Authority management method and device, equipment and storage medium
By analyzing user's operational behavior data and automatically managing user's permissions, the existing permission management methods are solved, and the existing permission management methods are poorly flexible and difficult to monitor in real time are achieved, efficient and accurate permission management is achieved, and data security is ensured.
Patent Information
- Application Number
- CN202510185501.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-18
- Publication Date
- 2025-05-23
AI Technical Summary
The existing permission management methods rely on manual application, approval and management, resulting in poor flexibility and difficulty in monitoring and managing user permission usage in real time, which may lead to waste of permissions and unreasonable use of resources.
By obtaining user's operational behavior data, analyze this data to determine whether to delay or recycle user's operational permissions. Specific methods include counting the user's operation frequency, evaluating the user's risk level using a risk assessment model, and automatically managing user's permissions based on these analysis results.
It realizes automated management of user permissions, improves the flexibility and accuracy of permission management, avoids abuse of permissions, timely recycles inefficient permissions, reduces resource waste, and improves system security.
Smart Images

Figure CN120030573A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular to a permission management method, device, equipment and storage medium. Background Art
[0002] The current permission management method mainly relies on manual application, approval and allocation of permissions. In addition, the validity period of permissions needs to be set manually, which makes permission management less flexible and difficult to monitor and manage the permission usage of each user in real time. Due to the limitations of manual management, once the validity period of permissions is set inappropriately, it may lead to waste of permissions or unreasonable use of resources. For example, the permissions of some users may have expired when they are needed, affecting their normal work. While the permissions of other users may still be valid when they are no longer needed, resulting in waste of resources and increasing system security risks. Summary of the invention
[0003] Based on this, it is necessary to provide a permission management method, device, equipment and storage medium for the above technical problems to solve at least one of the above technical problems.
[0004] The present invention provides a rights management method, comprising:
[0005] Acquire the user's operation behavior data, wherein the user refers to a user who has operation authority on the target system;
[0006] The operation behavior data is analyzed to perform extension management or authority recovery management on the user's operation authority according to the analysis result.
[0007] Optionally, according to a permission management method provided by the present invention, the analyzing the operation behavior data to perform extension management or permission recovery management on the user's operation permission according to the analysis result includes:
[0008] Based on the operation behavior data, counting a first operation frequency of the user on the target system;
[0009] If the first operation frequency is less than a preset quantity threshold, generating a prompt message and pushing it to the user;
[0010] Monitoring target behavior data of the user in a preset time period after receiving the prompt information;
[0011] According to the target behavior data, the operation authority of the user is managed for a longer period of time or for authority recovery.
[0012] Optionally, according to a permission management method provided by the present invention, the step of performing extension management or permission recovery management on the operation permission of the user according to the target behavior data includes:
[0013] Based on the target behavior data, counting a second operation frequency of the user on the target system;
[0014] If the second operation frequency is less than a preset quantity threshold, reclaiming the operation authority of the user;
[0015] If the second operation frequency is greater than or equal to a preset quantity threshold, the operation authority of the user is managed with extension.
[0016] Optionally, according to a permission management method provided by the present invention, the analyzing the operation behavior data to perform extension management or permission recovery management on the user's operation permission according to the analysis result includes:
[0017] Using a preset risk assessment model, a risk assessment is performed on the operation behavior data to obtain a risk assessment level;
[0018] According to the risk assessment level, the operation authority of the user is managed for a longer period of time or for authority recovery.
[0019] Optionally, according to a permission management method provided by the present invention, the step of performing extension management or permission recovery management on the user's operation permission according to the risk assessment level includes:
[0020] If the risk assessment level is a low risk level, then the operation authority of the user is managed on an extended basis;
[0021] If the risk assessment level is a high risk level, the operation authority of the user is revoked.
[0022] Optionally, according to a permission management method provided by the present invention, after performing the extension management on the operation permission of the user, the method further comprises:
[0023] Determine the extension period of the said operating authority;
[0024] If the current time has reached the extension period, the process returns to the step of obtaining the user's operation behavior data.
