Account matching method and device, computer readable storage medium and electronic equipment

By obtaining account information and server information in the user centralized management system and configuration management system, and matching it using machine learning models, the problem that the account information of different servers is difficult to correspond to user information is solved, and higher account matching accuracy and system management efficiency are achieved.

CN120144618APending Publication Date: 2025-06-13INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510219641.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-26
Publication Date
2025-06-13

AI Technical Summary

Technical Problem

The department and personnel information of the server that has been managed cannot be queried in the user centralized management system, and the specific user information corresponding to the account information corresponding to the server cannot be queried in the configuration management system, which makes it difficult for the account information of different servers to correspond to the specific user information, and it is easy to have account matching errors.

Method used

By obtaining the account information included in the N applications in the user system and the correspondence relationship between these account information and the server in the configuration system, the account information is input and the corresponding actual user information is determined using the preset target machine learning model, and the actual user information corresponding to the server is determined based on the correspondence relationship between the account and the server.

Benefits of technology

The purpose of matching server, account information and user information through machine learning models is achieved, thereby reducing the probability of account matching errors, improving the accuracy of user information management and the efficiency of system resources utilization.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120144618A_ABST
    Figure CN120144618A_ABST
Patent Text Reader

Abstract

The invention discloses an account matching method and device, a computer readable storage medium and electronic equipment. The method relates to the technical field of big data, and comprises the following steps: acquiring account information respectively included in N applications in a user system and a corresponding relationship between the account information respectively included in the N applications and a server in a configuration system; account information included in each of the N applications is input into a preset target machine learning model, actual user information corresponding to the account information included in each of the N applications is determined, and the actual user information represents identity authentication information of a user corresponding to the account information; and determining actual user information corresponding to the server based on the corresponding relationship between the account and the server in the configuration system. Through application of the method and the device, the problem that account matching errors are easy to occur due to the fact that account information corresponding to different servers is difficult to correspond to specific user information in related technologies is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of big data technology, and in particular, to an account matching method, device, computer-readable storage medium, and electronic device. Background Art

[0002] Since the department and personnel information of the managed servers cannot be queried in the user centralized management system, and the specific user information corresponding to the account information of the server cannot be queried in the configuration management system. And the account information corresponding to different servers and different applications may correspond to the same user information. In actual operation and maintenance, the addition and removal of server devices are involved every day, making it difficult to match the account information in the server with the user information, prone to mistakes, and there are certain risks.

[0003] In view of the problem that it is difficult to correspond the account information corresponding to different servers with specific user information in the related art, resulting in easy account matching mistakes, no effective solution has been proposed yet. Summary of the Invention

[0004] The main purpose of the present application is to provide an account matching method, device, computer-readable storage medium, and electronic device to solve the problem in the related art that it is difficult to correspond the account information corresponding to different servers with specific user information, resulting in easy account matching mistakes.

[0005] To achieve the above object, according to one aspect of the present application, an account matching method is provided. The method includes: obtaining the account information included in each of N applications in the user system and the corresponding relationship between the account information included in each of the N applications and the servers in the configuration system, where N is an integer greater than 0; inputting the account information included in each of the N applications into a preset target machine learning model to determine the actual user information corresponding to the account information included in each of the N applications, where the actual user information represents the identity authentication information of the user corresponding to the account information, and the target machine learning model is trained by sample user claim data, and the sample user claim data includes sample account information, sample actual user information, and the corresponding relationship between the sample account and the sample actual user; determining the actual user information corresponding to the server based on the corresponding relationship between the account and the server in the configuration system.

[0006] Optionally, obtaining the account information included in each of the N applications in the user system and the correspondence between the account information included in each of the N applications and the server in the configuration system includes: setting an interval duration; collecting, based on the interval duration, the account information included in each of the N applications in the user system and the server information in the configuration system; and determining, based on the account information included in each of the N applications in the user system and the server information in the configuration system, the correspondence between the account information included in each of the N applications and the server in the configuration system.

[0007] Optionally, the account information includes an account name, an application name corresponding to the account, and an account IP address, and the server information includes an application name, a server address, and environment resource information corresponding to the server.

[0008] Optionally, before inputting the account information included in each of the N applications into a preset target machine learning model to determine the actual user information corresponding to the account information included in each of the N applications, it further includes: obtaining an original machine learning model and sample user claim data; extracting eigenvalue in the sample account information and the sample actual user information in the sample user claim data; and training the original machine learning model with the eigenvalue and the correspondence between the sample account and the sample actual user to obtain the target machine learning model.

[0009] Optionally, inputting the account information included in each of the N applications into a preset target machine learning model to determine the actual user information corresponding to the account information included in each of the N applications further includes: generating a confirmation message, where the confirmation message is used to confirm whether the correspondence between the account information and the actual user information matches; sending the confirmation message to the account corresponding to the account information; and determining that the correspondence between the account information and the actual user information matches when receiving a confirmation that the correspondence matches returned by the account.

[0010] Optionally, when receiving a confirmation that the correspondence does not match returned by the account, determining that the account information is redundant data and clearing the redundant data.

[0011] Optionally, monitoring the behavior of the accounts in the user system; when it is monitored that the behavior of a target account in the user system is abnormal, backing up the account information of the target account to obtain backup account information; deleting the account information of the target account; and when a user system exception occurs within a preset duration after deleting the account information of the target account, regenerating the target account based on the backup account information.

[0012] To achieve the above object, according to another aspect of the present application, there is provided an account matching device. The device includes: an acquisition module, configured to acquire the account information included in each of the N applications in the user system and the correspondence between the account information included in each of the N applications and the server in the configuration system, where N is an integer greater than 0; an input module, configured to input the account information included in each of the N applications into a preset target machine learning model to determine the actual user information corresponding to the account information included in each of the N applications, where the actual user information represents the identity authentication information of the user corresponding to the account information, and the target machine learning model is trained by sample user claim data, and the sample user claim data includes sample account information, sample actual user information, and the correspondence between the sample account and the sample actual user; a determination module, configured to determine the actual user information corresponding to the server based on the correspondence between the account and the server in the configuration system.

