Account permission determination method and device and nonvolatile storage medium

By identifying the change operation instructions in the change work order and dynamically issuing account permissions, the problem of static and manual reliance on account permissions in the existing technology is solved, and efficient and secure dynamic authorization management of account change operations is achieved.

CN120180466APending Publication Date: 2025-06-20CHINA TELECOM CORP LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510240785.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-28
Publication Date
2025-06-20

AI Technical Summary

Technical Problem

In the prior art, the authorization of account permissions depends on static authorization configuration and manual approval, and cannot be dynamically adjusted, resulting in low operational efficiency and prone to operational risks.

Method used

By receiving a change ticket, identifying the change operation instructions, and determining the change operation permissions of the target account based on the identification results, issuing permissions within the change operation time period to ensure that the account only performs the change operation within the specified time period.

Benefits of technology

It realizes dynamic authorization management for account change operations, improves operation efficiency, reduces operation risks, and ensures refined control of account permissions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120180466A_ABST
    Figure CN120180466A_ABST
Patent Text Reader

Abstract

The invention discloses an account permission determination method and device and a nonvolatile storage medium. The method comprises the following steps: receiving a change work order; identifying the change work order to obtain an identification result which at least comprises a change operation instruction; based on the identification result, determining a change operation authority of the target account corresponding to the identification result, the change operation authority being an execution authority of the target account for executing the change operation instruction in the change operation time period; and issuing the change operation authority to the target account in the change operation time period. According to the method and the device, the technical problems that the operation efficiency is low and the operation risk is easy to occur due to the fact that the authorization of the account permission is configured through static authorization and depends on manual operation and the change operation of the account cannot be supervised in the related technology are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security. Specifically, it relates to a method, device, and non-volatile storage medium for determining account permissions. Background Art

[0002] In the wave of digital transformation, cloud network security has become the focus of attention in the field of information communication. To ensure the secure, stable, and efficient operation of the cloud network system, it is necessary to vigorously promote the construction of a large-scale maintenance and security system and emphasize the digital upgrade of the entire process. In this process, the management of change operations becomes particularly important because it directly affects the stability of the network and the quality of service. However, there are obvious limitations in the security operation and maintenance audit system in the related technology, especially in the control and supervision of change operations, which are difficult to meet the current high standards.

[0003] In the related technology, the access operation and maintenance authorization mechanism mainly relies on the 4A system (i.e., account management, authentication, authorization, and audit) or the bastion host system for static authorization configuration. This authorization method has a rough management and is not fine enough in controlling the changes of accounts. Although the change operations of character commands can be controlled to a certain extent through instruction-level authorization, this authorization is usually statically set and cannot be dynamically adjusted according to the specific requirements of the change work order. Even if dynamic privilege elevation is achieved through the vault mode, it is required that the vault auditor has a deep understanding of the change operation and can quickly judge the rationality of the operation. This manual approval method is difficult to be strictly effective, especially in emergency or complex change scenarios. In addition, the current technical solutions are difficult to automatically and timely detect the operation progress of change operations, including whether they are timed out, whether there are abnormalities or violations. It often relies on manual reporting or inquiries, which is not only inefficient but also prone to information lag, affecting the timely response and handling of faults.

[0004] For the above problems, no effective solutions have been proposed yet. Summary of the Invention

[0005] Embodiments of the present application provide a method, device, and non-volatile storage medium for determining account permissions, so as to at least solve the technical problems in the related technology that the authorization of account permissions is through static authorization configuration, relying on manual operations, unable to implement supervision on the change operations of accounts, resulting in low operation efficiency and prone to operation risks.

[0006] According to one aspect of the embodiments of the present application, a method for determining account permissions is provided, including: receiving a change work order; identifying the change work order to obtain an identification result, where the identification result at least includes: a change operation instruction; based on the identification result, determining the change operation permission of the target account corresponding to the identification result, where the change operation permission is the execution permission for the target account to execute the change operation instruction during the change operation time period; and issuing the change operation permission to the target account during the change operation time period.

[0007] In some embodiments of the present application, the identification result further includes: a change operation time period, change operator information, change operation asset information, and change operation instruction information, where the change operation indicated in the change operation instruction information at least includes a graphic type change operation or an instruction type change operation.

[0008] In some embodiments of the present application, based on the identification result, determining the change operation permission of the target account corresponding to the identification result includes: determining the change operation time period, change operation asset information, and change operation instruction information from the identification result; determining an access control rule for the target account during the change operation time period based on the change operation asset information and the change operation instruction information, where the access control rule at least includes the change operation asset information allowed to be accessed by the target account during the change operation time period and the change operation instructions allowed to be executed; and determining the change operation permission of the target account corresponding to the identification result based on the access control rule.

[0009] In some embodiments of the present application, when the operation instruction information includes a graphic type operation, issuing the change operation permission to the target account during the change operation time period includes: issuing the change operation permission to the target account through a network element device within a first preset time period before the change operation time period; the method further includes: recovering the change operation permission from the target account through the network element device within a second preset time period after the change operation time period.

