Authority management method and device, equipment, storage medium and program product
By dynamically obtaining and analyzing user work data, determining permission information in combination with classification models, and adjusting permissions through approval processes, the problem of low permission configuration efficiency in the existing technology is solved, and efficient permission management is achieved in large or rapidly changing organizations.
Patent Information
- Application Number
- CN202410526143.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-04-29
- Publication Date
- 2025-05-13
AI Technical Summary
In existing user rights management systems, permission allocation is usually static and manual, and it is difficult to respond to changes in organizational structure or responsibilities in a timely manner, resulting in low efficiency in permission configuration in large or rapidly changing organizations.
By obtaining the working data of the target user, performing feature extraction and classification model output, dynamically determine user permission information, and generating permission application information, and initiate an approval process to determine permission changes.
It realizes efficient configuration management of user permissions and dynamically adjusts permissions. It is suitable for large or rapidly changing organizations, reducing the workload of permission configuration and reducing security risks caused by improper permission configuration.
Smart Images

Figure CN119989371A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of intelligent operation and maintenance technology, and in particular to a permission management method, device, equipment, storage medium and program product. Background Art
[0002] As the business continues to develop, it is necessary to control access to the business system based on the permission management system. According to the permission management system, users can access and can only access the business resources for which they are authorized.
[0003] In existing user authority management systems, authority allocation is usually static and manual. For example, authority allocation can be based on roles. Different roles are configured in the authority management system, and then certain authorities are configured for the roles. Then, each user is assigned to a certain role to complete the authority allocation of the user.
[0004] However, this method is difficult to respond to changes in organizational structure or responsibilities in a timely manner. In other words, in large or rapidly changing organizations, manually configuring user permissions based on existing technologies is inefficient. Summary of the invention
[0005] Based on this, it is necessary to provide a permission management method, apparatus, device, storage medium and program product that can efficiently configure and manage user permissions in response to the above technical problems.
[0006] In a first aspect, the present application provides a permission management method, including: obtaining work data of a target user, the work data being determined based on the target user's position information, access records, historical permissions and workflow; performing feature extraction on the work data to obtain feature data of the target user; inputting the feature data into a classification model, and determining the permission information of the target user based on the output of the classification model; generating permission application information based on the permission information, the permission application information being used to indicate a change to the user permissions of the target user; and initiating an approval process based on the permission application information to determine whether to change the permission information of the target user.
[0007] In one of the embodiments, the permission application information is reviewed and approved to determine whether to change the permission information of the target user, including: obtaining a preset standard permission application information list, the preset standard permission application information list includes new common permission requests, new short-term permission requests and deletion permission requests; if the preset standard permission application information list includes permission application information, the approval is automatically completed.
[0008] In one of the embodiments, the permission application information is approved to determine whether to change the permission information of the target user, including: if the permission application information is not included in the preset standard permission application information list, sending the permission application information to the administrator; receiving the administrator's instruction information to approve the permission application information according to the instruction information.
[0009] In one of the embodiments, after generating permission application information based on permission information, the method further includes: sending the permission application information to a target user; if a permission request from the target user is received, approving the permission application information, the permission request includes the permission application information, the target user location information and the request time.
[0010] In one of the embodiments, the method further includes: if the location information of the target user in the permission request does not match the preset location information, and / or the request time in the permission request does not match the preset time range, then the permission application information is not approved.
[0011] In one of the embodiments, the method further includes: obtaining a virtual boundary corresponding to the office location and location information of the target user; and updating the permission information of the target user based on the virtual boundary and location information based on preset permission rules.
[0012] In one embodiment, the method further includes: receiving a login request from a target user, performing multiple verifications on the target user, and determining the identity information of the target user, wherein the multiple verifications include verifying the target user's login password, iris information, fingerprint information, verification code or hardware token; and determining the target user's authority information based on the target user's identity information.
[0013] In a second aspect, the present application also provides a rights management device, including:
[0014] The first acquisition module is used to acquire the work data of the target user, where the work data is determined based on the target user's position information, access records, historical permissions, and workflow;
[0015] The second acquisition module is used to extract features from the work data to obtain feature data of the target user;
[0016] A determination module, used to input the feature data into the classification model and determine the target user's permission information according to the output of the classification model;
[0017] A generation module, used to generate permission application information according to the permission information, used to indicate a change to the user permission of the target user;
[0018] The approval module is used to approve the permission application information to determine whether to change the permission information of the target user.
[0019] In one of the embodiments, the approval module is specifically used to obtain a preset standard permission application information list, which includes new common permission requests, new short-term permission requests, and deletion permission requests; if the preset standard permission application information list includes permission application information, the approval is automatically completed.
