4A Account Role Permission Control System Based on Business Process Authorization

By designing a 4A account role authority control system based on business process authorization, the shortcomings of permission management problems in the existing technology are solved, more accurate authorization and more efficient management are achieved, and security risks and risk of overreach of rights are reduced.

CN119885245BActive Publication Date: 2025-06-10CHINA TOWER CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510369030.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-27
Publication Date
2025-06-10
Estimated Expiration
2045-03-27

AI Technical Summary

Technical Problem

The existing role-based authorization methods cannot effectively adapt to complex and changeable organizational regional structures and business scenarios, resulting in permission management problems, such as unclear permission requirements, inaccurate authorization, and risk of data overreach, which brings security risks to the company's business development.

Method used

Design a 4A account role authority management system based on business process authorization, and build a job-role-business database through the data acquisition module, combining the importance empowerment module, the role automatic authorization module and the role audit module to realize automatic or manual role authorization to ensure the accuracy and management efficiency of authorization.

Benefits of technology

It improves the accuracy and management efficiency of authorization, reduces the risk of overreach of authority, enhances the security and controllability of account management, and adapts to complex and changeable organizational structures and business scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119885245B_ABST
    Figure CN119885245B_ABST
Patent Text Reader

Abstract

The present invention relates to a 4A account role permission control system based on business process authorization, belonging to the field of information technology. The system includes a data collection module, a position-role-business database, an importance weighting module, an input module for positions to be authorized, a data processing module, a role automatic authorization module, a role manual authorization module, a role review module, a business verification module, a role assignment module and other modules. The present invention can realize the control of 4A account role permissions, and can automatically or manually authorize roles for the positions of 4A accounts, which not only improves the accuracy of authorization, but also improves the management efficiency and is easy to promote and apply.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of information technology, and particularly relates to a 4A account role permission control system based on business process authorization. Background Art

[0002] Under the background of current digital human evaluation and strengthening regional account management, the existing role-based authorization method can no longer fit the complex and changeable organizational regional architecture and business scenarios of the company, resulting in various account permission management problems and posing security risks to the company's operation and development. For example, there are security risk problems such as unclear permission requirements, inaccurate authorization, etc. Specifically, after a user has a 4A account, they will also have the positions bound to the 4A account. Different positions play different roles in work, such as the role responsible for OA replies, the role responsible for business management, etc. In actual work, there may be multiple roles for the same position and they need to participate in multiple businesses; therefore, according to the actual work situation, one or more roles corresponding to the position will be assigned to each position; each role corresponds to one or more businesses; for example, the role responsible for business management may include multiple businesses such as order processing, billing processing, and report management.

[0003] The following are the deficiencies of the existing technology:

[0004] 1. Incompatibility between permission positions: unclear permission requirements, inaccurate authorization, unclear permission functions, and no audit for job transfers;

[0005] 2. Difficulties in permission application, review, and allocation: complex business processes, frequent business changes, applicants are not familiar with permissions, and configurators are not familiar with the business;

[0006] 3. Risk of multiple accounts for one person: problems such as multiple accounts, difficult management, and inconvenient use;

[0007] 4. Risk of data over-authorization: separation of data permissions and role permissions, and most systems do not design data permission control, etc.

[0008] Therefore, how to overcome the deficiencies of the existing technology is an urgent problem to be solved in the current field of information technology. Summary of the Invention

[0009] The purpose of the present invention is to solve the deficiencies of the existing technology and provide a 4A account role permission control system based on business process authorization.

[0010] To achieve the above purpose, the technical solution adopted by the present invention is as follows:

[0011] A 4A account role permission control system based on business process authorization, comprising:

[0012] A data acquisition module, which is used to collect the positions, roles and business information of historical 4A accounts, obtain the corresponding relationships between positions and roles, and between roles and businesses, and construct a position-role-business database;

[0013] A position-role-business database, which is connected to the data acquisition module and is used to store the position, role and business information collected by the data acquisition module, as well as the corresponding relationship table between positions and roles and the corresponding relationship table between roles and businesses;

[0014] An importance weighting module, which is respectively connected to the data acquisition module and the position-role-business database, is used to sort the importance levels of the businesses collected by the data acquisition module, then assign importance weights to the businesses according to the sorting results, the higher the importance level, the higher the weight, and then store them in the position-role-business database;

[0015] A position input module to be authorized, which is used to input the name and attributes of the position to be authorized; the position to be authorized is a position that has not been given role and business permissions;

[0016] A data processing module, which is respectively connected to the position-role-business database and the position input module to be authorized; a business weight threshold is pre-stored in the data processing module;

[0017] The data processing module is used to obtain all possible roles corresponding to the position name input by the position input module to be authorized according to the corresponding relationship table between positions and roles stored in the position-role-business database, and then obtain all possible businesses corresponding to these roles according to the corresponding relationship table between roles and businesses stored in the position-role-business database; then compare the business weights of these businesses with the business weight threshold respectively. If there is a situation where the business weight is greater than the business weight threshold, then this position is an important position; otherwise, it is a non-important position;

[0018] A role automatic authorization module, which is respectively connected to the position-role-business database, the position input module to be authorized and the data processing module; a role automatic authorization dual tower network model is pre-stored in the role automatic authorization module;

[0019] The role automatic authorization module is used to input the position attributes input by the position input module to be authorized into the first input channel of the role automatic authorization dual - tower network model, and input each role stored in the position - role - business database and the corresponding business of each role into the second input channel of the role automatic authorization dual - tower network model to obtain the matching scores between the position attributes and the roles; select the top three roles with the highest matching scores as the automatically authorized roles; if the data processing module determines that this position is an important position, then transmit the automatically authorized roles to the role manual authorization module; if the data processing module determines that this position is a non - important position, then transmit the automatically authorized roles and the corresponding business to the role review module;

[0020] The role manual authorization module is respectively connected to the position - role - business database, the position input module to be authorized, and the role automatic authorization module, and is used to obtain all possible roles and the corresponding business that the name of the position to be authorized input by the position input module to be authorized may correspond to according to the corresponding relationship table between positions and roles and the corresponding relationship table between roles and businesses stored in the position - role - business database, and perform manual processing according to the transmitted automatically authorized roles and the corresponding business to obtain the manually authorized roles; then transmit the manually authorized roles and the corresponding business to the role review module;

[0021] The role review module is respectively connected to the position input module to be authorized, the role automatic authorization module, and the role manual authorization module, and is used to review the automatically authorized roles for non - important positions, and review whether the automatically authorized roles conflict with the name and attributes of the position to be authorized input by the position input module to be authorized. If there is a conflict, it is considered that the review fails, and then the name, attributes, automatically authorized roles, and the corresponding business of the non - important position are returned to the role manual authorization module for manual processing; if there is no conflict, the review passes;

[0022] The role review module is also used to review whether the manually authorized roles transmitted by the role manual authorization module conflict with the name and attributes of the position to be authorized input by the position input module to be authorized. If there is a conflict, the name, attributes, manually authorized roles, and the corresponding business of this position are returned to the role manual authorization module for manual processing again; if there is no conflict, the review passes;

[0023] The business verification module is respectively connected to the role automatic authorization module and the role review module, and is used to verify the businesses corresponding to all the roles authorized for the position that has passed the review by the role review module. If there are duplicate businesses, perform an elimination operation. After elimination, transmit the roles and businesses corresponding to this position to the role manual authorization module for manual processing; if not, the verification passes;

[0024] The role assignment module is respectively connected to the position input module to be authorized and the business verification module, and is used to assign roles to the positions to be authorized according to the roles and corresponding businesses verified and passed by the business verification module.