[0010] In some embodiments of the present application, when the operation instruction information includes an instruction type operation, issuing the change operation permission to the target account during the change operation time period includes: issuing the change operation permission to the target account based on a control policy during the change operation time period, where the control policy is used to instruct the target account to execute the change operation instruction corresponding to the change operation permission and intercept instructions other than the change operation instruction corresponding to the change operation permission; the method further includes: recovering the change operation permission from the target account within a third preset time period after the change operation time period.

[0011] In some embodiments of the present application, the method further includes: during the change operation time period, collecting instruction logs corresponding to operation instructions executed by the target account at every fourth preset time period; determining the change operation progress and change operation compliance index of the target account based on the access control rules and the instruction logs; and pushing the change operation progress and change operation compliance index of the target account to the monitoring terminal.

[0012] In some embodiments of the present application, determining the change operation progress and change operation compliance index of the target account based on the access control rules and the instruction logs includes: determining the matching degree between the instructions included in the instruction logs and the change operation instructions in the access control rules based on the AI large model, and determining the change operation progress based on the matching degree; performing change operation compliance identification on the instructions included in the instruction logs based on the AI large model to obtain a change operation compliance result, where the change operation compliance result includes risk characteristics corresponding to the instructions; and determining the change operation compliance index based on the change operation compliance result.

[0013] In some embodiments of the present application, the method further includes: when the change operation compliance index is greater than the first preset threshold, updating the change work order to the change plan knowledge base; determining the operation proficiency of the target account based on the change operation progress and the change operation compliance index, and when the operation proficiency of the target account is greater than the second preset threshold, updating the operator name and operator number corresponding to the target account to the change operation talent pool.

[0014] According to another aspect of the embodiments of the present application, there is also provided a device for determining account permissions, including: a receiving module for receiving a change work order; an identifying module for identifying the change work order to obtain an identification result, where the identification result at least includes: a change operation instruction; a determining module for determining, based on the identification result, the change operation permission of the target account corresponding to the identification result, where the change operation permission is the execution permission for the target account to execute the change operation instruction during the change operation time period; and a sending module for sending the change operation permission to the target account during the change operation time period.

[0015] According to another aspect of the embodiments of the present application, there is also provided a non-volatile storage medium storing a program, where when the program runs, it controls the device where the non-volatile storage medium is located to execute the account permission determination method described in any one of the above.

[0016] According to another aspect of the embodiments of the present application, there is also provided an electronic device, including: a memory and a processor, where the processor is used to run the program stored in the memory, and when the program runs, it executes the account permission determination method described in any one of the above.

[0017] According to another aspect of the embodiments of the present application, there is also provided a computer program product, including computer instructions, which implement the method for determining account permissions described in any one of the above when executed by a processor.

[0018] In the embodiments of the present application, the method includes receiving a change work order; identifying the change work order to obtain an identification result, where the identification result at least includes: a change operation instruction; based on the identification result, determining the change operation permission of the target account corresponding to the identification result, where the change operation permission is the execution permission for the target account to execute the change operation instruction during the change operation time period; and issuing the change operation permission to the target account within the change operation time period. By identifying the change work order to obtain the identification result, then further determining the change operation permission of the target account corresponding to the identification result, and finally issuing the change operation permission to the target account within the change operation time period, the purpose of automatically issuing the change operation permission to the target account within the specified change operation time period and only allowing the target account to execute the change operation within the change operation time period is achieved. Furthermore, the technical problem in the related art that the authorization of account permissions is configured through static authorization and depends on manual operation, and it is impossible to implement supervision over the change operations of accounts, resulting in low operation efficiency and easy occurrence of operation risks is solved. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation to the present application. In the drawings:

[0020] Figure 1 is a hardware structure block diagram of a computer terminal for implementing the method for determining account permissions according to an embodiment of the present application;

[0021] Figure 2 is a flowchart of a method for determining account permissions according to an embodiment of the present application;

[0022] Figure 3 is a flowchart of another method for determining account permissions according to an embodiment of the present application;

[0023] Figure 4 is an operation flowchart of a method for determining account permissions according to an embodiment of the present application;

[0024] Figure 5 is a structural schematic diagram of a device for determining account permissions according to an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0025] To enable those skilled in the art to better understand the solution of this application, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this application without creative efforts shall fall within the scope of protection of this application.

[0026] The information collected in the embodiments of this application is information and data authorized by the user or fully authorized by all parties. Moreover, for the processing of relevant data such as collection, storage, use, processing, transmission, provision, disclosure, and application, all comply with the relevant laws, regulations, and standards of the relevant regions, necessary confidentiality measures are taken, it does not violate public order and good customs, and a corresponding operation entry is provided for the user to choose to authorize or reject the automated decision-making result; if the user chooses to reject, the expert decision-making process will be entered.

[0027] It should be noted that the terms "first", "second", etc. in the description and claims of this application and the above-mentioned accompanying drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of this application described here can be implemented in an order other than those illustrated or described here. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.

[0028] To better understand the embodiments of this application, the technical terms involved in the embodiments of this application are explained as follows:

[0029] Work order system: A process approval system. When applying for a change operation, submit the change plan description to the work order system, and relevant stakeholders will confirm and approve it. The plan can be executed only after the approval passes.

