User authority management method, system and equipment for service platform and medium

Through vector matching and role-attribute mapping rules, user permissions of the power grid management platform can be quickly and accurately configured, solving the problem of complex permission configuration and high error rate in existing technologies and realizing efficient and dynamic permission management.

CN120597299APending Publication Date: 2025-09-05GUANGZHOU POWER SUPPLY BUREAU GUANGDONG POWER GRID CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510730526.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-03
Publication Date
2025-09-05

AI Technical Summary

Technical Problem

When configuring permissions for new users on the existing power grid management platform, the operation is complex and error-prone, affecting normal business processes. Traditional manual operations are inefficient and difficult to achieve fast and accurate permission configuration.

Method used

Through vector matching, the most suitable role is selected from the existing role set, and associated attributes are generated based on functional attributes. The permissions are configured in combination with the role-permission and attribute-permission mapping rules, and the RBAC and ABAC models are used for permission management.

Benefits of technology

It improves the efficiency and accuracy of permission configuration, is suitable for stable and complex application scenarios, dynamically adjusts permissions to meet users' actual needs, and reduces labor costs and configuration error rates.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120597299A_ABST
    Figure CN120597299A_ABST
Patent Text Reader

Abstract

The invention discloses a user authority management method, system and device of a service platform and a medium, and belongs to the technical field of system authority management, and the method comprises the steps: carrying out the vector matching of user attributes, and screening out the most adaptive role of a to-be-processed user from an existing role set; wherein the user attributes comprise basic attributes and function attributes; obtaining common information of the user to be processed and other existing users according to the function attributes, and generating association attributes of the user to be processed through the common information; on the basis of a preset role-permission mapping rule and the most adaptive role, performing permission configuration on a to-be-processed user; and performing permission configuration on the to-be-processed user based on a preset attribute-permission mapping rule and the association attribute. Therefore, by implementing the method and the device, the problems of low user authority management efficiency and relatively high configuration error rate in the prior art can be solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application belongs to the technical field of system authority management, and specifically relates to a user authority management method, system, device and medium for a business platform. Background Art

[0002] Currently, business platform permission management is implemented based on the user-role-permission model. This model is the foundation of permission management and is widely used within the industry for basic permission management. However, this model can only provide simple permission configuration. Existing power grid management platforms often involve multiple functional modules and complex businesses. Configuring permissions for a newly created user can be complicated by the numerous systems involved. This can lead to issues like being unable to find business forms, not having permission to approve applications, or incomplete returns. Therefore, how to quickly and accurately configure permissions for new users or precisely change permissions for existing users within a massive power grid business platform without disrupting normal business processes remains a major challenge.

[0003] Traditionally, permissions configuration and changes are typically performed manually by operators. However, manual operations are inefficient, resulting in delayed permissions and lengthy processes. Furthermore, when users are faced with complex permissions, configuration errors are prone to occur, disrupting normal business processes. Summary of the Invention

[0004] This application proposes a user rights management method and system for a business platform, which can solve the problems of low efficiency and high configuration error rate of user rights management in the prior art.

[0005] A first aspect of the present application provides a method for user rights management of a service platform, the method comprising:

[0006] By performing vector matching on user attributes, the most suitable role for the user to be processed is selected from the existing role set; wherein the user attributes include basic attributes and functional attributes;

[0007] According to the functional attributes, obtaining the shared information of the user to be processed and other existing users, and generating the associated attributes of the user to be processed through the shared information;

[0008] Based on the preset role-authority mapping rules and the most suitable role, the permissions of the user to be processed are configured;

[0009] Based on the preset attribute-authority mapping rules and the associated attributes, the permissions of the user to be processed are configured.

[0010] The above solution first uses vector matching to quickly and accurately identify the most suitable role for the user in question from a wide range of existing roles, improving the efficiency of assigning the corresponding role to the user. Then, based on the functional attributes of the role in question, it collects shared information about the data and processes handled by the user in the business platform with other existing users. This information determines the functions that the user should possess beyond the bound role, and generates relevant associated attributes for the user in question. Role-based permissions are then configured based on the role-permission mapping rules and the identified most suitable role. Because user permissions are determined by their roles, the system provides a clear structure and facilitates centralized permissions management, making it suitable for relatively stable application scenarios. Flexible permissions configuration for the user in question based on attribute-permission mapping rules and associated attributes enables fine-grained permission control and real-time adjustment based on the user's actual operations, making it suitable for complex and changing application scenarios. Therefore, configuring permissions for the user in question based on both roles and attributes significantly improves permission configuration efficiency, eliminating the need for operators to search through forms one by one to find the corresponding permissions and then configure them. In addition to manually judging whether the permission should be configured, the system also takes attributes into consideration for dynamic permission configuration, so that the functions the user has can meet actual needs, greatly improving the configuration accuracy.

