A multi-privilege management method for an access control system

By dividing the access control system's permission module into fixed and flexible modules, and combining dynamic adjustment and monitoring indicator comparison, a permission management arrangement scheme is generated, which solves the problem of insufficient flexibility and accuracy of the permission management system in the existing technology, and realizes dynamic adaptation and security control of access control permissions.

CN121482914BActive Publication Date: 2026-04-24INMARS (FUJIAN) INFORMATION TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
INMARS (FUJIAN) INFORMATION TECH CO LTD
Filing Date
2026-01-09
Publication Date
2026-04-24

AI Technical Summary

Technical Problem

Existing access control systems lack flexibility and cannot adapt to dynamic permission requirements in complex scenarios. Permission configuration relies on human experience, resulting in insufficient accuracy in permission management and a lack of quantitative monitoring and evaluation of the permission execution process.

Method used

The access control system's permission module is divided into a fixed permission module and a flexible permission module. By dynamically adjusting the threshold and associated hierarchy of the target permission, a set of candidate adjustment combinations and a set of hierarchy combinations are generated. Combined with the weight settings, a permission management and arrangement scheme is generated. The access control intelligent management and control platform is used for permission allocation and arrangement. The permission status is dynamically adjusted by comparing the permission execution monitoring indicators with the standard indicators.

Benefits of technology

It improves the flexibility and accuracy of access control, enabling flexible configuration of access control combinations according to actual needs, ensuring security and controllability, timely intervention in non-compliant access usage, and enhancing the overall efficiency and security of access control management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121482914B_ABST
    Figure CN121482914B_ABST
Patent Text Reader

Abstract

The application discloses a kind of access control system multi-authorization management methods, it is related to access control system technical field, and its technical solution key points include the following steps: the fixed authority management project of fixed authority module and the flexible authority management project of flexible authority module in access control system are marked as pending programming authority project;Target authority dynamic adjustment threshold and target authority associated level number are handled to obtain selected adjustment combination set and selected level combination set;Target authority combination set is obtained by analyzing selected adjustment combination set and selected level combination set, and the authority management programming scheme is formed according to target authority combination set;Authority management programming scheme includes at least one authority programming link, and the authority programming link corresponds to authority programming standard index;Based on authority management programming scheme, the authority of access control system is distributed and programmed, and the authority execution monitoring index of user in authority programming link is obtained;Effect is to improve the overall efficiency and security of access control authority management.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of access control system technology, and more specifically, to a multi-access control system management method. Background Technology

[0002] Access control systems often employ a single, standardized permission configuration approach, typically defining only fixed permission types. This fails to accommodate the dynamic permission needs of different scenarios, resulting in insufficient flexibility and an inability to adapt to complex office or facility management environments. Furthermore, traditional solutions lack systematic analysis and adaptability assessment of permission combinations. Permission configuration often relies on manual experience, leading to issues such as unreasonable permission scopes and unclear hierarchical relationships, thus affecting the accuracy of access control. The execution monitoring and evaluation aspects of traditional access control systems are weak, often using simple "allow" or "deny" as the outcome of permission usage. There is a lack of quantitative monitoring of the permission execution process and no established evaluation mechanism, making it impossible to objectively reflect the user's permission compliance and hindering dynamic adjustment and closed-loop control of permission usage. Summary of the Invention

[0003] In view of the shortcomings of the existing technology, the purpose of this invention is to provide a multi-access management method for access control systems.

[0004] To achieve the above objectives, the present invention provides the following technical solution:

[0005] A method for multi-access control system management, comprising the following steps:

[0006] Mark the fixed permission management items in the fixed permission module and the flexible permission management items in the flexible permission module of the access control system as permission items to be arranged;

[0007] The target permission dynamic adjustment threshold and the number of associated hierarchical levels are processed to obtain the set of possible adjustment combinations and the set of possible hierarchical combinations;

[0008] The target permission combination set is obtained by analyzing the set of adjustment combinations and the set of hierarchical combinations to be selected. A permission management arrangement scheme is formed based on the target permission combination set. The permission management arrangement scheme includes at least one permission arrangement step, and each permission arrangement step has a corresponding permission arrangement standard indicator.

[0009] Based on the access control system's access control management and orchestration scheme, access permissions are allocated and orchestrated to obtain user access permission execution monitoring indicators during the access permission orchestration process. The access permission execution monitoring indicators are compared and judged with the corresponding access permission orchestration standard indicators to obtain the user's access permission execution performance during the access permission orchestration process.

[0010] Based on the user's performance in the permission execution process, obtain the user's evaluation value in the permission orchestration stage; based on the stage evaluation value, obtain the user's overall evaluation value in the permission management orchestration scheme.

[0011] Based on the comprehensive evaluation value, the user's access control permission usage results in the access control arrangement scheme are obtained.

[0012] Preferably, the target permission dynamic adjustment threshold and the number of associated hierarchical levels are processed to obtain a set of candidate adjustment combinations and a set of candidate hierarchical combinations, specifically including the following steps:

[0013] Based on the set target permission dynamic adjustment threshold, a set of permission adjustment combinations for the permission items to be arranged is obtained. Based on the total number of permission association levels of the permission items to be arranged in the permission adjustment combination set, the adjustment combination coefficient corresponding to the permission adjustment combination set is obtained. Based on the adjustment combination coefficient, a set of candidate adjustment combinations is obtained.

