A dynamic management system of authority based on integrated system

By generating dynamic permission profiles through data fusion and risk assessment, and combining event synchronization and policy optimization, the static and isolated problems of existing permission management solutions are solved, enabling real-time risk assessment and cross-system permission synchronization, thereby improving security and management efficiency.

CN120822234BActive Publication Date: 2026-04-28国投人力资源服务有限公司
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
国投人力资源服务有限公司
Filing Date
2025-09-17
Publication Date
2026-04-28

AI Technical Summary

Technical Problem

Existing access control solutions suffer from problems such as rigid static role assignment, delayed access control adjustments, isolated management of multiple systems, and lack of real-time context awareness, resulting in low security and management efficiency.

Method used

The system employs a data fusion module to aggregate data from multiple sources to generate dynamic permission profiles, combines a risk assessment module to conduct real-time risk assessments, generates permission adjustment instructions through a risk handling module, achieves cross-system permission synchronization through an event synchronization module, and utilizes a strategy optimization module for self-optimizing permission management.

Benefits of technology

It enables dynamic risk quantification of real-time user actions and business contexts, improving the agility and foresight of access control, eliminating security vulnerabilities, and enhancing management efficiency and user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120822234B_ABST
    Figure CN120822234B_ABST
Patent Text Reader

Abstract

The application belongs to the technical field of authority management, and specifically relates to a dynamic authority management system based on an integrated system, which, on one hand, periodically depicts a dynamic authority portrait of employees by integrating data of multiple systems, analyzes a dynamic risk value of real-time operation behaviors of employees based on the latest dynamic authority portrait, and performs an authority change operation in at least one target system associated with a risk operation, and on the other hand, analyzes metadata of event messages to identify an organization event type by monitoring an organization event queue in real time, matches a change rule corresponding to the organization event type, generates an authority synchronization instruction and starts a transactional operation, adopts a behavior risk real-time evaluation and an event-driven cross-system collaborative mechanism, realizes automatic and accurate dynamic adjustment of authority, and improves access control security and management efficiency in an integrated network environment, and in addition, introduces a self-optimization capability based on machine learning, so that the authority management has the characteristics of continuous learning and evolution.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of permission management technology, specifically a dynamic permission management system based on an integrated system. Background Technology

[0002] In the human resource management and service environment of modern enterprises, various information systems, such as human resource management systems, customer relationship management systems, and enterprise resource planning systems, have become core infrastructures supporting daily human resource operations and services. These systems rely on computer networks for large-scale, high-frequency data exchange and transmission. While improving the efficiency of human resource management, this also brings serious challenges to data security and privacy protection. To ensure the confidentiality, integrity, and availability of employee data and sensitive corporate information during transmission and use, dynamic access control is a key component of a network security system.

[0003] Currently, widely implemented access control solutions are primarily based on role-based access control. Human resources departments and system administrators collaborate to pre-define roles according to the organizational structure and job descriptions, and then configure a fixed set of permissions for each role. When a new employee joins the company, they are assigned one or more roles based on their department and job responsibilities, thereby gaining corresponding permissions. For temporary or project-based access needs, administrators typically adjust permissions manually through a manual approval process.

[0004] However, existing role-based access control mechanisms have several obvious limitations, mainly in the following aspects:

[0005] Existing technologies based on static roles for permission allocation are too rigid and cannot adapt to the frequent organizational restructuring, personnel turnover, and dynamic task allocation in modern enterprises, resulting in a significant lag in permission adjustments.

[0006] Enterprises typically have multiple independent information systems. However, current technology often isolates the access control between these systems, lacking a unified linkage mechanism. When an employee's position changes, the administrator needs to manually change permissions in multiple systems, which is cumbersome and prone to leaving residual permissions due to negligence, creating security risks.

[0007] In existing technologies, user access control decisions are based on a single basis and lack the ability to perceive and respond to real-time context. They rely solely on the user's static identity and cannot perceive the real-time risks of user operations. They also lack effective and timely dynamic response measures for potential unauthorized access or internal threats. Summary of the Invention

[0008] To overcome the shortcomings in the background art, embodiments of the present invention provide a dynamic permission management system based on an integrated system, which can effectively solve the problems involved in the background art.

[0009] The objective of this invention can be achieved through the following technical solution: a dynamic permission management system based on an integrated system, comprising: a data fusion module, a risk assessment module, a risk handling module, an event synchronization module, and a strategy optimization module.

