Method and system based on multi-cluster user authority management
By analyzing the permission request trend in a multi-cluster environment, identifying abnormal fluctuations, and optimizing cluster configuration, the problem of difficulty in dynamic adjustment of permission configuration in the existing technology is solved, and efficient resource integration and flexible permission management are achieved.
Patent Information
- Application Number
- CN202510182154.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-19
- Publication Date
- 2025-05-27
AI Technical Summary
The existing technology is difficult to dynamically adjust permission configuration in a multi-cluster environment, resulting in excessive concentration of resources or excessive loose permission application, increasing the risk of permission abuse, and lacking an effective cross-cluster resource integration mechanism, resulting in resource waste or conflict.
By obtaining the subcluster user list in the enterprise owner cluster environment, analyzing the permission request trend, identifying abnormal fluctuations, calculating the cluster permission density value, optimizing the subcluster configuration, and defining cross-cluster access rules, cross-cluster permission sharing is realized.
Dynamic optimization and adjustment of permission configuration is realized, resource waste and permission abuse are avoided, coordination efficiency between different clusters is improved, and flexibility in permission management is enhanced.
Smart Images

Figure CN120046138A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of account management, and particularly to a method and system for multi-cluster user privilege management. Background Art
[0002] The technical field of account management includes related technologies such as user authentication, privilege assignment, access control, and data protection. Its core content is to ensure the accurate execution of user operation privileges in the information system and prevent unauthorized access through systematic management of user accounts and privileges.
[0003] Among them, the method of user privilege management refers to a technical method for identifying, assigning, managing, and controlling the operation privileges of users in the system. This method covers the verification of user identities to confirm their legitimacy, determines the resources and function scopes that users can access based on user identity information and predefined rules. The specific implementation methods usually include mapping the operation scope of users through privilege identifiers or privilege tables, dynamically judging user operation privileges through a rule engine, and managing the application and changes of privileges in combination with log records.
[0004] The prior art fails to fully address the problem of fluctuating resource requirements in a multi-cluster environment during the privilege management process. In traditional solutions, privilege assignment usually relies on static rules and predefined privilege tables, making it difficult to adjust dynamically according to real-time changes. Therefore, when certain privileges are frequently requested or there is excessive resource concentration, it is often impossible to identify and make adjustments in a timely manner. This leads to problems such as over-occupation of resources in some sub-clusters or overly loose privilege applications, increasing the risk of privilege abuse. The current technology also lacks an effective cross-cluster resource integration mechanism, and there may be redundancy or conflicts in the privilege configurations between different clusters, and it is impossible to perform efficient resource sharing according to actual needs. For example, when different clusters have different privilege requirements, traditional technologies may not be able to adjust their shared configurations in a timely manner, resulting in resource waste or conflicts, thereby reducing the overall efficiency. Summary of the Invention
[0005] To solve the technical problems existing in the prior art, embodiments of the present invention provide a method and system for multi-cluster user privilege management. The technical solutions are as follows: A method for multi-cluster user privilege management includes the following steps: S1: Obtain a list of registered sub-cluster users in the enterprise master cluster environment. Each sub-cluster is associated with the master cluster through a unique identifier, collect privilege request data and extract key information, divide a sliding window for the key information according to a time period and perform trend analysis to generate a privilege request trend analysis result; S2: Based on the analysis result of the permission request trend, analyze the fluctuation value of the permission request frequency and extract the fluctuation range. By calculating the abnormal fluctuation value and comparing it with the preset fluctuation threshold, mark the abnormal level and associate the request time period to generate a list of abnormal fluctuation permission distributions; S3: Obtain the abnormal interval associated with the abnormal level and the request time period in the list of abnormal fluctuation permission distributions. Take the ratio of the number of sub-cluster users to the number of permissions within the abnormal interval as the cluster permission density value. After comparing it with the average density value, divide independent sub-clusters or merge similar permission resources to generate an optimized configuration table for abnormal sub-clusters; S4: Based on the optimized configuration table for abnormal sub-clusters, compare the adjusted cluster permission configurations, analyze the permission sharing requirements. By matching the permission sharing rules, map the correspondence between the outbound permissions and the target sub-clusters and define the cross-cluster access rules to generate a cross-cluster permission sharing mapping list; S5: Based on the cross-cluster permission sharing mapping list, maintain the global user access control record, match the sub-cluster permission rules with the user access requests to generate a user authentication and authorization token. Extract the access log and authentication information according to the authorization token to generate a management record of multi-cluster user authentication and access operations.
[0006] The improvements of the present invention are as follows. The analysis result of the permission request trend includes the fluctuation value of the permission request frequency, the user distribution range within the request time period, and the trend change of the permission type. The list of abnormal fluctuation permission distributions includes the abnormal fluctuation value, the abnormal level, and the request time period. The cluster permission density value is specifically the ratio of the number of sub-cluster users to the number of permissions within the selected abnormal interval. The optimized configuration table for abnormal sub-clusters includes the type similarity of permission resources and the merging result of similar permission resources. The cross-cluster permission sharing mapping list includes the correspondence between the outbound permissions and the target sub-clusters and the cross-cluster access rules. The management record of multi-cluster user authentication and access operations includes the user authentication and authorization token, the user access log, and the cross-cluster access operation log table.
[0007] The improvements of the present invention are as follows. In the enterprise main cluster environment, obtain the list of registered sub-cluster users. Each sub-cluster is associated with the main cluster through a unique identifier. Collect the permission request data and extract the key information. Divide the sliding window of the key information by time period and conduct trend analysis. The specific steps for generating the analysis result of the permission request trend are as follows: S101: Based on the list of registered sub-cluster users obtained in the main cluster environment, extract the unique identifier information of each sub-cluster, associate the identifier information with the main cluster, collect the permission request data of each sub-cluster user, parse the user request content through the permission request data, and extract the key information of the request timestamp, permission type, and user distribution to generate a dataset of sub-cluster key information; S102: Based on the key information dataset of the sub-clusters, divide it into consecutive sliding time windows according to the time period, statistically analyze the frequency of permission requests in each time window, extract the user distribution range information, and comprehensively analyze the user permission usage in each time window in combination with the permission type to generate a dataset of permission request frequency and distribution; S103: Based on the dataset of permission request frequency and distribution, conduct a modeling analysis on the changing trend of the permission request frequency within a specified time period. Combine the user distribution and permission type to obtain the trend change data of the permission type, and integrate the trend change data of the permission type into the information of permission changes within the time period to generate the result of permission request trend analysis.
[0008] The improvement of the present invention is that, based on the result of the permission request trend analysis, analyze the fluctuation value of the permission request frequency and extract the fluctuation range. By calculating the abnormal fluctuation value and comparing it with the preset fluctuation threshold, mark the abnormal level and associate it with the request time period. The specific steps for generating the list of abnormal fluctuation permission distribution are as follows: S201: Based on the result of the permission request trend analysis, analyze the change data of the request frequency of each permission type in each time period one by one, classify and statistically analyze the request frequency fluctuation, extract the fluctuation range and corresponding time distribution of each permission type, and generate the statistical data of permission frequency fluctuation; S202: Based on the statistical data of permission frequency fluctuation, compare the data within the fluctuation range with the preset fluctuation threshold item by item, identify the permission types whose fluctuations exceed the fluctuation threshold range, calculate the abnormal fluctuation value of the permission types that exceed the fluctuation threshold range, and analyze the time period and user distribution influence range of the abnormal data according to the abnormal fluctuation value to generate the abnormal permission fluctuation value and influence information; S203: Based on the abnormal permission fluctuation value and influence information, associate the abnormal fluctuation value with the time period and user distribution, mark the abnormal level according to the fluctuation intensity classification, and generate the list of abnormal fluctuation permission distribution according to the fluctuation influence of each type of abnormal permission, in combination with the permission type and time distribution.
