Detection report management method and system based on cloud platform

By acquiring and processing user identity, behavior, device, and environmental data, and dynamically assessing trust and configuring permissions, the problem of inaccurate permission configuration in the test report management system is solved, thereby achieving accuracy in test report access control and risk perception capabilities.

CN120915570APending Publication Date: 2025-11-07GUANGZHOU TESTING CENTRE OF CONSTRUCTION QUALITY AND SAFETY CO LTD +2
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511208566.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-27
Publication Date
2025-11-07

AI Technical Summary

Technical Problem

Existing test report management systems lack a dynamic trust assessment mechanism based on multi-dimensional data fusion, which makes it impossible to achieve real-time and accurate configuration of test report access permissions, resulting in inaccurate permission configuration and an inability to dynamically assess trust.

Method used

By acquiring user identity information, historical behavior records, device status data, and environmental perception data, heterogeneous data preprocessing is performed to extract behavioral regularity indicators. These indicators are then weighted and calculated in conjunction with user identity information to conduct risk assessment and environmental change assessment. Finally, permission levels and visible content ranges are configured based on trust scores.

Benefits of technology

It achieves accuracy and personalized matching capabilities for access control of test reports, strengthens risk perception and contextual relevance, dynamically adjusts permission levels and visible content, and adapts to differentiated access strategies in multi-user and multi-role environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120915570A_ABST
    Figure CN120915570A_ABST
Patent Text Reader

Abstract

The invention discloses a detection report management method and system based on a cloud platform, and the method comprises the steps: obtaining user identity information, historical behavior records, equipment state data and environment perception data, carrying out the heterogeneous data preprocessing, and obtaining an initial data set; according to the historical behavior record, extracting access frequency and behavior characteristics to obtain a behavior regularity index; according to the behavior regularity index and the user identity information, performing weighted calculation to obtain a preliminary trust score value; performing risk assessment according to the initial trust score value in combination with the equipment state data and the initial trust score value to obtain a comprehensive trust score; performing environment change evaluation according to the comprehensive trust score and the environment perception data to obtain a final trust score; and according to the final trust score, in combination with a preset rule base, extracting a report access limitation range and a risk level, and executing permission adjustment and range setting to obtain a final permission configuration scheme. According to the invention, real-time accurate configuration of the access permission of the detection report can be realized.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of cloud platform detection report management, and particularly relates to a detection report management method and system based on a cloud platform. BACKGROUND

[0002] At present, with the continuous improvement of the digital level in the industrial field, detection report management based on a cloud platform gradually becomes a core link in industrial data storage and big data management. Especially in the process of industrial production, equipment detection and quality control, the structured information carried by the detection report is huge, has the characteristics of strong sensitivity, frequent updating and various access roles, and therefore puts forward higher requirements on the security and dynamic response capability of the industrial cloud storage system. The traditional report management scheme cannot meet the needs of data permission fine-grained control and dynamic security management at the present stage.

[0003] In one prior art, the detection report management system usually relies on the static identity of the user to set the permission, ignores the dynamic evolution of the user access behavior, the change of the device use scene and the security correlation of the user historical interaction data. This kind of method often divides the permission based on fixed rules, lacks real-time evaluation of the user risk level and the access adjustment mechanism based on the trust degree, and therefore cannot make timely permission correction when multiple users are concurrent, cross-device access or abnormal behavior occurs. In addition, the current system rarely integrates big data storage analysis capability, cannot effectively integrate heterogeneous data such as user identity, behavior log, device state and the like, and is difficult to support trust score and adaptive access control.

[0004] The prior art lacks a dynamic trust evaluation mechanism based on multi-dimensional data fusion, and cannot realize real-time and accurate configuration of the detection report access permission. SUMMARY

[0005] The present application provides a detection report management method and system based on a cloud platform to solve the problem of inaccurate permission configuration and inability to dynamically evaluate trust in the prior art.

[0006] In a first aspect, to solve the above technical problems, the present application provides a detection report management method based on a cloud platform, comprising:

[0007] Obtaining user identity information, historical behavior records, device state data and environment perception data, and performing heterogeneous data preprocessing on the user identity information, the historical behavior records and the device state data to obtain a unified initial data set;

[0008] According to the historical behavior records in the initial data set, extracting user access frequency and behavior mode features to obtain a behavior regularity index;

[0009] According to the behavior regularity index, combined with the user identity information in the initial data set, weighted calculation is performed to obtain a preliminary trust score value;

[0010] According to the preliminary trust score value, combined with the device state data in the initial data set and the preliminary trust score value, risk assessment is performed to obtain a comprehensive trust score;

[0011] According to the comprehensive trust score, combined with the environment perception data, user environment change assessment is performed to obtain a final trust score;

[0012] According to the final trust score, combined with a preset rule base, a report access restriction range and a risk level are extracted, and permission level adjustment and visible content range setting are performed to obtain a final permission configuration scheme.

[0013] Preferably, according to the historical behavior records in the initial data set, user access frequency and behavior pattern features are extracted to obtain a behavior regularity index, including:

[0014] The historical behavior records in the initial data set are feature extracted to obtain user access frequency and initial behavior features;

[0015] Time series segmentation analysis is performed on the user access frequency and the initial behavior features to construct behavior distribution features in different time periods;

[0016] Based on the behavior distribution features, access duration and access peak interval of each time interval are analyzed to calculate a behavior concentration degree;

[0017] When the behavior concentration degree exceeds a preset behavior concentration degree threshold, it is determined that the corresponding time interval is a user active period;

[0018] For the access path preference and the behavior repetition frequency in the active period, cluster analysis is performed to identify behavior pattern features and habit tendency results of the user in a specific period;

[0019] Combined with the behavior pattern features and the habit tendency results, conditional matching analysis is performed to identify key behavior patterns to obtain a behavior regularity index for trust assessment.

[0020] Preferably, according to the behavior regularity index, combined with the user identity information in the initial data set, weighted calculation is performed to obtain a preliminary trust score value, including:

[0021] Time interval refinement analysis is performed on the behavior regularity index to construct behavior regularity feature values in different time periods;

[0022] The behavior regularity feature value is compared with user identity information in the initial data set, a behavior feature and role typical behavior interval matching analysis operation is performed, and role behavior data meeting role expectations is obtained;

[0023] According to the user identity information in the initial data set, a weighted calculation is performed in combination with the role behavior data, a matching degree of behavior feature and permission range is quantified, and a trust score basic value is obtained;

[0024] According to the trust score basic value, an interval determination operation is performed in combination with a preset trusted score interval, and a preliminary trust score value is obtained.

[0025] Preferably, according to the preliminary trust score value, risk assessment is performed in combination with device state data in the initial data set and the preliminary trust score value, and a comprehensive trust score is obtained, including:

[0026] According to the preliminary trust score value, risk factor identification and score adjustment operations are performed in combination with security parameters and network environment information in the device state data in the initial data set, and a comprehensive trust score is obtained;

[0027] The risk factor identification and score adjustment operation includes:

[0028] Based on the security parameters and a preset security threshold, a state comparison is performed to obtain device anomaly identification data;

[0029] Based on the network environment information, a risk level judgment is performed to obtain network risk identification data;

[0030] The device anomaly identification data and the network risk identification data are fused and processed, a preset trust score adjustment rule is combined to perform weighted correction on the preliminary trust score value, and score intermediate data is obtained;

[0031] According to the score intermediate data and a preset score mapping table, an interval matching operation is performed to obtain a comprehensive trust score.

[0032] Preferably, according to the comprehensive trust score, user environment change assessment is performed in combination with the environment perception data, and a final trust score is obtained, including:

[0033] According to the physical location information and the timestamp information in the environment perception data, geographic risk level identification is performed to obtain a location risk coefficient;

[0034] According to the access point information in the environment perception data, trusted network comparison is performed to obtain a network environment evaluation result;

[0035] According to the behavior data in the environment perception data and the historical behavior mode, behavior deviation analysis is performed to obtain behavior anomaly identification data;

[0036] According to the comprehensive trust score, the position risk coefficient, the network environment evaluation result, and the behavior anomaly identification data, dynamic score adjustment is performed to obtain a final trust score.

