User permission configuration method and device, electronic equipment and storage medium

By encoding the permission description text into a vector and matching it with the permission knowledge base, determining the permission intent and calling the corresponding interface to configure permissions, the problem of poor flexibility in permission configuration and maintenance of the RBAC model is solved, and more flexible and convenient permission management is achieved.

CN120124022APending Publication Date: 2025-06-10NANJING LINGXING TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311692929.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-08
Publication Date
2025-06-10

AI Technical Summary

Technical Problem

The existing RBAC model has poor flexibility in permission configuration and maintenance and complex maintenance, resulting in difficulty in permission configuration and maintenance.

Method used

By obtaining the permission description text, encode it as a permission description vector, and match it with the permission operation vector and the user role vector in the permission knowledge base, determine the permission intent, and then call the corresponding permission interface to configure permissions for the target user.

Benefits of technology

Improves the flexibility of permission configuration, simplifies the permission maintenance process, and reduces the maintenance needs for complex relationships.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120124022A_ABST
    Figure CN120124022A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a user permission configuration method and device, electronic equipment and a storage medium, and the method comprises the steps: obtaining a permission description text which comprises permission demand information and a target user; encoding the permission description text to obtain a permission description vector; matching the permission description vector with a permission operation vector and a user role vector in a permission knowledge base to determine a permission intention, the permission operation vector being a vector representation of a first association relationship between a role permission and an operation object, and the user role vector being a vector representation of a second association relationship between a user and a role; matching the permission intention with a permission interface description vector in a permission interface knowledge base, and determining a permission interface identifier; and calling a permission interface corresponding to the permission interface identifier to configure a permission corresponding to the permission intention for the target user. According to the embodiment of the invention, the flexibility of permission configuration is improved, and the convenience of permission maintenance is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the field of Internet technologies, and particularly to a method, device, electronic device, and storage medium for configuring user permissions. Background Art

[0002] After many companies reach a certain scale, in order to address security risk issues, they need to design user permissions.

[0003] In the prior art, the most widely used permission management model is the RBAC (Role-Based Access Control) model. Figure 1 It is a schematic diagram of the permission design of the RBAC model in the prior art. As Figure 1 shown, in the RBAC model, it is necessary to maintain the association relationships such as user-role, user-user group-role, user-organization-role, and user position-role. However, with the change of requirements, the number of systems is increasing, the business is becoming more and more complex, and the personnel organization permission maintenance relationship is becoming more and more complex, resulting in more and more difficult maintenance. Moreover, since it is necessary to configure permissions for users based on each association relationship, the flexibility of permission configuration is poor. Summary of the Invention

[0004] The embodiments of the present application provide a method, device, electronic device, and storage medium for configuring user permissions, which helps to improve the flexibility of permission configuration and the convenience of permission maintenance.

[0005] To solve the above problems, in a first aspect, the embodiments of the present application provide a method for configuring user permissions, including:

[0006] Obtaining a permission description text, where the permission description text includes permission requirement information and a target user;

[0007] Encoding the permission description text to obtain a permission description vector of the permission description text;

[0008] Matching the permission description vector with a permission operation vector and a user role vector in a permission knowledge base to determine a permission intention corresponding to the permission description text, where the permission operation vector is a vector representation of a first association relationship between a role permission and an operation object, and the user role vector is a vector representation of a second association relationship between a user and a role;

[0009] Matching the permission intention with a permission interface description vector in a permission interface knowledge base to determine a permission interface identifier corresponding to the permission intention, where the permission interface description vector is a vector representation of permission interface description information;

[0010] Call the permission interface corresponding to the permission interface identifier to configure the permission corresponding to the permission intention for the target user.