[0025] Furthermore, in the position input module to be authorized, the position attributes include the code, level, department, rank, function corresponding to the position name, and the 4A account associated with the position name of the position to be authorized input, and also include the city where the 4A account user is located and the working years.

[0026] Furthermore, in the role manual authorization module, the manual processing includes deleting roles, adding roles, and confirming roles.

[0027] Furthermore, in the role review module, during the review, if any of the department mismatch, level mismatch, or rank mismatch exists, it is judged as a contradiction and the review fails.

[0028] Furthermore, in the business verification module, the specific method of the elimination operation is as follows:

[0029] Set the repeated business as business M, and obtain the roles containing business M from all the roles authorized for this position;

[0030] For the obtained roles containing business M, obtain their matching scores in the automatic authorization module;

[0031] Retain business M in the role with the highest matching score; eliminate business M in other roles.

[0032] Furthermore, the data collection module is also used to periodically collect the roles corresponding to each position and the business information corresponding to the roles;

[0033] It also includes an empty business screening module and a data management module;

[0034] The empty business screening module is respectively connected to the data collection module and the position-role-business database, and is used to compare the information periodically collected by the data collection module with the information in the position-role-business database. If a certain role is not assigned to any position, or a certain business does not generate a corresponding role, the role information not assigned to any position and the business information not generating a corresponding role are sent to the data management module;

[0035] The data management module is respectively connected to the empty business screening module and the position-role-business database, and is used to manage positions, roles, and businesses; manage the roles not assigned to any position and the businesses not generating corresponding roles.

[0036] Further, the business verification module is also connected to the data acquisition module, and is used to screen according to the periodically collected roles corresponding to each position and the business information corresponding to the roles. If the position names of different 4A accounts are the same, and the same roles and businesses are assigned, the 4A account and its position, role, and business information will be sent to the data management module for manual processing, and the management staff will perform manual confirmation or role deletion.

[0037] Further, in the role automatic authorization module, the role automatic authorization twin tower network model includes an input layer, a representation layer, an interaction layer, a matching layer, and an output layer; the input layer, the representation layer, the interaction layer, the matching layer, and the output layer are connected in sequence;

[0038] In the input layer, the position attributes of the position are input into the first input channel, and the roles corresponding to the position and the businesses corresponding to each role are input into the second input channel;

[0039] In the representation layer, the position attributes are processed to obtain the semantic vector embedding1; the roles and the businesses corresponding to each role are processed to obtain the semantic vector embedding2, and it is sent to the interaction layer;

[0040] In the interaction layer, a matrix M is constructed, with a size of m×n; each cell in the matrix M is the similarity calculated by taking the dot product of the elements at each position of embedding1 and embedding2; calculating all the cells results in the similarity matrix M; the similarity matrix M is used as the input to the matching layer;

[0041] In the matching layer, 2D convolution and pooling are performed on the similarity matrix M, and finally a matching vector is obtained through a fully connected layer, which is used as the input to the output layer;

[0042] In the output layer, a softmax calculation is performed on the vector of the matching layer, and the matching scores of the position attributes of the position and the roles are output.

[0043] Further, the data acquisition module is also used to periodically collect the business processing situation. If there is a business that has not been processed for a long time, a warning will be issued, and the warning information will be sent to the data management module; then, the name and attributes of the position to be authorized will be input again through the position input module to be authorized, and the roles and corresponding businesses will be assigned again.

[0044] Further, the data acquisition module periodically collects the business operation situations corresponding to each position; if the business has not been operated for a continuous number of processing cycles, the 4A account and its position, role, and business information will be sent to the data management module for manual processing, and the business under the 4A account will be deleted.

[0045] When the present invention assigns weights to the importance of services, existing methods can be used, and the present invention does not impose special restrictions on this.

[0046] In the present invention, the services corresponding to roles are fixed; the services among different roles are not completely the same; for example, role A corresponds to service A; role B corresponds to service B; role B' corresponds to services A and B; role C corresponds to services A and C, and so on.

[0047] In the present invention, when the data acquisition module performs periodic acquisition, the present invention does not specifically limit this period, which can be set according to actual situations, such as one month.

[0048] In the present invention, the data management module manages positions, roles, and services, and manages roles that have not been assigned to any position and services for which corresponding roles have not been generated. Here, management includes modification, warning, and cleaning.

[0049] In the role review module of the present invention, during review, if there is any one of the following inconsistencies: department mismatch (for example, a user in the finance department applies for a position in the maintenance department), level mismatch (such as a city applying for provincial or headquarters authority), or rank mismatch (such as an employee applying for manager authority), it is determined as a contradiction and the review fails.

[0050] The present invention establishes a corresponding relationship between the user's 4A account and positions, roles, and services, and through regular audits, issues warnings to strengthen account and permission management, thereby effectively solving the problems existing in the background technology.

[0051] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0052] The present invention provides a 4A account role permission control system based on business process authorization, which can realize 4A account role permission control, and can automatically or manually authorize roles for the positions of 4A accounts. It not only improves the accuracy of authorization but also improves management efficiency, and is easy to promote and apply.

[0053] Existing methods only perform authorization on demand, without standardized management during the process, resulting in a relatively large number of unauthorized or unnecessary permission grants. Since there is no audit and verification, it is difficult to detect account unauthorized issues. Now, through the method of the present invention with layer-by-layer review and verification, effective 4A account role permission control can be carried out, and there will be no unauthorized situations, facilitating account management and cleaning up unauthorized authorizations. BRIEF DESCRIPTION OF THE DRAWINGS

[0054] Figure 1 It is a structural schematic diagram of the 4A account role permission control system based on business process authorization of the present invention;

[0055] Figure 2This is another structural schematic diagram of the 4A account role permission control system based on business process authorization of the present invention;

[0056] Figure 3 This is yet another structural schematic diagram of the 4A account role permission control system based on business process authorization of the present invention;

[0057] Figure 4 This is the structural schematic diagram of the dual - tower network model for automatic role authorization of the present invention;

[0058] Figure 5 This is the flowchart of the training, automatic authorization and subsequent manual authorization of the dual - tower network model for automatic role authorization

[0059] Figure 6 This is the flowchart of role authorization for important positions and non - important positions. Detailed implementation manners

[0060] The present invention will be further described in detail below with reference to the embodiments.

