Conference file dynamic authority management method and device, medium and product

By determining the operation permissions of the participating objects in the meeting and automatically adjusting the permissions using the pre-trained model, the problem that permission allocation in the existing technology cannot adapt to role changes is solved, dynamic permission management is realized, and meeting efficiency and effectiveness are improved.

CN120493293APending Publication Date: 2025-08-15GUANGZHOU BAOLUN ELECTRONICS CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510524664.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-24
Publication Date
2025-08-15

AI Technical Summary

Technical Problem

In the prior art, the permission allocation method of meeting documents cannot adapt to the scene of changes in the role of the participants, resulting in the need to manually modify the permissions, increasing the meeting time and inefficiency.

Method used

By determining the operation permissions of the attendees, collecting permission adjustment information during the meeting, and automatically adjusting permissions using the pre-trained permission adjustment model. The permission adjustment model is obtained based on historical meeting identity and information training, and is combined with neural networks such as LSTM or Transformer for permission management.

Benefits of technology

It realizes automatic adjustment of the permissions of the participants during the meeting, avoiding the interference of permission adjustment on the meeting, and improving the efficiency and effectiveness of the meeting.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120493293A_ABST
    Figure CN120493293A_ABST
Patent Text Reader

Abstract

The invention provides a conference file dynamic authority management method and device, a medium and a product, and relates to the technical field of computer security and authority management. The management method comprises the steps of determining an operation authority of a conference participating object to a conference file according to information of the conference participating object, and collecting authority adjustment information in a conference process; according to the permission adjustment information and a pre-trained permission adjustment model, the permission of the conference participating object is adjusted, the permission comprises the permission of the conference participating object for operating the conference file, and the permission adjustment model is obtained based on historical conference identity information and historical conference information training; according to the embodiment of the invention, the conference file processing authority of the conference participating object can be automatically adjusted in the conference process, dynamic authority management of the conference file is effectively realized, interference of authority adjustment on the conference is avoided, and the conference efficiency and the conference effect are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of computer security and rights management. Specifically, the present application relates to a method, device, medium and product for dynamic rights management of conference documents. Background Art

[0002] With the continuous development and popularization of intelligent equipment, traditional meeting formats have gradually been replaced by paperless meetings. Due to the advantages of paperless meetings such as high work efficiency, saving corporate costs, energy saving and environmental protection, they have been adopted and used by more and more enterprises and institutions.

[0003] Meeting document information management is a common issue in today's corporate management. Companies often hold meetings to communicate document information. When meeting topics, content, or document information need to be kept confidential, vigilance is especially important in managing meeting content and document information. Most existing technologies manually assign confidential meeting documents to designated participants during the meeting or manually edit the permissions of participants. This permission allocation method cannot adapt to the fixed permissions of participants during the meeting, and is difficult to adapt to scenarios where the roles of participants change in actual meeting environments. This results in the need for permission allocation personnel to manually modify permissions during the meeting, increasing meeting time and efficiency. Summary of the Invention

[0004] The present application provides a method, device, medium, and product for dynamic rights management of conference documents, which can solve the problem that existing rights allocation methods cannot adapt to role change scenarios. To achieve this goal, the present application provides the following solutions.

[0005] According to one aspect of an embodiment of the present application, a method for dynamic rights management of conference files is provided, comprising:

[0006] Determine the operating authority of the meeting participants for the meeting documents, and collect authority adjustment information during the meeting, wherein the authority adjustment information includes at least one of the meeting identity information and the meeting information;

[0007] The permissions of the participants are adjusted according to the permission adjustment information and a pre-trained permission adjustment model, wherein the permissions include permissions for the participants to operate conference files. The permission adjustment model is trained based on historical conference identity information and historical conference information.

[0008] In one possible implementation, the historical meeting information includes historical behavior data and meeting content features, and the training of the permission adjustment model includes:

[0009] Obtaining historical meeting information and historical meeting identity information corresponding to the historical meeting, and generating training samples based on the historical meeting information and the historical meeting identity information;

[0010] The training samples are used to perform neural network training to obtain a rights adjustment model, where the neural network includes any one of LSTM and Transformer.

[0011] In one possible implementation, determining the participant's permission to operate the conference file includes:

[0012] Determine a participant, collect information about the participant, and determine initial permissions of the participant based on the information, wherein the information about the participant includes at least one of identity information and device information;

[0013] The operation authority of the participant is determined based on the initial authority and the authority of the conference file, and the operation of the participant on the conference file is performed based on the operation authority. The operation authority includes at least one of the viewing authority, editing authority, downloading authority, forwarding authority, and restricted access object of the conference file.