[0011] In a second aspect, an embodiment of the present application provides a user permission configuration device, including:

[0012] A text acquisition module, configured to acquire a permission description text, where the permission description text includes permission requirement information and a target user;

[0013] A text encoding module, configured to encode the permission description text to obtain a permission description vector of the permission description text;

[0014] A permission intention determination module, configured to match the permission description vector with a permission operation vector and a user role vector in a permission knowledge base to determine the permission intention corresponding to the permission description text, where the permission operation vector is a vector representation of a first association relationship between a role permission and an operation object, and the user role vector is a vector representation of a second association relationship between a user and a role;

[0015] A permission interface determination module, configured to match the permission intention with a permission interface description vector in a permission interface knowledge base to determine a permission interface identifier corresponding to the permission intention, where the permission interface description vector is a vector representation of permission interface description information;

[0016] A permission configuration module, configured to call the permission interface corresponding to the permission interface identifier to configure the permission corresponding to the permission intention for the target user.

[0017] In a third aspect, an embodiment of the present application further provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the user permission configuration method described in the embodiment of the present application is implemented.

[0018] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, the user permission configuration method disclosed in the embodiment of the present application is implemented.

[0019] The configuration method, device, electronic device, and storage medium for user permissions provided by the embodiments of the present application, after obtaining the permission description text, convert the permission description text into a permission description vector, and then can match the permission description vector with the permission operation vector and user role vector in the permission knowledge base to determine the permission intent corresponding to the permission description text, match the permission intent with the permission interface description vector in the permission interface knowledge base to determine the permission interface identifier corresponding to the permission intent, and call the permission interface corresponding to the permission interface identifier to configure the permission corresponding to the permission intent for the target user. Since a corresponding permission can be configured for the target user through a permission description text given by the user, the flexibility of permission configuration is improved, and there is no need to maintain complex relationships, which improves the convenience of permission maintenance. Brief Description of the Drawings

[0020] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0021] Figure 1 It is a schematic diagram of the permission design of the RBAC model in the prior art;

[0022] Figure 2 It is a flowchart of a method for configuring user permissions provided by the embodiments of the present application;

[0023] Figure 3 It is a schematic diagram of converting interface description information into vector representation in the embodiments of the present application;

[0024] Figure 4 It is a schematic diagram of the construction process of the permission knowledge base in the embodiments of the present application;

[0025] Figure 5 It is a flowchart of automatic permission assignment in the embodiments of the present application;

[0026] Figure 6 It is a block diagram of a device for configuring user permissions provided by the embodiments of the present application. Detailed Embodiments

[0027] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are some, but not all, of the embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts belong to the scope of protection of the present application.

[0028] Figure 2 This is a flowchart of a method for configuring user permissions provided by an embodiment of the present application. This method for configuring user permissions can be executed by an electronic device such as a computer. As Figure 2 shown, the method includes: step 210 to step 250.

[0029] Step 210, obtain a permission description text, where the permission description text includes permission requirement information and target users.

[0030] When a user needs to obtain certain permissions, the user can input a permission description text including permission requirement information and the target users who need to obtain permissions, so that the electronic device executing this method for configuring user permissions obtains the permission description text input by the user. The user can input the permission description text in text form according to requirements. For example, the permission description text can be "I want XX permission", "I want the same permissions as Zhang San", "My team and the Platform Governance Department have recently been working on platform governance, and I need their permissions to handle problems", etc. Among them, the target user can be one user or multiple users. When the target user is multiple users, corresponding permissions can be configured for multiple users, and a virtual user group including multiple users can be established.

[0031] Step 220, encode the permission description text to obtain a permission description vector of the permission description text.

[0032] The Embedding technology of the LLM (Large Language Model) can be used to encode the permission description text, convert the permission description text into a vector, and obtain the permission description vector of the permission description text.

[0033] Step 230, match the permission description vector with the permission operation vector and the user role vector in the permission knowledge base to determine the permission intention corresponding to the permission description text. The permission operation vector is a vector representation of the first association relationship between role permissions and operation objects, and the user role vector is a vector representation of the second association relationship between users and roles.

[0034] Among them, the operation object is at least one function module that the role permission can operate on. The function module can be represented by a menu. A function module can be a menu at a certain level, such as a first-level menu, a second-level menu, a third-level menu, or a fourth-level menu, etc. The permission operation vector is obtained by encoding the first association relationship represented in text form. The user role vector is obtained by encoding the second association relationship represented in text form.

