A method for integrating multiple organizational structures and user permissions

By analyzing user permissions through multi-scale neural networks and generating permission mapping functions, the problems of permission conflicts and configuration errors under multiple organizational architectures are solved, enabling refined management and improved transparency of user permissions.

CN119760677BActive Publication Date: 2025-11-14BEIJING ORIENTAL TONGYU TECHNOLOGY CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202411815836.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-11
Publication Date
2025-11-14
Estimated Expiration
2044-12-11

AI Technical Summary

Technical Problem

Existing technologies suffer from high rates of permission conflicts and configuration errors in user permission management across multiple organizational structures. This is especially true when users belong to multiple organizational units and hold multiple positions, where permission merging can lead to conflicts. Administrators need to understand complex permission structures, which increases the error rate.

Method used

By acquiring users' permissions and permission levels in different organizations, a permission data set is generated. Multi-scale neural networks are used to determine the membership characteristics of user permissions, a multi-permission fusion network is constructed, a permission mapping function is generated, and permission fusion identifiers are bound to users to achieve refined management and fusion of permissions.

Benefits of technology

It enables fine-grained management of user permissions, adapts to permission management under multiple organizational structures, improves the transparency and consistency of permission management, reduces the error rate of permission configuration, and adapts to organizational restructuring and permission changes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119760677B_ABST
    Figure CN119760677B_ABST
Patent Text Reader

Abstract

This invention relates to the field of computer access control technology, and provides a method for multi-organizational architecture and user access control fusion, comprising: generating an access control dataset based on a user's organizational permissions and access control levels in different organizations; determining access control attributes and access control objects according to organizational permissions; determining access control weights and access control thresholds for a user in different organizations according to access control levels; inputting access control attributes, access control weights, and access control thresholds into a first multi-scale neural network to determine the first membership feature of user access control under the multi-organizational architecture; inputting access control objects, access control weights, and access control thresholds into a second multi-scale neural network to determine the second membership feature of user access control under the multi-scale architecture; inputting the first membership feature and the second membership feature into a trained multi-access control fusion network to generate multiple access control mapping functions; generating a user access control fusion identifier according to the access control mapping functions, and binding the access control fusion identifier to the multiple organizations to which the user belongs.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of industrial data processing, and in particular to a method for integrating multiple organizational structures and user permissions. Background Technology

[0002] In modern information society, due to work requirements, people may hold different positions or perform different tasks in different organizations, thus users may have different permissions within different organizations. However, existing permission management methods have some problems, such as permission conflicts and insufficient permissions. Therefore, it is necessary to provide a multi-organizational architecture and user permission integration method that can solve these problems.

[0003] Currently, patent CN202311068266.5 describes a method, system, and apparatus for user permission fusion based on multiple organizational architectures. It proposes a method to receive user login requests, statically configure and bind user permissions and role permissions to the user; receive user requests to enter a business application, and bind the organizational and role permissions of that business application to the user; based on permission priority, it performs fusion calculations on various permissions to obtain the user's actual effective permissions. This efficiently handles user permission issues across multiple organizational architectures, saves system costs, facilitates data management, and avoids permission chaos and conflicts.

[0004] However, the above technical solutions have many technical defects in practical implementation:

[0005] For example, when a user belongs to multiple organizational units and holds multiple roles, permission merging may lead to permission conflicts. For instance, a user may be granted a certain permission in one organizational unit, but the same permission may be denied in another organizational unit.

[0006] In addition, administrators need to understand complex permission structures, including different types of permissions and their priorities, which may increase the error rate of permission configuration. Summary of the Invention

[0007] This invention proposes a multi-organizational architecture and user permission fusion method to address the issue in existing technologies where permission fusion may lead to permission conflicts when a user belongs to multiple organizational units and holds multiple positions. For example, a user may be granted a permission in one organizational unit but have the same permission denied in another. Administrators need to understand complex permission structures, including different types of permissions and their priorities, which may increase the error rate of permission configuration.

[0008] This invention proposes a method for integrating multiple organizational structures and user permissions, including:

[0009] Obtain users' organizational permissions and permission levels in different organizations, and generate permission data sets;

[0010] Based on organizational permissions, determine the user's permission attributes and permission objects within different organizations;

[0011] Based on the permission level, determine the permission weight and permission threshold of a user in different organizations;

[0012] Input the permission attributes, permission weights, and permission thresholds into the first multi-scale neural network to determine the first membership feature of user permissions under multiple organizational structures;

[0013] Input the permission object, permission weight, and permission threshold into the second multi-scale neural network to determine the second membership feature of user permissions under the multi-scale architecture;

[0014] Input the first membership feature and the second membership first feature into the trained multi-permission fusion network to generate multiple permission mapping functions;

[0015] Based on the permission mapping function, a permission fusion identifier for the user is generated, and the permission fusion identifier is bound to multiple organizations to which the user belongs.