[0020] In one of the embodiments, the approval module is specifically used to send the permission application information to the management personnel if the permission application information is not included in the preset standard permission application information list; receive the instruction information from the management personnel to approve the permission application information according to the instruction information.
[0021] In one of the embodiments, the approval module is also used to send permission application information to the target user; if a permission request from the target user is received, the permission application information is approved, and the permission request includes the permission application information, the target user location information and the request time.
[0022] In one of the embodiments, the approval module is further used to not approve the permission application information if the location information of the target user in the permission request does not match the preset location information, and / or the request time in the permission request does not match the preset time range.
[0023] In one of the embodiments, the permission management device further includes a monitoring module for obtaining the virtual boundary corresponding to the office location and the location information of the target user; based on preset permission rules, the permission information of the target user is updated according to the virtual boundary and the location information.
[0024] In one of the embodiments, the permission management device also includes a login module, which is used to receive a login request from a target user, perform multiple verifications on the target user, and determine the identity information of the target user. The multiple verifications include verifying the target user's login password, iris information, fingerprint information, verification code or hardware token; and determining the target user's permission information based on the target user's identity information.
[0025] In a third aspect, the present application further provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, any of the methods described in the first aspect is implemented.
[0026] In a fourth aspect, the present application further provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements any of the methods described in the first aspect above.
[0027] In a fifth aspect, the present application further provides a computer program product, including a computer program, which, when executed by a processor, implements any of the methods described in the first aspect above.
[0028] The above-mentioned permission management method, device, equipment, storage medium and program product first obtain the work data of the target user, the work data is determined according to the target user's position information, access records, historical permissions and workflow, and then the work data is feature extracted to obtain the feature data of the target user, and then the feature data is input into the classification model, and the permission information of the target user is determined according to the output of the classification model, and then the permission application information is generated according to the permission information. The permission application information is used to indicate the change of the user permissions of the target user, and finally the approval process is initiated according to the permission application information to determine whether to change the permission information of the target user. The permission information corresponding to the target user can be determined by timely obtaining the work data of the target user, and then the permission information of the target user can be updated. The permissions of the target user can be dynamically adjusted. In large or rapidly changing organizations, permission management can be performed efficiently, while reducing the workload of permission configuration and reducing the security risks caused by improper permission configuration. BRIEF DESCRIPTION OF THE DRAWINGS
[0029] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the drawings required for use in the embodiments of the present application or related technical descriptions will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.
[0030] Figure 1 An application environment diagram of a rights management method in an embodiment;
[0031] Figure 2 A flowchart of a rights management method in one embodiment;
[0032] Figure 3 A schematic diagram of a flow chart of steps for approving permission application information in one embodiment;
[0033] Figure 4 A flowchart of a rights management method in another embodiment;
[0034] Figure 5 A flowchart of a rights management method in another embodiment;
[0035] Figure 6 A flowchart of a rights management method in another embodiment;
[0036] Figure 7 is a structural block diagram of a rights management device in an embodiment;
[0037] Figure 8 FIG. 4 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION
[0038] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0039] As the business continues to develop, it is necessary to control access to the business system based on the permission management system. According to the permission management system, users can access and can only access the business resources for which they are authorized.
[0040] In existing user authority management systems, authority allocation is usually static and manual. For example, authority allocation can be based on roles. Different roles are configured in the authority management system, and then certain authorities are configured for the roles. Then, each user is assigned to a certain role to complete the authority allocation of the user.
[0041] However, this method is difficult to respond to changes in organizational structure or responsibilities in a timely manner. In other words, in large or rapidly changing organizations, manually configuring user permissions based on existing technologies is inefficient.
[0042] In view of this, the embodiment of the present application provides a rights management method that can efficiently configure and manage user rights. The rights management method provided in the embodiment of the present application can be applied to Figure 1 In the application environment shown. Among them, the terminal 102 communicates with the server 104 through the network. The data storage system can store the data that the server 104 needs to process. The data storage system can be integrated on the server 104, or it can be placed on the cloud or other network servers. Among them, the terminal 102 can be, but is not limited to, various personal computers, laptops, smart phones, tablets, Internet of Things devices and portable wearable devices. The Internet of Things devices can be smart speakers, smart TVs, smart air conditioners, smart car devices, projection devices, etc. Portable wearable devices can be smart watches, smart bracelets, head-mounted devices, etc. The head-mounted device can be a virtual reality (VR) device, an augmented reality (AR) device, smart glasses, etc. The server 104 can be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server that provides cloud computing services.