[0009] The improvement of the present invention is to associate the abnormal fluctuation value with the time period and user distribution, and use the formula: ; Calculate the abnormal level value ; Wherein, is the abnormal permission request frequency in the th time period, is the average frequency of abnormal permission requests, is the abnormal duration in the th time period, is the number of users affected in the th time period, is the total number of time periods outside the fluctuation threshold range.
[0010] The present invention is improved in that an abnormal interval associated with the abnormal level and the requested time period is obtained from the abnormal fluctuation permission distribution list, the ratio of the number of sub-cluster users to the number of permissions within the abnormal interval is used as the cluster permission density value, and after comparison with the average density value, independent sub-clusters are divided or similar permission resources are merged to generate an optimized configuration table for abnormal sub-clusters. The specific steps are as follows: S301: Based on the abnormal fluctuation permission distribution list, extract the abnormal intervals associated with the abnormal level and the requested time period, calculate the ratio of the number of sub-cluster users to the number of permissions in each abnormal interval one by one, organize the ratios into a data set, and generate abnormal interval permission density data; S302: Based on the abnormal interval permission density data, compare and analyze the cluster permission density value of each abnormal interval with the average density value of all abnormal sub-clusters, screen out the abnormal intervals with a permission density value higher than the average density value, and divide them into new independent sub-clusters in combination with the permission request frequency and user activity information within the abnormal intervals to generate interval sub-cluster division data; S303: Based on the abnormal interval permission density data, for the abnormal intervals with a permission density value lower than the average density value, calculate the similarity between the types of permission resources within the interval, merge the permission resources with a similarity higher than the permission similarity threshold, and combine with the interval sub-cluster division data to generate an optimized configuration table for abnormal sub-clusters.
[0011] The present invention is improved in that for calculating the similarity between the types of permission resources within the interval, the formula: ; Obtain the similarity value of the permission resources ; where , respectively represent the sets of the th and th types of permission resources, is the size of the intersection of the permission resource sets, is the size of the union of the permission resource sets, is used to adjust the association degree between the permission resource set and the user permission coverage set , is the size of the intersection of the permission resource set and the user permission coverage set , is used to adjust and reflect the association degree between the permission resource set and the user permission coverage set , is the permission resource set The intersection size with the user permission override set .
[0012] The improvements of the present invention are as follows: Based on the optimized configuration table of the abnormal sub-cluster, compare the adjusted cluster permission configuration, analyze the permission sharing requirements, map the corresponding relationship between permissions and target sub-clusters through matching permission sharing rules, and define cross-cluster access rules, and generate a cross-cluster permission sharing mapping list. The specific steps are as follows: S401: Based on the optimized configuration table of the abnormal sub-cluster, extract the optimized permission configuration content, compare the optimized permission configuration content with the permission control rules of the main cluster, analyze the sharing requirements of the permission configuration, determine the outbound and inbound permission ranges of each sub-cluster, and generate permission sharing requirement data; S402: Based on the permission sharing requirement data, extract the outbound and inbound permission information of each sub-cluster, match the outbound and inbound permissions with the permission sharing rules defined by the main cluster one by one, establish the corresponding relationship between the outbound permissions and the target sub-clusters according to the matching results, and generate sub-cluster outbound permission mapping data; S403: Based on the sub-cluster outbound permission mapping data, combine the shared permission configuration and corresponding relationship of the target sub-cluster, define user cross-cluster access rules, determine the user permission range according to the access rules, and generate a cross-cluster permission sharing mapping list.
[0013] The improvements of the present invention are as follows: Based on the cross-cluster permission sharing mapping list, maintain the global user access control record, match the sub-cluster permission rules with the user access request, generate a user authentication authorization token, extract the access log and authentication information according to the authorization token, and generate the management record of multi-cluster user authentication and access operations. The specific steps are as follows: S501: Based on the cross-cluster permission sharing mapping list, extract the outbound and inbound permission rules of each sub-cluster, parse each permission rule, match the parsed permission content with the user's access request data one by one, determine the request validity and mark the matching content, and generate user access permission matching result data; S502: Based on the user access permission matching result data, allocate an authorization token to the successfully matched user access request, bind the token to the user identity information, and record the valid time period, permission range, and target sub-cluster information of the token at the same time, and generate user authorization token and allocation information; S503: Based on the user authorization token and allocation information, track and record the usage of the authorization token, extract the operation log and authentication record generated during the user access process, and classify and summarize the operation log and authentication record according to time and sub-cluster, and generate the management record of multi-cluster user authentication and access operations.
[0014] A system for multi-cluster user permission management, the system includes: The user permission request analysis module extracts the unique identifier of the sub-cluster based on the list of registered sub-cluster users obtained in the main cluster environment, collects permission request data and parses the timestamp, permission type, and user distribution information. It divides the data into sliding windows by time period, counts the permission request frequency and conducts trend analysis, and generates the permission request trend analysis result. The permission fluctuation anomaly detection module extracts the request frequency fluctuation data of the permission type based on the permission request trend analysis result, calculates the fluctuation range and compares it with the preset fluctuation threshold, identifies the abnormal fluctuation value, marks the abnormal level and associates the time period, and generates the abnormal fluctuation permission distribution list. The permission resource optimization configuration module extracts the abnormal interval associated with the abnormal level and time period based on the abnormal fluctuation permission distribution list, calculates the ratio of the number of sub-cluster users to the number of permissions as the permission density value, divides the independent sub-cluster or merges the similar permission resources after comparison with the average density value, and generates the abnormal sub-cluster optimization configuration table. The cross-cluster permission sharing module compares the adjusted permission configuration with the main cluster permission control rules based on the abnormal sub-cluster optimization configuration table, analyzes the sharing requirements of the outbound and inbound permissions, maps the outbound permissions to the target sub-cluster, defines the cross-cluster access rules, and generates the cross-cluster permission sharing mapping list. The user authentication management module extracts the sub-cluster permission rules and matches the user access requests based on the cross-cluster permission sharing mapping list, allocates authorization tokens and records the time and scope, extracts the access logs and authentication information, organizes and establishes the cross-cluster access operation log table, and generates the management record of multi-cluster user authentication and access operations.
[0015] The beneficial effects brought by the technical solution provided by the embodiments of the present invention at least include: By dynamically monitoring and analyzing the fluctuations in user permission requests, permission distribution, and resource requirements of sub - clusters, the permission configuration can be optimized and adjusted more precisely. This process first analyzes key information such as the frequency, fluctuations, and user distribution of permission requests to identify potential abnormal fluctuations, thus helping enterprises accurately locate the problems of insufficient and overly concentrated permission resources. This real - time analysis and adjustment mechanism can allocate system resources more reasonably by dynamically dividing or merging sub - clusters and optimizing the permission resource configuration, avoiding resource waste and permission abuse in permission management. By defining cross - cluster permission sharing rules, the collaborative efficiency between different clusters can be improved while ensuring data security. The permission density value and sharing requirement analysis further enhance the flexibility of permission management, enabling enterprises to achieve more efficient resource integration and allocation when facing different permission requirements. This process enables the system to quickly respond to user requests, optimize resource configuration in real - time, and ensure the transparency and compliance of each operation through detailed logs and authentication information. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] To more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0017] Figure 1 It is the flowchart of the method of the present invention; Figure 2 It is the schematic diagram of the detailed process of step S1 of the present invention; Figure 3 It is the schematic diagram of the detailed process of step S2 of the present invention; Figure 4 It is the schematic diagram of the detailed process of step S3 of the present invention; Figure 5 It is the schematic diagram of the detailed process of step S4 of the present invention; Figure 6 It is the schematic diagram of the detailed process of step S5 of the present invention; Figure 7 It is the system module diagram of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0018] The following will describe the technical solutions in the present invention with reference to the accompanying drawings.