[0011] In a possible implementation method of the first aspect, by performing vector matching on user attributes, the most suitable role for the user to be processed is screened from the existing role set, specifically:

[0012] Encoding the user attributes of the user to be processed to generate a first space vector;

[0013] Calculating the spatial distance between the first spatial vector and the role vector in the existing role set, and screening a candidate role set of the user to be processed from the existing role set based on the calculation result;

[0014] According to the configuration requirements of the user to be processed, the most suitable role is selected from the candidate role set.

[0015] The above solution uses a vector-based matching method to match the attributes of the user to be processed with the attributes of existing roles, initially finds a set of candidate roles that are similar to the user to be processed, and then filters out the most suitable role from the candidate role set, providing a basis for subsequent role-based permission configuration.

[0016] In a possible implementation method of the first aspect, a spatial distance between the first space vector and a role vector in an existing role set is calculated, and a candidate role set of the user to be processed is screened from the existing role set based on the calculation result, specifically:

[0017] The functional attribute is selected as the first dimension, and the spatial distance between the first space vector and the role vector on the first dimension is calculated, and roles that completely match the user to be processed on the first dimension are selected from the existing role set to obtain a first role set;

[0018] Selecting the basic attribute and the functional attribute corresponding to the basic attribute as a second dimension, and obtaining a user vector of an existing role in the first role set;

[0019] Obtaining vector similarity by calculating the spatial distance between the first spatial vector and the user vector of the existing character in the first character set in the second dimension;

[0020] The candidate role set is selected from the first role set based on vector similarity.

[0021] The above solution first uses functional attributes as the first dimension to find roles that fully match the user in question. This means finding roles that fully match the user's desired functions. Then, through matching on the second dimension, it finds roles that are even more similar to the user in question. Finally, it finds existing roles that share the same functions as the user in question and have similar basic personal information, effectively improving role matching efficiency.

[0022] In a possible implementation method of the first aspect, calculating the spatial distance between the first spatial vector and the user vector of an existing character in the first character set in the second dimension is specifically as follows:

[0023] The spatial distance in the second dimension is calculated as:

[0024]

[0025] Where x is the first space vector, y is the user vector of the existing character in the first character set, and x i is the value of x in the second dimension of i, y i is the value of y in the second dimension of i, w i is the weight on the i-th second dimension, and n is the total number of second dimensions.

[0026] In a possible implementation method of the first aspect, based on the functional attributes, shared information between the user to be processed and other existing users is obtained, and associated attributes of the user to be processed are generated based on the shared information, specifically:

[0027] Based on the same functional attributes, common information between the user to be processed and other existing users is collected, and business operation attributes of other existing users are obtained; wherein the business operation attributes are generated based on the business platform operation records of other existing users;

[0028] The associated attributes are generated for the user to be processed according to the common information and the business operation attributes.

[0029] The above solution uses the operation records of existing users on the business platform to determine the permissions that pending users with the same functional attributes should have in addition to the bound roles, and generates associated attributes for this purpose, so as to realize the configuration of updating permissions through dynamic factors such as operations and environment, and provide a basis for accurate implementation of permission configuration even under complex permission configuration requirements.

[0030] In a possible implementation method of the first aspect, based on a preset attribute-authority mapping rule and the associated attribute, permissions are configured for the user to be processed, specifically as follows:

[0031] Based on the attribute-authority mapping rule, configure process permissions for the user to be processed according to the functional attributes;

[0032] Based on the attribute-authority mapping rule, data permissions are configured for the user to be processed according to the associated attributes.

[0033] The above solution configures the user's operation permissions for business flows at different nodes through functional attributes, and configures the user's permissions to query and modify data through association attributes, thereby achieving precise configuration of permissions.

[0034] In a possible implementation method of the first aspect, the method further includes:

[0035] Using the functional attributes and the business operation attributes as personal attributes of existing users in the business platform, collecting the business platform operation records of the existing users according to a preset frequency;

[0036] Update the corresponding personal attributes through the business platform operation record;

[0037] According to the updated personal attributes, permissions are configured for the existing user.

[0038] The above solution will also collect the operation information of users on the business platform in real time, and then automatically configure corresponding permissions for the associated users based on the associated attributes of the operation information, so that the permission configuration can change with the actual situation of the platform. The permissions possessed by users can cope with the complex and changeable application environment of the business platform and meet the actual operation needs of users. It does not require manual regular updates, which greatly improves the efficiency of permission configuration.