[0010] The data fusion module is connected to the risk assessment module, the risk assessment module is connected to the risk management module, and both the risk management module and the event synchronization module are connected to the strategy optimization module.

[0011] The data fusion module aggregates multi-source data from the human resources system, business system, and security logs, performs standardization and semantic normalization on the multi-source data, and periodically generates dynamic permission profiles for employees.

[0012] The risk assessment module analyzes the dynamic risk value of employees' real-time operational behavior based on the behavioral risk parameters contained in the employee's latest dynamic permission profile and the real-time business context parameters obtained from the business system.

[0013] The risk management module generates a permission adjustment instruction based on the dynamic risk value, performs a permission change operation in at least one target system associated with the risk operation based on the permission adjustment instruction, and generates a permission adjustment record.

[0014] The event synchronization module monitors the organization's event queue in real time, parses the metadata of event messages to identify the organization's event type, matches the change rules corresponding to the event type, generates permission synchronization instructions and initiates transactional operations to synchronize permission status across multiple target systems and generate permission adjustment records.

[0015] The strategy optimization module collects employee permission adjustment records and operation behavior data within historical time windows, updates employee predicted permission needs, and automatically assigns temporary permissions with task cycle validity periods.

[0016] Compared with the prior art, the embodiments of the present invention have at least the following advantages or beneficial effects:

[0017] This invention achieves a shift from passive defense to proactive prediction by linking multi-source data fusion with dynamic risk assessment. It can not only quantify risks based on users' static role attributes, but also combine their real-time operational behaviors and business contexts. This allows for the immediate generation and execution of precise permission adjustment instructions when potential unauthorized access operations occur, greatly improving the agility and foresight in responding to dynamic threats.

[0018] This invention solves the problem of independent permission management in various application systems through an event-driven cross-system collaboration mechanism. When critical business events such as organizational structure or project status occur, it can automatically trigger a global and consistent permission synchronization operation, ensuring that the permission status of employees in the entire integrated environment is always consistent with their real business identity, fundamentally eliminating security vulnerabilities and management blind spots caused by asynchronous permissions.

[0019] This invention introduces a machine learning-based self-optimization capability, enabling access control to continuously learn and evolve. Through deep learning of historical operation behaviors and access control adjustment records, it intelligently predicts users' access control needs and proactively grants temporary access control with task cycles, significantly improving users' work efficiency and experience, and achieving a synergistic improvement in access control security and management efficiency. Attached Figure Description

[0020] The present invention will be further described with reference to the accompanying drawings, but the embodiments in the drawings do not constitute any limitation on the present invention. For those skilled in the art, other drawings can be obtained based on the following drawings without creative effort.

[0021] Figure 1 This is a schematic diagram of the module connection of the present invention.

[0022] Figure 2 This is a flowchart illustrating the permission change operation in the risk management module of this invention.

[0023] Figure 3 This is a flowchart illustrating the transactional operations in the event synchronization module of this invention. Detailed Implementation

[0024] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0025] Reference Figure 1 As shown, the present invention provides a dynamic permission management system based on an integrated system, including: a data fusion module, a risk assessment module, a risk handling module, an event synchronization module, and a strategy optimization module.

[0026] The data fusion module is connected to the risk assessment module, the risk assessment module is connected to the risk management module, and both the risk management module and the event synchronization module are connected to the strategy optimization module.

[0027] The data fusion module gathers multi-source data from the human resources system, business system, and security logs, performs standardization and semantic normalization on the multi-source data, and periodically generates dynamic permission profiles for employees.

[0028] In a preferred embodiment of the present invention, the multi-source data is subjected to standardization and semantic normalization processing, including: parsing the multi-source data, extracting organizational structure information, project task allocation information and historical access information, and performing aggregation operations on the extracted information through a preset data interface.

[0029] It should be noted that the above organizational structure information comes from the human resources system and includes at least fields such as employee ID, department, position, and reporting relationship. The project task allocation information comes from the business system and includes at least project ID, task responsible person, project role, and data access permissions. The historical access information comes from the security log and includes at least employee identification, access time, source IP address, operation object, and operation type.

[0030] Perform format conversion on the aggregated information according to a predefined standard data structure.