[0037] Preferably, according to the final trust score, a report access restriction range and a risk level are extracted in combination with a preset rule base, and permission level adjustment and visible content range setting are performed to obtain a final permission configuration scheme, including:

[0038] According to the final trust score, in combination with a permission mapping table in the preset rule base, access level identification is performed to obtain user permission level data;

[0039] According to the user permission level data, in combination with a report access classification rule in the preset rule base, report type screening is performed to obtain an accessible report type list;

[0040] According to the accessible report type list, in combination with a field permission control table in the preset rule base, field-level access permission matching is performed to obtain a field access permission mapping result;

[0041] According to the field access permission mapping result, report content reconstruction is performed to obtain personalized detection report content;

[0042] According to the final trust score, in combination with a permission level definition table in the preset rule base, permission level adjustment is performed to obtain a permission level configuration result;

[0043] According to the permission level configuration result and the personalized detection report content, permission configuration integration is performed to obtain a final permission configuration scheme.

[0044] Preferably, according to the permission level configuration result and the personalized detection report content, permission configuration integration is performed to obtain a final permission configuration scheme, including:

[0045] According to the permission level configuration result, in combination with the field access permission mapping result in the personalized detection report content, access control rule matching is performed to obtain field visibility configuration data;

[0046] According to the field visibility configuration data, in combination with the operation permission definition in the permission level configuration result, content presentation and operation boundary integration are performed to obtain a final permission configuration scheme.

[0047] In a second aspect, the present application provides a detection report management system based on a cloud platform, including:

[0048] The data acquisition module is configured to acquire user identity information, historical behavior records, device state data and environment perception data, and perform heterogeneous data preprocessing on the user identity information, the historical behavior records and the device state data to obtain a unified initial data set.

[0049] The behavior analysis module is configured to extract user access frequency and behavior pattern features from the historical behavior records in the initial data set to obtain a behavior regularity index.

[0050] The preliminary analysis module is configured to perform weighted calculation on the basis of the behavior regularity index and the user identity information in the initial data set to obtain a preliminary trust score value.

[0051] The comprehensive analysis module is configured to perform risk assessment on the basis of the preliminary trust score value, the device state data in the initial data set and the preliminary trust score value to obtain a comprehensive trust score.

[0052] The final analysis module is configured to perform user environment change assessment on the basis of the comprehensive trust score and the environment perception data to obtain a final trust score.

[0053] The scheme configuration module is configured to extract a report access restriction range and a risk level on the basis of the final trust score and a preset rule library, and perform permission level adjustment and visible content range setting to obtain a final permission configuration scheme.

[0054] In a third aspect, the present application further provides an electronic device, comprising a processor, a memory and a computer program stored in the memory and configured to be executed by the processor, wherein the processor executes the computer program to implement the cloud platform-based detection report management method according to any one of the above.

[0055] In a fourth aspect, the present application further provides a computer readable storage medium comprising a stored computer program, wherein the computer program controls a device where the computer readable storage medium is located to execute the cloud platform-based detection report management method according to any one of the above when the computer program is running.

[0056] Compared with the prior art, the present application has the following beneficial effects:

[0057] The present application discloses a cloud platform-based detection report management method to solve the problem of inaccurate permission configuration and inability to dynamically evaluate trust in the prior art.

[0058] (1) The accuracy and personalized matching ability of the detection report access control are improved. By introducing the joint analysis of user behavior frequency, behavior pattern and identity information, the system can identify the access rules and role characteristics of the user in the actual use process, thereby realizing the dynamic calculation of permissions based on behavior characteristics. Compared with the traditional static permission configuration method, this method can better reflect the user's real use behavior, making the permission configuration more in line with the user's actual needs, reducing the risks and inconveniences caused by excessive permission granting or restrictions.

[0059] (2) The risk perception ability and context relevance in the trust evaluation process are strengthened. This method not only considers user behavior, but also introduces device state data and environmental perception data as auxiliary judgment basis for risk assessment. Through comprehensive analysis of multi-dimensional data such as geographic location, network environment and behavior anomalies, the system can more effectively identify potential risk access scenarios and adjust the trust score accordingly, effectively avoiding unauthorized access or information leakage caused by device abnormalities or environmental changes.

[0060] (3) The dynamic linkage configuration of permission control results and actual visible content is realized. In the final configuration stage, the system jointly processes the permission level results and the detection report content, realizes field-level permission matching and content reconstruction, and makes the final presented detection report conform to the user permission range while retaining necessary business information. This linkage processing method improves the response flexibility of the system and the precision of content control, facilitating the implementation of differentiated report access strategies in a multi-user, multi-role environment. BRIEF DESCRIPTION OF DRAWINGS

[0061] Figure 1 is the flowchart of the detection report management method based on the cloud platform provided by the first embodiment of the present application;

[0062] Figure 2 is the structural diagram of the detection report management system based on the cloud platform provided by the second embodiment of the present application. DETAILED DESCRIPTION

[0063] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative labor fall within the scope of protection of the present application.

[0064] With reference to Figure 1 , the first embodiment of the present application provides a detection report management method based on a cloud platform, including the following steps:

[0065] S11, obtain user identity information, historical behavior records, device state data and environment perception data, and perform heterogeneous data preprocessing on the user identity information, the historical behavior records and the device state data to obtain a unified initial data set;

[0066] S12, extract user access frequency and behavior pattern features according to the historical behavior records in the initial data set to obtain a behavior regularity index;

[0067] S13, according to the behavior regularity index, combined with the user identity information in the initial data set, weighted calculation is performed to obtain a preliminary trust score value;

[0068] S14, according to the preliminary trust score value, combined with the device state data in the initial data set and the preliminary trust score value, risk assessment is performed to obtain a comprehensive trust score;

[0069] S15, according to the comprehensive trust score, combined with the environment perception data, user environment change assessment is performed to obtain a final trust score;

[0070] S16, according to the final trust score, combined with a preset rule base to extract a report access restriction range and a risk level, and execute permission level adjustment and visible content range setting to obtain a final permission configuration scheme.

[0071] In step S11, user identity information, historical behavior records, device state data and environment perception data need to be obtained, and the user identity information, the historical behavior records and the device state data are preprocessed to obtain a unified initial data set, including:

[0072] In one specific embodiment, the system first obtains user identity information through access to the identity authentication service of the unit, and the information content includes user unique identifier, organization to which the user belongs, duty level and role permission mark and other fields. These information is compared and verified with the registered user data archived in the database through calling the LDAP directory service interface, to ensure the identity legality and data consistency, and to provide a static identity basis for subsequent trust analysis.

[0073] At the same time, the system extracts the historical behavior records of the user in the last three months in the background log management module, and the data includes access time, access object (such as report number), access method (web / mobile terminal) and operation type (download, preview, forward, etc.). In order to ensure data integrity, the time stamps of the behavior records are all converted to UTC standard time, and are indexed and arranged according to user ID.

[0074] Device status data is obtained through the client security agent plug-in, and the collection items include terminal device type, operating system version, current IP address, device fingerprint summary (such as MAC address, CPU ID), and local security state (whether the antivirus software is turned on, firewall state, etc.). The data collection period is at login and before each request, and the data is transmitted back to the master service through TLS encryption to avoid information leakage.

[0075] Environment perception data is mainly derived from the location service and network environment information module. The geographic location information is obtained by calling the browser / device positioning API, with an accuracy control within 100 meters. Network access information includes access point SSID, network type (private network / public network), and signal strength level, which can be used to identify potential abnormal access environments.

[0076] In the preprocessing stage, to eliminate the structural differences of data from different sources, the system introduces a heterogeneous data standardization process. First, the user identity information, behavior logs, and device information are unified into structured JSON objects, and key-value alignment is performed according to the pre-set field rules. For data items with missing or inconsistent values, the system uses a historical mean-based interpolation and rule filling strategy to complete the filling and correction. For example, if the device information is missing for a certain behavior record, the system can automatically fill it based on the device types accessed by the user's neighbors. Finally, all data is aggregated into a unified initial data set, which serves as the basis for subsequent behavior feature extraction and trust score calculation.

