Dual identity dynamic switching and authority mapping system based on digital platform
By implementing a dual-identity dynamic switching and permission mapping system based on a digital platform, the problems of identity switching delay and permission redundancy in traditional systems have been solved. This system enables seamless collaborative management and security auditing of identity and permissions, thereby improving user experience and security.
Patent Information
- Application Number
- CN202511605558.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-05
- Publication Date
- 2026-01-27
AI Technical Summary
Traditional identity management systems struggle to achieve smooth identity switching and precise permission adaptation in dynamic environments, resulting in fragmented user experience, low operational efficiency, security redundancy, and response delays. Furthermore, rigid permission mappings pose a risk of conflict, and operational traceability gaps hinder security auditing.
The dual-identity dynamic switching and permission mapping system based on a digital platform achieves seamless switching between primary and secondary identities and dynamic permission reconstruction through identity management modules, environment awareness modules, identity switching engines, permission mapping engines, and permission execution interfaces. Combined with multi-level conflict arbitration and adaptive learning units, it constructs a closed-loop management system for identity and permissions.
It enables organic linkage and collaborative management between identities, dynamically adapts to user operation needs, reduces the risk of unauthorized operations and data leakage, improves the efficiency of permission adaptation and the convenience of operation, and provides auditable security throughout the process.
Smart Images

Figure CN121413029A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of identity and access control technology, and more specifically, to a dual identity dynamic switching and access control mapping system based on a digital platform. Background Technology
[0002] With the deepening of digital transformation, users frequently need to switch between different identities and permission modes in their daily work and collaborations. For example, under the same account, they may need to switch between member and leader identities depending on the scenario. Traditional identity management systems rely heavily on static permission allocation and independent login mechanisms for multiple accounts, making it difficult to support smooth identity switching and accurate permission adaptation in dynamic environments. This results in a fragmented user experience, low operational efficiency, and significant security vulnerabilities. The shortcomings of existing technologies: 1. Identity separation leads to redundant permissions.
[0003] The existing system lacks an organic link between the primary identity and the sub-identity. Users must log in to different accounts repeatedly in different scenarios. Permissions cannot be inherited or dynamically adjusted. Sub-identities often hold permissions that exceed actual needs, resulting in continuous security redundancy.
[0004] 2. Lack of environmental awareness leads to delayed handover.
[0005] The current identity switching mechanism relies entirely on manual judgment and operation, and cannot automatically trigger switching based on environmental factors such as operation time, location, device or network status. This results in users performing ordinary operations under high-privilege identities or engaging in sensitive behaviors in insecure environments, leading to significant response delays and misuse risks.
[0006] 3. Rigid permission mapping exacerbates the risk of conflict.
[0007] Traditional systems use static permission rules, which cannot dynamically generate appropriate and compliant permission sets based on real-time scenarios. When temporary privilege escalation is required, they can only grant full access or completely deny access, lacking fine-grained control capabilities and easily leading to permission conflicts, business interruptions, or data leaks.
[0008] 4. Operational traceability gaps hinder security audits.
[0009] Existing logging mechanisms struggle to link the operation sequences of primary and secondary identities. Identity switching events, permission change records, and behavioral data are stored in a scattered manner, making it impossible to form complete audit trails. This results in unauthorized behavior being difficult to trace and a lack of basis for security policy optimization.
[0010] Therefore, a dual identity dynamic switching and permission mapping system based on a digital platform is proposed to address the above problems. Summary of the Invention
[0011] In order to overcome the above-mentioned defects of the prior art, embodiments of the present invention provide a dual identity dynamic switching and permission mapping system based on a digital platform to solve the problems mentioned in the background art.