[0016] Furthermore, the generated permission data set also includes:

[0017] Obtain the organization to which the user belongs, and build the user permission model in each organization;

[0018] Based on the permission model, the permission scope and permission type of users in each organization are identified sequentially.

[0019] Based on the permission types of users in each organization, determine the permission triggering events for different permissions of users in an organization;

[0020] Determine the permission identifier of each user in the organization based on the permission-triggered events;

[0021] Based on the permission type and permission identifier, the permission data of users in each organization are identified sequentially, and the corresponding permission subset is generated.

[0022] The permission subsets are merged to form a permission data set.

[0023] Furthermore, the step of sequentially identifying user permission data in each organization includes:

[0024] Determine the first trigger result of the first permission triggering event for the user's target permission in each organization, wherein the first trigger result is used to execute the user's instruction after the first permission triggering event is triggered;

[0025] Based on the first trigger result, determine the scope of the user's target permissions and the topological organization nodes that match the corresponding permissions;

[0026] Based on the topology organization nodes, obtain the node data of each topology organization node in sequence, and generate permission data.

[0027] Furthermore, determining the user's permission attributes and permission objects within different organizations based on organizational permissions includes:

[0028] Based on organizational permissions, obtain application response information involved when a user triggers the corresponding user permission; among which, the application response information is the function options generated by the application triggered by the user permission when executing the user permission;

[0029] Based on the application response information, determine the permission attributes of the corresponding user permissions; among which, permission attributes include: permission identifier, permission name, permission description, permission level, permission group, permission scope, permission status, permission grantability, permission dependency, permission dynamism, and permission inheritance.

[0030] Based on the permission attributes, determine the permission objects directly associated with the corresponding user permissions.

[0031] Furthermore, determining the user's permission weight and permission threshold within different organizations based on permission levels includes:

[0032] Determine the user's permission roles within different organizations based on permission levels;

[0033] Based on the permission roles, determine the resource sensitivity of the customer's organizational permissions in different organizations, corresponding to the business operations of different organizations;

[0034] Based on resource sensitivity, determine the minimum and maximum values ​​of resource sensitivity for users accessing services in different organizations within different organizations, and determine the permission thresholds relative to users of services in different organizations;

[0035] Based on the permission threshold, determine the first configuration weight of different organizational businesses relative to the corresponding organizational structure; where the first configuration weight is the business weight, which is used to represent the importance of user permissions;

[0036] Based on the permission roles, a second configuration weight is determined for different organizational businesses relative to the organizational structure; where the second configuration weight is the machine weight, which is used to represent the degree of influence of different permission roles on user permissions;

[0037] The permission weight is determined by a deep weighting of business weight and machine weight; the deep weighting is used for weight regularization.

[0038] Furthermore, the step of inputting permission attributes, permission weights, and permission thresholds into a first multi-scale neural network to determine the first membership feature of user permissions under multiple organizational structures includes:

[0039] Obtain user permission attributes, permission weights, and permission thresholds under different organizational structures to generate multi-scale permission data;

[0040] Multi-scale permission data is mapped to a multi-scale fusion multi-scale correlation model to generate a multi-scale fusion feature set;

[0041] Based on the multi-scale fusion characteristics, membership functions for different permission attributes, permission weights, and permission thresholds in different organizational structures are established sequentially.

[0042] Based on the membership function, establish the first authority association matrix under the multi-organizational structure and determine the first membership feature.

[0043] Furthermore, the step of inputting the permission object, permission weight, and permission threshold into the second multi-scale neural network to determine the second membership feature of user permissions under the multi-scale architecture includes:

[0044] Based on the effects of permission objects, permission weights, and permission thresholds on the triggering process of user organization permissions, a multi-level hierarchical permission triggering model is established.

[0045] Based on the permission-triggered model, determine the multi-scale input parameters;

[0046] Based on the multi-scale input parameters, determine the indicator weights of each authority indicator in the multi-level hierarchy;

[0047] The index weights are input into the second multi-scale neural network to determine the multi-scale feature weights.

[0048] The multi-scale feature weights are transformed into second membership features using the Sigmoid function.

[0049] Furthermore, the first membership feature and the second membership feature are input into the trained multi-permission fusion network to generate multiple permission mapping functions, including:

[0050] Identify the multiple organizational structures to which users belong and construct a distributed multi-organizational structure network;

[0051] The fusion parameters are determined after the first membership feature and the second membership feature are input into the trained multi-authority fusion network.

[0052] The fusion parameters are associated with different network branches of the multi-organizational network to generate a permission mapping function.

[0053] Furthermore, the process of associating the fusion parameters with different network branches of the multi-organizational network includes...

[0054] Determine the associated computational tasks corresponding to any network branch in a multi-organizational network;

[0055] Based on the fusion parameters and the associated computational tasks, determine the unique functional correlation between different network branches and the fusion parameters;

[0056] Based on the unique functional correlation, the correlation mapping relationship between different network branches and fusion parameters is determined, and the correlation mapping function is generated;

[0057] Generate permission mapping functions by associating the mapping functions with user permissions.