[0077] The rule filling strategy is used to fill in missing or inconsistent data items in the data preprocessing stage. The system first fills in the missing data based on domain knowledge and business rules, such as inferring the missing device type from the user's historical behavior data or inferring the missing user data from the geographic location and time information. In addition, the system uses methods such as the K-Nearest Neighbors (KNN) algorithm to fill in missing values based on similar user records. For example, if a user's device information is missing, the system will fill it in based on the device information of similar users. For some missing fields, the system can also use statistical inference methods, such as calculating the mean or mode of the field to fill in the data. Behavior patterns and time information are also used as the basis for filling in missing data. Through analysis of the user's historical behavior, the system can reasonably fill in missing data items. Through these strategies, the system can ensure the consistency and completeness of the data, providing a high-quality initial data set for subsequent behavior feature extraction and trust score calculation.

[0078] In step S12, the user access frequency and behavior pattern features need to be extracted from the historical behavior records in the initial data set to obtain the behavior regularity indicators, including:

[0079] feature extraction is performed on the historical behavior records in the initial data set to obtain user access frequency and initial behavior features;

[0080] time series segmentation analysis is performed on the user access frequency and the initial behavior features to construct behavior distribution features in different time periods;

[0081] Based on the behavior distribution features, the access duration and access peak interval of each time interval are analyzed to calculate the behavior concentration;

[0082] When the behavior concentration exceeds a preset behavior concentration threshold, the corresponding time interval is determined as a user active period;

[0083] For the access path preference and behavior repetition frequency in the active period, clustering analysis is performed to identify the behavior pattern features and habit tendency results of the user in a specific period;

[0084] Combining the behavior pattern features and the habit tendency results, conditional matching analysis is performed to identify key behavior patterns to obtain behavior regularity indicators for trust assessment.

[0085] In one specific embodiment, the system first performs field parsing and cleaning on the historical behavior records in the initial data set, filters out the behavior logs related to access operations, including access time, access target number, access method and operation type. Then, by counting the access frequency of each user per day in the past 30 days, the average access times, maximum access density and access interval fluctuation range of the user are calculated to obtain the user's access frequency features, which reflect the user's activity level and behavior persistence.

[0086] In specific embodiments, the system further quantifies the user's access behavior by calculating the "access interval fluctuation range". This feature is used to describe the fluctuation of the time interval of the user's access operation, and can reflect the stability or irregularity of the user's behavior. In order to accurately calculate this fluctuation range, the system uses standard deviation as the measurement standard. The specific calculation method is as follows:

[0087] First, the system calculates the access interval time according to the access records of each user. Suppose the time points of the user's access operations in a period of time are t1, t2,..., tn, where t1 is the first access time and tn is the last access time. Then, the access interval time is calculated as the difference between adjacent access time points. Next, the system calculates the standard deviation of these access intervals to describe the fluctuation range of the interval.

[0088] Subsequently, the system constructs a time series based on the access timestamp information and divides the daily 24 hours into several preset time segments (e.g., 00:00-06:00, 06:00-12:00, etc.). The system performs segmented aggregation operations on the behavior data within each time segment to form a behavior distribution feature matrix. This matrix reflects the operation intensity of the user in different time segments, providing a basis for further analysis of the behavior timing characteristics.

[0089] The system extracts the behavior features of the user in different time segments by performing segmented aggregation operations on the user's access behavior, reflecting the user's activity level and behavior regularity. First, the system divides the 24 hours of each day into several preset time segments, for example, dividing a day into four time segments: 00:00-06:00, 06:00-12:00, 12:00-18:00, and 18:00-24:00. The division of these time segments can be adjusted according to actual needs to capture the user's activity peaks and troughs.

[0090] Next, the system performs aggregation operations on the behavior data within each time segment. The aggregation methods include the calculation of access times, access durations, or other related indicators. For example, the system can count the number of accesses in a certain time segment, calculate the average duration of each access, or obtain the maximum access frequency in that time segment. These aggregated data help describe the user's activity level and behavior intensity in each time segment.

[0091] For example, the system may find that a certain user has a higher number of accesses and longer access durations in the morning time segment (06:00-12:00), while having a lower number of accesses and shorter average access durations in the late-night time segment (00:00-06:00). This information is summarized into a behavior distribution feature matrix, with each row corresponding to a time segment and each column corresponding to a specific behavior feature (such as access times, access durations, etc.). This matrix not only provides the system with the time series characteristics of user activity, but also provides an important basis for subsequent behavior analysis and trust scoring.

[0092] For the behavior distribution features, the system calculates the access duration (i.e., the average duration of continuous operations) and the access peak interval (i.e., the time segment in which the number of accesses accounts for more than 30% of the total behavior) within each time interval, and calculates the "behavior concentration degree" based on these two quantitative indicators. The behavior concentration degree is defined as the degree of high-frequency operations concentrated in a few time segments, reflecting whether the user's behavior is regular and stable.

[0093] The system quantifies whether the user's access behavior is concentrated in a few specific time periods by calculating the behavior concentration, reflecting the regularity and stability of user behavior. First, the system calculates the access duration in each time period, which is the average duration of continuous operation by the user in that time period. The access duration is used to measure the user's activity level in a certain time period. If the user's operation in a certain time period is more concentrated and the access interval is shorter, the access duration in that time period will be longer, indicating that the user's behavior in that time period is more concentrated and regular.

[0094] Next, the system identifies the access peak interval, which is the part of a time period where the user's access frequency accounts for more than 30% of the total behavior frequency in that time period. The system counts the access frequency in each time period and finds the time period with the highest access frequency, which is considered as the peak interval. For example, if the user's access frequency in a certain time period accounts for more than 60% of the total access frequency in that time period, then these two time periods constitute the access peak interval, indicating that the user's operation in these time periods is more frequent.

[0095] Based on these indicators, the system further calculates the behavior concentration, which reflects whether the high-frequency operation is concentrated in a few time periods. The calculation formula of the behavior concentration is to calculate the ratio of the access frequency in the peak interval to the total access frequency. The higher the value, the more concentrated the user's behavior in a specific time period, and the more regular it is. For example, if a user has a total of 10 accesses in the 06:00-12:00 time period, of which 5 occur in the 06:30-07:00 and 08:00-08:30 time periods, which account for 80% of the total access frequency, then the user's behavior concentration is 0.8, reflecting the user's high activity and strong behavior regularity in these two time periods. In this way, the system can effectively identify the user's behavior pattern and provide important basis for subsequent trust score calculation and permission configuration.

[0096] When the behavior concentration of a certain time period is higher than the pre-set behavior concentration threshold (e.g. 0.65), the system determines that this time period is the user's "active period". In the active period, the system further extracts the user's access path sequence (such as first viewing the report overview, then viewing the risk field, and finally downloading the full text) and counts its frequency. The system uses a density-based clustering algorithm (such as DBSCAN) to cluster the access path sequence, extract the typical path preference and repeated access behavior, and use them as the user's behavior habit tendency features.

[0097] Finally, the behavior path patterns identified by the user in the active period are conditionally matched with the preset key behavior templates for analysis. If a behavior pattern matches the expected trusted behavior sequence (such as browsing and operating in standard order, reasonable operating time, etc.) to a high degree, it is marked as a "key behavior pattern". All key behavior pattern characteristics and user access concentration, path preference, etc. indicators together constitute the user's behavior regularity index, providing a basis for subsequent trust score.

[0098] In a specific embodiment, the system further determines whether the user's behavior conforms to the system's expected trusted behavior sequence by conditionally matching the behavior path patterns identified by the user in the active period with the preset key behavior templates. The expected trusted behavior sequence refers to a standard behavior pattern sequence set by the system based on the user's normal usage habits and platform operation specifications. This sequence specifically includes the user's operating order on the platform, access duration, reasonableness of operating time, and other dimensions of behavior requirements.

[0099] Specifically, the expected trusted behavior sequence includes the following aspects:

[0100] Standard operating order: When accessing the platform, the user will generally follow a certain order of operation. For example, in an online learning platform, the user's regular operation process should be to log in first, then select a course, and then learn and view the score, rather than skipping certain steps and directly entering unrelated pages. The system defines this normal behavior sequence as the standard operating order and uses it as the basis for trusted behavior.

[0101] Reasonable operating time: The time interval for each operation is also set to a reasonable range. For example, the user's stay time on a page should not be too short (e.g., immediately jump) or too long (e.g., long time without operation). The system analyzes the typical duration of user operations based on historical data and defines these durations as reasonable operating time. If the user stays on a page for too long or too short a time, the system will consider it as abnormal behavior and compare it with the expected trusted behavior sequence.