[0013] To achieve the above object, according to another aspect of the present application, there is also provided a computer-readable storage medium. The computer-readable storage medium includes an executable program stored therein. When the executable program runs, it controls the device where the computer-readable storage medium is located to execute any one of the above account matching methods.

[0014] To achieve the above object, according to another aspect of the present application, there is provided an electronic device, including: a memory storing an executable program; a processor configured to run the program, where when the program runs, it executes any one of the above account matching methods as claimed.

[0015] To achieve the above object, according to another aspect of the present application, there is provided a computer program product, including computer instructions, and when the computer instructions are executed by a processor, the steps of any one of the above account matching methods are implemented.

[0016] In an embodiment of the present application, an account matching method is adopted. By obtaining the account information included in each of the N applications in the user system and the corresponding relationship between the account information included in each of the N applications and the server in the configuration system, where N is an integer greater than 0; inputting the account information included in each of the N applications into a preset target machine learning model to determine the actual user information corresponding to the account information included in each of the N applications, where the actual user information represents the identity authentication information of the user corresponding to the account information, and the target machine learning model is trained by sample user claim data, and the sample user claim data includes sample account information, sample actual user information, and the corresponding relationship between the sample account and the sample actual user; based on the corresponding relationship between the account and the server in the configuration system, determining the actual user information corresponding to the server, achieving the purpose of matching the server, account information, and user information through the machine learning model, thereby realizing the technical effect of reducing the probability of account matching errors, and further solving the technical problem in the related art that it is difficult to correspond the account information corresponding to different servers with specific user information, resulting in easy occurrence of account matching errors. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] The accompanying drawings, which form a part of this application, are used to provide a further understanding of this application. The schematic embodiments and descriptions thereof of this application are used to explain this application and do not constitute an improper limitation to this application. In the drawings:

[0018] Figure 1 shows a hardware structure block diagram of a computer terminal for implementing the account matching method;

[0019] Figure 2 is a flowchart of the account matching method provided by an embodiment of this application;

[0020] Figure 3 is a timing diagram of the account matching method provided by an optional embodiment of this application;

[0021] Figure 4 is a structure block diagram of the account matching device provided by an embodiment of this application;

[0022] Figure 5 is a structure block diagram of an electronic device provided by an embodiment of this application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0023] To enable those skilled in the art to better understand the solution of this application, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this application without creative efforts shall fall within the scope of protection of this application.

[0024] It should be noted that the terms "first", "second", etc. in the description and claims of this application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily have to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of this application described here can be implemented in an order different from those illustrated or described here. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0025] It should be noted that the information collected in this application (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for display, data for analysis, etc.) are information and data authorized by the user or fully authorized by all parties. And the processing of relevant data such as collection, storage, use, processing, transmission, provision, disclosure and application complies with relevant laws, regulations and standards, takes necessary confidentiality measures, does not violate public order and good customs, and provides corresponding operation entrances for users to choose to authorize or refuse. For example, there is an interface between this system and relevant users or institutions to provide corresponding operation entrances for users to choose to agree or refuse the automated decision-making results; if the user chooses to refuse, the expert decision-making process will be entered.

[0026] Embodiment 1

[0027] According to the embodiments of this application, a method embodiment of an account matching method is also provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. And although the logical order is shown in the flowchart, in some cases, the steps shown or described here can be executed in a different order from here.

[0028] The method embodiment provided by the first embodiment of this application can be executed on a mobile terminal, a computer terminal or a similar computing device. Figure 1The following shows a hardware block diagram of a computer terminal (or mobile device) for implementing an account matching method. As Figure 1 shown, the computer terminal 10 (or mobile device) may include one or more processors 102 (shown as 102a, 102b, ……, 102n in the figure) (the processor 102 may include, but is not limited to, processing devices such as a microprocessor MCU or a programmable logic device FPGA), a memory 104 for storing data, and a transmission device 106 for communication functions. In addition, it may further include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the BUS bus), a network interface, a power supply, and / or a camera. Those of ordinary skill in the art can understand that Figure 1 the structure shown is only illustrative and does not limit the structure of the above-mentioned electronic device. For example, the computer terminal 10 may further include more or fewer components than Figure 1 shown in, or have a different configuration from Figure 1 shown.

[0029] It should be noted that the above one or more processors 102 and / or other data processing circuits are generally referred to as "data processing circuits" herein. The data processing circuit may be embodied in software, hardware, firmware, or any combination thereof, in whole or in part. In addition, the data processing circuit may be a single independent processing module, or be incorporated in whole or in part into any one of the other elements in the computer terminal 10 (or mobile device). As involved in the embodiments of the present application, the data processing circuit is used for processor control (such as the selection of a variable resistance terminal path connected to an interface).

[0030] The memory 104 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the account matching method in the embodiments of the present application. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, that is, implements the above-mentioned account matching method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some instances, the memory 104 may further include a memory remotely set relative to the processor 102, and these remote memories can be connected to the computer terminal 10 through a network. Examples of the above network include, but are not limited to, the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.

[0031] The transmission device 106 is used to receive or send data via a network. Specific examples of the above network may include a wireless network provided by the communication provider of the computer terminal 10. In one example, the transmission device 106 includes a network adapter (Network Interface Controller, NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 106 can be a Radio Frequency (RF) module, which is used to communicate with the Internet wirelessly.

[0032] The display can be, for example, a touch-screen Liquid Crystal Display (LCD), which enables the user to interact with the user interface of the computer terminal 10 (or mobile device).