[0025] Optionally, according to a permission management method provided by the present invention, before obtaining the user's operation behavior data, the method further includes:
[0026] When receiving a user's permission application request, send the permission application request to the approver for manual review;
[0027] When an approval result is received, an approval notification is generated and pushed to the user;
[0028] When a rejection result is received, a rejection notification is generated and pushed to the user.
[0029] The present invention also provides a rights management device, comprising:
[0030] An acquisition module, used to acquire the operation behavior data of the user, wherein the user refers to a user having operation authority on the target system;
[0031] The authority management module is used to analyze the operation behavior data to perform extension management or authority recovery management on the user's operation authority according to the analysis result.
[0032] The present invention also provides a computer device, comprising a memory, a processor, and computer-readable instructions stored in the memory and executable on the processor, wherein the processor implements the above-mentioned permission management method when executing the computer-readable instructions.
[0033] The present invention also provides one or more readable storage media storing computer-readable instructions, and the computer-readable instructions implement the above-mentioned permission management method when executed by a processor.
[0034] The present invention also provides a computer program product, comprising a computer program, wherein when the computer program is executed by a processor, the computer program implements any of the above-mentioned rights management methods.
[0035] The above-mentioned permission management method, device, equipment and storage medium include: obtaining the user's operation behavior data, wherein the user refers to a user with operation permissions on the target system; analyzing the operation behavior data to perform extension management or permission recovery management on the user's operation permissions according to the analysis results. The present invention analyzes the user's operation behavior data and automatically grants and recovers the user's permissions according to the analysis results. It has strong flexibility, effectively avoids the abuse of permissions, promptly recovers inefficient permissions, reduces the waste of resources, improves the accuracy and stability of permission management, and ensures data security. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings required for use in the description of the embodiments of the present invention will be briefly introduced below. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without paying creative labor.
[0037] Figure 1It is a flowchart of a rights management method in one embodiment of the present invention;
[0038] Figure 2 is a schematic diagram of a structure of a rights management device in one embodiment of the present invention;
[0039] Figure 3 is a schematic diagram of a computer device in one embodiment of the present invention. DETAILED DESCRIPTION
[0040] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0041] The terms used in one or more embodiments of the present invention are only for the purpose of describing specific embodiments, and are not intended to limit one or more embodiments of the present invention. The singular forms of "a", "said" and "the" used in one or more embodiments of the present invention are also intended to include plural forms, unless the context clearly indicates other meanings. It should also be understood that the term "and / or" used in one or more embodiments of the present invention refers to and includes any or all possible combinations of one or more associated listed items.
[0042] In one embodiment, specifically, Figure 1 As shown, Figure 1 1 is a flowchart of a rights management method in an embodiment of the present invention. The present invention provides a rights management method, including the following steps:
[0043] Step S11, obtaining user operation behavior data;
[0044] It should be noted that the user refers to a user who has operation permissions on the target system. In more detail: the user initiates an application on the target system. When the user's permission application request is received, the permission application request is sent to the approver for manual review; when the approval result is received, an approval notification is generated and pushed to the user; when the approval failure result is received, a rejection notification is generated and pushed to the user.
[0045] Specifically, the behavior data of the user operating the target system within a preset time period is monitored, for example, the number of times the system is accessed, the number of times a file is downloaded, and other behavior data.
[0046] Step S12: analyzing the operation behavior data to perform extension management or authority recovery management on the user's operation authority according to the analysis result.
[0047] It should be noted that permissions can include system login permissions, operation permissions for a certain function, file report permissions, and other permissions.
[0048] It should be noted that the extension management of user operation rights refers to extending the validity period of user operation rights and allowing users to continue to use the system. The permission recovery management of user operation rights refers to prohibiting users from continuing to use the system or a certain system function.
[0049] In one embodiment, the operation behavior data is analyzed to count the first operation frequency of the user on the target system, such as access frequency, download frequency, etc., and then the first operation frequency is compared with a preset quantity threshold. If the first operation frequency is less than the preset quantity threshold, it proves that the user has performed fewer operations in the target system, and the user's operation authority is reclaimed; if the first operation frequency is greater than or equal to the preset quantity threshold, the user's operation authority is deferred.