[0102] Browsing and operating according to standard process: The system compares the user's operation process with the standard process to see if there are any skipped steps or non-standard operations. For example, when a user browses goods on an e-commerce platform, the system will require the user to first browse the goods list, then select a specific good, and then perform operations such as adding to cart, checkout, etc. If the user directly jumps to the payment page, the system will judge this behavior as abnormal and match it with the expected trusted behavior sequence.

[0103] Behavior consistency and stability: The trusted behavior sequence also includes the consistency and stability of user operations. For example, if the user usually logs in and operates at a fixed time period every day (such as from 9:00 to 11:00 am every day), and the system finds that the user frequently operates at a non-fixed time period, the system will consider it as an abnormal behavior and compare it with the expected trusted behavior sequence to determine whether there is an abnormality.

[0104] When the user's behavior pattern matches the preset key behavior template to a high degree, the system will mark it as a "key behavior pattern". These key behavior patterns, combined with the user's access concentration, path preference and other behavior indicators, will together constitute the behavior regularity indicators of the user, providing a basis for subsequent trust score calculation.

[0105] In a specific embodiment, the preset of the behavior concentration threshold can be determined according to the historical behavior data of the user group and its distribution. First, the system analyzes the access density and time period concentration of all users from the user's historical behavior data, and calculates the access frequency distribution of each user in different time periods. Through the statistics of the behavior concentration of all users, the system calculates the mean and standard deviation of the behavior concentration.

[0106] Illustratively, in the application of an education platform, the system analyzed the behavior data of 1000 users in the past three months, counted the behavior concentration of all users, and calculated the mean of 0.58 and the standard deviation of 0.12 of the data set. According to this data, the system sets the behavior concentration threshold to be the mean plus one standard deviation (i.e. 0.70). At this time, all users with a behavior concentration greater than 0.70 are considered to have a higher regularity of behavior characteristics, and belong to the active period.

[0107] If the behavior concentration of a user exceeds the preset threshold of 0.70, the system will determine its active period as "highly active". For example, if a user accesses a report of a platform multiple times during the daily peak period (e.g. 8:00-10:00), and the behavior in this period accounts for more than 70% of the total access behavior, the system will determine this behavior as "highly concentrated", and consider this period as the active period of the user.

[0108] This preset behavior concentration threshold can be adjusted according to the characteristics of different platforms or application scenarios. For example, in a financial platform, since users pay more attention to reports, the system can appropriately lower the threshold to 0.65 to identify a wider active period; while in a social platform, since user behavior is more dispersed, the threshold can be increased to 0.75 to filter out highly concentrated behavior patterns.

[0109] In this way, the behavior concentration threshold can be flexibly adjusted according to the needs of different scenarios, ensuring that the user's active period can be accurately captured and timely basis can be provided for subsequent trust evaluation.

[0110] In step S13, the behavior regularity index needs to be combined with the user identity information in the initial data set to perform weighted calculation to obtain a preliminary trust score value, including:

[0111] Perform time interval refinement analysis on the behavior regularity index to construct behavior regularity feature values in different time periods;

[0112] Compare the behavior regularity feature values with the user identity information in the initial data set to perform matching analysis operation of behavior characteristics and role typical behavior interval to obtain role behavior data meeting the role expectation;

[0113] According to the user identity information in the initial data set, combined with the role behavior data, perform weighted calculation to quantify the matching degree of behavior characteristics and permission range to obtain a trust score base value;

[0114] According to the trust score base value, combined with the preset trust score interval, perform interval determination operation to obtain a preliminary trust score value.

[0115] In one specific embodiment, step S13 is mainly used to calculate the preliminary trust score value of the user by analyzing the user's historical behavior records, identity information and role characteristics. This process includes multiple links, and the data source and processing method of each link are carefully designed to ensure the accuracy and reliability of the trust score.

[0116] Firstly, the system will refine the user's historical behavior data by time to construct behavior regularity feature values in multiple time periods (such as hours, days, weeks). The behavior regularity index usually includes access frequency, access duration and operation type distribution. The system divides the behavior data of each user into different time periods by segmenting the timestamp information of the behavior log data, such as the number of accesses per hour or the number of active days per week. The system calculates the behavior characteristics in different time periods according to these data, such as frequent access in the morning 7:00-9:00 on weekdays, and concentrated in the afternoon on weekends. Through time interval refinement analysis, the system can more accurately identify the user's behavior pattern.

[0117] For example, suppose a user of an education platform has an access behavior in the past three months, the access frequency in the morning peak period of weekdays is 20 times / hour, and the access frequency on weekends is scattered, only 5 times / hour. At this time, the system can construct the behavior regularity feature value in each time interval according to these time period data to reflect the user's access habits.

[0118] In one specific embodiment, the system first extracts the behavior regularity indicators of the user by feature extraction on the historical behavior records of the user. Then, the system compares the behavior data of the user with the preset typical behavior patterns of the role to determine whether it meets the role expectation. In specific implementation, the system extracts the behavior pattern data of the role according to the identity information of the user (for example, teacher, student, administrator, etc.). For example, the behavior pattern of a teacher is to frequently access course content and manage the background, while the behavior pattern of a student is more focused on viewing course content and submitting homework. The system determines whether the behavior meets the role expectation by comparing the matching degree of the user behavior data and the role behavior pattern.

[0119] The quantification of the matching degree is realized by the cosine similarity measurement method. Cosine similarity evaluates the similarity between two vectors by calculating the included angle, and the value closer to 1 indicates higher similarity, and vice versa. Specifically, the system constructs a vector of the user's behavior characteristics (such as access frequency, access duration, operation type, etc.) in different time periods, and compares it with the typical behavior pattern vector of the preset role. If the cosine similarity value is high, it means that the user's behavior is highly consistent with the typical behavior pattern of the role, meeting the role expectation. For example, assume that the behavior characteristic vector of a user is A = [0.8, 0.2, 0.5] A = [0.8, 0.2, 0.5] A = [0.8, 0.2, 0.5], representing his access behavior in different time periods (such as access frequency in the morning, afternoon and evening), and the typical behavior pattern vector of the "teacher" role is B = [0.9, 0.3, 0.6] B = [0.9, 0.3, 0.6] B = [0.9, 0.3, 0.6]. By calculating the cosine similarity, the system can obtain the quantification result of the matching degree.

[0120] In one specific embodiment, the system uses weighted calculation to obtain the trust score base value by combining the user identity information and the behavior data meeting the role expectation. In specific operation, the system first extracts the behavior pattern data of the role according to the identity information of the user (for example, teacher, student, administrator, etc.). Each role has its typical behavior pattern, for example, the behavior pattern of a teacher is usually to frequently access course content and manage the background, while the behavior pattern of a student is more focused on viewing course content and submitting homework. The system matches the behavior data of the user with the typical behavior pattern of the preset role, calculates the matching degree, and thus assigns a corresponding weight to the behavior data.

[0121] The quantification of the matching degree is usually achieved by cosine similarity or Euclidean distance. Through these similarity measures, the system can obtain a value representing the similarity between the user behavior data and the role behavior pattern. For example, if the user's behavior pattern is highly consistent with the expected behavior pattern of the teacher role, the cosine similarity may be 0.85, indicating that the user behavior is highly matched with the teacher role, and the system will assign a higher weight, for example, 0.8, to this data. Conversely, if the user behavior is less matched with the expected behavior of the role (e.g., the matching degree is 0.4), the system will assign a lower weight (e.g., 0.3) to this behavior data.

[0122] For example, assume that the platform presets the behavior characteristic matching weight of the teacher role as 0.8 and the student role as 0.6. If the behavior of a certain teacher user is 90% matched with the role, then the behavior data will obtain a weight of 0.8. The system obtains a trust score base value, for example, 85 points, according to the weighted calculation result.

[0123] In a specific embodiment, the system performs interval determination according to the trust score base value and the preset trust score interval, obtaining a preliminary trust score value. Specifically, the system will determine whether the user's trust score base value falls within the preset interval according to the preset score interval (e.g., 0-100 points). If the score value is higher than a certain threshold (e.g., 80 points), it is considered that the user has a high trust degree, and is given a "high trust" score; if the score value is lower than the threshold, it is a "low trust" user. Through this interval determination, the system can dynamically adjust the user's access rights according to the score value.