[0031] Establish a mapping relationship between heterogeneous terms describing the same entity in data from different sources and a unified global identifier, so that the same entity in each data source can obtain a unique associated identifier and achieve semantic normalization processing.

[0032] It should be noted that the semantic normalization mentioned above is used to solve the problem of inconsistent terminology between different systems. For example, it maps employee numbers in the human resources system and user accounts in the business system to a unified unique user identifier, ensuring that the same entity in different data sources can be correctly associated. The mapping relationship between heterogeneous terms describing the same entity in different source data and the unified global identifier can be established before system development through the following steps:

[0033] A1. Extract key field names and their example values ​​for identifying core entities from the metadata or data dictionary of each data source system. Manually define the same global identifier for entities with the same attributes. Construct a mapping rule table to standardize the association between specific fields from different systems and the unified global identifier.

[0034] A2. Perform data aggregation test. Use the mapping rule table constructed above to perform real-time transformation on heterogeneous data samples. By comparing the global identifiers mapped to the same entity in different systems, verify whether the unique entity can be correctly associated. If an entity in a certain system is mapped to multiple different global identifiers or the association fails, trigger an exception and notify the administrator for manual review and rule optimization.

[0035] A3. Persistently store the successfully verified mapping rule table in the system cloud database and call it directly during system execution.

[0036] In a preferred embodiment of the present invention, the periodic generation of dynamic permission profiles of employees includes: mapping employees’ positions and reporting relationships based on organizational structure information within a preset period, and generating employee role attributes that include permission levels and department information.

[0037] It should be noted that the above-mentioned permission levels are core indicators used to quantify an employee's relative position level within the organization. Their values ​​directly anchor the employee's specific position in the reporting tree structure of their department. The reporting tree structure is based on the highest-ranking person in the department as the root node, and its permission level is uniformly defined as the first level.

[0038] As you move down the reporting line, each employee's permission level increases with their distance from the root node. That is, the root node's direct subordinates are at the second level, the direct subordinates' sub-subordinates are at the third level, and so on.

[0039] The higher the level number, the lower the employee's position level within the department, and the narrower the scope of operational authority granted.

[0040] Based on the project task allocation information within a preset period, inactive projects are filtered according to the project archive status, and employee IDs are used as keys to aggregate their roles and data access permissions in different active projects to generate employee project participation attributes.

[0041] By analyzing behavioral factors related to resource sensitivity, operation time, and access location in historical access information within a preset period, employee behavioral risk parameters are generated.

[0042] It should be noted that the specific analysis process for the above-mentioned behavioral factors related to resource sensitivity, operation time, and access location is as follows:

[0043] Extract business resource data from employees' historical access information within a preset period. Based on the sensitivity level of the business resource data bound to the business system, determine the number of times employees access different business sensitivity levels within the preset period. Assign weights to each sensitivity level. Calculate the behavioral factors related to resource sensitivity by weighted average of the number of times different business sensitivity levels are used. The weight assignment for each sensitivity level follows the principle that the higher the sensitivity level, the greater the weight assignment, and the sum of the weight assignments for each sensitivity level is 1.

[0044] The distribution of employees' historical login times and login IP addresses within a preset period is obtained. The frequency of their operations during non-working hours and the frequency of their access to uncommon locations are statistically analyzed and normalized to obtain behavioral factors related to operation time and access location. Uncommon locations are limited to login IP addresses whose time interval since the last occurrence exceeds a preset threshold of abnormal standard days.

[0045] The behavioral factors related to resource sensitivity, operation time, and access location are aggregated to quantify employee behavioral risk parameters.

[0046] By integrating the employee role attributes, project participation attributes, and behavioral risk parameters, a dynamic permission profile of the employee is generated.

[0047] The risk assessment module analyzes the dynamic risk value of an employee's real-time operational behavior based on the behavioral risk parameters contained in the employee's latest dynamic permission profile and the real-time business context parameters obtained from the business system.

[0048] In a preferred embodiment of the present invention, the step of parsing the dynamic risk value of the employee's real-time operation behavior includes: obtaining the access frequency, download volume and current project stage information of the operated data from the business system for the real-time collected operation behavior data, as the business context of the employee's operation.

[0049] By comparing the employee's role attributes and project participation attributes in the latest dynamic permission profile, the deviation risk score of the employee's current operation behavior from its own permission profile baseline pattern is quantified and recorded as the current behavior risk parameter.

