A user data management system and method based on data analysis
By analyzing historical tasks and user operation paths and dynamically adjusting user permissions, the problem of excessive allocation and slow adjustment of permissions in the traditional RBAC model is solved, and more accurate and efficient permission management is achieved.
Patent Information
- Application Number
- CN202510059252.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-15
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2045-01-15
AI Technical Summary
The role-based access control (RBAC) model of traditional user data management systems can easily lead to users gaining too much permissions, increasing the risk of data leakage, and the permission adjustment process is slow and unable to respond to task changes in a timely manner.
By collecting historical tasks and user data, extracting task characteristics and operation paths, calculating user permission scope indicators, establishing a mapping relationship between tasks and permissions, and dynamically adjusting user permissions to match real-time task requirements.
It realizes more accurate permission allocation, avoids excessive permission allocation, ensures data security, and improves the efficiency and response speed of permission management.
Smart Images

Figure CN119475300B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data management, and in particular to a user data management system and method based on data analysis. Background Art
[0002] With the continuous development of information technology and the advancement of enterprise digital transformation, the amount of data generated and processed by enterprises in daily operations has increased dramatically, involving more and more sensitive data types, including customer data, financial data, employee information, etc. These data usually require strict access control to prevent unauthorized access or abuse, while ensuring that relevant personnel can access the required information only when necessary. Therefore, how to effectively manage user data permissions and avoid excessive allocation of permissions and data leakage has become a key issue in enterprise information security management.
[0003] Traditional user data management systems are mostly based on the role-based access control (RBAC) model, which means that users are assigned predefined roles and permissions are assigned to each role. Although this model can simply and effectively assign permissions to employees in different positions, it has some obvious limitations. Specifically, since roles usually correspond to a relatively broad scope of responsibilities, traditional RBAC systems can easily lead to some users obtaining too many permissions. For example, a user may be granted permission to access a large amount of sensitive data, but in fact the user's work tasks only involve a part of the data. This excessive authorization not only increases the risk of data leakage, but also provides opportunities for data abuse. In addition, in traditional RBAC systems, changes in user permissions are usually manually configured, and the permission adjustment process is relatively slow. Once the task changes, or when a project team member needs to temporarily access a specific resource, the permissions may not be adjusted in time, resulting in some users not being able to access the required files or resources in time, affecting work efficiency. Summary of the invention
[0004] The object of the present invention is to provide a user data management system and method based on data analysis to solve the problems raised in the above background technology.
[0005] In order to solve the above technical problems, the present invention provides the following technical solutions:
[0006] A user data management method based on data analysis comprises the following steps:
[0007] Step S100. Collect the historical task list, extract the corresponding historical task features for each historical task in the historical task list, and divide the historical tasks according to the historical task features, thereby dividing them into several historical task types, and construct a corresponding historical task data set for each historical task type;
[0008] Step S200. Collect historical user data and associate the historical user data with corresponding historical tasks; analyze the historical user data corresponding to each historical task, extract the corresponding historical task operation path, and calculate the user authority range index based on the historical task operation path, so as to obtain the mapping relationship between the historical task and the user authority range index;
[0009] Step S300. Obtain a real-time task list, extract real-time task features for each real-time task in the real-time task list, analyze the correlation between the real-time task features and the historical task features, and thus obtain corresponding correlation indicators;
[0010] Step S400. Obtain the user authority range of the real-time task based on the correlation index; if the real-time task matches the historical task type, identify the user authority range index corresponding to the real-time task based on the matching result, thereby obtaining the user authority range corresponding to the real-time task; if the real-time task does not match the historical task type, output notification information to relevant personnel, and the relevant personnel assign the corresponding user authority range to the real-time task.
[0011] Furthermore, step S100 includes:
[0012] S101. Collect a list of historical tasks within a selected time period, wherein the list of historical tasks records the descriptive information of all historical tasks within the selected time period, such as the task name, task objectives, and data types involved in the tasks, and each historical task corresponds to a unique data number; for each historical task in the list of historical tasks, extract the corresponding historical task features, and vectorize the extracted historical task features to obtain a historical task feature vector Fi with a unified format, and Fi=[fi1,fi2,...,fin], wherein Fi represents the historical task feature vector of the i-th historical task in the list of historical tasks within the selected time period, and i represents the historical task data number in the list of historical tasks within the selected time period; fi1 represents the first eigenvalue of the historical task feature vector Fi, fi2 represents the second eigenvalue of the historical task feature vector Fi, and so on, fin represents the n-th eigenvalue of the historical task feature vector Fi;
[0013] S102. Summarize the historical task feature vectors corresponding to all historical tasks in the historical task list, and use the DBSCAN clustering algorithm to divide the historical tasks into different clusters according to the corresponding historical task feature vectors. Each cluster represents a historical task type, and the number of clusters is equal to the number of historical task types in the historical task list; label each historical task type with a unique type code, and summarize the historical task feature vectors of historical tasks of the same task type to form a historical task data set Am, where m represents the data number of the historical task type.