[0014] Based on the set target permission association level, a permission level combination set of permission items to be arranged is obtained. Based on the total permission adjustment range of the permission items to be arranged in the permission level combination set, the level combination coefficient corresponding to the permission level combination set is obtained. Based on the level combination coefficient, a candidate level combination set is obtained.

[0015] Preferably, the fixed permission module includes a core area fixed permission unit, a regular time period fixed permission unit, a dedicated device fixed permission unit, and a basic operation fixed permission unit;

[0016] The fixed access management items include fixed access management items for core areas, fixed access management items for regular time periods, fixed access management items for dedicated devices, and fixed access management items for basic operations.

[0017] Preferably, the target permission combination set is obtained by analyzing the set of adjustment combinations and the set of hierarchical combinations, and a permission management orchestration scheme is formed based on the target permission combination set, specifically including the following steps:

[0018] Set adjustment weights and hierarchical weights;

[0019] Based on the adjustment weights and hierarchical weights, the combination arrangement coefficients corresponding to the candidate adjustment combination set and the candidate hierarchical combination set are obtained;

[0020] The target permission combination set is obtained based on the combination arrangement coefficient, and the permission management arrangement scheme is formed based on the permission items to be arranged in the target permission combination set.

[0021] Preferably, the access control orchestration scheme includes at least one access control orchestration step, and each access control orchestration step corresponds to access control orchestration standard indicators, specifically including the following steps:

[0022] The permission items to be orchestrated based on the permission management orchestration scheme constitute the permission orchestration stage of the permission management orchestration scheme;

[0023] The permission orchestration process includes at least one process dimension; wherein, the process dimension includes a first process dimension and a second process dimension;

[0024] Based on the first stage dimension, set the stage weight parameters corresponding to the permission orchestration stage in the permission management orchestration scheme. The stage weight parameters correspond to the first stage dimension.

[0025] Based on the second stage dimension, set the corresponding stage standard execution parameters for the permission orchestration stage. The stage standard execution parameters correspond to the second stage dimension.

[0026] Based on the standard execution parameters and weight parameters of each stage, the permission orchestration standard indicators corresponding to each stage are generated; among them, the standard execution parameters of each stage include identity authentication compliance parameters and hierarchical matching standard parameters.

[0027] Preferably, the access control system is configured and permissions are allocated based on the permission management and orchestration scheme, and user permission execution monitoring indicators are obtained during the permission orchestration process. This specifically includes the following steps:

[0028] Import the access control orchestration scheme into the intelligent access control platform;

[0029] The access control intelligent management platform obtains user permission execution feedback data, which includes user identity authentication data and hierarchy matching data;

[0030] Based on the user's identity authentication data, obtain the user's identity authentication behavior in the permission orchestration process; based on the user's hierarchical matching data, obtain the user's hierarchical matching behavior in the permission orchestration process.

[0031] The identity authentication behavior and the hierarchical matching behavior constitute the user's actual execution behavior in the permission orchestration process. The actual execution behavior is marked as the user's permission execution monitoring indicator in the permission orchestration process.

[0032] Preferably, the permission execution monitoring indicators are compared and judged with the corresponding permission orchestration standard indicators in the permission orchestration stage to obtain the user's permission execution performance in the permission orchestration stage, specifically including the following steps:

[0033] The monitoring indicators for permission execution are compared and judged with the standard indicators for permission orchestration corresponding to the permission orchestration process.

[0034] If the permission execution monitoring indicators are inconsistent with the permission orchestration standard indicators corresponding to the permission orchestration stage, the user's permission execution behavior in the permission orchestration stage will be judged as non-compliant, and the permission execution monitoring indicators will be marked as non-compliant parameters of the stage.

[0035] Preferably, the user's evaluation value in the permission orchestration process is obtained based on the permission execution performance, specifically including the following steps:

[0036] The number of non-compliant parameters corresponding to non-compliant parameters in the acquisition process;

[0037] The total number of standard parameters for the standard execution parameters corresponding to the permission orchestration stage;

[0038] The user's evaluation value in the permission arrangement process is obtained based on the total number of standard parameters and the number of non-compliant parameters.

[0039] Preferably, the comprehensive evaluation value of the user in the access control arrangement scheme is obtained based on the evaluation value of each step, specifically including the following steps:

[0040] Obtain the corresponding stage weight parameters for the permission orchestration stage based on the first stage dimension;

[0041] The user's permission arrangement coefficient at each permission arrangement stage is obtained by weighting the stage evaluation value based on the stage weight parameter.

[0042] The user's overall evaluation value for the permission management arrangement scheme is obtained by summing the permission arrangement coefficients of each permission arrangement stage.

[0043] Preferably, the first step dimension includes the core area permission arrangement step, the regular time period permission arrangement step, the dedicated device permission arrangement step, the basic operation permission arrangement step, and the flexible adaptation permission arrangement step;

[0044] The second dimension includes the permission initialization stage, the permission association configuration stage, the permission level review stage, the permission dynamic adjustment stage, and the permission expiration and cancellation stage.