[0019] In the embodiments of the present invention, words such as "exemplarily" and "for example" are used to represent examples, illustrations or explanations. Any embodiment or design described as an "example" in the present invention should not be construed as being more preferred or having more advantages than other embodiments or designs. Rather, the use of the word "example" is intended to present concepts in a specific manner. In addition, in the embodiments of the present invention, the meaning expressed by "and / or" can be both, or either one of the two.
[0020] In the embodiments of the present invention, "image" and "picture" can sometimes be used interchangeably. It should be noted that when the difference is not emphasized, the meanings they express are the same. "(of)", "corresponding", and "corresponding" can sometimes be used interchangeably. It should be noted that when the difference is not emphasized, the meanings they express are the same.
[0021] In the embodiments of the present invention, sometimes subscripts such as W1 may be written in a non-subscript form such as W1. When the difference is not emphasized, the meanings they express are the same.
[0022] To make the technical problems to be solved, technical solutions and advantages of the present invention clearer, the following will be described in detail with reference to the accompanying drawings and specific embodiments.
[0023] The embodiments of the present invention provide a method for multi-cluster user permission management, including the following steps: S1: Obtain the list of registered sub-cluster users in the enterprise master cluster environment. Each sub-cluster is associated with the master cluster through a unique identifier. Collect permission request data and extract key information. Divide the sliding window of the key information by time period and perform trend analysis to generate a permission request trend analysis result; S2: Based on the permission request trend analysis result, analyze the fluctuation value of the permission request frequency and extract the fluctuation range. By calculating the abnormal fluctuation value and comparing it with the preset fluctuation threshold, mark the abnormal level and associate the request time period to generate an abnormal fluctuation permission distribution list; S3: Obtain the abnormal interval associated with the abnormal level and the request time period in the abnormal fluctuation permission distribution list. Use the ratio of the number of sub-cluster users to the number of permissions within the abnormal interval as the cluster permission density value. After comparing it with the average density value, divide independent sub-clusters or merge similar permission resources to generate an optimized configuration table for abnormal sub-clusters; S4: Based on the optimized configuration table for abnormal sub-clusters, compare the adjusted cluster permission configurations, analyze the permission sharing requirements. By matching the permission sharing rules, map out the corresponding relationship between the permissions and the target sub-clusters and define the cross-cluster access rules to generate a cross-cluster permission sharing mapping list; S5: Based on the cross-cluster permission sharing mapping list, maintain the global user access control record, match the sub-cluster permission rules with the user access request, generate the user authentication and authorization token, extract the access log and authentication information according to the authorization token, and generate the management record of multi-cluster user authentication and access operations; The results of the permission request trend analysis include the fluctuation value of the permission request frequency, the user distribution range within the request time period, and the trend changes of the permission types. The abnormal fluctuation permission distribution list includes the abnormal fluctuation value, the abnormal level, and the request time period. The cluster permission density value is specifically the ratio of the number of sub-cluster users to the number of permissions within the selected abnormal interval. The abnormal sub-cluster optimization configuration table includes the type similarity of the permission resources and the merging result of the same type of permission resources. The cross-cluster permission sharing mapping list includes the corresponding relationship between the outbound permissions and the target sub-clusters and the cross-cluster access rules. The management record of multi-cluster user authentication and access operations includes the user authentication and authorization token, the user access log, and the cross-cluster access operation log table.
[0024] Please refer to Figure 2 , obtain the list of registered sub-cluster users in the enterprise master cluster environment. Each sub-cluster is associated with the master cluster through a unique identifier. Collect the permission request data and extract the key information. Divide the sliding window of the key information by time period and perform trend analysis. The specific steps for generating the results of the permission request trend analysis are as follows: S101: Based on the list of registered sub-cluster users obtained in the master cluster environment, extract the unique identifier information of each sub-cluster, associate the identifier information with the master cluster, collect the permission request data of each sub-cluster user, parse the user request content through the permission request data, extract the key information of the request timestamp, permission type, and user distribution, and generate the sub-cluster key information dataset; Extract the unique identifier information of each sub-cluster in the enterprise. For example, the sub-clusters may include the financial system cluster, the sales system cluster, and the human resources system cluster. Associate the identifier information with the master cluster database through data docking technology. Use the enterprise permission management system (such as SAP GRC) to collect the permission request data of each sub-cluster user. Obtain the timestamp, permission type, and user department and role information of each permission request by parsing the permission request log. For example, the permission types include read permission, write permission, approval permission, and administrator permission. Use the distributed data processing method to count the user distribution and generate the sub-cluster key information dataset including the sub-cluster identifier information, permission request timestamp, permission type, and user distribution.
[0025] S102: Based on the key information dataset of sub - clusters, divide it into consecutive sliding time windows according to the time period. Conduct statistical analysis on the frequency of permission requests in each time window, extract the user distribution range information, summarize and analyze the user permission usage in each time window in combination with the permission type, and generate a dataset of permission request frequency and distribution; Set the period of the sliding time window according to the characteristics of the enterprise's business operation. For example, set the time window to be daily, weekly or monthly. Combining with the actual permission management requirements, count the frequency of user permission requests in each time window through permission request records, extract the user distribution range between different departments or sub - clusters within the enterprise, and analyze the user permission usage in combination with the data of the permission type. For example, the permission type can be specific to "financial statement viewing permission" in the financial system, "order management permission" in the sales system, "employee information modification permission" or "salary approval permission" in the human resources system. Analyze the request frequency and distribution of these permissions in different time windows, and finally summarize and generate a dataset of permission request frequency and distribution including the permission request frequency and the user distribution range.
[0026] S103: Based on the dataset of permission request frequency and distribution, conduct modeling analysis on the change trend of the permission request frequency within a specified time period. Combining with the user distribution and permission type, obtain the trend change data of the permission type, integrate the trend change data of the permission type into the information of permission changes within the time period, and generate the result of permission request trend analysis; Combining the enterprise's permission management requirements and business data, analyze the change trend of the permission request frequency within a specified time period. For example, monitor the change trend of different permission types in the time window. The permission types can include the new trend of the system administrator permission, the growth of the usage of the sales data writing permission, the decrease in the frequency of the human resources approval permission, etc. Display the trend change data of the permission type through data visualization means (such as PowerBI or Tableau), integrate these trend data into the information of permission changes within the time period. For example, within a certain quarter, the request frequency of the system administrator permission increased by 15%, the request frequency of the sales data writing permission increased by 30%, while the request frequency of the human resources approval permission decreased by 10%, and generate the result of permission request trend analysis.