[0012] To achieve the above objectives, the present invention provides the following technical solution: a dual-identity dynamic switching and permission mapping system based on a digital platform, comprising: The identity management module is used to register and store a user's primary identity and at least one associated sub-identity, and to establish a two-way binding relationship network between the primary identity and the sub-identity, wherein the sub-identity includes member identity and leader identity; The environmental awareness module monitors at least three dynamic environmental factors in real time, including the operation time range, geographical location area, network environment status, access device type, and associated account activity. The identity switching engine automatically or manually triggers seamless switching between the primary identity and the sub-identity based on the matching degree between the environmental factor analysis results output by the environmental perception module and the preset trigger conditions. The permission mapping engine dynamically reconstructs the main identity permissions according to a preset rule set during identity switching, generating a sub-identity permission set. The reconstruction method includes at least two of permission downgrade inheritance, dynamic blocking, and time limit. The permission execution interface monitors the matching of operation commands and permission sets in real time when the sub-identity is active, and intercepts and alerts unauthorized behavior in real time.
[0013] Optionally, the identity switching engine supports multiple triggering mechanisms: when the environmental perception module detects that the combination of environmental factors meets a preset threshold, it automatically performs identity switching; after receiving a user's manual switching command, it performs two-factor verification through biometric recognition and dynamic password to securely trigger the switching; in sensitive operation scenarios, it initiates seamless switching based on a session behavior pattern matching algorithm, and adopts a session key separation and progressive permission activation strategy during the switching process to ensure operation continuity and security.
[0014] Optionally, the permission mapping engine implements the following mechanisms when performing permission reconstruction: an intelligent permission degradation and inheritance mechanism, which dynamically selects to inherit some or all permissions of the main identity according to the operation scenario; an adaptive dynamic shielding mechanism, which automatically hides or disables sensitive permissions based on the real-time environmental risk level; a configurable time limit mechanism, which sets variable time windows and frequency limits for the permission activation rules of sub-identities; and provides a permission combination definition interface, which supports users to create custom permission packages based on task type or organizational level.
[0015] Optionally, the permission mapping engine also has a built-in multi-level conflict arbitration mechanism. When a conflict is detected between the primary identity's permissions and the sub-identity's constraint rules, the following operations are performed: automatically disabling low-priority permissions based on a preset risk model; generating a visual application channel and initiating a temporary authorization request to the primary identity; granting unauthorized permissions with limited time and scope of operation after passing multi-factor verification including biometrics and device binding; and recording all arbitration processes and operation paths in an encrypted audit log.
[0016] Optionally, the permission execution interface performs the following actions when it detects unauthorized behavior: immediately blocks the current operation and generates an alarm log containing the environment context; automatically initiates secondary verification of the primary identity to confirm the operation intent; if the unauthorized behavior is triggered continuously for a preset number of times, it forcibly switches back to the primary identity, freezes the sub-identity permissions, and starts the security audit process until manual intervention is required to resolve the issue.
[0017] Optionally, it also includes an operation tracing module, which is used to fully record the timestamps, environmental triggering factors, and permission change details of identity switching events; construct a correlation graph of the operation behaviors of the primary identity and the sub-identity, dynamically map the permission usage path and unauthorized attempt records; generate encrypted audit logs and periodically synchronize them to the secure storage area through a sharded storage mechanism; and provide a visual analysis interface to support the tracking and auditing of abnormal permission propagation paths.
[0018] Optionally, the environment perception module integrates an adaptive learning unit, which analyzes historical switching records and permission usage data through machine learning algorithms to dynamically optimize the weight of environmental factors and the switching trigger threshold. The learning unit has a feedback correction mechanism, which can automatically adjust the environment assessment model when permission conflicts or unauthorized events occur, so as to improve the accuracy and adaptability of the switching strategy.
[0019] Optionally, the conflict arbitration mechanism further includes a risk prediction extension unit, which is used to predict the potential risk level of the current permission conflict based on historical operation data; dynamically adjust the scope of permission disabling and the duration of temporary authorization according to the prediction results; generate risk mitigation suggestions and push them to the main identity terminal to form a closed-loop security decision support.