[0014] In one possible implementation, adjusting the permissions of the participant according to the permission adjustment information and a pre-trained permission adjustment model includes:

[0015] Inputting the permission adjustment information into the permission adjustment model, and obtaining the permission adjustment information output by the permission adjustment model, wherein the permission adjustment information includes at least one of temporary permission allocation, information shielding, and device restriction;

[0016] The current permissions of the participant are determined according to the permission adjustment information and the initial permissions, and the permissions of the participant are adjusted to the current permissions using a smart contract.

[0017] In one possible implementation, determining the authority of the conference document includes:

[0018] Obtaining an uploaded conference document and extracting content of the conference document, the content including keywords and context information;

[0019] The type of the conference file is determined according to the content, type and historical access records, and the authority of the conference file is determined based on the type, where the type includes any one of a confidential file and a public file.

[0020] In one possible implementation, the method includes:

[0021] Collect metadata and conference operation information of conference documents during the conference, use the main chain in the dual-chain blockchain to store the metadata of the conference documents, and use the operation chain in the dual-chain blockchain to store the conference operation information.

[0022] In one possible implementation, the method includes:

[0023] Obtaining meeting behavior information of the meeting participants;

[0024] If it is determined that the conference behavior information meets a preset condition, the conference file corresponding to the conference behavior information is destroyed, and the preset condition includes at least one of abnormal behavior and file access timeout.

[0025] According to one aspect of an embodiment of the present application, an embodiment of the present application provides an electronic device, including a memory, a processor, and a computer program stored in the memory, wherein the processor executes the computer program to implement the steps of any of the above methods.

[0026] According to one aspect of an embodiment of the present application, an embodiment of the present application provides a computer-readable storage medium having a computer program stored thereon, and the computer program implements the steps of the above-described method when executed.

[0027] According to one aspect of an embodiment of the present application, an embodiment of the present application provides a computer program product, including a computer program, which implements the steps of the above method when executed by a processor.

[0028] The beneficial effects of the technical solution provided by the embodiments of the present application are:

[0029] The dynamic permission management method for conference files provided in the present application determines the operation permissions of the participants on the conference files based on the information of the participants, and collects permission adjustment information during the meeting; adjusts the permissions of the participants according to the permission adjustment information and a pre-trained permission adjustment model, and the permissions include the permissions of the participants to operate conference files. The permission adjustment model is trained based on historical conference identity information and historical conference information. The embodiment of the present application can automatically adjust the permissions of the participants to process conference files during the meeting, effectively realize dynamic permission management of conference files, avoid interference of permission adjustment on the meeting, and improve meeting efficiency and meeting results. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following is a brief introduction to the drawings required for describing the embodiments of the present application.

[0031] Figure 1 A flowchart of a method for dynamic rights management of conference documents provided in an embodiment of the present application;

[0032] Figure 2 This is a structural diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0033] The following describes the embodiments of the present application in conjunction with the accompanying drawings. It should be understood that the embodiments described below in conjunction with the accompanying drawings are exemplary descriptions for explaining the technical solutions of the embodiments of the present application and do not constitute a limitation on the technical solutions of the embodiments of the present application.

[0034] Those skilled in the art will understand that, unless otherwise stated, the singular forms "a," "an," "said," and "the" used herein may also include plural forms. It should be further understood that the terms "including" and "comprising" used in the embodiments of the present application mean that the corresponding features can be implemented as the presented features, information, data, steps, operations, elements, and / or components, but do not exclude implementation as other features, information, data, steps, operations, elements, components, and / or combinations thereof supported by the present technical field. It should be understood that when we refer to an element as being "connected" or "coupled" to another element, the element can be directly connected or coupled to the other element, or it can refer to the element and the other element establishing a connection relationship through an intermediate element. In addition, the "connection" or "coupling" used herein may include wireless connection or wireless coupling. The term "and / or" used herein indicates at least one of the items defined by the term, for example, "A and / or B" indicates implementation as "A," or implementation as "A," or implementation as "A and B."

[0035] In order to make the objectives, technical solutions and advantages of this application clearer, the implementation methods of this application will be further described in detail below with reference to the accompanying drawings.

[0036] The following describes several exemplary embodiments to illustrate the technical solutions of the embodiments of the present application and the technical effects produced by the technical solutions of the present application. It should be noted that the following embodiments can refer to, draw on, or combine with each other, and the same terms, similar features, and similar implementation steps in different embodiments will not be repeated.

[0037] The method, device, medium and product for dynamic permission management of conference documents provided in this application are intended to solve at least one technical problem existing in the prior art.

[0038] Optionally, the device that executes the dynamic permission management method for conference documents of the present application may be a mobile phone, tablet computer, server, or other smart terminal that can conduct online conferences and adjust permissions during the conference.

[0039] Alternatively, as Figure 1 As shown, the dynamic rights management method for conference documents of this application includes:

[0040] S101: Determine the operating authority of the meeting participants for the meeting documents and collect authority adjustment information during the meeting.