[0030] In the related art, the access operation and maintenance authorization mechanism mainly relies on the 4A system (i.e., account management, authentication, authorization, and auditing) or the bastion host system for static authorization configuration. This authorization method has extensive management and is not fine enough in controlling account changes. Therefore, there is a technical problem in the related art that the authorization of account permissions is configured through static authorization and relies on manual operations, and it is impossible to implement supervision over account change operations, resulting in low operation efficiency and prone to operation risks. To solve this problem, relevant solutions are provided in the embodiments of this application, which are described in detail below.

[0031] According to an embodiment of the present application, an embodiment of a method for determining account permissions is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. And although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.

[0032] The method embodiment provided by the embodiment of the present application can be executed in a computer terminal or a similar computing device. Figure 1 A hardware structure block diagram of a computer terminal for implementing a method for determining account permissions is shown. As Figure 1 shown, the computer terminal 10 may include one or more (shown as 102a, 102b,..., 102n in the figure) processors 102 (the processor 102 may include, but is not limited to, a processing device such as a microprocessor MCU or a programmable logic device FPGA), a memory 104 for storing data, and a transmission device 106 for communication functions. In addition, it may further include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the BUS bus), a network interface, a power supply, and / or a camera. Those of ordinary skill in the art can understand that Figure 1 the structure shown is only illustrative and does not limit the structure of the above-mentioned electronic device. For example, the computer terminal 10 may further include more or fewer components than those Figure 1 shown, or have a different configuration from those Figure 1 shown.

[0033] It should be noted that the above one or more processors 102 and / or other data processing circuits can generally be referred to as "data processing circuits" in this article. The data processing circuit can be embodied in software, hardware, firmware, or any combination thereof, in whole or in part. In addition, the data processing circuit can be a single independent processing module, or be incorporated in whole or in part into any one of the other elements in the computer terminal 10. As involved in the embodiment of the present application, the data processing circuit is a kind of processor control (such as the selection of a variable resistance terminal path connected to an interface).

[0034] The memory 104 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the method for determining account permissions in the embodiments of the present application. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, that is, implements the above-mentioned method for determining account permissions. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some instances, the memory 104 may further include a memory remotely disposed relative to the processor 102, and these remote memories can be connected to the computer terminal 10 through a network. Examples of the above-mentioned network include but are not limited to the Internet, enterprise intranet, local area network, mobile communication network, and combinations thereof.

[0035] The transmission device 106 is used to receive or send data via a network. Specific examples of the above-mentioned network may include a wireless network provided by a communication provider of the computer terminal 10. In one instance, the transmission device 106 includes a network adapter (Network Interface Controller, NIC), which can be connected to other network devices through a base station and thus communicate with the Internet. In one instance, the transmission device 106 can be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.

[0036] The display can be, for example, a touch-screen liquid crystal display (LCD), and the liquid crystal display enables a user to interact with the user interface of the computer terminal 10.

[0037] Under the above operating environment, an embodiment of a method for determining account permissions is provided in the embodiments of the present application. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.

[0038] As Figure 2 shown, it is a flowchart of a method for determining account permissions provided in an embodiment of the present application, including:

[0039] Step S202, receiving a change work order; identifying the change work order to obtain an identification result, where the identification result at least includes: a change operation instruction.

[0040] In the technical solution provided in step S202, the recognition result further includes: the change operation time period, the change operator information, the change operation asset information, and the change operation instruction information. Among them, the change operation indicated in the change operation instruction information includes at least a graphic change operation or an instruction change operation. It should be noted that in order to ensure strict management of change operations, the account permissions will be cleared first. That is, the operation and maintenance system of this application will revoke the daily change operation permissions of the account, and the account is default authorized only to view operations and does not have the permission to perform change operations.

[0041] The following are specific embodiments:

[0042] For example, in the operation and maintenance system, it is necessary to change the relevant data of an account. At this time, a change work order can be generated. Among them, the change work order is the change plan: the change operation plan when the system is upgraded or changed. This change operation plan includes change operator information, change operation asset information, change operation instruction information, the scope of influence, etc. The change work order can be a formal document in information technology operation and maintenance management, used to plan, apply for, and approve change operations of information systems, network devices, application programs, or other IT infrastructure. First, the personnel or department that needs to perform the change operation creates a work order, fills in the detailed information of the change, and submits it to the work order system. Through docking with the work order system, the operation and maintenance system of this application receives the change work order (or called the change plan) approved by the business department of the work order system.

[0043] After receiving the change work order, the change plan recognition large model (a type of AI large model, and the AI large model includes the change plan recognition large model and the instruction traceback large model) recognizes the change work order to obtain the recognition result. The recognition result includes: the change operation instruction, the change operation time period, the change operator information, the operation asset information, and the operation instruction information. The change plan recognition large model deeply analyzes the content of the received work order. This model is trained to understand and extract the key operation instruction details in the change work order. Using natural language processing technology, the large model can recognize the operation language description in the work order and convert it into a structured change operation instruction. It can also recognize the change operation time period, the change operator information, the operation asset information, as well as the expected scope of influence and security level of each operation.

[0044] Step S204, based on the recognition result, determine the change operation permission of the target account corresponding to the recognition result, where the change operation permission is the execution permission for the target account to execute the change operation instruction during the change operation time period.

