Authority control method and system based on user sales data
Through the permission control method of user sales data, the matching degree processing of multi-source information carriers is used to solve the problem of repeated permission settings in different applications, and accurate permission control and cost reduction are achieved.
Patent Information
- Application Number
- CN202510405423.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-02
- Publication Date
- 2025-07-08
AI Technical Summary
In the prior art, permission control for different applications requires repeated setting of permissions of the same dimension, resulting in increased operational steps and maintenance costs, and easily lead to inconsistent definition of permission data.
By obtaining the multi-source information carrier to be controlled and executed, the request information carrier logic processing is performed, and the control strategy is obtained based on the matching degree, and the control strategy in the multi-source information carrier to be controlled is determined using the matching degree between the executed control request set and the request set to be controlled.
Accurate permission control over multi-source information carriers is realized, reducing repeated setting steps, reducing operational costs, and improving consistency in permission data definitions.
Smart Images

Figure CN120277693A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data security technology, and in particular to a permission control method and system based on user sales data. Background Art
[0002] With the development of Internet technology, data, as one of the core assets of an enterprise, ensuring data security has become a top priority for the company. In the prior art, the public key and private key of permissions are usually separated, or the website is blocked, or encryption is used to ensure that the company's data will not be leaked, thereby ensuring the security of the company's data.
[0003] When users use a data model for application analysis, they need to control permissions for each dimension in the application. However, in different applications, the same data dimensions may be included. The prior art performs independent permission control for different applications. For example, for company product sales analysis and company product quality analysis, permissions for products need to be controlled. This situation where different applications reference the same dimension requires repeated setting of dimension permissions, increasing the user's operation steps and maintenance costs, and easily leading to inconsistent definition of permission data. Summary of the Invention
[0004] To achieve the above object, the present application provides the following technical solutions:
[0005] According to the first aspect of the present invention, the present invention claims protection for a permission control method based on user sales data, which is characterized by including:
[0006] Obtain a multi-source information carrier of user permissions to be controlled and a multi-source information carrier of user permissions with control already executed, where the multi-source information carrier of user permissions to be controlled and the multi-source information carrier of user permissions with control already executed belong to the same data format of sales user control permissions;
[0007] Perform logical processing on the request information carrier of the multi-source information carrier of user permissions to be controlled to obtain a set of requests to be controlled;
[0008] Obtain the set of executed control requests corresponding to the control policy in the multi-source information carrier of user permissions with control already executed, and based on the matching degree between the set of executed control requests and the set of requests to be controlled, obtain the set of control requests corresponding to the control policy in the multi-source information carrier of user permissions to be controlled from the set of requests to be controlled.
[0009] Further, the step of obtaining the matching degree between the set of executed control requests and the set of requests to be controlled includes:
[0010] Based on the control history corresponding to the set of executed control requests in the multi-source information carrier of user permissions with control already executed, obtain the order of the set of executed control requests;
[0011] Based on the order of the executed control request set, the security level of the permission data of the executed control request set, and the security level of the permission data of the to-be-controlled request set, obtain the matching degree between the executed control request set and the to-be-controlled request set.
[0012] Furthermore, the control history includes a control period and a control intensity;
[0013] The obtaining of the order of the executed control request set based on the control history corresponding to the executed control request set in the multi-source information carrier of the executed control user permissions includes:
[0014] Based on the control period corresponding to the executed control request set in the multi-source information carrier of the executed control user permissions, obtain the first confidence level of the executed control request set;
[0015] Based on the control intensity corresponding to the executed control request set in the multi-source information carrier of the executed control user permissions, obtain the second confidence level of the executed control request set;
[0016] Based on the first confidence level and the second confidence level, obtain the order of the executed control request set.
[0017] Furthermore, the obtaining of the matching degree between the executed control request set and the to-be-controlled request set based on the order of the executed control request set, the security level of the permission data of the executed control request set, and the security level of the permission data of the to-be-controlled request set includes:
[0018] Based on the order of the executed control request set and the security level of the permission data of the executed control request set, obtain the weighted features of the executed control request set;
[0019] Perform an association calculation on the security level of the permission data of the to-be-controlled request set and the weighted features of the executed control request set to obtain the matching degree between the executed control request set and the to-be-controlled request set;
[0020] The performing of logical processing on the request information carrier of the to-be-controlled user permission multi-source information carrier to obtain a to-be-controlled request set includes:
[0021] Perform a request information carrier detection on the to-be-controlled user permission multi-source information carrier to obtain a plurality of to-be-controlled request information carriers;
[0022] Set the to-be-controlled request information carriers belonging to the same format as a group to obtain a plurality of to-be-controlled request information carrier groups;
[0023] Based on the request information carrier formats in each group of request information carriers to be controlled, obtain the matching groups of request information carriers to be controlled from each group of request information carriers to be controlled;
[0024] Perform request information carrier logical processing among the matching groups of request information carriers to be controlled to obtain the set of requests to be controlled.
