A method for managing the collection of enterprise data information permissions

By classifying aviation insurance data and embedding user profiles, a data association matrix is ​​established, and permission allocation is dynamically adjusted, thus solving the problem of incorrect permission configuration and achieving dynamic permission management and enhanced security.

CN120705232BActive Publication Date: 2026-01-23CIVIL AVIATION SHARING (BEIJING) TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510868088.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-26
Publication Date
2026-01-23
Estimated Expiration
2045-06-26

AI Technical Summary

Technical Problem

In the field of aviation insurance, existing technologies are insufficient to effectively identify and prevent over-authorization and under-authorization, resulting in inefficient allocation of permissions.

Method used

By acquiring multi-dimensional features of aviation insurance data, data is classified, a data relationship graph and a data association matrix are established, user profiles are embedded, permission mapping channels are identified, storage status and lifecycle are evaluated, and permission allocation is dynamically adjusted.

Benefits of technology

It enables dynamic management of permissions, provides real-time warnings of permission abuse, automatically identifies abnormal coupling situations, prevents permission configuration errors, and improves the efficiency and security of permission allocation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120705232B_ABST
    Figure CN120705232B_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of data management, in particular to a kind of enterprise data information collection authority management method, comprising: the data of aviation insurance data is graded, and hierarchical data set is formed;Record the data attribution of each element in hierarchical data set, based on the data attribution of hierarchical data set, apply the authentication business scope of each hierarchical data set, identify the data correlation matrix under the authentication business scope;Based on the data correlation matrix obtained, the user portrait of staff is embedded into data correlation matrix, and the target mapping channel of different user portrait and data correlation matrix is determined;Evaluate the storage state of target mapping channel, and with the control authority received by target mapping channel, determine the user authority mapping strategy of different users under user portrait;Based on the summary value of user authority mapping strategy, the growth rate of the number of authority allocation after authority mapping is identified, and the user authority of each level is adjusted and allocated according to the growth rate.It realizes the efficiency of aviation insurance data authority management.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data management, in particular to an enterprise data information collection permission management method. BACKGROUND

[0002] In the field of aviation insurance business, with the explosive growth of data volume and the complication of business scenarios, the permission allocation of staff needs to be adjusted, such as adaptation according to data sensitivity and user operation scenarios, and whether there is over-authorization and insufficient authorization needs to be identified to adjust the permission to meet the real-time requirements of aviation insurance business scenarios.

[0003] For example, Chinese Patent Publication No. CN118332055A discloses an insurance information data protection method and system based on artificial intelligence. The application obtains all insurance information data sequences; obtains the partition priority degree of each insurance information data according to the data change characteristics in each sequence, obtains all partition priority stacks through the partition priority degree; obtains the insurance information change degree of each partition priority stack according to the data change of the adjacent two sampling time points in the partition priority stack and the data quantity at each sampling time point; obtains the partition priority encryption index of each partition priority stack by combining the insurance information data difference characteristics of the adjacent two sampling time points in each partition priority stack; and encrypts and protects the insurance information data according to the partition priority encryption index.

[0004] For example, Chinese Patent Publication No. CN117591570A discloses an insurance data management method and device, electronic equipment and medium. The method includes identifying data features contained in each policy data and feature values of each data feature, determining a preset simulation graph of each policy data; performing data superposition according to the preset simulation graph of each policy data and each feature value to obtain a policy data simulation graph of each policy data; determining a target policy data simulation graph and target data when a data filling instruction is detected; matching the filling data of the data filling instruction with the target data to determine a data matching value, and when the data matching value is higher than a preset matching value, performing a corresponding operation and superimposing a feature on the position of the target data in the target policy data simulation graph; and when the annotation feature of the target policy data simulation graph is consistent with the data node quantity of the target policy data simulation graph, generating a filling completion instruction.

[0005] In the prior art, the management of insurance data is completed by updating the data in the stack and identifying the change form of insurance data at different sampling time points with an encryption index, and the management of insurance data is adjusted by simulating the position of the insurance data in the policy. However, in the complex insurance data scenario, the permissions and scenarios of each user need to be identified to prevent over-authorization and insufficient authorization of some permissions, so as to meet the utilization efficiency of aviation insurance data under permission allocation. SUMMARY

[0006] To solve the above technical problems, the technical scheme adopted by the present application is: an enterprise data information collection permission management method, comprising: S1, obtaining data sequences of aviation insurance data under different dimensions, and performing data classification on the accessed aviation insurance data to form a hierarchical data set.

