Enabling decision assistance method, apparatus and device for data security control

CN121256830BActive Publication Date: 2026-04-17FOSHAN POLYTECHNIC
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
FOSHAN POLYTECHNIC
Filing Date
2025-12-03
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

Non-technical approval personnel often struggle to accurately assess the rationality and potential risks of access control requirements in enabling decisions regarding data security controls. This leads to strong subjectivity, inconsistent standards, and insufficient risk identification, impacting both production efficiency and data security.

Method used

A dual-model separation architecture is adopted. The first model generates decision evaluation criteria through historical case statistics, and the second model performs structured verification analysis on this basis to avoid emotional information interference and dynamically adjust the weight configuration to adapt to different types of industrial data security applications.

Benefits of technology

It enables objective and consistent decision-making in the face of strong emotions or misinformation, improves the accuracy of risk identification and the objectivity of assessment, avoids the problems of excessive tension or excessive strictness, and provides reliable decision-making advice.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121256830B_ABST
    Figure CN121256830B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of data processing for risk management, in particular to an enabling decision assistance method, device and equipment for data security control. The application provides a method comprising: acquiring multi-data source information of a data security enabling application, and constructing a standardized feature vector according to the multi-data source information; calling a first large model, retrieving a historical similar case based on the standardized feature vector, counting risk distribution characteristics in the similar case, and generating a decision evaluation standard according to the risk distribution characteristics; calling a second large model, taking the decision evaluation standard output by the first large model as a decision framework, and performing structured verification analysis on the multi-data source information, and outputting an enabling decision suggestion, so as to avoid the bias of the multi-data source information directly affecting the enabling decision suggestion. The application can more accurately assist non-technical approval personnel to make decisions on whether to enable data control authority.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of data processing technology for risk management, and more particularly to an enabling decision support method, apparatus, and device for data security control. Background Technology

[0002] In modern industrial information technology environments, enabling refers to granting specific users access, operation, and / or management rights to critical data and production control systems for a specific period of time. Enable approval for data security controls is a crucial aspect of enterprise information security management, involving the evaluation and decision-making regarding permission requests from external suppliers, technical service personnel, and temporary staff.

[0003] The main challenge lies in the fact that, although enterprises have established relatively comprehensive identity authentication and access control mechanisms at the technical level, the actual approval process is often handled by non-technical personnel in business or administrative departments. While these personnel possess management and business judgment abilities, their understanding of complex system architectures, cybersecurity risks, and data sensitivity is limited, making it difficult for them to accurately assess the rationality of access requests, the appropriateness of the application scope, and the controllability of potential risks.

[0004] This gap between capability and technological complexity can easily lead to problems such as strong subjectivity, inconsistent standards, and insufficient risk identification in enabling decisions. On the one hand, excessive caution may constrain reasonable business needs and affect production efficiency and supplier collaboration; on the other hand, insufficient judgment may allow applications with potential risks, threatening enterprise data security.

[0005] Therefore, there is a need to propose a method and device to assist non-technical approvers in making enabling decisions regarding data security control, so that they can make more accurate decisions on whether to enable or disable data control permissions and achieve data security control. Summary of the Invention

[0006] To address, or at least partially address, the aforementioned technical problems, this application provides an enabling decision support method and apparatus for data security control, which can more accurately assist non-technical approval personnel in making decisions regarding whether or not to enable data control permissions.

[0007] In a first aspect, this application provides an enabling decision support method for data security control, the enabling decision support method for data security control comprising the following steps:

[0008] Obtain information from multiple data sources for the data security enablement application, and construct a standardized feature vector based on the information from the multiple data sources;

[0009] The first major model is invoked to retrieve historical similar cases based on the standardized feature vector, statistical risk distribution characteristics in similar cases are analyzed, and decision evaluation criteria are generated based on the risk distribution characteristics.

[0010] The second major model is invoked, and the decision evaluation criteria output by the first major model are used as the decision framework to perform structured verification analysis on the information from the multiple data sources, and output enabling decision recommendations, thereby avoiding the direct influence of information from multiple data sources on the preferences of enabling decision recommendations.

[0011] Optionally, the process of calling the first major model, retrieving historical similar cases based on the standardized feature vectors, statistically analyzing the risk distribution characteristics of the similar cases, and generating decision evaluation criteria based on the risk distribution characteristics includes the following steps:

[0012] The first major model matches the standardized feature vector with the historical case vector database to obtain the historical cases with the highest similarity based on a preset statistical number.

[0013] Extract approval results and subsequent event records from the historical cases, and statistically analyze the approval rate, problem occurrence rate, and problem type distribution.

[0014] Based on statistical results, the risk differentiation capabilities of four risk dimensions—identity verification, access control, time limits, and business assessment—in similar historical cases are analyzed, and the risk differentiation capabilities are normalized to form a dynamic weight configuration.

[0015] The output includes the decision evaluation criteria with the dynamic weight configuration as the verification criteria for each risk dimension, which is used to guide the structured verification analysis of the second major model.

[0016] Optionally, the process of calling the first major model to generate decision evaluation criteria also includes the following steps:

[0017] Perform cross-data source conflict detection on the information from the multiple data sources and calculate the conflict intensity between information from different data sources;

[0018] The dynamic weight configuration is adjusted based on the conflict intensity, wherein the degree of conflict is positively correlated with the weight adjustment magnitude of the corresponding risk dimension;

[0019] The output includes the decision evaluation criteria of the dynamic weight configuration as the verification criteria for each risk dimension, which is used to guide the structured verification analysis of the second major model. This includes: the output of the first major model includes the decision evaluation criteria of the adjusted dynamic weight configuration, which is used to guide the second major model to perform structured verification analysis based on the adjusted weight configuration.