[0043] In an exemplary embodiment, Figure 2 As shown, a permission management method is provided, which is applied to Figure 1 The server 104 in the example is used as an example to illustrate, including the following steps 201 to 205. Among them:
[0044] S201, the server obtains the work data of the target user.
[0045] Among them, the work data is determined based on the target user's position information, access records, historical permissions and workflow.
[0046] Optionally, the target user may be any user in the authority management system, and whether to change the role or authority of the user is determined based on the work data of the any user.
[0047] Optionally, target user work data can be collected in the following ways:
[0048] (1) You can integrate log management tools, such as Graylog or Filebeat, which can manage and analyze the target user's system login logs, access records, and operation logs to provide an overview of the target user's activities.
[0049] (2) By integrating with the workflow management system, the target user's activities in different projects and tasks can be obtained. By calling the external interfaces provided by each project and task system, the target user's activities and project participation can be queried.
[0050] (3) Network monitoring tools can be used to obtain the target user's activities in the corporate network, monitor and record network traffic, and then identify the applications or services frequently used by the target user.
[0051] (4) You can obtain the target user’s work data based on the target user’s feedback by obtaining the target user’s questionnaire survey results or conversation results.
[0052] (5) The role, position and organizational structure information of the target user can be obtained through the human resources management system and identity management system.
[0053] Optionally, the target user's position information, access records, historical permissions, workflow and other information are determined by any one of the above methods or a combination of multiple methods, thereby forming the target user's work data.
[0054] S202: The server extracts features from the working data to obtain feature data of the target user.
[0055] Optionally, perform data cleansing on the collected work data of the target users, review and verify the work data of the target users, discover and correct identifiable errors in the data files, and process erroneous data or conflicting data. Data cleansing may include checking data consistency, processing invalid values and missing values, etc.
[0056] Optionally, features can be input variables used to describe and predict the permissions of target users. Selecting the right features is crucial to building an effective machine learning model. The feature data of target users can include the target user's position, department, historical permissions, and frequency of access to specific systems. Feature extraction of work data also includes feature selection.
[0057] Optionally, feature extraction of the working data to obtain feature data of the target user can be achieved through a variety of analysis methods such as principal component analysis, linear discriminant analysis, multidimensional scaling analysis, independent component analysis and kernel principal component analysis. Among them, principal component analysis is a linear technology for analyzing, simplifying data sets and extracting main components. Kernel principal component analysis first performs nonlinear changes on the working data of the target user, and then performs principal component analysis in the transformed space to achieve nonlinear principal component analysis in the original space. In other words, kernel principal component analysis is a nonlinear technology.
[0058] S203, the server inputs the feature data into the classification model, and determines the authority information of the target user according to the output of the classification model.
[0059] In an embodiment of the present application, a classification model refers to a model obtained in advance through machine learning training that can predict the permission information of a target user based on the characteristic data of the target user. The model inputs the characteristic data of the target user and determines the permission information of the target user based on the output.
[0060] In one possible implementation, the classification model can be implemented based on a logistic regression algorithm, which has fast training speed and good interpretability.
[0061] In another possible implementation, the classification model can be implemented based on a decision tree algorithm. The decision tree is a non-parametric supervised learning method that can summarize decision rules from feature data and present these rules in a tree diagram structure to solve classification problems. The model is not very sensitive to data and does not require data preprocessing.
[0062] In another possible implementation, the classification model can be implemented based on the random forest algorithm. Random forest is an algorithm that integrates multiple trees through the idea of ensemble learning. The basic unit of random forest is the decision tree. By combining multiple classifiers, the final result is determined by voting or taking the average. The overall model has high accuracy and generalization function, and also has good stability.
[0063] In another possible implementation method, the classification model can be implemented based on the support vector algorithm. This model is supported by rigorous mathematical theory and has strong interpretability. It simplifies the classification problem. The final decision function is determined by only a few support vectors. The complexity of the calculation depends on the number of support vectors rather than the dimension of the sample space. This avoids the "curse of dimensionality" to a certain extent. When the model predicts, the prediction time is proportional to the number of support vectors.
[0064] Optionally, you can obtain a data set by obtaining the historical work data and corresponding permission information of all users, and use the data set to train the initial classification model to obtain a classification model. Training can allow the classification model to learn what kind of features correspond to what kind of permissions. The data set is divided into a training set and a test set. The initial classification model uses the training set to learn, and the test set is used to verify the accuracy of the classification model obtained after training.