[0007] S2, establishing a data relationship graph, recording the data attribution of each element in the hierarchical data set, and based on the data attribution of the hierarchical data set, applying the authentication business scope of each hierarchical data set to identify the data correlation matrix under the authentication business scope.

[0008] S3, based on the obtained data correlation matrix, embedding the user portrait of the staff into the data correlation matrix, and determining the target mapping channel of different user portraits and data correlation matrices.

[0009] S4, evaluating the storage state of the target mapping channel, and determining the user permission mapping strategy of different users under the user portrait according to the control permission received by the target mapping channel.

[0010] S5, based on the summary value of the user permission mapping strategy, identifying the growth rate of the number of permission allocations after permission mapping, and adjusting and allocating the user permissions at each level according to the growth rate.

[0011] The beneficial effects of the present application are: first, the hierarchical data classification of the present application divides the data set related to multiple permissions of aviation insurance data, describes the hierarchical data set that can be accessed by various users, and establishes a relationship graph of the hierarchical data set with the business scope, detects changes in the data permissions allocated to the associated and non-associated objects, uses the data correlation matrix to associate the data sets that may have incorrect permission allocation relationships, and realizes real-time early warning of permission abuse.

[0012] Second, the present application identifies strong coupling channels by calculating the user-data coupling degree based on the ratio of the actual number of permissions, the amount of access data, the user's initial permissions, and the total amount of data, automatically identifies abnormal coupling situations that occur under specific user permissions, prevents abnormal allocation of permissions in the case of errors in the setting of some staff or user portraits, marks the parts that exist abnormally as target mapping channels, and realizes automatic recycling of permissions based on the life cycle and update time of the associated data in the target mapping channel, and further realizes the dynamic nature of insurance data related permission allocation.

[0013] Third, the present application automatically identifies redundant permissions and missing permissions by checking the growth rate interval trigger strategy of the number of permission allocations, and collecting part of the historical data, to complete the allocation of permissions under different strategies, and realize dynamic allocation of permissions. BRIEF DESCRIPTION OF DRAWINGS

[0014] The application will be further described below in conjunction with the accompanying drawings and examples.

[0015] Figure 1 FIG. 1 is a flowchart of a business data information collection permission management method.

[0016] Figure 2 FIG. 2 is a flowchart of step S2 of the business data information collection permission management method.

[0017] Figure 3 FIG. 3 is a flowchart of step S3 of the business data information collection permission management method.

[0018] Figure 4 FIG. 4 is a flowchart of step S4 of the business data information collection permission management method.

[0019] Figure 5 FIG. 5 is a flowchart of step S5 of the business data information collection permission management method. DETAILED DESCRIPTION

[0020] Embodiments of the application will be described in detail below. The embodiments described below are exemplary and are intended to explain the application, but should not be construed as limiting the application. If a specific technique or condition is not mentioned in the embodiments, the technique or condition described in the literature in the art or according to the product manual is used.

[0021] Reference Figure 1 A business data information collection permission management method includes: S1, obtaining data sequences of aviation insurance data under different dimensions, performing data classification on the accessed aviation insurance data to form a classified data set.

[0022] S2, establishing a data relationship map to record the data attribution of each element in the classified data set, applying the authentication business scope of each classified data set based on the data attribution of the classified data set, and identifying the data correlation matrix under the authentication business scope.

[0023] S3, embedding the user portrait of the staff into the data correlation matrix based on the obtained data correlation matrix, and determining the target mapping channel of the different user portraits and the data correlation matrix.

[0024] S4, evaluating the storage state of the target mapping channel, and determining the user permission mapping strategy of different users under the user portrait according to the control permission received by the target mapping channel.

[0025] S5, identifying the growth rate of the number of permission mappings based on the summary value of the user permission mapping strategy, and adjusting and allocating the user permissions at each level according to the growth rate.

[0026] Preferably, when classifying data, aviation insurance data is divided into multiple levels according to the different contents it contains, such as publicly available flight information, processed and de-identified policy statistics, sensitive data involving personal or commercial privacy, highly sensitive data related to claims records, and confidential data such as flight safety reports. Based on the business attributes and sensitivity of aviation insurance data, it is divided into multiple different categories to facilitate subsequent permission mapping for the classified data, so as to describe the permission information allocated in different scenarios.

[0027] The implementation of step S1 includes: based on the acquired aviation insurance data, sending data classification verification information, and extracting multi-dimensional features under the insurance coverage, flight frequency, route distribution and sensitivity from the aviation insurance data.