[0058] Furthermore, generating the user's permission fusion identifier based on the permission mapping function includes:

[0059] In response to the permission mapping function, generate the user's permission hash ring;

[0060] The unique function solutions for user permissions in multiple organizational structures are recorded sequentially through the permission hash ring, and the unique function solutions are used as the unique mappings of the permission hash ring.

[0061] A unique mapping is used to generate a user's permission fusion identifier.

[0062] The advantages of this invention are as follows:

[0063] This invention enables fine-grained management of user permissions by analyzing user organizational permissions and permission levels. For the same user across different organizational structures, permission fusion can be implemented, and a verification method can then be used to enable permission invocation across multiple organizational structures. By training a multi-permission fusion network, this invention generates a permission mapping function that intelligently handles permission fusion issues, adapting to permission management across multiple organizational structures. It exhibits strong adaptability and scalability for organizational restructuring or permission changes. The generation and binding of user permission fusion identifiers in this invention clearly reveals the scope of each user's permissions, improving the transparency of permission management.

[0064] Other features and advantages of the invention will be set forth in the following description, and will be apparent in part from the description, or may be learned by practicing the invention. The objects and other advantages of the invention may be realized and obtained by means of the structures particularly pointed out in the written description and the accompanying drawings.

[0065] The technical solution of the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. Attached Figure Description

[0066] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used together with the embodiments of the invention to explain the invention and do not constitute a limitation thereof.

[0067] In the attached diagram:

[0068] Figure 1 This is a flowchart of a method for integrating multiple organizational structures and user permissions in an embodiment of the present invention;

[0069] Figure 2 This is a diagram illustrating the process of generating the permission data set in an embodiment of the present invention;

[0070] Figure 3 This is a flowchart illustrating the generation process of the permission fusion identifier in an embodiment of the present invention. Detailed Implementation

[0071] The preferred embodiments of the present invention will be described below with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are for illustration and explanation only and are not intended to limit the present invention.

[0072] like Figure 1 As shown, this embodiment provides a multi-organizational architecture and user permission fusion method proposed by the present invention, including:

[0073] Obtain users' organizational permissions and permission levels in different organizations, and generate permission data sets;

[0074] Based on organizational permissions, determine the user's permission attributes and permission objects within different organizations;

[0075] Based on the permission level, determine the permission weight and permission threshold of a user in different organizations;

[0076] Input the permission attributes, permission weights, and permission thresholds into the first multi-scale neural network to determine the first membership feature of user permissions under multiple organizational structures;

[0077] Input the permission object, permission weight, and permission threshold into the second multi-scale neural network to determine the second membership feature of user permissions under the multi-scale architecture;

[0078] Input the first membership feature and the second membership first feature into the trained multi-permission fusion network to generate multiple permission mapping functions;

[0079] Based on the permission mapping function, a permission fusion identifier for the user is generated, and the permission fusion identifier is bound to multiple organizations to which the user belongs.

[0080] The principle behind the above technical solution is as follows:

[0081] In practical implementation, this invention first obtains the user's organizational permissions and permission levels in different organizations, generating a permission data set. It then verifies the user's identity and queries permission records in each organization to obtain the user's permissions and permission levels within each organization. Next, based on the organizational permissions, it determines the user's permission attributes and permission objects within different organizations. This is achieved through analysis of the permission data.

[0082] Then, based on the permission level, the permission weight and permission threshold of the user in different organizations are determined. Specifically, through further analysis of permission data and permission attributes, the permission weight and permission threshold of the user in different organizations are determined.

[0083] Next, the permission attributes, permission weights, and permission thresholds are input into the first multi-scale neural network to determine the first membership features of user permissions under multiple organizational architectures. Specifically, the permission attributes, permission weights, and permission thresholds of users in different organizations are used as inputs, and the first multi-scale neural network learns and processes these data to obtain the first membership features of user permissions under multiple organizational architectures.

[0084] Then, the permission object, permission weight, and permission threshold are input into the second multi-scale neural network to determine the second membership feature of user permissions under the multi-scale architecture. Specifically, the permission object, permission weight, and permission threshold of the user in different organizations are used as input, and the second multi-scale neural network learns and processes them to obtain the second membership feature of user permissions under the multi-scale architecture.

[0085] Finally, the first and second membership features are input into the trained multi-permission fusion network to generate multiple permission mapping functions. Specifically, the first and second membership features obtained in the first two steps are fused and combined to obtain multiple permission mapping functions. Next, based on the permission mapping functions, a user's permission fusion identifier is generated, and the permission fusion identifier is bound to multiple organizations to which the user belongs.

[0086] In this process, user permissions are mapped to corresponding permission objects, generating a user permission fusion identifier. This identifier is then bound to multiple organizations to which the user belongs, allowing the user to switch freely between organizations while ensuring the consistency and integrity of user permissions. This invention extracts the membership features of user permissions through a multi-scale neural network, more accurately determining the user's permission position in complex organizational structures.