[0061] Those skilled in the art will understand that the following embodiments are only used to illustrate the present invention and should not be regarded as limiting the scope of the present invention. For those not specified in the embodiments regarding specific technologies, connection relationships or conditions, they shall be performed according to the technologies, connection relationships, conditions described in the literature in this field or according to the product manuals. Those materials, instruments or equipment not specified as to the manufacturer can all be obtained as conventional products through purchase.

[0062] Those skilled in the technical field of the present invention can understand that, unless specifically stated otherwise, the singular forms "a", "an", "the" and "said" used herein may also include the plural forms. It should be further understood that the term "comprising" used in the description of the present invention means the presence of the described features, integers, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or their groups. It should be understood that when we say an element is "connected" to another element, it can be directly connected to other elements, or there may also be intermediate elements. In addition, the "connection" used herein may include wireless connection. The phrase "and / or" used herein includes any and all combinations of one or more of the associated listed items.

[0063] In the description of the present invention, unless otherwise stated, "a plurality of" means two or more. The orientation or positional relationship indicated by terms such as "inside", "above", "below", etc. is based on the orientation or positional relationship shown in the drawings, and is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and thus cannot be understood as a limitation to the present invention.

[0064] In the description of the present invention, it should be noted that unless otherwise clearly specified and defined, the terms "installation", "connection", and "provided with" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be directly connected or indirectly connected through an intermediate medium. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention should be understood according to specific circumstances.

[0065] Those skilled in the art of the present technology can understand that unless otherwise defined, all terms (including technical terms and scientific terms) used herein have the same meaning as the general understanding of those of ordinary skill in the art to which the present invention belongs. It should also be understood that terms such as those defined in a general dictionary should be understood to have a meaning consistent with the meaning in the context of the prior art, and will not be interpreted with an idealized or overly formal meaning unless defined as herein.

[0066] Embodiment 1

[0067] As Figure 1 shown, a 4A account role permission control system based on business process authorization includes:

[0068] A data collection module 1, which is used to collect the positions, roles, and business information of historical 4A accounts, obtain the corresponding relationships between positions and roles, and between roles and businesses, and construct a position-role-business database;

[0069] A position-role-business database 2, which is connected to the data collection module 1 and is used to store the positions, roles, and business information collected by the data collection module 1, as well as the corresponding relationship tables between positions and roles and between roles and businesses;

[0070] An importance weighting module 3, which is respectively connected to the data collection module 1 and the position-role-business database 2, is used to sort the importance of the businesses collected by the data collection module 1, and then assign importance weights to the businesses according to the sorting results. The higher the importance, the higher the weight, and then store them in the position-role-business database 2;

[0071] A position input module 4 to be authorized, which is used to input the name and attributes of the position to be authorized; the position to be authorized is a position that has not been granted role and business permissions;

[0072] A data processing module 5, which is respectively connected to the position-role-business database 2 and the position input module 4 to be authorized; a business weight threshold is pre-stored in the data processing module 5;

[0073] The data processing module 5 is used to obtain all the roles that the job name input by the job to be authorized input module 4 may correspond to according to the corresponding relationship table between jobs and roles stored in the job-role-business database 2, and then obtain all the services that these roles may correspond to according to the corresponding relationship table between roles and services stored in the job-role-business database 2; then compare the service weights of these services with the service weight threshold respectively. If there is a situation where the service weight is greater than the service weight threshold, then this job is an important job; otherwise, it is a non-important job;

[0074] The role automatic authorization module 6 is respectively connected to the job-role-business database 2, the job to be authorized input module 4, and the data processing module 5; a role automatic authorization dual tower network model is pre-stored in the role automatic authorization module 6;

[0075] The role automatic authorization module 6 is used to input the job attributes input by the job to be authorized input module 4 into the first input channel of the role automatic authorization dual tower network model, and input each role stored in the job-role-business database 2 and the services corresponding to each role into the second input channel of the role automatic authorization dual tower network model to obtain the matching scores of the job attributes and the roles; select the top three roles with the highest matching scores as the automatically authorized roles; if the data processing module 5 determines that this job is an important job, then transmit the automatically authorized roles to the role manual authorization module 7; if the data processing module 5 determines that this job is a non-important job, then transmit the automatically authorized roles and the corresponding services to the role review module 8;

[0076] The role manual authorization module 7 is respectively connected to the job-role-business database 2, the job to be authorized input module 4, and the role automatic authorization module 6, and is used to obtain all the roles and corresponding services that the job name to be authorized input by the job to be authorized input module 4 may correspond to according to the corresponding relationship table between jobs and roles and the corresponding relationship table between roles and services stored in the job-role-business database 2, and perform manual processing according to the transmitted automatically authorized roles and the corresponding services to obtain the manually authorized roles; then transmit the manually authorized roles and the corresponding services to the role review module 8;

[0077] The role review module 8 is respectively connected to the job to be authorized input module 4, the role automatic authorization module 6, and the role manual authorization module 7, and is used to review the automatically authorized roles of non-important jobs, and review whether the automatically authorized roles are contradictory to the job name and job attributes to be authorized input by the job to be authorized input module. If there is a contradiction, it is considered that the review fails, and then the job name, job attributes, automatically authorized roles and the corresponding services of the non-important job are returned to the role manual authorization module 7 for manual processing; if there is no contradiction, the review passes;

[0078] The role review module 8 is also used to check whether the manually authorized role transmitted by the role manual authorization module 7 conflicts with the name and attributes of the position to be authorized input by the position input module to be authorized. If there is a conflict, the name of the position, the attributes of the position, the manually authorized role, and the corresponding business will be returned to the role manual authorization module 7 for manual processing again; if there is no conflict, the review is passed;

[0079] The business verification module 9 is respectively connected to the role automatic authorization module 6 and the role review module 8, and is used to verify the businesses corresponding to all the roles authorized for the position passed by the role review module 8. If there are duplicate businesses, the elimination operation will be performed. After elimination, the roles and businesses corresponding to the position will be returned to the role manual authorization module 7 for manual processing; if not, the verification is passed;

[0080] The role assignment module 10 is respectively connected to the position input module 4 to be authorized and the business verification module 9, and is used to assign roles to the position to be authorized according to the roles and corresponding businesses passed by the business verification module 9.

