Enterprise data information collection authority management method
By grading aviation insurance data and embedding user portraits, establishing a data association matrix, and dynamically adjusting authority allocation, the problem of inefficient authority allocation in aviation insurance business is solved, and dynamic management of authority and improved security are achieved.
Patent Information
- Application Number
- CN202510868088.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-26
- Publication Date
- 2025-09-26
- Estimated Expiration
- 2045-06-26
AI Technical Summary
In the aviation insurance business, existing technologies make it difficult to effectively identify and adjust the authority allocation of staff to prevent excessive authorization and insufficient authority, resulting in inefficient authority allocation.
By acquiring the multi-dimensional features of aviation insurance data, data classification is performed, data relationship maps and data association matrices are established, user portraits are embedded, permission mapping channels are identified, storage status and life cycle are evaluated, and permission allocation is dynamically adjusted.
It realizes the dynamic allocation of permissions, real-time warning of permission abuse, automatic identification of abnormal coupling situations, prevention of permission configuration errors, and improves the efficiency and security of permission allocation.
Smart Images

Figure CN120705232A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data management, and in particular to a method for managing enterprise data information collection authority. Background Art
[0002] In the aviation insurance business, with the explosive growth of data volume and the increasing complexity of business scenarios, it is necessary to adjust the authority allocation of staff, such as adapting it according to data sensitivity and user operation scenarios, and identifying whether there is excessive authorization or insufficient authority, so as to adjust the authority to the real-time requirements of aviation insurance business scenarios.
[0003] For example, Chinese patent publication number CN118332055A discloses an artificial intelligence-based insurance information data protection method and system. The method obtains all insurance information data sequences; based on the data change characteristics in each sequence, it determines the partition priority of each insurance information data, and from this, it obtains all partition priority stacks; based on the data changes between two adjacent sampling moments in the partition priority stack and the amount of data at each sampling moment, it determines the insurance information iteration level of each partition priority stack; based on the difference characteristics of the insurance information data between two adjacent sampling moments in each partition priority stack, it determines the partition priority encryption index of each partition priority stack; and based on the partition priority encryption index, it encrypts and protects the insurance information data.
[0004] For example, Chinese patent publication number CN117591570A discloses an insurance data management method, device, electronic device and medium, the method including identifying the data features contained in each policy data and the feature values of each data feature, and determining a preset simulation diagram for each policy data; superimposing data according to the preset simulation diagram of each policy number and each feature value to obtain a policy data simulation diagram for each policy data; determining a target policy data simulation diagram and target data when a data filling instruction is detected; matching the filling data of the data filling instruction with the target data to determine a data matching value, and when the data matching value is higher than the preset matching value, executing a corresponding operation, and superimposing a marked feature on the position of the target data in the target policy data simulation diagram; generating a filling completion instruction when the marked feature of the target policy data simulation diagram is consistent with the number of data nodes of the target policy data simulation diagram.
[0005] In the existing technology, after updating the data in the stack, the insurance data is managed by using encryption indicators to identify the change form of insurance data at different sampling times, and the management method of insurance data is adjusted by simulating the position of insurance policies in the insurance data; however, in complex insurance data scenarios, it is necessary to identify the permissions and scenarios assigned to each user to prevent the occurrence of excessive authorization of some permissions and insufficient permissions, so as to meet the utilization efficiency of aviation insurance data under permission allocation. Summary of the Invention
[0006] In order to solve the above technical problems, the technical solution adopted by the present invention is: a method for managing enterprise data information collection permissions, including: S1, obtaining data sequences of aviation insurance data in different dimensions, and performing data classification on the accessed aviation insurance data to form a hierarchical data set.
[0007] S2, establish a data relationship map, record the data ownership of each element in the hierarchical data set, based on the data ownership of the hierarchical data set, apply the authentication business scope of each hierarchical data set, and identify the data association matrix under the authentication business scope.
[0008] S3, based on the acquired data association matrix, embeds the user profile of the staff into the data association matrix and determines the target mapping channel between different user profiles and the data association matrix.
[0009] S4, evaluates the storage status of the target mapping channel, and determines the user permission mapping strategy for different users under the user profile based on the control permissions received by the target mapping channel.
