Label management-based large-scale government affair system authority distribution method and system

By adopting a tag-based management method in large government affairs systems, the automatic allocation and adjustment of permissions is solved, and the problems of low efficiency of permission allocation and high internal control risks in the existing technology are solved, and more efficient and secure permission management is achieved.

CN120046166APending Publication Date: 2025-05-27AISINO CORPORATION
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411928222.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-25
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

The existing technology cannot effectively solve the problem of automatic allocation of permissions in large government systems, resulting in low efficiency of permission allocation and high internal control risks.

Method used

Through a tag management method, personnel attribute tags and business attribute tags are established, and roles are automatically assigned according to preset tag allocation rules, and permissions are dynamically adjusted. When personnel or business attribute tags are changed, the corresponding roles and permissions are automatically adjusted.

Benefits of technology

It improves the efficiency of system permission allocation, reduces manual management risks, reduces permission configuration errors, and enhances system security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120046166A_ABST
    Figure CN120046166A_ABST
Patent Text Reader

Abstract

The invention discloses a large-scale government affair system authority distribution method and system based on label management, and the method comprises the steps: building a personnel attribute label based on personnel attribute information; establishing a service attribute tag based on the service attribute information; on the basis of a preset label distribution rule, roles are automatically distributed to the corresponding personnel attribute labels and the corresponding service attribute labels; when the personnel attribute tag or the business attribute tag is changed, adjusting a role corresponding to the changed personnel attribute tag or business attribute tag; and initiating access to the system based on the access authority obtained by the distributed role. According to the method and the system, the personnel with which the roles can be granted are managed through the rule, the personnel with the roles which can be granted are dynamically calculated according to the tags owned by the personnel and the role applicable tag rule, and automatic authorization is performed, so that the authority distribution efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information technology application technology, and more specifically, to a method and system for allocating permissions in a large-scale government affairs system based on tag management. Background Art

[0002] Prior art 1 (application number: CN201811644585.5) provides a method and system for completing the registration of information of Internet users in unmanned Internet cafes and the verification of their legal age through self-service terminal equipment, cameras, and face recognition technology. Prior art 1 uses a device to read the second-generation resident ID card information of Internet users to determine whether the Internet users meet the legal age requirements of the law, and uses face recognition technology to ensure the consistency between Internet users and registered users, solving the problem of Internet cafes verifying the legal age of Internet users in unmanned environments, as well as the problem of Internet cafes registering and submitting Internet users' information.

[0003] Prior art 2 (application number CN200710188244.7) provides a method for automatically allocating authority resources according to positions. When an employee logs into the system, the current position of the employee is first determined, and the authority resources corresponding to the position are determined from the position authority table. The authority resources in the position authority table are granted to the employee, and the employee obtains the corresponding system operation authority. When a system user changes his position and the corresponding system authority also needs to change, the new authority resource can be automatically granted to the user without the need to modify the authority again. Therefore, the amount of data processing during authorization is reduced, efficiency is improved, and the error rate during data processing is reduced, reducing the daily maintenance cost of the system.

[0004] Prior art 1 automatically determines whether a person has Internet access rights in an Internet cafe based on his / her age after real-name authentication; prior art 2 automatically obtains the rights of the logged-in person based on the person's position according to the mapping relationship between personnel and positions, and the mapping relationship between positions and rights. Both of the above methods cannot solve the problem of automatic allocation of rights in large-scale government systems with complex businesses.

[0005] Therefore, a technology is needed to solve the permission allocation problem of large-scale government systems based on tag management. Summary of the invention

[0006] The technical solution of the present invention provides a method and system for allocating permissions for a large-scale government affairs system based on tag management, so as to solve the problem of how to allocate permissions for a large-scale government affairs system based on tag management.

[0007] In order to solve the above problems, the present invention provides a method for allocating permissions in a large-scale government affairs system based on tag management, the method comprising:

[0008] Based on personnel attribute information, establish personnel attribute labels; based on business attribute information, establish business attribute labels;

[0009] Based on the preset label assignment rules, the roles are automatically assigned to the corresponding personnel attribute labels and business attribute labels;

[0010] When the personnel attribute label or the business attribute label changes, adjusting the corresponding role of the changed personnel attribute label or the business attribute label;

[0011] Initiate access to the system based on the access rights obtained by the assigned role.