[0014] Furthermore, the DBSCAN clustering algorithm is used to divide historical tasks into different clusters according to the corresponding historical task feature vectors. The specific contents are as follows:
[0015] For each historical task feature vector Fi, calculate the Euclidean distance d(Fi,Fj) between it and the historical task feature vectors Fj corresponding to other historical tasks in the historical task list. The specific calculation formula is:
[0016] d(Fi,Fj)={∑a∈[1,n],(fia-fja) 2}^(1 / 2);
[0017] Wherein, fia represents the ath eigenvalue in the historical task feature vector Fi, fja represents the ath eigenvalue in the historical task feature vector Fj, and a is a positive integer from 1 to n; the Euclidean distances d(Fi,Fj) between the historical task feature vector Fi and the historical task feature vector Fj corresponding to other historical tasks in the historical task list are summarized, arranged in ascending order, and the values corresponding to the first k Euclidean distances are selected to form the k-nearest neighbor distances of the historical task feature vector Fi; according to the k-nearest neighbor distances of the historical task feature vector Fi, a k-distance graph is drawn, in which the x-axis represents the index of the data point and the y-axis represents the k-nearest neighbor distance of the corresponding point; the data points are connected in sequence according to the index order of the data points to obtain a curve, and the Euclidean distance value corresponding to the first inflection point on the curve is the ε value; the minimum number of neighborhood points MinPts is defined as M. When the feature dimension is low, such as the task feature vector dimension is 2 or 3, MinPts can be selected as 2 or 4; if the feature dimension is high (for example, dozens of dimensions), MinPts=10 or higher can be considered;
[0018] For each historical task feature vector Fi, if the Euclidean distance of its k-nearest neighbor is less than or equal to ε, and the number of points contained in the neighborhood of the point is at least M, then the historical task feature vector Fi is a core point; if the historical task feature vector Fi is not a core point, but the ε neighborhood of the historical task feature vector Fi contains at least one core point, then the historical task feature vector Fi is a boundary point; if the historical task feature vector Fi is neither a core point nor a boundary point, then the historical task feature vector Fi is a noise point; for the historical task feature vector Fi identified as a core point, the historical task feature vector F The cluster where i is located is marked as a new cluster, denoted as cluster C; starting from the core point historical task feature vector Fi, find the neighborhood points of the historical task feature vector Fi, that is, all points in the ε neighborhood; add these neighborhood points to cluster C, if some of the neighborhood points are also core points, continue to expand cluster C from these core points; if the clusters extended from different core points have intersections, merge the two clusters into a large cluster; a boundary point belongs to a cluster if it belongs to the neighborhood of a core point, and the core point has been marked as part of the cluster; a boundary point does not belong to the neighborhood of any core point, then it is marked as a noise point.
[0019] Further, step S200 includes:
[0020] S201. Collect historical user data within a selected time period, wherein the historical user data refers to operation data generated by a user performing a historical task in a historical task list within the selected time period; extract the data number of the executed historical task from the historical user data, and associate the corresponding historical task feature vector according to the data number, thereby forming an associated data group of the historical user data and the historical task;
[0021] S202. For each associated data group, extract the corresponding historical task operation path Pi according to the corresponding historical user data, and Pi={(s1,b1),(s2,b2),...,(sk,bk)}, where Pi represents the historical task operation path of the i-th historical task in the historical task list of the user within the selected time period; s1 in (s1,b1) represents the operation interface of the user at the first step, and b1 represents the action performed by the user in the operation interface s1, such as clicking a button, entering a field, etc.; s2 in (s2,b2) represents the operation interface of the user at the second step, and b2 represents the action performed by the user in the operation interface s2; and so on, sk in (sk,bk) represents the operation interface of the user at the k-th step, bk represents the action performed by the user in the operation interface sk, and k represents the length of the operation path, that is, the total number of actions performed by the user when performing the historical task;
[0022] S203. According to the historical task operation path Pi, combined with the preset user permission set B, calculate the permission coverage index Cu(Pi), and Cu(Pi)=N(Pi) / N(B), where N(Pi) is the number of user permissions corresponding to the historical task operation path Pi in the user permission set B, and N(B) represents the number of user permissions in the preset user permission set B; calculate the diversity index Du(Pi), and Du(Pi)=N(Pi) / k; according to the permission coverage index Cu(Pi) and the diversity index Du(Pi), calculate the user permission range index Iu(Pi), and Iu(Pi)=w1·Cu(Pi)+w2·Du(Pi), where w1 and w2 represent weight coefficients, and w1+w2=1; summarize all historical task operation paths, and perform one-to-one mapping with the corresponding user permission range indicators, so as to establish a mapping relationship between historical tasks and user permission range indicators.
[0023] Furthermore, step S300 includes:
[0024] S301. Get a real-time task list, analyze each real-time task in the real-time task list in accordance with the analysis method of historical tasks, extract real-time task features from the real-time task, and form a real-time task feature vector Gh, where h represents the real-time task data number in the real-time task list;
[0025] S302. Calculate the Euclidean distance d(Gh, Cm) between the real-time task feature vector Gh and the core point Cm of the historical task type in the historical task list in sequence, and select the Euclidean distance value corresponding to the core point cluster C_min with the smallest distance to the real-time task feature vector Gh as the relevance index Rh of the real-time task.
[0026] Furthermore, step S400 includes:
[0027] S401. According to the relevance index Rh of the real-time task, compare the relevance index Rh with the ε value of the corresponding core point cluster C_min; if Rh is less than or equal to ε, it means that the real-time task matches the historical task type, and the historical task type is the historical task type corresponding to the core point cluster C_min; arrange the user authority range indicators in the historical task type of the core point cluster C_min in ascending order, and define the user authority range corresponding to the smallest user authority range indicator as the initial user authority range of the current real-time task;
[0028] S402. Acquire the real-time user data corresponding to the real-time task, obtain the real-time task operation path P'i according to the real-time user data, and obtain all the operation interface sequences S' of the executed steps of the current real-time task based on the real-time task operation path P'i, and S=[s'1,s'2,...,s'e], wherein s'1 represents the operation interface of the user at the first step, s'2 represents the operation interface of the user at the second step, and so on, s'e represents the operation interface of the user at the e-th step; and the operation interface of s'e is the predicted operation interface, which is predicted based on the last executed action b'e-1 of the operation interface of s'e-1; compare the operation interface sequence S with the operation interface sequence S corresponding to the historical tasks of the core point cluster C_min in turn, if the comparison results are completely consistent, adjust the user authority range of the current real-time task according to the corresponding historical tasks; if Rh is greater than ε, it means that the real-time task does not match the historical task type, output notification information to relevant personnel, and the relevant personnel assign the corresponding user authority range to the real-time task.
[0029] A user data management system based on data analysis, comprising: a historical task data processing module, a historical user data analysis module, a real-time task feature analysis module and a real-time task authority management module;
[0030] The historical task data processing module collects the historical task list, extracts the corresponding historical task features for each historical task in the historical task list, and divides the historical tasks according to the historical task features, thereby dividing them into several historical task types, and constructs a corresponding historical task data set for each historical task type;
[0031] The historical user data analysis module collects historical user data and associates the historical user data with corresponding historical tasks; analyzes the historical user data corresponding to each historical task, extracts the corresponding historical task operation path, and calculates the user authority range index based on the historical task operation path, thereby obtaining a mapping relationship between historical tasks and user authority range indicators;
[0032] The real-time task feature analysis module obtains the real-time task list, extracts the real-time task features for each real-time task in the real-time task list, and analyzes the correlation between the real-time task features and the historical task features, thereby obtaining corresponding correlation indicators;
[0033] The real-time task authority management module obtains the user authority range of the real-time task based on the correlation index; if the real-time task matches the historical task type, the user authority range index corresponding to the real-time task is identified according to the matching result, thereby obtaining the user authority range corresponding to the real-time task; if the real-time task does not match the historical task type, the notification information is output to the relevant personnel, and the relevant personnel assign the corresponding user authority range to the real-time task.