[0045] Compared with the prior art, the present invention has the following beneficial effects:

[0046] This invention unifies the management items of fixed permission modules and flexible permission modules into permission items to be orchestrated. This includes permissions for fixed scenarios such as core areas and regular time periods, as well as dynamically adaptable permissions, ensuring that all types of access control permissions are included in the management system, avoiding omissions in permission control, and making the scope of permission management more complete. By processing the dynamic adjustment threshold and associated level of target permissions, a set of candidate adjustment combinations and a set of candidate level combinations are generated. Further analysis yields the target permission combination set, allowing for flexible configuration of permission combinations according to actual management needs. This makes the permission management orchestration scheme more aligned with the permission control requirements of different scenarios, improving the flexibility and accuracy of permission configuration. The permission management orchestration scheme clearly defines the standard indicators for each permission orchestration stage. By comparing the user's permission execution monitoring indicators with the standard indicators, permission execution performance can be determined. The permission status can be dynamically adjusted based on the user's actual execution performance, ensuring the security and controllability of the access control system and enabling timely intervention against non-compliant permission usage, thus improving the overall efficiency and security of access control permission management. Attached Figure Description

[0047] Figure 1 This invention provides a schematic diagram illustrating the steps of a multi-access control system management method.

[0048] Figure 2 This is a schematic diagram illustrating the steps involved in obtaining the evaluation value in a multi-access control system method proposed in this invention. Detailed Implementation

[0049] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings.

[0050] Many specific details are set forth in the following description in order to provide a full understanding of the invention. However, the invention may also be practiced in other ways different from those described herein, and those skilled in the art can make similar extensions without departing from the spirit of the invention. Therefore, the invention is not limited to the specific embodiments disclosed below.

[0051] Secondly, the term "an embodiment" or "embodiment" as used herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The phrase "in one embodiment" appearing in different places throughout this specification does not necessarily refer to the same embodiment, nor is it a single embodiment or an embodiment selectively excluded from other embodiments.

[0052] Reference Figures 1-2 As shown.

[0053] The embodiments further illustrate the multi-access control system management method proposed in this invention.

[0054] A method for multi-access control system management, comprising the following steps:

[0055] Mark the fixed permission management items in the fixed permission module and the flexible permission management items in the flexible permission module of the access control system as permission items to be arranged;

[0056] The fixed permission module includes fixed permission units for core areas, fixed permission units for regular time periods, fixed permission units for dedicated devices, and fixed permission units for basic operations;

[0057] The fixed access control program includes fixed access control for core areas, fixed access control for regular time periods, fixed access control for dedicated devices, and fixed access control for basic operations.

[0058] First, the access control system's permission modules are divided into fixed permission modules and flexible permission modules. The permission management items in both modules are then uniformly marked as permission items to be orchestrated. The specific scope of permissions that need to be managed in the future is clearly defined, ensuring that all controllable permissions are included in the management system.

[0059] The fixed access module includes fixed access units for core areas, fixed access units for regular time periods, fixed access units for dedicated devices, and fixed access units for basic operations. The corresponding access management project for the core area fixed access unit is the core area fixed access management project. This unit targets core areas within the access control system's coverage area, such as the company's server room or finance department, areas involving important assets or information. This project clearly defines which personnel have fixed access permissions to these core areas; for example, only the company's IT operations personnel and finance department heads are assigned the access permissions corresponding to the core area fixed access management project.

[0060] The "Regular Time Period Fixed Permission Unit" corresponds to the "Regular Time Period Fixed Permission Management Project." It is for permission control during regular fixed time periods. For example, most companies' daily office hours are from 9:00 to 18:00 on weekdays. This project will stipulate that during this regular time period, the company's on-duty employees have normal access to the office area access control. Outside of this time period, if no other permission is configured, employees will not be able to pass through the office area access control.

[0061] The dedicated device fixed permission management project, which corresponds to the dedicated device fixed permission unit, is a permission management project centered around the dedicated devices associated with the access control system, such as classified printers and dedicated server devices connected to the access control system. This project restricts the operation of these devices to personnel in specific positions. For example, only the confidentiality specialists of an enterprise will be assigned the dedicated device fixed permission to use classified printers.

[0062] The basic operation fixed permission unit corresponds to the basic operation fixed permission management project, which targets the basic functions of access control, such as controlling the access control switch and querying the access control status. This project clarifies that general employees have the permissions to perform these basic operations, ensuring that employees can use the basic functions of access control to carry out their daily work normally.

[0063] The target permission dynamic adjustment threshold and the number of associated hierarchical levels are processed to obtain a set of candidate adjustment combinations and a set of candidate hierarchical combinations. The specific steps include:

[0064] Based on the set target permission dynamic adjustment threshold, a set of permission adjustment combinations for the permission items to be arranged is obtained. Based on the total number of permission association levels of the permission items to be arranged in the permission adjustment combination set, the adjustment combination coefficient corresponding to the permission adjustment combination set is obtained. Based on the adjustment combination coefficient, a set of candidate adjustment combinations is obtained.

[0065] Based on the set target permission association level, a permission level combination set of permission items to be arranged is obtained. Based on the total permission adjustment range of the permission items to be arranged in the permission level combination set, the level combination coefficient corresponding to the permission level combination set is obtained. Based on the level combination coefficient, a candidate level combination set is obtained.

[0066] A set of permission adjustment combinations for the permission items to be arranged is generated based on a pre-set target permission dynamic adjustment threshold. The target permission dynamic adjustment threshold refers to a pre-defined standard for the adjustable range of permissions. For example, for fixed permission items in core areas, the adjustment range is set to not exceed 20% of the original permission range; 20% is the corresponding target permission dynamic adjustment threshold. Based on the target permission dynamic adjustment threshold, the permission items to be arranged are combined according to different adjustment ranges, such as different combinations of 10% adjustment for core area permissions and 15% adjustment for permissions during regular time periods. These different combinations constitute the permission adjustment combination set.