[0050] It should be noted that the specific quantification process for the above deviation risk score is as follows:

[0051] The permission levels and department information contained in the employee role attributes, as well as the roles and data access permissions of different active projects aggregated in the employee project participation attributes, are integrated into a vector form and denoted as the baseline pattern vector. The permission levels, department, project in which the operation is performed, operation role, and access permissions touched by the operation in the employee's current operation behavior data are integrated into a vector form and denoted as the current behavior vector. The cosine similarity between the baseline pattern vector and the current behavior vector is calculated, and the reciprocal of the similarity is used as the deviation risk score.

[0052] The employee's operational business context is used as an adjustment coefficient for the current behavioral risk parameter, which is then mapped to the linear weighted fusion calculation of the current behavioral risk parameter and the behavioral risk parameter in the employee's latest dynamic permission profile, outputting the dynamic risk value of the employee's real-time operational behavior.

[0053] It should be noted that the specific process for obtaining the above adjustment coefficient is as follows: An excess risk coefficient is assigned to different lifecycle stages of the project, where the different lifecycle stages refer to the development phase, testing phase, operation phase, and closure phase. The excess risk coefficient refers to the corresponding permitted data access frequency range and download volume range for each lifecycle stage. If the current employee's access frequency or download volume of the manipulated data exceeds the permitted range for their respective project stage, it is considered an excess risk phenomenon. The product of the excess risk coefficient and the employee's current behavioral risk score is used as the adjusted current behavioral risk parameter. This limits the excess risk coefficient to the adjustment coefficient, and its value range is... .

[0054] Reference Figure 2 As shown, the risk handling module generates a permission adjustment instruction based on the dynamic risk value, performs a permission change operation in at least one target system associated with the risk operation based on the permission adjustment instruction, and generates a permission adjustment record.

[0055] In a preferred embodiment of the present invention, generating a permission adjustment instruction based on the dynamic risk value includes: extracting the risk threshold defined by the security policy stored in the cloud database.

[0056] The dynamic risk value of employees' real-time operational behavior is compared with the risk threshold. When the dynamic risk value exceeds the risk threshold, the risk event type is identified based on the operation type, operation object and operation context in the current operation behavior data.

[0057] It should be noted that the above risk event type identification logic is based on Table 1 below.

[0058] Table 1. Classification of Risk Event Types and Detailed Explanation of Identification Logic

[0059] Risk event types describe Recognition logic (based on operation type, object, and context) Suspicious data snooping Employees accessing sensitive data unrelated to their current work tasks Operation type: Read, Query Data breach or theft Employees attempted to massively transfer corporate data to external or unauthorized locations. Operation type: Download, copy, export, send email, upload to external website. Key identification criteria: The proportion of downloaded data for a single operation object relative to its total quantity reaches a preset batch exceeding standard, and the data download destination is a personal cloud storage or unauthorized external email address. Data corruption Employees maliciously or accidentally deleted or tampered with critical business data Operation types: delete, modify, format Abuse of privilege escalation Employees exploit or attempt to exploit existing permissions to obtain higher-level, unauthorized permissions. Operation type: Permission change, create new account, vulnerability exploitation Intrusion or brute-force cracking The account was misused, and unauthorized access was attempted. Operation type: Login, authentication. Key identification point: Failed login attempts exceed the threshold and... illegal operation Violation of company safety regulations Operation type: Installing unauthorized software, accessing illegal websites, sharing in violation of regulations

[0060] Based on the type of risk event and the source system of the data being manipulated, determine one or more target systems involved in the permission change operation.

[0061] It should be added that the process of determining the target system specifically refers to the risk association system library stored in the cloud database, which is jointly maintained by the security team, the operations team, and the business team. The risk association system library records all systems and their business attributes and relationships. When a certain type of risk event occurs on a source system, other systems associated with that source system are retrieved as the target system.

[0062] Based on the threshold amplitude decision, a permission downgrade sub-instruction or a temporary lock sub-instruction for the employee target system is generated as a permission adjustment instruction. The permission downgrade sub-instruction includes the permission item to be downgraded and its downgrade magnitude, and the temporary lock sub-instruction includes the lock duration.

[0063] It should be noted that the above-mentioned threshold amplitude decision includes: performing a ratio calculation between the dynamic risk value exceeding the risk threshold and the risk threshold to obtain the threshold amplitude; if the threshold amplitude is less than or equal to the first preset amplitude, the permission adjustment instruction is determined to be a permission downgrade sub-instruction, otherwise it is determined to be a temporary lock sub-instruction.