[0124] For example, assume that a user's trust score base value is 85 points, the preset trust score interval is 0-100 points, and 80 points is the threshold for high trust degree. Since the user's score value is 85 points, the system determines that the user is a "high trust" user and configures his / her rights according to this score.

[0125] In a specific embodiment, the system sets different trust score intervals according to the user's behavior characteristics and identity information to adapt to different application scenarios. In this example, the platform uses a score range of 0 to 100 points, and divides users into three categories of high trust, medium trust and low trust according to the regularity of their behavior, access frequency and identity role, so as to dynamically adjust the user's access rights according to the trust degree.

[0126] Specifically, the high-trust interval has a score range of 80-100 points, suitable for users with strong behavioral regularity and no abnormal operations. The behavior of such users fully matches their identity roles, and the system determines that their behavior conforms to the platform's preset standards through long-term data accumulation. Taking an enterprise information management platform as an example, users in the administrator role usually have high behavioral consistency, and their access behavior shows strong regularity, and each operation conforms to the management regulations. Therefore, the system sets the score of such users as high trust, and grants them access to all sensitive data and high-level functions.

[0127] The medium-trust interval has a score range of 60-79 points, suitable for users with occasional abnormalities. The behavior patterns of such users generally conform to the expectations of their identity roles, but occasionally have unstable operation behavior or access patterns. For example, a teacher role user in an online education platform mainly uploads teaching materials, but occasionally accesses student performance data, and the access time and frequency are irregular. The system will adjust the trust score based on these abnormal behaviors, classify them as medium-trust users, and make corresponding restrictions on permissions, such as not being able to access other sensitive data.

[0128] For the low-trust interval, the system sets the score range to 0-59 points, suitable for users whose behavior characteristics do not match their identity roles and have potential security risks. For example, newly registered users, temporary visitors, or users with abnormal device status, whose access behavior does not match their identity roles, and have frequent abnormal login behavior or illegal access risks. The system will set the trust score of such users as low trust, and limit their access permissions, allowing them to access only non-sensitive data, and requiring additional identity verification and review for each access.

[0129] In addition, the system also adjusts these score intervals flexibly according to different application scenarios. In a medical data management platform, due to the high sensitivity of data, the system sets the high-trust interval to 90-100 points, the medium-trust interval to 75-89 points, and the low-trust interval to 0-74 points. For example, when a doctor role user views patient medical records, if their operation shows high regularity and no abnormal behavior, their trust score is high, giving them full access rights; while a nursing staff or temporary visitor role, their trust score is low, and their access rights are limited.

[0130] In step S14, a comprehensive trust score is obtained by combining the preliminary trust score value, the device status data in the initial data set, and the preliminary trust score value, including:

[0131] According to the preliminary trust score value, the security parameters and network environment information in the device status data in the initial data set are combined to perform risk factor identification and score adjustment operations to obtain a comprehensive trust score.

[0132] The risk factor identification and score adjustment operation includes:

[0133] Performing state comparison based on the security parameters and the preset security threshold to obtain device anomaly identification data;

[0134] Performing risk level judgment based on the network environment information to obtain network risk identification data;

[0135] Fusing the device anomaly identification data and the network risk identification data, and performing weighted correction on the preliminary trust score value in combination with a preset trust score adjustment rule to obtain intermediate score data;

[0136] Performing interval matching operation according to the intermediate score data and a preset score mapping table to obtain a comprehensive trust score.

[0137] In one specific embodiment, step S14 is used to perform risk assessment by combining the preliminary trust score value of the user and the device state data, thereby obtaining a comprehensive trust score. This process first considers the security parameters of the device and the network environment information, and combines a preset rule to correct the preliminary trust score, ensuring that the evaluation result has higher accuracy and dynamic adaptability.

[0138] Firstly, the system combines the preliminary trust score value of the user with the security parameters of the device and the network environment information. Specifically, the system evaluates the security of the device by monitoring the state of the device in real time, such as the operating system version of the device, the security patch situation, whether there is malicious software, etc. At the same time, the system also considers the risk of the network environment, such as whether the current user is connected to a trusted network and the stability of the network connection. The system takes these information as risk factors and dynamically adjusts the preliminary trust score based on these factors to finally obtain a comprehensive trust score.

[0139] For example, in an online medical platform, if the operating system of the user's device is not updated to the latest version and is connected to an insecure public Wi-Fi network, the system will reduce the trust score of the user according to the risk information of the device and the network.

[0140] Specifically, the risk factor identification and score adjustment operation of the system includes the following key links:

[0141] The system compares the security parameters of the device (such as device hardware information, operating system version, security patch level, etc.) with the preset security standards. If the security parameters of the device do not meet the preset standards (for example, the device operating system version is outdated, critical security patches are not installed, etc.), the device is marked as an abnormal state, and device anomaly identification data is generated. For example, if a user's device fails to update the operating system in a timely manner, and the operating system version of the device is known to have security vulnerabilities, the system will generate device anomaly identification and reduce its trust score.

[0142] Next, the system evaluates the user's network environment and identifies whether the current network is secure. If the user is connected to an unencrypted public network or other potentially dangerous network environment, the system will judge that there is a high network risk, and generate network risk identification data. For example, if the user accesses sensitive information while using a public Wi-Fi network, the system will identify this behavior and generate network risk identification, indicating that this network environment poses a potential threat.

[0143] In a specific embodiment, the system first fuses the device anomaly identification data and the network risk identification data. The system adjusts the preliminary trust score according to the preset trust score adjustment rules. The weighting coefficients are set according to the influence of different risk factors on the trust score. For example, if the security of the device has a greater overall impact on the system, the device risk may be given a higher weight, while the risk of the network environment may only account for a small weight in some scenarios. Specifically, the system can preset different weighting coefficients according to business needs and actual risk assessment situations, such as a device security weight of 70% and a network environment risk weight of 30%.

[0144] In actual application, the system will adjust the preliminary trust score according to these weights. Assuming that the security score of the device is 0.9 (full score 1), and the risk score of the network environment is 0.5, the preliminary trust score is 0.8, and the system sets the device risk weight to 70% and the network risk weight to 30%, the two risk identifications and the preliminary trust score are calculated according to the weights. The weighted comprehensive trust score is calculated according to the following formula:

[0145] Comprehensive trust score = (preliminary trust score x (1-device risk weight)) + (device anomaly identification data x device risk weight) + (network risk identification data x network risk weight)

[0146] Through this weighted calculation, the system can dynamically adjust the trust score. For example, when the device has security vulnerabilities and the network environment is insecure, the system will make a large downward adjustment to the preliminary trust score to reflect the real security risk. If the device risk is low and the network environment risk is high, the system will adjust the trust score according to the corresponding weight to ensure that the final trust score more accurately reflects the user's trust level. Finally, the system determines the final comprehensive trust score by matching the interval through a pre-set score mapping table according to the weighted corrected score intermediate data. The mapping table maps the comprehensive trust score to different trust levels (such as high, medium, and low trust), and adjusts the user's access rights and operation range according to the trust level. For example, if the comprehensive trust score is above 80 points, the system will mark the user as a "high trust" user and give higher access rights; if the score is below 60 points, the user will be marked as a "low trust" user and access to sensitive data will be restricted.

[0147] It should be noted that in a specific embodiment, the pre-set security threshold is a standard used by the system to evaluate the security of the device and the network environment, and these thresholds are set according to different application scenarios and industry requirements. The system will compare the security parameters of the device (such as the operating system version, patch installation status, encryption support level, etc.) with these thresholds, and if the device does not meet the pre-set security requirements, it will be considered as a security risk, thereby affecting the user's trust score. For example, in a certain enterprise-level information platform, the system sets the minimum requirement for the operating system version to Windows 10, requires that the device must install the latest security updates for security patches, and requires that the device must use 256-bit AES encryption for encryption support. If the device's operating system version is lower than Windows 10 or does not have the latest patch installed, the system will mark the device as an "abnormal device" and reduce the trust score of the user corresponding to the device. This process is completed through real-time detection and comparison of device security information, ensuring that the platform can identify and respond to potential security risks in a timely manner. The role of this pre-set security threshold is to provide a dynamic security check mechanism to ensure that the device and network environment meet the minimum security requirements when performing trust evaluation. In this way, the system can discover devices that do not meet the standards in a timely manner and automatically adjust the user's trust score and access rights based on the security status of the device.