[0035] Match the permission description vector with the permission operation vector and the user role vector in the permission knowledge base respectively to determine the permission operation vector and the user role vector that match the permission description vector. Furthermore, the permission intention corresponding to the permission description text can be determined based on the permission operation vector and the user role vector that match the permission description vector. Among them, the permission intention refers to the required role permissions, that is, the association relationship between the role permissions and the functional modules that can be operated, which can be represented in the form of a vector or in the form of structured data.

[0036] In an embodiment of the present application, the step of matching the permission description vector with the permission operation vector and the user role vector in the permission knowledge base to determine the permission intention corresponding to the permission description text includes: matching the permission description vector with the permission operation vector in the permission knowledge base to obtain a first matching result; matching the permission description vector with the user role vector in the permission knowledge base to obtain a second matching result; and determining the permission intention corresponding to the permission description text according to the first matching result and the second matching result.

[0037] Match the permission description vector with each permission operation vector in the permission knowledge base to determine one or more permission operation vectors that match the permission description vector successfully as the first matching result.

[0038] Match the permission description vector with each user role vector in the permission knowledge base to determine one or more user role vectors that match the permission description vector successfully as the second matching result.

[0039] Combine the first matching result and the second matching result to determine the permission intention corresponding to the permission description text. The large language model can be used to combine the first matching result and the second matching result to determine the final permission intention.

[0040] By matching the permission description vector with the permission operation vector and the user role vector respectively and determining the final permission intention based on the two matching results, the permission intention of the permission description text input by the user can be determined accurately and quickly, improving the flexibility of permission configuration.

[0041] In an embodiment of the present application, the step of matching the permission description vector with the permission operation vector in the permission knowledge base to obtain a first matching result includes: matching the permission description vector with the permission operation vector in the permission knowledge base to determine the first matching degree between the permission description vector and each permission operation vector; and selecting a preset number of permission operation vectors in descending order of the first matching degree as the first matching result.

[0042] Match the permission description vector with each permission operation vector in the permission knowledge base, and calculate the first matching degree between the permission description vector and each permission operation vector. The first matching degree can be represented by the Euclidean distance or the cosine similarity. When the first matching degree is represented by the first Euclidean distance between the permission description vector and the permission operation vector, the first matching degree is inversely proportional to the first Euclidean distance, that is, the smaller the first Euclidean distance, the larger the first matching degree, and the larger the first Euclidean distance, the smaller the first matching degree; when the first matching degree is represented by the first cosine similarity, the first cosine similarity between the permission description vector and the permission operation vector can be directly used as the first matching degree.

[0043] Select a preset number (for example, select 3) of permission operation vectors in descending order of the first matching degree as the first matching result. When the first matching degree is represented by the first Euclidean distance between the permission description vector and the permission operation vector, a preset number of permission operation vectors can be selected in ascending order of the first Euclidean distance as the first matching result; or, when the first matching degree is represented by the first cosine similarity between the permission description vector and the permission operation vector, a preset number of permission operation vectors can be selected in descending order of the first cosine similarity as the first matching result.

[0044] By determining a preset number of permission operation vectors with a larger first matching degree based on the first matching degree between the permission description vector and the permission operation vector as the first matching result, the first matching result obtained in this way is semantically similar to the permission description text, which can improve the accuracy of permission intention recognition.

[0045] In an embodiment of the present application, the matching of the permission description vector with the user role vector in the permission knowledge base to obtain a second matching result includes: matching the permission description vector with the user role vector in the permission knowledge base, and determining the second matching degree between the permission description vector and each user role vector; selecting a preset number of user role vectors in descending order of the second matching degree as the second matching result.

[0046] Match the permission description vector with each user role vector in the permission knowledge base, and calculate the second matching degree between the permission description vector and each user role vector. The second matching degree can be represented by the Euclidean distance or the cosine similarity. When the second matching degree is represented by the second Euclidean distance between the permission description vector and each user role vector, the second matching degree is inversely proportional to the second Euclidean distance, that is, the smaller the second Euclidean distance, the larger the second matching degree, and the larger the second Euclidean distance, the smaller the second matching degree. When the second matching degree is represented by the second cosine similarity between the permission description vector and each user role vector, the second cosine similarity can be directly used as the second matching degree.