[0064] The permission items to be downgraded in the permission downgrade sub-instruction are determined by the type of risk event. For example, in the case of a data snooping event, the permission items to be downgraded are limited to data access permissions. In the case of a permission escalation abuse event, the permission items to be downgraded should include the permission items that the user attempted to acquire as well as the permission itself for performing permission change operations. The downgrade magnitude is positively correlated with the threshold amplitude. The threshold amplitude can be compared with the preset unit step standard amplitude, and the result can be rounded to match the downgrade step number to map the downgrade magnitude.

[0065] The temporary lock sub-instruction is limited to all employee permissions. The lock duration is also positively correlated with the threshold amplitude. When the threshold amplitude is within the first or second preset amplitude range, the lock duration is set to the basic lock standard, such as 30 minutes. When the threshold amplitude is within the second or third preset amplitude range, the lock duration is set to the intermediate lock standard, such as 2 hours. When the threshold amplitude is greater than the third preset amplitude, the lock duration is set to the advanced lock standard, such as 4 hours.

[0066] This invention, through the fusion of multi-source data and the linkage of dynamic risk assessment, achieves a shift from passive defense to proactive prediction. It can not only quantify risks based on users' static role attributes, but also combine their real-time operational behaviors and business contexts. This allows for the immediate generation and execution of precise permission adjustment instructions when potential unauthorized access operations occur, greatly improving the agility and foresight in responding to dynamic threats.

[0067] The event synchronization module monitors the organization's event queue in real time, parses the metadata of event messages to identify the organization's event type, matches the change rules corresponding to the organization's event type, generates permission synchronization instructions and initiates transactional operations to synchronize permission status across multiple target systems and generate permission adjustment records.

[0068] In a preferred embodiment of the present invention, parsing the metadata of the event message to identify the organizational event type includes: extracting metadata fields from the event messages in the organizational event queue, wherein the metadata fields include at least an event type identifier, an event source system identifier, and an event timestamp.

[0069] The event type identifier is matched with a predefined event type mapping table stored in the cloud database. The predefined event type mapping table defines the mapping relationship between event type identifiers from different source systems and internal standard event types.

[0070] When a match is successful, the matched internal standard event type will be output as the event type for identifying the organization. The internal standard event types include job change events, resignation events, and project completion events.

[0071] When a match fails, the event message is discarded and a retention log containing the original content of the event message and the reason for the match failure is created.

[0072] In a preferred embodiment of the present invention, the change rules corresponding to the organizational event type include the following:

[0073] Change rules for job change events: The system permissions of the original and new job roles are retained, the system permissions unique to the original job are removed, and the system permissions unique to the new job are granted according to the new job template.

[0074] Change rules for departure events: Disable the employee's access permissions in all business systems integrated with the HR system and terminate all of their active sessions.

[0075] Project closure event change rules: Based on the employee's role level in the closed project, the employee is divided into a role with retained traceability permissions or a role with revoked full permissions. If the employee is in the role with retained traceability permissions, then the employee retains read-only access to the data associated with the project ID, and all associated system operation permissions are simultaneously revoked. If the employee is in the role with revoked full permissions, then all data access permissions and system operation permissions associated with the project ID are revoked.

[0076] It should be added that the classification of the above employees into roles with retained traceability permissions or roles with revoked full permissions is directly related to the responsibilities of the role and the required level of trust. Usually, employees whose role level reaches the level of direct project responsibility or operation and maintenance are classified as having retained traceability permissions, while other project personnel are classified as having revoked full permissions.

[0077] Reference Figure 3 As shown, in a preferred embodiment of the present invention, the transactional operation includes the following: validating the permission synchronization instruction, confirming the existence of the user account status and permission role in the instruction, and generating a verified permission synchronization instruction.

[0078] It should be noted that the above validity verification includes multiple levels:

[0079] Verify that the instruction format conforms to the preset communication protocol and data structure specifications, and ensure that it fully contains the core fields necessary to perform the operation, including but not limited to the user's unique identifier, the content of the permission change operation, the target system resource identifier, and the operation timestamp.