[0067] Calculate the adjustment combination coefficient corresponding to the set of permission adjustment combinations. This is based on the total number of permission association levels for the permission items to be arranged within the set of permission adjustment combinations. The total number of permission association levels refers to the sum of the number of levels associated with each permission item to be arranged in each permission adjustment combination. For example, if a permission adjustment combination includes core area permissions and dedicated device permissions, with core area permissions associated with 3 levels and dedicated device permissions associated with 2 levels, then the total number of permission association levels for this combination is 5. The adjustment combination coefficient = total number of permission association levels ÷ total number of permission items to be arranged. Assuming the total number of permission items to be arranged is 4, then the adjustment combination coefficient for this combination is 5 ÷ 4 = 1.25. Based on the adjustment combination coefficient, select combinations that meet the requirements. For example, if the adjustment combination coefficient is set to be between 1 and 1.5, then combinations within this range are included in the candidate adjustment combination set.

[0068] Based on the set target number of permission association levels, a set of permission level combinations for the permission items to be orchestrated is generated. The target number of permission association levels is a pre-defined standard for the number of levels that each permission item should be associated with. For example, it is set that regular time period permissions should be associated with 2 levels, and basic operation permissions should be associated with 1 level. According to this standard, the permission items to be orchestrated are combined according to different numbers of association levels, such as a combination of regular time period permissions associated with 2 levels and basic operation permissions associated with 1 level. These combinations constitute the permission level combination set.

[0069] Calculate the hierarchical combination coefficient corresponding to the set of permission level combinations. This is based on the total adjustment range of the permission items to be arranged within the permission level combination set. The total adjustment range refers to the sum of the adjustment ranges of each permission item to be arranged within each permission level combination. For example, if a permission level combination includes regular time period permissions and basic operation permissions, and the adjustment range for regular time period permissions is 15% and the adjustment range for basic operation permissions is 10%, then the total adjustment range for this combination is 25%. The hierarchical combination coefficient = total permission adjustment range ÷ total number of permission items to be arranged. If the total number of permission items to be arranged is 4, the hierarchical combination coefficient for this combination is 25% ÷ 4 = 6.25%. Based on the hierarchical combination coefficient, select combinations that meet the requirements, such as setting the hierarchical combination coefficient to be between 5% and 8%. Combinations within this range are included in the candidate hierarchical combination set.

[0070] The target permission combination set is obtained by analyzing the set of potential adjustment combinations and the set of potential hierarchical combinations. A permission management orchestration scheme is then constructed based on this target permission combination set, specifically including the following steps:

[0071] Set adjustment weights and hierarchical weights;

[0072] Based on the adjustment weights and hierarchical weights, the combination arrangement coefficients corresponding to the candidate adjustment combination set and the candidate hierarchical combination set are obtained;

[0073] The target permission combination set is obtained based on the combination arrangement coefficient, and the permission management arrangement scheme is formed based on the permission items to be arranged in the target permission combination set.

[0074] The first step is to set the adjustment weights and hierarchical weights. These weights are pre-defined parameters based on the access control system's permission management requirements, reflecting the importance of the candidate adjustment combination set and candidate hierarchical combination set in the final permission combination. If the access control system prioritizes the flexibility of dynamic permission adjustment, the adjustment weight is set to 0.6; if the focus is more on the rationality of permission association hierarchies, the hierarchical weight is set to 0.4. Typically, the sum of the adjustment weight and the hierarchical weight is 1 to ensure the standardization of weight allocation.

[0075] The combination arrangement coefficient is a comprehensive index obtained by weighting the candidate adjustment combination set and the candidate hierarchical combination set together using adjustment weights and hierarchical weights. Combination arrangement coefficient = Adjustment combination coefficient of candidate adjustment combination set × Adjustment weight + Hierarchical combination coefficient of candidate hierarchical combination set × Hierarchical weight. For example, if the adjustment combination coefficient of a candidate adjustment combination is 1.25, the hierarchical combination coefficient of a candidate hierarchical combination is 6.25%, the adjustment weight is 0.6, and the hierarchical weight is 0.4, then the corresponding combination arrangement coefficient is 1.25 × 0.6 + 6.25% × 0.4 = 0.75 + 0.025 = 0.775. The combination arrangement coefficient is calculated for each pairing of candidate adjustment combinations and candidate hierarchical combinations.

[0076] Finally, the target permission combination set and permission management orchestration scheme are generated. A qualified threshold for the combination orchestration coefficient is set (e.g., 0.7). Combinations with orchestration coefficients not lower than this threshold are selected, and these qualified combinations constitute the target permission combination set. If a combination's orchestration coefficient is 0.775, it meets the threshold requirement and is included in the target permission combination set. The permission items to be orchestrated within the target permission combination set are extracted, such as fixed permission items for core areas and fixed permission items for regular time periods. These items are then integrated according to permission type, association level, and other logic to form a permission management orchestration scheme. The scheme clearly defines the adjustment rules and association level for each permission item, which is used for subsequent access control system permission allocation and control.