[0034] Further, the historical task data processing module includes a historical task list collection unit, a historical task feature extraction unit, and a historical task clustering unit;
[0035] The historical task list collection unit collects the historical task list within the specified time period; the historical task feature extraction unit extracts feature data from the historical tasks and converts these features into vector form; the historical task clustering unit clusters the historical tasks based on the DBSCAN clustering algorithm, each task type is marked with a unique code, and the corresponding historical task data set is constructed;
[0036] The historical user data analysis module includes a historical user data collection unit, a historical task operation path extraction unit, and an authority range indicator calculation unit;
[0037] The historical user data collection unit collects historical user data within a selected time period. The historical user data represents the operation data generated by each user in the process of executing historical tasks; the historical task operation path extraction unit extracts the operation path of the user when executing the task from the historical user data; the authority range indicator calculation unit calculates the coverage and diversity of user permissions based on the historical task operation path, and combines these two indicators to calculate the user authority range indicator corresponding to each historical task.
[0038] Further, the real-time task feature analysis module includes a real-time task list collection unit, a real-time task feature extraction unit, and a real-time task and historical task association analysis unit;
[0039] The real-time task list collection unit collects the real-time task list; the real-time task feature extraction unit extracts corresponding features for each task in the real-time task list to generate a real-time task feature vector; the real-time task and historical task association analysis unit calculates the Euclidean distance between the real-time task feature vector and the historical task feature vector, and obtains the corresponding historical task core point cluster according to the Euclidean distance between the real-time task feature vector and the historical task feature vector, thereby obtaining the correlation index of the real-time task.
[0040] Further, the real-time task authority management module includes a real-time task authority range analysis unit, a real-time task operation path analysis unit, and an authority adjustment and allocation unit;
[0041] The real-time task authority range analysis unit compares and analyzes the correlation index of the real-time task with the core point cluster of the historical task. If they match, the corresponding authority range index is obtained from the corresponding historical task type to obtain the initial authority range of the real-time task; the real-time task operation path analysis unit generates the corresponding real-time operation path based on the real-time user data of the real-time task; the authority adjustment and allocation unit adjusts the user authority range of the real-time task according to the comparison result of the real-time operation path of the real-time task and the historical operation path of the historical task; if the real-time task does not match any historical task type, the notification information is sent to the relevant personnel, who will allocate the authority.
[0042] Compared with the prior art, the beneficial effects of the present invention are as follows: the present invention dynamically determines the scope of authority of the user in a specific task by analyzing the operation path and user authority scope index based on the historical task, thereby ensuring that the authority allocation is more accurate; the real-time task determines whether it belongs to the existing historical task type according to the correlation index of the historical task, thereby avoiding excessive allocation of authority. The present invention realizes automatic authority management based on task characteristics by analyzing the historical task data and the user operation path, and can automatically calculate the corresponding user authority scope when the real-time task occurs, and adjust it in time; if the real-time task does not match the historical task type, it can also request manual authority allocation through the notification mechanism, thereby ensuring that the task can be supported on time. Through in-depth analysis of historical tasks, the system not only considers the description of the task and the data types involved, but also tracks the operation path of the user in the task in detail; based on the analysis of the user's actual operation path, the authority coverage and diversity indicators can be calculated, thereby quantifying the authority requirements of each user in different tasks; this method makes authority management more personalized, avoids the general authorization method based on fixed roles in traditional methods, and can allocate user authority more accurately. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] The accompanying drawings are used to provide a further understanding of the present invention and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation of the present invention. In the accompanying drawings:
[0044] Figure 1 It is a schematic diagram of a user data management system module based on data analysis of the present invention. DETAILED DESCRIPTION
[0045] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0046] See also Figure 1 , the present invention provides a technical solution:
[0047] A user data management system based on data analysis, comprising: a historical task data processing module, a historical user data analysis module, a real-time task feature analysis module and a real-time task authority management module;
[0048] The historical task data processing module collects the historical task list, extracts the corresponding historical task features for each historical task in the historical task list, and divides the historical tasks according to the historical task features, thereby dividing them into several historical task types, and constructs a corresponding historical task data set for each historical task type;
[0049] The historical user data analysis module collects historical user data and associates the historical user data with corresponding historical tasks; analyzes the historical user data corresponding to each historical task, extracts the corresponding historical task operation path, and calculates the user authority range index based on the historical task operation path, thereby obtaining a mapping relationship between historical tasks and user authority range indicators;
[0050] The real-time task feature analysis module obtains the real-time task list, extracts the real-time task features for each real-time task in the real-time task list, and analyzes the correlation between the real-time task features and the historical task features, thereby obtaining corresponding correlation indicators;
[0051] The real-time task authority management module obtains the user authority range of the real-time task based on the correlation index; if the real-time task matches the historical task type, the user authority range index corresponding to the real-time task is identified according to the matching result, thereby obtaining the user authority range corresponding to the real-time task; if the real-time task does not match the historical task type, the notification information is output to the relevant personnel, and the relevant personnel assign the corresponding user authority range to the real-time task.
[0052] The historical task data processing module includes a historical task list collection unit, a historical task feature extraction unit, and a historical task clustering unit;
[0053] The historical task list collection unit collects the historical task list within the specified time period; the historical task feature extraction unit extracts feature data from the historical tasks and converts these features into vector form; the historical task clustering unit clusters the historical tasks based on the DBSCAN clustering algorithm, each task type is marked with a unique code, and the corresponding historical task data set is constructed;
[0054] The historical user data analysis module includes a historical user data collection unit, a historical task operation path extraction unit, and an authority range indicator calculation unit;
[0055] The historical user data collection unit collects historical user data within a selected time period. The historical user data represents the operation data generated by each user in the process of executing historical tasks; the historical task operation path extraction unit extracts the operation path of the user when executing the task from the historical user data; the authority range indicator calculation unit calculates the coverage and diversity of user permissions based on the historical task operation path, and combines these two indicators to calculate the user authority range indicator corresponding to each historical task.