[0065] Optionally, the performance of the classification model is evaluated by comparing the predictions of the classification model on the test set with the actual results, and the model parameters are continuously optimized or the user feature data is reselected to improve the accuracy of the classification model. After the accuracy of the classification model reaches the preset standard, the classification model is used to analyze the user's characteristics and predict the permissions of each target user. At the same time, the classification model can be updated and retrained with the latest work data and corresponding user permissions, and the classification model can be continuously optimized and adjusted to improve the accuracy and adaptability of the classification model.
[0066] Optionally, during the classification model training process, data cleaning and feature extraction are performed to ensure the quality and representativeness of the data set, and to ensure that the selection and training process of the classification model is transparent and understandable, so as to provide more intelligent and personalized permission management and improve the flexibility, efficiency and security of permission management.
[0067] S204: The server generates permission application information according to the permission information.
[0068] The permission application information is used to indicate a change to the user permission of the target user.
[0069] Optionally, the target user's permission information is determined through the output of the classification model, and the target user's permission information is compared with the existing permission information of the current target user to determine the permissions that the target user needs to add or delete.
[0070] Optionally, permission application information may be generated according to the permission information in accordance with a preset permission application template, wherein the permission application information may include application for adding a new permission and application for deleting a permission, etc.
[0071] Optionally, the role information of the template user can be determined based on the output of the classification model, and the role information can be compared with the current role information of the target user. If the role information is consistent, there is no need to generate application information based on the permission information. If the role information is inconsistent, it is necessary to generate permission application information. The permission application information can be generated according to the preset role change application template, and the role information of the target user can be changed. Since different roles correspond to different permission information, the permissions of the target user can be changed by changing the role information of the target user.
[0072] S205: The server initiates an approval process according to the permission application information to determine whether to change the permission information of the target user.
[0073] In one possible implementation, the permission application information may be sent to a target user, and the target user determines whether to initiate an approval process based on the permission application information.
[0074] In another possible implementation, the server may spontaneously initiate an approval process after generating the permission application information.
[0075] Optionally, after entering the approval process, the permission application information needs to be reviewed according to the preset approval rules to decide whether to approve the permission application. If it meets the approval rules, it will be approved and the permission information of the target user will be changed. If it does not meet the approval rules, it will be rejected and the current permission information of the target user will be maintained.
[0076] Optionally, when reviewing permission application information, it can be achieved through automatic review, or it can be achieved by combining automated tools and manual review.
[0077] The above first obtains the work data of the target user, and the work data is determined according to the position information, access records, historical permissions and workflow of the target user. Then, the work data is feature extracted to obtain the feature data of the target user, and then the feature data is input into the classification model. The permission information of the target user is determined according to the output of the classification model, and then the permission application information is generated according to the permission information. The permission application information is used to indicate the change of the user permissions of the target user. Finally, the approval process is initiated according to the permission application information to determine whether to change the permission information of the target user. The permission information corresponding to the target user can be determined by timely obtaining the work data of the target user, and then the permission information of the target user can be updated. The permissions of the target user can be dynamically adjusted. In large or rapidly changing organizations, permission management can be performed efficiently, while reducing the workload of permission configuration and reducing the security risks caused by improper permission configuration.
[0078] In an exemplary embodiment, Figure 3As shown, based on the above embodiment, optionally, the permission application information is reviewed and approved to determine whether to change the permission information of the target user, including steps 301 to 303, wherein:
[0079] S301, the server obtains a preset standard permission application information list.
[0080] Among them, the preset standard permission application information list includes new common permission requests, new short-term permission requests and deletion permission requests.
[0081] S302: If the preset standard permission application information list includes the permission application information, the server automatically completes the approval.
[0082] Optionally, the preset standard permission application information list usually includes scenarios for standardization and low risk, and approval can be completed without manual intervention. New common permission requests include applications for access to a general document library by new employees, basic file access permission requests, and common software usage permission requests. New short-term permission requests can be automatically approved when the validity period of the applied permission is less than the preset validity period and does not involve sensitive data or key resources, and the permission can be automatically deleted after the permission expires. Deletion of permission requests can automatically delete the target user's old permissions when the target user leaves or his job responsibilities change.
[0083] Optionally, if the preset standard permission application information list includes permission application information, the permission application may usually be approved when the approval is completed.
[0084] S303: If the preset standard permission application information list does not include the permission application information, the server sends the permission application information to the administrator.
[0085] Optionally, receive instruction information from a management staff member to approve the permission application information according to the instruction information.
[0086] Optionally, scenarios that require more review may require a combination of automated tools and manual approval. For example, permission requests for access to sensitive data, permission to change key settings, permission requests involving key resources or major changes in responsibilities, and customized permission requests for special positions or specific projects that do not conform to the preset standard permission application information list require approval by the department heads or managers involved.