[0028] Data verification tokens are generated based on the verification results of multi-dimensional features, and the data verification tokens are used to send the aviation insurance data to each graded dataset.

[0029] When classifying data at this point, it is also necessary to consider the relative situation of user insurance. For example, the insurance coverage represents the number of customers who have taken out insurance, while flight frequency and flight distribution represent data related to different flights. Then, the sensitivity level represents whether the current aviation insurance data belongs to any of the following data types: basic information, high sensitivity, confidential, etc. After verifying these data, a data token is formed to represent the permissions required for each type of data. Then, these data are divided into multiple graded datasets.

[0030] Preferably, the data verification token is used to indicate the sensitivity level of the data corresponding to the coverage scope, flight frequency, route distribution, and sensitivity level, and then directly sends the corresponding data to the respective tiered dataset. The data verification token is an identifier set in the management of aviation insurance data. This identifier indicates the category of the currently received aviation insurance data, such as business query, flight information, customer information, etc. These identifiers under each category will then correspond to different sensitivity levels, and all of this is pre-labeled on the data itself upon receipt.

[0031] In one embodiment of the present invention, a data relationship graph is used to illustrate the source of each piece of data in the hierarchical dataset after data classification, such as flight data → airline operation system, thereby describing the source of data in the hierarchical dataset. The data attribution also indicates the relative person in charge of the data, such as passenger information → customer information department manager. These contents are regarded as the data attribution here, which is used to illustrate the relationship between data elements and the corresponding person in charge or department, and can represent the association between different data and responsible authority under business rules.

[0032] The authentication business scope then indicates the processing scope of each piece of data belonging to which personnel, and explains the identity authentication, permission verification and business scenario coverage required for each piece of data in the hierarchical data set after data reception, and is used to indicate the content of the personnel, scenarios and permissions associated with the current divided data set; for example, an underwriter can access the historical policy records of the applicant, and a claims handler can query the accident flight black box data, etc. After determining the initial permissions that can be assigned to different personnel, the data association matrix further indicates the parts that can be operated by different personnel, such as the underwriter can only query the data of a part of specific population, thereby limiting the associated parts of the aviation insurance data of different personnel.

[0033] As shown in Figure 2 , the implementation mode of step S2 includes defining the data entity under the current hierarchical data set, the data entity representing the policy information of each piece of data in the current hierarchical data set, and being used to explain that after receiving the policy information, it is combined with the data attribution to obtain the related business scope and related personnel.

[0034] According to the data entity, the data type is judged, the data type including passenger identity data, flight operation data, insurance product data and claims process data, and the data attribution is queried based on the data type of each data entity to obtain the data attribution corresponding to each data entity.

[0035] Based on the data attribution of the hierarchical data set, the implementation mode of the authentication business scope of each hierarchical data set further includes: based on the obtained data attribution, judging whether there is a superior data attribution for the current data entity, and if there is a superior data attribution, setting the authentication business scope based on the superior data attribution. The superior data attribution indicates that the data attribution corresponding to the current data entity still has a superior operable permission allocation, such as the current data being passenger identity data, which can be queried by customer service, and the customer service also has a superior operable permission for the data, so the range to which the current data can belong is described based on this superior, forming a relative data form of passenger→customer service→customer service manager→chief privacy officer to express the mapping relationship of the current data attribution.

[0036] Preferably, if there is a superior data attribution, the subordinate permission is inherited by default, and the superior data attribution is limited in permission based on the permission verification mode and constraint condition of the superior data attribution, to obtain the authentication business scope. At this time, the superior can inherit the subordinate permission, but the permission of the superior data attribution will be limited by the corresponding constraint condition and permission verification mode under part of the business scenarios.

[0037] If there is no superior data attribution, the current data entity is authenticated, the business scenario, permission verification method and constraint condition of the data entity are viewed, and the authentication business scope of the data entity is set based on the business scenario, permission verification method and constraint condition of the data entity. At this time, the permission verification method can be represented as complete access, only read and write permission, only read specific fields, etc. The constraint condition is represented as each access needs to be approved, the operation needs to be recorded, and the multiple verification is needed to restrict the use of the permission. The business scenario refers to the content expressed by the current data, such as the situation in the business scenarios of claim settlement, policy verification, and regular information query.

[0038] The final authentication business scope covers the staff, permission verification and constraint condition in the business scenario, and then describes the required permissions in different scenarios.