[0033] Under the above operating environment, the present application provides an Figure 2 account matching method as shown. Figure 2 It is a flowchart of the account matching method provided by the embodiment of the present application, and is used to execute Embodiment 1.

[0034] Step S201: Obtain the account information included in each of the N applications in the user system and the corresponding relationship between the account information included in the N applications and the server in the configuration system, where N is an integer greater than 0.

[0035] In this step, obtaining the account information included in each of the N applications in the user system and the corresponding relationship between this account information and the server in the configuration system involves cross-system data integration and matching. Among them, the user system can be a User Centralized Management System (UCM). For each application (denoted as Application A to Application N), relevant account information can be extracted from the UCM system. This includes the username of the account, password policy, account status, last login time, etc. The UCM system should support API or data export functions to allow automated data acquisition, usually in formats such as CSV, JSON, or XML. The configuration system can be a Configuration Management Database (CMDB). Server information related to the application can be obtained in the CMDB system. This includes the IP address of the server, server type, operating environment, deployment location, department to which it belongs, etc. Similarly, the CMDB system should provide API or data export functions to facilitate the acquisition of this information, and the format is similar to that of the UCM system. The account information and server information can be integrated, and the resource ID or resource name of the account information obtained from the UCM is used to match the identifier of the server resource in the CMDB system to determine the server to which the account belongs. Through the above matching and integration, a table or data structure can be established, and each account information entry is associated with its corresponding server information, including the IP, type, operating environment, etc. of the server.

[0036] The relationship among the server, applications, and accounts is multi-dimensional and closely interconnected, jointly constructing the infrastructure for system operation and user access. A single server can run multiple applications, and when an application is running, it is usually fixed on one or more servers. An application can have multiple accounts for users with different roles to log in and use. The permissions and access scopes of each account are configured by the user system according to security policies and business requirements. That is, an actual user can have corresponding accounts in different applications.

[0037] Step S202: Input the account information included in each of the N applications into a preset target machine learning model to determine the actual user information corresponding to the account information included in each of the N applications. Here, the actual user information represents the identity authentication information of the user corresponding to the account information, and the target machine learning model is trained with sample user claim data, which includes sample account information, sample actual user information, and the corresponding relationship between the sample account and the sample actual user.

[0038] In this step, the account information included in each of the N applications is input into the preset target machine learning model to determine the actual user information corresponding to these account information. The account information in the N applications serves as the input data for the model, and this information can be the username, account creation time, last login time, login frequency, security policies used, etc. At the same time, it is also necessary to collect the actual user information as the target data, such as the user's real name, email, phone number, department, position, and other identity authentication information. During the training phase, the sample user claim data is used to train the machine learning model. The sample user claim data includes: sample account information, which is the account information selected from historical data; sample actual user information, which is the user identity information corresponding to the sample account information; and the corresponding relationship between the sample account and the sample actual user, that is, which actual user is using the sample account, which is usually obtained through user claims or manual association. For the account information, the features that can be extracted can be account activity, such as login frequency, login time interval, etc.; the security policies of the account, such as password complexity, locking mechanism, access permissions, etc.; and the usage history of the account, such as the number of logins and operation records within a specific time period. For the actual user information, the features that can be extracted can be the department where the user is located, such as finance, technology, human resources, etc.; the role or responsibility of the user, such as administrator, ordinary employee, external consultant, etc.; and the active time of the user, such as weekdays, non-weekdays, specific time periods, etc. Once the model is trained and reaches a satisfactory performance, it can be deployed to the production environment, taking the account information in the N applications as the input to predict the corresponding user identity authentication information. In this way, the machine learning model can automatically classify the account information to the actual user, greatly improving the efficiency and accuracy of user claims.

[0039] Through the above steps, the machine learning-based method can effectively solve the user claim problem, enabling the user management system to automatically identify and associate account information with actual users, which is of great significance for large-scale user management, resource allocation, and automation of security policies.

[0040] Step S203: Determine the actual user information corresponding to the server based on the correspondence between the account and the server in the configuration system.

[0041] In this step, by determining the actual user information corresponding to the server based on the correspondence between the account and the server in the configuration system, the account information and the server information can be integrated to generate a mapping table containing the correspondence between the account and the server. This table should at least include the following columns: Account Name: The account identifier obtained from UCM. Server IP / Name: The server identifier obtained from CMDB. Account Status and Security Policy: Describing the current status of the account and the implemented security measures. Department and Maintenance Personnel of the Server: Describing the business attribution and maintenance responsibility of the server. Integrate the actual user information determined in the previous step with the server information and display it in the user security control platform, enabling application maintenance personnel and user managers to clearly understand the status and attribution of users on each server. This integration and display can be in the form of a table, chart, or detailed report for easy monitoring and management.

[0042] In this way, by integrating the data in UCM and CMDB and combining machine learning technology, refined management of accounts on the server can be achieved, ensuring that each account can be corresponded to actual user information, thereby improving the efficiency and accuracy of user security control.

[0043] Optionally, in the account matching method provided in the embodiments of the present application, obtaining the account information included in each of the N applications in the user system and the correspondence between the account information included in each of the N applications and the server in the configuration system includes: setting an interval duration; collecting the account information included in each of the N applications in the user system and the server information in the configuration system based on the interval duration; determining the correspondence between the account information included in each of the N applications and the server in the configuration system based on the account information included in each of the N applications in the user system and the server information in the configuration system.