[0041] Optionally, the permission adjustment information includes at least one of conference identity information and conference information. The conference identity information includes information such as the participant's role in the meeting, rank, department, whether to upload meeting files, account number, device used, current location, and IP address. The conference information includes information such as the operations performed by the participant in the meeting (such as accessing meeting files, editing meeting files, number of speeches), and the content of the meeting.

[0042] Optionally, determining the operating permissions of the participants for the conference documents includes: determining the participants, collecting information of the participants, and determining the initial permissions of the participants based on the information, where the information of the participants includes at least one of identity information and device information; determining the operating permissions of the participants based on the initial permissions and the permissions of the conference documents, and performing operations of the participants on the conference documents based on the operating permissions, where the operating permissions include at least one of viewing permissions, editing permissions, downloading permissions, forwarding permissions, and restricted access permissions for the conference documents.

[0043] Optionally, the initial permissions may include permission levels of the conference participants, and the permissions of the conference files may also include permission levels, and the operations that the conference participants can perform on different conference files are determined based on the permission levels.

[0044] Optionally, the view permission can be set to only allow the attendee to view the file, but not edit or download it. The edit permission can be set to allow the attendee to modify the file contents. The download permission can be set to allow the attendee to download the file locally. The forward permission can be set to allow the attendee to share the file with other attendees. The restricted access permission can include information about attendees who are denied access to or manipulation of the conference file.

[0045] Optionally, before a meeting, participants can be authenticated based on their identity and device information. This identity information can include biometric information (such as fingerprints or facial recognition) or use MFA (multi-factor authentication) to verify the participant's ability to attend the meeting. If verification is successful, the participant's initial permissions are determined based on their device information.

[0046] Optionally, device credibility can be obtained based on device information and abnormal behavior of participants can be detected. Initial permissions can be determined based on the device credibility and abnormal behavior detection results. Specifically, if the device credibility is lower than a preset credibility threshold (e.g., the device is an unregistered unfamiliar device), access rights can be reduced or the participant can be required to verify using a preset verification method. If abnormal behavior is detected, the participant's permissions can be restricted to limit the participant's access to specific meeting files or require the participant to use a VPN to participate in the meeting.

[0047] In one embodiment, the device information may include information such as device ID (IMEI, MAC address), operating system (iOS / Android), browser type, etc., and the device information is used to identify whether the device used by the participant has been registered, whether it has been marked as high-risk, and whether it is a commonly used device of the participant, thereby obtaining the credibility of the device. The information of the participant may also include the network type, and information such as IP address, address location, and network type may be used to detect whether the access is from an unfamiliar location. Identity information may include user behavior (such as past login devices, login frequency, and file access history). Based on user behavior, information such as the frequency of device changes, whether the login IP is abnormal, and whether the device is switched multiple times in a short period of time is obtained to detect abnormal behavior. The participant type is determined based on the credibility of the device and the detection results of abnormal behavior, and the corresponding initial permissions of the type are assigned. Among them, high-trust users have normal access, medium-trust users require MFA, and low-trust users have restricted access.

[0048] Optionally, device trustworthiness can be restored through identity re-verification, device trust mechanisms, and continuous monitoring. Specifically, multi-factor authentication (MFA) can be used for identity re-verification, such as through SMS verification codes, email verification codes, or OTPs (one-time passwords). Upon successful verification, access rights can be temporarily or permanently restored. Biometric authentication can also be used, using fingerprint or facial recognition for additional verification to confirm the user's identity and restore normal permissions. Administrator-authorized restoration can also be performed, and after review and risk-free confirmation, the administrator can manually restore permissions. Regarding the device trust mechanism, participants can mark the device as "trusted." If the device is new, after multi-factor authentication, participants can choose to mark it as trusted. This will increase its trustworthiness and prevent future privilege reductions. Device fingerprint storage can also be implemented. Low device trustworthiness may be due to IP changes or device replacements. After additional verification, the current device's fingerprint can be stored in a list of trusted devices, ensuring unrestricted access the next time the device is logged in. For continuous monitoring and dynamic recovery, behavioral consistency detection can be used. If the subsequent operations of the participant conform to normal behavior patterns (such as no abnormal file downloads and normal access times), the trustworthiness will be automatically increased. Recovery can also be based on time thresholds. When a device is marked as low trust, the permissions may be automatically reduced for a predetermined period of time. After a long period of stable use, the permissions can be automatically restored to the trustworthiness before the marking.