[0010] S5, based on the summary value of the user authority mapping policy, identifying the growth rate of the number of authority allocations after authority mapping, and adjusting and allocating user authority at all levels according to the growth rate.
[0011] The beneficial effects of the present invention are as follows: First, the present invention divides aviation insurance data into data sets involving multiple permissions through unified data classification, describes the hierarchical data sets that can be accessed by various users, and establishes a relationship map for the hierarchical data sets based on business scope. Change detection is performed on the assigned data permissions using associable and non-associated objects, and a data association matrix is used to associate data sets that may have errors in permission allocation relationships, thereby achieving real-time early warning of permission abuse.
[0012] 2. The present invention identifies strong coupling channels through the ratio of the actual number of permissions, the amount of accessed data to the user's initial permissions, the total amount of data, and the calculation of the user-data coupling degree, and automatically identifies abnormal coupling situations that occur under specific user permissions, preventing the problem of abnormal allocation of permissions when some staff members or user portraits are set incorrectly. The abnormal part is marked as a target mapping channel, and the permissions are automatically recovered based on the life cycle and update time of the associated data in the target mapping channel, thereby further realizing the dynamic allocation of insurance data-related permissions.
[0013] 3. The present invention triggers policy verification through the growth rate interval of the number of rights allocated, collects parts of historical data, and automatically identifies redundant rights and missing rights to complete the rights allocation problem under different policies, thereby realizing dynamic allocation processing of rights. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] The present invention will be further described below with reference to the accompanying drawings and examples.
[0015] Figure 1 It is a flowchart of an enterprise data information collection authority management method.
[0016] Figure 2 The present invention is a flowchart of step S2 of a method for managing enterprise data information collection rights.
[0017] Figure 3 The present invention is a flowchart of step S3 of a method for managing enterprise data information collection rights.
[0018] Figure 4 The present invention is a flowchart of step S4 of the enterprise data information collection authority management method.
[0019] Figure 5 The present invention is a flowchart of step S5 of the enterprise data information collection authority management method. DETAILED DESCRIPTION
[0020] The following embodiments of the present invention are described in detail. The embodiments described below are exemplary and are only used to explain the present invention, and are not to be construed as limiting the present invention. Where specific techniques or conditions are not specified in the embodiments, the techniques or conditions described in the literature in the art or in the product specifications shall be followed.
[0021] See Figure 1 , a method for managing enterprise data information collection rights, comprising: S1, obtaining data sequences of aviation insurance data in different dimensions, performing data classification on the accessed aviation insurance data, and forming a hierarchical data set.
[0022] S2, establish a data relationship map, record the data ownership of each element in the hierarchical data set, based on the data ownership of the hierarchical data set, apply the authentication business scope of each hierarchical data set, and identify the data association matrix under the authentication business scope.
[0023] S3, based on the acquired data association matrix, embeds the user profile of the staff into the data association matrix and determines the target mapping channel between different user profiles and the data association matrix.
[0024] S4, evaluates the storage status of the target mapping channel, and determines the user permission mapping strategy for different users under the user profile based on the control permissions received by the target mapping channel.
[0025] S5, based on the summary value of the user authority mapping policy, identifying the growth rate of the number of authority allocations after authority mapping, and adjusting and allocating user authority at all levels according to the growth rate.
[0026] Preferably, when performing data classification, aviation insurance data will be divided into multiple levels according to the different contents contained in it, such as public flight dynamics, desensitized policy statistics data after processing, sensitive data involving personal or commercial privacy, highly sensitive data related to claims records, and confidential data such as flight safety reports. According to the business attributes and sensitivity of aviation insurance data, it is divided into multiple different forms of categories, which facilitates the subsequent permission mapping of the data classification part to describe the permission information allocated in different scenarios.
[0027] The implementation method of step S1 includes: sending data classification verification information based on the acquired aviation insurance data, and extracting multi-dimensional features under insurance coverage, flight frequency, route distribution and sensitivity from the aviation insurance data.
[0028] A data verification token is generated based on the verification results of multi-dimensional features, and the aviation insurance data is sent to each hierarchical data set using the data verification token.
[0029] At this time, the relative situation of users' insurance coverage also needs to be considered when performing classification. For example, the coverage width represents the number of customers' insurance policies, and the flight frequency and flight distribution represent the data related to different flights. The sensitivity level represents whether the current aviation insurance data belongs to any data type such as basic information, high-sensitivity, and confidential. The results of these data verification are then formed into a data token to represent the permissions required for each type of data, and then these data are divided into multiple hierarchical data sets.