[0044] It should be noted that the setting of the interval duration is the basis for automated data collection and processing, which determines the frequency of data update. For example, an interval duration of once every 3 hours can be set to ensure the real-time and accuracy of data. The selection of the interval duration needs to comprehensively consider the system performance, data update frequency, and business requirements. When the set interval duration arrives, the system can automatically initiate a data collection task to obtain account information under N applications from the User Centralized Management System (UCM), including the username, status, security policy, etc. of the account. At the same time, obtain server information from the Configuration Management Database (CMDB), including the IP address, type, running environment, affiliated department, maintenance personnel, etc. of the server. Data collection can be carried out through methods such as API calls, database queries, or system log analysis. The collected account information and server information need to be integrated and matched to determine the association between the account and the server. This process can be achieved through the following methods:

[0045] Direct matching: Directly match the resource identifier (such as server IP) in the account information with the server information in the CMDB.

[0046] Indirect association: If there is no direct resource identifier in the account information, indirect association can be carried out by analyzing information such as the usage pattern, login time, and operation type of the account and information such as the running environment and affiliated department of the server.

[0047] Optionally, in the account matching method provided in the embodiment of the present application, the account information includes the account name, the application name corresponding to the account, and the account IP address, and the server information includes the application name, the server address, and the environmental resource information corresponding to the server.

[0048] It should be noted that account information such as the account IP address, resource type, application name, account name, and user security policy can be obtained from the user system; information such as the server address, the environmental resource information corresponding to the server, application name, running environment, deployment location, application maintenance department, and application maintainer can be obtained from the configuration system. The content displayed after the information integration of the two systems mainly includes: information such as resource IP, resource type, running environment, username, resource affiliated department, application name, application maintenance department, and application maintainer. When a user logs in to this system, only the user information of the servers maintained by himself and his professional group can be seen.

[0049] Optionally, in the account matching method provided in the embodiments of the present application, before inputting the account information included in each of the N applications into a preset target machine learning model to determine the actual user information corresponding to the account information included in each of the N applications, it further includes: obtaining an original machine learning model and sample user claim data; extracting feature values from the sample account information and sample actual user information in the sample user claim data; and training the original machine learning model using the feature values and the corresponding relationship between the sample account and the sample actual user to obtain the target machine learning model.

[0050] It should be noted that before inputting the account information in the N applications into a preset machine learning model to determine the actual user information corresponding to the account information, the machine learning model needs to be trained. The original machine learning model is a basic model constructed based on a specific algorithm, such as decision tree, random forest, support vector machine, neural network, etc. In its initial state, this model may not have been trained with any specific data, so its prediction ability is generalized and needs to be trained to adapt to a specific account matching task. The sample user claim data is historical data used to train the model, which contains known account information and corresponding actual user information, as well as the association rules between the account and the actual user. Data collection may involve extracting historical records from the user system (UCM) and the configuration system (CMDB), as well as obtaining the real identity and role information of users from other data sources. Data processing includes cleaning, formatting, and feature extraction to ensure data quality and model training effect. Then, feature values are extracted to convert the original data into a form that the model can understand. For account information, possible feature values include: the login frequency of the account. The active time distribution of the account. The security policy of the account, such as password strength, locking mechanism. The access record of the account, including the accessed applications, access time, and frequency. For actual user information, feature values that can be extracted are: the department affiliation of the employee. The job responsibilities and permissions of the employee. The login habits of the employee, such as the usual login time and location. The role and identity of the employee, such as administrator, developer, tester, etc. Using the extracted feature values and the corresponding relationship between the sample account and the actual user, the original machine learning model is trained. The training process is a process in which the model learns how to infer account ownership from the feature values. The model will learn which feature values are most critical for account matching and how these feature values are combined to predict the actual user of the account. After training, the model can also be optimized and verified to ensure its accuracy and robustness in actual applications. For example, model parameter tuning: adjusting the hyperparameters of the model to improve prediction accuracy. Cross-validation: using cross-validation techniques to evaluate the generalization ability of the model. Anomaly detection: checking for anomalies or unreasonable matches in the model prediction results and performing manual proofreading and correction.

[0051] Through the above steps, the finally obtained target machine learning model can make predictions based on the eigenvalue of the account information and accurately associate the account information with the actual user information. This model can be used to automatically process the account claiming problems in N applications, improving the efficiency and security of user management. During the application process of the model, it is also necessary to retrain and adjust the model regularly to adapt to new data patterns and business requirements.

[0052] Optionally, in the account matching method provided in the embodiment of the present application, when inputting the account information included in each of the N applications into a preset target machine learning model to determine the actual user information corresponding to the account information included in each of the N applications, it further includes: generating a confirmation message, where the confirmation message is used to confirm whether the corresponding relationship between the account information and the actual user information matches; sending the confirmation message to the account corresponding to the account information; and when receiving the confirmation that the corresponding relationship matches returned by the account, determining that the corresponding relationship between the account information and the actual user information matches.

[0053] It should be noted that during the process of inputting the account information in the N applications into the preset target machine learning model to determine the actual user information corresponding to the account information, the confirmation message can be sent again to improve the accuracy of account identification. For the matching result of each account, a confirmation message can be automatically generated and sent together with the predicted actual user information. The confirmation message usually includes a unique identifier for tracking the confirmation status. Sending the generated confirmation message to the account corresponding to the account information is usually carried out by means of email, in-system message or SMS, etc. When sending, the security of the information should be ensured, and encryption or a secure communication protocol should be used to prevent the leakage of information during transmission. The system waits for the response of the account holder to the confirmation message, and a reasonable time limit can be set for the response time, such as within 24 hours. This step is to ensure that the actual user of the account has enough time to check and confirm the accuracy of the matching result. If the confirmation from the account holder is received within the set time and the confirmation indicates that the corresponding relationship matches, the system will finally determine that the corresponding relationship between the account information and the actual user information matches and record this confirmation result in the user security control platform for subsequent permission management and behavior monitoring.