[0049] Optionally, when restoring permissions, the following additional verification mechanisms based on identity authentication or behavior analysis can be used, and permissions can be restored after the verification is passed. Among them, when based on identity authentication, a verification code can be sent to a registered mobile phone or to the registered email address of the participant via SMS, and the verification code entered by the participant is received. If the verification code is correct, the verification is passed. It is also possible to identify whether the object that needs permission restoration is the participant by fingerprint or facial recognition. If so, the verification is passed. The identity of the participant can also be verified by security questions or hardware security keys. When based on behavior analysis, it can be detected whether at least one of the following conditions is met: multiple successful accesses in a short period of time, the device has been trusted in the past, and permissions are manually restored after review by the administrator. If so, it is determined that the verification is passed.

[0050] Optionally, determining the permissions of conference files includes: obtaining uploaded conference files, extracting the content of the conference files, the content including keywords and contextual information; determining the type of conference files based on the content, type and historical access records, and determining the permissions of the conference files based on the type, the type including any of confidential files and public files.

[0051] Optionally, the extraction of meeting content can be achieved through NLP (Natural Language Processing). Specifically, NLP is used to process the text of the meeting document to extract keywords and contextual information. When determining the type of the meeting document, the text can be input into an existing confidential document classification model based on the keywords and contextual information, and the type of the meeting document can be determined based on the output of the model. It is also possible to calculate the similarity between the corresponding meeting document and a pre-stored confidential document based on the keywords and contextual information to obtain a confidentiality score corresponding to the similarity. If the confidentiality score is greater than a preset threshold, the meeting document is determined to be a confidential document.

[0052] Optionally, after obtaining the confidentiality score, it is also possible to determine whether the meeting document belongs to a preset field (such as finance, law, government policy, etc.) based on keywords and contextual information. If so, the confidentiality score of the meeting document is increased (such as increasing the score by a preset value based on the field to which it belongs). It is also possible to obtain the historical access records of the meeting document and determine whether the document is a sensitive document based on the historical access records (such as limiting access to specific personnel in the historical records). If so, the confidentiality score is increased or it is directly determined to be a confidential document. Specifically, different categories of meeting documents have different keywords extracted. The relevant keyword extraction table is shown in Table 1:

[0053] Table 1

[0054] category Example keywords Financial documents Budget, profit, tax, equity Legal Documents Contracts, litigation, compliance, confidentiality R&D Report Code, patents, algorithms, sensitive technologies

[0055] Optionally, keyword extraction can be done using TF-IDF (Term Frequency-Inverse Document Frequency): extracting high-information vocabulary (suitable for unsupervised scenarios); TextRank: selecting core words based on graph algorithms (suitable for long texts); deep learning BERT / GPT keyword extraction: more accurately identifying business-related words; knowledge graph-based entity recognition (NER): matching specific industry terms such as "confidential", "financial statements", etc.).

[0056] Optionally, after determining the type of meeting document, the confidentiality level of the meeting document can also be determined based on preset rules and extracted keywords. Among them, the preset rules can be: the more high-risk keywords, the higher the confidentiality level; if legal + financial + highly sensitive words appear, the confidentiality level of the document is confidential; if the keywords only contain project progress and task schedule, the confidentiality level is internal; if it is determined based on the keywords that there is no sensitive information, the confidentiality level is determined to be ordinary. After determining the confidentiality level of the meeting document, the initial permissions can be generated based on the confidentiality level of the meeting document and the information of the participants (such as assigning initial permissions based on the role (rank) of the participants + the confidentiality level of the file). The relevant initial permission allocation examples can be shown in Table 2:

[0057] Table 2

[0058] Role ordinary internal confidential Top Secret ordinary employees Read-only Read-only No permission No permission director Read-only Editable Read-only No permission executives Editable Editable Downloadable Read-only Super Administrator Full permissions Full permissions Full permissions Full permissions

[0059] Optionally, if the meeting document is determined to be confidential, its permissions can be set to restrict downloading and forwarding, allowing only specific people to access it. If the meeting document is determined to be public, it can be accessed by all participants.

[0060] Optionally, during the meeting, permission adjustment information of each participant is continuously collected, and the permission adjustment information may include meeting identity information and meeting information. Among them, the meeting identity information may include account information (such as user ID, job grade, department), role (such as ordinary employee, supervisor, executive, super administrator), device information of the device used to participate in the meeting (such as device unique identification, operating system), and meeting information may include behavioral data, environmental variables, and meeting content characteristics. Among them, behavioral data may include access records (number and frequency of file accesses), editing records (file modifications, version changes), operation types (download, share, print), historical behavior patterns (such as the behavior of participants in historical meetings) and other data, and environmental variables may include IP addresses (such as intranet IP / extranet IP / abnormal IP), device credibility (such as authenticated device / new device), geographic location (such as office / remote office / abnormal country), time information (such as last login time, access duration) and other information.

[0061] S102: Adjust the rights of the participants according to the rights adjustment information and the pre-trained rights adjustment model.