[0025] Further, the detecting the request information carriers of the multi-source information carriers of the user permissions to be controlled to obtain a plurality of request information carriers to be controlled includes:
[0026] Under a plurality of predetermined request information carrier formats, sequentially detect the request information carriers of the multi-source information carriers of the user permissions to be controlled to obtain the request information carriers to be controlled corresponding to each predetermined request information carrier format;
[0027] The multi-source information carrier of the executed control user permissions is the sales user control permission corresponding within a predetermined time period.
[0028] According to the second aspect of the present invention, the present invention requests to protect a permission control system based on user sales data, which is characterized by including:
[0029] An acquisition unit that acquires a multi-source information carrier of user permissions to be controlled and a multi-source information carrier of executed control user permissions, where the multi-source information carrier of user permissions to be controlled and the multi-source information carrier of executed control user permissions belong to the sales user control permissions of the same data format;
[0030] A processing unit that performs request information carrier logical processing on the multi-source information carrier of the user permissions to be controlled to obtain a set of requests to be controlled;
[0031] An output unit that acquires the set of executed control requests corresponding to the control policy in the multi-source information carrier of the executed control user permissions, and based on the matching degree between the set of executed control requests and the set of requests to be controlled, obtains the set of control requests corresponding to the control policy in the multi-source information carrier of the user permissions to be controlled from the set of requests to be controlled.
[0032] Further, the output unit further includes:
[0033] Based on the control history corresponding to the set of executed control requests in the multi-source information carrier of the executed control user permissions, obtain the order of the set of executed control requests;
[0034] Based on the order of the set of executed control requests, the permission data confidentiality level of the set of executed control requests, and the permission data confidentiality level of the set of requests to be controlled, obtain the matching degree between the set of executed control requests and the set of requests to be controlled.
[0035] Further, the control history includes a control period and a control intensity;
[0036] Obtaining the order of the executed control request set based on the control history corresponding to the executed control request set in the executed control user privilege multi-source information carrier includes:
[0037] Obtaining a first confidence level of the executed control request set based on the control period corresponding to the executed control request set in the executed control user privilege multi-source information carrier;
[0038] Obtaining a second confidence level of the executed control request set based on the control intensity corresponding to the executed control request set in the executed control user privilege multi-source information carrier;
[0039] Obtaining the order of the executed control request set based on the first confidence level and the second confidence level.
[0040] Further, obtaining the matching degree between the executed control request set and the to-be-controlled request set based on the order of the executed control request set, the classified level of the privilege data of the executed control request set, and the classified level of the privilege data of the to-be-controlled request set includes:
[0041] Obtaining the weighted feature of the executed control request set based on the order of the executed control request set and the classified level of the privilege data of the executed control request set;
[0042] Performing an association calculation on the classified level of the privilege data of the to-be-controlled request set and the weighted feature of the executed control request set to obtain the matching degree between the executed control request set and the to-be-controlled request set;
[0043] Performing request information carrier logical processing on the to-be-controlled user privilege multi-source information carrier to obtain a to-be-controlled request set includes:
[0044] Performing request information carrier detection on the to-be-controlled user privilege multi-source information carrier to obtain a plurality of to-be-controlled request information carriers;
[0045] Setting the to-be-controlled request information carriers belonging to the same format as a group to obtain a plurality of to-be-controlled request information carrier groups;
[0046] Based on the request information carrier format in each to-be-controlled request information carrier group, obtaining a matching to-be-controlled request information carrier group from each to-be-controlled request information carrier group;
[0047] Performing request information carrier logical processing among the matching to-be-controlled request information carrier groups to obtain the to-be-controlled request set.
[0048] Further, performing request information carrier detection on the multi-source information carrier of the user permission to be controlled to obtain a plurality of request information carriers to be controlled, including:
[0049] Performing request information carrier detection on the multi-source information carrier of the user permission to be controlled in sequence under a plurality of predetermined request information carrier formats to obtain the request information carriers to be controlled corresponding to each predetermined request information carrier format;
[0050] The multi-source information carrier of the executed user permission control is the sales user control permission corresponding within a predetermined time period.