[0080] By connecting to the metadata database of the human resources system, the system verifies that the user account specified in the instruction is in a normal active state, and that the permission roles, policies or access permissions that the instruction requires to be assigned or revoked actually exist and have been registered in the system permission configuration library, thus ensuring the logical feasibility of the operation.

[0081] Verify the credibility of the source and integrity of the instruction by checking whether it carries a valid digital signature or security token issued by an authorized certification authority, in order to identify the legitimacy of the instruction initiator and confirm that the instruction has not been tampered with during transmission.

[0082] Only when the permission synchronization command passes through all the above verification levels in sequence will it be deemed a valid command and allowed to execute subsequent synchronization operations.

[0083] A distributed transaction is initiated for the verified permission synchronization command. By calling the atomic operation interfaces provided by each target system, the permission status synchronization operation is coordinated to be performed among multiple target systems, and the atomicity of the operation of all systems is ensured.

[0084] Once the transaction is completed, a transactional permission synchronization record containing the operation results of each target system is generated, and the processing status of the corresponding event in the organization's event queue is updated.

[0085] This invention addresses the challenge of independent permission management across application systems through an event-driven cross-system collaboration mechanism. When critical business events such as organizational structure or project status occur, it can automatically trigger a global and consistent permission synchronization operation, ensuring that the permission status of employees in the entire integrated environment is always consistent with their actual business identity, fundamentally eliminating security vulnerabilities and management blind spots caused by asynchronous permissions.

[0086] The strategy optimization module collects employee permission adjustment records and operation behavior data within a historical time window, updates employee predicted permission needs, and automatically assigns temporary permissions with task cycle validity periods.

[0087] In a preferred embodiment of the present invention, the process of obtaining employee predicted permission requirements includes:

[0088] Based on the permission adjustment records and operation behavior data within the historical time window, a time series of employee behavior events is constructed.

[0089] Sequence pattern mining is performed on the time series of the behavioral events to identify permission usage patterns with periodicity or event-triggered characteristics.

[0090] It should be noted that the above-mentioned prefix tree algorithm can be used to identify permission usage patterns with periodic or event-triggered characteristics. The process is as follows:

[0091] B1. Clean and standardize the employee's permission adjustment records and operation behavior data within the historical time window, map the original operations to permission events, sort them by timestamp, and generate a time series of employee behavior events.

[0092] B2. Frequent patterns in the sequence are efficiently organized using a prefix tree structure. By recursively constructing a projection database for each frequent prefix, longer frequent subsequences are mined only in this projection database, avoiding the generation of all candidate sequences, thereby improving mining efficiency.

[0093] B3. Scan the prefix tree and each projection database to extract all frequent sequence patterns that meet the minimum support threshold. Each pattern represents a recurring sequence of permission operations.

[0094] B4. Analyze the historical occurrence time points of frequent sequence patterns. If the trend variance of the time interval reaches the preset stability threshold standard, the pattern is determined to be periodic, and its periodic parameters are recorded.

[0095] B5. Correlate frequent sequence patterns with external event logs. If a specific system or business event consistently occurs before a certain pattern occurs, then the pattern is determined to be event-triggered, and its triggering event type is recorded.

[0096] B6. Store the identified patterns and their metadata into the permission usage pattern library. The output includes associated users, permission operation sequences, target resources, periodic parameters, or triggering event conditions.

[0097] The permission usage pattern is input into a preset time series analysis model to predict the probability of occurrence, effective time, and expiration time of the pattern in the future, and to generate permission requirement prediction results.

[0098] It should be noted that the above-mentioned pre-set time series analysis model can be constructed based on a long short-term memory network, and its pre-training process includes the following steps in sequence:

[0099] C1. Based on the identified permission usage patterns and their historical occurrence times, construct a supervised learning training set. Use a subsequence of historical behavioral events as the model input, and use whether a specific pattern occurs after the sequence, the time of occurrence, and the duration as the label.

[0100] C2. Construct a multi-output LSTM neural network model. This network receives an event sequence vectorized by the embedding layer as input and has three independent output layers, which are used to regress the effective time offset and ineffective time offset of the pattern, respectively, and output the probability of the pattern occurring in the future time window through the Sigmoid activation function.

[0101] C3. The model training process aims to minimize the comprehensive loss function, which consists of three parts: the binary cross-entropy loss function is used to optimize the accuracy of the probability prediction, and the mean squared error loss function is used to optimize the prediction accuracy of the two regression tasks of effective time and failure time.

