·,·) refers to the similarity between the two words. It refers to the arc and the normalized time overlap of e. In addition, each node n in the Lattice i The time stamp t(ni) contained in ∈N will be used as a constraint to determine the termination of the search.

[0168] The data normalization method is used to confirm the keywords. First, the linguistic probability likelihood score of each candidate is normalized:

[0169]

[0170] Where Value is the set of linguistic scores in the keyword network; minValue and maxValue are the minimum and maximum values ​​in the set, respectively; x is the score before normalization; and y is the score after normalization. The sum of the scores is then calculated and marked as the final score of the arc in the keyword network.

[0171] In each keyword network, select the arc candidate with the highest score and determine whether it is a keyword. If so, output the keyword and time stamp; otherwise, skip and proceed to the next keyword network. This completes keyword detection.

[0172] Optionally, the training of the permission decision model to obtain an optimized permission decision model includes:

[0173] S41, using the cross entropy loss model, sums the cross entropy losses of all samples to obtain the cross entropy loss function;

[0174] The cross entropy loss expression is:

[0175]

[0176] Where Loss is the cross entropy loss, p is a probability distribution, and y is the binary encoding representation of the sample permission label. For the k-th category resource, when the sample permission belongs to the c-th category, y kc =1, otherwise y kc =0; M is the total number of resources, C is the total number of categories;

[0177] The cross entropy loss model is:

[0178]

[0179] Where N is the number of samples, y ikc is the true label of the cth category of the kth category resource of the i-th sample, p ikc is the probability that the i-th sample has the c-th type of permission in the k-th type of resource, Loss i is the cross entropy loss of the i-th sample, and L is the total loss value;

[0180] S42, calculating the gradient of the cross entropy loss function with respect to the parameters of the authority decision model;

[0181] S43, processing the gradient to obtain a first-order moment and a second-order moment;

[0182] S44, correcting the first-order moment and the second-order moment to obtain a corrected first-order moment and a corrected second-order moment;

[0183] S45, processing the modified first-order moment and the modified second-order moment to obtain parameter update information of the authority decision model;

[0184] S46, when the total loss value converges or reaches the preset number of training times, the parameter update information is processed to obtain an optimized authority decision model; otherwise, execute S42.

[0185] It can be seen that the present invention uses an optimized permission decision model to achieve fine-grained permission division and dynamic permission allocation, significantly improving the security and flexibility of the system. The method of the present invention can effectively analyze and accumulate the evolution of user behavior over time and environmental factors, so as to accurately adjust and grant permissions. This mechanism greatly reduces human configuration errors, improves management efficiency, and enhances the transparency of decisions by outputting probability values. The dynamic permission control function allows real-time response to changes in business needs and simplifies the permission update process without the need for complex code modifications or system redeployment. Integration with existing security frameworks not only improves the adaptability and security of the system, but also provides an efficient, scalable and easy-to-maintain permission management solution.

[0186] Example 2

[0187] See also Figure 2 , Figure 2 This is a flow chart of another method for elastic permission decision-making for multiple resources disclosed in an embodiment of the present invention. Figure 2 The described multi-resource oriented flexible permission decision method is applied to the field of computer security to implement permission control, which is not limited in the embodiments of the present invention. Figure 2 As shown, the multi-resource oriented elastic permission decision method may include the following operations:

[0188] 1. Obtain business system data information, and clean and encode the data.

[0189] When implementing this, it's first necessary to collect a large amount of user behavior data, including user characteristics, operation actions, operation content, environmental factors, and historical behavior. Based on business needs and data characteristics, the permission control training dataset uses internal enterprise data to extract useful features from the raw data, including the following:

[0190] User's basic information (such as age, gender, position, etc.),

[0191] Operation behavior (such as login time, operation frequency, etc.),

[0192] Operation content (such as the type of file accessed, the range of data modified, etc.),

[0193] Environmental factors (such as device type, network environment, etc.)