[0054] Through this process, it can be ensured that the corresponding relationship between the account predicted by the machine learning model and the actual user information has been confirmed by the user, thereby improving the accuracy and reliability of account matching. This is crucial for user security management, permission allocation, and compliance checking, and can effectively avoid security risks and management chaos caused by incorrect account ownership.

[0055] Optionally, in the account matching method provided in the embodiments of the present application, when receiving a confirmation that the corresponding relationship does not match returned by the account, determine the account information as redundant data and clear the redundant data.

[0056] It should be noted that for accounts that do not respond within the specified time or do not confirm the matching result, the system should set up subsequent processes, such as: resending the confirmation information to give the account holder a second chance to confirm. Mark the account as pending review and conduct manual review by the administrator or department head. For accounts that truly do not match, re-perform model prediction or manually adjust the attribution information of the account. The status and historical usage of the account can be analyzed to determine whether the account is redundant data. Redundant data refers to data that is no longer needed, no longer used, or does not match the current system state. The following points can be checked: Account activity: Check the recent login and operation records of the account. If the account has been inactive for a long time, it may be redundant. Account permissions and usage scenarios: If the account permissions do not match the actual requirements of the application, or the usage scenario of the account has nothing to do with the server's business, it may be marked as redundant. Matching degree with actual user information: If multiple feedbacks indicate that the attribution of the account cannot be correctly matched to the actual user, the system should regard it as redundant data. If it is confirmed that the account is redundant data, the account can be marked in the User Centralized Management System (UCM). The marking usually includes setting the account status to "redundant" or "pending deletion", and recording the reason why the account is marked as redundant. Before clearing the redundant data, a data backup operation can be performed to prevent accidental deletion or unforeseen problems during the deletion operation. The backup should include detailed information of the account, such as account name, permission settings, security policies, recent login records, and operation logs, etc. After confirming that all necessary security and confirmation steps are completed, the operation of clearing the redundant data will be executed. This may include deleting the account from the UCM, or setting its permissions to the lowest level to ensure that it does not pose a security threat to the existing system. At the same time, the access permissions of the account should be removed from any relevant servers, applications, or resources. After clearing the redundant data, the system should send notifications to relevant user managers, application maintenance personnel, and other team members who may be affected, informing them that the account has been confirmed as redundant and has been removed. Through such a process, the system can effectively identify and process redundant account data that no longer meets the current requirements, thereby maintaining the accuracy of user information and the efficient utilization of system resources, while reducing potential security risks.

[0057] Optionally, in the account matching method provided in the embodiments of the present application, monitor the behaviors of accounts in the user system; in the case where abnormal behaviors of a target account are monitored in the user system, back up the account information of the target account to obtain backup account information; delete the account information of the target account; in the case where the user system is abnormal within a preset time period after deleting the account information of the target account, regenerate the target account based on the backup account information.

[0058] It should be noted that the behavior patterns of all accounts in the user system can be continuously monitored, including login frequency, operation type, login time, accessed resources, etc. The monitoring mechanism can be real-time or periodic, depending on the system performance and security policies. Through a preset behavior analysis algorithm or machine learning model, the system can identify abnormal behaviors that do not conform to the normal behavior patterns, such as frequently failed login attempts, sensitive operations during non-working hours, and abnormally high data access volumes. Once an abnormal behavior is detected, the target account will be marked as "behavior abnormal". Before preparing to delete the target account with abnormal behavior, the system will automatically back up all relevant information of the account. The backup information should include but is not limited to account name, permission settings, security policies, recent login records, operation logs, and related server and application information. This step ensures that even after the deletion operation, if necessary, the account information can still be restored from the backup. After confirming that the backup is complete, the process of deleting the target account will be executed. The deletion operation should ensure that the association between the account and all relevant resources is completely removed, including but not limited to removing the account from the user central management system (UCM), revoking the access permissions of the account in the server and applications, and clearing any sensitive data related to the account. After deleting the target account, an abnormal monitoring period of a preset time period, such as 24 hours, can be entered. This is to observe whether the deletion of the target account has a negative impact on the normal operation of the user system or related applications. The monitoring metrics may include system performance, application availability, login and operation behaviors of other accounts, etc. If an abnormality in the user system is monitored within the preset time period and the analysis shows that the abnormality is caused by the deletion of the target account, the system will automatically trigger a fallback mechanism. Based on the previously backed-up account information, the system can regenerate the target account and restore its permissions and settings, so as to quickly restore the normal state of the system or application. In addition, the system will also record this event, including the cause of the abnormality, the details of the fallback operation, and subsequent processing suggestions, for in-depth analysis and formulation of preventive measures.

[0059] Through such a process, even in the face of abnormal account behaviors, its security and stability can be maintained, and at the same time, it is ensured that a quick fallback can be made when necessary, reducing the risk of business interruption. This closed-loop monitoring and management mechanism is particularly important for large and complex enterprise-level systems and can effectively cope with various security threats and operation errors.

[0060] Figure 3 is a timing diagram of the account matching method provided according to an alternative embodiment of the present application. As Figure 3 shown, it includes:

[0061] 1. The user administrator sets a scheduled task: The user administrator sets a scheduled task in the user security control system. This task can be periodic, such as once a week, and is used to automatically initiate the user rectification process.

[0062] 2. The system automatically sorts out the users who need to be rectified: When the scheduled task is executed, the system will automatically analyze the user data in the User Centralized Management System (UCM) and identify the users who need security policy adjustments, deletions, or permission changes.

[0063] 3. Send the rectification list to the user owner: The system sends the list of users who need to be rectified to the corresponding user owners (usually the application maintainers or the actual users of the accounts), and requests them to make a second confirmation to decide which users need to be actually adjusted.

[0064] 4. Feedback the result of the second confirmation: The user owners review the rectification list and confirm which users need to adjust the security policy, which users need to be deleted, and which users can remain unchanged. They feedback the confirmation result to the system.