[0056] The real-time task feature analysis module includes a real-time task list collection unit, a real-time task feature extraction unit, and a real-time task and historical task correlation analysis unit;
[0057] The real-time task list collection unit collects the real-time task list; the real-time task feature extraction unit extracts corresponding features for each task in the real-time task list to generate a real-time task feature vector; the real-time task and historical task association analysis unit calculates the Euclidean distance between the real-time task feature vector and the historical task feature vector, and obtains the corresponding historical task core point cluster according to the Euclidean distance between the real-time task feature vector and the historical task feature vector, thereby obtaining the correlation index of the real-time task.
[0058] The real-time task authority management module includes a real-time task authority range analysis unit, a real-time task operation path analysis unit, and an authority adjustment and allocation unit;
[0059] The real-time task authority range analysis unit compares and analyzes the correlation index of the real-time task with the core point cluster of the historical task. If they match, the corresponding authority range index is obtained from the corresponding historical task type to obtain the initial authority range of the real-time task; the real-time task operation path analysis unit generates the corresponding real-time operation path based on the real-time user data of the real-time task; the authority adjustment and allocation unit adjusts the user authority range of the real-time task according to the comparison result of the real-time operation path of the real-time task and the historical operation path of the historical task; if the real-time task does not match any historical task type, the notification information is sent to the relevant personnel, who will allocate the authority.
[0060] A user data management method based on data analysis comprises the following steps:
[0061] Step S100. Collect the historical task list, extract the corresponding historical task features for each historical task in the historical task list, and divide the historical tasks according to the historical task features, thereby dividing them into several historical task types, and construct a corresponding historical task data set for each historical task type;
[0062] Step S200. Collect historical user data and associate the historical user data with corresponding historical tasks; analyze the historical user data corresponding to each historical task, extract the corresponding historical task operation path, and calculate the user authority range index based on the historical task operation path, so as to obtain the mapping relationship between the historical task and the user authority range index;
[0063] Step S300. Obtain a real-time task list, extract real-time task features for each real-time task in the real-time task list, analyze the correlation between the real-time task features and the historical task features, and thus obtain corresponding correlation indicators;
[0064] Step S400. Obtain the user authority range of the real-time task based on the correlation index; if the real-time task matches the historical task type, identify the user authority range index corresponding to the real-time task based on the matching result, thereby obtaining the user authority range corresponding to the real-time task; if the real-time task does not match the historical task type, output notification information to relevant personnel, and the relevant personnel assign the corresponding user authority range to the real-time task.
[0065] Step S100 includes:
[0066] S101. Collect a list of historical tasks within a selected time period, wherein the list of historical tasks records the descriptive information of all historical tasks within the selected time period, such as the task name, task objectives, and data types involved in the tasks, and each historical task corresponds to a unique data number; for each historical task in the list of historical tasks, extract the corresponding historical task features, and vectorize the extracted historical task features to obtain a historical task feature vector Fi with a unified format, and Fi=[fi1,fi2,...,fin], wherein Fi represents the historical task feature vector of the i-th historical task in the list of historical tasks within the selected time period, and i represents the historical task data number in the list of historical tasks within the selected time period; fi1 represents the first eigenvalue of the historical task feature vector Fi, fi2 represents the second eigenvalue of the historical task feature vector Fi, and so on, fin represents the n-th eigenvalue of the historical task feature vector Fi;
[0067] S102. Summarize the historical task feature vectors corresponding to all historical tasks in the historical task list, and use the DBSCAN clustering algorithm to divide the historical tasks into different clusters according to the corresponding historical task feature vectors. Each cluster represents a historical task type, and the number of clusters is equal to the number of historical task types in the historical task list; label each historical task type with a unique type code, and summarize the historical task feature vectors of historical tasks of the same task type to form a historical task data set Am, where m represents the data number of the historical task type.
[0068] The DBSCAN clustering algorithm is used to divide historical tasks into different clusters according to the corresponding historical task feature vectors. The specific contents are as follows:
[0069] For each historical task feature vector Fi, calculate the Euclidean distance d(Fi,Fj) between it and the historical task feature vectors Fj corresponding to other historical tasks in the historical task list. The specific calculation formula is:
[0070] d(Fi,Fj)={∑a∈[1,n],(fia-fja) 2}^(1 / 2);
[0071] Wherein, fia represents the ath eigenvalue in the historical task feature vector Fi, fja represents the ath eigenvalue in the historical task feature vector Fj, and a is a positive integer from 1 to n; the Euclidean distances d(Fi,Fj) between the historical task feature vector Fi and the historical task feature vector Fj corresponding to other historical tasks in the historical task list are summarized, arranged in ascending order, and the values corresponding to the first k Euclidean distances are selected to form the k-nearest neighbor distances of the historical task feature vector Fi; according to the k-nearest neighbor distances of the historical task feature vector Fi, a k-distance graph is drawn, in which the x-axis represents the index of the data point and the y-axis represents the k-nearest neighbor distance of the corresponding point; the data points are connected in sequence according to the index order of the data points to obtain a curve, and the Euclidean distance value corresponding to the first inflection point on the curve is the ε value; the minimum number of neighborhood points MinPts is defined as M. When the feature dimension is low, such as the task feature vector dimension is 2 or 3, MinPts can be selected as 2 or 4; if the feature dimension is high (for example, dozens of dimensions), MinPts=10 or higher can be considered;
[0072] For each historical task feature vector Fi, if the Euclidean distance of its k-nearest neighbor is less than or equal to ε, and the number of points contained in the neighborhood of the point is at least M, then the historical task feature vector Fi is a core point; if the historical task feature vector Fi is not a core point, but the ε neighborhood of the historical task feature vector Fi contains at least one core point, then the historical task feature vector Fi is a boundary point; if the historical task feature vector Fi is neither a core point nor a boundary point, then the historical task feature vector Fi is a noise point; for the historical task feature vector Fi identified as a core point, the historical task feature vector F The cluster where i is located is marked as a new cluster, denoted as cluster C; starting from the core point historical task feature vector Fi, find the neighborhood points of the historical task feature vector Fi, that is, all points in the ε neighborhood; add these neighborhood points to cluster C, if some of the neighborhood points are also core points, continue to expand cluster C from these core points; if the clusters extended from different core points have intersections, merge the two clusters into a large cluster; a boundary point belongs to a cluster if it belongs to the neighborhood of a core point, and the core point has been marked as part of the cluster; a boundary point does not belong to the neighborhood of any core point, then it is marked as a noise point.