[0051] This application relates to the technical field of data security, and particularly to a permission control method and system based on user sales data. It obtains multi-source information carriers of the user permission to be controlled and the executed user permission control, and both belong to the sales user control permission in the same data format. Performing request information carrier logical processing on the multi-source information carrier of the user permission to be controlled to obtain a set of requests to be controlled; obtaining the set of executed control requests corresponding to the control policy in the multi-source information carrier of the executed user permission control, and based on the matching degree between the set of executed control requests and the set of requests to be controlled, obtaining the set of control requests corresponding to the control policy in the multi-source information carrier of the user permission to be controlled from the set of requests to be controlled. The present invention can effectively and accurately control sales users carrying multi-source information carriers in various formats, and give a feedback result relatively meeting the control requirements for the control requests. Description of the Drawings
[0052] Figure 1 It is a working flowchart of a permission control method based on user sales data requested to be protected by an embodiment of this application;
[0053] Figure 2 It is a second working flowchart of a permission control method based on user sales data requested to be protected by an embodiment of this application;
[0054] Figure 3 It is a third working flowchart of a permission control method based on user sales data requested to be protected by an embodiment of this application;
[0055] Figure 4 It is a fourth working flowchart of a permission control method based on user sales data requested to be protected by an embodiment of this application;
[0056] Figure 5 It is a fifth working flowchart of a permission control method based on user sales data requested to be protected by an embodiment of this application;
[0057] Figure 6 It is a structural unit diagram of a permission control system based on user sales data requested to be protected by an embodiment of this application. Detailed implementation mode
[0058] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0059] The present invention provides a permission control method based on user sales data. Figure 1 It is a schematic flowchart of the permission control method based on user sales data provided by the present invention, as Figure 1 shown, the method includes the following steps:
[0060] Step 110: Obtain a multi-source information carrier of the user permission to be controlled and a multi-source information carrier of the user permission with the control already executed. The multi-source information carrier of the user permission to be controlled and the multi-source information carrier of the user permission with the control already executed belong to the sales user control permission of the same data format.
[0061] The multi-source information carrier of the user permission with the control already executed refers to the executed behavior that contains the control strategy. For example, the multi-source information carrier of the user permission with the control already executed can be the offensive execution behavior that contains the control strategy and has been executed by the operator. Among them, the multi-source information carrier of the user permission to be controlled and the multi-source information carrier of the user permission with the control already executed belong to the sales user control permission of the same data format.
[0062] Step 120: Perform request information carrier logic processing on the multi-source information carrier of the user permission to be controlled to obtain a set of requests to be controlled.
[0063] Specifically, performing request information carrier logic processing on the multi-source information carrier of the user permission to be controlled means detecting the request information carrier from the multi-source information carrier of the user permission to be controlled and processing the intelligence logic between the request information carriers, and constructing a set of requests to be controlled with the detected request information carriers and the intelligence logic between the request information carriers.
[0064] It can be understood that since the multi-source information carrier of the user permission to be controlled is an execution behavior that needs to perform control strategy detection, there may or may not be a control strategy in the multi-source information carrier of the user permission to be controlled. That is, there may or may not be a control request set corresponding to the control strategy in the obtained set of requests to be controlled.
[0065] Among them, when performing request information carrier logic processing on the multi-source information carrier for controlling user permissions, the multi-source information carrier for controlling user permissions can be first detected for request information carriers to obtain multiple request information carriers to be controlled, and then a classification model can be used to obtain the request information carrier logic between the request information carriers to be controlled; alternatively, the request information carriers to be controlled in the multi-source information carrier for controlling user permissions and the logic between the request information carriers to be controlled can be processed simultaneously. The embodiments of the present invention do not make specific limitations on this.
[0066] Step 130: Obtain the executed control request set corresponding to the control policy in the multi-source information carrier for controlling user permissions that has been executed, and based on the matching degree between the executed control request set and the to-be-controlled request set, obtain the control request set corresponding to the control policy in the multi-source information carrier for controlling user permissions from the to-be-controlled request set.
[0067] Specifically, the executed control request set can be understood as the control request set corresponding to the control policy in the multi-source information carrier for controlling user permissions that has been executed. In some specific embodiments, the multi-source information carrier for controlling user permissions that has been executed can be subjected to request information carrier logic processing to obtain a candidate executed control request set, and the candidate executed control request set can be matched with a request library storing control request sets corresponding to multiple control policies, and the executed control request set corresponding to the control policy can be obtained from the candidate executed control request set. In some specific embodiments, the executed control request set corresponding to the control policy can be obtained from the multi-source information carrier for controlling user permissions that has been executed according to the control policy label.