[0039] In the identification data association matrix, the data that can be associated in different hierarchical sets needs to be bidirectionally allocated and mapped, and the association mapping relationship in the content of the business scenario, personnel and data type is combined, so as to facilitate subsequent input of user portrait to adjust the user permission allocation and setting.

[0040] That is, the implementation manner of step S2 further includes: based on the authentication business scope of each hierarchical data set, identifying the associated objects and non-associated objects in the authentication business scope based on a preset permission template, wherein the associated objects are used to indicate the staff that can be associated in the current business scenario; and the non-associated objects represent the staff that cannot be directly accessed and controlled.

[0041] If the states of the associated objects and the non-associated objects do not change after receiving the control permission, the corresponding associated objects are marked as the data association matrix.

[0042] This part of the content can automatically filter irrelevant objects based on the access control list and role mapping table corresponding to the preset permission template, to manage the permission allocation of the staff. According to the actual access information of the staff, the configuration information of the current data association matrix is viewed, such as the way of assigning data types, customer information, unit metadata, access permission types and permission validity period to each staff. The data assigned in this part is regarded as the current output data association matrix, to complete the basic permission configuration of the aviation insurance data.

[0043] If the state of the associable object changes after receiving the control authority, a re-evaluation is triggered, the number of actual authorities of the associable object is set as a score value through the authority set of the associable object in each hierarchical data set, and an authority score matrix is formed, each element in the authority score matrix representing a corresponding score value of an associable object in a hierarchical data set, and then the authority score matrix corresponding to each associable object is traversed, and the part with the maximum total score value of the traversed authority score matrix is taken as the output of the data association matrix.

[0044] If the state of the non-associable object changes after receiving the control authority, the non-associable object is marked and output as a high-risk association. As for the initial authority number, a set of initial authorities is set according to the data ownership of the staff, and then the actual authority number of the current received aviation insurance data under each data hierarchy is checked, and the maximum associable object corresponding to the actual authority number is taken as the output data association matrix to check whether the received aviation insurance data is sent to each staff according to the normal authority after the execution of the authority operation behavior, and the actual authority number is also used to distinguish whether there is a problem of excessive accumulation and distribution of authority, resulting in a high coupling phenomenon between business data and staff.

[0045] In an embodiment of the present application, when embedding a user portrait, if the currently embedded user portrait does not belong to the data association matrix and the authentication business scope, the user portrait is verified and the authentication business scope is re-determined. The user portrait is used to represent the data content in multiple dimensions such as the identity of the staff currently accessing, the initial allocated authority, and the executable authority behavior; and when establishing a target mapping channel, the difference between the data association matrix and the user portrait in the token-based association and the related data life cycle is also judged to select the target mapping channel corresponding to the user portrait.

[0046] As shown in Figure 3 The implementation mode of step S3 further includes: combining the data association matrix and the user portrait according to the actual authority number and the access data volume corresponding to the data association matrix, and identifying the coupling degree of the user portrait and the data association matrix.

[0047] Based on the coupling degree of the user portrait and the data association matrix, it is judged whether there are two data association matrices with the same coupling degree and the globally maximum coupling degree.

[0048] If the corresponding data association matrix exists, the target mapping channel is output; when it exists, a single user and multiple data form a strong symmetrical coupling, resulting in a single user needing two or more data to process when performing its permissions to operate, causing the problem of excessive accumulation of permissions or abuse of permissions, at which time it indicates that there is a risk in the current permission allocation and access, and the part of the permission needs to be reconfigured.

[0049] If it does not exist, the coupling degree range of each data association matrix is viewed based on the coupling degree, and the part exceeding the coupling degree boundary value is taken as the output target mapping channel. At this time, the boundary value of the coupling degree viewed is set as a confidence interval with the value of the coupling degree corresponding to the target mapping channel in the historical data under the adjacent batch, and with the 95% level of the confidence interval, the part exceeding the upper limit value and the lower limit value of the confidence interval is taken as the output target mapping channel; when the target mapping channel is output, the nearest multiple batch data of the current time needs to be processed, if there are continuous over-limit situations in the part of the data associated with the data association matrix in the continuous three batches, the related data is taken as the target mapping channel for subsequent processing, and the target mapping channel is set here to facilitate the viewing of the queried data in various situations, to prevent the abuse of permissions.