[0020] The technical effects and advantages of this invention are as follows: Compared with existing technologies, this invention establishes a two-way binding network between primary and secondary identities, achieving organic linkage and collaborative management between identities. It utilizes an environmental perception module to monitor multi-dimensional dynamic factors in real time and automatically or manually triggers an identity switching engine based on preset conditions, completing a seamless transition between primary and secondary identities and effectively avoiding delays and errors caused by manual switching. The permission mapping engine dynamically reconstructs primary identity permissions according to scenario requirements, generating a minimum permission set that precisely matches the operational needs of secondary identities through permission degradation inheritance, dynamic shielding, and time-limited mechanisms, ensuring functional availability while maximizing permission redundancy control. The system also intelligently resolves permission allocation conflicts through a multi-level conflict arbitration mechanism, intercepts unauthorized behavior in real time through the permission execution interface, and constructs a complete traceability chain by combining primary-secondary operation behavior correlation graphs, achieving full auditability of operations. Furthermore, it integrates adaptive learning units and risk prediction extension units, enabling the system to continuously optimize environmental assessment strategies and permission mapping rules based on historical data, forming a continuously evolving closed-loop management system for identities and permissions. Ultimately, it reduces the risk of unauthorized operations and data leakage while improving permission adaptation efficiency and operational convenience. Attached Figure Description
[0021] Figure 1 This is a system framework diagram of the present invention.
[0022] Figure 2 This is a flowchart of the identity and permission recognition execution process of the present invention. Detailed Implementation
[0023] The following will refer to the appendices in the embodiments of the present invention. Figure 1 and attached Figure 2 The technical solutions in the embodiments of the present invention are clearly and completely described herein. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present invention.
[0024] A dual-identity dynamic switching and permission mapping system based on a digital platform includes: The identity management module is used to register and store a user's primary identity and at least one associated sub-identity, and to establish a two-way binding relationship network between the primary identity and the sub-identity, wherein the sub-identity includes member identity and leader identity; The environmental awareness module monitors at least three dynamic environmental factors in real time, including the operation time range, geographical location area, network environment status, access device type, and associated account activity. The identity switching engine automatically or manually triggers seamless switching between the primary identity and the sub-identity based on the matching degree between the environmental factor analysis results output by the environmental perception module and the preset trigger conditions. The permission mapping engine dynamically reconstructs the main identity permissions according to a preset rule set during identity switching, generating a sub-identity permission set. The reconstruction method includes at least two of permission downgrade inheritance, dynamic blocking, and time limit. The permission execution interface monitors the matching of operation commands and permission sets in real time when the sub-identity is active, and intercepts and alerts unauthorized behavior in real time. The identity management module is responsible for registering and managing users' primary identities and associated sub-identities (such as member identities and leader identities), storing identity information in a database and building a two-way bound identity relationship network. The environment awareness module continuously collects multi-dimensional environmental data such as time, location, network, device, and account activity, generating an environmental risk score after data fusion and weighted calculation. The identity switching engine, based on the environmental score and preset conditions, automatically or manually triggers identity switching after two-factor authentication, employing session persistence and key isolation technologies to ensure a secure transition. The permission mapping engine dynamically reconstructs primary identity permissions during switching, generating permission sets adapted to sub-identity scenarios through degradation inheritance, dynamic masking, and time-limited mechanisms. The permission execution interface monitors operation commands in real time, intercepting unauthorized behavior and triggering secondary verification or recording audit logs. The system achieves dynamic closed-loop management of identity and permissions through modular collaboration.
[0025] The identity switching engine supports multiple triggering mechanisms: when the environmental perception module detects that the combination of environmental factors meets a preset threshold, it automatically executes identity switching; after receiving a user's manual switching command, it performs two-factor authentication through biometric recognition and dynamic password to securely trigger the switching; in sensitive operation scenarios, it initiates seamless switching based on a session behavior pattern matching algorithm. During the switching process, a session key separation and progressive permission activation strategy are adopted to ensure operation continuity and security. The automatic triggering mechanism of the identity switching engine relies on the comparison between the environmental risk value calculated in real time by the environmental perception module and the preset threshold. When the combination of environmental factors, such as operation time, geographical location, and network security, reaches the set conditions, the engine automatically starts the identity switching process. Before switching, the system will first save a snapshot of the current operation state to ensure that it can be restored after switching.