[0012] Preferably, the personnel attribute information includes: gender, age, political status, position, and rank;

[0013] The personnel attribute information is calculated and the personnel attribute label is determined by obtaining the calculation result.

[0014] Preferably, the label allocation rule includes:

[0015] The personnel attribute labels and the business attribute labels that match the roles are respectively set.

[0016] Preferably, when the personnel attribute label or the business attribute label changes, adjusting the corresponding role of the changed personnel attribute label or the business attribute label includes:

[0017] When the personnel attribute label or the business attribute label is changed and the assigned role does not conform to the label assignment rule, the assigned role of the personnel attribute label or the business attribute label is revoked;

[0018] When the personnel attribute tag or the business attribute tag is changed, a new role is assigned to the personnel attribute tag or the business attribute tag.

[0019] Preferably, the method further comprises: adjusting the roles assigned to the personnel attribute tags and the business attribute tags based on a customized role assignment method.

[0020] According to another aspect of the present invention, the present invention provides a system for allocating permissions in a large-scale government affairs system based on tag management, the system comprising:

[0021] An establishing unit, used to establish personnel attribute labels based on personnel attribute information; and to establish business attribute labels based on business attribute information;

[0022] An allocating unit, configured to automatically allocate roles to corresponding personnel attribute tags and business attribute tags based on a preset tag allocation rule;

[0023] An adjusting unit, configured to adjust a corresponding role of the changed personnel attribute label or the service attribute label when the personnel attribute label or the service attribute label changes;

[0024] The execution unit is used to initiate access to the system based on the access rights obtained by the assigned role.

[0025] Preferably, the personnel attribute information includes: gender, age, political status, position, and rank;

[0026] The establishing unit is further configured to calculate the personnel attribute information and determine the personnel attribute label through the obtained calculation result.

[0027] Preferably, the label allocation rule includes:

[0028] The personnel attribute labels and the business attribute labels that match the roles are respectively set.

[0029] Preferably, the adjustment unit is used to adjust the corresponding role of the changed personnel attribute label or the service attribute label when the personnel attribute label or the service attribute label changes, and is also used to:

[0030] When the personnel attribute label or the business attribute label is changed and the assigned role does not conform to the label assignment rule, the assigned role of the personnel attribute label or the business attribute label is revoked;

[0031] When the personnel attribute tag or the business attribute tag is changed, a new role is assigned to the personnel attribute tag or the business attribute tag.

[0032] Preferably, the adjustment unit is further used to adjust the roles assigned to the personnel attribute tags and the business attribute tags based on a customized role assignment method.

[0033] The technical solution of the present invention provides a method and system for assigning permissions in a large-scale government affairs system based on tag management, wherein the method includes: establishing personnel attribute tags based on personnel attribute information; establishing business attribute tags based on business attribute information; automatically assigning roles to corresponding personnel attribute tags and business attribute tags based on preset tag assignment rules; when personnel attribute tags or business attribute tags change, adjusting the corresponding roles of the changed personnel attribute tags or business attribute tags; initiating access to the system based on the access rights obtained by the assigned roles. The technical solution of the present invention aims at the problems of complex role and permission management, improper permission allocation, internal control risks, etc. in large-scale government affairs systems. Based on personnel information attributes, resource (functional permission) attributes, and role applicable rule attributes, the scope of permissions that can be granted to personnel is dynamically calculated. The technical solution of the present invention improves the efficiency of system permission allocation and reduces manual management risks. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] A more complete understanding of exemplary embodiments of the present invention may be obtained by referring to the following drawings:

[0035] Figure 1 A flowchart of a method for allocating permissions to a large-scale government affairs system based on tag management according to a preferred embodiment of the present invention;

[0036] Figure 2 A schematic diagram of the overall architecture according to a preferred embodiment of the present invention;

[0037] Figure 3 A personnel label mapping relationship diagram according to a preferred embodiment of the present invention;

[0038] Figure 4 A role label mapping relationship diagram according to a preferred embodiment of the present invention;

[0039] Figure 5 Automatically assigning a logic diagram to roles according to a preferred embodiment of the present invention; and

[0040] Figure 6 A system structure diagram for allocating permissions to a large-scale government affairs system based on tag management according to a preferred embodiment of the present invention. DETAILED DESCRIPTION

[0041] Now, exemplary embodiments of the present invention are described with reference to the accompanying drawings. However, the present invention can be implemented in many different forms and is not limited to the embodiments described herein. These embodiments are provided to disclose the present invention in detail and completely and to fully convey the scope of the present invention to those skilled in the art. The terms used in the exemplary embodiments shown in the accompanying drawings are not intended to limit the present invention. In the accompanying drawings, the same units / elements are marked with the same reference numerals.