[0020] Optionally, the process of performing cross-data source conflict detection on the multi-data source information and calculating the conflict intensity between different data source information includes the following steps:

[0021] Execution time consistency verification: Compare the fault start time recorded in the monitoring system data with the time point described by the applicant in the application form data, as well as the logical relationship between the application submission time and the claimed urgency level, in order to analyze the intensity of the time conflict;

[0022] Perform consistency verification of phenomenon description: compare the correspondence between the fault phenomenon described by the applicant in the application form and the abnormal event in the monitoring system data, as well as the matching degree between the description of the scope of impact and the actual monitored equipment scope, in order to analyze the intensity of phenomenon conflict;

[0023] Execution permission request rationality verification: Analyze the matching degree between the permission request scope in the application form and the fault impact scope displayed by the monitoring system data, determine the minimum necessary permission scope based on fault location, and analyze the permission conflict intensity.

[0024] Optionally, the process of adjusting the dynamic weight configuration based on the conflict intensity includes the following steps:

[0025] Calculate the total conflict intensity value based on the time conflict intensity, phenomenon conflict intensity, and permission conflict intensity;

[0026] Calculate the proportion of each conflict dimension in the total value of conflict intensity;

[0027] The weight adjustment range is determined based on the sum of the conflict intensities, and the weights of the corresponding risk dimensions in the dynamic weight configuration are adjusted according to the weight adjustment range and the proportion of each conflict dimension.

[0028] The adjusted weights are normalized to ensure that the sum of the weights is 1.

[0029] Optionally, the first major model matches the standardized feature vector with a historical case vector database to obtain a preset number of historical cases with the highest similarity, including the following steps:

[0030] The standardized feature vector is compared with the standardized feature vector of historical cases stored in the historical case vector database to calculate the similarity and obtain the database search identifier corresponding to the historical case with the highest preset statistical number of similarities.

[0031] Based on the database lookup identifier, retrieve the corresponding historical case details from the independently stored case database, including approval results, subsequent event records, and issue classification information;

[0032] The historical case vector database stores the standardized feature vector representations and corresponding identifiers of historical cases, while the case database stores the detailed content of historical cases. This separate storage of the two prevents the detailed case content from directly affecting the feature matching process.

[0033] Optionally, the second major model uses the decision evaluation criteria output by the first major model as a decision framework to perform structured verification analysis on the information from the multiple data sources, specifically including:

[0034] A differentiated verification process is executed based on the adjusted dynamic weight configuration, and verification strategies of different depths are adopted for different risk dimensions according to the weight.

[0035] Among them, the high-weight dimension executes the preset comprehensive verification strategy, the medium-weight dimension executes the preset key verification strategy, and the low-weight dimension executes the preset basic verification strategy.

[0036] Output natural language-enabled decision-making suggestions for non-technical managers, including verification results of various dimensions, overall compliance, approval decision types, and implementation requirements.

[0037] Secondly, this application provides an enabling decision support device for data security control, the device comprising at least one module for executing any of the enabling decision support methods for data security control described in the first aspect.

[0038] Thirdly, this application provides a computer device including a processor for executing a computer program stored in a memory to implement the enabling decision support method for data security control as described in any of the first aspects.

[0039] The technical solution provided in this application has the following advantages compared with the prior art:

[0040] One of its beneficial effects and its working principle is as follows:

[0041] When managers process multimodal raw data containing strong emotional elements, such as monitoring system ERROR logs and applicants' urgent statements, they are easily influenced by emotional information, leading to biased judgments. When faced with a large number of abnormal error messages, they may assume the situation is indeed urgent and tend to recommend approval. When the application text is strongly emotionally expressed, emotional descriptions can impair their ability to conduct objective analysis. This phenomenon results in a lack of consistency and objectivity in approval decisions.

[0042] Similarly, when large models targeting human preferences are directly exposed to this emotionally charged multimodal data, similar judgment biases will occur. When faced with a dense number of error logs or requests with intense emotional language, large models are easily misled by the intensity of this emotion, thus making decisions that are not objective enough.

[0043] This application addresses this issue by designing a dual-model separation architecture. The first major model obtains decision-making evaluation criteria through cleaned historical case statistics, avoiding potentially emotional expressions in current applications. The second major model analyzes current application materials under the guidance of these objective criteria. Because of the rational decision-making framework, it maintains objectivity even when faced with emotionally charged application content. The two models work together: one ensures the objectivity of the criteria, and the other ensures the comprehensiveness of the analysis, preventing the undue influence of emotional information from multimodal data on the final decision.

[0044] This separation architecture enables consistent objectivity in approval decisions across various circumstances. Regardless of the number of error messages reported by the monitoring system or the urgency of the applicant's description, the proposed method makes rational judgments without being swayed by superficial emotional intensity.

[0045] Therefore, it avoids both the problem of relaxing review standards due to excessive tension and the problem of being overly strict due to emotional resistance, allowing managers without technical backgrounds to obtain objective, consistent, and reliable decision-making advice.

[0046] Therefore, the enabling decision support method for data security control proposed in this application can more accurately assist non-technical approvers in making decisions on whether or not to enable data control permissions.