[0077] Access control orchestration schemes include at least one access orchestration step, and each access orchestration step corresponds to access orchestration standard indicators, specifically including the following steps:

[0078] The permission items to be orchestrated based on the permission management orchestration scheme constitute the permission orchestration stage of the permission management orchestration scheme;

[0079] The permission orchestration process includes at least one process dimension; wherein, the process dimension includes a first process dimension and a second process dimension;

[0080] Based on the first stage dimension, set the stage weight parameters corresponding to the permission orchestration stage in the permission management orchestration scheme. The stage weight parameters correspond to the first stage dimension.

[0081] Based on the second stage dimension, set the corresponding stage standard execution parameters for the permission orchestration stage. The stage standard execution parameters correspond to the second stage dimension.

[0082] The first dimension includes the core area permission arrangement stage, the regular time period permission arrangement stage, the dedicated device permission arrangement stage, the basic operation permission arrangement stage, and the flexible adaptation permission arrangement stage.

[0083] The second dimension includes the permission initialization stage, permission association configuration stage, permission level review stage, permission dynamic adjustment stage, and permission expiration and cancellation stage.

[0084] Based on the standard execution parameters and weight parameters of each stage, the permission orchestration standard indicators corresponding to each stage are generated; among them, the standard execution parameters of each stage include identity authentication compliance parameters and hierarchical matching standard parameters.

[0085] Based on the identified permission items to be orchestrated in the permission management orchestration scheme, each item is broken down into corresponding permission orchestration steps. For example, if the permission items to be orchestrated include fixed permission items for core areas, a core area permission orchestration step is generated; if it includes fixed permission items for regular time periods, a regular time period permission orchestration step is generated, thus ensuring that each permission item to be orchestrated corresponds to a specific execution step.

[0086] Each permission orchestration stage includes at least one stage dimension, which is divided into a first stage dimension and a second stage dimension. The first stage dimension is based on permission type, specifically including core area permission orchestration, regular time period permission orchestration, dedicated device permission orchestration, basic operation permission orchestration, and flexible adaptation permission orchestration. Different permission items correspond to different first stage dimension types. The second stage dimension is based on the permission execution flow, including permission initialization, permission association configuration, permission level review, dynamic permission adjustment, and permission expiration / cancellation. Each permission orchestration stage covers these flow-based dimensions.

[0087] Next, we configure the weight parameters and standard execution parameters for each stage. For the first stage dimension, we set the weight parameters based on the importance of the corresponding permissions, with different weights for different first stage dimensions. For example, the core area permission orchestration stage is of high importance, so its weight parameter is set to 0.3; the regular time period permission orchestration stage has a weight of 0.25; the dedicated device permission orchestration stage has a weight of 0.2; the basic operation permission orchestration stage has a weight of 0.15; and the flexible adaptation permission orchestration stage has a weight of 0.1. The sum of these weight parameters is set to 1 to reflect the relative importance of different stages. For the second stage dimension, we set the corresponding standard execution parameters. These parameters correspond to the process of the second stage dimension and specifically include identity authentication compliance parameters and hierarchical matching standard parameters. For example, in the permission hierarchical review stage, the identity authentication compliance parameter is set to a face recognition pass rate of no less than 99%, and the hierarchical matching standard parameter can be set to a matching degree of no less than 100% between the permission level and the user's job level.

[0088] By combining the standard execution parameters and weight parameters of each stage, a weighted calculation is performed to obtain the standard permission orchestration index for each stage. The standard permission orchestration index = Σ (Stage standard execution parameter × corresponding stage weight parameter). Taking the core area permission orchestration stage as an example, if the identity authentication compliance parameter in the corresponding permission level review stage is 99% and the corresponding weight parameter is 0.3, and the level matching standard parameter is 100% and the corresponding weight parameter is 0.2, then the standard index for this stage in the permission level review process is 99% × 0.3 + 100% × 0.2 = 49.7%. Combining the parameters and corresponding weights of other second-stage dimensions, the complete standard permission orchestration index for the core area permission orchestration stage is obtained. This index will serve as the basis for subsequent evaluation of whether permission execution is compliant.

[0089] Based on the access control system's access control management and orchestration scheme, permissions are allocated and orchestrated, and user permission execution monitoring indicators are obtained during the access control orchestration process. Specifically, this includes the following steps:

[0090] Import the access control orchestration scheme into the intelligent access control platform;

[0091] The access control intelligent management platform obtains user permission execution feedback data, which includes user identity authentication data and hierarchy matching data;

[0092] Based on the user's identity authentication data, obtain the user's identity authentication behavior in the permission orchestration process; based on the user's hierarchical matching data, obtain the user's hierarchical matching behavior in the permission orchestration process.

[0093] The identity authentication behavior and the hierarchical matching behavior of the process constitute the actual execution behavior of the user in the permission orchestration process. The actual execution behavior of the process is marked as the permission execution monitoring indicator of the user in the permission orchestration process.

[0094] The access control orchestration scheme is imported into the intelligent access control platform. This platform is the core control carrier of the access control system, responsible for receiving, parsing, and executing rules related to access control. For example, the orchestration scheme, including core area permissions and regular time period permissions, is fully synchronized to the platform, allowing the platform to clearly define the execution standards and control requirements for each permission item.

[0095] The intelligent access control platform collects real-time feedback data on user access permissions during their use. This data primarily includes identity authentication data and hierarchical matching data. Identity authentication data is information generated when a user verifies their identity during access control, such as facial recognition image information and password input records. Hierarchical matching data is information on the user's job level and the corresponding level of permission requested. For example, if a user is a regular employee and requests access to a core area, the platform will record the correspondence between this job level and the permission.