[0050] As for the above-mentioned coupling degree calculation method, the coupling degree is represented as the sum of the ratio of the actual permission quantity and the access data quantity of each level under the data classification to the initial allocation permission quantity and the total data quantity of the user of the currently received aviation insurance data; it needs to be noted that the access data quantity refers to the access data quantity under the actual permission quantity, and the total data quantity represents the data quantity of each data set under the data classification, and then the obtained coupling degree can reflect the aggregation of the user's operation behavior related to different aviation insurance data, to find out whether there is an excessive allocation of permissions and abnormal configuration of permissions.

[0051] In an embodiment of the present application, when evaluating the storage state of the target mapping channel, the actual storage state of each data under the mapping channel established for different user portraits is obtained based on the differentiated storage form of the corresponding data.

[0052] As shown in Figure 4 The implementation mode of step S4 further includes: viewing the permission position under the target mapping channel, differentially analyzing each control permission according to the life cycle corresponding to the permission position, and extracting the differential unit corresponding to the target mapping channel.

[0053] The target mapping channel is regionally mapped according to the update state of the differential unit.

[0054] The update time interval corresponding to the target mapping channel is extracted, and the user permission mapping strategy is obtained according to the update time interval.

[0055] The life cycle represented at this time is the time interval during which a user has access to part of the aviation insurance data. The life cycle is revoked for data querying and processing by part of the personnel according to an automatic expiration mechanism to prevent the stacking of user permissions. For example, the corresponding data in the target mapping channel is differentiated and retained through the creation period, active period, decay period and frozen period of the data to form differentiated units corresponding to the four periods. The differentiated units represent the data set corresponding to different life cycles after the life cycle is divided. The creation period represents the time period after creation. The active period represents the peak period of data querying. The decay period represents the time period during which the corresponding data querying sharply decreases. The frozen period represents the time period during which the permission of the corresponding data is about to be automatically revoked or the time period of the temporary permission applied.

[0056] Then the data in the target mapping channel is segmented according to the four periods, and it is identified whether the segmented data is updated. If the querying permission and content are updated, the updated part is regionally mapped.

[0057] Preferably, the creation period represents a 7-day creation period after the permission is allocated. During the period, the access log is recorded throughout the process, and the relevant data situation can be viewed at any time. The active period represents that the access frequency is ≥1 time / week within 30 days, and the permission is automatically renewed to complete the active feedback of part of the data that needs to be viewed in time. The decay period represents that the access frequency is <1 time / week and lasts for 30 days, triggering the permission downgrade, such as from “edit” to “read only”. If there is no operation on certain data, the permission can be reduced to ensure the security of the corresponding data retained. The frozen period represents that the permission is automatically revoked after 90 days of non-access. The permission needs to be re-applied and approved. The data after the frozen period belongs to the retained data stored in the database and basically does not need to be viewed and processed. Only in special cases can it be viewed and processed to illustrate the efficiency of insurance data management and storage in different scenarios.

[0058] The above-mentioned related permissions for data processing can be used to regulate the processing method of the relevant data by the staff. When part of the data has not been changed for a long time, it means that the relevant data only needs to be stored and does not need to be operated. The permission of the relevant staff can be revoked to prevent errors in the corresponding data. When the data in the updated target mapping channel is regionally mapped, the corresponding data is sorted in descending order of the permission level and the access frequency used by the staff. For example, the access frequency is the first keyword for sorting. When the access frequency is the same, the permission level is sorted. In this way, the data mapping and corresponding sorting are completed.

[0059] Preferably, the permission level is classified according to the level corresponding to the data classification to sort the data for different staff.

[0060] Afterwards, the implementation manner of performing regional mapping on the target mapping channel according to the part of performing regional mapping further includes: based on different target mapping channels, performing equal interval division on the data association matrix corresponding to the target mapping channel, using the division result to view the control authority of the target mapping channel, and using the user portrait corresponding to the target mapping channel to determine whether each division result is in an updateable state when the target mapping channel is updated, if it is in an updateable state, comparing the historical control authority with the current control authority based on the mapping relationship under the target mapping channel, to compare the difference in receiving aviation insurance data at each time point; and extracting the updated target mapping channel as output data.

[0061] At this time, the comparison process is to compare the control authority of the historical control authority in the updateable state to obtain the control authority covered in the current updateable state and the difference part of the corresponding query data, to complete the regional mapping of the differentiated unit.

[0062] Preferably, when obtaining the user authority mapping strategy in the update time interval, the implementation manner of obtaining the user authority mapping strategy further includes: obtaining the control authority set of the staff through the target mapping channel corresponding to the detected control authority, and identifying the update time interval under the business scope and employee category represented by each user portrait according to the minimum authority principle of each user portrait.