[0030] Preferably, a data verification token is used to identify the data corresponding to the coverage, flight frequency, route distribution, and sensitivity level, and then directly send the corresponding data to each classified data set. The data verification token is an identifier set in the aviation insurance data management. This identifier will indicate the classification of the currently received aviation insurance data, such as business inquiry, flight information, customer information, etc. The identifiers under these classifications are then mapped to different sensitivity levels. These are pre-labeled on the data itself when it is received.
[0031] In one embodiment of the present invention, a data relationship map is used to illustrate the source of each piece of data in a hierarchical data set after data classification, such as flight data → airline operating system, so as to describe the source of data in the hierarchical data set. Subsequently, data ownership will also indicate the relative person in charge of this data, such as passenger information → head of the customer information department; these contents are regarded as data ownership here, which is used to illustrate the relationship between data elements and corresponding persons in charge or departments, and can represent the association between different data and responsible authorities under business rules.
[0032] The authentication business scope will then indicate the processing scope of each piece of data to which type of person, and explain the identity authentication, permission verification, and business scenario coverage required for each piece of data in the hierarchical dataset after data reception. It is used to indicate the personnel, scenarios, and permissions that can be associated with the currently divided dataset; for example, underwriters can access the insured's historical policy records, and claims adjusters can query the black box data of accident flights, etc. After determining the initial permissions that can be assigned to different personnel, the data association matrix will further explain the parts that different personnel can operate. For example, underwriters can only query the data of a specific group of people, thereby limiting the association between different personnel and aviation insurance data.
[0033] like Figure 2 As shown, the implementation method of step S2 includes: defining the data entity under the current hierarchical data set, the data entity represents the policy information of each data in the current hierarchical data set, which is used to illustrate that after receiving the policy information, it is combined with the data attribution to identify it to obtain the relevant business scope and relevant personnel.
[0034] Based on the data entity, determine the data type, which includes passenger identity data, flight operation data, insurance product data, and claims process data. Guided by the data type of each data entity, query the data ownership to obtain the data ownership corresponding to each data entity.
[0035] Based on the data ownership of hierarchical data sets, the implementation method of applying the authentication business scope of each hierarchical data set also includes: based on the obtained data ownership, determining whether the current data entity has a superior data ownership. If a superior data ownership exists, then the authentication business scope is set based on the superior data ownership. The superior data ownership indicates that the data ownership corresponding to the current data entity still has the authority to operate by the superior. For example, if the current data is passenger identity data, which can be queried through customer service, and the customer service still has the authority to operate the data by the superior, then the scope of the current data ownership is described based on this superior, forming a relative data form of passenger → customer service → customer service manager → chief privacy officer to express the mapping relationship of the current data ownership.
[0036] Preferably, if a superior data ownership exists, the subordinate's permissions are inherited by default, and the superior data ownership is restricted by the permission verification method and constraints of the superior data ownership to obtain the authenticated business scope. In this case, the superior can inherit the subordinate's permissions, but in some business scenarios, the superior data ownership's permissions will be subject to corresponding constraints and permission verification methods.
[0037] If no superior data ownership exists, the current data entity is authenticated, and the business scenario, permission verification method, and constraints of the data entity are reviewed. Based on these business scenarios, permission verification methods, and constraints, the data entity's authentication business scope is set. Permission verification methods can be expressed as full access, read-write permissions only, or reading only specific fields. Constraints can be expressed as restricting permission usage, such as requiring approval for each access, requiring screen recording for operations, or requiring multiple verifications. Business scenarios indicate the content expressed by the current data, such as situations in business scenarios like claims processing, policy verification, and general information inquiries.
[0038] The final authentication business scope will cover the staff, permission verification and constraints in the business scenario, and then explain the permissions required in different scenarios.
[0039] When identifying the data association matrix, it is necessary to bidirectionally allocate and map the data that can be associated under different hierarchical sets, combined with the association mapping relationship under the content of business scenarios, personnel, and data types, to facilitate the subsequent input of user portraits to adjust the permission allocation and settings of each user.