[0045] In the technical solution provided in step S204, based on the recognition result, there are various ways to determine the change operation permission of the target account corresponding to the recognition result. For example: determine the change operation time period, change operation asset information, and change operation instruction information from the recognition result; determine the access control rule of the target account during the change operation time period based on the change operation asset information and the change operation instruction information, where the access control rule at least includes the change operation asset information allowed to be accessed by the target account during the change operation time period and the change operation instructions allowed to be executed; determine the change operation permission of the target account corresponding to the recognition result based on the access control rule.

[0046] The following are specific embodiments:

[0047] Determine the change operation time period, change operation asset information, and change operation instruction information from the recognition result, and then determine the access control rule of the target account during the change operation time period based on the change operation asset information and the change operation instruction information. Specifically: Determine the access control rule of the target account during the change operation time period based on the change operation asset information and the change operation instruction information, which is implemented as customizing the access control rule for the target user. Use a deep learning model to analyze the change operation instruction information and the change operation asset information, and predict the possible risks and operation modes of the change operation. Based on these predictions, automatically generate the access control rule to ensure that the access control rule not only includes the change operation asset information allowed to be accessed by the target account during the change operation time period and the change operation instructions allowed to be executed, but also can intelligently adjust the permission level according to the behavior pattern and operation environment of the operator to achieve more accurate risk prevention and control. At the same time, the access control rule can also be dynamically adjusted according to the real-time situation of the change operation (such as device status, network traffic, system load, etc.). For example, during high-load periods, the system automatically restricts the high-risk operation permissions for critical assets to ensure system stability and security. To ensure that the access control rule is not maliciously modified, blockchain technology can be used to store and verify the access control rule to ensure that the rule will not be maliciously tampered with after generation. The distributed characteristics of the blockchain can also improve the reliability and availability of the rule, and ensure the effective execution of the rule even in the case of partial system failures.

[0048] Step S206, issue the change operation permission to the target account during the change operation time period.

[0049] In the technical solution provided in step S206, when the operation instruction information includes graphic operations, there are multiple implementation manners for issuing the change operation permission to the target account during the change operation time period. For example: during the first preset time period before the change operation time period, the change operation permission is issued to the target account through the network element device; the method further includes: during the second preset time period after the change operation time period, the change operation permission is withdrawn from the target account through the network element device.

[0050] When the operation instruction information includes instruction operations, there are multiple implementation manners for issuing the change operation permission to the target account during the change operation time period. For example: during the change operation time period, the change operation permission is issued to the target account based on a control policy, where the control policy is used to instruct the target account to execute the change operation instruction corresponding to the change operation permission and intercept instructions other than the change operation instruction corresponding to the change operation permission; the method further includes: during the third preset time period after the change operation time period, the change operation permission is withdrawn from the target account.

[0051] The following are specific embodiments:

[0052] During the change operation time period, the change operation permission is issued to the target account. First, a pre-authorization is performed on the account (i.e., to confirm the change operation permission of the target account). The change operation permission is the execution permission of the change operation instruction corresponding to the changed asset of the applied change work order by the target account during the change operation time period. Then, an instruction authorization is performed. When the change operation indicated in the operation instruction information includes a graphic change operation, during the first preset time period before the change operation time period, the change operation permission is issued to the target account through the network element device; during the second preset time period after the change operation time period, the change operation permission is retrieved from the target account through the network element device. Specifically: Since graphic operations cannot directly control the operation instructions of users, during the first preset time period before the change operation time period, the operation and maintenance system issues the change operation permission to the target account in advance through the network element device, that is, automatically logs in to the network element device during the first preset time period and sets the instruction-level permission (change operation permission) of the account. The first preset time period here can be a few minutes to a few hours before the start of the change window, and the specific duration depends on the complexity of the change operation and the requirements of the preparatory work. The purpose of pre-authorization is to ensure that the operator can immediately access the target asset and start the operation when the change window opens, without waiting for real-time permission updates or manual intervention. During the second preset time period after the end of the change operation time period, the system automatically retrieves the change operation permission from the target account through the network element device. This step is aimed at timely restricting the operator's permission to prevent misoperation or unauthorized access after the change operation ends. The selection of the second preset time period is also important. It needs to be long enough to ensure that all change operation instructions have been executed, but not too long to increase security risks. Through the integration with the network element device, an automated process for permission issuance and retrieval is achieved. This includes using interfaces to communicate with the network element device and automatically executing commands for permission setting and retrieval. At the same time, the system needs to have an exception handling mechanism. For example, when the automatic login fails or the permission retrieval is unsuccessful, it can start a backup process or notify the management staff for manual intervention to ensure the reliability of permission management.

[0053] For the case where the operation instruction information contains instruction - type operations, instruction authorization is carried out in the following way: During the change operation time period, the change operation permission is issued to the target account based on the control policy. The control policy is used to instruct the target account to execute the change operation instruction corresponding to the change operation permission and intercept instructions other than the change operation instruction corresponding to the change operation permission. The change operation permission is withdrawn from the target account within the third preset time period after the change operation time period. Specifically: During the change operation time period, the change operation permission is issued to the target account through the control policy. The implementation of the control policy is based on a bastion host or a similar security operation and maintenance control system. The control policy includes a list of allowed instructions for the target account and the corresponding execution permissions. Before the change window is opened, the system automatically activates these policies, allowing the target account to execute only the instructions clearly listed in the work order. During the change operation time period, the system monitors all operation instructions of the target account in real - time. For any instruction outside the list of allowed instructions, the system will immediately intercept it to prevent its execution. In addition, even for instructions in the list of allowed instructions, the system will conduct secondary verification based on their risk levels and the current network status to ensure that the execution of the instructions not only meets the requirements of the work order but also does not pose a threat to system stability. Within the third preset time period after the end of the change operation time period, the system automatically withdraws the change operation permission from the target account. The setting of this time period takes into account the delay in instruction execution and the operation completion time of the operator, ensuring that all change operation instructions have been executed or appropriately interrupted, and then immediately restoring to the default security access control state.