[0063] If the update time interval of the target mapping channel is less than the preset threshold value, it indicates that there is an exception when the current received data is processed for the target mapping channel, and the user authority mapping strategy is obtained based on the maximum update time interval of the closest frequency in the historical data of the target mapping channel.

[0064] If the update time interval is greater than the preset threshold value, it represents that the user data processed in the target mapping channel is normal, and the authority mapping strategy does not need to be set.

[0065] The control authority set described above adopts a role-data-operation three-dimensional matrix, for example, the role is an underwriting officer, the data is policy information, and the operation includes read-only, review, and export three permission modes. In the manner of setting the control authority set to dynamically clip the authority, the control authority contained in the control authority set can be minimized. If the user can only have export authority when processing high-sensitivity level policies, the export authority is deleted when it is in a low-sensitivity level, thereby minimizing the available authority of the current staff.

[0066] The minimum authority principle described above means that the control authority of the current staff can only correspond to the current aviation insurance data to control the number of control authorities of the current staff based on the sensitivity level of the aviation insurance data.

[0067] After the update time interval corresponding to the preset threshold value can be updated by historical data statistics, the average value of the update time interval under the normal aviation insurance data processing is taken as the preset threshold value at this time, if the current update time interval is less than the preset threshold value, there may be excessive update and permission change abnormal problems, and the data under the nearest several batches from the current time are combined and analyzed to find the maximum time interval, and the operation is audited, if there is a problem, the update time interval is adjusted to the maximum time interval of the nearest batch, and the user permission mapping strategy with the same maximum time interval value is found from the database; The user permission mapping strategy at this time can represent the operation strategy of temporarily increasing the permission of the staff or temporarily reducing the permission, to complete the closed-loop verification, dynamic adaptation and other contents of the permission, and improve the adaptability and risk prevention and control ability of the permission mapping strategy.

[0068] In an embodiment of the application, the summary value of the user permission mapping strategy represents the symbol value of the implemented strategy, at this time, it is necessary to identify the growth of the number of permissions allocated to the user after temporary adjustment of the permission, whether there is a problem of excessive authorization and authorization abnormality, and automatically recover part of the role reference permission exceeding the reference permission, such as the reference permission configured by the administrator being 30, and the current holding being 35, then recovering 5.

[0069] As shown in Figure 5 The implementation mode of step S5 includes: based on the number of permissions allocated after permission mapping, setting a growth rate interval, checking the current permission allocation number according to the abnormal mode of the growth rate interval in each range value.

[0070] The above-mentioned abnormal mode will represent the role mapping error, permission inheritance defect and life cycle space-time problem, the role mapping error represents that the permission is inherited incorrectly in part of the scene, resulting in abnormal growth of the permission of part of the users, the permission inheritance permission also represents that there is an abnormal problem in the permission allocation, and the life cycle out of control represents the problem that the archived data can still be accessed. As for the growth rate interval, three percentage values can be used to describe the current permission allocation number growth rate, for example, divided into four states of safety, observation, high risk and emergency, when the abnormality is found, the abnormal mode tag of the current database archive is viewed according to the growth rate value.

[0071] Preferably, the division of the growth rate interval can be divided by 5%, 15%, and 30%. The 5% represents the number of temporary permissions assigned to the user under normal data maintenance. This ratio can also be set based on the average number of temporary permissions assigned under normal maintenance according to historical data. The 15% represents the number of temporary permissions assigned to the user in an emergency. This value can also be set based on the number of temporary permissions assigned to the user in an emergency according to historical data. The 30% represents the average number of temporary permissions assigned to the user in an abnormal situation. This value can also be set based on the average number of temporary permissions assigned to the user in an abnormal situation according to historical data. It should be noted that the three values for dividing the growth rate interval are only used to illustrate the current division of the growth rate. In actual processing, the relevant average values obtained from the data of multiple batches or historical data are used for setting.

[0072] Determine whether the current growth rate is greater than the predicted growth rate. If it is greater than the predicted growth rate, it is considered that the current user permission mapping strategy is the target strategy. Otherwise, it is considered to be a non-target strategy.

[0073] The predicted growth rate is set to 30% to divide the number of temporary permissions assigned in the corresponding state. This is used to identify the number of permissions assigned in the normal situation and the abnormal situation. Then, the additional abnormal permissions are traced back to the initial baseline permissions to achieve closed-loop adjustment of the user permissions at all levels.