[0065] 5. User backup and automated rectification: For the users confirmed to need adjustment or deletion, the system first makes a user backup to save the original state information of the users, including but not limited to passwords, permissions, security policies, etc. Then, the system automatically adjusts the security policies of the users or deletes redundant users according to the confirmed rectification plan.

[0066] 6. Application and user monitoring: After the rectification is completed, the system enters the monitoring stage and monitors the abnormal behaviors of all rectified users for 24 hours. This includes monitoring the user login status, operation behaviors, and the system's response after the rectification.

[0067] 7. Abnormal behavior is detected: If abnormal user behaviors are detected during the monitoring process, such as being frequently locked, multiple login failures, or application anomalies, the system will take immediate actions.

[0068] 8. Send the information of abnormal users to the user administrator: After the system detects an abnormality, it will send the specific information of the abnormal users to the user administrator, including the type and time of the abnormal behavior, as well as the possible reasons.

[0069] 9. Send the information of abnormal users to the user owner: At the same time, the system will also send the abnormal information to the user owners so that they can conduct more detailed inspections and problem positioning.

[0070] 10. Automatic fallback mechanism: For anomalies confirmed to be caused by rectification, the system will automatically trigger the fallback mechanism and use the backup information to restore the user to the state before rectification to avoid further system problems.

[0071] 11. Problem analysis and recording: User managers and user owners will analyze abnormal behaviors and record the causes and solutions of the problems.

[0072] The account matching method provided by the embodiment of the present application obtains the account information included in each of the N applications in the user system and the corresponding relationship between the account information included in each of the N applications and the server in the configuration system, where N is an integer greater than 0; inputs the account information included in each of the N applications into a preset target machine learning model to determine the actual user information corresponding to the account information included in each of the N applications, where the actual user information represents the identity authentication information of the user corresponding to the account information, and the target machine learning model is trained through sample user claim data, and the sample user claim data includes sample account information, sample actual user information, and the corresponding relationship between the sample account and the sample actual user; based on the corresponding relationship between the account and the server in the configuration system, determines the actual user information corresponding to the server, achieving the purpose of matching the server, account information, and user information through the machine learning model, thereby realizing the technical effect of reducing the probability of account matching errors, and further solving the technical problem in the related art that it is difficult to correspond the account information corresponding to different servers with specific user information, resulting in easy occurrence of account matching errors.

[0073] It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.

[0074] Embodiment 2

[0075] The embodiment of the present application also provides an account matching device. It should be noted that the account matching device of the embodiment of the present application can be used to execute the account matching method provided by the embodiment of the present application. The account matching device provided by the embodiment of the present application is introduced below.

[0076] According to the embodiment of the present application, there is also provided an account matching device for implementing the above account matching method. Figure 4 is the structural block diagram of the account matching device provided by the embodiment of the present application, as Figure 4 shown, the device includes:

[0077] An obtaining module 41 is configured to obtain the account information included in each of the N applications in the user system and the corresponding relationship between the account information included in each of the N applications and the server in the configuration system, where N is an integer greater than 0.

[0078] An input module 42 is connected to the obtaining module 41 and is configured to input the account information included in each of the N applications into a preset target machine learning model to determine the actual user information corresponding to the account information included in each of the N applications, where the actual user information represents the identity authentication information of the user corresponding to the account information, and the target machine learning model is trained by using sample user claim data, and the sample user claim data includes sample account information, sample actual user information, and the corresponding relationship between the sample account and the sample actual user.

[0079] A determining module 43 is connected to the input module 42 and is configured to determine the actual user information corresponding to the server based on the corresponding relationship between the account and the server in the configuration system.

[0080] The account matching device provided by the embodiment of the present application achieves the purpose of matching the server, the account information, and the user information through a machine learning model, thereby realizing the technical effect of reducing the probability of account matching errors, and further solving the technical problem in the related art that it is difficult to correspond the account information corresponding to different servers to specific user information, resulting in easy occurrence of account matching errors. Optionally, in the Z device provided by the embodiment of the present application,

[0081] Optionally, in the account matching device provided by the embodiment of the present application, the obtaining module is configured to obtain the account information included in each of the N applications in the user system and the corresponding relationship between the account information included in each of the N applications and the server in the configuration system, including: setting an interval duration; collecting the account information included in each of the N applications in the user system and the server information in the configuration system based on the interval duration; and determining the corresponding relationship between the account information included in each of the N applications and the server in the configuration system based on the account information included in each of the N applications in the user system and the server information in the configuration system.

[0082] Optionally, in the account matching device provided by the embodiment of the present application, the account information includes an account name, an application name corresponding to the account, and an account IP address, and the server information includes an application name, a server address, and environment resource information corresponding to the server.

[0083] Optionally, in the account matching device provided in the embodiments of the present application, before the input module is used to input the account information included in each of the N applications into a preset target machine learning model to determine the actual user information corresponding to the account information included in each of the N applications, it further includes: obtaining an original machine learning model and sample user claim data; extracting eigenvalue in the sample account information and sample actual user information in the sample user claim data; and using the eigenvalue and the corresponding relationship between the sample account and the sample actual user to train the original machine learning model to obtain the target machine learning model.

[0084] Optionally, in the account matching device provided in the embodiments of the present application, the input module is used to input the account information included in each of the N applications into a preset target machine learning model to determine the actual user information corresponding to the account information included in each of the N applications, and it further includes: generating a confirmation message, where the confirmation message is used to confirm whether the corresponding relationship between the account information and the actual user information matches; sending the confirmation message to the account corresponding to the account information; and when receiving the confirmation that the corresponding relationship matches returned by the account, determining that the corresponding relationship between the account information and the actual user information matches.