[0054] In addition, to achieve full - process monitoring and management of account operations, during the change operation time period, the instruction logs corresponding to the operation instructions executed by the target account are collected every fourth preset time period; based on the access control rules and the instruction logs, the change operation progress and the change operation compliance index of the target account are determined; and the change operation progress and the change operation compliance index of the target account are pushed to the monitoring terminal.

[0055] In the above steps, there are various ways to determine the change operation progress and the change operation compliance index of the target account based on the access control rules and the instruction logs. For example: Based on the AI large - model, determine the matching degree between the instructions contained in the instruction log and the change operation instructions in the access control rules, and determine the change operation progress based on the matching degree; Based on the AI large - model, conduct change operation compliance identification on the instructions contained in the instruction log to obtain the change operation compliance result, where the change operation compliance result contains the risk characteristics corresponding to the instructions; Determine the change operation compliance index based on the change operation compliance result.

[0056] In order to better implement the change operation processing of the account change work order in the future, provide reference and talent reserve for subsequent change operations, further optimize the operation process, and improve the overall operation and maintenance efficiency and quality, when the compliance index of the change operation is greater than the first preset threshold, the change work order is updated to the change plan knowledge base; based on the progress of the change operation and the compliance index of the change operation, the operation proficiency of the target account is determined, and when the operation proficiency of the target account is greater than the second preset threshold, the operator name and operator number corresponding to the target account are updated to the change operation talent pool.

[0057] The following are specific embodiments:

[0058] During the change operation time period, the system performs instruction backtracking every fourth preset time period (for example, every 2 minutes), and automatically collects the instruction logs corresponding to the operation instructions executed by the target account. These instruction logs record all the operations of the operator during the change window, including key information such as executed commands, modified configurations, accessed asset information, and operation time. Based on the instruction backtracking large model, natural language processing technology and pattern matching algorithms are applied to compare the collected instruction logs with the change operation instructions defined in the access control rules, and the matching degree is automatically calculated. The matching degree calculation not only considers the text matching of the instructions, but also considers the context environment of the instruction execution, such as the asset status of the operation, system load, etc., to more comprehensively evaluate the compliance of the instructions. Based on the instruction matching degree calculated by the AI large model, the system dynamically updates the progress of the change operation. This includes the ratio of the number of operation instructions matching the change plan to the total number of instructions to be executed, and the weighted average progress index according to the importance and risk level of the operation. In this way, the system can reflect the real execution status of the change operation in real time. When analyzing the instruction logs, the AI large model simultaneously identifies the possible risk characteristics corresponding to each instruction. Risk characteristics include but are not limited to the potential side effects of the operation, potential impacts on system stability and security, etc. Based on the identified risk characteristics, the system generates the compliance result of the change operation, which includes the risk assessment of all operation instructions. According to the compliance result, the compliance index of the change operation is calculated, which is a comprehensive score reflecting the overall compliance level of the change operation. The calculation of this index considers the severity and occurrence frequency of all risk characteristics. When the compliance index is lower than the preset threshold, the system automatically triggers the warning process to notify the management personnel for manual review to prevent potential security risks and operation errors. All the progress and compliance indexes of the change operation, as well as the specific instruction matching degree and risk characteristic information, are pushed to the monitoring terminal in real time. The monitoring terminal can be the web interface of the management platform or a specific application installed on the mobile device, providing real-time charts, dashboards and other visualization tools to help the management personnel intuitively understand and monitor the execution situation of the change operation.

[0059] To quickly identify and cultivate highly skilled operators and provide data support for the construction of the operation and maintenance team, when the compliance index of the change operation is greater than the first preset threshold, update the change work order to the change plan knowledge base; determine the operation proficiency of the target account based on the change operation progress and the compliance index of the change operation, and when the operation proficiency of the target account is greater than the second preset threshold, update the operator name and operator number corresponding to the target account to the change operation talent pool. Specifically: when the compliance index of the change operation is higher than the first preset threshold (for example, 90%), it indicates that the operator shows a high degree of compliance and professionalism when executing the change work order. At this time, the system automatically updates the information of the change work order, including detailed content such as operation steps, change operation instructions used, operation time, and scope of influence, to the change plan knowledge base. The change plan knowledge base not only accumulates successful change operation cases but also analyzes and classifies these cases through AI technology to extract the best practices of operation, solutions to common problems, and potential risk points. This provides a rich data foundation for subsequent operator training, change plan writing, and risk assessment.