[0194] Historical behavior (such as past permission application records, violation records, etc.).

[0195] The data is then preprocessed, including cleaning, deduplication, and missing value processing, to facilitate subsequent feature engineering and model training. The data preprocessing steps and their implementation methods are as follows:

[0196] 1) Data cleaning

[0197] The goal is to remove errors, incompleteness, inaccuracies, irrelevant parts, or noise from the dataset. This includes correcting obvious spelling or typos, standardizing text fields, and identifying and handling outliers.

[0198] 2) Deduplication

[0199] The goal is to identify and remove duplicate records from a dataset. Implementation methods involve using database queries (such as `DELETE DUPLICATES` in SQL) or programming tools (such as the `drop_duplicates()` function in the Pandas library).

[0200] 3) Missing value processing

[0201] The purpose is to handle missing values ​​in the data, which may be values ​​that are not recorded due to various reasons. The processing methods include:

[0202] Delete rows or columns with missing values, fill missing values ​​with specific values ​​such as mean, median, mode, or fixed values, infer missing values ​​based on other values, build models using other variables to predict missing values, etc.

[0203] 4) Data encoding

[0204] The user's behavior and environmental characteristics need to be encoded into a format that the LSTM can understand, and then the model can predict the user's permission requirements based on this encoded data. When encoding training data into LSTM input, this step includes the following:

[0205] The training data is converted into a sequence of time steps in chronological order.

[0206] Convert non-numeric data to numeric form so that LSTM can process it. This includes converting text data into word embeddings and converting categorical data into one-hot encoding.

[0207] Standardize or normalize numerical data to ensure that all features are in the same numerical range. For the feature vector X = [x1, x2, ..., x n], and its standardization formula is: Here, μ is the sample mean and σ is the sample standard deviation.

[0208] Divide the sequence data into small batches to fit within the model's input size and memory constraints.

[0209] The encoder encodes the input sequence into a fixed-length hidden representation. The encoder's LSTM layer processes the time steps of the input sequence and outputs a hidden state that summarizes the entire sequence information. The specific steps are as follows:

[0210] User information code:

[0211] Age: normalize it to the range [0,1].

[0212] Gender: Gender is categorical data and is converted using one-hot encoding, with male [1,0] and female [0,1].

[0213] Position: Use one-hot encoding for conversion. Advanced [1, 0, 0], Intermediate [0, 1, 0], Beginner [0, 0, 1].

[0214] Role information encoding: Use one-hot encoding for conversion, administrator [1,0,0], ordinary user [0,1,0], guest [0,0,1].

[0215] Environmental information encoding: Mapping the 24 hours of a day to the range [0,1] to capture periodic patterns at different times of the day.

[0216] Historical behavior encoding: Login counts and file access counts are normalized or calibrated to the same [0,1] range.

[0217] 2. Build an authority decision model based on the acquired business system data information and the authority attributes of the business system.

[0218] Based on the characteristics of the training data obtained in step 1 and the requirements for fine-grained elastic permissions for multiple resources, a parallel LSTM model is designed, such as Figure 3 As shown, the output of the multi-resource parallel LSTM elastic permission model is designed to be fully connected, with a sigmoid activation function. The output for each resource is a vector whose elements represent the decision probability of each sub-permission being executable. For example, y1 is the permission probability vector for resource 1, and the elements of the vector represent the probability of the corresponding sub-operation permission being executable, such as the probability of obtaining read, write, execute permissions, or reading or modifying permissions for a specific paragraph or line in a text.

[0219] Hidden layer: In the hidden layer of LSTM, such as Figure 4As shown in the figure, each time step receives an input and the cell state from the previous time step. Then, through a series of gating mechanisms (including a forget gate, input gate, and output gate) and cell state updates, the cell state and hidden state for the current time step are calculated and output. The value of the forget gate is obtained by passing the current input and the hidden state from the previous time step through a fully connected layer and applying the sigmoid function. This value is between 0 and 1, with 0 indicating complete forgetfulness and 1 indicating complete retention.