[0085] Optionally, in the account matching device provided in the embodiments of the present application, when receiving the confirmation that the corresponding relationship does not match returned by the account, determining that the account information is redundant data and clearing the redundant data.

[0086] Optionally, in the account matching device provided in the embodiments of the present application, monitor the behavior of the accounts in the user system; when monitoring that the behavior of a target account in the user system is abnormal, back up the account information of the target account to obtain backup account information; delete the account information of the target account; and when a user system exception occurs within a preset time period after deleting the account information of the target account, regenerate the target account based on the backup account information.

[0087] It should be noted here that the above-mentioned obtaining module 41, input module 42, and determining module 43 correspond to steps S201 to S203 in Embodiment 1. The functions of the two modules and the corresponding steps are the same in terms of the implemented examples and application scenarios, but are not limited to the content disclosed in the above-mentioned Embodiment 1. It should be noted that the above-mentioned module or unit can be a hardware component or a software component stored in a memory (for example, memory 104) and processed by one or more processors (for example, processors 102a, 102b,..., 102n), and the above-mentioned module can also be a part of the device and can run in the computer terminal 10 provided in Embodiment 1.

[0088] Embodiment 3

[0089] Embodiments of the present application also provide a storage medium. Optionally, in this embodiment, the above storage medium may be used to store the program code executed by the account matching method provided in the first embodiment above.

[0090] Optionally, in this embodiment, the above storage medium may be located in any one of the computer terminals in the computer terminal group in the computer network, or in any one of the mobile terminals in the mobile terminal group.

[0091] Embodiment 4

[0092] Embodiments of the present application may provide an electronic device. Figure 5 It is a structural block diagram of an electronic device provided according to an embodiment of the present application. As Figure 5 shown, the electronic device may include: one or more ( Figure 5 only one is shown in the figure) processors 502, a memory 504, a storage controller, and a peripheral interface, where the peripheral interface is connected to a radio frequency module, an audio module, and a display.

[0093] Among them, the memory can be used to store software programs and modules, such as the program instructions / modules corresponding to the methods and devices in the embodiments of the present application. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, that is, implements the above methods. The memory may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some instances, the memory may further include a memory remotely provided relative to the processor, and these remote memories may be connected to the terminal through a network. Examples of the above network include but are not limited to the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.

[0094] The processor can call the information and application programs stored in the memory through a transmission device to perform the following steps: obtaining the account information included in each of the N applications in the user system and the corresponding relationship between the account information included in each of the N applications and the server in the configuration system, where N is an integer greater than 0; inputting the account information included in each of the N applications into a preset target machine learning model to determine the actual user information corresponding to the account information included in each of the N applications, where the actual user information represents the identity authentication information of the user corresponding to the account information, and the target machine learning model is trained through sample user claim data, and the sample user claim data includes sample account information, sample actual user information, and the corresponding relationship between the sample account and the sample actual user; determining the actual user information corresponding to the server based on the corresponding relationship between the account and the server in the configuration system.

[0095] The processor can also call the information and application programs stored in the memory through the transmission device to execute the following steps: Obtain the account information included in each of the N applications in the user system and the correspondence between the account information included in each of the N applications and the servers in the configuration system, including: setting an interval duration; collecting, based on the interval duration, the account information included in each of the N applications in the user system and the server information in the configuration system; and determining, based on the account information included in each of the N applications in the user system and the server information in the configuration system, the correspondence between the account information included in each of the N applications and the servers in the configuration system.

[0096] The processor can also call the information and application programs stored in the memory through the transmission device to execute the following steps: The account information includes the account name, the application name corresponding to the account, and the account IP address, and the server information includes the application name, the server address, and the environmental resource information corresponding to the server.

[0097] The processor can also call the information and application programs stored in the memory through the transmission device to execute the following steps: Before determining the actual user information corresponding to the account information included in each of the N applications by inputting the account information included in each of the N applications into a preset target machine learning model, it further includes: obtaining the original machine learning model and sample user claim data; extracting the feature values in the sample account information and the sample actual user information in the sample user claim data; and training the original machine learning model with the feature values and the correspondence between the sample accounts and the sample actual users to obtain the target machine learning model.

[0098] The processor can also call the information and application programs stored in the memory through the transmission device to execute the following steps: When inputting the account information included in each of the N applications into a preset target machine learning model to determine the actual user information corresponding to the account information included in each of the N applications, it further includes: generating a confirmation message, where the confirmation message is used to confirm whether the correspondence between the account information and the actual user information matches; sending the confirmation message to the account corresponding to the account information; and determining that the correspondence between the account information and the actual user information matches when receiving the confirmation that the correspondence matches returned by the account.

[0099] The processor can also call the information and application programs stored in the memory through the transmission device to execute the following steps: When receiving the confirmation that the correspondence does not match returned by the account, determine that the account information is redundant data and clear the redundant data.

[0100] The processor can also call the information and application programs stored in the memory through the transmission device to perform the following steps: monitor the behaviors of the accounts in the user system; in the case where abnormal behaviors of a target account are detected in the user system, back up the account information of the target account to obtain backup account information; delete the account information of the target account; in the case where the user system is abnormal within a preset time period after deleting the account information of the target account, regenerate the target account based on the backup account information.

[0101] By adopting the embodiment of the present application, a method for account matching is provided. By obtaining the account information included in each of the N applications in the user system and the corresponding relationship between the account information included in each of the N applications and the server in the configuration system, where N is an integer greater than 0; inputting the account information included in each of the N applications into a preset target machine learning model to determine the actual user information corresponding to the account information included in each of the N applications, where the actual user information represents the identity authentication information of the user corresponding to the account information, and the target machine learning model is trained through sample user claim data, and the sample user claim data includes sample account information, sample actual user information, and the corresponding relationship between the sample account and the sample actual user; based on the corresponding relationship between the account and the server in the configuration system, determine the actual user information corresponding to the server, achieving the purpose of matching the server, account information, and user information through the machine learning model, thereby realizing the technical effect of reducing the probability of account matching errors, and further solving the technical problem in the related art that it is difficult to correspond the account information corresponding to different servers with specific user information, resulting in easy occurrence of account matching errors.