[0087] In one possible implementation, for permission requests that do not conform to a preset standard permission application information list, the permission application information can be directly sent to a manager, and then the manager's input instructions are received, and the permission application information is approved based on the input instructions obtained.
[0088] In another possible implementation method, for permission requests that do not meet the preset standard permission application information list, you can first obtain the historical approval records, then find other applications in the historical approval records that are similar to the permission application information, and then determine the approval rate of similar applications in the historical approval records. Finally, the permission application information and the approval rate are sent to the management personnel at the same time. The approval rate can provide the management personnel with an approval reference. After sending the permission application information and the approval rate to the management personnel, the management personnel's input instructions are received, and the approval of the permission application information is completed according to the obtained input instructions.
[0089] Optionally, in emergency situations, for permission requests that do not meet the preset standard permission application information list, such as when immediate access to critical systems is required, the server can automatically complete the approval and grant the target user the relevant permissions. At the same time, this authorization operation needs to be marked for subsequent review.
[0090] The above-mentioned method obtains a preset standard permission application information list. If the preset standard permission application information list includes the permission application information, the approval is automatically completed. If the preset standard permission application information list does not include the permission application information, the permission application information is sent to the management personnel. Automatic approval is used for routine and low-risk permission management, and semi-automatic approval is used for permission management when dealing with complex or high-risk situations. By combining automatic and semi-automatic approval, the efficiency of user permission management can be effectively improved while ensuring the necessary security and compliance.
[0091] In an exemplary embodiment, Figure 4 As shown, based on the above embodiment, optionally, after generating permission application information according to permission information, the method further includes steps 401 to 402, wherein:
[0092] S401, the server sends permission application information to the target user.
[0093] Optionally, after generating the permission application information, the permission application information can be sent to the terminal of the target user, and the input instructions of the target user can be received through the terminal and sent to the server, so that the server decides whether to initiate an approval process based on the input instructions of the target user. For example, through the output of the classification model, it is determined that the target user needs to add the permission to view a certain document. After generating the permission application information according to the preset permission application template, the permission application information is sent to the target user to prompt the target user to apply for permission.
[0094] Optionally, the permission application information for the deletion permission may not be sent to the target user, and the server may directly initiate the approval process.
[0095] Optionally, the permission application information can be sent to the target user's terminal through a message push platform, email, or text message, and the target user can log in to the permission management system through the terminal and input permission request instructions to the server. Alternatively, the permission application information sent to the target user can include a link to initiate the approval process, or the target user can click a link in the received permission application information on the terminal to input permission request instructions to the server.
[0096] S402: If a permission request from a target user is received, the server examines and approves the permission application information.
[0097] The permission request includes permission application information, target user location information and request time.
[0098] Optionally, after receiving the permission request from the target user, the location information and request time of the target user are determined from the permission request.
[0099] Optionally, the target user's location information can be determined by the IP segment carried in the permission request, or the target user's authorization can be requested before the target user initiates the permission request. After obtaining the target user's authorization, the target user's location information can be obtained through the user terminal's GPS, Wi-Fi or Bluetooth positioning. This application does not limit this.
[0100] Optionally, the request time can be a timestamp carried by the terminal when inputting the permission request instruction, or it can be a timestamp carried by the server when receiving the permission request. The embodiment of the present application does not limit this. At the same time, the embodiment of the present application does not limit the time format of the request time. It can be consistent with the time format in the preset time range, or it can be inconsistent with the time format in the preset time range. When the request time is inconsistent with the time format in the preset time range, the time format can be converted during comparison.
[0101] Optionally, the location information of the target user is compared with the preset location information, and the request time is compared with the preset time range. The preset location information and the preset time range can be pre-set. The preset location information can be an office or other designated area, and the preset time range can be working hours.
[0102] Optionally, if the location information of the target user in the permission request does not match the preset location information, and / or the request time in the permission request does not match the preset time range, the permission application information will not be approved.
[0103] Optionally, when the location information does not match the preset location information, the permission application information may not be approved, and there is no need to judge the request time. Alternatively, when the request time does not match the preset time range, the permission application information may not be approved, and there is no need to judge the request location. Alternatively, when the location information does not match the preset location information, it is determined whether the request time is within the preset time range. Only when both conditions are met at the same time, the permission application information will not be approved. The above conditions can be configured through configuration files or configuration items.