[0062] Optionally, the authority includes the authority of the participant to operate the conference file, and the authority adjustment model is trained based on historical conference identity information and historical conference information.

[0063] Optionally, historical meeting information includes historical behavior data, meeting content features, and training of the permission adjustment model, including: obtaining historical meeting information and historical meeting identity information corresponding to historical meetings, generating training samples based on the historical meeting information and historical meeting identity information; using the training samples to train a neural network to obtain a permission adjustment model, and the neural network includes any one of LSTM and Transformer.

[0064] In one embodiment, historical meeting information is used to obtain participant identities (roles / levels), historical behavior data (file access frequency, operation types), and meeting content characteristics (keywords, confidentiality level). Training samples are generated based on this data. Meeting content characteristics can be obtained by accessing a database or log file used to store meeting content. Based on this training sample, an LSTM or Transformer neural network is used to train a permission adjustment model.

[0065] Optionally, during the use of the model, reinforcement learning can be used to dynamically optimize the permission adjustment strategy of the permission adjustment model. Among them, the intelligent permission agent (Agent) can be trained through RL to automatically learn the optimal permission adjustment strategy to adapt to different meeting scenarios, such as high-level meetings, remote meetings, cross-departmental collaboration, etc. Through reinforcement learning, a balance is achieved between security and user experience to avoid permission blocking caused by misjudgment. Specifically, the permission optimization process can be designed using state (State), action (Action), and reward (Reward). (1) The state space (State) represents the current security environment of the system, user behavior data, etc.:

[0066] state={

[0067] "user_role": user role (administrator, ordinary member, etc.),

[0068] "access_history": access records (recently accessed files, times),

[0069] "device_trust": device trustworthiness (whether it has been authenticated),

[0070] "location_risk": location risk (office network / remote / VPN),

[0071] "behavior_anomaly": behavioral anomaly score (high frequency downloads, etc.)

[0072] }

[0073] (2) Action space (Action) represents the permission adjustment operations that can be performed:

[0074] actions = ["Upgrade permissions", "Maintain permissions", "Downgrade permissions", "Deny access"]

[0075] (3) Reward mechanism is used to design reward functions so that the RL agent can learn the optimal authority adjustment strategy. For example:

[0076] Positive rewards (encourage correct adjustment of permissions):

[0077] Normal access, no security incidents occurred → +5

[0078] After reducing permissions, abnormal behavior was prevented → +10

[0079] Negative rewards (penalizing incorrect adjustments):

[0080] Misjudgment results in users being unable to access normal files → -5

[0081] Failure to adjust permissions leads to security incidents → -10

[0082] The relevant code representation can be:

[0083]

[0084]

[0085] During training, a Deep Q-Network (DQN) can be combined with a Deep Neural Network (DNN) to learn the optimal permission adjustment strategy. When a participant accesses a meeting file, the RL agent obtains the current state (State), predicts the optimal permission adjustment (Action) based on the current state, optimizes the permission adjustment information output by the permission adjustment model based on this optimal permission adjustment, and optimizes the permission adjustment based on the reward mechanism (Reward).

[0086] Optionally, temporary permission allocation can assign certain temporary permissions to the participants, and these permissions (such as editing, downloading) are only valid during the meeting or within a specific time, and are automatically revoked afterwards. Information shielding can be to set the participants as low-level users who can only view part of the meeting file information or to set the participants as high-level users who can access the complete file. When a high-risk device (such as an unregistered device) is detected based on the device information in the identity information, the permission adjustment model can output device restriction suggestions to limit the participants' permissions to download or edit meeting files. After the permission adjustment information is released, the permission adjustment information can be used to call a smart contract based on the permission adjustment information, and the permissions of the participants can be changed using the smart contract. Among them, the permission adjustment is decentralized and cannot be tampered with by using smart contracts to change permissions.

[0087] Optionally, the permission adjustment information may include information on whether a high-risk scenario has been identified. After obtaining the permission adjustment information, it can also be determined whether the permission adjustment information includes information on identifying a high-risk scenario or whether the permission change meets the preset review conditions. If so, the permission change application including the permission adjustment information will be sent to the preset administrator, and whether to execute the operation of the permission adjustment information will be determined based on the administrator's review information. High-risk scenarios may include participants accessing a large number of confidential files in a short period of time, identifying suspicious behavior (such as participants viewing files unrelated to their own positions) but the confidence level of the suspicious behavior is lower than the preset confidence level. The preset review conditions include that the permission change involves cross-departmental approval.

[0088] In one embodiment, the conference file is a confidential file that is only allowed to be edited by the speaker. During the meeting, the conference identity of the participant is detected. If it is determined that the conference identity has changed to a speaker, the permission adjustment model outputs information that allows the speaker to edit. Based on the information output by the permission adjustment model, the smart contract is called to set temporary permissions for the participant to edit the conference file. When the participant speaks, he or she can annotate the conference file. In addition, when the conference identity of the participant is no longer a speaker, the permission adjustment model outputs information that does not allow the participant to edit based on the obtained conference identity. The terminal executing the method of the present application calls the smart contract based on the information to cancel the temporary permission.