[0074] The target strategy and non-target strategy of the user permission mapping strategy after mapping are counted, and a permission allocation warning signal is output based on the target strategy and non-target strategy. During the adjustment, the part of the strategy that causes the abnormal permission allocation is also output. This part is processed normally and abnormally to facilitate subsequent database update of the mapping strategy.

[0075] When outputting the permission allocation warning signal, the processing method also includes checking the detection duration corresponding to the growth rate of the permission allocation quantity, and checking the position of the target strategy on the time axis of the detection duration, retrieving the adjustment method of the target strategy, and completing the adjustment of the user permissions at all levels.

[0076] The detection duration is used to display the data marked as the target strategy in the form of a time axis. For example, a detection duration of 7 consecutive days is used. If there is an abnormal situation in the permission growth in any time period within the seven days, it will be continuously monitored. After checking the position of the time period where the problem occurs, the excess permissions are restored to the baseline. After describing the detection of the abnormal permission growth, the processing method corresponding to the current target strategy is selected, such as repairing the role mapping vulnerability, checking the marked sensitive data, and then outputting to the external device to complete the processing of the abnormal permission distribution.

[0077] The detection time length is a relevant parameter corresponding to the growth rate of the permission allocation data. The growth rate value obtained under the detection time length is used as a common search condition together with the detection time length and the target strategy to search for a processing mode. The processing mode obtained after the search is used as a basis for adjusting the user permissions at each level in the target strategy. The basis is output to the outside to assist the staff in understanding the relevant permission allocation situation in each business scope.

[0078] Although the embodiments of the present application have been shown and described above, it should be understood that the above embodiments are exemplary and should not be construed as limiting the present application. Those skilled in the art can make changes, modifications, replacements and variations to the above embodiments within the scope of the present application, which are still covered by the protection scope of the present application.

Claims

1. A method for managing enterprise data information collection permissions, characterized in that, include: S1, acquire data sequences of aviation insurance data under different dimensions, classify the accessed aviation insurance data into a hierarchical dataset; The implementation of step S1 includes: based on the acquired aviation insurance data, sending data classification verification information, extracting multi-dimensional features under the insured breadth, flight frequency, route distribution and sensitivity in the aviation insurance data; generating data verification tokens based on the verification results of the multi-dimensional features, the data verification tokens are identifiers set in the management of aviation insurance data, used to determine the classification category of aviation insurance data, and sending aviation insurance data to each classification dataset using the data verification tokens; S2, establish a data relationship graph, record the data ownership of each element in the hierarchical dataset, and based on the data ownership of the hierarchical dataset, apply the authentication business scope of each hierarchical dataset to identify the data association matrix under the authentication business scope; Data attribution is used to explain the relationship between data elements and the corresponding responsible persons or departments; The scope of authentication services indicates which personnel are responsible for processing each piece of data, and explains the identity verification, permission verification, and business scenario coverage required for each piece of data in the hierarchical dataset after data reception. The data association matrix is ​​used to bidirectionally assign and map data that can be associated under different hierarchical sets, assigning labels to associated objects, and allowing users to view the configuration information of the data association matrix based on the actual access information of staff. S3, based on the acquired data association matrix, embed the staff user profiles into the data association matrix, and determine the target mapping channels between different user profiles and the data association matrix; The implementation of step S3 also includes: combining the data association matrix with the user profile based on the actual number of permissions and the amount of data accessed corresponding to the data association matrix, and identifying the coupling metric between the user profile and the data association matrix; based on the coupling metric between the user profile and the data association matrix, determining whether there are two data association matrices with the same coupling metric and the largest global value of the coupling metric; if so, using the corresponding data association matrix as the target mapping channel for output; if not, checking the coupling metric range of each data association matrix based on the coupling metric, and using the part exceeding the coupling metric boundary value as the target mapping channel for output. The coupling metric is calculated as the sum of the ratios of the actual number of permissions and the amount of data accessed at each level of the currently received aviation insurance data under the data hierarchy to the number of permissions initially assigned to the user and the total amount of data, which is taken as its coupling degree. S4. Evaluate the storage status of the target mapping channel and determine the user permission mapping strategy for different users under the user profile based on the control permissions received by the target mapping channel. Storage status represents the lifecycle of permissions, indicating the timeframe during which a user has access to specific content within the aviation insurance data. S5, based on the summary value of the user permission mapping strategy, identify the growth rate of the number of permissions allocated after permission mapping, and adjust the allocation of user permissions at all levels according to the growth rate; The summary value represents the flag value of the implemented strategy.