[0039] A second aspect of the present application provides a user rights management system for a business platform, the system comprising: a role screening module, an associated attribute generation module, a role-rights configuration module, and an attribute-rights configuration module;

[0040] The role screening module is used to screen out the most suitable role for the user to be processed from the existing role set by performing vector matching on user attributes; wherein the user attributes include basic attributes and functional attributes;

[0041] The associated attribute generation module is used to obtain the common information of the user to be processed and other existing users based on the functional attributes, and generate the associated attributes of the user to be processed based on the common information;

[0042] The role-authority configuration module is used to configure the permissions of the user to be processed based on the preset role-authority mapping rules and the most suitable role;

[0043] The attribute-authority configuration module is used to configure the authority of the user to be processed based on the preset attribute-authority mapping rules and the associated attributes.

[0044] A third aspect of the present application provides a terminal device, which includes: a terminal device including a processor and a memory, the memory storing a computer program, and the processor implementing the steps of a user authority management method for a business platform as described in any one of the embodiments of the present application when executing the computer program.

[0045] A fourth aspect of the present application provides a storage medium storing computer-readable program code, which, when executed, implements the steps of a user rights management method for a business platform according to any one of the embodiments of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] In order to more clearly illustrate the technical solution of the present application, the following is a brief introduction to the drawings required for use in the implementation. Obviously, the drawings described below are only some implementation methods of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0047] Figure 1 This is a specific flow chart of a method for user rights management of a business platform provided by a certain embodiment of the present application;

[0048] Figure 2 This is a vector matching diagram of a user rights management method for a business platform provided in one embodiment of the present application;

[0049] Figure 3 This is a structural diagram of a user rights management system for a business platform provided in one embodiment of the present application;

[0050] Figure 4 A structural diagram of a terminal device is provided for a certain embodiment of the present application. DETAILED DESCRIPTION

[0051] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0052] It should be understood that the step numbers used herein are only for convenience of description and are not intended to limit the order in which the steps are to be executed.

[0053] First embodiment

[0054] The existing user-role-permission model can generally only implement basic permission management functions, such as user management, role management, and permission allocation. When it is necessary to configure permissions for users in multiple systems on the business platform, permission operations become complicated and cannot be configured in an integrated manner. Instead, manual configuration is required on each system, which is inefficient. Therefore, how to achieve accurate and automated permission configuration is a technical problem that needs to be solved.

[0055] like Figure 1 As shown, in order to solve the problems of low efficiency and high configuration error rate of rights management in the prior art, the first embodiment of the present application provides a specific flow diagram of a user rights management method for a business platform. The user rights management method for the business platform of this embodiment includes steps S1 to S4, which are detailed as follows:

[0056] Step S1: By performing vector matching on user attributes, the most suitable role for the user to be processed is selected from the existing role set.

[0057] In this embodiment of the present application, the user attributes of the user to be processed are first obtained, including basic attributes and functional attributes. The basic attributes include but are not limited to attributes related to the user, such as name, age, and gender, while the functional attributes are attributes related to authority allocation, such as department, position, and level.

[0058] When binding roles for pending users, due to the huge number of roles in the business platform, it is necessary to screen many roles within this large range to obtain a batch of candidate roles, and then conduct detailed screening within the candidate roles to determine the final most suitable role.

[0059] This embodiment of the present application uses vector proximity matching to find a suitable role for a user to be processed. First, the user attributes of the user to be processed are encoded and mapped to the candidate role space of an existing role set, resulting in a first spatial vector. The spatial distance between the first spatial vector and the role vectors in the existing role set is then calculated. This spatial distance is used to measure the similarity between the user to be processed and the existing roles, thereby determining a candidate role set for the user to be processed.

[0060] Specifically, the calculation of spatial distance is divided into matching on discrete dimensions and matching on continuous dimensions. First, a first dimension in which some functional attributes are discrete is selected, and then by calculating the spatial distance, the role vector in the existing role set that completely matches the first spatial vector on the first dimension is found to obtain the first role set. The first role set is actually the existing roles that are exactly the same as the user to be processed in terms of functional attributes. Among them, because the first dimension is the functional attributes that are dispersed and discontinuous with each other, for example, departments are dispersed and unrelated, and positions are also dispersed, so the vector matching based on the first dimension is also discrete matching.

[0061] Then, based on the first role set, a portion of continuous basic attributes and a portion of functional attributes are selected as the second dimension. The spatial distance between the first spatial vector and the existing roles in the first role set along the second dimension is calculated. This spatial distance is then used to measure the similarity between the user to be processed and the existing roles in the first role set. The calculation results are sorted by similarity, and a candidate role set is output. Because the second dimension is constructed based on continuous basic attributes and functional attributes, for example, age and level can be continuous, vector matching based on the second dimension is actually continuous matching.