[0050] In one embodiment, the operation behavior data is analyzed to count the first operation frequency of the user on the target system, and then the first operation frequency is compared with a preset quantity threshold. If the first operation frequency is less than the preset quantity threshold, a prompt message is generated and pushed to the user to prompt the user that more operations may be required and the user authority may be revoked; further, the target behavior data of the user in a preset time period after receiving the prompt message is monitored to observe whether the user has changed or taken corresponding operations; based on the target behavior data, the second operation frequency of the user on the target system is counted; if the second operation frequency is less than the preset quantity threshold, it proves that the user's operation frequency after receiving the prompt message is still low and there is a potential risk, and then the user's operation authority is revoked; if the second operation frequency is greater than or equal to the preset quantity threshold, it proves that the user's operation frequency after receiving the prompt message has increased and the risk is low, and then the user's operation authority is deferred.
[0051] In one embodiment, a risk assessment model is pre-trained, and the preset risk assessment model is used to perform risk assessment on the operation behavior data to obtain a risk assessment level; if the risk assessment level is a low risk level, the user's operation authority is managed with an extension, that is, the user's access authority period is extended; if the risk assessment level is a high risk level, the user's operation authority is revoked to stop the user's operation authority.
[0052] In addition, in one embodiment, after the operation authority of the user is extended, the extension period of the operation authority is determined; if the current time has reached the extension period, the step of obtaining the user's operation behavior data is returned to re-obtain the user's operation behavior data, including access records, download records, etc., thereby realizing periodic extension management or authority recovery management of the user's operation authority to ensure the security and stability of the system.
[0053] The embodiment of the present invention, through the above scheme, includes: obtaining the user's operation behavior data, wherein the user refers to a user with operation authority on the target system; analyzing the operation behavior data to perform extension management or authority recovery management on the user's operation authority according to the analysis result. The present invention analyzes the user's operation behavior data and automatically grants and recovers the user's authority according to the analysis result. It has strong flexibility, effectively avoids the abuse of authority, recovers inefficient authority in time, reduces resource waste, improves the accuracy and stability of authority management, and ensures data security.
[0054] In one embodiment of the present invention, the operation behavior data is analyzed to perform extension management or permission recovery management on the user's operation authority according to the analysis result, including:
[0055] Based on the operation behavior data, the first operation frequency of the user on the target system is counted; if the first operation frequency is less than a preset quantity threshold, a prompt message is generated and pushed to the user; the target behavior data of the user in a preset time period after receiving the prompt message is monitored; and according to the target behavior data, the operation authority of the user is extended or reclaimed.
[0056] Specifically, the system will collect the user's operation data on the target system, and based on these data, calculate the frequency of a certain specific operation of the user (that is, the first operation frequency), for example, the frequency of access and download times of the user on the target system. Then, the first operation frequency is compared with a preset quantity threshold. If the first operation frequency is greater than or equal to the preset quantity threshold, it proves that the user frequently accesses the system, and the user's operation authority is automatically extended. In addition, if the first operation frequency is less than the preset quantity threshold, it proves that the user has performed fewer operations in the target system, and then a prompt message is generated to remind the user that more operations may be required, and the information is pushed to the user.
[0057] After the user receives the prompt information, the system will monitor the user's behavior data (i.e., target behavior data) in the next preset time period to observe whether the user has changed or taken corresponding actions, wherein the preset time period can be set according to the actual situation and is not specifically limited here. Furthermore, based on the user's target behavior data in the preset time period, the system will make further operation authority management decisions to extend the operation authority of the user or reclaim the authority. Extended management means that the user's authority may be extended; authority reclaim management means that the user's authority will be revoked.