[0047] Its second beneficial effect and its working principle are as follows:

[0048] Different types of industrial data security applications have exhibited varying risk distributions in historical practice. Some types of applications are prone to identity verification issues, such as incomplete or expired identification documents from external suppliers, while others are susceptible to privilege abuse, such as maintenance personnel gaining access to sensitive data beyond their scope of maintenance. Traditional approval systems employ fixed evaluation criteria and cannot be adjusted based on this historical experience.

[0049] This application converts multi-data source information from the current application into standardized feature vectors and uses similarity calculations to find a set of similar cases in a historical case database. Statistical analysis is performed on these similar cases to calculate the frequency of occurrence and risk differentiation capabilities of each risk dimension in historical cases. If 40% of the retrieved similar cases involve privilege abuse while authentication issues only account for 15%, the system will increase the weight of the privilege control dimension and decrease the weight of the authentication dimension. This dynamic weight adjustment mechanism allows each assessment to utilize risk distribution patterns from historical experience.

[0050] This weighting adjustment based on historical experience improves the accuracy of the assessment. Different types of applications receive assessment criteria that align with their historical risk characteristics, avoiding the problems associated with uniform standards. More attention is paid to risk points that have historically caused problems, while processes are appropriately simplified for areas that have performed well historically. This improves the accuracy of risk identification and avoids unnecessary approval delays.

[0051] Its third beneficial effect and its working principle are as follows:

[0052] Data security applications in industrial environments involve multiple independent data sources, including forms filled out by the applicant, automatically monitored data from the system, uploaded attachments, and business-related information. When an applicant attempts to provide false information or exaggerate the severity of a problem, logical conflicts at the factual level can arise between these different data sources.

[0053] For example, an applicant may claim that the equipment malfunctioned from a certain point in time, but monitoring system records show that the equipment operated normally during that period. Or, the applicant may describe needing full system administrator privileges, but actual monitoring data shows that the problem is concentrated in only a few modules. Traditional approval systems lack the ability to detect conflicts across data sources and cannot identify such inconsistencies.

[0054] This application employs three dimensions for cross-data source factual conflict detection: time consistency verification, phenomenon description consistency verification, and permission request rationality verification. For example, it compares the fault start time recorded by the monitoring system with the time point described by the applicant, analyzes the correspondence between the fault phenomena described by the applicant and abnormal events in the monitoring logs, and assesses the matching degree between the requested permission scope and the actual impact scope of the fault. By identifying these conflicts, the intensity of the conflicts is quantified, a comprehensive conflict index is calculated, and the sensitivity weight of the risk assessment is dynamically adjusted according to the degree of conflict. The higher the degree of conflict, the greater the increase in the weight of key risk dimensions, thus making the risk assessment more sensitive.

[0055] This multi-data source cross-validation mechanism improves the ability to identify fraudulent applications. By cross-validating data from multiple sources, it avoids being deceived by a single data source. Furthermore, by adjusting the level of approval rigor based on the degree of conflict, it ensures security while avoiding hindering legitimate applications.

[0056] Therefore, the enabling decision support method for data security control proposed in this application can more accurately assist non-technical approvers in making decisions on whether or not to enable data control permissions. Attached Figure Description

[0057] Figure 1 A schematic diagram illustrating an application scenario for the enabling decision-making method for data security control provided in this application embodiment;

[0058] Figure 2One of the flowcharts for an enabling decision method for data security control provided in an embodiment of this application;

[0059] Figure 3 A second flowchart of an enabling decision method for data security control provided in an embodiment of this application;

[0060] Figure 4 The third flowchart of the enabling decision method for data security control provided in the embodiments of this application. Detailed Implementation

[0061] The technical solutions in this application will now be described with reference to the accompanying drawings.

[0062] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the implementation methods of this application will be further described in detail below with reference to the accompanying drawings.

[0063] Before providing a detailed explanation of the embodiments of this application, let's first introduce the application scenarios involved in the embodiments of this application.

[0064] Figure 1 This is a schematic diagram illustrating an application scenario for the enabling decision-making method for data security control provided in an embodiment of this application. For example... Figure 1 As shown, the person requesting data control permissions submits a data security enable application to the non-technical approver, who then approves the application and provides feedback through the enable decision support device.

[0065] The decision-making assistance device, according to the following embodiment, first calls a first major model (configurable in a cloud server) to retrieve historical similar cases based on standardized feature vectors and generate decision evaluation criteria. Then, it calls a second major model (configurable in a cloud server) to perform structured verification analysis of information from multiple data sources using the decision evaluation criteria as a framework. Based on the analysis results, the decision-making assistance device outputs natural language enabling decision suggestions for non-technical approval personnel, assisting them in deciding whether or not to enable data control permissions. The first and second major models described in this embodiment can be implemented using existing general-purpose large language models, such as the "Wenxin Yiyan" and "Tongyi Qianwen" series of large language models.

[0066] The enabling decision support method for data security control provided in this application embodiment can be executed by an enabling decision support device for data security control. The device includes at least one module, which is used to execute the enabling decision support method for data security control described in the following embodiments.

[0067] Figure 2 This is one of the flowcharts for an enabling decision method for data security control provided in an embodiment of this application. (Refer to...) Figure 2 As shown, the enabling decision support method for data security includes the following steps:

[0068] S201: Obtain multi-source data information of the data security enable application, and construct a standardized feature vector based on the multi-source data information.

[0069] Specifically, in this embodiment of the application, the multi-source data includes application form data, system backend data, monitoring system data, uploaded attachment data, and business-related data.