[0220] The formula of LSTM is as follows:

[0221] Forget gate value: f t =σ(W f ·[h t-1 ,x t ]+b f )

[0222] Candidate values:

[0223] Input gate value: i t =σ(W i ·[h t-1 ,x t ]+b i )

[0224] Cell status update:

[0225] Output gate value: o t =σ(W o ·[h t-1 ,x t ]+b o )

[0226] Hide status update:h t =o t *tanh(c t )

[0227] Where W and b are the learnable weights between output and input, h t-1 is the hidden state of the previous moment, x t is the current input, σ is the sigmoid function, and tanh is the hyperbolic tangent function. The initial values ​​h0 and c0 are set to 0 or 1.

[0228] In LSTM, deciding which new information to store in memory cells is a crucial process. This process involves two main components: the input gate and the tanh layer. The input gate is responsible for filtering and determining which parts of the memory cell will be updated, thereby controlling the flow of information. At the same time, a tanh layer generates a new candidate value vector This vector contains new information that may be incorporated into the memory cell. The calculation of these two components depends on the input of the current time step and the hidden state passed down from the previous time step, which enables LSTM to effectively capture long-term dependencies when processing sequential data and update its internal state in a timely manner.

[0229] 3. Train the designed permission decision model based on the cross entropy and Adam optimization algorithm to obtain the trained permission decision model. This includes the following:

[0230] Cross-entropy is used as the loss function of the network. The cross-entropy loss function measures the difference between the probability distribution predicted by the model and the probability distribution of the actual label. The cross-entropy loss function for fine-grained permission classification is calculated using the following formula:

[0231]

[0232] where p kc is a probability distribution, and y is the binary encoding representation of the sample permission label. For the k-th resource, when the sample permission belongs to the c-th category, y kc =1, otherwise y kc =0; M is the total number of resources, and C is the total number of categories.

[0233] In order to get the average loss of a batch, you need to sum the losses of all samples and then divide it by the number of samples N, that is:

[0234]

[0235] Where N is the number of samples, y ikc is the true label of the cth category of the kth category resource of the i-th sample, p ikc is the probability that the i-th sample has the c-th type of permission in the k-th type of resource, Loss i is the cross entropy loss of the i-th sample, and L is the total loss value;

[0236] In order to minimize the cross entropy loss function, it is necessary to calculate the gradient of the loss function with respect to the model parameters and update the parameters using the Adam optimization algorithm. This includes the following:

[0237] Calculate gradient: Calculate the gradient of the cross entropy loss function of the current batch of data with respect to the model parameters.

[0238] Update the first-order moment estimate: According to the Adam algorithm, update the stored first-order moment (the exponentially weighted average of the gradient)

[0239] m t =β1·m t-1 +(1-β1)·dw

[0240] where dw is the current gradient, β1 is the exponential decay rate of the first-order moment estimate between 0 and 1, and m t is the first-order moment at time t, m t-1 is the first-order moment at time t-1.

[0241] Update the second-order moment estimate: Update the second-order moment (exponentially weighted average of the squared gradient) v t =β2·v t-1 +(1-β2)·dw 2 , β2 is the exponential decay rate of the second-order moment estimate between 0 and 1, v t is the second-order moment at time t, v t-1 is the second-order moment at time t-1.

[0242] Corrected Deviation: Calculates the first-order moment after deviation correction and second-order moment

[0243] Update model parameters: Finally, use the ratio of the corrected first-order moment to the second-order moment to update the model parameters Where α is the learning rate, ∈ is a very small number to prevent division by zero, and θ t is the model parameter at time t, θ t+1 is the model parameter at time t+1.

[0244] Iterative training: Repeat the above process until the loss value converges or the preset number of training times is reached.