[0073] In this example, assume that there is a list of historical tasks, the dimension of the feature vector of each historical task is n, and the number of tasks is N; k=5 is selected to calculate the 5 nearest neighbor distances of each task. The following is the process of estimating the ε value:
[0074] For historical task F1, calculate its distance with other historical tasks F2, F3, …, FN, and select the first 5 nearest historical tasks to calculate the Euclidean distance of these historical tasks; for historical task F2, similarly calculate its 5 nearest neighbor distances; repeat the above process for all historical tasks.
[0075] For each historical task, plot the sorted values of its 5 nearest neighbor distances and display these values in a chart, where the x-axis is the index (or number) of the task and the y-axis is the k-nearest neighbor distance; observe the curve in the chart and identify the first inflection point. The y-axis value corresponding to this inflection point is the recommended ε value; for example: if the distances from task 1 to task 2 and task 3 are very close, the curve is very smooth, but starting from task 4, the slope of the curve increases significantly, then the value corresponding to the distance of task 4 is our estimated ε value. By finding the inflection point position in the k-nearest neighbor distance sorting graph of all tasks, the range of ε values is determined, and the first inflection point value is usually selected as the ε value. Depending on the dimension of the historical task feature vector, the choice of MinPts may be different: if the dimension of the task feature is low, such as 2 or 3 dimensions, a smaller MinPts (such as 2 or 4) can be selected, and it is easier to identify obvious dense areas. If the dimension of the task feature is high and the feature space is large, such as dozens of dimensions, a larger MinPts (such as 10 or higher) can be selected to capture more dense areas and avoid interference from noise points. In this embodiment, assuming that the dimension of the task feature is a relatively high n-dimensional (for example, 10 dimensions or more), MinPts = 10 is selected.
[0076] Once you have determined your ε and MinPts values, you can start categorizing tasks based on these values:
[0077] Core point: If the distance of the five nearest neighbors of the historical task feature vector Fi is less than or equal to ε, and the neighborhood of the point contains at least MinPts points, then Fi is a core point.
[0078] Boundary point: If Fi is not a core point, but its ε neighborhood contains at least one core point, then Fi is a boundary point.
[0079] Noise point: If Fi is neither a core point nor a boundary point, then Fi is a noise point.
[0080] For the historical task feature vector Fi that has been identified as a core point, start to build cluster C. First, starting from Fi, find all the points that belong to the ε neighborhood of Fi. Add these points to cluster C and continue to find the neighborhood of these points. If some points are also core points, continue to expand cluster C from these points. If there is an intersection between the different expanded clusters, it means that they actually belong to the same cluster. At this time, the two clusters need to be merged into a larger cluster.
[0081] For a border point, it will be assigned to a cluster where a core point is located. A border point belongs to the neighborhood of a core point, and the core point has been marked as part of the cluster. For a noise point, it does not belong to the neighborhood of any core point, so it will be marked as noise and is usually not assigned to any cluster.
[0082] Step S200 includes:
[0083] S201. Collect historical user data within a selected time period, wherein the historical user data refers to operation data generated by a user performing a historical task in a historical task list within the selected time period; extract the data number of the executed historical task from the historical user data, and associate the corresponding historical task feature vector according to the data number, thereby forming an associated data group of the historical user data and the historical task;
[0084] S202. For each associated data group, extract the corresponding historical task operation path Pi according to the corresponding historical user data, and Pi={(s1,b1),(s2,b2),...,(sk,bk)}, where Pi represents the historical task operation path of the i-th historical task in the historical task list of the user within the selected time period; s1 in (s1,b1) represents the operation interface of the user at the first step, and b1 represents the action performed by the user in the operation interface s1, such as clicking a button, entering a field, etc.; s2 in (s2,b2) represents the operation interface of the user at the second step, and b2 represents the action performed by the user in the operation interface s2; and so on, sk in (sk,bk) represents the operation interface of the user at the k-th step, bk represents the action performed by the user in the operation interface sk, and k represents the length of the operation path, that is, the total number of actions performed by the user when performing the historical task;
[0085] In this embodiment, the operation path corresponding to each historical task is extracted from the historical user data, and the operation path refers to the action sequence of the user when performing a certain historical task; the specific operation path can be represented by the following aspects:
[0086] User actions: For each task, record every action performed by the user during the task, such as click, input, submit, select, etc.
[0087] Timestamp: records the time of each user action, making it easier to analyze the sequence of user behavior.
[0088] Context information: Each user action may be accompanied by some context information, such as the page operated on, the object of the operation, etc.
[0089] After converting this information into an operation path, it can be represented as a combination of a series of discrete states and actions, which can be formally expressed as: Pi={(s1,b1),(s2,b2),...,(sk,bk)}; each operation path Pi is composed of a sequence of user behaviors, and these operation paths can be used to provide a basis for subsequent authority scope calculations.
[0090] S203. According to the historical task operation path Pi, combined with the preset user permission set B, calculate the permission coverage index Cu(Pi), and Cu(Pi)=N(Pi) / N(B), where N(Pi) is the number of user permissions corresponding to the historical task operation path Pi in the user permission set B, and N(B) represents the number of user permissions in the preset user permission set B; calculate the diversity index Du(Pi), and Du(Pi)=N(Pi) / k; according to the permission coverage index Cu(Pi) and the diversity index Du(Pi), calculate the user permission range index Iu(Pi), and Iu(Pi)=w1·Cu(Pi)+w2·Du(Pi), where w1 and w2 represent weight coefficients, and w1+w2=1; summarize all historical task operation paths, and perform one-to-one mapping with the corresponding user permission range indicators, so as to establish a mapping relationship between historical tasks and user permission range indicators.