[0047] Select a preset number (for example, select 3) of user role vectors in descending order of the second matching degree as the second matching result. When the second matching degree is represented by the second Euclidean distance between the permission description vector and the user role vector, a preset number of user role vectors can be selected in ascending order of the second Euclidean distance as the second matching result; or, when the second matching degree is represented by the second cosine similarity between the permission description vector and the user role vector, a preset number of user role vectors can be selected in descending order of the second cosine similarity as the second matching result.

[0048] By determining a preset number of user role vectors with a larger second matching degree based on the second matching degree between the permission description vector and the user role vector as the second matching result, the second matching result obtained in this way is semantically similar to the permission description text, which can improve the accuracy of permission intention recognition.

[0049] In an embodiment of the present application, the determining the permission intention corresponding to the permission description text according to the first matching result and the second matching result includes:

[0050] Obtain the target first association relationship corresponding to each permission operation vector in the first matching result, and obtain the target second association relationship corresponding to each user role vector in the second matching result. The target first association relationship and the target second association relationship are each represented in text form;

[0051] Use the target first association relationship, the target second association relationship, and the permission description text as prompt words, and determine the permission intention corresponding to the permission description text through a large language model according to the prompt words.

[0052] The permission operation vectors in the first matching result can be decoded into the target first association relationship in text form, the user role vectors in the second matching result can be decoded into the target second association relationship in text form, the target first association relationship, the target second association relationship, and the permission description text are organized into prompt words for the large language model, and the prompt words are input into the large language model. With the permission description text in the prompt words as a prompt, the large language model processes the target first association relationship and the target second association relationship to determine the permission intent corresponding to the permission description text.

[0053] By using the large language model to process the target first association relationship, the target second association relationship, and the permission description text, the permission intent in the permission description text can be accurately identified.

[0054] Step 240: Match the permission intent with the permission interface description vectors in the permission interface knowledge base to determine the permission interface identifier corresponding to the permission intent. The permission interface description vectors are vector representations of permission interface description information.

[0055] Among them, the permission interface description information is the description information of the permission interface, which is represented in text form. The permission interface is the interface for performing permission operations, such as may include interfaces for querying permissions, automatically creating OA approval processes, automatically granting permissions, automatically revoking permissions, etc. The permission interface description information can be represented in the form shown in Table 1.

[0056] Table 1 Sample of Permission Interface Description Information

[0057]

[0058]

[0059]

[0060]

[0061]

[0062] The permission interface knowledge base is a vector database used to store permission interface description vectors. For example, the Chroma database can be used. Figure 3 It is a schematic diagram of converting the interface description information of the permission system related interfaces into vector representations in the embodiments of the present application. As Figure 3 shown, through the Embedding technology of the LLM, the permission interface description information corresponding to each permission interface identifier can be converted into vector representations to obtain the permission interface description vectors corresponding to each permission interface identifier, and the permission interface description vectors are stored in the permission interface knowledge base.

[0063] When the permission intention is represented in the form of a vector, the permission intention can be directly matched with the permission interface description vectors in the permission interface knowledge base to determine one or more permission interface description vectors with the highest matching degree, or determine one or more permission interface description vectors with a matching degree greater than the matching degree threshold, and determine the permission interface identifier corresponding to the determined permission interface description vector as the permission interface identifier corresponding to the permission intention; when the permission intention is represented by structured data, the permission intention can be converted into a vector representation, and the vector representation of the permission intention is matched with the permission interface description vectors in the permission interface knowledge base to determine one or more permission interface description vectors with the highest matching degree, or determine one or more permission interface description vectors with a matching degree greater than the matching degree threshold, and determine the permission interface identifier corresponding to the determined permission interface description vector as the permission interface identifier corresponding to the permission intention.

[0064] Step 250, call the permission interface corresponding to the permission interface identifier to configure the permission corresponding to the permission intention for the target user.