[0096] The platform extracts actual execution behaviors during the extraction process. It parses the collected identity authentication data and hierarchical matching data, converting them into corresponding execution behaviors. For identity authentication data, the platform extracts the user's identity authentication behavior during the permission orchestration process. For example, if a user's facial recognition verification in the core area permission orchestration process takes 2 seconds and passes, this operation is marked as the identity authentication behavior for that stage. For hierarchical matching data, the platform extracts the hierarchical matching behavior during the process. For example, if a regular employee applies for core area permissions, the platform records the behavior where the job level and permission level do not match.

[0097] Finally, permission execution monitoring metrics are generated. The identity authentication behavior and the hierarchical matching behavior together constitute the user's actual execution behavior in the permission orchestration process. This actual execution behavior is directly marked as the user's permission execution monitoring metric for that permission orchestration process. For example, in the aforementioned core area permission orchestration process, the two behaviors—facial recognition verification taking 2 seconds and the mismatch between job level and permission level—jointly serve as the user's permission execution monitoring metric for that stage. Subsequently, the platform compares this metric with pre-set permission orchestration standard metrics to determine whether permission execution is compliant.

[0098] The user's permission execution performance is compared and judged against the corresponding permission orchestration standard indicators in the permission orchestration process. This includes the following steps:

[0099] The monitoring indicators for permission execution are compared and judged with the standard indicators for permission orchestration corresponding to the permission orchestration process.

[0100] If the permission execution monitoring indicators are inconsistent with the permission orchestration standard indicators corresponding to the permission orchestration stage, the user's permission execution behavior in the permission orchestration stage will be judged as non-compliant, and the permission execution monitoring indicators will be marked as non-compliant parameters of the stage.

[0101] Initiate a process to compare permission execution monitoring metrics with permission orchestration standard metrics. Permission execution monitoring metrics are the actual execution behavior data generated by users during the permission orchestration process, such as a 3-second face recognition verification time or a mismatch between job level and permission level in the core area permission orchestration process. Permission orchestration standard metrics, on the other hand, are pre-defined execution specifications for this stage, such as a face recognition verification time ≤ 2 seconds and a perfect match between job level and permission level in the core area permission process. Perform consistency checks on each dimension of these two types of metrics one by one.

[0102] The performance of permission execution is determined based on the comparison results. If the permission execution monitoring indicators are inconsistent with the corresponding permission orchestration standard indicators, the user's permission execution performance in that permission orchestration stage is directly judged as non-compliant. If the user's facial recognition in the core area permission stage takes 3 seconds, exceeding the standard indicator's 2-second limit, or if the user's job level does not match the core area permission level, the performance of that stage is judged as non-compliant if any of these inconsistencies occur.

[0103] Non-compliant monitoring indicators are marked. When an execution is determined to be non-compliant, the corresponding permission execution monitoring indicator is marked as a non-compliant parameter for the process. These parameters will serve as the core basis for subsequent calculation of process evaluation values ​​and comprehensive evaluation values. For example, two monitoring indicators, namely, a facial recognition time of 3 seconds and a mismatch between job level and permission level, are marked as non-compliant parameters for the core area permission arrangement process, facilitating subsequent quantitative evaluation of the user's permission usage.

[0104] The evaluation value of a user in the permission orchestration process is obtained based on the user's performance in executing permissions. This includes the following steps:

[0105] The number of non-compliant parameters corresponding to non-compliant parameters in the acquisition process;

[0106] The total number of standard parameters for the standard execution parameters corresponding to the permission orchestration stage;

[0107] The user's evaluation value in the permission arrangement process is obtained based on the total number of standard parameters and the number of non-compliant parameters.

[0108] To obtain the number of non-compliant parameters, first count the number of parameters marked as non-compliant in the permission orchestration process. For example, in the core area permission orchestration process, if there are two non-compliant situations, namely, face recognition taking longer than the standard and mismatch between job level and permission level, then the number of non-compliant parameters for this process is 2.

[0109] Extract the total number of standard execution parameters for the current permission orchestration stage. The standard execution parameters for a stage are the sum of all preset compliance judgment dimensions under that stage. For example, if the standard execution parameters for the core area permission orchestration stage include three items: face recognition time, identity information matching degree, and job level matching degree, then the total number of standard parameters for that stage is 3.

[0110] The evaluation value for each stage is calculated using the formula: Stage Evaluation Value = (Total Standard Parameters - Number of Non-compliant Parameters) ÷ Total Standard Parameters × 100. Taking the core area permission orchestration stage as an example, if the total number of standard parameters is 3 and the number of non-compliant parameters is 2, then the stage evaluation value is (3-2) ÷ 3 × 100 ≈ 33.33. This value directly reflects the user's compliance level in this permission orchestration stage; a higher value indicates a more compliant performance.

[0111] For example, if a user has 2 standard parameters and 0 non-compliant parameters in the permission arrangement process during a regular period, the evaluation value of the process is (2-0)÷2×100=100, which means that the process is fully compliant. If the number of non-compliant parameters is 1, the evaluation value of the process is 50, which means that half of the process is non-compliant.