[0026] The environmental sensing module continuously collects multi-dimensional environmental data, including time, location, network, device, and account activity. After data fusion and weighted calculation, an environmental risk score is generated.
[0027] Where E represents the comprehensive environmental risk score; The weight of the i-th environmental factor is W_i; f_i represents the normalized value of the i-th environmental factor; n represents the total number of environmental factors; This formula is used in the environmental perception module to calculate a unified risk score based on multiple environmental factors (such as time, location, network status, etc.), which serves as the trigger for identity switching.
[0028] The manual triggering mechanism allows users to initiate a switching request through a graphical interface or voice command. After receiving the request, the system calls biometric identification components such as face recognition or fingerprint recognition, combined with dynamic password verification, to complete two-factor authentication. Once authentication is successful, the switching operation is executed immediately to prevent unauthorized access.
[0029] The seamless triggering mechanism is applied to sensitive operation scenarios. It analyzes the user's operation sequence in real time through a session behavior pattern matching algorithm. If it detects that the user is about to perform a high-privilege operation but the current identity and permissions are insufficient, the system will automatically trigger an identity switch without interrupting the user's operation, thus improving the user experience.
[0030] During the switching process, the engine uses session key separation technology to generate independent encryption keys for sub-identity sessions, avoiding the risk of leakage of the main identity key. At the same time, the permission change adopts a gradual effect strategy, that is, basic permissions are loaded first to ensure the continuity of operation, and then complex permissions are loaded gradually to reduce the impact of switching on system performance.
[0031] The permission mapping engine implements the following mechanism when performing permission reconstruction: intelligent permission downgrade inheritance mechanism, which dynamically selects to inherit some or all permissions of the main identity according to the operation scenario; Through an intelligent permission downgrade and inheritance mechanism, the system dynamically calculates the sub-identity permission set based on the scenario sensitivity coefficient α.
[0032] Where P_inherit represents the set of permissions inherited by the child identity; P_master represents the master identity and permission set; P_base represents the basic permission set (such as public permissions). α Scene sensitivity coefficient (0 ≤ α ≤ 1); The "intelligent permission degradation and inheritance mechanism" used in the permission mapping engine dynamically adjusts the proportion of permissions inherited by the child identity from the main identity based on the scenario.
[0033] An adaptive dynamic masking mechanism automatically hides or disables sensitive permissions based on real-time environmental risk levels; a configurable time-limited mechanism allows setting variable time windows and frequency limits for permissions to take effect for sub-identities; and a permission combination definition interface is provided, allowing users to create custom permission packages based on task type or organizational level. The intelligent permission degradation and inheritance mechanism of the permission mapping engine is implemented through a rule engine and a context-aware algorithm. The rule engine loads predefined permission inheritance strategies, such as inheritance rules based on roles, tasks, or environments. The context-aware algorithm analyzes the characteristics of the current operation scenario in real time, such as task criticality and data sensitivity, and dynamically determines the scope of permissions that can be inherited by the sub-identity. For example, a leader inherits all approval permissions in an approval scenario, but only some permissions in a normal query scenario.
[0034] The adaptive dynamic shielding mechanism integrates an environmental risk assessment module. This module continuously receives risk scores from the environmental awareness module. When the risk score exceeds a set threshold, the shielding mechanism automatically hides or disables high-risk permission options, such as disabling data export functionality in an external network environment and hiding the administrator operation menu on high-risk devices. The risk threshold can be dynamically adjusted based on historical security events.
[0035] The configurable time-limited mechanism provides permission control in two dimensions: time and frequency. The time dimension allows setting an effective time period for sub-identity permissions, such as being valid during working hours. The frequency dimension limits the number of times a permission can be used, such as a maximum of 5 calls. After the time limit or the number of calls exceeds the limit, the permission will automatically expire and requires re-authentication or application for temporary authorization.