[0104] The above-mentioned method sends the permission application information to the target user. If the permission request of the target user is received, the permission application information is approved. The permission request includes the permission application information, the target user's location information and the request time. After obtaining the permission request of the target user, if the location information of the target user in the permission request does not match the preset location information, and / or the request time in the permission request does not match the preset time range, the permission application information will not be approved, which can further ensure the security and compliance of the target user's permission approval.
[0105] In an exemplary embodiment, Figure 5 As shown, based on the above embodiment, optionally, the method further includes step 501 to step 502, wherein:
[0106] S501, the server obtains the virtual boundary corresponding to the office location and the location information of the target user.
[0107] Optionally, geo-fencing technology is used to create virtual boundaries of office locations or special locations, and a monitoring system is implemented to obtain location information of target users, wherein the location information of the target user can be sent to the server periodically by the target user terminal, or can be sent to the server in real time.
[0108] Optionally, edge computing technology can be used to process the location information of the target user to reduce latency and improve the response speed and efficiency of permission management.
[0109] S502: The server updates the target user's permission information based on the preset permission rules and the virtual boundary and location information.
[0110] Optionally, determine whether the target user's location information is entering or leaving an office or a special location, and update the target user's permission information so that the target user can have access rights to certain systems only when at a designated location. The preset permission rules may include the update scope of the target user's permission information, that is, when the target user leaves the office or a special location, set which permissions of the target user are unusable or delete which permissions of the target user; when the target user enters the office or a special location, restore the target user's permissions or add new permissions to the target user. For example, the target user has permissions to access a general document library and sensitive data at the same time. When the target user leaves the office or a special location, the target user can access the general document library but cannot access sensitive data. After entering the office or a special location, the target user can access both the general document library and sensitive data.
[0111] Optionally, the preset permission rules may also include updating the permission information of the target user according to time, such as which permissions of the target user can be used outside working hours and which permissions cannot be used.
[0112] By obtaining the virtual boundary corresponding to the office location and the location information of the target user, and updating the target user's permission information based on the virtual boundary and location information based on the preset permission rules, the efficiency of user permission management can be improved, the target user's permissions can be managed flexibly, and the security of the target user's permission management can be ensured.
[0113] In an exemplary embodiment, based on the above embodiment, optionally, the method also includes: the server receives a login request from a target user, performs multiple verifications on the target user, and determines the identity information of the target user, wherein the multiple verifications include verifying the target user's login password, iris information, fingerprint information, verification code or hardware token; and determines the target user's authority information based on the target user's identity information.
[0114] Optionally, when the target user logs into the rights management system or a related system at a terminal, the identity of the target user is verified to determine the rights information of the target user according to the identity information of the target user.
[0115] Optionally, the identity authentication of the target user includes the following steps: (1) performing basic identity authentication on the target user by obtaining the user name and password of the target user uploaded by the terminal; (2) determining whether additional identity authentication is required according to preset verification rules, the preset verification rules being based on the role of the target user, the sensitivity of the access request or other risk indicators; (3) if additional verification is required, executing step (4); if no additional verification is required, the user login is successful, and the target user's permission information is determined based on the target user's identity information; (4) selecting a second factor for identity authentication. By default, a biometric method such as iris recognition or fingerprint recognition is used as the second factor. The biometric method is unique and has higher security during identity authentication. The user can also choose other verification methods, such as SMS verification code, email verification code or hardware token; (5) verifying the second factor to authenticate the target user. If the second factor verification passes, the target user's permission information is determined based on the target user's identity information.
[0116] Optionally, when iris recognition is used as a second factor for identity authentication, the following authentication process is considered: (1) When the target user registers, an initial iris scan is performed through the terminal's camera or other external shooting equipment, and the target user's initial iris data is sent to the server, which processes the initial iris data to obtain and store the target user's iris data; (2) When logging in, after the user enters the user name and password, the server sends a command to the terminal to prompt the target user to perform an iris scan for second factor authentication; (3) The server compares the acquired iris data of the target user with the stored iris data to verify the target user's identity; (4) When the target user's identity is confirmed, the target user's existing permission information is determined based on the target user's identity information.
[0117] Optionally, when performing second factor verification, only biometric verification may be required to determine whether the target user's identity has been authenticated, or multiple second factor verifications may be required at the same time to determine whether the target user's identity has been authenticated.
[0118] Optionally, the process and results of the target user's login verification are monitored and recorded to conduct security monitoring and auditing based on the records. The identity of the target user is verified in the above manner, combined with traditional identity authentication and additional security measures, which greatly enhances the security of permission management and effectively prevents unauthorized access. At the same time, by recording and monitoring authentication attempts, possible security threats can be responded to in a timely manner, further improving the security of permission management.