[0040] That is, the implementation method of step S2 also includes: based on the authentication business scope of each hierarchical data set, using a preset permission template to identify the associable objects and non-associated objects under the authentication business scope, where the associable objects are used to illustrate the staff who can be associated with the current business scenario; non-associated objects represent staff who cannot be directly accessed and controlled.
[0041] If the states of the associable object and the non-associated object do not change after receiving the control authority, the corresponding associable object will be marked as a data association matrix.
[0042] This section manages staff permissions by automatically filtering irrelevant objects based on the access control lists and role mapping tables corresponding to preset permission templates. It also reviews the current configuration information for different data association matrices based on the staff's actual access information, such as the data type, customer information, unit metadata, access permission type, and validity period assigned to each staff member. This assigned data is treated as the current output data association matrix to complete the basic permission configuration for aviation insurance data.
[0043] If the state of an associable object changes after receiving control permissions, a reassessment is triggered. The permission set of the associable objects in each hierarchical dataset is used to set a score based on the ratio of the actual number of permissions of the associable object to the initial number of permissions, forming a permission scoring matrix. Each element in the permission scoring matrix represents the score corresponding to an associable object in a hierarchical dataset. The permission scoring matrix corresponding to each associable object is then traversed, and the part with the largest total score of the permission scoring matrix after traversal is output as the data association matrix.
[0044] If the state of a non-associated object changes after receiving control permissions, the non-associated object is marked and output as a high-risk association. As for the initial number of permissions, a set of initial permissions is set based on the data ownership of the staff member. The actual number of permissions for the currently received aviation insurance data at each data level is then checked. The largest associable object corresponding to the actual number of permissions is used as the output data association matrix to check whether the received aviation insurance data is sent to each staff member according to the normal permissions after the permission operation is executed. At the same time, checking the actual number of permissions is also used to determine whether there is an issue of excessive accumulation and allocation of permissions, which leads to excessive coupling between business data and staff members.
[0045] In one embodiment of the present invention, when embedding a user profile, if the currently embedded user profile does not fall within the data association matrix and the authentication business scope, the user profile is verified and its authentication business scope is redefined. The aforementioned user profile is used to represent data content under multiple dimensions, such as the identity of the currently accessed staff member, initially assigned permissions, and executable permission behaviors. Simultaneously, when establishing a target mapping channel, it is also necessary to determine the differentiated retention methods and related data lifecycles of the data association matrix and user profile after token-based association to select the target mapping channel corresponding to the user profile.
[0046] like Figure 3 As shown, the implementation method of step S3 also includes: combining the data association matrix with the user profile based on the actual number of permissions and the amount of accessed data corresponding to the data association matrix, and identifying the coupling measurement between the user profile and the data association matrix.
[0047] Based on the coupling measurement of user profile and data association matrix, it is determined whether there are two data association matrices with the same coupling amount and the global maximum coupling value.
[0048] If it exists, the corresponding data association matrix is used as the output target mapping channel; when it exists, it is easy for a single user to form a strong symmetrical coupling with multiple data, resulting in a single user needing two or more types of data to process when performing operations with their permissions, resulting in problems such as abuse of permissions or excessive accumulation of permissions. At this time, it can be indicated that there are risks in the current permission allocation and access, and these permissions need to be reconfigured.
[0049] If it does not exist, the coupling degree range of each data association matrix is checked based on the coupling degree, and the part exceeding the coupling degree boundary value is used as the output target mapping channel. The boundary value of the coupling degree checked at this time will set the confidence interval based on the coupling degree value corresponding to the target mapping channel in adjacent batches in the historical data, and at the 95% level of its confidence interval, the part exceeding the upper and lower limits of the confidence interval will be used as the output target mapping channel; when outputting the target mapping channel, it is necessary to process the multiple batches of data closest to the current time. If there is a continuous excess of some data associated with the data association matrix in three consecutive batches, the relevant data will be used as the target mapping channel for subsequent processing. Setting the target mapping channel here is to facilitate viewing the data queried in various situations and prevent the abuse of authority.