[0042] Unless otherwise specified, the terms (including technical terms) used herein have the commonly understood meanings to those skilled in the art. In addition, it is understood that the terms defined in commonly used dictionaries should be understood to have the same meanings as those in the context of the relevant fields, and should not be understood as idealized or overly formal meanings.

[0043] Figure 1 A flowchart of a method for allocating permissions to a large-scale government affairs system based on tag management according to a preferred embodiment of the present invention.

[0044] The present invention adopts the permission management model of RBAC (role-based access control) + ABAC (attribute-based access control), introduces the concept of tag management on this basis, and divides tags into personnel attribute tags and business attribute tags. The mapping relationship between personnel and tags, and the mapping relationship between roles and tags are established, and the permission allocation of personnel is completed through automatic matching of roles and personnel attribute tags, and the permission allocation mode is changed from "manual allocation" to "automatic adaptation as the main and manual allocation as the auxiliary", which resolves the problem of difficulty in permission allocation of large-scale government affairs systems.

[0045] The present invention aims at the problems of complex role and authority management, improper authority allocation, internal control risks, etc. in large-scale government affairs systems. Based on personnel information attributes, resource (functional authority) attributes, and role applicable rule attributes, the scope of authority that can be granted to personnel is dynamically calculated. At the same time, a tag management mechanism is introduced. Based on personnel basic attribute tags and business attribute tags, the role can be granted to personnel with which types of tags through rule management, and according to the tags owned by the personnel and the role applicable tag rules, the personnel to whom the role can be granted are dynamically calculated, and automatic authorization is performed, and the authority allocation mode is changed from "manual allocation" to "automatic adaptation as the main and manual allocation as the auxiliary", which resolves the problem of difficulty in authority allocation in large-scale government affairs systems, improves allocation efficiency, and reduces manual management risks.

[0046] like Figure 1 As shown, the present invention provides a method for allocating permissions in a large-scale government affairs system based on tag management, the method comprising:

[0047] Step 101: Create a personnel attribute tag based on personnel attribute information; create a business attribute tag based on business attribute information;

[0048] Preferably, the personnel attribute information includes: gender, age, political status, position, and rank;

[0049] By calculating the personnel attribute information, the personnel attribute label is determined based on the obtained calculation result.

[0050] The present invention establishes a label management mechanism, which divides labels into personnel attribute labels and business attribute labels. Personnel attribute labels are automatically calculated based on personnel gender, age, political status, position, rank, etc., and corresponding labels are assigned to personnel according to the calculation results; business attribute labels are uniformly defined by the business department, and the leaders of each department manually label the personnel in their department.

[0051] Step 102: Based on a preset label assignment rule, the roles are automatically assigned to corresponding personnel attribute labels and business attribute labels;

[0052] Preferably, the label allocation rules include:

[0053] Set the personnel attribute labels and business attribute labels that match the roles respectively.

[0054] The present invention establishes a role allocation rule management mechanism. Based on the personnel label location, the business supervisory unit specifies which roles need to be set and which labels the roles can be granted to. The system automatically allocates qualified personnel according to the label allocation rules set for the roles and the personnel's labels.

[0055] Step 103: When the personnel attribute label or the business attribute label is changed, the corresponding role of the changed personnel attribute label or business attribute label is adjusted;

[0056] Preferably, when a personnel attribute label or a business attribute label is changed, adjusting the corresponding role of the changed personnel attribute label or business attribute label includes:

[0057] When the personnel attribute tag or business attribute tag is changed and the assigned role does not meet the tag assignment rules, the assigned role of the personnel attribute tag or business attribute tag is revoked;

[0058] When the personnel attribute label or the business attribute label is changed, a new role is assigned to the personnel attribute label or the business attribute label.

[0059] The present invention establishes a dynamic adjustment mechanism for permissions. When a personnel label changes, the corresponding role is revoked for personnel who no longer meet the role allocation label rules; the corresponding role is granted to newly added personnel who meet the role allocation label rules.