[0081] Embodiment 2

[0082] As Figure 2 shown, the 4A account role permission control system based on business process authorization includes:

[0083] The data collection module 1 is used to collect the position, role and business information of historical 4A accounts, obtain the corresponding relationship between positions and roles, and the corresponding relationship between roles and businesses, and construct a position-role-business database;

[0084] The position-role-business database 2 is connected to the data collection module 1, and is used to store the position, role and business information collected by the data collection module 1, as well as the corresponding relationship table between positions and roles and the corresponding relationship table between roles and businesses;

[0085] The importance weighting module 3 is respectively connected to the data collection module 1 and the position-role-business database 2, and is used to sort the importance of the businesses collected by the data collection module 1, and then assign importance weights to the businesses according to the sorting results. The higher the importance, the higher the weight, and then store them in the position-role-business database 2;

[0086] The position input module 4 to be authorized is used to input the name and attributes of the position to be authorized; the position to be authorized is a position that has not been assigned role and business permissions yet;

[0087] The data processing module 5 is respectively connected to the position-role-business database 2 and the position input module 4 to be authorized; a business weight threshold is pre-stored in the data processing module 5;

[0088] The data processing module 5 is used to obtain all possible roles corresponding to the job name input by the job input module 4 to be authorized according to the corresponding relationship table between jobs and roles stored in the job-role-business database 2, and then obtain all possible services corresponding to these roles according to the corresponding relationship table between roles and services stored in the job-role-business database 2; then compare the service weights of these services with the service weight threshold respectively. If there is a situation where the service weight is greater than the service weight threshold, then this job is an important job; otherwise, it is a non-important job;

[0089] The role automatic authorization module 6 is respectively connected to the job-role-business database 2, the job input module 4 to be authorized, and the data processing module 5; a role automatic authorization dual tower network model is pre-stored in the role automatic authorization module 6;

[0090] The role automatic authorization module 6 is used to input the job attributes input by the job input module 4 to be authorized into the first input channel of the role automatic authorization dual tower network model, and input each role stored in the job-role-business database 2 and the services corresponding to each role into the second input channel of the role automatic authorization dual tower network model to obtain the matching score between the job attributes and the role; select the top three roles with the highest matching score as the automatically authorized roles; if the data processing module 5 determines that this job is an important job, then transmit the automatically authorized roles to the role manual authorization module 7; if the data processing module 5 determines that this job is a non-important job, then transmit the automatically authorized roles and the corresponding services to the role review module 8;

[0091] The role manual authorization module 7 is respectively connected to the job-role-business database 2, the job input module 4 to be authorized, and the role automatic authorization module 6, and is used to obtain all possible roles and corresponding services corresponding to the job name to be authorized input by the job input module 4 to be authorized according to the corresponding relationship table between jobs and roles and the corresponding relationship table between roles and services stored in the job-role-business database 2, and perform manual processing according to the transmitted automatically authorized roles and the corresponding services to obtain the manually authorized roles; then transmit the manually authorized roles and the corresponding services to the role review module 8;

[0092] The role review module 8 is respectively connected to the job input module 4 to be authorized, the role automatic authorization module 6, and the role manual authorization module 7, and is used to review the automatically authorized roles of non-important jobs, and review whether the automatically authorized roles are contradictory to the job name and job attributes input by the job input module to be authorized. If there is a contradiction, it is considered that the review fails, and then the job name, job attributes, automatically authorized roles and corresponding services of the non-important job are returned to the role manual authorization module 7 for manual processing; if there is no contradiction, the review passes;

[0093] The role review module 8 is also used to check whether the manually authorized role transmitted by the role manual authorization module 7 conflicts with the name and attributes of the position to be authorized input by the position input module to be authorized. If there is a conflict, the position name, position attributes, manually authorized role, and corresponding business of this position are returned to the role manual authorization module 7 for manual processing again; if there is no conflict, the review is passed;

[0094] The business verification module 9, which is respectively connected to the role automatic authorization module 6 and the role review module 8, is used to verify the businesses corresponding to all the roles authorized for the positions passed by the role review module 8. If there are duplicate businesses, an elimination operation is performed. After elimination, the roles and businesses corresponding to this position are returned to the role manual authorization module 7 for manual processing; if not, the verification is passed;

[0095] The role assignment module 10, which is respectively connected to the position input module 4 to be authorized and the business verification module 9, is used to assign roles to the positions to be authorized according to the roles and corresponding businesses passed by the business verification module 9.

[0096] In the position input module 4 to be authorized, the position attributes include the code, level, department, rank, function corresponding to the position name, and the 4A account associated with the name of the position to be authorized input, and also include the city where the 4A account user is located and the working years.

[0097] In the role manual authorization module 7, the manual processing includes deleting roles, adding roles, and confirming roles.

[0098] In the role review module 8, during the review, if there is any one of the department mismatch, level mismatch, or rank mismatch, it is judged as a conflict and the review fails.

[0099] In the business verification module 9, the specific method of the elimination operation is as follows:

[0100] Let the duplicate business be business M, and obtain the roles containing business M from all the roles authorized for this position;

[0101] For the obtained roles containing business M, obtain their matching scores in the automatic authorization module 6;

[0102] Retain business M in the role with the highest matching score; eliminate business M in other roles.

[0103] The data collection module 1 is also used to periodically collect the roles corresponding to each position and the business information corresponding to the roles;

[0104] It also includes an empty business screening module 11 and a data management module 12;

[0105] The empty service screening module 11 is respectively connected to the data acquisition module 1 and the position-role-service database 2, and is used to compare the information periodically collected by the data acquisition module 1 with the information in the position-role-service database. If a certain role is not assigned to any position, or a certain service does not generate a corresponding role, the role information that is not assigned to any position and the service information that does not generate a corresponding role are sent to the data management module 12;

[0106] The data management module 12 is respectively connected to the empty service screening module 11 and the position-role-service database 2, and is used to manage positions, roles, and services; manage roles that are not assigned to any position and services that do not generate corresponding roles.

[0107] Embodiment 3

[0108] As Figure 2 shown, the 4A account role permission control system based on business process authorization includes:

[0109] The data acquisition module 1 is used to collect the position, role, and service information of historical 4A accounts, obtain the corresponding relationship between positions and roles, and the corresponding relationship between roles and services, and construct a position-role-service database;

[0110] The position-role-service database 2 is connected to the data acquisition module 1 and is used to store the position, role, and service information collected by the data acquisition module 1, as well as the corresponding relationship table between positions and roles and the corresponding relationship table between roles and services;

[0111] The importance weighting module 3 is respectively connected to the data acquisition module 1 and the position-role-service database 2, and is used to sort the importance of the services collected by the data acquisition module 1, and then assign importance weights to the services according to the sorting results. The higher the importance, the higher the weight, and then store them in the position-role-service database 2;

[0112] The position input module 4 to be authorized is used to input the name and attributes of the position to be authorized; the position to be authorized is a position that has not been assigned role and service permissions;

[0113] The data processing module 5 is respectively connected to the position-role-service database 2 and the position input module 4 to be authorized; a service weight threshold is pre-stored in the data processing module 5;

[0114] The data processing module 5 is used to obtain all the roles that the job name input by the job to be authorized input module 4 may correspond to according to the corresponding relationship table of jobs and roles stored in the job-role-business database 2, and then obtain all the services that these roles may correspond to according to the corresponding relationship table of roles and services stored in the job-role-business database 2; then compare the service weights of these services with the service weight threshold respectively. If there is a situation where the service weight is greater than the service weight threshold, then this job is an important job; otherwise, it is a non-important job;