[0089] Optionally, an AI (such as a large model) tool can be called to analyze the permission adjustment information and meeting documents, and the permission adjustment information can be obtained based on the analysis results of the AI tool. Among them, the behavioral data of the participants (such as access frequency, operation type, access time) can be obtained, and the behavioral data can be input into the AI tool to obtain the behavioral analysis results of the participants (such as frequent downloading of confidential files, long-term access by trusted users), and permissions can be adjusted according to the behavioral analysis results (such as sudden frequent downloading of confidential files → reduce permissions; long-term access by trusted users → permissions can be upgraded). When the behavioral analysis results show that the participants perform high-risk behaviors, the permissions of the participants are reduced. If the behavioral analysis results show that the participants perform low-risk behaviors, the current permissions of the participants are maintained or the permissions are upgraded. Examples of relevant permission adjustments are shown in Table 3:

[0090] Table 3

[0091] Behavior Influence Sudden and frequent access to sensitive files Reduce access permissions Access from unauthorized devices Revoke permissions Multiple compliance operations by trusted users Can escalate privileges

[0092] Optionally, the method of the present application also includes: collecting metadata of conference documents and conference operation information during the meeting, using the main chain in the dual-chain blockchain to store the metadata of the conference documents, and using the operation chain in the dual-chain blockchain to store the conference operation information. The integrity and traceability of the data are ensured by the dual-chain blockchain storage method. Specifically, the main chain can store the metadata of the conference documents (hash value, version, confidentiality level and creation time), thereby recording the change information of the text. The operation chain records the operation information of the conference documents (such as operation type, timestamp, signature, device fingerprint and other information). The operation types include access, editing, downloading, forwarding and other types to ensure that all operations on conference documents in the meeting can be traced.

[0093] Optionally, each permission adjustment operation also generates a transaction record and writes it to the blockchain after the permission compliance is verified by the smart contract. The data written to the blockchain can be shown in Table 4:

[0094] Table 4

[0095] Field content user Operator ID Operation Type View / Download / Edit Document ID Unique file identifier Timestamp Operation time Device fingerprint Accessing device information Permission verification Comply with permission policy

[0096] In one embodiment, the participants upload the meeting file and calculate the hash value of the meeting file: use SHA-256 to calculate the unique hash of the file. Record the metadata of the meeting file to the main chain: use the main chain to store the hash value, version, confidentiality level, and creator information of the file. During the meeting, data needs to be stored (such as the editing or downloading operation of the participants triggers the data recording operation). The master node generates a transaction based on the data to be stored (including the hash value, signature, and other information of the meeting file corresponding to the operation data). The corresponding backup node verifies the data generated by the master node and stores it in consensus after verification, thereby realizing the storage of data. The relevant code for realizing the storage of evidence can be:

[0097]

[0098]

[0099] Optionally, when a participant accesses a file (e.g., viewing, downloading, or editing), the access behavior is recorded and an access record (timestamp, operation type, signature of the accessed object, and device fingerprint of the accessed device) is generated. The hash value of the operation data is calculated, and the access record and the hash value are submitted to the operation chain. The master node broadcasts the submitted data, and the backup node verifies and stores it. The relevant code stored in the operation chain can be:

[0100]

[0101] Optionally, after information is stored through the main chain and operation chain, the main chain and operation can also be used to query the information stored in the blockchain, thereby achieving data traceability and preventing meeting documents from being tampered with, thereby improving data security.

[0102] Optionally, the method of the present application also includes: obtaining meeting behavior information of the participants; if it is determined that the meeting behavior information meets preset conditions, destroying the meeting files corresponding to the meeting behavior information, and the preset conditions include at least one of abnormal behavior and file access timeout.

[0103] Optionally, abnormal behavior may include high-frequency downloading (download frequency greater than a preset frequency), unauthorized device access, and file access timeout may be that the access time is not within a preset time period (such as 72 hours after the meeting ends).

[0104] Optionally, when detecting whether the participant meets the file access timeout condition, a confirmation box for access may be popped up to the participant. If the participant enters access confirmation information through the confirmation box, it is determined that the participant meets the file access timeout condition.

[0105] Optionally, after determining that the conference behavior information meets the preset conditions, a request for information destruction may be sent to the administrator. If an instruction allowing destruction is received from the administrator, the conference file destruction operation is performed.