[0070] For example, in this embodiment of the application, the application form data includes basic information filled in by the applicant, including applicant type, permission level, access method, application purpose, textual description of the reason for the application, urgency level, and estimated processing time.

[0071] The system's backend data includes applicant history, credit rating, application time, network environment information, and department status information, which are automatically obtained from the system.

[0072] The monitoring system data includes monitoring logs, event statistics, device status snapshots, and fault distribution statistics of related devices that are automatically associated with the system.

[0073] The uploaded attachments include screenshots of the fault symptoms, explanatory documents, and metadata information provided by the applicant.

[0074] Business-related data includes impact analysis automatically associated by the system, production status information, and relevant personnel information.

[0075] The process of constructing a 35-dimensional standardized feature vector based on the information from the multiple data sources includes:

[0076] Extract the applicant type code (3D one-hot vector), permission level code (4D one-hot vector), access method code (3D one-hot vector), and expected processing time from the application form data, and then perform log-normalized data (1D).

[0077] Extract the application time code (3-dimensional one-hot vector), the normalized values ​​of historical application frequency and credit rating (1-dimensional each), and the department status code (3-dimensional) from the system backend data.

[0078] Extract data sensitivity level (1-dimensional), business relevance calculation value (1-dimensional), and department affiliation code (5-dimensional one-hot vector) from the data associated with the business system.

[0079] Extract normalized values ​​(3 dimensions each) of fault severity, equipment impact range, and system stability from the monitoring system data.

[0080] The above-mentioned features are combined to form a 35-dimensional standardized feature vector.

[0081] S202: Call the first major model, retrieve historical similar cases based on the standardized feature vector, statistically analyze the risk distribution characteristics of similar cases, and generate decision evaluation criteria based on the risk distribution characteristics.

[0082] Figure 3 This is a second flowchart of an enabling decision method for data security control provided in an embodiment of this application. See also... Figure 3 As shown, specifically, the process of calling the first major model, retrieving historical similar cases based on the standardized feature vector, statistically analyzing the risk distribution characteristics of similar cases, and generating decision evaluation criteria based on the risk distribution characteristics includes the following steps:

[0083] S301: The first major model matches the standardized feature vector with the historical case vector database to obtain the historical cases with the highest similarity based on a preset statistical number.

[0084] Figure 4 This is the third flowchart of an enabling decision method for data security control provided in an embodiment of this application. See also... Figure 4 As shown, the first major model matches the standardized feature vector with the historical case vector database to obtain the historical cases with the highest similarity based on a preset statistical number of data points. This process includes the following steps:

[0085] S401: Calculate the similarity between the standardized feature vector and the standardized feature vector of historical cases stored in the historical case vector database, and obtain the database search identifier corresponding to the historical case with the highest preset statistical number of similarities.

[0086] Specifically, in this embodiment of the application, the historical case vector database is constructed as a knowledge base, and the first major model calls the RAG retrieval tool through MCP (Model Context Protocol) to perform retrieval.

[0087] This knowledge base stores 35-dimensional standardized feature vectors converted from multiple historical approval cases, with each vector corresponding to a unique database lookup identifier. When the first main model receives the standardized feature vector of the current application, it performs a search and matching within the knowledge base.

[0088] The similarity calculation employs a cosine similarity algorithm, calculating the cosine similarity between the 35-dimensional standardized feature vector of the current application and the feature vector of each historical case in the knowledge base. The RAG system sorts the similarities of all historical cases and selects a preset statistical number of historical cases with the highest similarity. For example, in this embodiment, the preset statistical number is 10, so the 10 historical cases with the highest similarity are selected, and a list of database lookup identifiers corresponding to these highly similar historical cases is returned.

[0089] S402: Retrieve detailed historical case data from the independently stored case database based on the database lookup identifier, including approval results, subsequent event records, and issue classification information.

[0090] Specifically, in this embodiment of the application, the first major model calls the database retrieval tool through MCP and uses the database search identifier list returned by the RAG retrieval tool in step S401 to retrieve the corresponding historical case details from the independently stored case database.

[0091] The case database stores detailed data including complete application information, approval process records, final approval results (approved, rejected, or conditionally approved), actual implementation status after approval, and subsequent event records (such as abuse of power, time constraints, or security incidents). It also includes issue classification information, categorizing subsequently discovered issues into types such as authentication issues, access control issues, time constraint issues, and business assessment issues. In this way, complete information on historical cases most similar to the current application is obtained for subsequent statistical analysis.

[0092] The historical case vector database, serving as the RAG knowledge base, stores standardized feature vector representations and corresponding identifiers of historical cases. The case database stores the detailed content of historical cases. This separation of storage prevents detailed case content from directly influencing the RAG retrieval process. This separate storage design ensures the objectivity of the RAG feature retrieval process and avoids interference from potentially sentimental descriptions within historical cases that could affect similarity calculations.

[0093] S302: Extract approval results and subsequent event records from the historical cases with the highest preset statistical quantity of similarity, and statistically analyze the approval pass rate, problem occurrence rate and problem type distribution; based on the statistical results, analyze the risk differentiation ability of the four risk dimensions of identity verification, access control, time limit and business assessment in similar historical cases, and normalize the risk differentiation ability to form a dynamic weight configuration.

[0094] Specifically, after receiving detailed data on the 10 most similar historical cases obtained in step S301, the first major model uses MCP to call statistical analysis tools to analyze these cases. This involves extracting subsequent issue records for each historical case and classifying and statistically analyzing the issues according to four risk dimensions: identity verification, access control, time limits, and business assessment. For example, in the 10 similar cases, an identity verification issue occurred once, an access control issue occurred four times, a time limit issue occurred twice, and a business assessment issue occurred once.