[0060] At the same time, based on the change operation progress and compliance index, comprehensively evaluate the operation proficiency of the operator. The operation proficiency demonstrates various factors such as the operator's understanding and execution speed of the change plan, degree of compliance with access control rules, and ability to handle emergencies. The scoring formula for the operation proficiency score is specifically determined by the weighted average of the change operation progress and the compliance index of the change operation, as well as the weighted value of the operator's historical performance. If the operation proficiency of the operator is higher than the second preset threshold (for example, 85%), it is considered that the operator has a high skill level and the ability to execute change operations. The system will automatically update the change operation talent pool and record information such as the operator's name, number, and operation proficiency score. The change operation talent pool is used to identify and manage highly skilled operators, provide a reference for subsequent change operation assignments, and at the same time provide data support for the personal skill development of operators and team building. The system can regularly analyze the data in the change operation talent pool to identify the operators with the highest skills and the most proficient operations, and give rewards or further training opportunities.

[0061] Through the above steps, the change work order application for change and the change operation permissions are closely linked to achieve authorization and supervision of operation according to the order. At the same time, it solves the refined dynamic authorization control of character and graphical operations. Automatically identify the operation progress and risks. Effectively restrict the compliance of change operations, thereby providing success rate and reducing the resulting failures. Dynamically generate the permission rules for the change operator within the change window period according to the content of the identified change plan, so as to strictly control the operation instructions that the operator can execute within the window period. And collect the operation instruction records, analyze whether the change operation is carried out strictly in accordance with the change plan, and the progress of the current operation. Real-time feedback to the monitoring terminal to assist in the monitoring and auditing operations of change operations, achieving precise control in multiple dimensions of time, access object, and operation content, effectively reducing potential security risks and possibilities such as illegal operations of non-change operations and misoperations within the window, and providing a new and practical control technology solution for change operations.

[0062] Figure 3 It is a flowchart of another method for determining account permissions provided according to an embodiment of the present application, as Figure 3As shown, first, an application for a change operation approved by the work order approval system (i.e., a change work order) is received. Then, based on the change plan recognition large model (a type of AI large model), the change work order transmitted by the work order approval system is received, and AI technology is used to analyze the content of the change plan, including key information such as the operation time period, operation assets, and operation instructions, providing data support for subsequent pre-authorization and operation control. (That is, the above-mentioned recognition of the change work order to obtain the recognition result). The pre-authorization module is used to generate dynamic permission rules based on the information parsed by the change plan recognition large model, providing the minimum permissions for the operator to operate during the change window period to ensure the compliance and security of the operation. (That is, the above-mentioned determination of the change operation permissions of the target account corresponding to the recognition result based on the recognition result). The instruction authorization module is used to closely cooperate with the pre-authorization module during the change operation to control the instructions executed by the operator, only allowing the execution of the instructions in the approved work order, and other commands will be intercepted, thereby realizing the fine control of the operation instructions. (That is, the above-mentioned distribution of the change operation permissions to the target account during the change operation time period). The instruction authorization module is mainly used to control two types of instruction operations, graphic operations and instruction operations. The character terminal (abbreviated as CRT) client represents character-based access operations (i.e., the above-mentioned instruction type change operations), and the network management system represents graphic access operations (i.e., the above-mentioned graphic type change operations). The connection between the pre-authorization module and these two clients indicates that the system can effectively control different types of access operations. The network management service and the network element device display system demonstrate the control ability of the underlying network devices. The pre-authorization module indirectly controls the network element devices through the network management service to realize the management of change operations on network devices. Other hosts refer to the hosts corresponding to the target account. The instruction traceback large model (a type of AI large model) is responsible for collecting and analyzing the instruction logs executed by the operator, comparing them with the change plan, and identifying the progress of the operation and possible compliance issues. This module introduces AI technology to enable intelligent traceback analysis, improving the monitoring efficiency and accuracy. (That is, the above-mentioned collection of the instruction logs corresponding to the operation instructions executed by the target account every fourth preset time period; determination of the change operation progress and change operation compliance metrics of the target account based on the access control rules and the instruction logs; pushing the change operation progress and change operation compliance metrics of the target account to the monitoring terminal). The change operation monitoring large screen (i.e., the above-mentioned monitoring terminal) serves as the monitoring terminal of the entire system, real-time displaying the progress and compliance status of the change operation, providing an intuitive view of the operation situation for the management personnel, facilitating real-time monitoring and decision-making.