[0068] In addition, the matching degree between the executed control request set and the to-be-controlled request set is used to represent the similarity degree between the executed control request set and the to-be-controlled request set. The higher the matching degree, the higher the similarity degree between the executed control request set and the to-be-controlled request set, and thus the greater the probability that the to-be-controlled request set contains the control policy in the executed control request set.
[0069] Optionally, when the matching degree between any to-be-controlled request set and the executed control request set is greater than a threshold, the corresponding to-be-controlled request set is obtained as the control request set corresponding to the control policy.
[0070] In some specific embodiments, before obtaining the control request set corresponding to the control policy in the multi-source information carrier of the user permissions to be controlled from the set of requests to be controlled based on the matching degree between the executed control request set and the set of requests to be controlled, the set of requests to be controlled and the executed control request set are sequentially linked with the request information carriers, so that the request information carriers in the multi-source information carrier of the user permissions to be controlled and the executed control user permissions can be linked with the corresponding request information carriers in their request libraries, avoiding the problem that the ambiguity between the request information carriers affects the accuracy of obtaining the matching degree between the executed control request set and the set of requests to be controlled.
[0071] It can be seen that in the permission control method based on user sales data provided by the embodiments of the present invention, since the executed control request set is the control request set corresponding to the control policy, based on the matching degree between the executed control request set and the set of requests to be controlled, the control request set corresponding to the control policy in the multi-source information carrier of the user permissions to be controlled can be accurately obtained from the set of requests to be controlled, further improving the detection accuracy of the control policy.
[0072] Based on the above embodiments, Figure 2 is a schematic flowchart of the method for obtaining the matching degree between the executed control request set and the set of requests to be controlled provided by the present invention. As Figure 2 shown, the steps for obtaining the matching degree between the executed control request set and the set of requests to be controlled include:
[0073] Step 210: Obtain the order of the executed control request set based on the control history corresponding to the executed control request set in the multi-source information carrier of the executed control user permissions;
[0074] Step 220: Obtain the matching degree between the executed control request set and the set of requests to be controlled based on the order of the executed control request set, the classified level of the permission data of the executed control request set, and the classified level of the permission data of the set of requests to be controlled.
[0075] The classified level of the permission data of the executed control request set is used to characterize the intelligence information of the executed control request set, and the classified level of the permission data of the set of requests to be controlled is used to characterize the intelligence information of the set of requests to be controlled. Based on the classified level of the permission data of the executed control request set and the classified level of the permission data of the set of requests to be controlled, the intelligence matching degree between the executed control request set and the set of requests to be controlled can be obtained. The greater the intelligence matching degree and the higher the order, the higher the matching degree between the executed control request set and the set of requests to be controlled.
[0076] Based on any of the above embodiments, the control history includes the control period and the control intensity;
[0077] Figure 3It is a schematic flowchart of an implementation manner of step 210 in the method for obtaining the matching degree between the executed control request set and the to-be-controlled request set provided by the present invention. As Figure 3 shown, step 210 includes:
[0078] Step 211: Obtain the first confidence level of the executed control request set based on the control period corresponding to the executed control request set in the multi-source information carrier of the executed control user permissions.
[0079] Step 212: Obtain the second confidence level of the executed control request set based on the control intensity corresponding to the executed control request set in the multi-source information carrier of the executed control user permissions.
[0080] Step 213: Obtain the order of the executed control request set based on the first confidence level and the second confidence level.
[0081] Specifically, the closer the control period is to the current period corresponding to the multi-source information carrier of the to-be-controlled user permissions, the higher the probability that the operator controls the multi-source information carrier of the executed control user permissions again, that is, the higher the probability that the multi-source information carrier of the to-be-controlled user permissions contains the control policy in the multi-source information carrier of the executed control user permissions, and the greater the first confidence level.
[0082] The more the control intensity, the higher the degree of interest of the operator in the control policy in the multi-source information carrier of the executed control user permissions, and further the higher the probability that the operator controls the multi-source information carrier of the executed control user permissions again, that is, the higher the probability that the multi-source information carrier of the to-be-controlled user permissions contains the control policy in the multi-source information carrier of the executed control user permissions, and the greater the second confidence level.
[0083] On this basis, obtain the order of the executed control request set based on the first confidence level and the second confidence level. Optionally, the order of the executed control request set can be obtained based on the product of the first confidence level and the second confidence level, or the order of the executed control request set can be obtained based on the sum of the first confidence level and the second confidence level.