[0115] The role automatic authorization module 6 is respectively connected to the job-role-business database 2, the job to be authorized input module 4, and the data processing module 5; a role automatic authorization dual tower network model is pre-stored in the role automatic authorization module 6;

[0116] The role automatic authorization module 6 is used to input the job attributes input by the job to be authorized input module 4 into the first input channel of the role automatic authorization dual tower network model, and input each role stored in the job-role-business database 2 and the services corresponding to each role into the second input channel of the role automatic authorization dual tower network model to obtain the matching score between the job attributes and the role; select the top three roles with the highest matching score as the automatically authorized roles; if the data processing module 5 determines that this job is an important job, then transmit the automatically authorized roles to the role manual authorization module 7; if the data processing module 5 determines that this job is a non-important job, then transmit the automatically authorized roles and the corresponding services to the role review module 8;

[0117] The role manual authorization module 7 is respectively connected to the job-role-business database 2, the job to be authorized input module 4, and the role automatic authorization module 6, and is used to obtain all the roles and corresponding services that the job name to be authorized input by the job to be authorized input module 4 may correspond to according to the corresponding relationship table of jobs and roles and the corresponding relationship table of roles and services stored in the job-role-business database 2, and perform manual processing according to the transmitted automatically authorized roles and the corresponding services to obtain the manually authorized roles; then transmit the manually authorized roles and the corresponding services to the role review module 8;

[0118] The role review module 8 is respectively connected to the job to be authorized input module 4, the role automatic authorization module 6, and the role manual authorization module 7, and is used to review the automatically authorized roles of non-important jobs, and review whether the automatically authorized roles are contradictory to the job name and job attributes input by the job to be authorized input module. If there is a contradiction, it is considered that the review fails, and then the job name, job attributes, automatically authorized roles and the corresponding services of the non-important job are returned to the role manual authorization module 7 for manual processing; if there is no contradiction, the review passes;

[0119] The role review module 8 is also used to check whether the manually authorized role transmitted by the role manual authorization module 7 conflicts with the name and attributes of the position to be authorized input by the position input module to be authorized. If there is a conflict, the position name, position attributes, manually authorized role, and corresponding business of this position will be returned to the role manual authorization module 7 for manual processing again; if there is no conflict, the review is passed;

[0120] The business verification module 9 is respectively connected to the role automatic authorization module 6 and the role review module 8, and is used to verify the businesses corresponding to all the roles authorized for the positions passed by the role review module 8. If there are duplicate businesses, an elimination operation will be performed. After elimination, the roles and businesses corresponding to this position will be returned to the role manual authorization module 7 for manual processing; if not, the verification is passed;

[0121] The role assignment module 10 is respectively connected to the position input module 4 to be authorized and the business verification module 9, and is used to assign roles to the positions to be authorized according to the roles and corresponding businesses passed by the business verification module 9.

[0122] In the position input module 4 to be authorized, the position attributes include the code, level, department, rank, function corresponding to the position name, and the 4A account associated with the name of the position to be authorized input, and also include the city where the 4A account user is located and the working years.

[0123] In the role manual authorization module 7, the manual processing includes deleting roles, adding roles, and confirming roles.

[0124] In the role review module 8, during the review, if there is any one of the department mismatch, level mismatch, and rank mismatch, it is judged as a conflict and the review fails.

[0125] In the business verification module 9, the specific method of the elimination operation is:

[0126] Let the duplicate business be business M, and obtain the roles containing business M from all the roles authorized for this position;

[0127] For the obtained roles containing business M, obtain their matching scores in the automatic authorization module 6;

[0128] Retain business M in the role with the highest matching score; eliminate business M in other roles.

[0129] The data collection module 1 is also used to periodically collect the roles corresponding to each position and the business information corresponding to the roles;

[0130] It also includes an empty business screening module 11 and a data management module 12;

[0131] The empty service screening module 11 is respectively connected to the data acquisition module 1 and the position-role-service database 2, and is used to compare the information periodically collected by the data acquisition module 1 with the information in the position-role-service database. If there is a role that has not been assigned to any position, or a service that has not generated a corresponding role, the role information that has not been assigned to any position and the service information that has not generated a corresponding role are sent to the data management module 12;

[0132] The data management module 12 is respectively connected to the empty service screening module 11 and the position-role-service database 2, and is used to manage positions, roles, and services; manage roles that have not been assigned to any position and services that have not generated corresponding roles.

[0133] The service verification module 9 is also connected to the data acquisition module 1, and is used to screen according to the roles corresponding to each position and the service information corresponding to the roles periodically collected. If the position names of different 4A accounts are the same, and the same roles and services are assigned, the 4A accounts and their position, role, and service information are sent to the data management module 12 for manual processing, and the management personnel perform manual confirmation or role deletion.

[0134] In the role automatic authorization module 6, the role automatic authorization double-tower network model includes an input layer, a representation layer, an interaction layer, a matching layer, and an output layer; the input layer, the representation layer, the interaction layer, the matching layer, and the output layer are connected in sequence;

[0135] In the input layer, the position attributes of the position are input into the first input channel, and the roles corresponding to the position and the services corresponding to each role are input into the second input channel;

[0136] In the representation layer, the position attributes are processed to obtain the semantic vector embedding1; each role and the services corresponding to each role are processed to obtain the semantic vector embedding2, and it is sent to the interaction layer;

[0137] In the interaction layer, a matrix M is constructed, with a size of m×n; each cell in the matrix M is the similarity calculated by taking the dot product of the elements at each position of embedding1 and embedding2; calculating all the cells results in the similarity matrix M; the similarity matrix M is used as the input to the matching layer;

[0138] In the matching layer, 2D convolution and pooling are performed on the similarity matrix M, and finally a matching vector is obtained through a fully connected layer, which is used as the input to the output layer;

[0139] In the output layer, a softmax calculation is performed on the vector of the matching layer, and the matching score of the position attributes of the position and the role is output.

[0140] The data acquisition module 1 is also used to periodically collect the business processing status. If there is a business that has not been processed for a long time, a warning is issued, and the warning information is sent to the data management module 12; then, the name and attributes of the position to be authorized are input again through the position input module 4 to be authorized, and the role and corresponding business are assigned again.

[0141] The data acquisition module 1 periodically collects the business operation status corresponding to each position; if the business has not been operated for multiple consecutive processing cycles, the 4A account and its position, role, and business information are sent to the data management module 12 for manual processing, and the business under the 4A account is deleted.

[0142] Application example

[0143] For the problem of account permission management, the present invention invents a solution for the whole-process account control covering account permission application, approval, use, and auditing - the 4A account role permission control system based on business process authorization. This example adopts the 4A account role permission control system based on business process authorization described in Embodiment 3.

[0144] I. Permission application stage

[0145] This stage includes two aspects. The first aspect is automatic authorization, and the second aspect is manual authorization.

[0146] The position input module to be authorized is used to input the name and attributes of the position to be authorized; the position to be authorized is a position that has not been assigned a role and business permissions yet;

[0147] First aspect: Based on the role automatic authorization twin tower network model, permissions are automatically assigned to the 4A account positions of users.