[0119] As an optional implementation, Figure 6 As shown, the permission management method provided in the embodiment of the present application may include the following specific steps:
[0120] S601, the server obtains the work data of the target user.
[0121] Among them, the work data is determined based on the target user's position information, access records, historical permissions and workflow.
[0122] S602: The server extracts features from the work data to obtain feature data of the target user.
[0123] S603, the server inputs the feature data into the classification model, and determines the authority information of the target user according to the output of the classification model.
[0124] S604, the server generates permission application information according to the permission information, where the permission application information is used to indicate a change to the user permission of the target user.
[0125] S605: The server sends the permission application information to the target user.
[0126] S606: If a permission request from the target user is received, the server examines and approves the permission application information.
[0127] The permission request includes permission application information, target user location information and request time.
[0128] S607: If the location information of the target user in the permission request does not match the preset location information, and / or the request time in the permission request does not match the preset time range, the server does not approve the permission application information.
[0129] S608, the server obtains a preset standard permission application information list, where the preset standard permission application information list includes a request for adding a common permission, a request for adding a short-term permission, and a request for deleting a permission;
[0130] S609: If the preset standard permission application information list includes the permission application information, the server automatically completes the approval.
[0131] S610: If the preset standard permission application information list does not include the permission application information, the server sends the permission application information to the administrator.
[0132] S611, the server receives instruction information from the administrator to review and approve the permission application information according to the instruction information.
[0133] S612: The server obtains the virtual boundary corresponding to the office location and the location information of the target user.
[0134] S613: The server updates the target user's permission information based on the preset permission rules and the virtual boundary and location information.
[0135] It should be understood that, although the various steps in the flowcharts involved in the above-mentioned embodiments are displayed in sequence according to the indication of the arrows, these steps are not necessarily executed in sequence according to the order indicated by the arrows. Unless there is a clear explanation in this article, the execution of these steps does not have a strict order restriction, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-mentioned embodiments can include multiple steps or multiple stages, and these steps or stages are not necessarily executed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a part of the steps or stages in other steps.
[0136] Based on the same inventive concept, the embodiment of the present application also provides a rights management device for implementing the rights management method involved above. The implementation solution provided by the device to solve the problem is similar to the implementation solution recorded in the above method, so the specific limitations in one or more rights management device embodiments provided below can refer to the limitations on the rights management method above, and will not be repeated here.
[0137] In an exemplary embodiment, Figure 7 As shown, a rights management device 700 is provided, comprising: a first acquisition module 701, a second acquisition module 702, a determination module 703, a generation module 704 and an approval module 705, wherein:
[0138] The first acquisition module 701 is used to acquire the work data of the target user, where the work data is determined based on the position information, access records, historical permissions and workflow of the target user;
[0139] The second acquisition module 702 is used to extract features from the work data to obtain feature data of the target user;
[0140] The determination module 703 is used to input the characteristic data into the classification model and determine the authority information of the target user according to the output of the classification model;
[0141] A generating module 704, used to generate permission application information according to the permission information, used to indicate a change to the user permission of the target user;
[0142] The approval module 705 is used to approve the permission application information to determine whether to change the permission information of the target user.
[0143] In one of the embodiments, the approval module 705 is specifically used to obtain a preset standard permission application information list, which includes new common permission requests, new short-term permission requests and deletion permission requests; if the preset standard permission application information list includes permission application information, the approval is automatically completed.
[0144] In one embodiment, the approval module 705 is specifically used to send the permission application information to the management personnel if the permission application information is not included in the preset standard permission application information list; receive the instruction information from the management personnel to approve the permission application information according to the instruction information.
[0145] In one embodiment, the approval module 705 is also used to send permission application information to the target user; if a permission request from the target user is received, the permission application information is approved, and the permission request includes the permission application information, the target user location information and the request time.
[0146] In one embodiment, the approval module 705 is also used to not approve the permission application information if the location information of the target user in the permission request does not match the preset location information, and / or the request time in the permission request does not match the preset time range.
[0147] In one of the embodiments, the permission management device further includes a monitoring module for obtaining the virtual boundary corresponding to the office location and the location information of the target user; based on preset permission rules, the permission information of the target user is updated according to the virtual boundary and the location information.
[0148] In one of the embodiments, the permission management device also includes a login module, which is used to receive a login request from a target user, perform multiple verifications on the target user, and determine the identity information of the target user. The multiple verifications include verifying the target user's login password, iris information, fingerprint information, verification code or hardware token; and determining the target user's permission information based on the target user's identity information.