[0084] Based on any of the above embodiments, Figure 4 It is a schematic flowchart of an implementation manner of step 220 in the method for obtaining the matching degree between the executed control request set and the to-be-controlled request set provided by the present invention. As Figure 4 shown, step 220 includes:
[0085] Step 221: Obtain the weighted feature of the executed control request set based on the order of the executed control request set and the classified level of the permission data of the executed control request set.
[0086] Step 222: Perform an association calculation on the permission data confidentiality level of the to-be-controlled request set and the weighted features of the executed control request set to obtain the matching degree between the executed control request set and the to-be-controlled request set.
[0087] In some specific embodiments, the permission data confidentiality level of the executed control request set can be weighted based on the order of the executed control request set to obtain the weighted features of the executed control request set. Among them, the weighted features can be used to characterize the probability of the control policies in the executed control request set appearing in the multi-source information carriers of the to-be-controlled user permissions.
[0088] Performing an association calculation on the permission data confidentiality level of the to-be-controlled request set and the weighted features of the executed control request set can obtain the matching degree between the executed control request set and the to-be-controlled request set. The higher the matching degree, the higher the similarity between the to-be-controlled request set and the executed control request set, and thus the greater the probability that the to-be-controlled request set contains the control policies in the executed control request set.
[0089] Based on any of the above embodiments, Figure 5 is a schematic flowchart of an implementation manner of step 120 in the permission control method based on user sales data provided by the present invention, as Figure 5 shown, step 120 includes:
[0090] Step 121: Perform a request information carrier detection on the multi-source information carriers of the to-be-controlled user permissions to obtain a plurality of to-be-controlled request information carriers;
[0091] Step 122: Set the to-be-controlled request information carriers belonging to the same format as a group to obtain a plurality of to-be-controlled request information carrier groups;
[0092] Step 123: Based on the request information carrier formats in each to-be-controlled request information carrier group, obtain the matching to-be-controlled request information carrier groups from each to-be-controlled request information carrier group;
[0093] Step 124: Perform a request information carrier logical process among the matching to-be-controlled request information carrier groups to obtain a to-be-controlled request set.
[0094] In an embodiment of the present invention, request information carrier detection is performed on multi-source information carriers with user permissions to be controlled, obtaining a plurality of request information carriers to be controlled. And the request information carriers to be controlled belonging to the same format are set as a group, obtaining a plurality of groups of request information carriers to be controlled. Thus, based on the request information carrier formats in each group of request information carriers to be controlled, a matching group of request information carriers to be controlled can be obtained from each group of request information carriers to be controlled, and request information carrier logic processing is performed among the matching groups of request information carriers to be controlled, obtaining a set of request information carriers to be controlled. Among them, the matching groups of request information carriers to be controlled can be understood as two groups of request information carriers to be controlled in which there is a request information carrier logic between the request information carriers in the groups. For example, if group 1 of request information carriers to be controlled and group 2 of request information carriers to be controlled are matching groups of request information carriers to be controlled, then there is a request information carrier logic between the request information carriers in group 1 of request information carriers to be controlled and the request information carriers in group 2 of request information carriers to be controlled.
[0095] In an embodiment of the present invention, the group of request information carriers to be controlled corresponding to a person and the group of request information carriers to be controlled corresponding to an organization are used as matching groups of request information carriers to be controlled, that is, the quality levels of the request information carrier labels in both groups of request information carriers to be controlled are set to 1, and the remaining request information carrier labels are set to 0. On this basis, the request information carrier logic between the request information carriers is discriminated for the request information carrier labels with a quality level of 1, and no request information carrier logic discrimination is performed on the request information carrier labels with a quality level of 0.
[0096] It can be seen that, aiming at the problem of high time complexity in joint processing, in an embodiment of the present invention, based on the request information carrier formats in each group of request information carriers to be controlled, a matching group of request information carriers to be controlled is obtained from each group of request information carriers to be controlled, and request information carrier logic processing is performed among the matching groups of request information carriers to be controlled, obtaining a set of request information carriers to be controlled, greatly reducing the discrimination intensity between the head request information carrier and the tail request information carrier, reducing the processing complexity. At the same time, performing request information carrier logic processing among the matching groups of request information carriers to be controlled also greatly improves the accuracy of request information carrier logic processing, and thus can accurately obtain the set of request information carriers to be controlled.