[0148] Before the 4A account is constructed, weights will be assigned to each existing business based on work experience or the importance of the business system; for example, the crm system (business 1) is more important than the - planning system (business 2), and a higher weight will be assigned to it.

[0149] Specifically,

[0150] The importance weighting module is used to sort the importance of the business, and then assign weights according to the sorting results. The higher the importance, the higher the weight;

[0151] The business weight threshold is pre-stored in the data processing module;

[0152] The data processing module is used to obtain all possible roles corresponding to the job name input by the job input module to be authorized according to the corresponding relationship table of jobs and roles stored in the job-role-business database, and then obtain all possible businesses corresponding to these roles according to the corresponding relationship table of roles and businesses stored in the job-role-business database; if there are businesses greater than the business weight threshold among these businesses, then this job is an important job; otherwise, it is a non-important job.

[0153] Regarding the design concept of the dual-tower network model for role automatic authorization, it stems from the classic "dual-tower" network structure. On the left and right sides are two independent sub-networks. The left side is the job tower of 4A accounts, and the right side is the role tower. The parameters of the two towers are not shared. The core idea of the network is to map jobs and roles into the same semantic space and perform matching by measuring the similarity between jobs and roles in this space.

[0154] The role automatic authorization module pre-stores a dual-tower network model for role automatic authorization;

[0155] The role automatic authorization module is used to input the job attributes into the first input channel of the dual-tower network model for role automatic authorization, and input each role stored in the job-role-business database and the business corresponding to each role into the second input channel of the dual-tower network model for role automatic authorization to obtain the matching score between the job attributes and the role; select the top three roles with the highest matching scores as the automatically authorized roles; if the data processing module determines that this job is an important job, then transmit the automatically authorized roles to the role manual authorization module; if the data processing module determines that this job is a non-important job, then transmit the automatically authorized roles and the corresponding businesses to the role review module.

[0156] The dual-tower network model for role automatic authorization of the present invention includes an input layer, a representation layer, an interaction layer, a matching layer, and an output layer, as Figure 4 .

[0157] In the input layer, we input the existing various roles and the businesses corresponding to each role, as well as the job attributes of the 4A account to which permissions need to be granted.

[0158] In the representation layer, a CNN or Transformer network model will be used to process the job attributes to obtain the semantic vector embedding1, process each role and the business corresponding to each role to obtain the semantic vector embedding2, and send them to the interaction layer.

[0159] Taking the Transformer network model as an example:

[0160] 1. Tokenize the input job attributes, add special tokens, generate position encodings, and obtain the initial input word embedding vectors;

[0161] 2. Construct a job tower Transformer encoder network, including a multi-head attention mechanism and a feed-forward neural network layer, to perform multi-layer feature extraction and transformation on the input embeddings;

[0162] 3. Obtain the final job attribute embedding vector from the output of the Transformer (e.g., take the vector corresponding to the [CLS] special token).

[0163] The role tower is the same.

[0164] Through the calculation of the representation layer model of the job tower, the job attribute features are extracted, namely embedding1 (a vector of length m); for each role and the business corresponding to each role, through the calculation of the representation layer model of the role tower, the role attribute features are extracted, namely embedding2 (a vector of length n).

[0165] Through the calculation of the representation layer model of the job tower for the job attributes, the job attribute features are extracted, namely embedding1 (a vector of length m); for each role and the business corresponding to each role, through the calculation of the representation layer model of the role tower, the role attribute features are extracted, namely embedding2 (a vector of length n).

[0166] In the interaction layer, although the two towers are separate during training, the introduction of the interaction layer can supplement cross-combination features. Construct a matrix M with size m×n; each cell in matrix M is the similarity calculated by taking the dot product of the elements at each position of embedding1 and embedding2; after calculating all cells, the similarity matrix M is obtained; the similarity matrix M is used as the input to the matching layer;

[0167] In the matching layer, perform 2D convolution and pooling on M, and finally obtain the matching vector vector through a fully connected layer (here, the 2D matrix M is reduced to a 1D vector vector for easy subsequent softmax calculation) (with size d). vector is used as the input to the output layer.

[0168] In the output layer, perform softmax calculation on the vector from the matching layer, and output the matching score between the 4A account and the role (taking values from 0 to 1). It can be extended to the authorization business meaning score, such as 0 to 100. Originally, the model output is a value of 0 < x < 1. For easy understanding by personnel, it is written here that it can be converted to the authorization business meaning score. The simplest way is: authorization business meaning score = int(100×x).

[0169] The reason for choosing the dual - tower network is as follows: This network structure has been verified to have good applicability in multiple fields; it is flexible in structure and can be adjusted and optimized according to specific application scenarios; it is convenient for deployment and online operation, and has high service real - time performance.

[0170] Model training:

[0171] When the model is used, it needs to be trained first.

[0172] For this, various historical data will be collected to make a binary classification dataset (positive samples and negative samples). Among them, the positive samples are the positions, roles, and business information of historical 4A accounts, and the negative samples are the roles and businesses that a user is authorized but has no operations on, as well as the roles and businesses that are not authorized.

[0173] Using the positive samples and negative samples as training samples, the model is trained to establish the association relationship between the position attributes, roles, and the businesses corresponding to the roles for subsequent use.

[0174] In the present invention, the dual - tower network model for role automatic authorization uses the position, role, and business information of historical 4A accounts as positive samples for training, and continuously uses the data periodically collected by the data acquisition module as positive samples for further training to improve the accuracy of the model.

[0175] The initial authorization process for the positions of 4A accounts is implemented by the dual - tower network model for role automatic authorization, and subsequent manual adjustment can be carried out through the role manual authorization module.

[0176] For example, in position A, more than 90% of the people are given role A. Then when assigning a role to the new 4A account position A, the role automatic authorization module will recommend assigning role A to this position A.

[0177] Another example is that in position A, more than 90% of the staff located in City A are given role B. Then when the user of the new 4A account is also located in City A as shown in the position attributes of the account position, the role automatic authorization module will recommend assigning role B to this position A.

[0178] In addition, in actual work, as the work experience or working hours of the staff accumulate, more business processes may be gradually opened for the staff.

[0179] For example, when the working years of the staff in the position attributes are 1 - 3 years, they will be given role A to handle business A. When the working years of this staff in the position attributes reach 3 - 5 years, they will be given role B and the handling of business A will be increased. At this time, when the working years of the staff change, the role automatic authorization module will remove the corresponding role assignment suggestions.

[0180] Second aspect: Manual authorization

[0181] It is used to obtain all possible roles and corresponding services of the name of the position to be authorized input by the position input module to be authorized according to the corresponding relationship table between positions and roles and the corresponding relationship table between roles and services stored in the position-role-business database, and perform manual processing according to the transmitted automatically authorized roles and corresponding services, so as to obtain manually authorized roles; then transmit the manually authorized roles and corresponding services to the role review module;

[0182] An example of the corresponding relationship table between positions and roles is shown in Table 1,

[0183] Table 1

[0184]

[0185] An example of the corresponding relationship table between roles and services is shown in Table 2.