[0058] The embodiment of the present invention, through the above scheme, includes: based on the operation behavior data, counting the first operation frequency of the user on the target system; if the first operation frequency is less than the preset number threshold, generating a prompt message and pushing it to the user; monitoring the target behavior data of the user in a preset time period after receiving the prompt message; and performing extension management or permission recovery management on the user's operation authority according to the target behavior data. It realizes automatic authorization and recovery management of user's authority according to the operation frequency of the user on the target system, effectively avoiding abuse of authority, timely recovering inefficient authority, reducing resource waste, improving the accuracy and stability of authority management, and ensuring data security.
[0059] In one embodiment of the present invention, performing extension management or permission recovery management on the operation authority of the user according to the target behavior data includes:
[0060] Based on the target behavior data, the second operation frequency of the user on the target system is counted; if the second operation frequency is less than a preset number threshold, the user's operation authority is revoked; if the second operation frequency is greater than or equal to the preset number threshold, the user's operation authority is extended.
[0061] Specifically, based on the user's target behavior data on the target system, calculate the user's second operation frequency (for example, access frequency or download frequency) within a preset time period after receiving the prompt information. Compare the second operation frequency with the preset quantity threshold: If the second operation frequency is less than the preset quantity threshold, it proves that the user's operation frequency after receiving the prompt information is still low, and there is a potential risk. The user's operation authority is reclaimed to prevent unnecessary risks. If the second operation frequency is greater than or equal to the preset quantity threshold, it proves that the user's operation frequency after receiving the prompt information has increased, and the risk is low. Therefore, the user's operation authority is managed with a delay, allowing the user to continue using the system.
[0062] The embodiment of the present invention, through the above scheme, includes: based on the target behavior data, counting the second operation frequency of the user on the target system; if the second operation frequency is less than the preset number threshold, reclaiming the user's operation authority; if the second operation frequency is greater than or equal to the preset number threshold, performing extension management on the user's operation authority. Automatically granting and reclaiming the user's authority according to the user's operation frequency within a preset time period after receiving the prompt information, effectively avoiding abuse of authority, timely reclaiming inefficient authority, reducing resource waste, improving the accuracy and stability of authority management, and ensuring data security.
[0063] In one embodiment of the present invention, the operation behavior data is analyzed to perform extension management or permission recovery management on the user's operation authority according to the analysis result, including:
[0064] The operation behavior data is risk assessed using a preset risk assessment model to obtain a risk assessment level; and the user's operation authority is extended or reclaimed based on the risk assessment level.
[0065] It should be noted that when the risk assessment model can be a neural network model or an SVM model, historical behavior data is obtained, data processing is performed on the historical behavior data, and the processed data is labeled with risk levels. For example, users who frequently use the target system are at a low risk level, and users who occasionally use the target system are at a high risk level. The risk assessment model is thus trained using the user's historical behavior data and its risk level. Specifically, the operation behavior data is input into a preset risk assessment model for risk assessment to obtain a risk assessment level; if the risk assessment level is a low risk level, the user's operation authority is managed on an extended basis; if the risk assessment level is a high risk level, the user's operation authority is revoked.
[0066] The embodiment of the present invention, through the above scheme, includes: using a preset risk assessment model to conduct risk assessment on the operation behavior data to obtain a risk assessment level; and according to the risk assessment level, performing extension management or permission recovery management on the user's operation authority. It realizes the use of a preset risk assessment model to conduct risk assessment, and then automatically grants and recovers the user's authority according to the assessment result, effectively avoiding the abuse of authority, timely recovering inefficient authority, reducing resource waste, and improving the accuracy and stability of authority management.
[0067] It should be understood that the order of execution of the steps in the above embodiment does not necessarily mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiment of the present invention.
[0068] In one embodiment, a rights management device is provided, which corresponds one-to-one to the rights management method in the above embodiment. Figure 2 As shown, Figure 2 : is a schematic diagram of a structure of a rights management device in an embodiment of the present invention, the rights management device comprises:
[0069] The acquisition module 21 is used to acquire the operation behavior data of the user, wherein the user refers to the user who has the operation authority on the target system;
[0070] The authority management module 22 is used to analyze the operation behavior data and to perform extension management or authority recovery management on the user's operation authority according to the analysis result.