[0102] C4. Use time series cross-validation to divide the training set and validation set. Iteratively adjust the weight parameters in the LSTM network through backpropagation algorithm and Adam optimizer until the prediction error of the model on the validation set converges to within the preset allowable threshold.

[0103] C5. Use the reserved test set to evaluate the performance of the trained model, ensuring that its prediction accuracy for the probability of pattern occurrence, effective time and failure time meets the application requirements. After verification, solidify the model parameters into the preset time series analysis model.

[0104] In a preferred embodiment of the present invention, the execution process of automatically allocating temporary permissions with a task period validity period includes: if the probability of occurrence of the permission usage pattern in the permission demand prediction result is greater than the preset trigger probability, then based on the effective and expiration times predicted by the permission usage pattern, the task period validity period of the temporary permission is set, the permission granting process is automatically triggered at the effective time to configure the relevant system temporary permissions, and the permission revokement process is automatically triggered at the expiration time to remove the temporary permissions.

[0105] This invention introduces a machine learning-based self-optimization capability, enabling permission management to continuously learn and evolve. Through deep learning of historical operation behaviors and permission adjustment records, it intelligently predicts users' permission needs and proactively grants temporary permissions with task cycles, significantly improving users' work efficiency and experience, and achieving a synergistic improvement in access control security and management efficiency.

[0106] The above description is merely an example and illustration of the structure of the present invention. Those skilled in the art can make various modifications or additions to the specific embodiments described, or use similar methods to replace them, as long as they do not deviate from the structure of the invention or exceed the scope defined by the present invention, and all such modifications and additions should fall within the protection scope of the present invention.

Claims

1. A dynamic permission management system based on an integrated system, characterized in that, include: The data fusion module gathers multi-source data from the human resources system, business system, and security logs, performs standardized processing and semantic normalization of the multi-source data, and periodically generates dynamic permission profiles for employees. The risk assessment module analyzes the dynamic risk value of employees' real-time operational behavior based on the behavioral risk parameters contained in the employee's latest dynamic permission profile and the real-time business context parameters obtained from the business system. The risk management module generates permission adjustment instructions based on dynamic risk values, performs permission change operations in at least one target system associated with the risk operation based on the permission adjustment instructions, and generates permission adjustment records. The event synchronization module monitors the organization's event queue, parses the metadata of event messages to identify the organization's event type, matches the change rules corresponding to the organization's event type, generates permission synchronization instructions and initiates transactional operations to synchronize permission status across multiple target systems and generate permission adjustment records. The strategy optimization module collects employee permission adjustment records and operation behavior data within historical time windows, updates employee predicted permission needs, and automatically assigns temporary permissions with task cycle validity periods. The process for obtaining employee prediction permission requirements includes: Based on historical time window records of permission adjustments and operational behavior data, a time series of employee behavior events is constructed. Sequence pattern mining is performed on the time series of the behavioral events to identify permission usage patterns with periodicity or event-triggered characteristics. The permission usage pattern is input into a preset time series analysis model to predict the probability of occurrence, effective time and expiration time of the pattern in the future, and generate permission requirement prediction results. The process of automatically assigning temporary permissions with a task period validity period includes: If the probability of occurrence of the permission usage pattern in the permission requirement prediction result is greater than the preset trigger probability, then based on the effective and expiration time of the predicted permission usage pattern, the task cycle validity period of the temporary permission is set, and the permission granting process is automatically triggered at the effective time to configure the relevant system temporary permissions, and the permission revokement process is automatically triggered at the expiration time to remove the temporary permissions.

2. The permission dynamic management system based on an integrated system according to claim 1, characterized in that, The multi-source data undergoes standardization and semantic normalization processing, including: The multi-source data is parsed to extract organizational structure information, project task allocation information, and historical access information. The extracted information is then aggregated through a pre-defined data interface. Perform format conversion on the aggregated information according to a predefined standard data structure; Establish a mapping relationship between heterogeneous terms describing the same entity in data from different sources and a unified global identifier, so that the same entity in each data source can obtain a unique associated identifier and achieve semantic normalization processing.