[0087] The beneficial effects of the above scheme are:

[0088] This invention enables fine-grained management of user permissions by analyzing user organizational permissions and permission levels. For the same user across different organizational structures, permission fusion can be implemented, and a verification method can then be used to enable permission invocation across multiple organizational structures. By training a multi-permission fusion network, this invention generates a permission mapping function that intelligently handles permission fusion issues, adapting to permission management across multiple organizational structures. It exhibits strong adaptability and scalability for organizational restructuring or permission changes. The generation and binding of user permission fusion identifiers in this invention clearly reveals the scope of each user's permissions, improving the transparency of permission management.

[0089] As one embodiment of the present invention, the generated permission set further includes:

[0090] Obtain the organization to which the user belongs, and build the user permission model in each organization;

[0091] Based on the permission model, the permission scope and permission type of users in each organization are identified sequentially.

[0092] Based on the permission types of users in each organization, determine the permission triggering events for different permissions of users in each organization;

[0093] Determine the permission identifier of each user in the organization based on the permission-triggered events;

[0094] Based on the permission type and permission identifier, the permission data of users in each organization are identified sequentially, and the corresponding permission subset is generated.

[0095] The permission subsets are merged to form a permission data set.

[0096] The principle behind the above technical solution is as follows:

[0097] like Figure 2 As shown, in actual implementation, organization affiliation identification aims to determine which organizations a user belongs to. This involves defining the organizational categories for permission integration, as different organizations may have different permissions. Permission model building involves constructing a permission model for each organization to which a user belongs. The permission model defines the permission structure and types for users within that organization.

[0098] Permission scope and type identification uses a permission model to identify the scope of a user's permissions (i.e., which resources a user can access) and the type of permissions (such as functional permissions, data permissions, etc.) within each organization. Permission trigger event determination involves defining permission trigger events based on the permission type. These events are the conditions or actions that trigger permissions to take effect, such as user login, access to a specific application, or execution of a specific operation.

[0099] Permission identifier determination involves assigning a unique identifier to each permission-triggered event. This identifier is used to uniquely identify permissions within the permission dataset. Permission data identification and subset generation involve identifying the specific permission data of a user within each organization based on the permission type and the permission identifier, and generating a permission subset.

[0100] Permission subset fusion is the process of combining all permission subsets to form a comprehensive permission data set, which represents a user's overall permissions across all organizations.

[0101] This invention provides fine-grained permission management by identifying and defining permission scope, type, and triggering events, enabling precise control over user behavior and resource access. The permission model is designed to adapt to changes in organizational structure, allowing for flexible addition or modification of permissions, thereby improving system scalability. By integrating permission subsets from different organizations, it ensures consistency of user permissions across different organizations, avoiding permission conflicts and confusion.

[0102] As an embodiment of the present invention, the step of sequentially identifying the permission data of users in each organization includes:

[0103] Determine the first trigger result of the first permission triggering event for the user's target permission in each organization, wherein the first trigger result is used to execute the user's instruction after the first permission triggering event is triggered;

[0104] Based on the first trigger result, determine the scope of the user's target permissions and the topological organization nodes that match the corresponding permissions;

[0105] Based on the topology organization nodes, obtain the node data of each topology organization node in sequence, and generate permission data.

[0106] The principle behind the above technical solution is as follows:

[0107] In actual implementation, the permission triggering event and its result can determine the first permission triggering event for a user's target permission, that is, the specific event or condition that triggers the permission to take effect. The first triggering result is the action or command that should be executed when this permission triggering event occurs, usually executing a certain instruction from the user.

[0108] The scope of permissions and topology organization nodes are determined based on the initial trigger result. This determines the scope of a user's target permissions, i.e., the specific resources or functions the user can access or operate. Simultaneously, topology organization nodes that match these permissions are identified. A topology organization node refers to a specific location within the network or organizational structure, representing the specific scope of the permission's effect.

[0109] Node data acquisition and permission data generation involve sequentially retrieving data from each node within a defined organizational topology. This data may include organizational structure, resource information, and role information. Based on this node data, permission data is generated, defining the user's permissions on specific organizational nodes.

[0110] Event-driven access control defines permission triggering events and their results, thus enabling access control to be closely linked to specific user behaviors or system events, thereby improving the real-time performance and responsiveness of access control.

[0111] This invention, by defining the scope of permissions and topological organizational nodes, can precisely define the range of user permissions, thereby preventing permission abuse and misuse. By acquiring data from the topological organizational nodes, structured permission data can be generated, which is easier for the system to understand and execute, improving the accuracy and efficiency of permission configuration. This solution allows permission configuration to be combined with the organization's topology, making permission configuration more flexible and adaptable to dynamic changes in the organizational structure.