[0091] In this embodiment, the preset user permission set B has the following explanation:
[0092] If the operation bx is to click a button, then the permission set B may include the page, function module, database access rights, etc. corresponding to the button.
[0093] If the operation bx is to input a field, then the permission set B may include the editability of the input field, the permission to access the data in the field, etc.
[0094] Therefore, the preset user permission set B is divided into the following categories to be associated with the operation path of the historical task:
[0095] Functional permissions: permissions related to task functions, such as accessing the task interface, viewing task details, and modifying tasks.
[0096] Interface element permissions: Permissions related to interface elements (such as buttons, input boxes, and drop-down menus). For example, clicking a button, filling in a field, selecting an option, etc.
[0097] Data access rights: Permission items related to data operations, such as reading, modifying, or deleting data.
[0098] Operation path permissions: Specific to each step in a task, the permissions required for the user to perform an operation in a certain state. For example, the permissions required to click a button in a certain interface state.
[0099] The calculation process for N(Pi) is as follows:
[0100] Initialize counter: define a counter N(Pi)=0 to count the number of permissions found in permission set B;
[0101] Traverse the operation path: traverse each step (sk, bk) in Pi;
[0102] For each step, check whether the action bk is in the permission set B;
[0103] If bk belongs to B, add 1 to the counter N(Pi);
[0104] Return result: The final N(Pi) is the number of matches of the actions of all steps in the user operation path Pi in the permission set B.
[0105] Step S300 includes:
[0106] S301. Get a real-time task list, analyze each real-time task in the real-time task list in accordance with the analysis method of historical tasks, extract real-time task features from the real-time task, and form a real-time task feature vector Gh, where h represents the real-time task data number in the real-time task list;
[0107] S302. Calculate the Euclidean distance d(Gh, Cm) between the real-time task feature vector Gh and the core point Cm of the historical task type in the historical task list in sequence, and select the Euclidean distance value corresponding to the core point cluster C_min with the smallest distance to the real-time task feature vector Gh as the relevance index Rh of the real-time task.
[0108] Step S400 includes:
[0109] S401. According to the relevance index Rh of the real-time task, compare the relevance index Rh with the ε value of the corresponding core point cluster C_min; if Rh is less than or equal to ε, it means that the real-time task matches the historical task type, and the historical task type is the historical task type corresponding to the core point cluster C_min; arrange the user authority range indicators in the historical task type of the core point cluster C_min in ascending order, and define the user authority range corresponding to the smallest user authority range indicator as the initial user authority range of the current real-time task;
[0110] S402. Acquire the real-time user data corresponding to the real-time task, obtain the real-time task operation path P'i according to the real-time user data, and obtain all the operation interface sequences S' of the executed steps of the current real-time task based on the real-time task operation path P'i, and S=[s'1,s'2,...,s'e], wherein s'1 represents the operation interface of the user at the first step, s'2 represents the operation interface of the user at the second step, and so on, s'e represents the operation interface of the user at the e-th step; and the operation interface of s'e is the predicted operation interface, which is predicted based on the last executed action b'e-1 of the operation interface of s'e-1; compare the operation interface sequence S with the operation interface sequence S corresponding to the historical tasks of the core point cluster C_min in turn, if the comparison results are completely consistent, adjust the user authority range of the current real-time task according to the corresponding historical tasks; if Rh is greater than ε, it means that the real-time task does not match the historical task type, output notification information to relevant personnel, and the relevant personnel assign the corresponding user authority range to the real-time task.
[0111] In this embodiment, the prediction process of s'e in all operation interface sequences S' of the executed steps corresponding to the real-time task is as follows:
[0112] Assume that Manager Zhang of the sales department is tasked with handling a contract with a new major customer and communicating with the customer. The task involves multiple steps, including checking customer information, processing quotations, approving contracts, and subsequent follow-up communications.
[0113] Step 1: Get real-time user data
[0114] After Manager Zhang enters the system, the system will obtain Manager Zhang's task data in real time and monitor Manager Zhang's operations in the system. For example, the system can identify that the client project he is currently working on is "Contract Signing for Client A", which is a real-time task.
[0115] Step 2: Get the operation path P'i based on the real-time task data
[0116] Based on Mr. Zhang's current task data, the system constructs his operation path P'i. This path shows each operation interface that Mr. Zhang has passed through from the beginning of processing the task to the current state.
[0117] Step 3: Get the operation interface sequence S'
[0118] The system will generate a sequence S' of the current operation interface based on the real-time task operation path P'i. Each step corresponds to a specific operation interface. For example:
[0119] Step 1: s'1 = "Customer A's homepage"
[0120] Step 2: s'2 = "Customer A details page"
[0121] Step 3: s'3 = "Contract Approval Page";
[0122] At this time, the executed operation interface sequence S' is: [s'1, s'2, s'3]; then according to the last operation action in the "contract approval page" in the real-time task operation path P'i, for example (for example, click "submit approval" or "review contract"), the next possible operation interface s'4 can be predicted. Assuming that the last action performed by Manager Zhang on the contract approval page is "submit approval", the system may predict that he will enter the "customer communication page" to confirm the contract details with the customer or conduct follow-up communication; then s'e=s'4="customer communication page"; therefore, the current operation interface sequence S'=[s'1, s'2, s'3, s'4]; compare the current operation interface sequence S' with the historical task operation interface sequence in the core point cluster C_min. If the current operation interface sequence S' is completely consistent with the historical task operation sequence S, then adjust the corresponding user authority range according to the historical task of the corresponding historical task operation sequence S.
[0123] It should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device.