[0050] As for the calculation method of the above coupling degree, it is expressed as the sum of the ratios of the actual number of permissions and access data volume of each level of the currently received aviation insurance data under data classification to the user's initial allocated permission number and total data volume as its coupling degree; it should be noted that the access data volume refers to the access data volume under the actual permission number, while the total data volume refers to the data volume of each hierarchical data set under the data classification. The coupling degree obtained can then reflect the aggregation of the user's current operation behaviors related to different aviation insurance data, to find out whether there is excessive allocation of permissions and abnormal permission configuration.
[0051] In one embodiment of the present invention, when evaluating the storage status of the target mapping channel, the actual storage status of each data under the mapping channel currently established for different user portraits is obtained based on the differentiated storage form of the corresponding data.
[0052] like Figure 4 As shown, the implementation method of step S4 also includes: checking the permission position under the target mapping channel, performing differential analysis on each control permission based on the life cycle corresponding to the permission position, and extracting the differential unit corresponding to the target mapping channel.
[0053] Perform region mapping on the target mapping channel with the updated state of the differentiation unit.
[0054] Extract the update time interval corresponding to the target mapping channel, and obtain the user permission mapping policy based on the update time interval.
[0055] The life cycle represented at this time is the time interval during which a certain user has access rights to part of the aviation insurance data. This life cycle is used according to the automatic expiration mechanism to revoke the data query and processing rights of some personnel to prevent user rights from stacking. For example, the corresponding data in the target mapping channel is retained differentially through the data creation period, active period, decay period and frozen period, forming differentiated units corresponding to these four periods. The differentiated units represent the data sets corresponding to different life cycles after the life cycle is divided; the creation period represents the time period just created, the active period represents the peak period of such data query, the decay period represents the time period when the corresponding data query decreases sharply, and the frozen period represents the time period when the corresponding data permission is about to be automatically revoked or temporary permission is applied.
[0056] Then, after the data in the target mapping channel is segmented using these four cycles, it is identified whether each segmented data has been updated. If the query permissions and content have been updated, the updated part will be regionally mapped.
[0057] Preferably, the creation period means a 7-day creation period after the permission is assigned, during which the access log records the entire process and the relevant data can be viewed at any time; the active period means that the access frequency is ≥ 1 time / week within 30 days, and the permission is automatically renewed to complete the activity feedback of some data that needs to be viewed in time. The decay period means that the access frequency is < 1 time / week and lasts for 30 days, which triggers permission downgrade, such as from "edit" to "read-only". If there is a situation where certain data is not frequently operated, its permissions can be lowered to ensure the security of the corresponding data retention. The freezing period means that the permission will be automatically revoked if there is no access for 90 days, and it needs to be re-applied and approved. The data after the freezing period belongs to the retained data stored in the database that basically does not need to be viewed and processed. It can only be viewed and processed under specific circumstances to illustrate the efficiency of insurance data management and storage in different scenarios.
[0058] The above-mentioned permissions for data processing can be used to regulate the way staff handle relevant data. When some data has not changed for a long time, it means that the relevant data only needs to be stored and no other operations are required. The permissions of the relevant staff can be revoked to prevent errors in the corresponding data. At the same time, when the data in the updated target mapping channel is regionally mapped, the corresponding data is sorted from large to small according to the permission level and access frequency used by the staff. For example, the access frequency is the first keyword for sorting. When the access frequencies are the same, sort by permission level, so as to complete the data mapping and corresponding sorting.
[0059] Preferably, the authority levels are classified according to the corresponding levels when the data is classified to sort out the data for different staff members.
[0060] Afterwards, the processing continues according to the part of performing regional mapping. The implementation method of performing regional mapping on the target mapping channel also includes: based on different target mapping channels, the data association matrix corresponding to the target mapping channel is divided into equal intervals, and the control authority of the target mapping channel is viewed using the division result, and the user portrait corresponding to the target mapping channel is used to determine whether each division result is in an updateable state when the target mapping channel is updated. If it is in an updateable state, the historical control authority is compared with the current control authority based on the mapping relationship under the target mapping channel, so as to compare the difference in the received aviation insurance data at each time point; and the updated target mapping channel is extracted as the output data.
[0061] The comparison process at this time is to obtain the control permissions covered in the current updateable state and the data difference part of the corresponding query by comparing the historical control permissions in the updateable state to complete the area mapping of the differentiated unit.