[0112] As an embodiment of the present invention, determining the user's permission attributes and permission objects in different organizations based on organizational permissions includes:

[0113] Based on organizational permissions, obtain application response information involved when a user triggers the corresponding user permission; among which, the application response information is the function options generated by the application triggered by the user permission when executing the user permission;

[0114] Based on the application response information, determine the permission attributes of the corresponding user permissions; among which, permission attributes include: permission identifier, permission name, permission description, permission level, permission group, permission scope, permission status, permission grantability, permission dependency, permission dynamism, and permission inheritance.

[0115] Based on the permission attributes, determine the permission objects directly associated with the corresponding user permissions.

[0116] The principle behind the above technical solution is as follows:

[0117] In practice, application response information acquisition occurs when a user triggers a specific permission, and the application response information related to that permission is obtained. Application response information represents the functional options provided by the application when executing user permissions; it reflects the application's response to the permission request.

[0118] Permission attribute determination involves identifying the permission attributes of a user based on the application's response information. These attributes are metadata that provides a detailed description and classification of permissions, including permission identifier, name, description, level, grouping, scope, status, assignability, dependency, dynamism, and inheritance.

[0119] The determination of permission objects is based on permission attributes; the system identifies permission objects directly associated with user permissions. A permission object refers to the specific entity to which the permission applies, such as a specific data record, functional module, or resource.

[0120] This invention achieves fine-grained permission management by acquiring application response information and determining permission attributes, making permission configuration more precise and flexible. The acquisition and use of application response information ensures that users receive appropriate feedback and functional options when executing permissions, thereby improving user experience. Detailed definitions of permission attributes help clearly describe various aspects of permissions, making permission management and understanding more intuitive. By identifying permission objects, user access to and operations on specific resources can be more precisely controlled, improving system security. Permission attributes provide multiple dimensions to describe permissions, allowing administrators to flexibly configure permissions according to actual needs. This solution considers permission dependencies and inheritance, which helps handle complex permission relationships, especially in multi-organizational architectures.

[0121] As an embodiment of the present invention, determining the user's permission weight and permission threshold in different organizations based on permission levels includes:

[0122] Determine the user's permission roles within different organizations based on permission levels;

[0123] Based on the permissions and roles, determine the corresponding organizational permissions of customers in different organizations and the resource sensitivity of different organizational businesses in turn;

[0124] Based on resource sensitivity, determine the minimum and maximum values ​​of resource sensitivity for users accessing services in different organizations within different organizations, and determine the permission thresholds relative to users of services in different organizations;

[0125] Based on the permission threshold, determine the first configuration weight of different organizational businesses relative to the corresponding organizational structure; where the first configuration weight is the business weight, which is used to represent the importance of user permissions;

[0126] Based on the permission roles, a second configuration weight is determined for different organizational businesses relative to the organizational structure; where the second configuration weight is the machine weight, which is used to represent the degree of influence of different permission roles on user permissions;

[0127] The permission weight is determined by a deep weighting of business weight and machine weight; the deep weighting is used for weight regularization.

[0128] The principle behind the above technical solution is as follows:

[0129] In practice, permission roles are assigned to users within different organizations based on their permission levels. A permission role is an abstraction of the operations a user can perform and the resources they can access within an organization. Resource sensitivity analysis analyzes the correspondence between user permission roles and the resource sensitivity of different organizational businesses. Resource sensitivity refers to the degree of confidentiality, integrity, and availability requirements of business resources. Permission thresholds, based on resource sensitivity, determine the minimum and maximum sensitivity values ​​for a user's access to resources in different organizational businesses, thus determining the user's permission threshold. Permission thresholds are the restrictions on a user's access to specific resources. Business weight configuration, based on permission thresholds, assigns a first configuration weight (business weight) to different organizational businesses relative to their organizational structure, representing the importance of user permissions relative to the business. Machine weight configuration, based on permission roles, determines a second configuration weight (machine weight) for different organizational businesses relative to the organizational structure, representing the magnitude of the impact of different permission roles on user permissions. Deep weighting determines permission weights by deep weighting of business weights and machine weights, i.e., regularizing the weights to determine the final permission weights. Deep weighting is used to balance the differences between different weights and ensure the rationality and accuracy of permission weights.

[0130] This invention enables fine-grained permission management by defining permission roles and resource sensitivity, ensuring that users can only access resources within their authorized scope. Setting permission thresholds effectively protects sensitive resources and prevents unauthorized access. Configuring business weights reflects the importance of different business functions, facilitating reasonable permission decisions in case of conflicts. Configuring machine weights considers the influence of different permission roles, making permission allocation more aligned with the organization's actual needs. Through deep weighting, permission weights can be flexibly adjusted to adapt to changes in organizational structure and business processes.

[0131] As an embodiment of the present invention, the step of inputting permission attributes, permission weights, and permission thresholds into a first multi-scale neural network to determine the first membership feature of user permissions under multiple organizational structures includes:

[0132] Obtain user permission attributes, permission weights, and permission thresholds under different organizational structures to generate multi-scale permission data;

[0133] Multi-scale permission data is mapped to a multi-scale fusion multi-scale correlation model to generate a multi-scale fusion feature set;

[0134] Based on the multi-scale fusion characteristics, membership functions for different permission attributes, permission weights, and permission thresholds in different organizational structures are established sequentially.