[0149] Each module in the above-mentioned rights management device can be implemented in whole or in part by software, hardware or a combination thereof. Each module can be embedded in or independent of a processor in a computer device in the form of hardware, or can be stored in a memory in a computer device in the form of software, so that the processor can call and execute operations corresponding to each module above.
[0150] In an exemplary embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as shown in FIG. Figure 8As shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, referred to as I / O) and a communication interface. The processor, the memory and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store data. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, a permission management method is implemented.
[0151] Those skilled in the art will understand that Figure 8 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.
[0152] In an exemplary embodiment, a computer device is provided, including a memory and a processor, wherein a computer program is stored in the memory, and the processor implements the steps in the above-mentioned method embodiments when executing the computer program.
[0153] In an exemplary embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments are implemented.
[0154] In an exemplary embodiment, a computer program product is provided, including a computer program, and when the computer program is executed by a processor, the steps in the above method embodiments are implemented.
[0155] It should be noted that the user information (including but not limited to user device information, user personal information, user access records, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant regulations.
[0156] A person of ordinary skill in the art can understand that all or part of the processes in the above-mentioned embodiment method can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to the memory, database or other medium used in the embodiments provided in the present application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. As an illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in each embodiment provided in this application may include at least one of a relational database and a non-relational database. Non-relational databases may include distributed databases based on blockchains, etc., but are not limited to this. The processor involved in each embodiment provided in this application may be a general-purpose processor, a central processing unit, a graphics processor, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, an artificial intelligence (AI) processor, etc., but are not limited to this.
[0157] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.
[0158] The above-described embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the present application. It should be pointed out that, for a person of ordinary skill in the art, several variations and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the attached claims.
Claims
1. A rights management method, characterized in that: The method comprises: Acquire work data of a target user, wherein the work data is determined according to the position information, access records, historical permissions and workflow of the target user; Extracting features from the work data to obtain feature data of the target user; Inputting the characteristic data into a classification model, and determining the authority information of the target user according to the output of the classification model; Generate permission application information according to the permission information, wherein the permission application information is used to indicate a change to the user permission of the target user; An approval process is initiated according to the permission application information to determine whether to change the permission information of the target user.
2. The method according to claim 1, characterized in that The approving the permission application information to determine whether to change the permission information of the target user includes: Obtain a list of preset standard permission application information, wherein the list of preset standard permission application information includes requests for adding common permissions, requests for adding short-term permissions, and requests for deleting permissions; If the permission application information is included in the preset standard permission application information list, the approval is automatically completed.
3. The method according to claim 2, characterized in that The approving the permission application information to determine whether to change the permission information of the target user includes: If the permission application information is not included in the preset standard permission application information list, sending the permission application information to the administrator; Receive instruction information from the administrator to approve the permission application information according to the instruction information.
4. The method according to claim 2, characterized in that: After generating permission application information according to the permission information, the method further includes: Sending the permission application information to the target user; If a permission request from the target user is received, the permission application information is approved, and the permission request includes permission application information, target user location information and request time.
5. The method according to claim 4, characterized in that The method further comprises: If the location information of the target user in the permission request does not match the preset location information, and / or the request time in the permission request does not match the preset time range, the permission application information will not be approved.
6. The method according to any one of claims 1 to 5, characterized in that: The method further comprises: Obtaining a virtual boundary corresponding to the office location and location information of the target user; Based on a preset authority rule, the authority information of the target user is updated according to the virtual boundary and the location information.
7. The method according to claim 1, characterized in that The method further comprises: Receiving a login request from the target user, performing multiple verifications on the target user, and determining the identity information of the target user, wherein the multiple verifications include verifying a login password, iris information, fingerprint information, a verification code, or a hardware token of the target user; The authority information of the target user is determined according to the identity information of the target user.
8. A rights management device, characterized in that: The device comprises: A first acquisition module is used to acquire work data of a target user, wherein the work data is determined according to the position information, access records, historical permissions and workflow of the target user; A second acquisition module is used to extract features from the work data to obtain feature data of the target user; A determination module, used to input the feature data into a classification model, and determine the authority information of the target user according to the output of the classification model; A generating module, used to generate permission application information according to the permission information, used to indicate a change to the user permission of the target user; The approval module is used to approve the permission application information to determine whether to change the permission information of the target user.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.
Citation Information
Patent Citations
Enterprises network access authority control method and device
CN106060041A
Access control method and device, electronic equipment and storage medium
CN117216783A
Management authority matching method, device and system
CN117540404A
Pre-Access Location-Based Rule Initiation in a Virtual Computing Environment
US20120203906A1