[0062] Optionally, in the embodiment of the present application, department and position are selected as the first dimension, and level and age are selected as the second dimension.

[0063] To better illustrate the difference between discrete and continuous matching, Figure 2 A vector matching diagram is provided. As shown in the figure, the left figure shows discrete matching, and the right figure shows continuous matching. In the left figure, the horizontal axis represents discrete positions, the vertical axis represents discrete departments, and the red dots represent the users to be processed. The box called the first role set also contains existing roles that fully match the users to be processed in the first two dimensions of department and position, namely, existing roles in Department 2 and Position 2. Continuous matching is then performed based on the first role set. The horizontal axis of the right figure represents continuous levels, and the vertical axis represents continuous ages. Through continuous matching, two approximate existing roles are found for the role to be processed: an existing role that is slightly older than the role to be processed and is also at Level 2, and an existing role that is slightly younger than the role to be processed and is also at Level 2.

[0064] In addition, discrete matching is actually considered to be completely consistent matching, that is, it belongs to the same position in the discrete space; while continuous matching follows the following formula:

[0065]

[0066] Where d is the spatial distance between vectors, x is the first spatial vector, y is the user vector, and x i is the value of the first space vector in the second dimension of i, y i is the value of the user vector in the second dimension of i, w i is the weight on the i-th second dimension, and n is the total number of second dimensions.

[0067] Optionally, in an embodiment of the present application, the weight of level in the second dimension is set to 0.9, and the weight of age in the second dimension is set to 0.1.

[0068] Finally, the candidate role set is sorted according to the spatial distance obtained by the above formula, and then the most suitable role for the user to be processed is screened out, and the user to be processed is bound to the most suitable role.

[0069] Step S2: acquiring the shared information between the user to be processed and other existing users according to the functional attributes, and generating associated attributes of the user to be processed through the shared information.

[0070] In the embodiment of the present application, firstly, based on the same functional attributes, the common information of the user to be processed and other existing users is collected.

[0071] For example, in the power grid business platform, user A and user B belong to the same department, and the functional attribute "department" of user A and user B is the same. Then, the common information of user A and user B is collected for this department, including but not limited to user A and user B having access rights to a certain data form, and user A and user B having process approval rights related to this department.

[0072] At the same time, the business operation attributes of other existing users with the same functional attributes in the platform are obtained, including but not limited to system login records, form creation records, etc. The business operation attributes are generated based on the operation records stored by other existing users in the power grid business platform and can be directly obtained from the platform background.

[0073] As an improvement to the above solution, the business operation attributes and user attributes are stored and updated together as data of existing users in the platform, and permission management can be dynamically performed according to changes in the platform's environmental conditions, which can meet the permission management requirements of large-scale cross-system platforms.

[0074] Then, based on the shared information and the business operation attributes of other existing users, the associated attributes are generated for the user to be processed. The associated attributes will also be stored as part of the user like other attributes, assisting the ABAC model in attribute-based permission control.

[0075] The association data is used to describe the association between a user and other users, such as whether the users belong to the same department, are in the same platform ledger, and are on the same process node.

[0076] Step S3: Based on the preset role-authority mapping rules and the most suitable role, permissions are configured for the user to be processed.

[0077] In the embodiment of the present application, the RBAC model is used to implement role-based permission management. The RBAC model is called Role-Based Access Control, which controls access rights based on roles, and obtains corresponding permissions by assigning users to different roles.

[0078] Therefore, based on the preset role-permission mapping rules, the permissions corresponding to the most suitable role are configured for the pending user who has been bound to the most suitable role.

[0079] While role-based permission configuration is relatively simple and can manage user permissions by assigning and adjusting roles, meeting relatively simple access control requirements, this approach is only suitable for relatively secure and stable systems. Furthermore, the permissions assigned are based solely on the user's role. When faced with complex environments involving cross-system operations where users may have additional permissions in other systems beyond their bound roles, assigning permissions solely based on roles is insufficient to meet actual needs. Therefore, to ensure that users on the power grid business platform can smoothly operate across multiple integrated systems within the platform and to improve the accuracy of permission configuration, permission configuration based on the user's ever-changing attributes is also necessary.

[0080] Step S4: Based on the preset attribute-authority mapping rules and the associated attributes, permissions are configured for the user to be processed.

[0081] To address dynamically changing and diverse permission configuration scenarios, user permissions are dynamically determined based on user operations, platform resources, and the environment. To achieve this, the embodiments of this application employ the ABAC model for permission management. The ABAC model, short for Attribute-Based Access Control, is a model that determines access permissions based on attributes. It offers high flexibility and scalability, enabling permission decisions based on a variety of conditions and contextual information.