[0095] Subsequently, the first major model uses MCP to call a weight calculation tool to calculate dynamic weights based on the frequency of occurrence of issues in each dimension. The principle of weight calculation is that dimensions with higher issue frequency are considered to have greater risk among similar application types and should be assigned higher weights for focused attention. Therefore, in this embodiment, the weight calculation tool normalizes the issue frequency of each dimension: identity verification weight = 1 / 8 = 0.125, access control weight = 4 / 8 = 0.5, time restriction weight = 2 / 8 = 0.25, and business assessment weight = 1 / 8 = 0.125, to form a dynamic weight configuration for each risk dimension.

[0096] S303: Perform cross-data source conflict detection on the multi-data source information and calculate the conflict intensity between different data source information.

[0097] Specifically, it includes the following steps:

[0098] Execution time consistency verification: Compare the fault start time recorded in the monitoring system data with the time point described by the applicant in the application form data, as well as the logical relationship between the application submission time and the claimed urgency level, in order to analyze the intensity of the time conflict.

[0099] Perform consistency verification of phenomenon descriptions: compare the correspondence between the fault phenomena described by the applicant in the application form and the abnormal events in the monitoring system data, as well as the degree of matching between the description of the scope of impact and the actual monitored equipment scope, in order to analyze the intensity of phenomenon conflicts.

[0100] Execution permission request rationality verification: Analyze the matching degree between the permission request scope in the application form and the fault impact scope displayed by the monitoring system data, determine the minimum necessary permission scope based on fault location, and analyze the permission conflict intensity.

[0101] Specifically, in this embodiment of the application, after receiving information from multiple data sources, the first major model performs cross-data source conflict detection according to the following task prompt examples:

[0102] One of the prompt word templates:

[0103] Role Definition: You are a professional industrial data security approval analyst with extensive experience in verifying information from multiple data sources, and you are skilled at identifying logical conflicts and factual inconsistencies between different data sources.

[0104] Analysis dimensions:

[0105] Time Consistency Verification: Compare the application description time with the monitoring record time to analyze the logical rationality of the application delay and urgency. Scoring Criteria: Small time difference with logical rationality is scored from 0 to 0.3; slight contradiction is scored from 0.3 to 0.6; obvious contradiction is scored from 0.6 to 1.0.

[0106] Phenomenon Description Consistency Verification: Compare the degree of matching between the application description and the monitoring records to analyze the consistency of the scope of the fault's impact. Scoring Criteria: High match is 0 to 0.3, basic match with differences is 0.3 to 0.6, and obvious discrepancy is 0.6 to 1.0.

[0107] Permission request rationality verification: Analyze the matching degree between the requested permission scope and the actual impact scope of the fault, and deduce the minimum necessary permissions. Scoring criteria: 0 to 0.3 for meeting the minimum necessary principle, 0.3 to 0.6 for slightly exceeding the actual requirement, and 0.6 to 1.0 for obviously excessive requests.

[0108] Output format:

[0109] {

[0110] Time conflict intensity: Value from 0 to 1;

[0111] Conflict intensity: Value from 0 to 1;

[0112] Permission conflict intensity: Values ​​from 0 to 1;

[0113] }

[0114] Specifically, when performing the three types of verifications mentioned above, the first large model does not rely on preset fixed thresholds or hard-coded rules. Instead, it leverages the semantic understanding, logical reasoning, domain knowledge, and common sense learned from massive amounts of text during the training phase to autonomously synthesize information from multiple data sources (i.e., using the large model's own fuzzy reasoning ability to analyze and obtain results). Essentially, the actual function of the task prompts is to provide semantic guidance and guiding scoring ranges as a framework, helping the first large model map the qualitative judgment derived from reasoning into a quantified conflict intensity value. The specific value is determined autonomously by the first large model based on its semantic understanding of the conflict level.

[0115] In terms of time consistency verification, the essence is similar to the logical judgment made by a professional engineer: that is, comparing the time recorded in the device monitoring logs in the monitoring system data with the time mentioned in the text description of the application reason in the application form data, and analyzing the time deviation between the two. At the same time, it analyzes the logical consistency between the application time and the urgency claimed in the application form to determine whether the application delay is consistent with the stated urgency.

[0116] Similarly, in terms of verifying the consistency of phenomenon descriptions, the essence is to compare the fault phenomenon described in the textual description of the application reason in the application form with the monitoring log records in the monitoring system data, analyzing the semantic consistency between the two in terms of fault type and severity. At the same time, it compares the degree of matching between the impact scope described in the application reason and the impact scope analysis in the business-related data. This determines the degree to which the phenomenon description matches the actual phenomenon.

[0117] Similarly, in verifying the rationality of permission requests, the essence is to deduce the minimum necessary permissions required to complete the fault handling based on the fault distribution statistics in the monitoring system data and the impact range analysis in the business-related data. The permission levels and access methods in the application form data are then compared with the deduced minimum necessary permissions to determine whether the requested permissions exceed the necessary scope.

[0118] S304: Adjust the dynamic weight configuration based on the conflict intensity, wherein the degree of conflict is positively correlated with the weight adjustment range of the corresponding risk dimension.