[0106] Optionally, the hash value corresponding to the conference file accessed by the participant who meets the preset conditions can be obtained and compared with the hash value stored in the blockchain evidence. If a match is successful (i.e., the blockchain stores the hash value corresponding to the accessed file), the file accessed by the participant is determined to be a controlled file and the file is destroyed. If the match fails, the file accessed by the participant is determined to be not a controlled file and the destruction operation is not performed.

[0107] Optionally, a trusted execution environment (TEE) can be called to physically delete the file. After the file is destroyed, the access rights of all objects related to the file (such as the original file owner, authorized users, historical access users, etc.) are revoked.

[0108] The dynamic permission management method for conference files provided in the present application determines the operation permissions of the participants on the conference files based on the information of the participants, and collects permission adjustment information during the meeting; adjusts the permissions of the participants according to the permission adjustment information and a pre-trained permission adjustment model, and the permissions include the permissions of the participants to operate conference files. The permission adjustment model is trained based on historical conference identity information and historical conference information. The embodiment of the present application can automatically adjust the permissions of the participants to process conference files during the meeting, effectively realize dynamic permission management of conference files, avoid interference of permission adjustment on the meeting, and improve meeting efficiency and meeting results.

[0109] Based on the same inventive concept, the embodiment of the present application provides an electronic device, such as Figure 2 As shown, Figure 2 The electronic device 2000 shown includes a processor 2001 and a memory 2003 . The processor 2001 and the memory 2003 are communicatively connected, for example, via a bus 2002 .

[0110] Processor 2001 can be a CPU (Central Processing Unit), a general-purpose processor, a DSP (Digital Signal Processor), an ASIC (Application Specific Integrated Circuit), an FPGA (Field-Programmable Gate Array), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It can implement or execute the various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. Processor 2001 can also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, etc.

[0111] Bus 2002 may include a path for transmitting information between the aforementioned components. Bus 2002 may be a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus, for example. Bus 2002 may be divided into an address bus, a data bus, a control bus, and so on. For ease of illustration, the figure shows only one thick line, but this does not indicate that there is only one bus or only one type of bus.

[0112] The memory 2003 may be a ROM (Read-Only Memory) or other types of static storage devices that can store static information and instructions, a RAM (random access memory) or other types of dynamic storage devices that can store information and instructions, or an EEPROM (Electrically Erasable Programmable Read Only Memory), a CD-ROM (Compact Disc Read-Only Memory) or other optical disk storage, optical disk storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited to these.

[0113] Optionally, the electronic device 2000 may further include a communication unit 2004. The communication unit 2004 may be used to receive and transmit signals. The communication unit 2004 may allow the electronic device 2000 to communicate with other devices wirelessly or by wire to exchange data. It should be noted that in actual applications, the number of communication units 2004 is not limited to one.

[0114] Optionally, the electronic device 2000 may further include an input unit 2005. The input unit 2005 may be configured to receive input digital, character, image, and / or sound information, or to generate key signal input related to user settings and function control of the electronic device 2000. The input unit 2005 may include, but is not limited to, one or more of a touch screen, a physical keyboard, function keys (such as a volume control key, a power key, etc.), a trackball, a mouse, a joystick, a camera, a microphone, and the like.

[0115] Optionally, the electronic device 2000 may further include an output unit 2006. The output unit 2006 may be used to output or display information processed by the processor 2001. The output unit 2006 may include, but is not limited to, one or more of a display device, a speaker, a vibration device, and the like.

[0116] Although the electronic device 2000 is shown with various devices, it should be understood that it is not required to implement or possess all the devices shown, and more or fewer devices may be implemented or possessed instead.

[0117] Optionally, the memory 2003 is used to store a computer program for executing the solution of the present application, and the execution is controlled by the processor 2001. The processor 2001 is used to execute the computer program stored in the memory 2003 to implement the steps of any method provided in the embodiments of the present application.

[0118] Based on the same inventive concept, an embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by an electronic device / processor, it implements the steps of any method provided in the present application / implements the steps of various optional implementation methods of the method provided in the present application.

[0119] Based on the same inventive concept, an embodiment of the present application provides a computer program product, which includes a computer program, which, when executed by an electronic device / processor, implements the steps of any method provided in the present application / implements the steps of various optional implementation methods of the method provided in the present application.

[0120] Those skilled in the art will appreciate that the steps, measures, and schemes in the various operations, methods, and processes discussed in this application may be interchanged, modified, combined, or deleted. Furthermore, other steps, measures, and schemes in the various operations, methods, and processes discussed in this application may also be interchanged, modified, rearranged, decomposed, combined, or deleted. Furthermore, steps, measures, and schemes in the related art that are similar to those disclosed in this application may also be interchanged, modified, rearranged, decomposed, combined, or deleted.