[0065] After determining the permission interface identifier corresponding to the permission intention, the permission interface corresponding to the permission interface identifier can be called to configure the permission corresponding to the permission intention for the target user. For example, call the automatic authorization interface to grant the permission corresponding to the permission intention to the target user, or call the automatic permission revocation interface to revoke the permission corresponding to the permission intention from the target user.

[0066] The user permission configuration method provided by the embodiments of the present application, after obtaining the permission description text, converts the permission description text into a permission description vector, and then can match the permission description vector with the permission operation vector and user role vector in the permission knowledge base to determine the permission intention corresponding to the permission description text, match the permission intention with the permission interface description vectors in the permission interface knowledge base to determine the permission interface identifier corresponding to the permission intention, and call the permission interface corresponding to the permission interface identifier to configure the permission corresponding to the permission intention for the target user. Since a corresponding permission can be configured for the target user through a permission description text given by the user, the flexibility of permission configuration is improved, and there is no need to maintain complex relationships, which improves the convenience of permission maintenance.

[0067] Based on the above technical solution, before matching the permission description vector with the permission operation vector and the user role vector in the permission knowledge base to determine the permission intention of the user, the following steps are further included: obtaining a permission operation document, which records the first association relationship between the role permission and the operation object in text form; encoding each of the first association relationships to obtain the permission operation vector, and storing each of the permission operation vectors into the permission knowledge base; obtaining a user role document, which records the second association relationship between the user and the role in text form; encoding each of the second association relationships to obtain the user role vector, and storing each of the user role vectors into the permission knowledge base.

[0068] Among them, the permission knowledge base is a vector database for storing permission operation vectors and user role vectors. For example, the Chroma database can be used.

[0069] Figure 4 It is a schematic diagram of the construction process of the permission knowledge base in the embodiment of the present application. As Figure 4 shown, the permission operation document and the user role document are processed separately. When processing the permission operation document, load the

[0070] first association relationship between the role permission and the operation object recorded in text form. An example of the permission operation document is shown in Table 2. The operation object can include the first-level menu, the second-level menu, the third-level menu, the fourth-level menu, etc. The first association relationship can also correspond to the data owner (Owner) and the system administrator. The data owner is generally the person who reviews the current role permission; perform text tokenization processing on each first association relationship in the permission operation document. Based on the tokenization processing result, each first association relationship can be encoded through the Embedding technology of the LLM, convert the first association relationship into a permission operation vector, and store the permission operation vector into the permission knowledge base as the basic data for subsequent permission configuration. When processing the user role document, load the user role document, which records the second association relationship between the user and the role in text form. An example of the user role document is shown in Table 3, which lists the roles of each user; perform text tokenization processing on each second association relationship in the user role document. Based on the tokenization processing result, each second association relationship can be encoded through the Embedding technology of the LLM, convert the second association relationship into a user role vector, and store the user role vector into the permission knowledge base, which can also be used as the basic data for subsequent permission configuration. Among them, the permission operation document is configured based on requirements, and the second association relationship in the user role document can be pre-configured data or data automatically generated based on permission configuration data.

[0071] Example of the permission operation document in Table 2

[0072]

[0073] Example of the user role document in Table 3

[0074]

[0075] By encoding each first association relationship recorded in the permission operation document and storing it in the permission knowledge base, and encoding each second association relationship recorded in the user role document and storing it in the permission knowledge base, it provides basic data for permission configuration and facilitates flexible configuration of user permissions. When the first association relationship recorded in the permission operation document is updated, the permission operation vector stored in the permission knowledge base can be updated in a timely manner. For example, when a first association relationship needs to be added, the configurator can directly add the first association relationship in text form in the permission operation document, and the system can directly encode the added first association relationship in the permission operation document and store it in the permission knowledge base.

[0076] Based on the above technical solution, before calling the permission interface corresponding to the permission interface identifier to configure the permission corresponding to the permission intention for the target user, it further includes: if there is a permission approver corresponding to the permission intention, generating a permission approval process corresponding to the permission intention according to the permission approver, and executing the permission approval process;

[0077] The calling the permission interface corresponding to the permission interface identifier to configure the permission corresponding to the permission intention for the target user includes: after the permission intention is approved, calling the permission interface corresponding to the permission interface identifier to configure the permission corresponding to the permission intention for the target user.