[0097] Based on any of the above embodiments, request information carrier detection is performed on multi-source information carriers with user permissions to be controlled, obtaining a plurality of request information carriers to be controlled, including:
[0098] Under multiple predetermined request information carrier formats, request information carrier detection is sequentially performed on multi-source information carriers with user permissions to be controlled, obtaining the request information carriers to be controlled corresponding to each predetermined request information carrier format.
[0099] In the embodiment of the present invention, aiming at the phenomenon of overlapping request information carriers, the request information carriers are processed in each predetermined request information carrier format, which can avoid the problem of missing nested request information carriers and losing key information, and greatly improve the accuracy of detecting the request information carriers to be controlled.
[0100] Based on any of the above embodiments, the executed control user privilege multi-source information carrier is the sales user control privilege corresponding to a predetermined time period.
[0101] Specifically, the closer the control period corresponding to the executed control user privilege multi-source information carrier is to the control period corresponding to the user privilege multi-source information carrier to be controlled, the greater the probability that the operator will control the control strategy in the executed control user privilege multi-source information carrier again. Therefore, the predetermined time period can be set as a time period closer to the control period corresponding to the user privilege multi-source information carrier to be controlled, so as to accurately detect the control strategy for the user privilege multi-source information carrier to be controlled and improve the accuracy of the control strategy detection result.
[0102] Based on any of the above embodiments, another privilege control method based on user sales data provided by the present invention includes:
[0103] First, obtain the user privilege multi-source information carrier to be controlled and the executed control user privilege multi-source information carrier. Among them, the user privilege multi-source information carrier to be controlled and the executed control user privilege multi-source information carrier belong to the sales user control privilege of the same data format.
[0104] Next, in multiple predetermined request information carrier formats, sequentially perform request information carrier detection on the user privilege multi-source information carrier to be controlled to obtain the request information carriers to be controlled corresponding to each predetermined request information carrier format, and set the request information carriers to be controlled belonging to the same format as a group to obtain multiple groups of request information carriers to be controlled. Based on the request information carrier formats in each group of request information carriers to be controlled, obtain the matching groups of request information carriers to be controlled from each group of request information carriers to be controlled, and perform request information carrier logic processing among the matching groups of request information carriers to be controlled to obtain a set of requests to be controlled. Perform request information carrier linking on the set of requests to be controlled to map the set of requests to be controlled into the expression form in the prior request library.
[0105] Perform key information matching processing on the executed control user privilege multi-source information carrier to obtain the set of executed control requests corresponding to the control strategy in the executed control user privilege multi-source information carrier. Perform request information carrier linking on the set of executed control requests to map the set of executed control requests into the expression form in the prior request library.
[0106] After obtaining the set of executed control requests, based on the control history corresponding to the set of executed control requests in the multi-source information carrier of the executed control user permissions, obtain the order of the set of executed control requests. Based on the order of the set of executed control requests, the classified level of the permission data of the set of executed control requests, and the classified level of the permission data of the set of requests to be controlled, obtain the matching degree between the set of executed control requests and the set of requests to be controlled.
[0107] Finally, based on the matching degree between the set of executed control requests and the set of requests to be controlled, obtain the set of control requests corresponding to the control policy in the multi-source information carrier of the user permissions to be controlled from the set of requests to be controlled.
[0108] The permission control system based on user sales data provided by the present invention will be described below. The permission control system based on user sales data described below can be correspondingly referred to the permission control method based on user sales data described above.
[0109] Based on any of the above embodiments, Figure 6 is a schematic structural diagram of the permission control system based on user sales data provided by the present invention, as Figure 6 shown, the system includes:
[0110] An acquisition unit 1010, configured to acquire a multi-source information carrier of user permissions to be controlled and a multi-source information carrier of executed control user permissions, where the multi-source information carrier of user permissions to be controlled and the multi-source information carrier of executed control user permissions belong to the sales user control permissions of the same data format;
[0111] A processing unit 1020, configured to perform logical processing on the request information carrier of the multi-source information carrier of the user permissions to be controlled to obtain a set of requests to be controlled;
[0112] An output unit 1030, configured to acquire the set of executed control requests corresponding to the control policy in the multi-source information carrier of the executed control user permissions, and based on the matching degree between the set of executed control requests and the set of requests to be controlled, obtain the set of control requests corresponding to the control policy in the multi-source information carrier of the user permissions to be controlled from the set of requests to be controlled.