[0135] Based on the membership function, establish the first authority association matrix under the multi-organizational structure and determine the first membership feature.

[0136] The principle behind the above technical solution is as follows:

[0137] In practical implementation, multi-scale permission data generation involves collecting user permission attributes (such as permission identifiers, names, and descriptions), permission weights (reflecting permission importance), and permission thresholds (restrictions on permissions) across different organizational structures, and generating multi-scale permission data. This data contains permission information at different dimensions and granularities. Multi-scale fusion feature set generation maps the generated multi-scale permission data to a multi-scale fusion correlation model. This model can process and fuse data at different scales, generating a comprehensive feature set that reflects the correlation of permission data at different scales. Membership function establishment, based on the multi-scale fusion features, establishes membership functions for permission attributes, permission weights, and permission thresholds across different organizational structures. The membership function, a concept in fuzzy logic, describes the degree to which an element belongs to a set. First permission correlation matrix establishment uses membership functions to create a first permission correlation matrix across multiple organizational structures. This matrix represents the degree of correlation between different permissions. First membership feature determination determines the user's permission membership features, i.e., the degree to which a user's permissions belong to a specific permission set, based on the first permission correlation matrix.

[0138] This invention utilizes multi-scale data analysis to achieve a more comprehensive understanding and management of user permissions, adapting to the complexities of different organizational structures. The generation of multi-scale fusion feature sets enables the integration of different permission information across multiple dimensions, improving the accuracy of permission management. The application of membership functions makes permission management more flexible, handling the uncertainty of permission boundaries and better simulating permission relationships in real-world multi-organizational structures.

[0139] As an embodiment of the present invention, the step of inputting the permission object, permission weight, and permission threshold into a second multi-scale neural network to determine the second membership feature of user permissions under the multi-scale architecture includes:

[0140] Based on the effects of permission objects, permission weights, and permission thresholds on the triggering process of user organization permissions, a multi-level hierarchical permission triggering model is established.

[0141] Based on the permission-triggered model, determine the multi-scale input parameters;

[0142] Based on the multi-scale input parameters, determine the indicator weights of each authority indicator in the multi-level hierarchy;

[0143] The index weights are input into the second multi-scale neural network to determine the multi-scale feature weights.

[0144] The multi-scale feature weights are transformed into second membership features using the Sigmoid function.

[0145] The principle behind the above technical solution is as follows:

[0146] In practical implementation, a multi-level hierarchical permission triggering model is established. This is mainly achieved by analyzing the roles of permission objects, permission weights, and permission thresholds in different operation or decision-making processes. A multi-level model is constructed to simulate how these permissions are triggered or applied in different contexts. The multi-level hierarchical permission triggering model can reflect the interaction and influence between different permission elements. Determining multi-scale input parameters is based on the constructed permission triggering model, identifying the input parameters that need to be considered at different levels and scales. Input parameters may include the user's role, the sensitivity of the operation, and environmental conditions (such as access time and location).

[0147] Multi-scale analysis allows models to consider these factors at different levels of abstraction, thus better capturing the details of complex permission logic. Determining the weights of each permission indicator involves analyzing and evaluating the contribution and impact of different permission indicators on the overall permission management goals, assigning a weight to each indicator. This step directly affects the quality of the final permission decision. Inputting the obtained indicator weights into a specially designed multi-scale neural network and transforming them into second membership features involves further optimizing and integrating these weights to generate a more accurate and adaptive permission configuration scheme. Through the Sigmoid function transformation, the output can be standardized to between 0 and 1, forming the so-called second membership features. These second membership features more intuitively represent the degree of membership or access ability of a user to different permission objects.

[0148] As an embodiment of the present invention, the step of inputting the first membership feature and the second membership feature into the trained multi-permission fusion network to generate multiple permission mapping functions includes:

[0149] Identify the multiple organizational structures to which users belong and construct a distributed multi-organizational structure network;

[0150] The fusion parameters are determined after the first membership feature and the second membership feature are input into the trained multi-authority fusion network.

[0151] The fusion parameters are associated with different network branches of the multi-organizational network to generate a permission mapping function.

[0152] The technical principle of the above technical solution is as follows:

[0153] In practical implementation, building a distributed multi-organizational network involves establishing a network model that reflects the relationships between different organizations, departments, or roles within a user's multi-organizational structure. Essentially, the network model is a graph structure where nodes represent organizations, departments, or roles, and edges represent the permissions or data flow relationships between them.

[0154] Determining the fusion parameters involves inputting the first membership feature (which may represent permission assignment based on role or attribute) and the second membership feature (which may represent permission adjustment based on behavior, context, or predictive analytics) into a pre-trained multi-permission fusion network. The multi-permission fusion network learns the interactions and influences between the two membership features to determine a set of fusion parameters that optimally combine the two features to generate more accurate and adaptive permission configurations.