[0060] Step 104: Initiate access to the system based on the access rights obtained by the assigned role.

[0061] Preferably, the method further includes: adjusting the roles assigned to the personnel attribute tags and the business attribute tags based on a customized role assignment method.

[0062] The present invention establishes an auxiliary mechanism for manually assigning roles, and if the automatically assigned role authority is insufficient, it can be supplemented by manual granting.

[0063] In view of the complexity of role and authority management in large-scale government affairs systems, improper authority allocation, internal control risks and other issues, this invention proposes to manage personnel authority based on tags, so as to achieve the purpose of automating and refining system authority management and achieve "precise use of authority and consistency of authority and responsibility". At the same time, since digital business operation standards stipulate which types of personnel can use corresponding authority, various illegal authorizations can be effectively avoided and internal control risks can be prevented. The specific benefits are as follows:

[0064] The automated authority allocation provided by the present invention can reduce repetitive and inefficient manual allocation work and improve the efficiency of authority allocation, especially when employees join or leave or when the organizational structure changes, it can automatically trigger authority changes and effectively reduce management costs;

[0065] The automated allocation provided by the present invention can reduce permission configuration errors caused by human errors and reduce the risk of data leakage. For example, when an employee resigns, the system can recover all system permissions and accounts in seconds, reducing the risk of enterprise data leakage.

[0066] The present invention can reduce the demand for human resources and save labor costs through automatic authority allocation, while reducing potential losses caused by improper authority management.

[0067] The present invention can control permissions more accurately, avoid permission abuse, and improve system security through automated permission allocation.

[0068] Figure 6 A system structure diagram for allocating permissions to a large-scale government affairs system based on tag management according to a preferred embodiment of the present invention.

[0069] like Figure 6 As shown, the present invention provides a system for allocating permissions for a large-scale government affairs system based on tag management, the system comprising:

[0070] The establishing unit 501 is used to establish a personnel attribute tag based on the personnel attribute information; and to establish a business attribute tag based on the business attribute information;

[0071] Preferably, the personnel attribute information includes: gender, age, political status, position, and rank;

[0072] The establishing unit is also used to calculate the personnel attribute information and determine the personnel attribute label through the obtained calculation result.

[0073] The present invention establishes a label management mechanism, which divides labels into personnel attribute labels and business attribute labels. Personnel attribute labels are automatically calculated based on personnel gender, age, political status, position, rank, etc., and corresponding labels are assigned to personnel according to the calculation results; business attribute labels are uniformly defined by the business department, and the leaders of each department manually label the personnel in their department.

[0074] An allocating unit 502, configured to automatically allocate roles to corresponding personnel attribute tags and business attribute tags based on a preset tag allocation rule;

[0075] Preferably, the label allocation rules include:

[0076] Set the personnel attribute labels and business attribute labels that match the roles respectively.

[0077] The present invention establishes a role allocation rule management mechanism. Based on the personnel label location, the business supervisory unit specifies which roles need to be set and which labels the roles can be granted to. The system automatically allocates qualified personnel according to the label allocation rules set for the roles and the personnel's labels.

[0078] An adjusting unit 503, configured to adjust a corresponding role of a changed personnel attribute label or a changed service attribute label when a personnel attribute label or a service attribute label changes;

[0079] Preferably, the adjusting unit 503 is used to adjust the corresponding role of the changed personnel attribute label or service attribute label when the personnel attribute label or service attribute label is changed, and is also used to:

[0080] When the personnel attribute tag or business attribute tag is changed and the assigned role does not meet the tag assignment rules, the assigned role of the personnel attribute tag or business attribute tag is revoked;

[0081] When the personnel attribute label or the business attribute label is changed, a new role is assigned to the personnel attribute label or the business attribute label.

[0082] Preferably, the adjusting unit 503 is further configured to adjust the roles assigned to the personnel attribute tags and the business attribute tags based on a customized role assignment method.

[0083] The present invention establishes a dynamic adjustment mechanism for permissions. When a personnel label changes, the corresponding role is revoked for personnel who no longer meet the role allocation label rules; the corresponding role is granted to newly added personnel who meet the role allocation label rules.

[0084] The execution unit 504 is used to initiate access to the system based on the access rights obtained by the assigned role.