[0186] Table 2

[0187]

[0188] During manual processing, the automatically authorized roles and corresponding services can be seen, and other existing roles (including document administrators, system administrators, company leaders, etc.) and corresponding services can also be seen. At this time, it may be necessary to manually check the roles to achieve manual authorization of the position roles of the 4A account.

[0189] In actual work, for the same position, different people may be assigned different roles. For example, both Zhang San and Li Si are assigned position A, and the roles assigned to Zhang San correspond to role A, role B, and role C, while Li Si only needs to be assigned role A and role B. However, since Li Si and Zhang San have the same position, Li Si will be assigned role A, role B, and role C in automatic authorization.

[0190] At this time, the manager can make a secondary adjustment to delete role C for Li Si.

[0191] The present invention considers that as the number of employees in the enterprise expands, more and more people may be in the same position, but are assigned different roles. At this time, directly assigning through the position-role correspondence table may not be able to well assist the manager in quickly assigning roles. Therefore, first use the role automatic authorization module for automatic authorization, and then perform manual authorization for important positions or special situations (such as failed role review), so as to provide suggestions for role assignment for the manager.

[0192] The present invention can train an automatic authorization dual - tower network model for roles based on the corresponding relationships between positions and roles, and between roles and operations in the enterprise, so that the network can achieve automatic role authorization for positions. To avoid certain errors that may occur during the automatic authorization process, for important positions, manual processing can be used for adjustment in the follow - up. The flowchart is as shown in Figure 5 shown below.

[0193] In an enterprise, the importance levels of different positions may vary. Therefore, positions with relatively high importance can be screened out first.

[0194] For non - important positions, only through automatic processing, role authorization is performed for these positions with relatively low importance.

[0195] For important positions, role authorization can be first performed through automatic processing, and then the role authorization results can be adjusted through manual processing, so as to ensure the stability of role authorization within the enterprise. The flowchart is as shown in Figure 6 shown below.

[0196] II. Review Stage

[0197] Check whether there is a contradiction between the manually authorized role transmitted by the manual role authorization module and the name and attributes of the position to be authorized input by the position input module to be authorized. If there is a contradiction, the position name, position attributes, manually authorized role, and the corresponding operation are returned to the manual role authorization module for re - manual processing; if there is no contradiction, the review is passed;

[0198] Check the operations corresponding to all the roles authorized for the positions passed by the role review module. If there are duplicate operations, elimination operations are performed. After elimination, the roles and operations corresponding to this position are returned to the manual role authorization module for manual processing; if not, the check is passed;

[0199] Assign roles to the positions to be authorized according to the roles and corresponding operations passed by the check.

[0200] III. Usage Stage

[0201] After a position in the 4A account is assigned to a certain role, the 4A account can be used to log in to the system. In the system, the operation menu corresponding to the assigned role can be viewed, and clicking on the menu can achieve the viewing and processing of operations.

[0202] In actual work, as roles are continuously assigned, it is possible that a certain role is not assigned to any account, or a certain business does not generate a corresponding role, resulting in the stagnation of the business. Therefore, it is necessary to regularly check whether there are any businesses not associated with roles and whether there are any roles not bound to accounts. If such businesses or roles exist, the business or role can be reported to the management in a timely manner to remind the management to handle it as soon as possible.

[0203] Specifically:

[0204] The data collection module periodically collects the roles corresponding to each position and the business information corresponding to the roles;

[0205] The empty business screening module compares the information periodically collected by the data collection module with the information in the position-role-business database. If a certain role is not assigned to any position, or a certain business does not generate a corresponding role, the role information not assigned to any position and the business information not generating a corresponding role are sent to the data management module;

[0206] The data management module is used to manage positions, roles, and businesses; manage roles not assigned to any position and businesses not generating corresponding roles; management includes modification, warning, and cleaning.

[0207] For some specific accounts, it may be impossible to accurately assign existing roles to them. In this case, a new role can be established and specific corresponding businesses can be selected for the role.

[0208] IV. Audit Phase

[0209] Due to the needs of actual work, there may be some businesses that have not been processed for a long time. Then, for these businesses, a separate processing detection cycle can be set. If no operation is performed within a processing detection cycle, or no operation is performed in multiple processing cycles, the business in the 4A account can be deleted.

[0210] Specifically:

[0211] The data collection module is also used to periodically collect the business processing situation. If there is a business that has not been processed for a long time, a warning is issued and the warning information is sent to the data management module; then, the name and attributes of the position to be authorized are re-entered through the position input module to be authorized, and roles and corresponding businesses are re-assigned.

[0212] The data collection module also periodically collects the business operation situations corresponding to each position; if the business is not operated in multiple consecutive processing cycles, the 4A account and its position, role, and business information are sent to the data management module for manual processing, and the business under the 4A account is deleted.

[0213] The foregoing has shown and described the basic principles, main features and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited by the above embodiments, and what is described in the above embodiments and the specification is only to illustrate the principle of the present invention. Without departing from the spirit and scope of the present invention, the present invention will have various changes and improvements, and these changes and improvements fall within the scope of the present invention claimed. The scope of the present invention claimed is defined by the appended claims and their equivalents.