2. The enterprise data information collection permission management method according to claim 1, characterized in that, Step S2 can be implemented in the following ways: Based on the authentication business scope of each hierarchical dataset, the associated and unassociated objects under the authentication business scope are identified by a preset permission template; the associated objects are used to describe the staff that can be associated in the current business scenario, which are the personnel indicated by the identity verification, permission verification and business scenario coverage required for each piece of data in the hierarchical dataset after the data is received. Unrelated objects represent staff members whose access control is not directly available; If the state of both associable and unassociated objects remains unchanged after receiving control permissions, then the corresponding associable object will be marked as a data association matrix. If a non-associated object changes its state after receiving control permissions, the non-associated object is marked and output as a high-risk association.

3. The enterprise data information collection permission management method according to claim 1, characterized in that, Define the data entities under the current hierarchical dataset, determine the data type based on the data entities, query the data ownership based on the data type of each data entity, and obtain the data ownership corresponding to each data entity. Based on the obtained data ownership, it is determined whether the current data entity has a superior data ownership. If a superior data ownership exists, the lower-level permissions are inherited by default. The permissions of the superior data ownership are restricted by the permission verification method and constraints of the superior data ownership to obtain the scope of authentication business. If there is no parent data owner, the current data entity is authenticated. The business scenario, permission verification method and constraints of the data entity are viewed. Based on the business scenario, permission verification method and constraints of the data entity, the authentication business scope of the data entity is set.

4. The enterprise data information collection permission management method according to claim 1, characterized in that, The implementation of step S4 also includes: Examine the permission locations under the target mapping channel, perform differential analysis on each control permission based on the lifecycle corresponding to the permission location, and extract the differential units corresponding to the target mapping channel; Based on the updated state of the differentiated units, perform region mapping on the target mapping channel; Extract the update time interval corresponding to the target mapping channel, and obtain the user permission mapping policy based on the update time interval; The implementation method of regional mapping of target mapping channels also includes: based on different target mapping channels, dividing them into equally spaced parts using the data association matrix corresponding to the target mapping channels, using the division results to view the control permissions of the target mapping channels, and using the user profile corresponding to the target mapping channels to determine whether each division result is in an updatable state when the target mapping channels are updated. If it is in an updatable state, then based on the mapping relationship under the target mapping channels, comparing the historical control permissions with the current control permissions, and extracting the updated target mapping channels as the output data.

5. The enterprise data information collection permission management method according to claim 4, characterized in that, Other ways to implement user permission mapping strategies include: By using the target mapping channel corresponding to the detected control permissions, the control permission set of the staff is obtained. The control permission set is based on the principle of minimizing permissions for each user profile, and the update time interval is identified under the business scope and employee type represented by different user profiles. If the target mapping channel update interval is less than the preset threshold, it indicates that there is an anomaly in the current received data processing for the target mapping channel. In this case, the user permission mapping strategy is obtained based on the maximum update interval of the nearest frequency of the target mapping channel in the historical data. If the update interval is greater than the preset threshold, it means that the user data processed in the target mapping channel is normal and no permission mapping policy needs to be set.

6. The enterprise data information collection permission management method according to claim 1, characterized in that, Step S5 can be implemented in the following ways: Based on the number of permissions allocated after permission mapping, a growth rate range is set, and the current number of permissions allocated is checked by the abnormal patterns of the growth rate range under each range value. Determine whether the current growth rate is greater than the predicted growth rate. If it is greater than the predicted growth rate, the user permission mapping strategy currently marked is considered to be the target strategy; otherwise, it is considered to be a non-target strategy. After statistical mapping, the target and non-target policies of the user permission mapping strategy are determined, and permission allocation warning signals are output based on the target and non-target policies.

7. The enterprise data information collection permission management method according to claim 6, characterized in that, The handling methods for output permission allocation warning signals also include: Examine the detection duration corresponding to the growth rate under the permission allocation quantity, and retrieve the adjustment method of the target strategy based on the occurrence position of the target strategy on the timeline where the detection duration is located.

Citation Information

Patent Citations

  • Insurance data management method and device, electronic equipment and medium

    CN117591570A

  • Insurance information data protection method and system based on artificial intelligence

    CN118332055A

  • Enterprise authority management method, system and equipment based on machine learning and medium

    CN119397503A

  • Method and system based on multi-cluster user authority management

    CN120046138A