[0082] Platform permissions are generally divided into process permissions and data permissions. Process permissions are permissions designed for business functions, including the ability to add new processes, review processes, and archive processes, and are related to process nodes. Data permissions allow you to add, delete, query, and modify certain data, and are not related to process nodes.

[0083] Through pre-set attribute-permission mapping rules, permissions are configured based on the attributes of the pending user. Specifically, based on functional attributes, process permissions are assigned to pending users. For example, a department manager can approve applications within that department on the platform. Data permissions are also assigned to pending users based on associated attributes. For example, users at the same level in the same department can view each other's newly created forms.

[0084] Through attribute-based permission configuration, user permissions can be dynamically adjusted based on actual conditions. For example, in environments where permissions need to be adjusted frequently, permissions can be dynamically adjusted based on factors such as user role, location, and time of day. In enterprises with complex permission requirements, more detailed permission control can be provided to meet diverse needs.

[0085] As an improvement to the above solution, this embodiment of the present application also periodically collects business platform operation records of existing users within the platform, and then updates the user's personal attributes, including functional attributes and business operation attributes, based on the business platform operation records. The updated personal attributes are then used to reconfigure permissions for existing users, i.e., update the existing user's permissions to adapt to the dynamic environment of the business platform.

[0086] For example, user A and user B belong to the same department. When user A creates a new business form, user A's business operation attributes will update the form creation record, and user B will update the attribute "form creator's department". In the subsequent permission configuration, user B will be granted the permission to view the new form created by user A.

[0087] By combining role-based permission configuration and attribute-based permission configuration, the embodiment of the present application can be applied to the complex environment of the power grid business platform that integrates multiple systems, dynamically perform permission management, and effectively reduce labor costs and error costs caused by permission configuration errors.

[0088] The implementation of the embodiments of the present application has the following beneficial effects:

[0089] The embodiment of the present application improves the efficiency of configuring corresponding roles for users by first using vector matching to quickly and accurately find the most suitable role that is similar to the user to be processed in a wide range of existing roles. Then, based on the functional attributes of the role to be processed, the shared information of the user to be processed and other existing users in the business platform processing data and processes is collected, the functions that the user to be processed should have in addition to the bound role are determined, and relevant associated attributes are generated for the user to be processed. Then, based on the role-authority mapping rules and the determined most suitable role, role-based permission configuration is performed. Because the user's permissions are determined by the role to which they belong, its structure is clear and convenient for centralized management of permissions, which can be applied to relatively stable application scenarios. Flexible configuration of permissions for the user to be processed based on attribute-authority mapping rules and associated attributes can achieve fine-grained control of permissions and can adjust permissions in real time according to the user's actual operation situation, which is applicable to complex and changeable application scenarios. Therefore, by configuring permissions for the user to be processed based on roles and attributes respectively, the efficiency of permission configuration can be greatly improved, and the operator does not need to search the form one by one to find the corresponding permissions and then configure them. In addition to manually judging whether the permission should be configured, the system also takes attributes into consideration for dynamic permission configuration, so that the functions the user has can meet actual needs, greatly improving the configuration accuracy.

[0090] Second embodiment

[0091] Furthermore, in order to implement the user rights management system of the business platform corresponding to the above method embodiment to achieve the corresponding functions and technical effects, Figure 3 A structural diagram of a user rights management system for a business platform is provided. For ease of explanation, only the parts related to this embodiment are shown. The user rights management system for the business platform provided in this embodiment of the application includes:

[0092] The role screening module 201 is used to screen out the most suitable role for the user to be processed from the existing role set by performing vector matching on user attributes; wherein the user attributes include basic attributes and functional attributes.

[0093] In the embodiment of the present application, the user attributes of the user to be processed are encoded to generate a first space vector;

[0094] Calculating the spatial distance between the first spatial vector and the role vector in the existing role set, and screening a candidate role set of the user to be processed from the existing role set based on the calculation result;

[0095] According to the configuration requirements of the user to be processed, the most suitable role is selected from the candidate role set.

[0096] The associated attribute generation module 202 is configured to obtain the common information between the user to be processed and other existing users according to the functional attributes, and generate associated attributes of the user to be processed based on the common information.

[0097] In the embodiment of the present application, firstly, based on the same functional attributes, the common information of the user to be processed and other existing users is collected.

[0098] For example, in the power grid business platform, user A and user B belong to the same department, and the functional attribute "department" of user A and user B is the same. Then, the common information of user A and user B is collected for this department, including but not limited to user A and user B having access rights to a certain data form, and user A and user B having process approval rights related to this department.

[0099] At the same time, the business operation attributes of other existing users with the same functional attributes in the platform are obtained, including but not limited to system login records, form creation records, etc. The business operation attributes are generated based on the operation records stored by other existing users in the power grid business platform and can be directly obtained from the platform background.