[0062] Preferably, when obtaining the user authority mapping strategy based on the update time interval, the implementation method of obtaining the user authority mapping strategy also includes: obtaining the staff's control authority set through the target mapping channel corresponding to the detected control authority, and the control authority set identifies the update time interval under the business scope and employee type represented by different user portraits based on the principle of minimizing permissions for each user portrait.
[0063] If the target mapping channel update time interval is less than the preset threshold, it means that there is an exception when the current received data is processed for the target mapping channel. The user permission mapping strategy is obtained based on the maximum update time interval of the closest frequency of the target mapping channel in the historical data.
[0064] If the update time interval is greater than the preset threshold, it means that the user data processed in the target mapping channel is normal and there is no need to set a permission mapping policy.
[0065] The above-mentioned control permission set adopts a three-dimensional matrix of role-data-operation. For example, if the role is an underwriting specialist, the data is policy information, and it is at a high sensitivity level under data analysis, the operations include three permission modes: read-only, review, and export. When setting the control permission set, the permissions are dynamically trimmed to minimize the number of control permissions included in the control permission set. If the user only has export permissions when processing high-sensitivity policies, the export permissions will be deleted when the user is at a low sensitivity level, thereby minimizing the permissions available to the current staff.
[0066] The above-mentioned principle of minimizing permissions means that the control permissions of the current staff can only correspond to the current aviation insurance data, so as to control the amount of control permissions of the current staff based on the sensitivity level of the aviation insurance data.
[0067] Afterwards, the preset threshold corresponding to the update time interval can be calculated through historical data statistics, and the average value of the update time interval under normal aviation insurance data processing is used as the preset threshold at this time. If the current update time interval is less than the preset threshold, there may be problems of excessive updates and abnormal authority changes. The data under the batches closest to the current time will be merged and analyzed to find the largest time interval, and the operation will be reviewed. If there is a problem, the update time interval will be adjusted to the maximum time interval of the closest batch, and the user authority mapping strategy with the same value as this maximum time interval will be found from the database; the user authority mapping strategy at this time can represent an operation strategy for temporarily increasing the staff's authority or temporarily reducing the authority, to complete the closed-loop verification and dynamic adaptation of the authority, and improve the adaptability and risk prevention and control capabilities of the authority mapping strategy.
[0068] In one embodiment of the present invention, the summary value of the user authority mapping policy represents the symbol value of the implemented policy. At this time, it is necessary to identify the growth of the number of permissions allocated to the corresponding user after the temporary adjustment of the permissions, whether there are problems of over-authorization and authorization anomalies, and automatically reclaim the part that exceeds the role baseline permissions. For example, if the administrator configures the baseline permissions to be 30 items and currently holds 35 items, 5 items will be reclaimed.
[0069] like Figure 5 As shown, the implementation of step S5 includes: setting a growth rate interval based on the permission allocation quantity after permission mapping, and checking the current permission allocation quantity based on the abnormal mode of the growth rate interval under each range value.
[0070] The aforementioned abnormal patterns can indicate role mapping errors, permission inheritance defects, and lifecycle time and space issues. Role mapping errors indicate incorrect permission inheritance in certain scenarios, leading to abnormal permission growth for some users. Permission inheritance errors also indicate abnormal permission allocation issues. Lifecycle outages indicate issues with archived data remaining accessible. The growth rate range can be described using three percentage values to describe the current growth rate of permission allocations. For example, these are categorized into four states: safe, observation, high-risk, and emergency. When anomalies are detected in these four states, the abnormal pattern tags in the current database archive are checked based on their growth rate values.
[0071] Preferably, the growth rate interval can be divided into three values: 5%, 15%, and 30%, where 5% represents the number of temporary permissions granted to users under normal data maintenance. In addition to the 5% represented at this time, this ratio can also be set based on the average value of the number of temporary permissions granted under normal maintenance according to historical data, which accounts for the current user permissions; as for the value of 15%, it represents the number of temporary permissions granted to users in an emergency. At this time, it can also be set based on the number of temporary permissions granted to users in an emergency according to historical data; as for 30%, it represents the average value of the number of temporary permissions granted to users under abnormal circumstances. Here, it can also be set based on the average value of historical data under corresponding abnormal circumstances. It should be noted that the three values for dividing the growth rate interval are only used to schematically demonstrate the current division processing method for the growth rate value. In actual processing, it is set based on the relevant average value obtained from multiple batches of data or historical data.