[0027] Please refer to Figure 3 , based on the result of the permission request trend analysis, analyze the fluctuation value of the permission request frequency and extract the fluctuation range. By calculating the abnormal fluctuation value and comparing it with the preset fluctuation threshold, mark the abnormal level and associate the request time period. The specific steps to generate the list of abnormal fluctuation permission distribution are as follows: S201: Based on the results of the permission request trend analysis, analyze the request frequency change data of each permission type in each time period one by one, classify and count the request frequency fluctuations, extract the fluctuation range and corresponding time distribution of each permission type, and generate permission frequency fluctuation statistical data; Analyze the request frequency change data of permissions in each time period in the enterprise permission management system, classify and count the request fluctuations of each permission type. The permission types include the financial statement reading permission in the financial system, the order approval permission in the sales system, and the employee information modification permission in human resources. The time distribution range can be refined into working time periods (such as 9 am to 5 pm), non-working time periods (such as 6 pm to 8 am the next day), and holidays. The fluctuation range refers to the change amplitude of the permission request frequency. For example, the change range of the permission request frequency on a certain day is from 10 to 50 times. Record the time distribution and fluctuation range of these permission requests through statistical analysis tools (such as Elasticsearch and Kibana), and organize and generate permission frequency fluctuation statistical data.
[0028] S202: Based on the permission frequency fluctuation statistical data, compare the data within the fluctuation range with the preset fluctuation threshold item by item, identify the permission types whose fluctuations exceed the fluctuation threshold range, calculate the abnormal fluctuation values of the permission types that exceed the fluctuation threshold range, and analyze the time period and user distribution influence range of the abnormal data according to the abnormal fluctuation values, and generate abnormal permission fluctuation values and influence information; Identify the permission types whose fluctuations exceed the fluctuation threshold range, and calculate the abnormal fluctuation value for the permission types that exceed the threshold range according to the formula , where the calculation of the abnormal fluctuation value is as follows. In the formula, is the abnormal fluctuation value, which is used to quantify the intensity of the permission request frequency fluctuation. It is obtained by calculating through the permission frequency fluctuation statistical data, and the result is used to evaluate whether there are abnormalities in the permission usage behavior. is the request frequency of the permission type in the th time period that exceeds the threshold range. It is directly obtained from the permission request log. For example, extract the time distribution data of the permission requests from the permission management system (such as Elasticsearch). is the average request frequency of the permission type in all time periods that exceed the threshold. The permission request frequency data is obtained through the permission management system or the log analysis tool, and the summation and average value calculations are completed during the analysis process. is the number of time periods that exceed the threshold range, which is determined by comparing the permission request frequency with the fluctuation threshold. For example, the total number of time periods when the request frequency is higher than the set threshold. represents the sum of the squares of the frequency differences for all time periods that exceed the threshold range.
[0029] For example, obtain the request frequency of the permission type from the statistical data of permission frequency fluctuations. For example, if the permission type is the financial statement reading permission, the recorded request frequencies for different time periods are 250, 180, 210, 190, 230, 170, 220, 200, 240, and 185 respectively. Set the fluctuation threshold to 200. By comparing the request frequency of each time period with the threshold, identify the time periods that exceed the threshold. The frequencies that exceed the threshold are 250, 210, 230, 220, and 240, and the corresponding number of time periods is 5, that is .
[0030] Calculate the average request frequency of the permission type that exceeds the threshold: ; Calculate the sum of the squares of the differences between the frequency of each time period that exceeds the threshold and the average value: ; Calculate the abnormal fluctuation value: ; According to the example of the request frequencies for the time periods of the financial statement reading permission, the recorded frequencies are 250, 180, 210, 190, 230, 170, 220, 200, 240, and 185 respectively. The time periods can be specifically divided into two-hour intervals for each day, such as: 9:00 - 11:00 am, 11:00 - 13:00, 13:00 - 15:00 pm, 15:00 - 17:00, 17:00 - 19:00 pm, 19:00 - 21:00, and 21:00 - 23:00 at night. Among these time periods, the request frequency of 250 that exceeds the threshold corresponds to 9:00 - 11:00 am, 210 corresponds to 11:00 - 13:00, 230 corresponds to 13:00 - 15:00, 220 corresponds to 15:00 - 17:00, and 240 corresponds to 19:00 - 21:00. Combining with the abnormal fluctuation value of 200, further analysis reveals that the high-frequency requests with abnormal fluctuations are concentrated in the morning from 9:00 - 11:00 and in the afternoon from 13:00 - 15:00. These time periods are usually the concentrated operation periods for data processing by the enterprise's finance department. Analyzing the user distribution, it is found that the abnormal fluctuation permissions are mainly triggered by remote users in Area A and Area B of the finance department. The abnormal behavior involves high-frequency financial statement reading and data export operations, which are uncommon phenomena in the normal work process and may be caused by user misoperations or abnormal login activities. Based on the above analysis, generate detailed information including the abnormal permission fluctuation value of 200 and its influence scope, which clarifies that the time periods involved in the abnormal permissions are 9:00 - 11:00 am, 13:00 - 15:00, and 19:00 - 21:00, and the influence scope of the user distribution is mainly concentrated in Area A and Area B of the finance department.
[0031] S203: Based on the abnormal permission fluctuation value and impact information, associate the abnormal fluctuation value with the time period and user distribution, classify and mark the abnormal level according to the fluctuation intensity, and generate a list of abnormal fluctuation permission distributions by combining the fluctuation impact of each type of abnormal permission with the permission type and time distribution; Associate the abnormal fluctuation value with the time period and user distribution, using the formula: ; Calculate the abnormal level value ; where is the frequency of abnormal permission requests in the th time period, directly obtained from the permission request records. is the average frequency of abnormal permission requests, calculated from the frequency data exceeding the fluctuation threshold range. is the abnormal duration (in hours) of the th time period, obtained from the time period distribution data. is the number of users affected in the th time period, obtained by counting the number of user IDs involved in the permission log records. is the total number of time periods exceeding the fluctuation threshold range, obtained by comparing the permission frequency with the fluctuation threshold.
[0032] Parameter acquisition process and example If the permission type is the financial statement reading permission, the abnormal fluctuation value distribution is as follows: Request frequency: Average frequency: Time period duration: (unit: hours) Number of affected users: Total number of time periods: , calculate the relative fluctuation value of the frequency in each time period: ; Obtain the relative fluctuation value: .
[0033] Calculate the contribution value of each time period: ; The first time period: ; The second time period: ; The third time period: ; Calculate the total contribution value: ; Calculate the abnormal level: ; The calculation result is . According to the calculated abnormal level value, divide the permission fluctuation into multiple levels according to the abnormal level, for example: Low abnormality , Medium anomaly , High anomaly . Perform a correlation analysis on the anomaly level values of each permission type with their corresponding time distributions and user influence scopes, and screen out the permission types with significant influence. For example, mark the permission type with an anomaly level of 2.13 as a medium anomaly permission, and identify the specific permission types associated with it, such as the financial statement reading permission. Combining with the permission request logs, determine the high-frequency request time periods of the abnormal permissions, such as 9:00 - 11:00 am and 1:00 - 3:00 pm. Count the number of users and their affiliated departments affected by the abnormal permission fluctuations during the high-frequency request time periods. For example, remote users in the finance department are concentratedly affected, and integrate to generate a list of abnormal fluctuation permission distributions.