[0100] As an improvement to the above solution, the business operation attributes and user attributes are stored and updated together as data of existing users in the platform, and permission management can be dynamically performed according to changes in the platform's environmental conditions, which can meet the permission management requirements of large-scale cross-system platforms.

[0101] Then, based on the shared information and the business operation attributes of other existing users, the associated attributes are generated for the user to be processed. The associated attributes will also be stored as part of the user like other attributes, assisting the ABAC model in attribute-based permission control.

[0102] The association data is used to describe the association between a user and other users, such as whether the users belong to the same department, are in the same platform ledger, and are on the same process node.

[0103] The role-authority configuration module 203 is used to configure the authority of the user to be processed based on the preset role-authority mapping rules and the most suitable role.

[0104] In the embodiment of the present application, the RBAC model is used to implement role-based permission management. The RBAC model is called Role-Based Access Control, which controls access rights based on roles, and obtains corresponding permissions by assigning users to different roles.

[0105] Therefore, based on the preset role-permission mapping rules, the permissions corresponding to the most suitable role are configured for the pending user who has been bound to the most suitable role.

[0106] While role-based permission configuration is relatively simple and can manage user permissions by assigning and adjusting roles, meeting relatively simple access control requirements, this approach is only suitable for relatively secure and stable systems. Furthermore, the permissions assigned are based solely on the user's role. When faced with complex environments involving cross-system operations where users may have additional permissions in other systems beyond their bound roles, assigning permissions solely based on roles is insufficient to meet actual needs. Therefore, to ensure that users on the power grid business platform can smoothly operate across multiple integrated systems within the platform and to improve the accuracy of permission configuration, permission configuration based on the user's ever-changing attributes is also necessary.

[0107] The attribute-authority configuration module 204 is used to configure the authority of the user to be processed based on the preset attribute-authority mapping rules and the associated attributes.

[0108] In this embodiment of the present application, to cope with dynamically changing and diverse permission configuration scenarios, user permissions are dynamically determined based on user operations, platform resources, and the environment. To achieve this, this embodiment of the present application uses the ABAC model for permission management. The ABAC model, short for Attribute-Based Access Control, is a model that determines access permissions based on attributes. It is highly flexible and scalable, and can make permission decisions based on a variety of conditions and contextual information.

[0109] Platform permissions are generally divided into process permissions and data permissions. Process permissions are permissions designed for business functions, including the ability to add new processes, review processes, and archive processes, and are related to process nodes. Data permissions allow you to add, delete, query, and modify certain data, and are not related to process nodes.

[0110] Through pre-set attribute-permission mapping rules, permissions are configured based on the attributes of the pending user. Specifically, based on functional attributes, process permissions are assigned to pending users. For example, a department manager can approve applications within that department on the platform. Data permissions are also assigned to pending users based on associated attributes. For example, users at the same level in the same department can view each other's newly created forms.

[0111] Through attribute-based permission configuration, user permissions can be dynamically adjusted based on actual conditions. For example, in environments where permissions need to be adjusted frequently, permissions can be dynamically adjusted based on factors such as user role, location, and time of day. In enterprises with complex permission requirements, more detailed permission control can be provided to meet diverse needs.

[0112] As an improvement to the above solution, this embodiment of the present application also periodically collects business platform operation records of existing users within the platform, and then updates the user's personal attributes, including functional attributes and business operation attributes, based on the business platform operation records. The updated personal attributes are then used to reconfigure permissions for existing users, i.e., update the existing user's permissions to adapt to the dynamic environment of the business platform.

[0113] For example, user A and user B belong to the same department. When user A creates a new business form, user A's business operation attributes will update the form creation record, and user B will update the attribute "form creator's department". In the subsequent permission configuration, user B will be granted the permission to view the new form created by user A.

[0114] By combining role-based permission configuration and attribute-based permission configuration, the embodiment of the present application can be applied to the complex environment of the power grid business platform that integrates multiple systems, dynamically perform permission management, and effectively reduce labor costs and error costs caused by permission configuration errors.

[0115] In some embodiments, the role screening module 201 is specifically:

[0116] First, obtain the user attributes of the user to be processed, including basic attributes and functional attributes. Basic attributes include but are not limited to user-related attributes such as name, age, and gender, while functional attributes are attributes related to authority allocation, such as department, position, and level.

[0117] When binding roles for pending users, due to the huge number of roles in the business platform, it is necessary to screen many roles within this large range to obtain a batch of candidate roles, and then conduct detailed screening within the candidate roles to determine the final most suitable role.