[0148] It should be noted that the preset score mapping table is used to convert the comprehensive trust score into specific trust levels, and different access permissions are assigned to users according to different trust levels. The system calculates a comprehensive trust score according to multi-dimensional data such as user behavior patterns, device states, and network environment information, and then uses the score mapping table to determine the user's access permission range according to the score. For example, in an online education platform, the system sets the score mapping table as follows: if the user's trust score is in the 90-100 score interval, the user will be assigned a "high trust" level and can access all sensitive data on the platform; if the trust score is 70-89, it is "medium trust", which can access regular data but not sensitive information; while 50-69 is marked as "low trust", only non-sensitive information can be accessed; and a trust score of 0-49 will be assigned as "very low trust", which can only access public information. This score mapping table allows the system to dynamically adjust the user's access permissions according to the user's actual behavior and trust level. For example, if a user has a security vulnerability in the login device, the trust score will be lowered due to the device security problem, and in the subsequent use process, the system will limit the user's access to sensitive information according to the low trust score, ensuring that only users who meet the preset trust criteria can access high-risk data on the platform. The role of the score mapping table is to provide a standardized and standardized trust evaluation framework, which ensures that users of different levels can only access the data allowed by their trust level by accurately setting the score interval. This process ensures that the platform can dynamically adjust the permission configuration under different user trust levels, improving the security and data protection capabilities of the system.

[0149] In step S15, the user environment change evaluation needs to be performed according to the comprehensive trust score in combination with the environment perception data to obtain a final trust score, including:

[0150] According to the physical location information and timestamp information in the environment perception data, a geographic risk level identification is performed to obtain a location risk coefficient;

[0151] According to the access point information in the environment perception data, a trusted network comparison is performed to obtain a network environment evaluation result;

[0152] According to the behavior data and historical behavior patterns in the environment perception data, a behavior deviation analysis is performed to obtain behavior anomaly identification data;

[0153] According to the comprehensive trust score, in combination with the location risk coefficient, the network environment evaluation result, and the behavior anomaly identification data, a dynamic score adjustment is performed to obtain a final trust score.

[0154] In one specific embodiment, step S15 is used to evaluate the user's environment change based on the combination of the comprehensive trust score and the environmental perception data, so as to obtain a final trust score. This process involves multiple data sources, including the user's physical location information, network environment information and behavior data. Through multi-dimensional information analysis, the user's trust score is dynamically adjusted to ensure that the score reflects the user's current behavior and environmental risk.

[0155] Firstly, the system will identify the geographic risk level through the user's device physical location information (such as GPS coordinates) and timestamp information, combined with the geographic information system (GIS) database. The system assesses the risk of the location by querying the security level of the area where the user is currently located. For example, if the user's location is a high-risk area (such as a known location of frequent network attacks or a location with high incidence of device theft), a higher location risk coefficient will be assigned to the location.

[0156] For example, in a medical data platform, if the user is located in an isolated ward area or a specific ward of a hospital, the system will automatically mark this location as a low-risk area, while if the user is located in a public place (such as an airport or a coffee shop), it will be determined as a high-risk area, which will affect the trust score.

[0157] In one specific embodiment, the system will obtain the access point information of the user's device (such as Wi-Fi SSID, BSSID, signal strength, etc.) and compare it with the preset trusted network list. If the user is currently connected to a known secure network (such as an enterprise intranet or a home Wi-Fi), the network environment is evaluated as trusted and a lower network risk level is assigned to it; otherwise, if the user is connected to a public network (such as a free Wi-Fi or an unfamiliar network), the network environment is evaluated as untrusted, which will negatively affect the trust score. For example, in a certain financial platform, if a user accesses account data on the internal network of a bank, it will be identified as a safe network environment, while if the user accesses the platform on the open Wi-Fi of a coffee shop, the connection will be marked as a potential risk environment.

[0158] In one specific embodiment, the system will analyze the deviation between the user's current behavior data and his historical behavior patterns. For example, the system will check the user's login time, access content, device type, etc. and compare it with his past behavior patterns. If it is found that a user logs in using an unusual device at an unusual time (such as late at night or during a holiday) and accesses content that is inconsistent with his normal behavior patterns, the system will mark it as abnormal behavior and generate behavior anomaly identification data. For example, if a user who usually accesses the system during the day logs in through a new device at night and accesses a large amount of data, the system will automatically mark it as abnormal behavior, which will affect the user's final trust score.

[0159] In a specific embodiment, the system combines the comprehensive trust score with all the above risk factors (location risk coefficient, network environment assessment result and behavior anomaly identification data) to perform dynamic score adjustment. The system assigns different weights to each risk factor according to preset rules, and adjusts the trust score according to these weights. If the behavior anomaly and network risk are high, the final trust score of the user will be greatly reduced, and vice versa. For example, on a medical platform, if a user's trust score is 85 points, and he is located in a high-risk location (such as a public place), uses an untrusted network and exhibits abnormal behavior, the system will adjust the user's trust score downward and obtain a final trust score of 70 points. This score reflects the security risk and trust status in the current user environment.

[0160] In step S16, the final trust score needs to be combined with the preset rule base to extract the report access restriction range and risk level, and perform permission level adjustment and visible content range setting to obtain the final permission configuration scheme, including:

[0161] According to the final trust score, the permission mapping table in the preset rule base is combined to perform access level identification to obtain user permission level data;

[0162] According to the user permission level data, the report access classification rules in the preset rule base are combined to perform report type screening to obtain an accessible report type list;

[0163] According to the accessible report type list, the field permission control table in the preset rule base is combined to perform field-level access permission matching to obtain a field access permission mapping result;

[0164] According to the field access permission mapping result, the report content is reconstructed to obtain personalized detection report content;

[0165] According to the final trust score, the permission level definition table in the preset rule base is combined to perform permission level adjustment operation to obtain permission level configuration result;

[0166] According to the permission level configuration result and the personalized detection report content, the permission configuration integration is performed to obtain the final permission configuration scheme.

[0167] The permission configuration integration according to the permission level configuration result and the personalized detection report content to obtain the final permission configuration scheme includes:

[0168] According to the permission level configuration result, the field access permission mapping result in the personalized detection report content is combined to perform access control rule matching to obtain field visibility configuration data;

[0169] According to the field visibility configuration data, combined with the operation permission definition in the permission level configuration result, content presentation and operation boundary integration are performed to obtain a final permission configuration scheme.

[0170] In a specific embodiment, the purpose of step S16 is to comprehensively adjust the report access permission of the user by combining the final trust score of the user with the preset rule library, and generate a personalized permission configuration scheme. This process includes multiple links from permission mapping, report type screening to field-level permission control, finally ensuring that the user can only access the content within the trust score range.

[0171] Firstly, the system will compare the final trust score with the preset permission mapping table. The permission mapping table defines the access permission level corresponding to different trust scores. The system determines the user's permission level by comparison. Specifically, if the user's trust score is high, the system will assign a higher access permission level to the user, and vice versa.

[0172] For example, assuming that a user's final trust score is 88, the system maps it to "high-level permission" through the permission mapping table, and gives it the permission to access all types of reports and data. If another user's trust score is 65, the user is assigned "medium-level permission" and can only access regular reports and basic data.

[0173] In a specific embodiment, the system filters out the report types that the user can access according to the user's permission level data combined with the preset report access classification rules. For example, the system will assign different categories of report permissions according to the permission level, such as "course report", "report card", "teacher feedback" reports in the education platform. High-level permission users can access all reports, while medium-level permission users can only access some report types.

[0174] For example, for a user with "high-level permission", the system allows him to access all types of detection reports, while for a user with "medium-level permission", it only allows access to "regular health reports" and "course learning progress" reports.

[0175] In a specific embodiment, the system will combine the preset field permission control table to match the field-level access permission according to the list of report types accessible by the user. The field permission control table defines the access requirements of each report field, and the system will determine which fields can be displayed, which fields should be hidden or encrypted according to the user's permission level. For example, sensitive information fields such as patient name and academic performance can only be accessed by users with high-level permission.

[0176] For example, for a health report, the system allows a "high-level permission" user to view the patient's name, diagnosis report, and prescription information, but only displays basic diagnosis information and treatment recommendations for a "medium-level permission" user, and hides sensitive personal information fields.