[0119] Calculate the total conflict intensity value based on the time conflict intensity, phenomenon conflict intensity, and permission conflict intensity;

[0120] Calculate the proportion of each conflict dimension in the total value of conflict intensity;

[0121] The weight adjustment range is determined based on the sum of the conflict intensities, and the weights of the corresponding risk dimensions in the dynamic weight configuration are adjusted according to the weight adjustment range and the proportion of each conflict dimension.

[0122] The adjusted weights are normalized to ensure that the sum of the weights is 1.

[0123] Specifically, after receiving the conflict intensity of each dimension from step S303, the first major model adjusts the weights according to the following calculation process:

[0124] The first major model calculates the sum of conflict intensities by directly summing the intensity of time-related conflicts, the intensity of phenomena-related conflicts, and the intensity of authority-related conflicts.

[0125] For example, assuming that the time conflict intensity output by step S303 is 0.1, the phenomenon conflict intensity is 0.05, and the permission conflict intensity is 0.8, the total conflict intensity calculated by the first major model is: Total Conflict = 0.1 + 0.05 + 0.8 = 0.95.

[0126] The first major model calculates the proportion of each conflict dimension in the total conflict intensity.

[0127] Based on the above example, the proportion of time conflicts = 0.1 ÷ 0.95 = 0.105, the proportion of phenomenon conflicts = 0.05 ÷ 0.95 = 0.053, and the proportion of permission conflicts = 0.8 ÷ 0.95 = 0.842.

[0128] The first major model determines the weight adjustment range based on the sum of the conflict intensities.

[0129] In this embodiment of the application, the adjustment strategy is as follows:

[0130] When the total conflict value is less than 1, the weight adjustment is 5%;

[0131] When the total conflict value is between 1 and 2, the weight adjustment is 10%.

[0132] When the total number of conflicts is greater than 2, the weight adjustment is 15%.

[0133] The numerical setting of the weight adjustment range is based on experience and can be fine-tuned by technical personnel according to the actual situation.

[0134] Based on the above example, the total conflict value is 0.95, which is less than 1, so the weight adjustment range is determined to be 5%.

[0135] The first major model adjusts the weights of the corresponding risk dimensions in the dynamic weight configuration based on the weight adjustment magnitude and the proportion of each conflict dimension.

[0136] The adjustment formula is: Adjusted weight = Original weight × (1 + Conflict percentage × Weight adjustment range).

[0137] After weight adjustment, normalization is performed so that the adjusted weight sum is 1.

[0138] S305: The first major model output includes decision evaluation criteria with adjusted dynamic weight configuration, which guides the second major model to perform structured verification analysis based on the adjusted weight configuration.

[0139] Specifically, after the first major model completes the weight adjustment and normalization process, it outputs the final dynamic weight configuration as the decision evaluation standard.

[0140] S203: Call the second major model, use the decision evaluation criteria output by the first major model as the decision framework, perform structured verification analysis on the information from the multiple data sources, and output enabling decision recommendations, thereby avoiding the direct influence of information from multiple data sources on the preferences of enabling decision recommendations.

[0141] Specifically, the following steps are included:

[0142] A differentiated verification process is executed based on the adjusted dynamic weight configuration, and verification strategies of different depths are adopted for different risk dimensions according to the weight.

[0143] Among them, the high-weight dimension executes the preset comprehensive verification strategy, the medium-weight dimension executes the preset key verification strategy, and the low-weight dimension executes the preset basic verification strategy.

[0144] Output natural language-enabled decision-making suggestions for non-technical managers, including verification results of various dimensions, overall compliance, approval decision types, and implementation requirements.

[0145] Specifically, after receiving the decision evaluation criteria output by the first model and the multi-data source information of the current application, the second model performs structured verification analysis according to the following task prompts:

[0146] Prompt template two:

[0147] Role Definition: A professional data security approval and verification specialist who conducts comprehensive verification and analysis of applications based on objective decision-making and evaluation standards.

[0148] Verification Strategy: Verification of high-weight dimensions (i.e., verification of all relevant information and their corresponding relationships): Perform comprehensive verification on risk dimensions with a weight greater than 0.4, and verify in detail the information from multiple data sources related to this dimension, including application form data, system backend data, monitoring system data, uploaded attachment data, and business-related data, to ensure that all relevant information is complete and reliable.

[0149] Verification criteria: If the information is complete and credible, the verification conclusion is "compliant"; if the information is basically complete but there are doubts when corroborating each other, the verification conclusion is "partially compliant"; if the information is incomplete or there are obvious problems when corroborating each other, the verification conclusion is "non-compliant". The specific judgment is made independently by you based on semantic understanding and logical reasoning.

[0150] Verification of medium-weighted dimensions (i.e., verification of the main judgment criteria): Focus on verifying the risk dimensions with weights of 0.2 to 0.4, paying attention to the key information and main risk points of this dimension, and ensuring the credibility of the main judgment basis.

[0151] Verification criteria: If the key information passes verification, the verification conclusion is "compliant"; if the key information is basically credible but needs to be supplemented, the verification conclusion is "partially compliant"; if the key information is questionable or missing, the verification conclusion is "non-compliant". The specific judgment is made independently by you based on semantic understanding and logical reasoning.

[0152] Verification of low-weight dimensions (i.e., verification of necessary information is sufficient): Perform basic verification on risk dimensions with a weight of less than 0.2 to confirm that the necessary information for that dimension has been provided.

[0153] Verification criteria: If the necessary information is clear, the verification conclusion is "compliant"; if the necessary information is vague but acceptable, the verification conclusion is "partially compliant"; if the necessary information is missing or incorrect, the verification conclusion is "non-compliant". The specific judgment is made independently by you based on semantic understanding and logical reasoning.