[0112] Based on the evaluation value of each step, a comprehensive evaluation value for the user's access control orchestration scheme is obtained, which includes the following steps:

[0113] Obtain the corresponding stage weight parameters for the permission orchestration stage based on the first stage dimension;

[0114] The user's permission arrangement coefficient at each permission arrangement stage is obtained by weighting the stage evaluation value based on the stage weight parameter.

[0115] The user's overall evaluation value in the permission management and arrangement scheme is obtained by summing the permission arrangement coefficients of each permission arrangement stage.

[0116] The weight parameters for each permission orchestration stage are determined based on the first stage dimension, which is categorized according to the importance of permissions. For example, the core area permission orchestration stage is of high importance and its corresponding stage weight parameter is set to 0.3; the regular time period permission orchestration stage is set to 0.25; the dedicated device permission orchestration stage is set to 0.2; the basic operation permission orchestration stage is set to 0.15; and the flexible adaptation permission orchestration stage is set to 0.1. These weight parameters reflect the proportion of different stages in the overall permission management solution; the higher the importance of the stage, the larger the weight parameter.

[0117] The evaluation value of each permission orchestration stage is weighted according to the stage weight parameter to obtain the corresponding permission orchestration coefficient. The permission orchestration coefficient = stage evaluation value × stage weight parameter. For example, if a user's stage evaluation value in the core area permission orchestration stage is 33.33 and the corresponding stage weight parameter is 0.3, then the permission orchestration coefficient for this stage is 33.33 × 0.3 ≈ 10; if the user's stage evaluation value in the regular time period permission orchestration stage is 100 and the corresponding stage weight parameter is 0.25, then the permission orchestration coefficient for this stage is 100 × 0.25 = 25.

[0118] The overall evaluation value of a user within the entire permission management scheme is calculated by summing the permission orchestration coefficients of all stages. The overall evaluation value is calculated as Σ (permission orchestration coefficients for each stage). Taking a scheme that includes five stages—including flexible adaptation of basic operations on dedicated devices in core areas during regular hours—as an example, if the permission orchestration coefficients for each stage are 10, 25, 18, 15, and 8 respectively, then the overall evaluation value is 10 + 25 + 18 + 15 + 8 = 76. This value represents the overall performance across all stages; a higher value indicates a higher level of compliance with the entire permission management scheme.

[0119] For example, if a user has a low evaluation score in the core area but performs well in other areas, the overall evaluation score will reflect the overall balance result; if the evaluation scores of multiple high-weight areas are low, the overall evaluation score will also be lowered accordingly, which directly reflects the overall compliance level of the user's use of permissions.

[0120] Based on the comprehensive evaluation value, the user's access control permission usage results in the access control arrangement scheme are obtained.

[0121] First, a threshold range for the comprehensive evaluation value is pre-defined, with different ranges corresponding to different access control permission usage results. These thresholds are determined based on the security requirements and management rules of the access control system. For example, if the comprehensive evaluation value is ≥80, the corresponding permission usage result is that the permission is effective; if the comprehensive evaluation value is ≤60 and <80, the corresponding permission usage result is that the permission is adjusted; and if the comprehensive evaluation value is <60, the corresponding permission usage result is that the permission is frozen.

[0122] The system matches a user's overall assessment score against these threshold ranges to determine the corresponding access control permission usage results. For example, if a user's overall assessment score is 90, falling within the ≥80 range, their access control permissions are effective, meaning the user can normally use all access control permissions configured in the access control management orchestration scheme. If the overall assessment score is 70, since 70 falls within the 60 to 80 range, the corresponding result is permission adjustment, which reduces the user's permission range; for example, previously held core area permissions may be temporarily restricted to being available only during working hours. If the overall assessment score is 50, since 50 is below 60, the corresponding result is permission freeze; the system suspends all access control permissions for the user until they complete the rectification of their access control usage specifications and pass the assessment again.

[0123] If a company's access control system is configured such that a comprehensive evaluation value ≥90 grants active permissions and allows for flexible access requests, 80-89 grants active permissions but restricts flexible access, 70-79 allows for permission adjustments, and below 70 grants frozen permissions, then an employee with a comprehensive evaluation value of 92 can not only use fixed permissions normally but also apply for flexible temporary visitor permissions. If their comprehensive evaluation value is 75, their permissions will be adjusted to only allow use of regular hours and basic operations, and permissions for core areas and dedicated devices will be temporarily revoked.

[0124] By directly linking the comprehensive evaluation value to the permission usage result in this way, the security control of the access control system can be guaranteed, and the permission status can be flexibly adjusted according to the actual performance of the user, thus realizing dynamic adaptation of permission management.