[0036] The permission combination definition interface allows users to quickly create custom permission templates based on task type (e.g., financial audit), cross-functional combinations (e.g., query and export combinations), or organizational hierarchy (e.g., department manager permission packages) through a graphical interface or script configuration. Templates support import, export, and version management, facilitating the reuse and auditing of permission policies.
[0037] The permission mapping engine also incorporates a multi-level conflict arbitration mechanism. When a conflict is detected between the primary identity's permissions and the sub-identity's constraint rules, the following actions are taken: Low-priority permissions are automatically disabled based on a preset risk model; a visual application channel is generated, and a temporary authorization request is initiated to the primary identity; after passing multi-factor verification including biometrics and device binding, unauthorized permissions with limited time and scope of operation are granted; all arbitration processes and operation paths are recorded in an encrypted audit log. The system's preset risk model categorizes permission conflicts into multiple levels, such as high-risk, medium-risk, and low-risk, comprehensively considering factors such as the functional impact of conflicting permissions, data sensitivity, and operation history. When a permission conflict is detected, the arbitration mechanism first automatically disables low-priority or high-risk permission operations to prevent the conflict from escalating. For example, if a sub-identity attempts to perform a highly sensitive operation when the current environment is risky, the system directly rejects the operation.
[0038] For low- to medium-risk conflicts, the system generates a visual application channel, presented to the user via pop-up or message, clearly explaining the conflict type, risk level, and reason for the application. The user can initiate a temporary authorization request with a single click through the interface. After the request is sent to the primary identity terminal, a multi-factor verification process is triggered. Verification factors include biometrics such as face or fingerprint, and device binding information such as trusted device identifiers, ensuring the legitimacy of the request source.
[0039] Upon successful verification, the system grants a restricted unauthorized access permission. This permission is valid for a limited timeframe, such as 10 minutes, and the scope of operation is limited to this specific operation. The permission automatically expires upon timeout or completion. All arbitration decision-making processes, including conflict detection, risk assessment, disabling operations, authorization requests, verification results, and permission granting details, are written to an encrypted audit log in real time. The log is protected using asymmetric encryption technology to ensure the integrity and immutability of post-audit.
[0040] The permission execution interface executes the following actions upon detecting unauthorized behavior: immediately blocking the current operation and generating an alarm log containing the environment context; automatically initiating secondary verification of the primary identity to confirm the operation intent; if the unauthorized behavior is triggered consecutively a preset number of times, forcibly switching back to the primary identity, freezing the sub-identity's permissions, and initiating a security audit process until manual intervention is required to resolve the issue. During this process, the operation parser intercepts operation instructions initiated by the sub-identity in real time, parsing elements such as operation type, target object, and parameter content, and converting them into standardized permission check requests. Upon receiving the request, the permission checker performs a rapid match with the currently active sub-identity's permission set. The matching algorithm is based on a permission tree or access control list structure, supporting fuzzy matching and regular expressions to ensure both efficiency and accuracy in the check.
[0041] When unauthorized actions are detected, the response executor immediately blocks the operation, rolls back partially executed steps to prevent data inconsistency, and generates an alarm log containing operation details, user ID, timestamp, device information, network status, and other environmental context. The system then automatically initiates a secondary authentication process for the primary identity, pushing a verification request to the primary identity terminal, requiring the user to confirm their intent via biometrics or a dynamic password. Successful verification allows the user to continue; otherwise, the operation remains blocked.
[0042] For repeated unauthorized actions, the system has a built-in counter and time window mechanism. When the number of unauthorized actions exceeds the set threshold within a short period of time, it is determined to be malicious behavior, the sub-identity session is forcibly terminated, the main identity is switched back, and all permissions of the sub-identity are temporarily frozen to prevent further risk spread.