[0154] Output format:

[0155] {

[0156] Verification results for each dimension: Verification conclusions for each of the above weighted dimensions, sorted by weight priority;

[0157] Overall compliance: Values ​​from 0 to 1;

[0158] Approval decision types: Approval / Conditional Approval / Rejection;

[0159] Implementation requirements: Specific implementation conditions and monitoring measures;

[0160] }

[0161] Specifically, when performing the aforementioned verification analysis, the second model does not rely on pre-set fixed rules or hard-coded judgment criteria. Instead, it leverages the semantic understanding, logical reasoning, domain knowledge, and common sense learned from massive amounts of text during the training phase to autonomously synthesize information from multiple data sources (i.e., using the large model's own fuzzy reasoning capabilities to analyze and obtain results). Essentially, the task prompts serve as a framework for the verification strategy and guiding judgment criteria, helping the second model perform structured verification and provide decision-making suggestions. The specific judgments are autonomously made by the second model based on its semantic understanding of the information's credibility.

[0162] The essential goal is to improve verification efficiency by using prompts to guide the development of differentiated verification strategies.

[0163] The comprehensive verification approach is to verify the authenticity of all information, which means to conduct detailed cross-validation of information from multiple data sources related to the risk dimension to ensure that all relevant information is complete and reliable.

[0164] Taking identity verification as an example, the information that needs to be verified includes: the applicant type and application purpose in the application form data, the applicant's historical records and credit rating in the system backend data, supporting documents in the uploaded attachment data, and relevant personnel information in the business-related data. The second major model cross-validates the completeness and consistency of this information.

[0165] Taking access control as an example, the information that needs to be verified includes: the permission level, access method, and application reason in the application form data; the applicant's historical records in the system backend data; the fault distribution statistics in the monitoring system data; and the impact scope analysis in the business-related data. The second major model cross-validates the match between the application permission scope and actual needs.

[0166] Taking the time constraint dimension as an example, the information that needs to be verified includes: the urgency level and estimated processing time in the application form data, the application time in the system backend data, and the device monitoring logs and event statistics in the monitoring system data. The second major model cross-validates the logical consistency between the fault occurrence time, application submission time, and urgency level.

[0167] Taking the business evaluation dimension as an example, the information that needs to be verified includes: the application purpose and reasons in the application form data, the equipment status snapshots and fault distribution statistics in the monitoring system data, and the impact scope analysis and production status information in the business-related data. The second major model cross-validates the rationality of the application purpose and the actual business status.

[0168] The key verification approach is to verify the authenticity of the main judgment criteria, that is, to verify the key information of this risk dimension and ensure that the main judgment basis is credible.

[0169] Taking access control as an example, the key information that needs to be verified includes: the permission level and access method in the application form data, and the impact scope analysis in the business-related data. The goal of the second major model is to determine the match between permission requests and business requirements.

[0170] Taking identity verification as an example, the key information that needs to be verified includes: the applicant type in the application form data and the credit rating in the system backend data. The goal of the second major model is to determine the credibility of the applicant's identity.

[0171] Taking the time constraint dimension as an example, the key information that needs to be verified includes: the urgency level in the application form data, the application time in the system backend data, and the device monitoring logs in the monitoring system data. The goal of the second major model is to determine the logical consistency between application timeliness and urgency level.

[0172] Taking business evaluation as an example, the key information that needs to be verified includes: the application purpose in the application form data and the production status information in the business-related data. The goal of the second major model is to determine the rationality of the application purpose and the current business status.

[0173] The basic verification approach is to verify the existence of information, that is, to confirm the necessary information for the risk dimension and ensure that the basic information has been provided.

[0174] Taking time constraints as an example, the necessary information to confirm includes: the expected processing time and urgency level in the application form data.

[0175] Taking identity verification as an example, the necessary information to be confirmed includes: the applicant type in the application form data.

[0176] Taking access control as an example, the necessary information to confirm includes: the permission level in the application form data.

[0177] Taking business evaluation as an example, the necessary information to be confirmed includes: the purpose of the application in the application form data.

[0178] The goal of the second major model is to confirm that the basic information has been filled in and is within a reasonable range.

[0179] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer instructions. When the computer instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device such as a server or data center that integrates one or more available media. The available media can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., digital versatile discs (DVDs)), or semiconductor media (e.g., solid-state disks (SSDs)).

[0180] In the various embodiments of this application, unless otherwise specified or logically conflicting, the terminology and / or descriptions between different embodiments are consistent and can be referenced mutually. Technical features in different embodiments can be combined to form new embodiments based on their inherent logical relationships. In the embodiments of this application, "at least one" refers to one or more, and "more than one" refers to two or more. "And / or" describes the association relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone, where A and B can be singular or plural. In the textual description of the embodiments of this application, the character " / " generally indicates that the preceding and following related objects have an "or" relationship. In this application, "first," "second," and various numerical designations are only for ease of description and are not used to limit the scope of the embodiments of this application. For example, they are used to distinguish different messages, rather than to describe a specific order or sequence.

[0181] It is understood that the various numerical designations used in the embodiments of this application are merely for descriptive convenience and are not intended to limit the scope of the embodiments of this application. The order of the process numbers does not imply the order of execution; the execution order of each process should be determined by its function and internal logic.