Claims

1. The 4A account role authority management and control system based on business process authorization is characterized by: include: The data collection module (1) is used to collect the position, role and business information of the historical 4A accounts, obtain the corresponding relationship between the position and the role, and the corresponding relationship between the role and the business, and build a position-role-business database; A position-role-business database (2) connected to the data collection module (1) and used to store the position, role and business information collected by the data collection module (1), as well as a corresponding relationship table between positions and roles, and a corresponding relationship table between roles and businesses; The importance weighting module (3) is connected to the data collection module (1) and the position-role-business database (2) respectively, and is used to sort the importance of the businesses collected by the data collection module (1), and then weight the businesses according to the sorting results. The higher the importance, the higher the weight, and then the business is stored in the position-role-business database (2); The position input module (4) to be authorized is used to input the position name and position attributes to be authorized; the position to be authorized is a position that has not yet been assigned a role and business authority; The data processing module (5) is connected to the position-role-business database (2) and the position input module (4) to be authorized respectively; the data processing module (5) has a business weight threshold pre-stored therein; The data processing module (5) is used to obtain all roles that may correspond to the position name input by the position input module (4) to be authorized according to the position-role-business database (2) stored in the position-role-business database (2), and then obtain all businesses that may correspond to these roles according to the role-business database (2) stored in the position-role-business database (2); then compare the business weights of these businesses with the business weight threshold respectively; if there is a situation where the weight is greater than the business weight threshold, the position is an important position; otherwise, it is a non-important position; The role automatic authorization module (6) is respectively connected to the position-role-business database (2), the position input module to be authorized (4), and the data processing module (5); the role automatic authorization module (6) pre-stores a role automatic authorization double-tower network model; The role automatic authorization module (6) is used to input the job attributes input by the job input module (4) to be authorized into the first input channel of the role automatic authorization double-tower network model, and input each role and the business corresponding to each role stored in the job-role-business database (2) into the second input channel of the role automatic authorization double-tower network model to obtain the matching score of the job attributes and the role; The first three roles with the highest matching scores are selected as automatically authorized roles; if the data processing module (5) determines that the position is an important position, the automatically authorized role is transmitted to the role manual authorization module (7); if the data processing module (5) determines that the position is a non-important position, the automatically authorized role and the corresponding business are transmitted to the role review module (8); The role manual authorization module (7) is connected to the position-role-business database (2), the position input module (4) to be authorized, and the role automatic authorization module (6) respectively, and is used to obtain all roles and corresponding businesses that may correspond to the position name to be authorized input by the position input module (4) to be authorized according to the position-role-business database (2) The corresponding relationship table and the role-business corresponding relationship table stored in the position-role-business database (2), and perform manual processing based on the automatically authorized role and the corresponding business, so as to obtain the manually authorized role; and then transmit the manually authorized role and the corresponding business to the role review module (8); The role review module (8) is connected to the position input module (4) to be authorized, the role automatic authorization module (6) and the role manual authorization module (7) respectively, and is used to review the automatically authorized role of the non-important position, and review whether the automatically authorized role is inconsistent with the position name and position attribute to be authorized input by the position input module to be authorized. If there is a contradiction, it is considered that the review fails, and then the position name, position attribute, automatically authorized role and corresponding business of the non-important position are returned to the role manual authorization module (7) for manual processing; if there is no contradiction, the review passes; The role review module (8) is also used to review whether the manually authorized role transmitted by the role manual authorization module (7) is inconsistent with the job title and job attribute to be authorized input by the job input module to be authorized. If there is a contradiction, the job title, job attribute, manually authorized role and corresponding business of the job are returned to the role manual authorization module (7) for manual processing again; if there is no contradiction, the review is passed; The business verification module (9) is connected to the role automatic authorization module (6) and the role review module (8) respectively, and is used to verify the business corresponding to all roles authorized for the positions that have been reviewed and approved by the role review module (8). If there are duplicate businesses, they are eliminated. After elimination, the roles and businesses corresponding to the positions are returned to the role manual authorization module (7) for manual processing; if there are no duplicate businesses, the verification is passed; The role assignment module (10) is connected to the position input module (4) to be authorized and the business verification module (9) respectively, and is used to assign roles to the position to be authorized according to the roles and corresponding businesses verified by the business verification module (9).

2. The 4A account role authority management and control system based on business process authorization according to claim 1 is characterized in that: In the position input module (4) to be authorized, the position attributes include the code, level, department, rank, function corresponding to the position name and the 4A account associated with the input position name to be authorized, and also include the city where the 4A account user is located and the years of work experience.

3. The 4A account role authority management and control system based on business process authorization according to claim 1 is characterized in that: In the role manual authorization module (7), manual processing includes deleting roles, adding roles, and confirming roles.

4. The 4A account role authority management and control system based on business process authorization according to claim 1 is characterized in that: In the role review module (8), during the review, if there is any inconsistency in department, level or rank, it will be judged as a contradiction and the review will not pass.

5. The 4A account role authority management and control system based on business process authorization according to claim 1 is characterized in that: In the business verification module (9), the specific method of the elimination operation is: Suppose the repeated business is business M, and obtain the role containing business M from all roles authorized by the position; For the obtained role containing business M, obtain its matching score in the automatic authorization module (6); The business M in the role with the highest matching score is retained; and the business M in other roles is eliminated.

6. The 4A account role authority management and control system based on business process authorization according to claim 1 is characterized in that: The data collection module (1) is also used to periodically collect the roles corresponding to each position and the business information corresponding to the roles; It also includes a vacant business screening module (11) and a data management module (12); The empty business screening module (11) is connected to the data collection module (1) and the position-role-business database (2) respectively, and is used to compare the information periodically collected by the data collection module (1) with the information in the position-role-business database. If a role is not assigned to any position, or a business does not generate a corresponding role, the role information that is not assigned to any position and the business information that does not generate a corresponding role are sent to the data management module (12); The data management module (12) is connected to the empty business screening module (11) and the position-role-business database (2) respectively, and is used to manage positions, roles, and businesses; and to manage roles that are not assigned to any positions and businesses that have not generated corresponding roles.

7. The 4A account role authority management and control system based on business process authorization according to claim 6 is characterized in that: The business verification module (9) is also connected to the data collection module (1) and is used to periodically collect the roles corresponding to each position and the business information corresponding to the roles for screening. If different 4A accounts have the same position name and are assigned the same role and business, the 4A account and its position, role and business information are sent to the data management module (12) for manual processing, and the management personnel manually confirm or delete the role.

8. The 4A account role authority management and control system based on business process authorization according to claim 1 is characterized in that: In the role automatic authorization module (6), the role automatic authorization double-tower network model includes an input layer, a representation layer, an interaction layer, a matching layer, and an output layer; the input layer, the representation layer, the interaction layer, the matching layer, and the output layer are sequentially connected; In the input layer, the post attributes of the post are input into the first input channel, and the roles corresponding to the post and the businesses corresponding to each role are input into the second input channel; In the presentation layer, the job attributes are processed to obtain the semantic vector embedding1; each role and the business corresponding to each role are processed to obtain the semantic vector embedding2, which is sent to the interaction layer; In the interaction layer, a matrix M is constructed with a size of m×n. Each cell in the matrix M is the similarity calculated by performing a dot product of the elements at each position of embedding1 and embedding2. The similarity matrix M is obtained by calculating all the cells. The similarity matrix M is used as the input of the matching layer. In the matching layer, the similarity matrix M is subjected to 2D convolution and pooling, and finally the matching vector is obtained through full connection as the input of the output layer; In the output layer, a softmax calculation is performed on the vector of the matching layer to output the job attributes of the job and the matching score of the role.

9. The 4A account role authority management and control system based on business process authorization according to claim 1 is characterized in that: The data collection module (1) is also used to periodically collect business processing status. If there is a business that has not been processed for a long time, an early warning will be issued and the early warning information will be sent to the data management module (12); then the name of the position to be authorized and the position attributes are re-entered through the position input module to be authorized (4), and the role and corresponding business are re-assigned.

10. The 4A account role authority management and control system based on business process authorization according to claim 1 is characterized in that: The data collection module (1) periodically collects the business operation status corresponding to each position; if the business is not operated for multiple consecutive processing cycles, the 4A account and its position, role, and business information are sent to the data management module (12) for manual processing, and the business under the 4A account is deleted.

Citation Information

Patent Citations

  • Enterprise-level information system permission management system

    CN108197895A

  • Two tower network extension for jointly optimizing multiple different types of recommendations

    US20250005440A1