[0043] Simultaneously, a security audit process is initiated to collect relevant operation logs, environmental data, and user behavior records, generate a security incident report, and notify the security administrator to intervene and handle the matter.
[0044] It also includes an operation tracing module, which is used to fully record the timestamps, environmental triggering factors, and permission change details of identity switching events; construct a correlation graph of the operation behaviors of the primary identity and the sub-identity, dynamically map the permission usage path and unauthorized attempt records; generate encrypted audit logs and periodically synchronize them to a secure storage area through a sharded storage mechanism; and provide a visual analysis interface to support the tracking and auditing of abnormal permission propagation paths. Among them, the operation tracing module collects event data generated by various modules of the system in real time through a distributed log collection agent, including the timestamps of identity switching events, triggering environmental factors, permission change details, conflict arbitration decisions, unauthorized interception records, etc. The data is cleaned and formatted and then stored in a central log database.
[0045] The module constructs a graph of the relationship between the main identity and the sub-identity's operational behavior based on the collected data. The graph is implemented using graph database technology. Nodes represent identities or operational events, and edges represent relationships such as permission inheritance, switching sequences, and unauthorized attempts. The graph supports real-time updates and dynamic queries, and can intuitively display the permission usage path and security event propagation chain.
[0046] The audit log generation component periodically extracts data from the log repository to generate structured log files. These files are encrypted using a symmetric encryption algorithm to ensure integrity. A sharded storage mechanism divides the log files into shards based on time or type and synchronizes them through a secure channel to multiple physically isolated storage areas, such as local encrypted hard drives, private cloud storage, or blockchain nodes, achieving redundant backup and tamper-proof log protection.
[0047] The visualization analysis interface provides a graphical user interface that allows auditors to explore correlation graphs and trace abnormal permission propagation paths through drag-and-drop, filtering, and drill-down methods. For example, it can trace an unauthorized access incident back to the identity switching decision or environmental triggering factors. The interface supports the generation of audit reports and risk heatmaps to assist in security decision-making. The module also integrates an alarm function; when abnormal patterns such as frequent unauthorized access or permission abuse are detected, alarms are automatically triggered and pushed to the security management platform.
[0048] The environment perception module integrates an adaptive learning unit, which analyzes historical switching records and permission usage data through machine learning algorithms to dynamically optimize the weights of environmental factors and the switching trigger threshold. The learning unit has a feedback correction mechanism that can automatically adjust the environment assessment model when permission conflicts or unauthorized events occur, so as to improve the accuracy and adaptability of the switching strategy. The adaptive learning unit of the environment perception module adopts an online machine learning framework to continuously collect historical switching records, permission usage data, environmental factor values, and security event records to form a training dataset.
[0049] Learning units are based on formulas The weights w_i of each environmental factor are dynamically adjusted to improve the accuracy of environmental assessments.
[0050] Where Δwi represents the adjustment amount of the weight of the i-th environmental factor; m represents the learning rate; n represents the error signal; Z_i represents the value of the environmental factor in the event.
[0051] The dataset undergoes feature engineering to extract key features such as environmental factor values, switching results, permission usage frequency, and conflict occurrence frequency for model training. The learning unit applies clustering algorithms like K-means or classification algorithms like decision trees to assign weights to environmental factors, calculate the influence of each factor on the switching decision, and dynamically adjust the switching trigger threshold to make the system more adaptable to environmental changes.
[0052] For example, by analyzing historical data and discovering that the handover failure rate is high in certain network environments, the unit automatically reduces the weight of network factors or increases their trigger thresholds to reduce false handovers. The feedback correction mechanism is a core component of the unit. When a permission conflict or unauthorized event occurs, the mechanism automatically triggers a model correction process. This process includes event backtracking, factor reassessment, and model retraining. By comparing the environmental data at the time of the event with the model prediction results, model biases are identified, and reinforcement learning algorithms are used to adjust model parameters to improve future prediction accuracy. The learning unit also supports model version management, allowing administrators to compare the performance of different versions and revert to a stable version when necessary.