[0071] The rights management module 22 is also used for:
[0072] Based on the operation behavior data, counting a first operation frequency of the user on the target system;
[0073] If the first operation frequency is less than a preset quantity threshold, generating a prompt message and pushing it to the user;
[0074] Monitoring target behavior data of the user in a preset time period after receiving the prompt information;
[0075] According to the target behavior data, the operation authority of the user is managed for a longer period of time or for authority recovery.
[0076] The rights management module 22 is also used for:
[0077] Based on the target behavior data, counting a second operation frequency of the user on the target system;
[0078] If the second operation frequency is less than a preset quantity threshold, reclaiming the operation authority of the user;
[0079] If the second operation frequency is greater than or equal to a preset quantity threshold, the operation authority of the user is managed with extension.
[0080] The rights management module 22 is also used for:
[0081] Using a preset risk assessment model, a risk assessment is performed on the operation behavior data to obtain a risk assessment level;
[0082] According to the risk assessment level, the operation authority of the user is managed for a longer period of time or for authority recovery.
[0083] The rights management module 22 is also used for:
[0084] If the risk assessment level is a low risk level, then the operation authority of the user is managed on an extended basis;
[0085] If the risk assessment level is a high risk level, the operation authority of the user is revoked.
[0086] The rights management device also includes:
[0087] Determine the extension period of the said operating authority;
[0088] If the current time has reached the extension period, the process returns to the step of obtaining the user's operation behavior data.
[0089] The rights management device also includes:
[0090] The approval module is used to send the permission application request to the approver for manual review when receiving the permission application request from the user;
[0091] A first push module is used to generate an approval notification and push it to the user when receiving the approval result;
[0092] The second push module is used to generate a rejection notification and push it to the user when receiving a rejection result.
[0093] For the specific definition of the rights management device, please refer to the definition of the rights management method above, which will not be repeated here. Each module in the above rights management device can be implemented in whole or in part by software, hardware and a combination thereof. The above modules can be embedded in or independent of the processor in the computer device in the form of hardware, or can be stored in the memory of the computer device in the form of software, so that the processor can call and execute the operations corresponding to the above modules.
[0094] In one embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as follows: Figure 3 As shown, Figure 3: is a schematic diagram of a computer device in an embodiment of the present invention. The computer device includes a processor, a memory, a network interface and a database connected by a device bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a readable storage medium and an internal memory. The readable storage medium stores an operating device, a computer-readable instruction and a database. The internal memory provides an environment for the operation of the operating device and the computer-readable instructions in the readable storage medium. The database of the computer device is used to store data involved in the permission management method. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer-readable instruction is executed by the processor, a permission management method is implemented. It includes: obtaining the user's operation behavior data, wherein the user refers to a user with operation permissions on the target system; analyzing the operation behavior data, so as to perform extension management or permission recovery management on the user's operation permissions according to the analysis results. The readable storage medium provided in this embodiment includes a non-volatile readable storage medium and a volatile readable storage medium.
[0095] In one embodiment, a computer device is provided. The computer device may be a terminal device, and its internal structure diagram may be as follows: Figure 3 As shown. The computer device includes a processor, a memory, and a network interface connected through a device bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a readable storage medium. The readable storage medium stores computer-readable instructions. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer-readable instructions are executed by the processor, a permission management method is implemented. The readable storage medium provided in this embodiment includes a non-volatile readable storage medium and a volatile readable storage medium.
[0096] In one embodiment, a computer device is provided, including a memory, a processor, and computer-readable instructions stored in the memory and executable on the processor, and when the processor executes the computer-readable instructions, the steps of the above-mentioned permission management method are implemented, including: obtaining the user's operation behavior data, wherein the user refers to a user with operation permissions on the target system; analyzing the operation behavior data, and performing extension management or permission recovery management on the user's operation permissions according to the analysis results.