[0085] The present invention establishes an auxiliary mechanism for manually assigning roles, and if the automatically assigned role authority is insufficient, it can be supplemented by manual granting.

[0086] It will be appreciated by those skilled in the art that embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program codes. The schemes in the embodiments of the present invention may be implemented in various computer languages, for example, object-oriented programming language Java and literal scripting language JavaScript, etc.

[0087] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0088] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0089] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0090] Although the preferred embodiments of the present invention have been described, those skilled in the art may make other changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present invention.

[0091] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalents, the present invention is also intended to include these modifications and variations.

[0092] The invention has been described above with reference to a few embodiments. However, it is readily apparent to a person skilled in the art that other embodiments than the ones disclosed above are equally within the scope of the invention, as defined by the appended patent claims.

[0093] Generally, all terms used in the claims are to be interpreted according to their ordinary meaning in the technical field, unless explicitly defined otherwise herein. All references to "a / said / the [means, components, etc.]" are to be openly interpreted as at least one instance of the means, components, etc., unless explicitly stated otherwise. The steps of any method disclosed herein do not necessarily have to be performed in the exact order disclosed, unless explicitly stated otherwise.

Claims

1. A method for allocating permissions in a large-scale government affairs system based on tag management, the method comprising: Establish personnel attribute labels based on personnel attribute information; Establish business attribute labels based on business attribute information; Based on the preset label assignment rules, the roles are automatically assigned to the corresponding personnel attribute labels and business attribute labels; When the personnel attribute label or the business attribute label changes, adjusting the corresponding role of the changed personnel attribute label or the business attribute label; Initiate access to the system based on the access rights obtained by the assigned role.

2. According to the method of claim 1, the personnel attribute information includes: Gender, age, political affiliation, position, and rank; The personnel attribute information is calculated and the personnel attribute label is determined by obtaining the calculation result.

3. The method according to claim 1, wherein the label allocation rule comprises: The personnel attribute labels and the business attribute labels that match the roles are respectively set.

4. The method according to claim 1, wherein when the personnel attribute label or the business attribute label changes, adjusting the corresponding role of the changed personnel attribute label or the business attribute label comprises: When the personnel attribute label or the business attribute label is changed and the assigned role does not conform to the label assignment rule, the assigned role of the personnel attribute label or the business attribute label is revoked; When the personnel attribute tag or the business attribute tag is changed, a new role is assigned to the personnel attribute tag or the business attribute tag.

5. The method according to claim 1, further comprising: Based on the customized role allocation method, the roles allocated to the personnel attribute tags and the business attribute tags are adjusted.

6. A system for allocating permissions in a large-scale government affairs system based on tag management, the system comprising: An establishing unit, used for establishing a personnel attribute label based on the personnel attribute information; Establish business attribute labels based on business attribute information; An allocating unit, configured to automatically allocate roles to corresponding personnel attribute tags and business attribute tags based on a preset tag allocation rule; An adjusting unit, configured to adjust a corresponding role of the changed personnel attribute label or the service attribute label when the personnel attribute label or the service attribute label changes; The execution unit is used to initiate access to the system based on the access rights obtained by the assigned role.

7. The system according to claim 6, wherein the personnel attribute information comprises: Gender, age, political affiliation, position, and rank; The establishing unit is further configured to calculate the personnel attribute information and determine the personnel attribute label through the obtained calculation result.

8. The system according to claim 6, wherein the label allocation rule comprises: The personnel attribute labels and the business attribute labels that match the roles are respectively set.

9. The system according to claim 6, wherein the adjustment unit is used to adjust the corresponding role of the changed personnel attribute label or the service attribute label when the personnel attribute label or the service attribute label changes, and is also used to: When the personnel attribute label or the business attribute label is changed and the assigned role does not conform to the label assignment rule, the assigned role of the personnel attribute label or the business attribute label is revoked; When the personnel attribute tag or the business attribute tag is changed, a new role is assigned to the personnel attribute tag or the business attribute tag.

10. The system according to claim 6, wherein the adjustment unit is further used to adjust the roles assigned to the personnel attribute labels and the business attribute labels based on a customized role assignment method.

Citation Information

Patent Citations

  • Resources distribution method and system

    CN101159053A

  • Method and system for automatically allocating permission to application system users

    CN111400683A