3. The permission dynamic management system based on an integrated system according to claim 2, characterized in that, The periodic generation of dynamic permission profiles for employees includes: Based on the organizational structure information within a preset period, the system maps employee positions and reporting relationships, generating employee role attributes that include permission levels and department information. Based on the project task allocation information within a preset period, inactive projects are filtered according to the project archive status, and employee ID is used as the key to aggregate their roles and data access permissions in different active projects to generate employee project participation attributes. By analyzing the behavioral factors related to resource sensitivity, operation time and access location in historical access information within a preset period, employee behavior risk parameters are generated. By integrating the employee role attributes, project participation attributes, and behavioral risk parameters, a dynamic permission profile of the employee is generated.

4. The permission dynamic management system based on an integrated system according to claim 3, characterized in that, The dynamic risk value of analyzing employees' real-time operational behavior includes: For real-time collected operational behavior data, the access frequency, download volume and current project stage information of the data being operated on are obtained from the business system, which serves as the business context for employee operations. By comparing the employee's role attributes and project participation attributes in the latest dynamic permission profile, the deviation risk score of the employee's current operation behavior from its own permission profile baseline pattern is quantified and recorded as the current behavior risk parameter. The employee's operational business context is used as the contribution weight adjustment coefficient of the current behavioral risk parameter, which is mapped to the linear weighted fusion calculation of the current behavioral risk parameter and the behavioral risk parameter in the employee's latest dynamic permission profile, and outputs the dynamic risk value of the employee's real-time operational behavior.

5. The permission dynamic management system based on an integrated system according to claim 1, characterized in that, Based on the dynamic risk value, a permission adjustment instruction is generated, including: Extract the risk thresholds defined by the security policies stored in the cloud database; The dynamic risk value of employees' real-time operational behavior is compared with the risk threshold. When the dynamic risk value exceeds the risk threshold, the risk event type is identified based on the operation type, operation object and operation context in the current operation behavior data. Based on the type of risk event and the source system of the data being manipulated, determine one or more target systems involved in the permission change operation; Based on the threshold amplitude decision, a permission downgrade sub-instruction or a temporary lock sub-instruction for the employee target system is generated as a permission adjustment instruction. The permission downgrade sub-instruction includes the permission item to be downgraded and its downgrade magnitude, and the temporary lock sub-instruction includes the lock duration.

6. The permission dynamic management system based on an integrated system according to claim 1, characterized in that, The parsing of event message metadata to identify the organization's event type includes: Extract metadata fields from the event messages in the organization's event queue. The metadata fields include at least an event type identifier, an event source system identifier, and an event timestamp. Match event type identifiers with a predefined event type mapping table stored in the cloud database. The predefined event type mapping table defines the mapping relationship between event type identifiers from different source systems and internal standard event types. When a match is successful, the matched internal standard event type will be output as the event type that identifies the organization. The internal standard event types include job change events, resignation events, and project completion events. When a match fails, the event message is discarded and a retention log containing the original content of the event message and the reason for the match failure is created.

7. A dynamic permission management system based on an integrated system according to claim 6, characterized in that, The change rules corresponding to the organization event types include the following: (1) Rules for changing job positions: retain the intersection of system permissions of the original and new job roles, remove the unique system permissions of the original job, and grant the unique system permissions of the new job according to the template of the new job. (2) Rules for changing departure events: Set the employee's access permissions to invalid in all business systems integrated with the human resources system and terminate all of their active sessions; (3) Rules for changing project closure events: Based on the employee's role level in the project closure, the employee is divided into a role with retained traceability permissions or a role with full permissions revoked. If the employee is a role with retained traceability permissions, then the employee is granted read-only access to the data associated with the project ID, and all associated system operation permissions are simultaneously revoked. If the employee is a role with full permissions revoked, then all data access permissions and system operation permissions associated with the project ID are revoked.

8. The permission dynamic management system based on an integrated system according to claim 1, characterized in that, The transactional operations include the following: The validity of the permission synchronization instruction is verified to confirm the existence of the employee account status and permission role in the instruction, and a verified permission synchronization instruction is generated. A distributed transaction is initiated for the verified permission synchronization command. By calling the atomic operation interface provided by each target system, the permission state synchronization operation is coordinated to be performed among multiple target systems, and the atomicity of the operation of all systems is ensured. Once the transaction is completed, a transactional permission synchronization record containing the operation results of each target system is generated, and the processing status of the corresponding event in the organization's event queue is updated.

Citation Information

Patent Citations

  • Method for comprehensively displaying enterprise management information based on Web technology

    CN118917562A

  • Human resource authority management method and system

    CN119598443A