[0078] If there is also a permission approver associated with the first association relationship corresponding to the determined permission intention, such as the data owner (Owner) shown in Table 2, at this time, generating a permission approval process corresponding to the permission intention according to the permission approver, and executing the permission approval process, sending the approval process node to the permission approver, obtaining the approval result of the permission approver, and when the approval result is approval passed, calling the permission interface corresponding to the permission interface identifier to configure the permission corresponding to the permission intention for the target user.

[0079] When there is a permission approver corresponding to the permission intention, a permission approval process can be automatically generated, and after approval, the permission can be configured for the target user, which can improve the efficiency of permission configuration.

[0080] Figure 5 It is the flowchart of automatic permission assignment in the embodiment of the present application, as Figure 5As shown in the figure, after vectorizing the permission operation documents and user role documents in the knowledge base related to the permission system based on LangChain + LLM, a permission knowledge base is obtained; the permission description text (such as the questions, intents, chat content, etc. entered by the user) is obtained, the content of the permission description text is vectorized, and it is matched with the permission knowledge base to obtain the top 3 relevant intents (including the top 3 target first association relationships and the top 3 target second association relationships); the top 3 relevant intents and the permission description text are used as prompts (Prompts), the prompts are input into the large language model to obtain the final permission intent; the final permission intent is matched with the permission interface knowledge base through the execution engine (Action Server) to determine the permission interface identifier, create a permission approval process, and automatically assign permissions upon approval.

[0081] The embodiment of the present application provides a dynamic permission allocation system based on LangChain + large language model LLM (such as Chatgpt, chatGLM, Baichuan Intelligence, etc.), which can automatically adjust the permission level according to factors such as user roles, task requirements, environmental conditions, and the context of the conversation, and can identify sensitive topics in group chat content, and determine the corresponding target users based on the sensitive topics, and then can automatically lower the permission level of the target users to ensure data security, thereby improving the security and flexibility of the system, and only need to maintain the permission operation documents, solving the problem of difficult manual permission maintenance.

[0082] Figure 6 is a block diagram of a user permission configuration device provided by an embodiment of the present application, as Figure 6 shown, the device includes:

[0083] A text acquisition module 610, configured to acquire a permission description text, where the permission description text includes permission requirement information and a target user;

[0084] A text encoding module 620, configured to encode the permission description text to obtain a permission description vector of the permission description text;

[0085] A permission intent determination module 630, configured to match the permission description vector with the permission operation vector and the user role vector in the permission knowledge base to determine the permission intent corresponding to the permission description text, where the permission operation vector is a vector representation of the first association relationship between the role permission and the operation object, and the user role vector is a vector representation of the second association relationship between the user and the role;

[0086] A permission interface determination module 640, configured to match the permission intention with a permission interface description vector in a permission interface knowledge base, and determine a permission interface identifier corresponding to the permission intention, where the permission interface description vector is a vector representation of permission interface description information;

[0087] A permission configuration module 650, configured to call the permission interface corresponding to the permission interface identifier to configure the permission corresponding to the permission intention for the target user.

[0088] Optionally, the apparatus further includes:

[0089] A permission operation document acquisition module, configured to acquire a permission operation document, where the permission operation document records a first association relationship between the role permission and the operation object in a text form;

[0090] A first vector conversion module, configured to encode each of the first association relationships to obtain the permission operation vector, and store each of the permission operation vectors in the permission knowledge base;

[0091] A user role document acquisition module, configured to acquire a user role document, where the user role document records a second association relationship between the user and the role in a text form;

[0092] A second vector conversion module, configured to encode each of the second association relationships to obtain the user role vector, and store each of the user role vectors in the permission knowledge base.

[0093] Optionally, the permission intention determination module includes:

[0094] A first vector matching unit, configured to match the permission description vector with the permission operation vector in the permission knowledge base to obtain a first matching result;

[0095] A second vector matching unit, configured to match the permission description vector with the user role vector in the permission knowledge base to obtain a second matching result;

[0096] A permission intention determination unit, configured to determine the permission intention corresponding to the permission description text according to the first matching result and the second matching result.