[0118] This embodiment of the present application uses vector proximity matching to find a suitable role for a user to be processed. First, the user attributes of the user to be processed are encoded and mapped to the candidate role space of an existing role set, resulting in a first spatial vector. The spatial distance between the first spatial vector and the role vectors in the existing role set is then calculated. This spatial distance is used to measure the similarity between the user to be processed and the existing roles, thereby determining a candidate role set for the user to be processed.

[0119] Specifically, the calculation of spatial distance is divided into matching on discrete dimensions and matching on continuous dimensions. First, a first dimension in which some functional attributes are discrete is selected, and then by calculating the spatial distance, the role vector in the existing role set that completely matches the first spatial vector on the first dimension is found to obtain the first role set. The first role set is actually the existing roles that are exactly the same as the user to be processed in terms of functional attributes. Among them, because the first dimension is the functional attributes that are dispersed and discontinuous with each other, for example, departments are dispersed and unrelated, and positions are also dispersed, so the vector matching based on the first dimension is also discrete matching.

[0120] Then, based on the first role set, a portion of continuous basic attributes and a portion of functional attributes are selected as the second dimension. The spatial distance between the first spatial vector and the existing roles in the first role set along the second dimension is calculated. This spatial distance is then used to measure the similarity between the user to be processed and the existing roles in the first role set. The calculation results are sorted by similarity, and a candidate role set is output. Because the second dimension is constructed based on continuous basic attributes and functional attributes, for example, age and level can be continuous, vector matching based on the second dimension is actually continuous matching.

[0121] Optionally, in the embodiment of the present application, department and position are selected as the first dimension, and level and age are selected as the second dimension.

[0122] In addition, discrete matching is actually considered to be completely consistent matching, that is, it belongs to the same position in the discrete space; while continuous matching follows the following formula:

[0123]

[0124] Where d is the spatial distance between vectors, x is the first spatial vector, y is the user vector, and x i is the value of the first space vector in the second dimension of i, y i is the value of the user vector in the second dimension of i, w i is the weight on the i-th second dimension, and n is the total number of second dimensions.

[0125] Optionally, in an embodiment of the present application, the weight of level in the second dimension is set to 0.9, and the weight of age in the second dimension is set to 0.1.

[0126] Finally, the candidate role set is sorted according to the spatial distance obtained by the above formula, and then the most suitable role for the user to be processed is screened out, and the user to be processed is bound to the most suitable role.

[0127] The implementation of the embodiments of the present application has the following beneficial effects:

[0128] The embodiment of the present application improves the efficiency of configuring corresponding roles for users by first using vector matching to quickly and accurately find the most suitable role that is similar to the user to be processed in a wide range of existing roles. Then, based on the functional attributes of the role to be processed, the shared information of the user to be processed and other existing users in the business platform processing data and processes is collected, the functions that the user to be processed should have in addition to the bound role are determined, and relevant associated attributes are generated for the user to be processed. Then, based on the role-authority mapping rules and the determined most suitable role, role-based permission configuration is performed. Because the user's permissions are determined by the role to which they belong, its structure is clear and convenient for centralized management of permissions, which can be applied to relatively stable application scenarios. Flexible configuration of permissions for the user to be processed based on attribute-authority mapping rules and associated attributes can achieve fine-grained control of permissions and can adjust permissions in real time according to the user's actual operation situation, which is applicable to complex and changeable application scenarios. Therefore, by configuring permissions for the user to be processed based on roles and attributes respectively, the efficiency of permission configuration can be greatly improved, and the operator does not need to search the form one by one to find the corresponding permissions and then configure them. In addition to manually judging whether the permission should be configured, the system also takes attributes into consideration for dynamic permission configuration, so that the functions the user has can meet actual needs, greatly improving the configuration accuracy.

[0129] Further, Figure 4 This is a structural diagram of a terminal device provided in one embodiment of the present application. Figure 4 As shown, the terminal device 3 of this embodiment includes: at least one processor 30 (in Figure 4 Only one is shown) and a memory 31 and a computer program 32 stored in the memory 31 and executable on the at least one processor. When the processor 30 executes the computer program 32, the steps of a user authority management method for a business platform described in any one of the embodiments of the present application can be implemented.

[0130] The terminal device 3 may be a computing device such as a desktop computer, a cloud server, or a laptop computer. The computing device may include but is not limited to a processor 30 and a memory 31 . Figure 4 This is merely an example of the terminal device 3 and does not constitute a limitation on the terminal device 3 , which may include more or fewer components than those shown in the figure.

[0131] An embodiment of the present application provides a storage medium storing computer-readable program code, which implements the steps of the above-mentioned method for user rights management of a business platform when the computer-readable program code is executed.