[0034] Please refer to Figure 4 , obtain the anomaly intervals associated with the anomaly levels and request time periods in the list of abnormal fluctuation permission distributions, use the ratio of the number of sub-cluster users to the number of permissions within the anomaly intervals as the cluster permission density value, and after comparing with the average density value, divide independent sub-clusters or merge similar permission resources. The specific steps to generate the optimized configuration table of abnormal sub-clusters are as follows: S301: Based on the list of abnormal fluctuation permission distributions, extract the anomaly intervals associated with the anomaly levels and request time periods, calculate the ratio of the number of sub-cluster users to the number of permissions within each anomaly interval one by one, organize the ratios into a data set, and generate anomaly interval permission density data; Extract the abnormal intervals associated with the abnormal levels and the requested time periods, and calculate the ratio of the number of sub-cluster users to the number of permissions in each abnormal interval one by one as the cluster permission density value. For example, the abnormal interval is divided into 9:00 to 11:00 in the morning and 13:00 to 15:00 in the afternoon. In the abnormal interval from 9:00 to 11:00 in the morning, the number of active users recorded in the finance sub-cluster is 150. Extract the types of permissions involved in the finance sub-cluster during this time period through the permission management system, a total of 20 types. The cluster permission density value is calculated by the ratio of the number of users to the number of permissions, that is, the permission density value of the finance sub-cluster from 9:00 to 11:00 in the morning is 150 ÷ 20 = 7.5 (users / permissions). Similarly, for the abnormal interval from 13:00 to 15:00 in the afternoon, the number of active users recorded in the sales sub-cluster is 200. Extract the types of permissions involved in the sales sub-cluster during this time period through the permission management system, a total of 25 types, and the cluster permission density value is 200 ÷ 25 = 8.0 (users / permissions). Organize the number of users, the number of permissions, and the calculated permission density values of the sub-clusters in all abnormal intervals. For example, the density of the finance sub-cluster from 9:00 to 11:00 in the morning is 7.5, and the density of the sales sub-cluster from 13:00 to 15:00 in the afternoon is 8.0. The organized data set will provide a clear basis for subsequent permission distribution and sub-cluster division. Among them, users / permissions represents the average number of users corresponding to each permission type within a specific time period. Specifically, the value of users / permissions is a ratio, indicating the average usage density of each permission type in a sub-cluster. This indicator is obtained by calculating the ratio of the number of active users in a certain time period to the number of permissions involved.
[0035] S302: Based on the permission density data of the abnormal intervals, compare and analyze the cluster permission density value of each abnormal interval with the average density value of all abnormal sub-clusters, screen the abnormal intervals with permission density values higher than the average density value, and combine the permission request frequency and user activity information within the abnormal intervals to divide them into new independent sub-clusters, generating interval sub-cluster division data; Compare the cluster permission density value of each abnormal interval with the average density value of all abnormal sub - clusters. For example, set the average density value to 7.0 (users / permissions). Screen the abnormal intervals with permission density values higher than the average density value. For example, the permission densities from 9:00 am to 11:00 am and from 13:00 pm to 15:00 pm are 7.5 and 8.0 respectively, both higher than the average value. Combining with the permission request frequency data, it is found that the permission request frequency from 9:00 am to 11:00 am is 300 times, the user activity is relatively high, and the active users are mainly concentrated in the finance department. The permission requests are concentrated on financial statement reading and data export; the permission request frequency from 13:00 pm to 15:00 pm is 400 times, the user activity is mainly concentrated in the sales department, and the permission requests are concentrated on order approval and data modification. According to the analysis results, divide the abnormal intervals with permission density higher than the average value into new independent sub - clusters. For example, define the morning abnormal interval as the "finance high - density sub - cluster" and the afternoon abnormal interval as the "sales high - density sub - cluster", generate interval sub - cluster division data, and provide a basis for the permission management of sub - clusters.
[0036] S303: Based on the abnormal interval permission density data, for the abnormal intervals with permission density values lower than the average density value, calculate the similarity between the permission resource types within the interval, merge the permission resources with similarity higher than the permission similarity threshold, and combine with the interval sub - cluster division data to generate an optimized configuration table for abnormal sub - clusters; For calculating the similarity between the permission resource types within the interval, use the formula: ; Obtain the similarity value of the permission resources ; Among them, is used to quantify the degree of association between two types of permission resources, improve the calculation accuracy by combining the coverage rate of user permissions, and the result value ranges from 0 to 1, indicating from no association to complete overlap. 、 respectively represent the sets of the nd and th types of permission resources. For example, the permission resources include financial statement reading permission and data export permission, which are obtained by extracting permission distribution data through the permission management system. is the size of the intersection of the permission resource sets, reflecting the number of overlapping permissions between two types of permission resources. For example, for the permission sets and , the intersection is , so the size of the intersection is 1. is the size of the union of the permission resource sets, reflecting the total amount of all permissions of two types of permission resources. For example, for the permission sets and , the union is , so the size of the union is 3, for adjusting the collection of permission resources and the user permission coverage set The degree of association is determined through experiments or historical data analysis. For example, it can be analyzed through the access frequency recorded in the user permission request log. is the collection of permission resources and the user permission coverage set The size of the intersection, indicating the part of the permission set covered by the user. For example, the user permission coverage set , the permission set , and the intersection is , so the size of the intersection is 1. for adjusting to reflect the collection of permission resources and the user permission coverage set The degree of association is determined through statistical analysis of historical permission data. For example, information can be extracted through the frequency distribution recorded in the user permission log. is the collection of permission resources and the user permission coverage set The size of the intersection, indicating the part of the permission set covered by the user. For example, the user permission coverage set , the permission set , and the intersection is , so the size of the intersection is 1. The value range is non - negative real numbers, that is , usually set as in the interval to ensure the stability and interpretability of the calculation. The value range is the same as , which is , and is often set within the interval of . and The setting method is set through historical data analysis: extract the historical intersection data between the collection of permission resources and and the user permission coverage set . For example, count the frequency of user - requested permission resources, calculate the proportion of permission resources actually used by the user. For example and , and set the initial values of and according to the proportion. It is also possible to conduct a weight assessment based on the sensitivity and importance of permission resources in the business scenario. For example, the financial permission resources may have a higher impact on the enterprise than ordinary permission resources. For important permission sets and higher association strengths are assigned respectively. For example, set , , to highlight the priority consideration for more important permission resources.
[0037] Extract the set of permission resource types from the abnormal interval permission density data. For example, the set of permission resources from 9:00 to 11:00 in the morning is , and the set of permission resources from 13:00 to 15:00 in the afternoon is , and the user permission coverage set is , and the acquisition process is as follows: The size of the intersection of the permission resource sets: By counting the common permission types in the permission resource sets and , the intersection is obtained as , so the size of the intersection is 1.
[0038] The size of the union of the permission resource sets: Count all the permission types of the permission resource sets and , and the union is obtained as , so the size of the union is 3.
[0039] The intersection size of the permission resource set and the user permission coverage set : By analyzing the user permission coverage set and the permission resource set , the intersection is obtained as , and the intersection size is 1.
[0040] The intersection size of the permission resource set and the user permission coverage set : By analyzing the user permission coverage set and the permission resource set , the intersection is obtained as , and the intersection size is 1.
[0041] Set the improvement parameter , , set based on the experimental data of historical analysis.