[0072] Determine whether the current growth rate is greater than the predicted growth rate. If it is greater than the predicted growth rate, the currently marked user permission mapping policy is considered to be the target policy; otherwise, it is considered to be a non-target policy.
[0073] At this time, the predicted growth rate is divided by the number of temporary permissions granted under the state corresponding to the 30% value to identify the number of permissions allocated in relatively routine processing and in abnormal situations. The additional abnormal permissions granted are then traced back to the initial baseline permissions to achieve closed-loop adjustment of user permissions at all levels.
[0074] After mapping, the target and non-target policies of the user permission mapping policy are counted, and warning signals for permission allocation are output based on the target and non-target policies. During adjustments, the policy components that have been identified as causing abnormal permission allocation are also output, and these normal and abnormal components are processed to facilitate subsequent database updates of relevant mapping policies.
[0075] When outputting the permission allocation warning signal, the processing method also includes: checking the detection time corresponding to the growth rate under the permission allocation quantity, and using the appearance position of the target strategy on the time axis of the detection time to call the adjustment method of the target strategy to complete the adjustment of user permissions at all levels.
[0076] At this time, the detection duration is used to display the data marked as the target policy in the form of a timeline. For example, if a detection duration is 7 consecutive days, and if there is a situation that is considered to be abnormal permission growth in any time period within these seven days, it will be continuously monitored. After checking the location of the time period where the problem occurs, these exceeded permissions will be restored to the baseline. After describing the situation where abnormal permission growth is detected, the processing method corresponding to the current target policy is selected, such as patching the role mapping vulnerability, checking the marked sensitive data, and then outputting it to the external device after using the mark to complete the processing of the abnormal permission distribution.
[0077] Therefore, the above-mentioned detection time is used as the relevant parameter corresponding to the growth rate of the authority allocation data. The growth rate value obtained under the detection time is used, and the growth rate value, detection time and target strategy are used as common search conditions. The processing method obtained after the retrieval is used as the basis for adjusting the user permissions at all levels in the target strategy, and the basis is used as data output to the outside to assist staff in the allocation of relevant permissions for each business scope.
[0078] Although the embodiments of the present invention have been shown and described above, it will be understood that the above embodiments are illustrative and are not to be construed as limitations on the present invention. A person skilled in the art may make changes, modifications, substitutions and variations to the above embodiments within the scope of the present invention, which are still covered by the scope of protection of the present invention.
Claims
1. A method for managing enterprise data information collection rights, characterized in that: include: S1, obtain the data series of aviation insurance data in different dimensions, perform data classification based on the accessed aviation insurance data, and form a hierarchical data set; S2: Establish a data relationship map to record the data ownership of each element in the hierarchical data set. Based on the data ownership of the hierarchical data set, apply the authentication business scope of each hierarchical data set to identify the data association matrix under the authentication business scope. S3, based on the acquired data association matrix, embeds the user profile of the staff into the data association matrix and determines the target mapping channel between different user profiles and the data association matrix; S4, evaluating the storage status of the target mapping channel and determining the user permission mapping policy for different users under the user profile based on the control permissions received by the target mapping channel; S5, based on the summary value of the user authority mapping policy, identifying the growth rate of the number of authority allocations after authority mapping, and adjusting and allocating user authority at all levels according to the growth rate.
2. The enterprise data information collection authority management method according to claim 1, characterized in that: The implementation of step S1 includes: Based on the acquired aviation insurance data, data classification verification information is sent to extract multi-dimensional features in the aviation insurance data, including coverage width, flight frequency, route distribution, and sensitivity. A data verification token is generated based on the verification results of multi-dimensional features, and the aviation insurance data is sent to each hierarchical data set using the data verification token.
3. The enterprise data information collection authority management method according to claim 1, characterized in that: The implementation of step S2 includes: Based on the authentication business scope of each hierarchical data set, the preset permission template is used to identify the associated objects and non-associated objects under the authentication business scope; If the states of both the associable object and the non-associated object do not change after receiving the control authority, the corresponding associable object will be marked as a data association matrix; If the state of a non-associated object changes after receiving control authority, the non-associated object will be marked and output as a high-risk association.