[0182] Finally, it should be noted that the above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any changes or substitutions within the technical scope disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. An enabling decision assistance method for data security control, characterized in that, The enabling decision support method for data security control includes the following steps: Obtain information from multiple data sources for the data security enablement application, and construct a standardized feature vector based on the information from the multiple data sources; The first major model is invoked to retrieve historical similar cases based on the standardized feature vector, statistical risk distribution characteristics in similar cases are analyzed, and decision evaluation criteria are generated based on the risk distribution characteristics. The second major model is invoked, and the decision evaluation criteria output by the first major model are used as the decision framework to perform structured verification analysis on the information from the multiple data sources, and output enabling decision suggestions, thereby avoiding the direct influence of information from multiple data sources on the preferences of enabling decision suggestions; The process of calling the first major model, retrieving historical similar cases based on the standardized feature vectors, statistically analyzing the risk distribution characteristics of similar cases, and generating decision evaluation criteria based on the risk distribution characteristics includes the following steps: The first major model matches the standardized feature vector with the historical case vector database to obtain the historical cases with the highest similarity based on a preset statistical number. Extract approval results and subsequent event records from the historical cases, and statistically analyze the approval rate, problem occurrence rate, and problem type distribution. Based on statistical results, the risk differentiation capabilities of four risk dimensions—identity verification, access control, time limit, and business assessment—in similar historical cases are analyzed, and the risk differentiation capabilities are normalized to form a dynamic weight configuration. The output includes the decision evaluation criteria with the dynamic weight configuration as the verification criteria for each risk dimension, which is used to guide the structured verification analysis of the second major model.

2. The enablement decision assistance method for data security control according to claim 1, characterized in that, The process of using the primary model to generate decision evaluation criteria also includes the following steps: Perform cross-data source conflict detection on the information from the multiple data sources and calculate the conflict intensity between information from different data sources; The dynamic weight configuration is adjusted based on the conflict intensity, wherein the degree of conflict is positively correlated with the weight adjustment magnitude of the corresponding risk dimension; The output includes the decision evaluation criteria of the dynamic weight configuration as the verification criteria for each risk dimension, which is used to guide the structured verification analysis of the second major model. This includes: the output of the first major model includes the decision evaluation criteria of the adjusted dynamic weight configuration, which is used to guide the second major model to perform structured verification analysis based on the adjusted weight configuration.

3. The enabling decision support method for data security control according to claim 2, characterized in that, The process of performing cross-data source conflict detection on the information from multiple data sources and calculating the conflict intensity between different data sources includes the following steps: Execution time consistency verification: Compare the fault start time recorded in the monitoring system data with the time point described by the applicant in the application form data, as well as the logical relationship between the application submission time and the claimed urgency level, in order to analyze the intensity of the time conflict; Perform consistency verification of phenomenon description: compare the correspondence between the fault phenomenon described by the applicant in the application form and the abnormal events in the monitoring system data, as well as the degree of matching between the description of the scope of impact and the actual monitored equipment scope, in order to analyze the intensity of phenomenon conflict. Execution permission request rationality verification: Analyze the matching degree between the permission request scope in the application form and the fault impact scope displayed by the monitoring system data, determine the minimum necessary permission scope based on fault location, and analyze the permission conflict intensity.

4. The enablement decision assistance method for data security control according to claim 3, characterized in that, The process of adjusting the dynamic weight configuration based on the conflict intensity includes the following steps: Calculate the total conflict intensity value based on the time conflict intensity, phenomenon conflict intensity, and permission conflict intensity; Calculate the proportion of each conflict dimension in the total value of conflict intensity; The weight adjustment range is determined based on the sum of the conflict intensities, and the weights of the corresponding risk dimensions in the dynamic weight configuration are adjusted according to the weight adjustment range and the proportion of each conflict dimension. The adjusted weights are normalized to ensure that the sum of the weights is 1.

5. The enablement decision assistance method for data security control according to claim 1, wherein, The first major model matches the standardized feature vectors with a historical case vector database to obtain a preset number of historical cases with the highest similarity. The process includes the following steps: The standardized feature vector is compared with the standardized feature vector of historical cases stored in the historical case vector database to calculate the similarity and obtain the database search identifier corresponding to the historical case with the highest preset statistical number of similarities. Based on the database lookup identifier, retrieve the corresponding historical case details from the independently stored case database, including approval results, subsequent event records, and issue classification information; The historical case vector database stores the standardized feature vector representations and corresponding identifiers of historical cases, while the case database stores the detailed content of historical cases. This separate storage of the two prevents the detailed case content from directly affecting the feature matching process.

6. The enablement decision assistance method for data security control according to claim 1, wherein, The second major model uses the decision evaluation criteria output by the first major model as a decision framework to perform structured verification analysis on the information from the multiple data sources, specifically including: A differentiated verification process is executed based on the adjusted dynamic weight configuration, and verification strategies of different depths are adopted for different risk dimensions according to the weight. Among them, the high-weight dimension executes the preset comprehensive verification strategy, the medium-weight dimension executes the preset key verification strategy, and the low-weight dimension executes the preset basic verification strategy. Output natural language-enabled decision-making suggestions for non-technical managers, including verification results of various dimensions, overall compliance, approval decision types, and implementation requirements.

7. An enabling decision support device for data security control, characterized in that, The apparatus includes at least one module for performing the enabling decision support method for data security control as described in any one of claims 1-6.

8. Computer device, characterized in that The computer device includes a processor for executing a computer program stored in a memory to implement the enabling decision support method for data security control as described in any one of claims 1-6.