[0155] Generating permission mapping functions involves using defined fusion parameters to associate and map different network branches of a distributed, multi-organizational network. Essentially, it applies the fusion parameters to different parts of the network model to generate a series of permission mapping functions. These functions describe which permissions should be granted to users under different organizational structures and operational scenarios.

[0156] As an embodiment of the present invention, the step of associating and mapping the fusion parameters with different network branches of the multi-organizational network includes:

[0157] Determine the associated computational tasks corresponding to any network branch in a multi-organizational network;

[0158] Based on the fusion parameters and the associated computational tasks, determine the unique functional correlation between different network branches and the fusion parameters;

[0159] Based on the unique functional correlation, the correlation mapping relationship between different network branches and fusion parameters is determined, and the correlation mapping function is generated;

[0160] Assign the mapping function to the user's permissions to generate the permission mapping function.

[0161] The principle behind the above technical solution is as follows:

[0162] In practical implementation, identifying the associated computational tasks involves recognizing the specific computational tasks that each network branch in a multi-organizational network needs to perform. These tasks may be related to data access, access control, policy enforcement, etc. Determining unique functional relationships is based on fusion parameters (which comprehensively consider various factors such as user attributes, behavioral patterns, and environmental conditions). This step aims to establish a mathematical relationship between each network branch and the fusion parameters. This typically involves complex algorithm design to ensure that each network branch can adjust its behavior (such as access control policies) according to changes in the fusion parameters.

[0163] The generation of association mapping functions involves creating a unique association mapping function for each network branch based on the unique functional relationships defined above. These functions define how to dynamically adjust permission configurations according to fusion parameters, thereby achieving more flexible and granular permission management.

[0164] As an embodiment of the present invention, generating the user's permission fusion identifier according to the permission mapping function includes:

[0165] In response to the permission mapping function, generate the user's permission hash ring;

[0166] The unique function solutions for user permissions in multiple organizational structures are recorded sequentially through the permission hash ring, and the unique function solutions are used as the unique mappings of the permission hash ring.

[0167] A unique mapping is used to generate a user's permission fusion identifier.

[0168] The principle behind the above technical solution is as follows:

[0169] like Figure 3 As shown, in practical implementation, a permission hash ring is generated, and a permission mapping function is used to generate the user's permission hash ring. A hash ring is a data structure used in consistent hashing algorithms in distributed systems to effectively manage and locate data. In this application, it is used to manage and locate user permission information. A unique function solution record sequentially records the unique function solutions of user permissions in a multi-organizational architecture through the permission hash ring. A unique function solution refers to a unique result calculated by the permission mapping function for each permission; this result represents the permission's position on the hash ring. A unique mapping is used as a unique mapping on the permission hash ring based on the unique function solution for each permission. This means that each permission can find a unique position on the hash ring, thus ensuring the uniqueness of the permission identifier. The permission fusion identifier is generated by the above unique mapping, creating the user's permission fusion identifier. The permission fusion identifier is a comprehensive representation of all permissions a user has in a multi-organizational architecture; it can be used to quickly identify and verify a user's permission set.

[0170] Obviously, those skilled in the art can make various modifications and variations to this invention without departing from its spirit and scope. Therefore, if these modifications and variations fall within the scope of the claims of this invention and their equivalents, this invention also intends to include these modifications and variations.

Claims

1. A method for integrating multiple organizational structures and user permissions, characterized in that, include: Obtain users' organizational permissions and permission levels in different organizations, and generate permission data sets; Based on organizational permissions, determine the user's permission attributes and permission objects within different organizations; Based on the permission level, determine the permission weight and permission threshold of a user in different organizations; The step of determining the user's permission weight and permission threshold within different organizations based on permission levels includes: Determine the user's permission roles within different organizations based on permission levels; Based on the permission roles, determine the resource sensitivity of the customer's organizational permissions in different organizations, corresponding to the business operations of different organizations; Based on resource sensitivity, determine the minimum and maximum values ​​of resource sensitivity for users accessing services in different organizations within different organizations, and determine the permission thresholds relative to users of services in different organizations; Based on the permission threshold, determine the first configuration weight of different organizational businesses relative to the corresponding organizational structure; where the first configuration weight is the business weight, which is used to represent the importance of user permissions; Based on the permission roles, a second configuration weight is determined for different organizational businesses relative to the organizational structure; where the second configuration weight is the machine weight, which is used to represent the degree of influence of different permission roles on user permissions; The permission weight is determined by a deep weighting of business weight and machine weight; the deep weighting is used for weight regularization. Input the permission attributes, permission weights, and permission thresholds into the first multi-scale neural network to determine the first membership feature of user permissions under multiple organizational structures; The step of inputting permission attributes, permission weights, and permission thresholds into a first multi-scale neural network to determine the first membership feature of user permissions under multiple organizational structures includes: Obtain user permission attributes, permission weights, and permission thresholds under different organizational structures to generate multi-scale permission data; Multi-scale permission data is mapped to a multi-scale fusion multi-scale correlation model to generate a multi-scale fusion feature set; Based on the multi-scale fusion characteristics, membership functions for different permission attributes, permission weights, and permission thresholds in different organizational structures are established sequentially. Based on the membership function, establish the first authority association matrix under the multi-organizational structure and determine the first membership feature; Input the permission object, permission weight, and permission threshold into the second multi-scale neural network to determine the second membership feature of user permissions under the multi-scale architecture; Input the first membership feature and the second membership first feature into the trained multi-permission fusion network to generate multiple permission mapping functions; Based on the permission mapping function, a permission fusion identifier for the user is generated, and the permission fusion identifier is bound to multiple organizations to which the user belongs.