[0245] Verification and testing: Test the performance of the model trained in step 3 on an independent validation set to evaluate its generalization ability. Conduct unit testing, integration testing, and performance testing to ensure the accuracy and robustness of the model. For fine-grained permission classification, effective testing is a key step in ensuring system security and reliability. The specific implementation method is as follows:

[0246] 1) Unit testing: This focuses on the smallest testable unit, typically a single function or method. For fine-grained permission classification, testing can be performed on the logical unit of permission checking, for example, verifying that a specific permission check function correctly identifies the user's permission level. The correctness of the code execution path can be verified by simulating scenarios with different user permissions.

[0247] 2) Integration testing: Integration testing focuses on how well multiple components or modules work together. In a permissions system, permission control services are combined with other services such as user authentication and business logic for comprehensive testing. The goal of this testing is to confirm that these integrated services work together to achieve correct permission control.

[0248] 3) Performance Testing: Performance testing evaluates system performance under high load, including response time and stability. For permission control systems, performance testing can simulate scenarios where multiple users are simultaneously requesting permission verification, ensuring that the system does not experience bottlenecks or failures due to excessive load in the actual operating environment.

[0249] Deployment and Monitoring: Deploy the parallel LSTM model trained in steps 2 and 3 to the actual access control system to provide real-time access control services. Implement a monitoring mechanism to track the model's performance and decision-making process. Manual intervention and adjustments are performed for abnormal or unreasonable access allocations.

[0250] 4. Collect new data based on actual operations, adjust the threshold for permissions, and continuously update and optimize the model. Through the feedback mechanism, respond to new security threats and business changes to maintain the effectiveness and accuracy of the model.

[0251] It can be seen that the present invention demonstrates an advanced permission management framework that integrates long short-term memory networks (LSTM), which is designed to accurately handle dynamic permission decision-making problems in multi-resource environments. By serializing business system entities such as users, roles, environmental information, and historical behavior data into time series data points, this framework constructs an efficient parallel LSTM network model, which can not only output fine-grained permission decisions for various types of resources, but also accurately capture and reflect the complex interactive relationships between entities and resources that evolve over time, thereby generating a comprehensive permission decision guidance network. In addition, the model enhances the system administrator's understanding of the basis for model decisions by providing a probability distribution perspective, achieving a high degree of transparency and explainability. Overall, the present invention provides a smart permission management solution for business systems in a multi-resource context that is both secure and reliable and has explanatory capabilities, significantly improving compliance and operational efficiency.

[0252] Example 3

[0253] See also Figure 5 , Figure 5 This is a flow chart of a multi-resource flexible authority decision-making device disclosed in an embodiment of the present invention. Figure 5 The described flexible permission decision device for multiple resources is applied to the field of computer security to implement permission control, which is not limited in the embodiment of the present invention. Figure 5 As shown, the multi-resource oriented flexible permission decision-making device may include the following operations:

[0254] S301, an information acquisition module, used to acquire business system data information and business system authority attribute information;

[0255] The business system data information includes user basic information, operation behavior information, operation content information, environmental factor information and historical behavior information;

[0256] S302, an information preprocessing module, configured to preprocess the business system data information to obtain preprocessed business system data information;

[0257] S303, a model building module, configured to build a permission decision model based on the pre-processed business system data information and the permission attribute information of the business system;

[0258] S304, a model training module, configured to train the authority decision model to obtain an optimized authority decision model;

[0259] S305, a flexible authority decision module is used to process the data information of the actual running business system using the trained authority decision model to obtain the user's flexible authority decision result.

[0260] Example 4

[0261] See also Figure 6 , Figure 6 This is a flow chart of another flexible permission decision-making device for multiple resources disclosed in an embodiment of the present invention. Figure 6 The described flexible permission decision device for multiple resources is applied to the field of computer security to implement permission control, which is not limited in the embodiment of the present invention. Figure 6 As shown, the multi-resource oriented flexible permission decision-making device may include the following operations:

[0262] A memory 401 storing executable program code;

[0263] a processor 402 coupled to the memory 401;

[0264] The processor 402 calls the executable program code stored in the memory 401 to execute the steps of the multi-resource oriented flexible permission decision method described in the first and second embodiments.