[0132] The specific embodiments described above further illustrate the purpose, technical solutions, and beneficial effects of this application. It should be understood that the above description is merely a specific embodiment of this application and is not intended to limit the scope of protection of this application. In particular, it should be noted that for those skilled in the art, any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of this application should be included in the scope of protection of this application.

Claims

1. A user rights management method for a business platform, characterized in that: include: By performing vector matching on user attributes, the most suitable role for the user to be processed is selected from the existing role set; wherein the user attributes include basic attributes and functional attributes; According to the functional attributes, obtaining the shared information of the user to be processed and other existing users, and generating the associated attributes of the user to be processed through the shared information; Based on the preset role-authority mapping rules and the most suitable role, the permissions of the user to be processed are configured; Based on the preset attribute-authority mapping rules and the associated attributes, the permissions of the user to be processed are configured.

2. The user rights management method of the business platform according to claim 1, characterized in that: By performing vector matching on user attributes, the most suitable role for the user to be processed is selected from the existing role set, specifically: Encoding the user attributes of the user to be processed to generate a first space vector; Calculating the spatial distance between the first spatial vector and the role vector in the existing role set, and screening a candidate role set of the user to be processed from the existing role set based on the calculation result; According to the configuration requirements of the user to be processed, the most suitable role is selected from the candidate role set.

3. The user rights management method of the service platform according to claim 2, characterized in that: The step of calculating the spatial distance between the first spatial vector and the role vectors in the existing role set, and filtering out a candidate role set of the user to be processed from the existing role set according to the calculation result, is specifically as follows: The functional attribute is selected as the first dimension, and the spatial distance between the first space vector and the role vector on the first dimension is calculated, and roles that completely match the user to be processed on the first dimension are selected from the existing role set to obtain a first role set; Selecting the basic attribute and the functional attribute corresponding to the basic attribute as a second dimension, and obtaining a user vector of an existing role in the first role set; Obtaining vector similarity by calculating the spatial distance between the first spatial vector and the user vector of the existing character in the first character set in the second dimension; The candidate role set is selected from the first role set based on vector similarity.

4. The user rights management method of the service platform according to claim 3, characterized in that: The calculation of the spatial distance between the first spatial vector and the user vector of the existing character in the first character set in the second dimension is specifically as follows: The spatial distance in the second dimension is calculated as: Where x is the first space vector, y is the user vector of the existing character in the first character set, and x i is the value of x in the second dimension of i, y i is the value of y in the second dimension of i, w i is the weight on the i-th second dimension, and n is the total number of second dimensions.

5. The user rights management method of the business platform according to claim 1, characterized in that: The method of obtaining the shared information of the user to be processed and other existing users based on the functional attributes and generating the associated attributes of the user to be processed through the shared information is as follows: Based on the same functional attributes, common information between the user to be processed and other existing users is collected, and business operation attributes of other existing users are obtained; wherein the business operation attributes are generated based on the business platform operation records of other existing users; The associated attributes are generated for the user to be processed according to the common information and the business operation attributes.

6. The user rights management method of the service platform according to claim 1, characterized in that: The permission configuration for the user to be processed based on the preset attribute-permission mapping rule and the associated attributes is specifically as follows: Based on the attribute-authority mapping rule, configure process permissions for the user to be processed according to the functional attributes; Based on the attribute-authority mapping rule, data permissions are configured for the user to be processed according to the associated attributes.

7. The user rights management method of a business platform according to any one of claims 1 to 6, characterized in that: Also includes: Using the functional attributes and the business operation attributes as personal attributes of existing users in the business platform, collecting the business platform operation records of the existing users according to a preset frequency; Update the corresponding personal attributes through the business platform operation record; According to the updated personal attributes, permissions are configured for the existing user.

8. A user rights management system for a business platform, characterized in that: include: Role screening module, associated attribute generation module, role-authority configuration module and attribute-authority configuration module; The role screening module is used to screen out the most suitable role for the user to be processed from the existing role set by performing vector matching on user attributes; wherein the user attributes include basic attributes and functional attributes; The associated attribute generation module is used to obtain the common information of the user to be processed and other existing users based on the functional attributes, and generate the associated attributes of the user to be processed based on the common information; The role-authority configuration module is used to configure the permissions of the user to be processed based on the preset role-authority mapping rules and the most suitable role; The attribute-authority configuration module is used to configure the authority of the user to be processed based on the preset attribute-authority mapping rules and the associated attributes.

9. A terminal device, characterized in that: The method comprises a processor and a memory, wherein the memory stores a computer program, and when the processor executes the computer program, the method implements the steps of the user rights management method of a business platform according to any one of claims 1 to 7.

10. A storage medium, characterized in that: The storage medium stores computer-readable program code, and when the computer-readable program code is executed, the steps of the user rights management method of a business platform according to any one of claims 1 to 7 are implemented.