[0097] Optionally, the first vector matching unit is specifically configured to:

[0098] Match the permission description vector with the permission operation vector in the permission knowledge base, and determine a first matching degree between the permission description vector and each of the permission operation vectors;

[0099] Select a preset number of permission operation vectors in descending order of the first matching degree as the first matching result.

[0100] Optionally, the second vector matching unit is specifically configured to:

[0101] Match the permission description vector with the user role vectors in the permission knowledge base to determine the second matching degree between the permission description vector and each user role vector;

[0102] Select a preset number of user role vectors in descending order of the second matching degree as the second matching result.

[0103] Optionally, the permission intention determination unit is specifically configured to:

[0104] Obtain the target first association relationships corresponding to the permission operation vectors in the first matching result, and obtain the target second association relationships corresponding to the user role vectors in the second matching result, where the target first association relationships and the target second association relationships are respectively represented in text form;

[0105] Use the target first association relationship, the target second association relationship, and the permission description text as prompt words, and determine the permission intention corresponding to the permission description text through a large language model according to the prompt words.

[0106] Optionally, the device further includes:

[0107] A permission approval module, configured to generate a permission approval process corresponding to the permission intention according to the permission approver if the permission intention corresponds to a permission approver, and execute the permission approval process;

[0108] The permission configuration module is specifically configured to:

[0109] After the permission intention is approved, call the permission interface corresponding to the permission interface identifier to configure the permission corresponding to the permission intention for the target user.

[0110] The user permission configuration device provided by the embodiments of the present application is used to implement the steps of the user permission configuration method described in the embodiments of the present application. For the specific implementation manners of the modules of the device, refer to the corresponding steps and will not be elaborated here.

[0111] The user privilege configuration device provided by the embodiments of the present application, after obtaining the privilege description text, converts the privilege description text into a privilege description vector, and then can match the privilege description vector with the privilege operation vector and the user role vector in the privilege knowledge base to determine the privilege intention corresponding to the privilege description text, match the privilege intention with the privilege interface description vector in the privilege interface knowledge base to determine the privilege interface identifier corresponding to the privilege intention, and call the privilege interface corresponding to the privilege interface identifier to configure the privilege corresponding to the privilege intention for the target user. Since a privilege description text given by the user can be used to configure the corresponding privilege for the target user, the flexibility of privilege configuration is improved, and there is no need to maintain complex relationships, which improves the convenience of privilege maintenance.

[0112] Correspondingly, the embodiments of the present application further provide an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, it implements the user privilege configuration method as described in the embodiments of the present application. The electronic device can be a PC, a server, etc.

[0113] The embodiments of the present application further provide a computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, it implements the steps of the user privilege configuration method as described in the embodiments of the present application.

[0114] Each embodiment in this specification is described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. The same or similar parts among the embodiments can be referred to each other. For the device embodiments, since they are basically similar to the method embodiments, the description is relatively simple. For the relevant parts, refer to the partial description of the method embodiments.

[0115] The above has introduced in detail a user privilege configuration method, device, electronic device, and storage medium provided by the embodiments of the present application. Specific examples are used in this article to elaborate on the principle and implementation manner of the present application. The description of the above embodiments is only used to help understand the method and its core idea of the present application; at the same time, for those of ordinary skill in the art, according to the idea of the present application, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present application.

[0116] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the above technical solution, in essence, or the part that contributes to the prior art can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

Claims

1. A method for configuring user permissions, characterized in that, it includes: Obtain a permission description text, where the permission description text includes permission requirement information and a target user; Encode the permission description text to obtain a permission description vector of the permission description text; Match the permission description vector with a permission operation vector and a user role vector in a permission knowledge base to determine the permission intent corresponding to the permission description text, where the permission operation vector is a vector representation of the first association relationship between a role permission and an operation object, and the user role vector is a vector representation of the second association relationship between a user and a role; Match the permission intent with a permission interface description vector in a permission interface knowledge base to determine the permission interface identifier corresponding to the permission intent, where the permission interface description vector is a vector representation of permission interface description information; Call the permission interface corresponding to the permission interface identifier to configure the permission corresponding to the permission intent for the target user.