[0124] Finally, it should be noted that the above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art can still modify the technical solutions described in the aforementioned embodiments or replace some of the technical features therein by equivalents. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. A user data management method based on data analysis, characterized in that: The method comprises the following steps: Step S100. Collect the historical task list, extract the corresponding historical task features for each historical task in the historical task list, and divide the historical tasks according to the historical task features, thereby dividing them into several historical task types, and construct a corresponding historical task data set for each historical task type; Step S200. Collect historical user data and associate the historical user data with corresponding historical tasks; analyze the historical user data corresponding to each historical task, extract the corresponding historical task operation path, and calculate the user authority range index based on the historical task operation path, so as to obtain the mapping relationship between the historical task and the user authority range index; Step S300. Obtain a real-time task list, extract real-time task features for each real-time task in the real-time task list, analyze the correlation between the real-time task features and the historical task features, and thus obtain corresponding correlation indicators; Step S400. Obtain the user authority range of the real-time task based on the correlation index; if the real-time task matches the historical task type, identify the user authority range index corresponding to the real-time task based on the matching result, thereby obtaining the user authority range corresponding to the real-time task; if the real-time task does not match the historical task type, output notification information to relevant personnel, and the relevant personnel assign the corresponding user authority range to the real-time task.
2. A user data management method based on data analysis according to claim 1, characterized in that: The step S100 includes: S101. Collect a list of historical tasks within a selected time period, wherein the list of historical tasks records the description information of all historical tasks within the selected time period, and each historical task corresponds to a unique data number; for each historical task in the list of historical tasks, extract the corresponding historical task features, and vectorize the extracted historical task features to obtain a historical task feature vector Fi with a unified format, and Fi=[fi1,fi2,...,fin], wherein Fi represents the historical task feature vector of the i-th historical task in the list of historical tasks within the selected time period, and i represents the historical task data number in the list of historical tasks within the selected time period; fi1 represents the first eigenvalue of the historical task feature vector Fi, fi2 represents the second eigenvalue of the historical task feature vector Fi, and so on, fin represents the n-th eigenvalue of the historical task feature vector Fi; S102. Summarize the historical task feature vectors corresponding to all historical tasks in the historical task list, and use the DBSCAN clustering algorithm to divide the historical tasks into different clusters according to the corresponding historical task feature vectors. Each cluster represents a historical task type, and the number of clusters is equal to the number of historical task types in the historical task list; label each historical task type with a unique type code, and summarize the historical task feature vectors of historical tasks of the same task type to form a historical task data set Am, where m represents the data number of the historical task type.
3. A user data management method based on data analysis according to claim 2, characterized in that: The DBSCAN clustering algorithm is used to divide historical tasks into different clusters according to the corresponding historical task feature vectors. The specific contents are as follows: For each historical task feature vector Fi, calculate the Euclidean distance d(Fi,Fj) between it and the historical task feature vectors Fj corresponding to other historical tasks in the historical task list. The specific calculation formula is: d(Fi,Fj)={∑a∈[1,n],(fia-fja) 2 }^(1 / 2); Among them, fia represents the ath eigenvalue in the historical task feature vector Fi, fja represents the ath eigenvalue in the historical task feature vector Fj, and a is a positive integer from 1 to n; the Euclidean distances d(Fi,Fj) between the historical task feature vector Fi and the historical task feature vector Fj corresponding to other historical tasks in the historical task list are summarized, arranged in ascending order, and the values corresponding to the first k Euclidean distances are selected to form the k-nearest neighbor distances of the historical task feature vector Fi; according to the k-nearest neighbor distances of the historical task feature vector Fi, a k-distance graph is drawn, in which the x-axis represents the index of the data point and the y-axis represents the k-nearest neighbor distance of the corresponding point; the data points are connected in sequence according to the index order of the data points to obtain a curve, and the Euclidean distance value corresponding to the first inflection point on the curve is the ε value; the minimum number of neighborhood points MinPts is defined as M; For each historical task feature vector Fi, if the Euclidean distance of its k-nearest neighbors is less than or equal to ε, and the number of points contained in the neighborhood of the point is at least M, then the historical task feature vector Fi is a core point; if the historical task feature vector Fi is not a core point, but the ε neighborhood of the historical task feature vector Fi contains at least one core point, then the historical task feature vector Fi is a boundary point; if the historical task feature vector Fi is neither a core point nor a boundary point, then the historical task feature vector Fi is a noise point; for the historical task feature vector Fi identified as a core point, the historical task feature vector Fi is The cluster where the feature vector Fi is located is marked as a new cluster, denoted as cluster C; starting from the core point historical task feature vector Fi, find the neighborhood points of the historical task feature vector Fi, and add these neighborhood points to cluster C. If some of the neighborhood points are also core points, continue to expand cluster C from these core points; if the clusters extended from different core points have intersections, merge the two clusters into a large cluster; a boundary point belongs to a cluster if it belongs to the neighborhood of a core point, and the core point has been marked as part of the cluster; a boundary point does not belong to the neighborhood of any core point, then it is marked as a noise point.
4. The user data management method based on data analysis according to claim 3 is characterized in that: The step S200 includes: S201. Collect historical user data within a selected time period, wherein the historical user data refers to operation data generated by a user performing a historical task in a historical task list within the selected time period; extract the data number of the executed historical task from the historical user data, and associate the corresponding historical task feature vector according to the data number, thereby forming an associated data group of the historical user data and the historical task; S202. For each associated data group, extract the corresponding historical task operation path Pi according to the corresponding historical user data, and Pi={(s1,b1),(s2,b2),...,(sk,bk)}, where Pi represents the historical task operation path of the i-th historical task in the historical task list of the user in the selected time period; s1 in (s1,b1) represents the operation interface of the user at the first step, and b1 represents the action performed by the user under the operation interface s1; s2 in (s2,b2) represents the operation interface of the user at the second step, and b2 represents the action performed by the user under the operation interface s2; and so on, sk in (sk,bk) represents the operation interface of the user at the k-th step, bk represents the action performed by the user under the operation interface sk, and k represents the length of the operation path, that is, the total number of actions performed by the user when performing the historical task; S203. According to the historical task operation path Pi, combined with the preset user permission set B, calculate the permission coverage index Cu(Pi), and Cu(Pi)=N(Pi) / N(B), where N(Pi) is the number of user permissions corresponding to the historical task operation path Pi in the user permission set B, and N(B) represents the number of user permissions in the preset user permission set B; calculate the diversity index Du(Pi), and Du(Pi)=N(Pi) / k; according to the permission coverage index Cu(Pi) and the diversity index Du(Pi), calculate the user permission range index Iu(Pi), and Iu(Pi)=w1·Cu(Pi)+w2·Du(Pi), where w1 and w2 represent weight coefficients, and w1+w2=1; summarize all historical task operation paths, and perform one-to-one mapping with the corresponding user permission range indicators, so as to establish a mapping relationship between historical tasks and user permission range indicators.