[0121] In the description of the present application, the directions or positional relationships indicated by words such as "center", "up", "down", "front", "back", "left", "right", "vertical", "horizontal", "top", "bottom", "inside", and "outside" are based on the exemplary directions or positional relationships shown in the accompanying drawings. They are for the convenience of describing or simplifying the description of the embodiments of the present application, and do not indicate or imply that the device or component referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be understood as limitations on the present application.

[0122] The terms "first," "second," "third," "fourth," "1," "2," and the like (if any) in the specification and claims of this application and the accompanying drawings are used to distinguish similar objects and are not necessarily used to describe a particular order or sequential sequence. It should be understood that the terms used in this manner are interchangeable where appropriate, so that the embodiments of the application described herein can be implemented in an order other than that shown or described in the drawings.

[0123] It should be understood that, although each operation step is indicated by arrows in the flowchart of the embodiment of the present application, the order of implementation of these steps is not limited to the order indicated by the arrows. Unless otherwise clearly stated herein, in some implementation scenarios of the embodiment of the present application, the implementation steps in each flowchart can be performed in other orders according to demand. In addition, some or all of the steps in each flowchart can include multiple sub-steps or multiple stages based on actual implementation scenarios. Some or all of these sub-steps or stages can be executed at the same time, and each sub-step or stage in these sub-steps or stages can also be executed at different times respectively. Under different scenarios at the execution time, the execution order of these sub-steps or stages can be flexibly configured according to demand, and the embodiment of the present application does not limit this.

[0124] The above description is only an optional implementation method for some implementation scenarios of this application. It should be pointed out that for ordinary technicians in this technical field, without departing from the technical concept of the solution of this application, the use of other similar implementation methods based on the technical ideas of this application also falls within the protection scope of the embodiments of this application.

Claims

1. A method for dynamic rights management of conference documents, characterized in that: include: Determine the operating authority of the meeting participants for the meeting documents, and collect authority adjustment information during the meeting, wherein the authority adjustment information includes at least one of the meeting identity information and the meeting information; The permissions of the participants are adjusted according to the permission adjustment information and a pre-trained permission adjustment model, wherein the permissions include permissions for the participants to operate conference files. The permission adjustment model is trained based on historical conference identity information and historical conference information.

2. The method for dynamic rights management of conference documents according to claim 1, characterized in that: The historical meeting information includes historical behavior data and meeting content features. The training of the permission adjustment model includes: Obtaining historical meeting information and historical meeting identity information corresponding to the historical meeting, and generating training samples based on the historical meeting information and the historical meeting identity information; The training samples are used to perform neural network training to obtain a rights adjustment model, where the neural network includes any one of LSTM and Transformer.

3. The method for dynamic rights management of conference documents according to claim 1, characterized in that: Determining the participant's authority to operate the conference documents includes: Determine a participant, collect information about the participant, and determine initial permissions of the participant based on the information, wherein the information about the participant includes at least one of identity information and device information; The operation authority of the participant is determined based on the initial authority and the authority of the conference file, and the operation of the participant on the conference file is performed based on the operation authority. The operation authority includes at least one of the viewing authority, editing authority, downloading authority, forwarding authority, and restricted access object of the conference file.

4. The method for dynamic rights management of conference documents according to claim 3, characterized in that: The adjusting the rights of the participants according to the rights adjustment information and the pre-trained rights adjustment model includes: Inputting the permission adjustment information into the permission adjustment model, and obtaining the permission adjustment information output by the permission adjustment model, wherein the permission adjustment information includes at least one of temporary permission allocation, information shielding, and device restriction; The current permissions of the participant are determined according to the permission adjustment information and the initial permissions, and the permissions of the participant are adjusted to the current permissions using a smart contract.

5. The method for dynamic rights management of conference documents according to claim 3, characterized in that: The determination of the authority of the meeting documents includes: Obtaining an uploaded conference document and extracting content of the conference document, the content including keywords and context information; The type of the conference file is determined according to the content, type and historical access records, and the authority of the conference file is determined based on the type, where the type includes any one of a confidential file and a public file.

6. The method for dynamic rights management of conference documents according to claim 1, characterized in that: The method comprises: Collect metadata and conference operation information of conference documents during the conference, use the main chain in the dual-chain blockchain to store the metadata of the conference documents, and use the operation chain in the dual-chain blockchain to store the conference operation information.

7. The method for dynamic rights management of conference documents according to claim 1, characterized in that: The method comprises: Obtaining meeting behavior information of the meeting participants; If it is determined that the conference behavior information meets a preset condition, the conference file corresponding to the conference behavior information is destroyed, and the preset condition includes at least one of abnormal behavior and file access timeout.

8. An electronic device comprising a memory, a processor, and a computer program stored in the memory, characterized in that: The processor executes the computer program to implement the steps of the method according to any one of claims 1 to 7.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed, the steps of the method according to any one of claims 1 to 7 are implemented.

10. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.