[0265] Example 5

[0266] An embodiment of the present invention discloses a computer-readable storage medium storing a computer program for electronic data exchange, wherein the computer program enables a computer to execute the steps of the multi-resource flexible permission decision-making method described in the first and second embodiments.

[0267] The device embodiments described above are merely illustrative. Modules described as separate components may or may not be physically separate, and components shown as modules may or may not be physical modules, i.e., they may be located in one place or distributed across multiple network modules. Some or all of the modules may be selected based on actual needs to achieve the objectives of the present embodiment. Persons of ordinary skill in the art will be able to understand and implement the present invention without inventive effort.

[0268] Through the detailed description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus the necessary general hardware platform, or of course, by means of hardware. Based on this understanding, the above technical solution, in essence, or the portion that contributes to the prior art, can be embodied in the form of a software product, which can be stored in a computer-readable storage medium, including a read-only memory (ROM), a random access memory (RAM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), a one-time programmable read-only memory (OTPROM), an electronically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, magnetic disk storage, magnetic tape storage, or any other computer-readable medium capable of carrying or storing data.

[0269] Finally, it should be noted that the method and device for flexible permission decision-making for multiple resources disclosed in the embodiments of the present invention are only preferred embodiments of the present invention, and are only used to illustrate the technical solutions of the present invention, rather than to limit them. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that the technical solutions described in the aforementioned embodiments can still be modified, or some of the technical features therein can be replaced by equivalents. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.

Claims

1. A multi-resource oriented elastic permission decision method, characterized in that: The method comprises: S1, obtain business system data information and business system authority attribute information; The business system data information includes user basic information, operation behavior information, operation content information, environmental factor information and historical behavior information; S2, preprocessing the business system data information to obtain preprocessed business system data information; S3, constructing an authority decision model based on the pre-processed business system data information and the authority attribute information of the business system; S4, training the permission decision model to obtain an optimized permission decision model, including: S41, using the cross entropy loss model, sums the cross entropy losses of all samples to obtain the cross entropy loss function; The cross entropy loss expression is: Where Loss is the cross entropy loss, p is a probability distribution, and y is the binary encoding representation of the sample permission label. For the k-th category resource, when the sample permission belongs to the c-th category, y kc =1, otherwise y kc =0; M is the total number of resources, C is the total number of categories; The cross entropy loss model is: Where N is the number of samples, y ikc is the true label of the cth category of the kth category resource of the i-th sample, p ikc is the probability that the i-th sample has the c-th type of permission in the k-th type of resource, Loss i is the cross entropy loss of the i-th sample, and L is the total loss value; S42, calculating the gradient of the cross entropy loss function with respect to the parameters of the authority decision model; S43, processing the gradient to obtain a first-order moment and a second-order moment; S44, correcting the first-order moment and the second-order moment to obtain a corrected first-order moment and a corrected second-order moment; S45, processing the modified first-order moment and the modified second-order moment to obtain parameter update information of the authority decision model; S46, when the total loss value converges or reaches the preset number of training times, processing the parameter update information to obtain an optimized authority decision model; otherwise, executing S42; S5, using the optimized authority decision model, processing the actual operating business system data information to obtain the user's flexible authority decision result.

2. The multi-resource flexible permission decision-making method according to claim 1 is characterized in that: The preprocessing of the business system data information to obtain preprocessed business system data information includes: S21, performing data cleaning on the business system data information to obtain first business system data information; S22, performing deduplication processing on the first business system data information to obtain second business system data information; S23, performing missing value processing on the second business system data information to obtain third business system data information; S24, encoding the third business system data information to obtain pre-processing business system data information.