[0053] The conflict arbitration mechanism also includes a risk prediction extension unit, used to predict the potential risk level of the current permission conflict based on historical operation data; dynamically adjust the scope of permission disabling and the duration of temporary authorization according to the prediction results; generate risk mitigation suggestions and push them to the primary identity terminal to form a closed-loop security decision support. The risk prediction extension unit is integrated into the conflict arbitration mechanism, accessing the historical operation database to obtain data such as permission conflict events, operation context, handling results, and subsequent impacts. The unit uses time series analysis or risk prediction models such as logistic regression and random forest to train the risk prediction model. The model input includes features such as the current conflicting permission type, operation sensitivity, user historical behavior, and environmental risk value, and the output is the potential risk level, such as high, medium, or low.
[0054] During the prediction process, the unit calculates the risk probability in real time and dynamically adjusts the arbitration strategy based on the probability value. For example, for high-risk conflicts, the scope of permission restriction is expanded to the relevant operation set, or the temporary authorization duration is shortened to the minimum necessary time; for low-risk conflicts, restrictions are relaxed to reduce business disruption. The unit also generates risk mitigation suggestions based on best practices and historical handling experience, such as prompting users to shorten authorization time, add operation confirmation steps, or switch to a more secure environment. These suggestions are delivered to the primary identity terminal via push notifications or interface pop-ups to assist users in making quick decisions.
[0055] All prediction results, adjustment strategies, and recommendations are recorded in the audit log for model performance evaluation and continuous optimization. The unit uses a closed-loop feedback mechanism to compare the actual effects of each arbitration with the prediction results, continuously improving the prediction model and enhancing the system's predictive power and decision-making intelligence.
[0056] The workflow of this invention begins with the user registering a primary identity and sub-identities and completing two-way binding. The environment awareness module continuously monitors multi-dimensional factors such as time, location, network, and device, and calculates risk values. The identity switching engine automatically triggers a seamless switch based on the environment, or responds to a manual switch via two-factor authentication, employing session key separation for security during the process. The permission mapping engine then dynamically reconstructs the primary identity permissions, generating a minimum permission set suitable for sub-identity scenarios through downgrade inheritance, dynamic masking, and time-limited constraints. The permission execution interface monitors operations in real time, intercepting unauthorized behavior and triggering secondary verification or conflict arbitration. The operation tracing module records events throughout the process and constructs a behavior correlation graph, storing logs in encrypted fragments. The system analyzes historical data through an adaptive learning unit, continuously optimizing environment assessment and permission policies to achieve closed-loop management.
[0057] Finally, the following points should be noted: First, in the description of this application, it should be noted that, unless otherwise specified and limited, the terms "installation", "connection", and "linkage" should be interpreted broadly, and can be mechanical or electrical connections, or internal connections between two components, or direct connections. "Up", "down", "left", "right", etc. are only used to indicate relative positional relationships. When the absolute position of the described object changes, the relative positional relationship may change. Secondly: The accompanying drawings of the embodiments disclosed in this invention only involve the structures involved in the embodiments disclosed in this invention. Other structures can refer to the general design. In the absence of conflict, the same embodiment and different embodiments of this invention can be combined with each other. In conclusion, the above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A dual-identity dynamic switching and permission mapping system based on a digital platform, characterized in that, include: The identity management module is used to register and store a user's primary identity and at least one associated sub-identity, and to establish a two-way binding relationship network between the primary identity and the sub-identity, wherein the sub-identity includes member identity and leader identity; The environmental awareness module monitors at least three dynamic environmental factors in real time, including the operation time range, geographical location area, network environment status, access device type, and associated account activity. The identity switching engine automatically or manually triggers seamless switching between the primary identity and the sub-identity based on the matching degree between the environmental factor analysis results output by the environmental perception module and the preset trigger conditions. The permission mapping engine dynamically reconstructs the main identity permissions according to a preset rule set during identity switching, generating a sub-identity permission set. The reconstruction method includes at least two of permission downgrade inheritance, dynamic blocking, and time limit. The permission execution interface monitors the matching of operation commands and permission sets in real time when the sub-identity is active, and intercepts and alerts unauthorized behavior in real time.