[0063] Figure 4 is the operation flowchart of a method for determining account permissions provided according to an embodiment of the present application, as Figure 4As shown, the specific operation steps of the whole method are described in detail. From the beginning to the end, the whole process of the change operation corresponding to the target account from application to execution and then backtracking is shown. Preparatory work is carried out in advance (i.e. before the change operation is executed and before the change operation time period), and the change operation authority is recovered daily, that is, the operator's daily change operation authority is recovered to ensure that the operator cannot perform the change operation during the non-change window (non-change operation time period), thereby reducing the risk of misoperation. Based on the open application program interface (Open Api), the change plan file is received (i.e., the change work order is received as mentioned above), and the change plan is parsed through the big model, that is, the details of the plan are parsed through the AI ​​big model (i.e., the change work order is identified as mentioned above to obtain the identification result). This is the starting point of the whole process and provides a basis for subsequent pre-authorization and operation control. Pre-authorization is performed according to the content of the parsed application plan. That is, according to the parsed results of the change plan, the operator's authority rules within the change window period are dynamically generated to ensure that the operator's operation scope strictly matches the work order content. (i.e., based on the identification result, the change operation authority of the target account corresponding to the identification result is determined above). During the process (i.e., within the change operation time period), for network management type graphic operations (i.e., graphic type change operations), a scheduled task is set. Before the change window, the account authority is automatically set by logging into the network element device. Afterwards (i.e., after the change operation time period), after the change expires, the account authority is automatically revoked by logging into the network element device. (i.e., when the operation instruction information contains graphic type operations, the change operation authority is sent to the target account within the change operation time period, including: within the first preset time period before the change operation time period, the change operation authority is sent to the target account through the network element device; the method also includes: within the second preset time period after the change operation time period, the change operation authority is revoked from the target account through the network element device); for command type character operations (i.e., the above command type change operations), a time limit authorization is set. The policy takes effect during the window period, and the control instruction is issued. After the change period expires, the policy automatically becomes invalid. (That is, in the case where the operation instruction information contains instruction-type operations, the change operation authority is issued to the target account within the change operation time period, including: issuing the change operation authority to the target account based on the control policy within the change operation time period, wherein the control policy is used to instruct the target account to execute the change operation instruction corresponding to the change operation authority, and intercept instructions other than the change operation instruction corresponding to the change operation authority; the method also includes: revoking the change operation authority from the target account within a third preset time period after the change operation time period).Meanwhile, during the process, instruction collection is carried out, the differences between the instructions and the change order of the solution are analyzed, and the execution progress and execution integrity are presented (that is, during the change operation time period, the instruction logs corresponding to the operation instructions executed by the target account are collected every fourth preset time period; based on the access control rules and the instruction logs, the change operation progress and the change operation compliance index of the target account are determined; the change operation progress and the change operation compliance index of the target account are pushed to the monitoring terminal).

[0064] An embodiment of the present application provides a device for determining account permissions, as Figure 5 shown, including:

[0065] A receiving module 502, configured to receive a change work order.

[0066] An identifying module 504, configured to identify the change work order to obtain an identification result, where the identification result at least includes: a change operation instruction.

[0067] A determining module 506, configured to determine, based on the identification result, the change operation permission of the target account corresponding to the identification result, where the change operation permission is the execution permission for the target account to execute the change operation instruction during the change operation time period.

[0068] The determining module 506 is further configured to determine a change operation time period, change operation asset information, and change operation instruction information from the identification result; determine an access control rule for the target account during the change operation time period based on the change operation asset information and the change operation instruction information, where the access control rule at least includes the change operation asset information allowed to be accessed by the target account during the change operation time period and the change operation instructions allowed to be executed; determine the change operation permission of the target account corresponding to the identification result based on the access control rule.

[0069] A sending module 508, configured to send the change operation permission to the target account during the change operation time period.

[0070] The sending module 508 is further configured to, when the operation instruction information includes a graphic operation, send the change operation permission to the target account through the network element device within a first preset time period before the change operation time period; and take back the change operation permission from the target account through the network element device within a second preset time period after the change operation time period.

[0071] The sending module 508 is also used to send the change operation authority to the target account based on the control policy within the change operation time period when the operation instruction information includes instruction-type operations, wherein the control strategy is used to instruct the target account to execute the change operation instruction corresponding to the change operation authority, and to intercept instructions other than the change operation instruction corresponding to the change operation authority; and to revoke the change operation authority from the target account within a third preset time period after the change operation time period.

[0072] It should be noted that Figure 5 The account authority determination device shown is used to perform Figure 2 The method for determining account permissions shown is therefore Figure 2 The relevant explanations in the method for determining the account authority in also apply to the device for determining the account authority, and will not be repeated here.

[0073] It should be noted that the various modules in the above-mentioned account authority determination device can be program modules (for example, a set of program instructions that implement a certain specific function) or hardware modules. For the latter, it can be expressed in the following forms, but is not limited to this: the expression form of each of the above-mentioned modules is a processor, or the functions of each of the above-mentioned modules are implemented by a processor.

[0074] The embodiment of the present application also provides a non-volatile storage medium, the non-volatile storage medium includes a stored program, wherein when the program is running, the device where the non-volatile storage medium is located is controlled to execute the above method for determining account permissions. For example, receiving a change work order; identifying the change work order to obtain an identification result, wherein the identification result at least includes: a change operation instruction; based on the identification result, determining the change operation permission of the target account corresponding to the identification result, wherein the change operation permission is the execution permission of the target account to execute the change operation instruction during the change operation time period; and issuing the change operation permission to the target account during the change operation time period.

[0075] The embodiment of the present application also provides an electronic device, the electronic device includes a processor, the processor is used to run a program, wherein the above method for determining account permissions is executed when the program is running. For example, receiving a change work order; identifying the change work order to obtain an identification result, wherein the identification result at least includes: a change operation instruction; based on the identification result, determining the change operation permission of the target account corresponding to the identification result, wherein the change operation permission is the execution permission of the target account to execute the change operation instruction during the change operation time period; and issuing the change operation permission to the target account during the change operation time period.