[0177] In a specific embodiment, according to the above field access permission mapping result, the system reconstructs the report content to generate a personalized report view. That is, according to the user's permission, the corresponding field is hidden or displayed, ensuring that the user can only access the data within the scope of his permission. This process ensures the personalization and security of the report content.

[0178] For example, for a user with "medium-level permission", the system will hide the patient's name, ID number, and other personal information in the health report, and only display the report content that the user can access, such as disease diagnosis and treatment recommendations.

[0179] In a specific embodiment, the system will adjust the permission level according to the final trust score combined with the pre-set permission level definition table. If the final trust score is high, the system will set the user's permission level to "high-level permission", otherwise it will be set to "medium-level permission" or "low-level permission". The permission level definition table sets the specific permission operations corresponding to each trust score range.

[0180] For example, if a user's final trust score is 92, the system will classify it as "high-level permission" according to the permission level definition table and give it the highest permission to access the report; if the score is 70, it is "medium-level permission", and the system limits its access to some reports.

[0181] In a specific embodiment, the system will integrate the permission level configuration result and the personalized detection report content to generate the final permission configuration scheme. This scheme ensures that the user's permission corresponds to his trust score, while ensuring the security and personalized display of the report content. For example, the system will generate a report view that meets the user's needs according to the user's permission level, ensuring that the user can only access data that corresponds to his trust level.

[0182] For example, for a "high-level permission" user, the system generates a fully open report that displays all data fields; for a "low-level permission" user, the system hides some sensitive fields (such as patient name, diagnosis details, etc.) and only displays basic medical information.

[0183] It should be noted that the permission mapping table is used to map the user's comprehensive trust score to its corresponding access permission level. The system dynamically determines the accessible content and functions of the user according to the user's trust score. These score intervals are set according to platform requirements, industry standards and user behavior characteristics. For example, in an education platform, the system sets the following permission mapping rules: for users with trust scores between 80-100 points (such as long-term active teachers and administrators), they are assigned "high-level permissions" and can access all educational resources, grade reports and teaching tools; for users with trust scores between 70-79 points (such as some students or teachers), the system gives them "intermediate permissions" and limits their access to some sensitive data such as transcripts or student privacy information; and users with trust scores below 70 points are given "low-level permissions" and can only access basic reports and public information on the platform. Such a mapping table ensures that the system's permission control at different trust levels is both reasonable and dynamic.

[0184] It should be noted that the report access classification rules are used to refine the types of reports that users of different roles and trust levels can access. According to the user's role (such as student, teacher, administrator) and trust score, the system filters out the types of reports that the user can access according to the set classification rules. For example, in an online education platform, users with the role of teacher can access all types of teaching reports, including student performance, course feedback and teaching progress data, while students can only access their own learning progress reports and transcripts and cannot view the performance of other students or other sensitive data. Administrators can access all report data within the platform, including system operation data and student behavior analysis. Through these classification rules, the system can ensure that users of different identities can only access data that matches their permissions and trust levels, avoiding the leakage of sensitive information.

[0185] It should be noted that the field permission control table is used in the system to perform fine-grained permission control on the fields in the report content. According to the user's trust score and role characteristics, the system can set different access levels for each field in the report. For example, in a medical health management platform, doctors need to access the complete medical history, treatment history and personal information of patients, while nurses or other medical staff can only access the treatment records and some basic information of patients. The system sets permissions according to the user's trust score and role, hides or encrypts certain sensitive fields. If a low-trust user (such as an external temporary visitor) tries to access the detailed medical history information of a patient, the system will hide the fields related to personal privacy (such as the patient's name, ID number, etc.) and only display the basic information that does not involve privacy (such as disease type, treatment plan). This fine-grained control ensures the security of data and dynamically adjusts the visibility of content according to different roles and trust levels.

[0186] It is noted that the permission level definition table defines the operation permissions of users in different trust score ranges. This table defines the specific operation permissions corresponding to each trust score interval in the background system and ensures that the permission configuration matches the trust score. For example, in a certain financial platform, the system sets the trust score of users in the range of 90-100 points, and the user will have full operation permissions, such as data query, modification, deletion, and report generation. For users with a trust score between 70-89 points, they can only query data and view reports, and cannot modify sensitive data. Users with a trust score between 50-69 points can only perform basic query operations and cannot access any sensitive information. For users with a low trust score (such as 0-49 points), the system will limit their access permissions, allowing them to view only public basic information and requiring additional identity verification for each operation. This trust score-based permission allocation ensures that the system can flexibly adjust user operation permissions to meet different risk management needs.

[0187] In summary, the present application provides a cloud platform-based detection report management method and system to solve the problem of inaccurate permission configuration and inability to dynamically evaluate trust in the prior art.

[0188] Referring to Figure 2 The second embodiment of the present application provides a cloud platform-based detection report management system, comprising:

[0189] A data acquisition module is configured to acquire user identity information, historical behavior records, device state data, and environmental perception data, and to perform heterogeneous data preprocessing on the user identity information, the historical behavior records, and the device state data to obtain a unified initial data set.

[0190] A behavior analysis module is configured to extract user access frequency and behavior pattern features from the historical behavior records in the initial data set to obtain a behavior regularity index.

[0191] A preliminary analysis module is configured to perform weighted calculation based on the behavior regularity index and the user identity information in the initial data set to obtain a preliminary trust score value.

[0192] A comprehensive analysis module is configured to perform risk assessment based on the preliminary trust score value, the device state data in the initial data set, and the preliminary trust score value to obtain a comprehensive trust score.

[0193] A final analysis module is configured to perform user environment change assessment based on the comprehensive trust score and the environmental perception data to obtain a final trust score.

[0194] A scheme configuration module is configured to extract a report access restriction range and a risk level according to the final trust score in combination with a preset rule base, and perform permission level adjustment and visible content range setting to obtain a final permission configuration scheme.

[0195] It should be noted that the cloud platform-based detection report management system provided by the embodiments of the present application is used to execute all process steps of the cloud platform-based detection report management method provided by the above embodiments, and the working principles and beneficial effects of the two are one-to-one correspondence, thus not being repeated.

[0196] The embodiments of the present application also provide an electronic device. The electronic device includes a processor, a memory, and a computer program, such as a behavior analysis program, stored in the memory and executable on the processor. The processor implements the steps in the above various cloud platform-based detection report management method embodiments when executing the computer program, for example Figure 1 The processor implements the functions of the modules / units in the above various device embodiments when executing the computer program, such as a behavior analysis module.

[0197] For example, the computer program can be divided into one or more modules / units, which are stored in the memory and executed by the processor to complete the present application. The one or more modules / units can be a series of computer program instruction segments capable of completing a specific function, which are used to describe the execution process of the computer program in the electronic device.

[0198] The electronic device can be a desktop computer, a notebook, a palm computer, and a smart tablet, etc. The electronic device can include, but is not limited to, a processor and a memory. Those skilled in the art can understand that the above components are only examples of the electronic device and do not constitute a limitation on the electronic device, and the electronic device can include more or fewer components than the above, or combine certain components, or different components, for example, the electronic device can also include an input / output device, a network access device, a bus, etc.

[0199] The processor can be a central processing unit (CPU), and can also be other general-purpose processors, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic device, discrete gate or transistor logic, discrete hardware components, etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor. The processor is a control center of the electronic device, and connects various parts of the electronic device through various interfaces and lines.

[0200] The memory can be used to store the computer program and / or modules, and the processor realizes various functions of the electronic device by running or executing the computer program and / or modules stored in the memory, and calling the data stored in the memory. The memory can mainly include a program storage area and a data storage area, wherein the program storage area can store an operating system, at least one application program required by a function (such as a sound playing function, an image playing function, etc.), etc.; and the data storage area can store data created according to the use of the mobile phone (such as audio data, a phone book, etc.), etc. In addition, the memory can include a high-speed random access memory, and can also include a nonvolatile memory, for example, a hard disk, a memory, a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, at least one disk storage device, a flash memory device, or other volatile solid-state memory device.