[0113] On the other hand, the present invention also provides a computer program product, which includes a computer program stored on a non-transitory computer-readable storage medium. The computer program includes program requests. When the program requests are executed by a computer, the computer can execute the permission control method based on user sales data provided by the above-mentioned various methods. The method includes: obtaining a multi-source information carrier of user permissions to be controlled and a multi-source information carrier of executed user permissions. The multi-source information carrier of user permissions to be controlled and the multi-source information carrier of executed user permissions belong to the sales user control permissions in the same data format; performing logical processing on the request information carrier of the multi-source information carrier of user permissions to be controlled to obtain a set of requests to be controlled; obtaining the set of executed control requests corresponding to the control policy in the multi-source information carrier of executed user permissions, and based on the matching degree between the set of executed control requests and the set of requests to be controlled, obtaining the set of control requests corresponding to the control policy in the multi-source information carrier of user permissions to be controlled from the set of requests to be controlled.
[0114] In another aspect, the present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it is configured to execute the permission control method based on user sales data provided by the above-mentioned various methods. The method includes: obtaining a multi-source information carrier of user permissions to be controlled and a multi-source information carrier of executed user permissions. The multi-source information carrier of user permissions to be controlled and the multi-source information carrier of executed user permissions belong to the sales user control permissions in the same data format; performing logical processing on the request information carrier of the multi-source information carrier of user permissions to be controlled to obtain a set of requests to be controlled; obtaining the set of executed control requests corresponding to the control policy in the multi-source information carrier of executed user permissions, and based on the matching degree between the set of executed control requests and the set of requests to be controlled, obtaining the set of control requests corresponding to the control policy in the multi-source information carrier of user permissions to be controlled from the set of requests to be controlled.
[0115] Although the present invention has been described in detail with reference to the foregoing embodiments, for those skilled in the art, they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some of the technical features. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A permission control method based on user sales data, characterized in that, Including: Obtaining a multi-source information carrier for the user permission to be controlled and a multi-source information carrier for the executed user permission control. The multi-source information carrier for the user permission to be controlled and the multi-source information carrier for the executed user permission control belong to the sales user control permission of the same data format; Performing request information carrier logic processing on the multi-source information carrier for the user permission to be controlled to obtain a set of requests to be controlled; Obtaining the set of executed control requests corresponding to the control policy in the multi-source information carrier for the executed user permission control, and obtaining the set of control requests corresponding to the control policy in the multi-source information carrier for the user permission to be controlled from the set of requests to be controlled based on the matching degree between the set of executed control requests and the set of requests to be controlled.
2. The permission control method based on user sales data according to claim 1, wherein The step of obtaining the matching degree between the set of executed control requests and the set of requests to be controlled includes: Based on the control history corresponding to the set of executed control requests in the multi-source information carrier for the executed user permission control, obtaining the order of the set of executed control requests; Based on the order of the set of executed control requests, the classified level of the permission data of the set of executed control requests, and the classified level of the permission data of the set of requests to be controlled, obtaining the matching degree between the set of executed control requests and the set of requests to be controlled.
3. The permission control method based on user sales data according to claim 2, wherein The control history includes a control period and a control intensity; The step of obtaining the order of the set of executed control requests based on the control history corresponding to the set of executed control requests in the multi-source information carrier for the executed user permission control includes: Based on the control period corresponding to the set of executed control requests in the multi-source information carrier for the executed user permission control, obtaining the first confidence level of the set of executed control requests; Based on the control intensity corresponding to the set of executed control requests in the multi-source information carrier for the executed user permission control, obtaining the second confidence level of the set of executed control requests; Based on the first confidence level and the second confidence level, obtaining the order of the set of executed control requests.
4. The permission control method based on user sales data according to claim 2, wherein The step of obtaining the matching degree between the set of executed control requests and the set of requests to be controlled based on the order of the set of executed control requests, the classified level of the permission data of the set of executed control requests, and the classified level of the permission data of the set of requests to be controlled includes: Based on the order of the set of executed control requests and the classified level of the permission data of the set of executed control requests, obtaining the weighted features of the set of executed control requests; Performing an association calculation on the classified level of the permission data of the set of requests to be controlled and the weighted features of the set of executed control requests to obtain the matching degree between the set of executed control requests and the set of requests to be controlled; The step of performing request information carrier logic processing on the multi-source information carrier for the user permission to be controlled to obtain a set of requests to be controlled includes: Performing request information carrier detection on the multi-source information carrier for the user permission to be controlled to obtain a plurality of request information carriers to be controlled; Setting the request information carriers to be controlled belonging to the same format as a group to obtain a plurality of groups of request information carriers to be controlled; Based on the request information carrier formats in each group of to-be-controlled request information carriers, obtain the matching groups of to-be-controlled request information carriers from each group of to-be-controlled request information carriers; Perform request information carrier logical processing among the matching groups of to-be-controlled request information carriers to obtain the set of to-be-controlled requests.