2. The method for integrating multiple organizational structures and user permissions as described in claim 1, characterized in that, The generated permission data set also includes: Obtain the organization to which the user belongs, and build the user permission model in each organization; Based on the permission model, the permission scope and permission type of users in each organization are identified sequentially. Based on the permission types of users in each organization, determine the permission triggering events for different permissions of users in each organization; Determine the permission identifier of each user in the organization based on the permission-triggered events; Based on the permission type and permission identifier, the permission data of users in each organization are identified sequentially, and the corresponding permission subset is generated. The permission subsets are merged to form a permission data set.

3. The method for integrating multiple organizational structures and user permissions as described in claim 2, characterized in that, The step of sequentially identifying user permission data in each organization includes: Determine the first trigger result of the first permission triggering event for the user's target permission in each organization, wherein the first trigger result is used to execute the user's instruction after the first permission triggering event is triggered; Based on the first trigger result, determine the scope of the user's target permissions and the topological organization nodes that match the corresponding permissions; Based on the topology organization nodes, obtain the node data of each topology organization node in sequence, and generate permission data.

4. The method for integrating multiple organizational structures and user permissions as described in claim 1, characterized in that, The step of determining the user's permission attributes and permission objects within different organizations based on organizational permissions includes: Based on organizational permissions, obtain application response information involved when a user triggers the corresponding user permission; among which, the application response information is the function options generated by the application triggered by the user permission when executing the user permission; Based on the application response information, determine the permission attributes of the corresponding user permissions; among which, permission attributes include: permission identifier, permission name, permission description, permission level, permission group, permission scope, permission status, permission grantability, permission dependency, permission dynamism, and permission inheritance. Based on the permission attributes, determine the permission objects directly associated with the corresponding user permissions.

5. The method for integrating multiple organizational structures and user permissions as described in claim 1, characterized in that, The step of inputting the permission object, permission weight, and permission threshold into the second multi-scale neural network to determine the second membership feature of user permissions under the multi-scale architecture includes: Based on the effects of permission objects, permission weights, and permission thresholds on the triggering process of user organization permissions, a multi-level hierarchical permission triggering model is established. Based on the permission-triggered model, determine the multi-scale input parameters; Based on the multi-scale input parameters, determine the indicator weights of each authority indicator in the multi-level hierarchy; The index weights are input into the second multi-scale neural network to determine the multi-scale feature weights. The multi-scale feature weights are transformed into second membership features using the Sigmoid function.

6. The method for integrating multiple organizational structures and user permissions as described in claim 1, characterized in that, The first membership feature and the second membership feature are input into the trained multi-permission fusion network to generate multiple permission mapping functions, including: Identify the multiple organizational structures to which users belong and construct a distributed multi-organizational structure network; The fusion parameters are determined after inputting the first membership feature and the second membership feature into the trained multi-authority fusion network. The fusion parameters are associated with different network branches of the multi-organizational network to generate a permission mapping function.

7. The method for integrating multiple organizational structures and user permissions as described in claim 6, characterized in that, The process of associating and mapping the fusion parameters with different network branches of a multi-organizational network includes: Determine the associated computational tasks corresponding to any network branch in a multi-organizational network; Based on the fusion parameters and the associated computational tasks, determine the unique functional correlation between different network branches and the fusion parameters; Based on the unique functional correlation, the correlation mapping relationship between different network branches and fusion parameters is determined, and the correlation mapping function is generated; Assign the mapping function to the user's permissions to generate the permission mapping function.

8. The method for integrating multiple organizational structures and user permissions as described in claim 1, characterized in that, The step of generating a user's permission fusion identifier based on the permission mapping function includes: In response to the permission mapping function, generate the user's permission hash ring; The unique function solutions for user permissions in multiple organizational structures are recorded sequentially through the permission hash ring, and the unique function solutions are used as the unique mappings of the permission hash ring. A unique mapping is used to generate a user's permission fusion identifier.

Citation Information

Patent Citations

  • User permission fusion method, system and device based on multi-organizational architecture

    CN116805070B

  • Decision permission division method of man-machine task decision system

    CN114139196A

  • User permission fusion method, system and device based on multi-organization structure

    CN116805070A