[0097] In one embodiment, a readable storage medium is provided, the readable storage medium stores computer-readable instructions, and the computer-readable instructions are executed by the processor to implement the above-mentioned rights management method steps. A person of ordinary skill in the art can understand that all or part of the processes in the above-mentioned embodiment method can be completed by instructing the relevant hardware through computer-readable instructions, and the computer-readable instructions can be stored in a non-volatile readable storage medium or a volatile readable storage medium. When the computer-readable instructions are executed, they may include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application may include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM), etc.
[0098] In one embodiment, a computer program product is also provided, which includes a computer program. The computer program can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the permission management methods provided by the above methods.
[0099] Those skilled in the art can clearly understand that for the convenience and simplicity of description, only the division of the above-mentioned functional units and modules is used as an example. In actual applications, the above-mentioned functions can be distributed and completed by different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above.
[0100] The embodiments described above are only used to illustrate the technical solutions of the present invention, rather than to limit the same. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that the technical solutions described in the aforementioned embodiments may still be modified, or some of the technical features may be replaced by equivalents. Such modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included in the protection scope of the present invention.
Claims
1. A rights management method, characterized in that: include: Acquire the user's operation behavior data, wherein the user refers to a user who has operation authority on the target system; The operation behavior data is analyzed to perform extension management or authority recovery management on the user's operation authority according to the analysis result.
2. The rights management method according to claim 1, characterized in that: The analyzing the operation behavior data to perform extension management or permission recovery management on the user's operation authority according to the analysis result includes: Based on the operation behavior data, counting a first operation frequency of the user on the target system; If the first operation frequency is less than a preset quantity threshold, generating a prompt message and pushing it to the user; Monitoring target behavior data of the user in a preset time period after receiving the prompt information; According to the target behavior data, the operation authority of the user is managed for a longer period of time or for authority recovery.
3. The rights management method according to claim 2, characterized in that: The step of performing extension management or permission recovery management on the user's operation authority according to the target behavior data includes: Based on the target behavior data, counting a second operation frequency of the user on the target system; If the second operation frequency is less than a preset quantity threshold, reclaiming the operation authority of the user; If the second operation frequency is greater than or equal to a preset quantity threshold, the operation authority of the user is managed with extension.
4. The rights management method according to claim 1, characterized in that: The analyzing the operation behavior data to perform extension management or permission recovery management on the user's operation authority according to the analysis result includes: Using a preset risk assessment model, a risk assessment is performed on the operation behavior data to obtain a risk assessment level; According to the risk assessment level, the operation authority of the user is managed for a longer period of time or for authority recovery.
5. The rights management method according to claim 4, characterized in that: The step of performing extension management or authority recovery management on the user's operation authority according to the risk assessment level includes: If the risk assessment level is a low risk level, then the operation authority of the user is managed on an extended basis; If the risk assessment level is a high risk level, the operation authority of the user is revoked.
6. The method for managing rights according to any one of claims 1 to 5, characterized in that: After the extension management of the operation authority of the user is performed, the method further includes: Determine the extension period of the said operating authority; If the current time has reached the extension period, the process returns to the step of obtaining the user's operation behavior data.
7. The rights management method according to claim 1, characterized in that: Before obtaining the user's operation behavior data, the method further includes: When receiving a user's permission application request, send the permission application request to the approver for manual review; When an approval result is received, an approval notification is generated and pushed to the user; When a rejection result is received, a rejection notification is generated and pushed to the user.
8. A rights management device, characterized in that: include: An acquisition module, used to acquire the operation behavior data of the user, wherein the user refers to a user having operation authority on the target system; The authority management module is used to analyze the operation behavior data to perform extension management or authority recovery management on the user's operation authority according to the analysis result.
9. A computer device comprising a memory, a processor, and computer-readable instructions stored in the memory and executed on the processor, characterized in that: When the processor executes the computer-readable instructions, the rights management method according to any one of claims 1 to 7 is implemented.
10. A readable storage medium having computer readable instructions stored thereon, characterized in that: When the computer-readable instructions are executed by a processor, the rights management method according to any one of claims 1 to 7 is implemented.