2. A dual-identity dynamic switching and permission mapping system based on a digital platform as described in claim 1, characterized in that, The identity switching engine supports multiple triggering mechanisms: when the environmental perception module detects that the combination of environmental factors meets a preset threshold, it automatically performs identity switching; after receiving a user's manual switching command, it performs two-factor authentication through biometric recognition and dynamic password to securely trigger the switching; in sensitive operation scenarios, it initiates seamless switching based on a session behavior pattern matching algorithm, and adopts a session key separation and progressive permission activation strategy during the switching process to ensure operation continuity and security.
3. A dual-identity dynamic switching and permission mapping system based on a digital platform as described in claim 1, characterized in that, The permission mapping engine implements the following mechanism when performing permission reconstruction: intelligent permission downgrade inheritance mechanism, which dynamically selects to inherit some or all permissions of the main identity according to the operation scenario; An adaptive dynamic shielding mechanism automatically hides or disables sensitive permissions based on the real-time environmental risk level. A configurable time limit mechanism allows setting variable time windows and frequency limits for permission activation rules for sub-identities; It also provides an interface for defining permission combinations, allowing users to create custom permission packages based on task type or organizational level.
4. A dual-identity dynamic switching and permission mapping system based on a digital platform as described in claim 3, characterized in that, The permission mapping engine also has a built-in multi-level conflict arbitration mechanism. When a conflict is detected between the primary identity's permissions and the sub-identity's constraint rules, the following operations are performed: automatically disable low-priority permissions based on a preset risk model; generate a visual application channel and initiate a temporary authorization request to the primary identity; and after passing multi-factor verification that includes biometrics and device binding, grant unauthorized permissions with limited time and scope of operation. All arbitration processes and operational paths are recorded in encrypted audit logs.
5. A dual-identity dynamic switching and permission mapping system based on a digital platform as described in claim 1, characterized in that, When the permission execution interface detects unauthorized behavior, it performs the following actions: immediately blocks the current operation and generates an alarm log containing the environment context; automatically initiates secondary authentication of the primary identity to confirm the operation intent; If the unauthorized behavior is triggered a preset number of times, the system will forcibly switch back to the primary identity, freeze the sub-identity's permissions, and initiate a security audit process until manual intervention is required to resolve the issue.
6. A dual-identity dynamic switching and permission mapping system based on a digital platform as described in claim 1, characterized in that, It also includes an operation tracing module, which is used to fully record the timestamps, environmental triggering factors, and permission change details of identity switching events; construct a relationship graph of the operation behaviors of the primary identity and the sub-identity, dynamically map the permission usage path and unauthorized attempt records; generate encrypted audit logs and periodically synchronize them to a secure storage area through a sharded storage mechanism; Provides a visual analysis interface to support the tracking and auditing of abnormal permission propagation paths.
7. A dual-identity dynamic switching and permission mapping system based on a digital platform as described in claim 2, characterized in that, The environment perception module integrates an adaptive learning unit, which analyzes historical switching records and permission usage data through machine learning algorithms to dynamically optimize the weight of environmental factors and the switching trigger threshold. The learning unit has a feedback correction mechanism that can automatically adjust the environment assessment model when permission conflicts or unauthorized events occur, so as to improve the accuracy and adaptability of the switching strategy.
8. A dual-identity dynamic switching and permission mapping system based on a digital platform as described in claim 4, characterized in that, The conflict arbitration mechanism also includes a risk prediction extension unit, which is used to predict the potential risk level of the current permission conflict based on historical operation data; The scope of disabled permissions and the duration of temporary authorizations will be dynamically adjusted based on the prediction results. Risk mitigation suggestions are generated and pushed to the primary identity terminal to form a closed-loop security decision support system.