[0042] Calculate the improvement similarity: ; When the permission resource similarity is higher than the permission similarity threshold (for example, set to 0.8), merge the relevant permission resources to optimize the permission configuration. Combining the calculation results , the similarity does not reach the threshold, so there is no need to merge permission resources. However, if the calculation results of some permission resources are higher than 0.8, for example, the improved similarity of the financial statement reading permission and the data export permission is 0.85, the following steps can be taken to merge the permission resources and generate an optimized configuration table for abnormal sub-clusters by combining interval sub-cluster data partitioning: Classify the permission resources with similarity higher than the threshold into the same category. For example, merge the financial statement reading permission and the data export permission into "financial data management permission" to reduce the redundancy of permission items. Adjust the permission resource configuration involved in the sub-cluster to ensure that the newly merged permission resources can cover the usage scenarios of the original permissions. For example, in the finance sub-cluster, set "financial data management permission" as the main permission type for users and adjust the usage conditions and allocation rules of the permissions. Re-distribute the user distribution according to the result of the permission merge to ensure that the operations of users under the new permission resources are not affected. For example, uniformly adjust the users who originally had the financial statement reading permission and the data export permission to the user group with "financial data management permission" and confirm that the operation records of the users conform to the permission coverage. Combine the interval sub-cluster data partitioning, associate the result of the permission resource merge with the time period and user distribution information of the abnormal sub-cluster, and generate an optimized configuration table. For example, in the finance sub-cluster from 9:00 to 11:00 in the morning, the permission type is updated to "financial data management permission", covering 150 users, and the operation frequency is 300 times; in the sales sub-cluster from 13:00 to 15:00 in the afternoon, the permission resources are not merged, and the original permission type is retained.
[0043] Please refer to Figure 5 , based on the optimized configuration table of the abnormal sub-cluster, compare the adjusted cluster permission configuration, analyze the permission sharing requirements, map the correspondence between the outgoing permissions and the target sub-clusters by matching the permission sharing rules, and define the cross-cluster access rules. The specific steps to generate the cross-cluster permission sharing mapping list are as follows: S401: Based on the optimized configuration table of the abnormal sub-cluster, extract the optimized permission configuration content, compare the optimized permission configuration content with the permission control rules of the main cluster, analyze the sharing requirements of the permission configuration, determine the outgoing permission and incoming permission ranges of each sub-cluster, and generate permission sharing requirement data; Extract the optimized permission configuration content. For example, the optimized configuration content of the finance sub-cluster includes "financial data management permissions", and the optimized configuration content of the sales sub-cluster includes "order processing permissions". Compare these optimized permission configuration contents with the permission control rules of the main cluster, analyze the permission sharing requirements of each sub-cluster, and determine the outbound and inbound permission scopes of each sub-cluster. For example, the outbound permissions of the finance sub-cluster are "financial data viewing" and "data export", and the inbound permissions are "order status query"; the outbound permissions of the sales sub-cluster are "order status update" and "data modification", and the inbound permissions are "financial approval record query". By analyzing the sharing requirements, generate permission sharing requirement data to provide a basis for subsequent permission mapping between sub-clusters.
[0044] S402: Based on the permission sharing requirement data, extract the outbound and inbound permission information of each sub-cluster, match the outbound and inbound permissions with the permission sharing rules defined in the main cluster one by one, and establish the corresponding relationship between the outbound permissions and the target sub-clusters according to the matching results to generate sub-cluster outbound permission mapping data; Extract the outbound and inbound permission information of each sub-cluster. For example, the outbound permissions of the finance sub-cluster are "financial data viewing" and "data export", and the inbound permissions are "order status query"; the outbound permissions of the sales sub-cluster are "order status update" and "data modification", and the inbound permissions are "financial approval record query". Match these outbound and inbound permissions with the permission sharing rules defined in the main cluster one by one. For example, the permission sharing rules of the main cluster stipulate that the "financial data viewing" outbound permission of the finance sub-cluster can match the "financial approval record query" inbound permission of the sales sub-cluster, and the "order status update" outbound permission of the sales sub-cluster can match the "order status query" inbound permission of the finance sub-cluster. Establish the corresponding relationship between the outbound permissions and the target sub-clusters according to the matching results to generate sub-cluster outbound permission mapping data. For example, a two-way mapping of outbound and inbound permissions is formed between the finance sub-cluster and the sales sub-cluster.
[0045] S403: Based on the sub-cluster outbound permission mapping data, combine the shared permission configuration and corresponding relationship of the target sub-cluster, define the user cross-cluster access rules, determine the user permission scope according to the access rules, and generate a cross-cluster permission sharing mapping list; Combine the shared permission configurations and corresponding relationships of target sub - clusters. For example, the shared permission configuration of the finance sub - cluster is "financial data viewing" and "data export", and the shared permission configuration of the sales sub - cluster is "order status update" and "data modification". Define cross - cluster user access rules. For example, the access rules stipulate that users in the finance sub - cluster can cross - cluster access the "order status update" permission of the sales sub - cluster, but need to meet the corresponding permission verification conditions. Users in the sales sub - cluster can cross - cluster access the "financial data viewing" permission of the finance sub - cluster, but can only view financial data matching the order. Determine the user permission scope according to the access rules. For example, the user permission scope of the finance sub - cluster includes the status update permission related to orders, and the user permission scope of the sales sub - cluster includes the financial data viewing permission matching the order. Finally, generate a cross - cluster permission sharing mapping list.
[0046] Please refer to Figure 6 , based on the cross - cluster permission sharing mapping list, the specific steps for maintaining the global user access control record, matching the sub - cluster permission rules with the user access request, generating the user authentication authorization token, extracting the access log and authentication information according to the authorization token, and generating the management record of multi - cluster user authentication and access operations are as follows: S501: Based on the cross - cluster permission sharing mapping list, extract the outbound and inbound permission rules of each sub - cluster, parse each permission rule, match the parsed permission content with the user's access request data one by one, determine the validity of the request and mark the matching content, and generate user access permission matching result data; Extract the outbound and inbound permission rules of each sub - cluster. For example, the outbound permission rules of the finance sub - cluster are "financial data viewing" and "data export", and the inbound permission rules of the sales sub - cluster are "order status query" and "approval record access". Parse each permission rule to clarify the usage conditions of the permission. For example, the "financial data viewing" permission is limited to querying the financial records of specific orders, and the "order status query" permission is limited to viewing the current transaction status. Match the parsed permission content with the user's access request data one by one. For example, the user requests to query the financial data of order 1001, which matches the "financial data viewing" rule of the finance sub - cluster. Confirm the validity of the user request through the match. For example, if the request contains content outside the permission scope, it is regarded as invalid. Mark the valid matching content. For example, the request to view the financial data of order 1001 is successfully matched and recorded as a valid request. Finally, generate user access permission matching result data, which includes the permission type of the user request, the matching status, and the sub - cluster information of the match.
[0047] S502: Based on the user access permission matching result data, allocate an authorization token to the successfully matched user access request, bind the token to the user identity information, and at the same time record the valid time period, permission scope, and target sub-cluster information of the token to generate the user authorization token and allocation information; Allocate an authorization token to the successfully matched user access request. For example, if the user's request to view the financial data of order 1001 is successfully matched, an authorization token is generated to allow the user to access. Bind the token to the user identity information. For example, the user ID is U123 and the bound token is Token-001. Record the valid time period of the token. For example, the valid time is from 9:00 to 11:00 on January 15, 2025, the permission scope is "viewing the financial data of order 1001", and the target sub-cluster is the finance sub-cluster. By recording the user identity, permission scope, and valid time period, the security and timeliness of token use are ensured. Finally, generate the user authorization token and allocation information, including the token ID, user identity, permission scope, and target sub-cluster.
[0048] S503: Based on the user authorization token and allocation information, track and record the usage of the authorization token, extract the operation logs and authentication records generated during the user access process, classify and summarize the operation logs and authentication records by time and sub-cluster, and generate the management records of multi-cluster user authentication and access operations; Track and record the usage of the authorization token. For example, monitor the usage status of the token in real time through operation logs and authentication records. Extract the operation logs generated during the user access process. For example, record the detailed operation time and operation content of user ID U123 using Token-001 to access the financial data of order 1001. Synchronize the authentication records. For example, verify the identity binding and validity status of the token to ensure that the token is only used within the preset valid time period. Classify and summarize the operation logs and authentication records by time and sub-cluster. For example, classify and summarize the user operation logs and authentication records of the finance sub-cluster, including access time, access content, and authentication results. Finally, generate the management records of multi-cluster user authentication and access operations to provide support for the security review of permission usage and permission optimization in a multi-cluster environment.