3. The multi-resource flexible permission decision-making method according to claim 2 is characterized in that: The step of performing data cleaning on the business system data information to obtain first business system data information includes: S211, correcting the business system data information, removing erroneous information and incomplete information, and obtaining corrected business system data information; S212: De-noise the modified business system data information to obtain first business system data information.

4. The multi-resource flexible permission decision-making method according to claim 2 is characterized in that: The encoding of the third business system data information to obtain pre-processed business system data information includes: S241, converting the data information of the third business system in chronological order to obtain a time step sequence; the time step sequence includes non-numeric data and numeric data; the non-numeric data includes text data and category data; S242, processing the time step sequence to obtain a preprocessed time step sequence; S243, segmenting the preprocessing time step sequence to obtain segmentation data information; S244: Encode the segmented data information to obtain pre-processing business system data information.

5. The multi-resource flexible permission decision-making method according to claim 4 is characterized in that: The processing of the time step sequence to obtain a preprocessed time step sequence includes: S2421, performing data conversion on the text data to obtain word embedding data information; S2422, converting the category data to obtain one-hot encoded data information; S2423, normalizing the non-numeric data to obtain normalized data information; S2424: Integrate the word embedding data information, the one-hot encoded data information, and the normalized data information to obtain a preprocessing time step sequence.

6. The multi-resource flexible permission decision-making method according to claim 5, characterized in that: The performing data conversion on the text data to obtain word embedding data information includes: S24211, extracting keywords from the text data to obtain text keyword information; S24212, converting the text keyword information to obtain word vector information; S24213, performing cluster analysis on the word vector information to obtain word embedding data information.

7. A flexible permission decision device for multiple resources, characterized in that: The device comprises: Information acquisition module, used to obtain business system data information and business system authority attribute information; The business system data information includes user basic information, operation behavior information, operation content information, environmental factor information and historical behavior information; An information preprocessing module, configured to preprocess the business system data information to obtain preprocessed business system data information; A model building module, configured to build a permission decision model based on the pre-processed business system data information and the permission attribute information of the business system; The model training module is used to train the permission decision model to obtain an optimized permission decision model, including: S41, using the cross entropy loss model, sums the cross entropy losses of all samples to obtain the cross entropy loss function; The cross entropy loss expression is: Where Loss is the cross entropy loss, p is a probability distribution, and y is the binary encoding representation of the sample permission label. For the k-th category resource, when the sample permission belongs to the c-th category, y kc =1, otherwise y kc =0; M is the total number of resources, C is the total number of categories; The cross entropy loss model is: Where N is the number of samples, y ikc is the true label of the cth category of the kth category resource of the i-th sample, p ikc is the probability that the i-th sample has the c-th type of permission in the k-th type of resource, Loss i is the cross entropy loss of the i-th sample, and L is the total loss value; S42, calculating the gradient of the cross entropy loss function with respect to the parameters of the authority decision model; S43, processing the gradient to obtain a first-order moment and a second-order moment; S44, correcting the first-order moment and the second-order moment to obtain a corrected first-order moment and a corrected second-order moment; S45, processing the modified first-order moment and the modified second-order moment to obtain parameter update information of the authority decision model; S46, when the total loss value converges or reaches the preset number of training times, processing the parameter update information to obtain an optimized authority decision model; otherwise, executing S42; The elastic authority decision module is used to process the data information of the actual running business system using the optimized authority decision model to obtain the user's elastic authority decision result.

8. A flexible permission decision device for multiple resources, characterized in that: The device comprises: a memory storing executable program code; a processor coupled to the memory; The processor calls the executable program code stored in the memory to execute the multi-resource flexible permission decision method according to any one of claims 1 to 6.

9. A computer storable medium, characterized in that The computer storable medium stores computer instructions, and when the computer instructions are called, they are used to execute the multi-resource oriented flexible permission decision method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Dynamic authority control method, system and device and storage medium

    CN116738391A

  • Authority change method, system and device and storage medium

    CN116881898A