[0102] Those of ordinary skill in the art can understand that Figure 5 The structure shown is only for illustration, and the electronic device can also be a smart phone (such as an Android phone, an iOS phone, etc.), a tablet computer, a handheld computer, and terminal devices such as Mobile Internet Devices (MID), PAD, etc. Figure 5 It does not limit the structure of the above electronic device. For example, the electronic device may further include more or fewer components (such as a network interface, a display device, etc.) than those shown in Figure 5 or have a different configuration from that shown in Figure 5 shown.

[0103] Those of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by a program instructing the hardware related to the terminal device. This program can be stored in a computer-readable storage medium, and the storage medium can include: a flash drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, an optical disc, etc.

[0104] Embodiment 5

[0105] The present application also provides a computer program product, which is suitable for executing a program for performing the steps of any one of the above account matching methods when executed on a data processing device.

[0106] The serial numbers of the above embodiments of the present application are only for description and do not represent the advantages or disadvantages of the embodiments.

[0107] In the above embodiments of the present application, the descriptions of each embodiment have their own emphases. For the parts not detailed in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0108] In several embodiments provided by the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed mutual coupling or direct coupling or communication connection can be through some interfaces. The indirect coupling or communication connection of units or modules can be in an electrical or other form.

[0109] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0110] In addition, the functional units in each embodiment of the present application can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.

[0111] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), mobile hard disks, magnetic disks, or optical discs.

[0112] The above are only the preferred embodiments of this application. It should be noted that for those of ordinary skill in the art, without departing from the principle of this application, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of this application.

Claims

1. An account matching method, characterized in that: include: Obtaining account information included in each of N applications in the user system and a correspondence between the account information included in each of the N applications and a server in the configuration system, where N is an integer greater than 0; Input the account information included in each of the N applications into a preset target machine learning model to determine the actual user information corresponding to the account information included in each of the N applications, wherein the actual user information represents the identity authentication information of the user corresponding to the account information, and the target machine learning model is trained by sample user claiming data, and the sample user claiming data includes sample account information, sample actual user information, and the correspondence between the sample account and the sample actual user; Based on the correspondence between the account and the server in the configuration system, actual user information corresponding to the server is determined.

2. The method according to claim 1, characterized in that The obtaining of the account information respectively included in the N applications in the user system and the corresponding relationship between the account information respectively included in the N applications and the server in the configuration system includes: Set the interval duration; Based on the interval duration, collecting account information respectively included in N applications in the user system and server information in the configuration system; Based on the account information respectively included in the N applications in the user system and the server information in the configuration system, a corresponding relationship between the account information respectively included in the N applications and the server in the configuration system is determined.

3. The method according to claim 2, characterized in that Also includes: The account information includes the account name, the application name corresponding to the account and the account IP address, and the server information includes the application name, the server address and the environment resource information corresponding to the server.

4. The method according to claim 1, characterized in that Before inputting the account information included in each of the N applications into a preset target machine learning model to determine the actual user information corresponding to the account information included in each of the N applications, the method further includes: Obtaining the original machine learning model and the sample user claiming data; Extracting feature values ​​from sample account information and sample actual user information in the sample user claiming data; The target machine learning model is obtained by using the characteristic value and the correspondence between the sample account and the actual user of the sample to the original machine learning model.

5. The method according to claim 1, characterized in that The inputting the account information included in each of the N applications into a preset target machine learning model to determine the actual user information corresponding to the account information included in each of the N applications further includes: Generate confirmation information, wherein the confirmation information is used to confirm whether the corresponding relationship between the account information and the actual user information matches; Sending the confirmation information to the account corresponding to the account information; When receiving the confirmation that the corresponding relationship matches returned by the account, it is determined that the corresponding relationship between the account information and the actual user information matches.

6. The method according to claim 5, characterized in that Also includes: In the case that the confirmation correspondence received from the account does not match, the account information is determined to be redundant data, and the redundant data is cleared.

7. The method according to any one of claims 1 to 6, characterized in that: Also includes: Monitor the behavior of accounts in the user's system; When abnormal behavior of the target account is detected in the user system, the account information of the target account is backed up to obtain backup account information; Deleting the account information of the target account; In the event that the user system abnormality occurs within a preset period of time after the account information of the target account is deleted, the target account is regenerated based on the backup account information.

8. An account matching device, characterized in that: include: An acquisition module, used to acquire account information included in each of N applications in the user system and a correspondence between the account information included in each of the N applications and a server in the configuration system, where N is an integer greater than 0; An input module, used to input the account information included in each of the N applications into a preset target machine learning model, and determine the actual user information corresponding to the account information included in each of the N applications, wherein the actual user information represents the identity authentication information of the user corresponding to the account information, and the target machine learning model is trained by sample user claiming data, and the sample user claiming data includes sample account information, sample actual user information, and a correspondence between a sample account and a sample actual user; The determination module is used to determine the actual user information corresponding to the server based on the corresponding relationship between the account and the server in the configuration system.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium includes a stored executable program, wherein when the executable program is executed, the device where the computer-readable storage medium is located is controlled to execute the account matching method according to any one of claims 1 to 7.

10. An electronic device, characterized in that: include: A memory storing an executable program; A processor, configured to run the program, wherein the program, when running, executes the account matching method described in any one of claims 1 to 7.

11. A computer program product comprising computer instructions, characterized in that: When the computer instructions are executed by a processor, the steps of the account matching method described in any one of claims 1 to 7 are implemented.