[0049] Please refer to Figure 7 , a system based on multi-cluster user permission management, the system includes: The user permission request analysis module extracts the unique identifier of the sub-cluster based on the list of registered sub-cluster users obtained in the main cluster environment, collects permission request data and parses the timestamp, permission type, and user distribution information, divides the data into sliding windows according to the time period, counts the permission request frequency and conducts trend analysis, and generates the permission request trend analysis result; Based on the analysis result of the permission request trend, the permission fluctuation anomaly detection module extracts the request frequency fluctuation data of the permission type, calculates the fluctuation range, compares it with the preset fluctuation threshold, identifies the abnormal fluctuation value, marks the abnormal level, associates the time period, and generates a list of abnormal fluctuation permission distributions; Based on the list of abnormal fluctuation permission distributions, the permission resource optimization configuration module extracts the abnormal intervals associated with the abnormal level and the time period, calculates the ratio of the number of sub-cluster users to the number of permissions as the permission density value, divides independent sub-clusters or merges similar permission resources after comparison with the average density value, and generates an optimized configuration table for abnormal sub-clusters; Based on the optimized configuration table for abnormal sub-clusters, the cross-cluster permission sharing module compares the adjusted permission configuration with the main cluster permission control rules, analyzes the sharing requirements for outbound and inbound permissions, maps the outbound permissions to the target sub-cluster, defines cross-cluster access rules, and generates a cross-cluster permission sharing mapping list; Based on the cross-cluster permission sharing mapping list, the user authentication management module extracts the sub-cluster permission rules, matches the user access requests, allocates authorization tokens, records the time and scope, extracts the access logs and authentication information, organizes and establishes a cross-cluster access operation log table, and generates a management record for multi-cluster user authentication and access operations.
[0050] It should be understood that the term "and / or" in this article is merely a description of the association relationship between associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. Here, A and B can be singular or plural. In addition, the character " / " in this article generally represents an "or" relationship between the associated objects before and after, but it may also represent an "and / or" relationship, which can be specifically understood by referring to the context.
[0051] In the present invention, "at least one" means one or more, and "multiple" means two or more. "At least one of the following items (pieces)" or its similar expressions refer to any combination of these items, including any combination of single item (piece) or plural items (pieces). For example, at least one of a, b, or c can represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, and c can be single or multiple.
[0052] It should be understood that in various embodiments of the present invention, the magnitude of the sequence numbers of the above processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present invention.
[0053] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in connection with the embodiments disclosed herein can be implemented in electronic hardware, or in a combination of computer software and electronic hardware. Whether these functions are executed in hardware or software depends on the specific application and design constraints of the technical solution. Skilled artisans may use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of the present invention.
[0054] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the devices, apparatuses, and units described above can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein.
[0055] In several embodiments provided by the present invention, it should be understood that the disclosed devices, apparatuses, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces, and the indirect coupling or communication connection of the devices or units can be in electrical, mechanical, or other forms.
[0056] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place, or can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0057] In addition, the functional units in each embodiment of the present invention can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit.
[0058] When the above-mentioned functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art or a part of this technical solution can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes: various media that can store program codes such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs.
[0059] As described above, the above are only specific implementation manners of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of changes or substitutions, which should all be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.
Claims
1. A method for multi-cluster user rights management, characterized in that: The following steps are involved: S1: Obtain a list of registered sub-cluster users in the enterprise main cluster environment. Associate each sub-cluster with the main cluster through a unique identifier. Collect permission request data and extract key information. Divide the key information into sliding windows according to time periods and perform trend analysis to generate permission request trend analysis results. S2: Based on the permission request trend analysis result, analyze the permission request frequency fluctuation value and extract the fluctuation range, calculate the abnormal fluctuation value and compare it with the preset fluctuation threshold, mark the abnormal level and associate the request time period, and generate an abnormal fluctuation permission distribution list; S3: Obtain an abnormal interval associated with an abnormal level and a request time period in the abnormal fluctuation permission distribution list, take the ratio of the number of sub-cluster users to the number of permissions in the abnormal interval as the cluster permission density value, compare it with the average density value, and then divide it into independent sub-clusters or merge similar permission resources to generate an abnormal sub-cluster optimization configuration table; S4: Based on the abnormal sub-cluster optimization configuration table, compare the adjusted cluster permission configuration, analyze the permission sharing requirements, map the corresponding relationship between the outgoing permissions and the target sub-cluster by matching the permission sharing rules, define the cross-cluster access rules, and generate a cross-cluster permission sharing mapping list; S5: Based on the cross-cluster permission sharing mapping list, maintain global user access control records, match sub-cluster permission rules with user access requests, generate user authentication authorization tokens, extract access logs and authentication information based on the authorization tokens, and generate management records of multi-cluster user authentication and access operations.
2. The method for multi-cluster user rights management according to claim 1, characterized in that: The permission request trend analysis result includes the fluctuation value of the permission request frequency, the user distribution range within the request time period, and the trend change of the permission type. The abnormal fluctuation permission distribution list includes the abnormal fluctuation value, the abnormal level, and the request time period. The cluster permission density value is specifically the ratio of the number of sub-cluster users to the number of permissions within the selected abnormal interval. The abnormal sub-cluster optimization configuration table includes the type similarity of permission resources and the merging result of similar permission resources. The cross-cluster permission sharing mapping list includes the correspondence between the outgoing permission and the target sub-cluster, and the cross-cluster access rules. The management records of multi-cluster user authentication and access operations include user authentication authorization tokens, user access logs, and cross-cluster access operation log tables.
3. The method for multi-cluster user rights management according to claim 1, characterized in that: Obtain a list of registered sub-cluster users in the enterprise main cluster environment. Associate each sub-cluster with the main cluster through a unique identifier. Collect permission request data and extract key information. Divide the key information into sliding windows according to time periods and perform trend analysis. The specific steps for generating permission request trend analysis results are as follows: S101: Based on the list of registered sub-cluster users obtained in the main cluster environment, extract the unique identification information of each sub-cluster, associate the identification information with the main cluster, collect the permission request data of each sub-cluster user, parse the user request content through the permission request data, extract the request timestamp, permission type and key information of user distribution, and generate a sub-cluster key information data set; S102: Based on the sub-cluster key information data set, the data is divided into continuous sliding time windows according to the time period, and the frequency of permission requests in each time window is statistically analyzed, and user distribution range information is extracted. The user permission usage in each time window is summarized and analyzed in combination with the permission type, and a permission request frequency and distribution data set is generated; S103: Based on the permission request frequency and distribution data set, model and analyze the permission request frequency change trend within a specified time period, combine user distribution and permission type, obtain the permission type trend change data, integrate the permission type trend change data into the permission change information within the time period, and generate the permission request trend analysis result.