[0076] According to another aspect of the embodiments of the present application, a computer program product is further provided, including a computer program, which implements the above method for determining account permissions when executed by a processor. For example, receiving a change work order; identifying the change work order to obtain an identification result, where the identification result at least includes: a change operation instruction; based on the identification result, determining the change operation permission of the target account corresponding to the identification result, where the change operation permission is the execution permission for the target account to execute the change operation instruction during the change operation time period; and issuing the change operation permission to the target account during the change operation time period.

[0077] In the above embodiments of the present application, the descriptions of the various embodiments have their own emphases. For parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.

[0078] In several embodiments provided by the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are merely illustrative. For example, the division of the units can be a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces. The indirect coupling or communication connection of units or modules can be in an electrical or other form.

[0079] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place, or they can be distributed to multiple units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0080] In addition, in each embodiment of the present application, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.

[0081] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the related technology, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application. The foregoing storage medium includes: various media that can store program codes, such as USB flash drives, read-only memories (ROMs), random access memories (RAMs), mobile hard disks, magnetic disks, or optical discs.

[0082] The above are only the preferred embodiments of this application. It should be noted that for those of ordinary skill in the art, without departing from the principle of this application, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of this application.

Claims

1. A method for determining account authority, characterized in that: include: Receive change orders; Identify the change work order to obtain an identification result, wherein the identification result at least includes: a change operation instruction; Based on the identification result, determining the change operation permission of the target account corresponding to the identification result, wherein the change operation permission is the execution permission of the target account to execute the change operation instruction during the change operation time period; The change operation authority is issued to the target account within the change operation time period.

2. The method according to claim 1, characterized in that: The identification result also includes: the change operation time period, change operator information, change operation asset information, and change operation instruction information, wherein the change operation indicated in the change operation instruction information at least includes a graphic change operation or an instruction change operation.

3. The method according to claim 2, characterized in that The determining, based on the identification result, the change operation permission of the target account corresponding to the identification result includes: Determining the change operation time period, the change operation asset information, and the change operation instruction information from the identification result; Determine the access control rules of the target account within the change operation time period based on the change operation asset information and the change operation instruction information, wherein the access control rules at least include the change operation asset information that the target account is allowed to access within the change operation time period and the change operation instruction that is allowed to be executed; The change operation permission of the target account corresponding to the identification result is determined based on the access control rule.

4. The method according to claim 2, characterized in that In a case where the operation instruction information includes a graphic operation, the step of sending the change operation authority to the target account within the change operation time period includes: In a first preset time period before the change operation time period, the change operation authority is sent to the target account through a network element device; The method further comprises: Within a second preset time period after the change operation time period, the change operation authority is reclaimed from the target account through the network element device.

5. The method according to claim 2, characterized in that: In a case where the operation instruction information includes an instruction type operation, the step of sending the change operation authority to the target account within the change operation time period includes: The change operation authority is issued to the target account based on a control policy within the change operation time period, wherein the control policy is used to instruct the target account to execute the change operation instruction corresponding to the change operation authority and to intercept instructions other than the change operation instruction corresponding to the change operation authority; The method further includes: revoking the change operation authority from the target account within a third preset time period after the change operation time period.

6. The method according to claim 3, characterized in that The method further comprises: During the change operation time period, collecting instruction logs corresponding to the operation instructions executed by the target account every fourth preset time period; Determining the change operation progress and change operation compliance index of the target account based on the access control rule and the instruction log; The change operation progress and change operation compliance indicators of the target account are pushed to the monitoring terminal.

7. The method according to claim 6, characterized in that The determining the change operation progress and the change operation compliance index of the target account based on the access control rule and the instruction log includes: Determine the matching degree between the instruction contained in the instruction log and the change operation instruction in the access control rule based on the AI ​​big model, and determine the change operation progress based on the matching degree; Based on the AI ​​big model, the instructions contained in the instruction log are identified for compliance of the change operation to obtain a compliance result of the change operation, wherein the compliance result of the change operation includes risk characteristics corresponding to the instruction; The change operation compliance indicator is determined based on the change operation compliance result.

8. The method according to claim 6, characterized in that The method further comprises: When the compliance index of the change operation is greater than a first preset threshold, updating the change work order to a change solution knowledge base; The operation proficiency of the target account is determined based on the change operation progress and the change operation compliance index, and when the operation proficiency of the target account is greater than a second preset threshold, the operator name and operator number corresponding to the target account are updated to the change operation talent pool.

9. A device for determining account authority, characterized in that: include: The receiving module is used to receive the change work order; An identification module, used to identify the change work order and obtain an identification result, wherein the identification result at least includes: a change operation instruction; a determination module, configured to determine, based on the identification result, a change operation permission of a target account corresponding to the identification result, wherein the change operation permission is an execution permission of the target account to execute the change operation instruction during a change operation time period; The issuing module is used to issue the change operation authority to the target account within the change operation time period.

10. A non-volatile storage medium, characterized in that: The non-volatile storage medium stores a program, wherein when the program is running, the device where the non-volatile storage medium is located is controlled to execute the method for determining account authority according to any one of claims 1 to 8.

11. An electronic device, characterized in that: include: A memory and a processor, wherein the processor is used to run a program stored in the memory, wherein the program executes the method for determining account permissions described in any one of claims 1 to 8 when running.

12. A computer program product comprising computer instructions, characterized in that: When the computer instructions are executed by a processor, the method for determining the account authority described in any one of claims 1 to 8 is implemented.