4. The enterprise data information collection authority management method according to claim 1, characterized in that: Define the data entities under the current hierarchical data set, determine the data type based on the data entity, query the data ownership based on the data type of each data entity, and obtain the data ownership corresponding to each data entity; Based on the acquired data ownership, determine whether the current data entity has a parent data ownership. If so, the parent data ownership inherits the subordinate permissions by default, and uses the parent data ownership's permission verification method and constraints to restrict the parent data ownership and obtain the authentication business scope; If there is no superior data ownership, the current data entity is authenticated, and the business scenario, permission verification method and constraints of the data entity are checked. Based on the business scenario, permission verification method and constraints of the data entity, the authentication business scope of the data entity is set.
5. The enterprise data information collection authority management method according to claim 1, characterized in that: The implementation of step S3 further includes: Based on the actual number of permissions and the amount of accessed data corresponding to the data association matrix, the data association matrix is combined with the user profile to identify the coupling metric between the user profile and the data association matrix. Based on the coupling measurement between user profile and data association matrix, determine whether there are two data association matrices with the same coupling amount and the global maximum coupling value; If it exists, the corresponding data association matrix is used as the output target mapping channel; If it does not exist, the coupling range of each data association matrix is checked based on the coupling degree, and the part exceeding the coupling degree boundary value is used as the output target mapping channel.
6. The enterprise data information collection authority management method according to claim 1, characterized in that: The implementation of step S4 further includes: Check the permission location under the target mapping channel, perform differential analysis on each control permission based on the life cycle corresponding to the permission location, and extract the differential units corresponding to the target mapping channel; Performing regional mapping on the target mapping channel based on the updated state of the differentiation unit; Extract the update time interval corresponding to the target mapping channel, and obtain the user permission mapping policy based on the update time interval.
7. The enterprise data information collection authority management method according to claim 6, characterized in that: The implementation method of performing region mapping on the target mapping channel also includes: Based on different target mapping channels, the data association matrix corresponding to the target mapping channel is divided into equal intervals. The division results are used to check the control authority of the target mapping channel. The user portrait corresponding to the target mapping channel is used to determine whether each division result is in an updateable state when the target mapping channel is updated. If it is in an updateable state, the historical control authority is compared with the current control authority based on the mapping relationship under the target mapping channel, and the updated target mapping channel is extracted as the output data.
8. The enterprise data information collection authority management method according to claim 6, characterized in that: The implementation method of obtaining user rights mapping policy also includes: By mapping the target channel corresponding to the detected control permissions, the control permission set of the staff member is obtained. The control permission set is based on the principle of minimizing permissions for each user profile, and the update time intervals under the business scope and employee type represented by different user profiles are identified; If the target mapping channel update time interval is less than the preset threshold, it means that there is an exception when the current received data is processed for the target mapping channel. Then, the user permission mapping strategy is obtained based on the maximum update time interval of the closest frequency of the target mapping channel in the historical data; If the update time interval is greater than the preset threshold, it means that the user data processed in the target mapping channel is normal and there is no need to set a permission mapping policy.
9. The enterprise data information collection authority management method according to claim 1, characterized in that: The implementation of step S5 includes: Based on the number of permissions allocated after permission mapping, a growth rate range is set, and the current number of permissions allocated is checked based on the abnormal patterns of the growth rate range under various range values; Determine whether the current growth rate is greater than the predicted growth rate. If it is, the currently marked user permission mapping policy is considered the target policy; otherwise, it is considered a non-target policy. The target and non-target policies of the user authority mapping policy after mapping are counted, and the authority allocation warning signal is output based on the target and non-target policies.
10. The enterprise data information collection authority management method according to claim 9, characterized in that: When outputting the authority allocation warning signal, the processing method also includes: View the detection duration corresponding to the growth rate of the number of allocated permissions, and use the target policy's position on the timeline of the detection duration to adjust the target policy.
Citation Information
Patent Citations
Enterprise-level authority management method and system, electronic equipment and storage medium
CN115292272A
Enhanced identity authentication and resource access control system
CN116633638A
Data authority management method and device based on API configuration, equipment and medium
CN117407893A
Financial data access authority management method and system
CN119046994A
Enterprise authority management method, system and equipment based on machine learning and medium
CN119397503A
Cited By
Automatic sensitivity modeling method and system for full life cycle of equipment
CN121051793A