4. The method for multi-cluster user rights management according to claim 1, characterized in that: Based on the permission request trend analysis results, the permission request frequency fluctuation value is analyzed and the fluctuation range is extracted. By calculating the abnormal fluctuation value and comparing it with the preset fluctuation threshold, marking the abnormal level and associating the request time period, the specific steps of generating the abnormal fluctuation permission distribution list are as follows: S201: Based on the permission request trend analysis result, analyze the request frequency change data of each permission type in each time period one by one, classify and count the request frequency fluctuations, extract the fluctuation range and corresponding time distribution of each permission type, and generate permission frequency fluctuation statistics; S202: Based on the authority frequency fluctuation statistical data, the data within the fluctuation range is compared with the preset fluctuation threshold one by one, the authority type whose fluctuation exceeds the fluctuation threshold range is identified, the abnormal fluctuation value of the authority type exceeding the fluctuation threshold range is calculated, and the time period of the abnormal data and the user distribution impact range are analyzed according to the abnormal fluctuation value, and the abnormal authority fluctuation value and impact information are generated; S203: Based on the abnormal authority fluctuation value and impact information, the abnormal fluctuation value is associated with the time period and user distribution, and the abnormal level is marked according to the fluctuation intensity classification. According to the fluctuation impact of each type of abnormal authority, combined with the authority type and time distribution, an abnormal fluctuation authority distribution list is generated.
5. The method for multi-cluster user rights management according to claim 4, characterized in that: Associate the abnormal fluctuation value with the time period and user distribution using the formula: ; Calculate the anomaly level value ; in, It is The frequency of abnormal permission requests in a time period, is the average frequency of abnormal permission requests, It is The duration of the abnormality in the time period, It is The number of users affected in each time period, is the total number of time periods outside the volatility threshold range.
6. The method for multi-cluster user rights management according to claim 1, characterized in that: The specific steps of obtaining the abnormal interval associated with the abnormal level and the requested time period in the abnormal fluctuation permission distribution list, taking the ratio of the number of sub-cluster users to the number of permissions in the abnormal interval as the cluster permission density value, and dividing independent sub-clusters or merging similar permission resources after comparing with the average density value, and generating the abnormal sub-cluster optimization configuration table are as follows: S301: Based on the abnormal fluctuation permission distribution list, extract the abnormal intervals associated with the abnormal level and the request time period, calculate the ratio of the number of sub-cluster users to the number of permissions in each abnormal interval one by one, organize the ratios into a data set, and generate abnormal interval permission density data; S302: Based on the abnormal interval authority density data, compare and analyze the cluster authority density value of each abnormal interval with the average density value of all abnormal subclusters, select abnormal intervals with authority density values higher than the average density value, and divide them into new independent subclusters based on the authority request frequency and user activity information in the abnormal intervals to generate interval subcluster division data; S303: Based on the abnormal interval permission density data, for abnormal intervals where the permission density value is lower than the average density value, calculate the similarity between the permission resource types in the interval, merge the permission resources whose similarity is higher than the permission similarity threshold, and generate an abnormal sub-cluster optimization configuration table in combination with the interval sub-cluster division data.
7. The method for multi-cluster user rights management according to claim 6, characterized in that: To calculate the similarity between permission resource types within a range, the formula is used: ; Get the similarity value of the permission resource ; in, , Respectively represent Class and A collection of class permission resources. is the intersection size of the permission resource collection, is the union size of the permission resource collection, Used to adjust the permission resource collection Override collection with user permissions The degree of correlation, Is a collection of permission resources Override collection with user permissions The size of the intersection, Used to adjust the resource collection that reflects permissions Override collection with user permissions The degree of correlation, Is a collection of permission resources Override collection with user permissions The intersection size.
8. The method for multi-cluster user rights management according to claim 1, characterized in that: Based on the abnormal sub-cluster optimization configuration table, the adjusted cluster permission configuration is compared, the permission sharing requirements are analyzed, the corresponding relationship between the outgoing permissions and the target sub-cluster is mapped by matching the permission sharing rules and the cross-cluster access rules are defined. The specific steps for generating the cross-cluster permission sharing mapping list are as follows: S401: extracting optimized permission configuration content based on the abnormal sub-cluster optimization configuration table, comparing the optimized permission configuration content with the permission control rules of the main cluster, analyzing the sharing requirements of the permission configuration, determining the outbound permission and inbound permission range of each sub-cluster, and generating permission sharing requirement data; S402: extracting outbound permission and inbound permission information of each sub-cluster based on the permission sharing requirement data, matching the outbound permission and inbound permission with the permission sharing rules defined by the main cluster one by one, establishing a corresponding relationship between the outbound permission and the target sub-cluster according to the matching result, and generating sub-cluster outbound permission mapping data; S403: Based on the sub-cluster outbound permission mapping data, combined with the shared permission configuration and corresponding relationship of the target sub-cluster, define user cross-cluster access rules, determine the user permission range according to the access rules, and generate a cross-cluster permission sharing mapping list.
9. The method for multi-cluster user rights management according to claim 1, characterized in that: Based on the cross-cluster permission sharing mapping list, maintaining global user access control records, matching sub-cluster permission rules with user access requests, generating user authentication authorization tokens, extracting access logs and authentication information based on the authorization tokens, and generating management records of multi-cluster user authentication and access operations are as follows: S501: Based on the cross-cluster permission sharing mapping list, extract the outbound permission and inbound permission rules of each sub-cluster, parse each permission rule, match the parsed permission content with the user's access request data one by one, determine the request validity and mark the matching content, and generate user access permission matching result data; S502: Based on the user access right matching result data, assign an authorization token to the successfully matched user access request, bind the token to the user identity information, and record the token's valid time period, permission scope, and target subcluster information to generate a user authorization token and assignment information; S503: Based on the user authorization token and allocation information, the usage of the authorization token is tracked and recorded, the operation logs and authentication records generated during the user access process are extracted, the operation logs and authentication records are classified and summarized according to time and sub-cluster, and management records of multi-cluster user authentication and access operations are generated.
10. A system based on multi-cluster user rights management, characterized in that: According to any one of claims 1 to 9, the method for multi-cluster user rights management is implemented, and the system comprises: The user permission request analysis module extracts the unique identifier of the sub-cluster based on the registered sub-cluster user list obtained in the main cluster environment, collects permission request data and parses the timestamp, permission type and user distribution information, divides the data into sliding windows according to time periods, counts the frequency of permission requests and performs trend analysis, and generates permission request trend analysis results; The permission fluctuation anomaly detection module extracts the request frequency fluctuation data of the permission type based on the permission request trend analysis result, calculates the fluctuation range and compares it with the preset fluctuation threshold, identifies the abnormal fluctuation value, marks the abnormal level and associates the time period, and generates the abnormal fluctuation permission distribution list; The authority resource optimization configuration module extracts the abnormal interval associated with the abnormal level and time period based on the abnormal fluctuation authority distribution list, calculates the ratio of the number of sub-cluster users to the number of authorities as the authority density value, divides independent sub-clusters or merges similar authority resources after comparing with the average density value, and generates an abnormal sub-cluster optimization configuration table; The cross-cluster permission sharing module compares the adjusted permission configuration with the permission control rules of the main cluster based on the abnormal sub-cluster optimization configuration table, analyzes the sharing requirements of outbound permissions and inbound permissions, maps the outbound permissions to the target sub-cluster, defines cross-cluster access rules, and generates a cross-cluster permission sharing mapping list; Based on the cross-cluster permission sharing mapping list, the user authentication management module extracts sub-cluster permission rules and matches user access requests, allocates authorization tokens and records time and scope, extracts access logs and authentication information, organizes and establishes a cross-cluster access operation log table, and generates management records of multi-cluster user authentication and access operations.
Citation Information
Cited By
Enterprise data information collection authority management method
CN120705232A
A method for managing the collection of enterprise data information permissions
CN120705232B