2. The method according to claim 1, characterized in that, before the matching the permission description vector with the permission operation vector and the user role vector in the permission knowledge base to determine the permission intent of the user, it further includes: Obtain a permission operation document, where the permission operation document records the first association relationship between the role permission and the operation object in text form; Encode each of the first association relationships to obtain the permission operation vector, and store each permission operation vector in the permission knowledge base; Obtain a user role document, where the user role document records the second association relationship between the user and the role in text form; Encode each of the second association relationships to obtain the user role vector, and store each user role vector in the permission knowledge base.

3. The method according to claim 1, characterized in that, the matching the permission description vector with the permission operation vector and the user role vector in the permission knowledge base to determine the permission intent corresponding to the permission description text includes: Match the permission description vector with the permission operation vector in the permission knowledge base to obtain a first matching result; Match the permission description vector with the user role vector in the permission knowledge base to obtain a second matching result; Determine the permission intent corresponding to the permission description text according to the first matching result and the second matching result.

4. The method according to claim 3, characterized in that, the matching the permission description vector with the permission operation vector in the permission knowledge base to obtain a first matching result includes: Match the permission description vector with the permission operation vector in the permission knowledge base to determine the first matching degree between the permission description vector and each permission operation vector; Select a preset number of permission operation vectors in descending order of the first matching degree as the first matching result.

5. The method according to claim 3, characterized in that, Matching the permission description vector with the user role vectors in the permission knowledge base to obtain a second matching result includes: Matching the permission description vector with the user role vectors in the permission knowledge base to determine the second matching degree between the permission description vector and each user role vector; Selecting a preset number of user role vectors in descending order of the second matching degree as the second matching result.

6. The method according to any one of claims 3-5, wherein, Determining the permission intention corresponding to the permission description text according to the first matching result and the second matching result includes: Obtaining the target first association relationships corresponding to the permission operation vectors in the first matching result, and obtaining the target second association relationships corresponding to the user role vectors in the second matching result, where the target first association relationships and the target second association relationships are respectively represented in text form; Using the target first association relationship, the target second association relationship, and the permission description text as prompt words, and determining the permission intention corresponding to the permission description text through a large language model according to the prompt words.

7. The method according to any one of claims 1-5, wherein, Before calling the permission interface corresponding to the permission interface identifier to configure the permission corresponding to the permission intention for the target user, it further includes: If there is a permission approver corresponding to the permission intention, generating a permission approval process corresponding to the permission intention according to the permission approver, and executing the permission approval process; Calling the permission interface corresponding to the permission interface identifier to configure the permission corresponding to the permission intention for the target user includes: After the permission intention is approved, calling the permission interface corresponding to the permission interface identifier to configure the permission corresponding to the permission intention for the target user.

8. A device for configuring user permissions, wherein, it includes: A text acquisition module for acquiring a permission description text, where the permission description text includes permission requirement information and a target user; A text encoding module for encoding the permission description text to obtain a permission description vector of the permission description text; A permission intention determination module for matching the permission description vector with permission operation vectors and user role vectors in a permission knowledge base to determine the permission intention corresponding to the permission description text, where the permission operation vector is a vector representation of the first association relationship between a role permission and an operation object, and the user role vector is a vector representation of the second association relationship between a user and a role; A permission interface determination module for matching the permission intention with a permission interface description vector in a permission interface knowledge base to determine the permission interface identifier corresponding to the permission intention, where the permission interface description vector is a vector representation of permission interface description information; A permission configuration module for calling the permission interface corresponding to the permission interface identifier to configure the permission corresponding to the permission intention for the target user.

9. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein, when the processor executes the computer program, the configuration method of the user privilege according to any one of claims 1 to 7 is implemented.

10. A computer-readable storage medium, having stored thereon a computer program, wherein, when the program is executed by a processor, the configuration method of the user privilege according to any one of claims 1 to 7 is implemented.