5. A user data management method based on data analysis according to claim 4, characterized in that: The step S300 includes: S301. Get a real-time task list, analyze each real-time task in the real-time task list in accordance with the analysis method of historical tasks, extract real-time task features from the real-time task, and form a real-time task feature vector Gh, where h represents the real-time task data number in the real-time task list; S302. Calculate the Euclidean distance d(Gh, Cm) between the real-time task feature vector Gh and the core point Cm of the historical task type in the historical task list in sequence, and select the Euclidean distance value corresponding to the core point cluster C_min with the smallest distance to the real-time task feature vector Gh as the relevance index Rh of the real-time task.
6. A user data management method based on data analysis according to claim 5, characterized in that: The step S400 includes: S401. According to the relevance index Rh of the real-time task, compare the relevance index Rh with the ε value of the corresponding core point cluster C_min; if Rh is less than or equal to ε, it means that the real-time task matches the historical task type, and the historical task type is the historical task type corresponding to the core point cluster C_min; arrange the user authority range indicators in the historical task type of the core point cluster C_min in ascending order, and define the user authority range corresponding to the smallest user authority range indicator as the initial user authority range of the current real-time task; S402. Acquire the real-time user data corresponding to the real-time task, obtain the real-time task operation path P'i according to the real-time user data, and obtain all the operation interface sequences S' of the executed steps of the current real-time task based on the real-time task operation path P'i, and S=[s'1,s'2,...,s'e], wherein s'1 represents the operation interface of the user at the first step, s'2 represents the operation interface of the user at the second step, and so on, s'e represents the operation interface of the user at the e-th step; and the operation interface of s'e is the predicted operation interface, which is predicted based on the last executed action b'e-1 of the operation interface of s'e-1; compare the operation interface sequence S with the operation interface sequence S corresponding to the historical tasks of the core point cluster C_min in turn, if the comparison results are completely consistent, adjust the user authority range of the current real-time task according to the corresponding historical tasks; if Rh is greater than ε, it means that the real-time task does not match the historical task type, output notification information to relevant personnel, and the relevant personnel assign the corresponding user authority range to the real-time task.
7. A user data management system based on data analysis, applied to a user data management method based on data analysis according to any one of claims 1 to 6, characterized in that: The system includes: a historical task data processing module, a historical user data analysis module, a real-time task feature analysis module and a real-time task authority management module; The historical task data processing module collects the historical task list, extracts the corresponding historical task features for each historical task in the historical task list, and divides the historical tasks according to the historical task features, thereby dividing them into several historical task types, and constructs a corresponding historical task data set for each historical task type; The historical user data analysis module collects historical user data and associates the historical user data with corresponding historical tasks; analyzes the historical user data corresponding to each historical task, extracts the corresponding historical task operation path, and calculates the user authority range index based on the historical task operation path, thereby obtaining a mapping relationship between the historical tasks and the user authority range index; The real-time task feature analysis module obtains a real-time task list, extracts real-time task features for each real-time task in the real-time task list, and analyzes the correlation between the real-time task features and the historical task features, thereby obtaining corresponding correlation indicators; The real-time task authority management module obtains the user authority range of the real-time task according to the correlation index; if the real-time task matches the historical task type, the user authority range index corresponding to the real-time task is identified according to the matching result, thereby obtaining the user authority range corresponding to the real-time task; if the real-time task does not match the historical task type, a notification message is output to relevant personnel, and the relevant personnel assign the corresponding user authority range to the real-time task.
8. A user data management system based on data analysis according to claim 7, characterized in that: The historical task data processing module includes a historical task list collection unit, a historical task feature extraction unit and a historical task clustering unit; The historical task list collection unit collects the historical task list within a specified time period; the historical task feature extraction unit extracts feature data from the historical tasks and converts these features into vector form; the historical task clustering unit clusters the historical tasks based on the DBSCAN clustering algorithm, each task type is marked as a unique code, and a corresponding historical task data set is constructed; The historical user data analysis module includes a historical user data collection unit, a historical task operation path extraction unit, and an authority range index calculation unit; The historical user data collection unit collects historical user data within a selected time period, and the historical user data represents the operation data generated by each user in the process of executing historical tasks; the historical task operation path extraction unit extracts the operation path of the user when executing the task from the historical user data; the authority range indicator calculation unit calculates the coverage and diversity of user permissions based on the historical task operation path, and combines these two indicators to calculate the user authority range indicator corresponding to each historical task.
9. The user data management system based on data analysis according to claim 7, characterized in that: The real-time task feature analysis module includes a real-time task list collection unit, a real-time task feature extraction unit, and a real-time task and historical task association analysis unit; The real-time task list collecting unit collects the real-time task list; The real-time task feature extraction unit extracts corresponding features from each task in the real-time task list to generate a real-time task feature vector; The real-time task and historical task association analysis unit calculates the Euclidean distance between the real-time task feature vector and the historical task feature vector, obtains the corresponding historical task core point cluster according to the Euclidean distance between the real-time task feature vector and the historical task feature vector, and thus obtains the association index of the real-time task.
10. The user data management system based on data analysis according to claim 7, characterized in that: The real-time task authority management module includes a real-time task authority range analysis unit, a real-time task operation path analysis unit and an authority adjustment and allocation unit; The real-time task authority range analysis unit compares and analyzes the real-time task with the core point cluster of the historical task according to the correlation index of the real-time task. If they match, the corresponding authority range index is obtained from the corresponding historical task type, so as to obtain the initial authority range of the real-time task; the real-time task operation path analysis unit generates the corresponding real-time operation path based on the real-time user data of the real-time task; the authority adjustment and allocation unit adjusts the user authority range of the real-time task according to the comparison result of the real-time operation path of the real-time task and the historical operation path of the historical task; if the real-time task does not match any historical task type, the notification information is sent to the relevant personnel, who will allocate the authority.
Citation Information
Patent Citations
Method and device for access terminal permission control and host terminal
CN110175437A
Permission management method, device and system and computer readable storage medium
CN112765591A