5. The permission control method based on user sales data according to claim 4, wherein The detecting of request information carriers for the multi-source information carriers of to-be-controlled user permissions to obtain a plurality of to-be-controlled request information carriers includes: Under a plurality of predetermined request information carrier formats, sequentially detect the request information carriers for the multi-source information carriers of to-be-controlled user permissions to obtain the to-be-controlled request information carriers corresponding to each predetermined request information carrier format; The multi-source information carriers of the executed control user permissions are the sales user control permissions corresponding within a predetermined time period.
6. A permission control system based on user sales data, characterized in that, It includes: An obtaining unit that obtains the multi-source information carriers of to-be-controlled user permissions and the multi-source information carriers of the executed control user permissions, where the multi-source information carriers of to-be-controlled user permissions and the multi-source information carriers of the executed control user permissions belong to the sales user control permissions of the same data format; A processing unit that performs request information carrier logical processing on the multi-source information carriers of to-be-controlled user permissions to obtain a set of to-be-controlled requests; An output unit that obtains the set of executed control requests corresponding to the control policies in the multi-source information carriers of the executed control user permissions, and based on the matching degree between the set of executed control requests and the set of to-be-controlled requests, obtains the set of control requests corresponding to the control policies in the multi-source information carriers of to-be-controlled user permissions from the set of to-be-controlled requests.
7. The permission control system based on user sales data according to claim 6, characterized in that, The output unit further includes: Based on the control history corresponding to the set of executed control requests in the multi-source information carriers of the executed control user permissions, obtain the order of the set of executed control requests; Based on the order of the set of executed control requests, the permission data confidentiality level of the set of executed control requests, and the permission data confidentiality level of the set of to-be-controlled requests, obtain the matching degree between the set of executed control requests and the set of to-be-controlled requests.
8. The privilege control system based on user sales data according to claim 7, wherein, The control history includes a control cycle and a control intensity; The obtaining of the order of the set of executed control requests based on the control history corresponding to the set of executed control requests in the multi-source information carriers of the executed control user permissions includes: Based on the control cycle corresponding to the set of executed control requests in the multi-source information carriers of the executed control user permissions, obtain the first confidence level of the set of executed control requests; Based on the control intensity corresponding to the set of executed control requests in the multi-source information carriers of the executed control user permissions, obtain the second confidence level of the set of executed control requests; Based on the first confidence level and the second confidence level, obtain the order of the set of executed control requests.
9. The permission control system based on user sales data according to claim 8, wherein The obtaining of the matching degree between the set of executed control requests and the set of to-be-controlled requests based on the order of the set of executed control requests, the permission data confidentiality level of the set of executed control requests, and the permission data confidentiality level of the set of to-be-controlled requests includes: Obtain the weighted features of the executed control request set based on the order of the executed control request set and the security level of the permission data of the executed control request set; Perform an association calculation on the security level of the permission data of the to-be-controlled request set and the weighted features of the executed control request set to obtain the matching degree between the executed control request set and the to-be-controlled request set; The logical processing of the request information carrier for the multi-source information carrier of the to-be-controlled user permission to obtain the to-be-controlled request set includes: Perform a request information carrier detection on the multi-source information carrier of the to-be-controlled user permission to obtain a plurality of to-be-controlled request information carriers; Set the to-be-controlled request information carriers belonging to the same format as a group to obtain a plurality of to-be-controlled request information carrier groups; Based on the request information carrier format in each to-be-controlled request information carrier group, obtain the matching to-be-controlled request information carrier groups from each to-be-controlled request information carrier group; Perform request information carrier logical processing among the matching to-be-controlled request information carrier groups to obtain the to-be-controlled request set.
10. The permission control system based on user sales data according to claim 9, characterized in that, The performing a request information carrier detection on the multi-source information carrier of the to-be-controlled user permission to obtain a plurality of to-be-controlled request information carriers includes: Under a plurality of predetermined request information carrier formats, sequentially perform a request information carrier detection on the multi-source information carrier of the to-be-controlled user permission to obtain the to-be-controlled request information carriers corresponding to each predetermined request information carrier format; The executed control user permission multi-source information carrier is the sales user control permission corresponding to a predetermined time period.
Citation Information
Patent Citations
User dynamic data authority control method and system
CN117332430A
Data processing method and device, electronic equipment and storage medium
CN117932641A
Financial security control method and device based on Internet of Things
CN119363492A
Security protection method and system based on multi-source data
CN119475367A