[0201] The modules / units integrated in the electronic device, if realized in the form of software function units and sold or used as independent products, can be stored in a computer readable storage medium. Based on such understanding, all or part of the processes in the above-mentioned embodiment methods can also be completed by a computer program instructing related hardware, and the computer program can be stored in a computer readable storage medium. The computer program can implement the steps of each method embodiment when executed by a processor. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or some intermediate forms, etc. The computer readable medium can include any entity or device, recording medium, U disk, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal, and software distribution medium, etc. that can carry the computer program code. It should be noted that the contents included in the computer readable medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction, for example, in some jurisdictions, according to legislation and patent practice, the computer readable medium does not include electrical carrier signals and telecommunication signals.

[0202] It should be noted that the above-described device embodiments are only schematic, and the units described as separate components can or can not be physically separated, and the components shown as units can or can not be physical units, that is, they can be located in one place, or distributed on multiple network units. Part or all of the modules can be selected according to actual needs to achieve the purpose of the embodiment. In addition, the connection relationship between the modules in the device embodiment provided by the present application indicates that there is a communication connection between them, which can be realized as one or more communication buses or signal lines. Those skilled in the art can understand and implement it without creative labor.

[0203] The above-described specific embodiments further illustrate the purpose, technical solutions and beneficial effects of the present application. It should be understood that the above-described specific embodiments are only for the specific embodiments of the present application and are not used to limit the protection scope of the present application. It is particularly pointed out that any modification, equivalent replacement, improvement, etc. made by those skilled in the art within the spirit and principles of the present application should be included in the protection scope of the present application.

Claims

1. A cloud platform-based detection report management method, characterized by The method comprises the following steps: Obtain user identity information, historical behavior records, device state data and environment perception data, and preprocess the user identity information, historical behavior records and device state data to obtain a unified initial data set; According to the historical behavior records in the initial data set, extract user access frequency and behavior pattern features to obtain behavior regularity indicators; According to the behavior regularity indicators, combined with the user identity information in the initial data set, perform weighted calculation to obtain a preliminary trust score value; According to the preliminary trust score value, combined with the device state data in the initial data set and the preliminary trust score value, perform risk assessment to obtain a comprehensive trust score; According to the comprehensive trust score, combined with the environment perception data, perform user environment change assessment to obtain a final trust score; According to the final trust score, combined with a preset rule base, extract a report access restriction range and a risk level, and perform permission level adjustment and visible content range setting to obtain a final permission configuration scheme. 2.The cloud platform-based detection report management method of claim 1, wherein, According to the historical behavior records in the initial data set, extract user access frequency and behavior pattern features to obtain behavior regularity indicators, including: Extract features from the historical behavior records in the initial data set to obtain user access frequency and initial behavior features; Perform time series segmentation analysis on the user access frequency and the initial behavior features to construct behavior distribution features in different time periods; Based on the behavior distribution features, analyze the access duration and peak interval of each time interval to calculate the behavior concentration; When the behavior concentration exceeds a preset behavior concentration threshold, the corresponding time interval is determined as a user active period; Perform clustering analysis on the access path preference and behavior repetition frequency in the active period to identify behavior pattern features and habit tendency results of the user in a specific period; Perform conditional matching analysis combined with the behavior pattern features and the habit tendency results to identify key behavior patterns to obtain behavior regularity indicators for trust assessment. 3.The cloud platform-based detection report management method of claim 1, wherein, According to the behavior regularity indicators, combined with the user identity information in the initial data set, perform weighted calculation to obtain a preliminary trust score value, including: Perform time interval refinement analysis on the behavior regularity indicators to construct behavior regularity feature values in different time periods; Compare the behavior regularity feature values with the user identity information in the initial data set to perform matching analysis of behavior features and role typical behavior intervals to obtain role behavior data consistent with the role expectations; According to the user identity information in the initial data set, combined with the role behavior data, perform weighted calculation to quantify the matching degree of behavior features and permission range to obtain a trust score base value; According to the trust score base value, combined with a preset trust score interval, perform interval determination to obtain a preliminary trust score value. 4.The cloud platform-based detection report management method of claim 1, wherein, According to the preliminary trust score value, combined with the device state data in the initial data set and the preliminary trust score value, perform risk assessment to obtain a comprehensive trust score, including: According to the preliminary trust score value, in combination with a security parameter in the device state data in the initial data set and network environment information, a risk factor identification and score adjustment operation is performed to obtain a comprehensive trust score; The risk factor identification and score adjustment operation includes: Based on the security parameter and a preset security threshold, a state comparison is performed to obtain device anomaly identification data; Based on the network environment information, a risk level judgment is performed to obtain network risk identification data; The device anomaly identification data and the network risk identification data are fused and processed, and a preset trust score adjustment rule is used to perform weighted correction on the preliminary trust score value to obtain score intermediate data; According to the score intermediate data and a preset score mapping table, an interval matching operation is performed to obtain a comprehensive trust score. 5.The cloud platform-based detection report management method of claim 1, wherein, According to the comprehensive trust score, in combination with the environment perception data, a user environment change evaluation is performed to obtain a final trust score, including: According to the physical location information and the timestamp information in the environment perception data, a geographic risk level identification is performed to obtain a location risk coefficient; According to the access point information in the environment perception data, a trusted network comparison is performed to obtain a network environment evaluation result; According to the behavior data and the historical behavior pattern in the environment perception data, a behavior deviation analysis is performed to obtain behavior anomaly identification data; According to the comprehensive trust score, in combination with the location risk coefficient, the network environment evaluation result and the behavior anomaly identification data, a dynamic score adjustment is performed to obtain a final trust score. 6.The cloud platform-based detection report management method of claim 1, wherein, According to the final trust score, in combination with a preset rule base, an access restriction range and a risk level are extracted, and a permission level adjustment and a visible content range setting are performed to obtain a final permission configuration scheme, including: According to the final trust score, in combination with a permission mapping table in the preset rule base, an access level identification is performed to obtain user permission level data; According to the user permission level data, in combination with a report access classification rule in the preset rule base, a report type screening is performed to obtain an accessible report type list; According to the accessible report type list, in combination with a field permission control table in the preset rule base, a field-level access permission matching is performed to obtain a field access permission mapping result; According to the field access permission mapping result, a report content reconstruction is performed to obtain a personalized detection report content; According to the final trust score, in combination with a permission level definition table in the preset rule base, a permission level adjustment operation is performed to obtain a permission level configuration result; According to the permission level configuration result and the personalized detection report content, a permission configuration integration is performed to obtain a final permission configuration scheme. 7.The cloud platform-based detection report management method of claim 6, wherein, According to the permission level configuration result and the personalized detection report content, a permission configuration integration is performed to obtain a final permission configuration scheme, including: According to the permission level configuration result, in combination with the field access permission mapping result in the personalized detection report content, an access control rule matching is performed to obtain field visibility configuration data; According to the field visibility configuration data, the operation permission definition in the permission level configuration result is combined to perform content presentation and operation boundary integration, and a final permission configuration scheme is obtained. 8.A cloud platform-based detection report management system, characterized in that, The method comprises the following steps: The data acquisition module is configured to acquire user identity information, historical behavior records, device state data, and environment perception data, and to perform heterogeneous data preprocessing on the user identity information, the historical behavior records, and the device state data to obtain a unified initial data set. The behavior analysis module is configured to extract user access frequency and behavior pattern features from the historical behavior records in the initial data set to obtain a behavior regularity index. The preliminary analysis module is configured to perform weighted calculation on the basis of the behavior regularity index and the user identity information in the initial data set to obtain a preliminary trust score value. The comprehensive analysis module is configured to perform risk assessment on the basis of the preliminary trust score value, the device state data in the initial data set, and the preliminary trust score value to obtain a comprehensive trust score. The final analysis module is configured to perform user environment change assessment on the basis of the comprehensive trust score and the environment perception data to obtain a final trust score. The scheme configuration module is configured to extract a report access restriction range and a risk level on the basis of the final trust score and a preset rule library, and to perform permission level adjustment and visible content range setting to obtain a final permission configuration scheme.

9. An electronic device, comprising: The computer readable storage medium comprises a stored computer program, wherein the computer program controls the device in which the computer readable storage medium is located to perform the cloud platform-based detection report management method according to any one of claims 1 to 7 when the computer program is running.

10. A computer-readable storage medium, characterized in that, The computer readable storage medium comprises a stored computer program, wherein the computer program controls the device in which the computer readable storage medium is located to perform the cloud platform-based detection report management method according to any one of claims 1 to 7 when the computer program is running.