[0125] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0126] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0127] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A multi-access control system method, characterized in that, The method includes the following steps: Mark the fixed permission management items of the fixed permission module and the flexible permission management items of the flexible permission module in the access control system as permission items to be arranged; The target permission dynamic adjustment threshold and the number of associated hierarchical levels are processed to obtain the set of possible adjustment combinations and the set of possible hierarchical combinations; The target permission combination set is obtained by analyzing the set of potential adjustment combinations and the set of potential hierarchical combinations. A permission management orchestration scheme is then constructed based on this target permission combination set. The permission management orchestration scheme includes at least one permission orchestration step, each with corresponding permission orchestration standard indicators. Specifically, it includes the following steps: The permission items to be orchestrated based on the permission management orchestration scheme constitute the permission orchestration stage of the permission management orchestration scheme; The permission orchestration process includes at least one process dimension; wherein, the process dimension includes a first process dimension and a second process dimension; Based on the first stage dimension, set the stage weight parameters corresponding to the permission orchestration stage in the permission management orchestration scheme. The stage weight parameters correspond to the first stage dimension. Based on the second stage dimension, set the corresponding stage standard execution parameters for the permission orchestration stage. The stage standard execution parameters correspond to the second stage dimension. Based on the standard execution parameters and weight parameters of each stage, the permission orchestration standard indicators corresponding to each stage are generated; among them, the standard execution parameters of each stage include identity authentication compliance parameters and hierarchical matching standard parameters; Based on the access control system's access control management and orchestration scheme, permissions are allocated and orchestrated, and user permission execution monitoring indicators are obtained during the access control orchestration process. Specifically, this includes the following steps: Import the access control orchestration scheme into the intelligent access control platform; The access control intelligent management platform obtains user permission execution feedback data, which includes user identity authentication data and hierarchy matching data; Based on the user's identity authentication data, obtain the user's identity authentication behavior in the permission orchestration process; based on the user's hierarchical matching data, obtain the user's hierarchical matching behavior in the permission orchestration process. The identity authentication behavior and the hierarchical matching behavior of the process constitute the actual execution behavior of the user in the permission orchestration process. The actual execution behavior of the process is marked as the permission execution monitoring indicator of the user in the permission orchestration process. By comparing the permission execution monitoring indicators with the corresponding permission orchestration standard indicators in the permission orchestration process, the user's permission execution performance in the permission orchestration process can be obtained. Based on the user's performance in the permission execution process, obtain the user's evaluation value in the permission orchestration stage; based on the stage evaluation value, obtain the user's overall evaluation value in the permission management orchestration scheme. Based on the comprehensive evaluation value, the user's access control permission usage results in the access control arrangement scheme are obtained.

2. The multi-access control system management method according to claim 1, characterized in that, The target permission dynamic adjustment threshold and the number of associated hierarchical levels are processed to obtain a set of candidate adjustment combinations and a set of candidate hierarchical combinations. The specific steps include: Based on the set target permission dynamic adjustment threshold, a set of permission adjustment combinations for the permission items to be arranged is obtained. Based on the total number of permission association levels of the permission items to be arranged in the permission adjustment combination set, the adjustment combination coefficient corresponding to the permission adjustment combination set is obtained. Based on the adjustment combination coefficient, a set of candidate adjustment combinations is obtained. Based on the set target permission association level, a permission level combination set of permission items to be arranged is obtained. Based on the total permission adjustment range of the permission items to be arranged in the permission level combination set, the level combination coefficient corresponding to the permission level combination set is obtained. Based on the level combination coefficient, a candidate level combination set is obtained.

3. The multi-access control system management method according to claim 1, characterized in that, The fixed permission module includes a core area fixed permission unit, a regular time period fixed permission unit, a dedicated device fixed permission unit, and a basic operation fixed permission unit. The fixed access management items include fixed access management items for core areas, fixed access management items for regular time periods, fixed access management items for dedicated devices, and fixed access management items for basic operations.

4. The multi-access control system management method according to claim 1, characterized in that, The target permission combination set is obtained by analyzing the set of potential adjustment combinations and the set of potential hierarchical combinations. A permission management orchestration scheme is then constructed based on this target permission combination set, specifically including the following steps: Set adjustment weights and hierarchical weights; Based on the adjustment weights and hierarchical weights, the combination arrangement coefficients corresponding to the candidate adjustment combination set and the candidate hierarchical combination set are obtained; The target permission combination set is obtained based on the combination arrangement coefficient, and the permission management arrangement scheme is formed based on the permission items to be arranged in the target permission combination set.

5. The multi-access control system management method according to claim 4, characterized in that, The user's permission execution performance is compared and judged against the corresponding permission orchestration standard indicators in the permission orchestration process. This includes the following steps: The monitoring indicators for permission execution are compared and judged with the standard indicators for permission orchestration corresponding to the permission orchestration process. If the permission execution monitoring indicators are inconsistent with the permission orchestration standard indicators corresponding to the permission orchestration stage, the user's permission execution behavior in the permission orchestration stage will be judged as non-compliant, and the permission execution monitoring indicators will be marked as non-compliant parameters of the stage.

6. The multi-access control system management method according to claim 5, characterized in that, The evaluation value of a user in the permission orchestration process is obtained based on the user's performance in executing permissions. This includes the following steps: The number of non-compliant parameters corresponding to non-compliant parameters in the acquisition process; The total number of standard parameters for the standard execution parameters corresponding to the permission orchestration stage; The user's evaluation value in the permission arrangement process is obtained based on the total number of standard parameters and the number of non-compliant parameters.

7. A multi-access control system management method according to claim 6, characterized in that, Based on the evaluation value of each step, a comprehensive evaluation value for the user's access control orchestration scheme is obtained, which includes the following steps: Obtain the corresponding stage weight parameters for the permission orchestration stage based on the first stage dimension; The user's permission arrangement coefficient at each permission arrangement stage is obtained by weighting the stage evaluation value based on the stage weight parameter. The user's overall evaluation value for the permission management arrangement scheme is obtained by summing the permission arrangement coefficients of each permission arrangement stage.

8. A multi-access control system management method according to claim 5, characterized in that, The first dimension includes the core area permission arrangement stage, the regular time period permission arrangement stage, the dedicated device permission arrangement stage, the basic operation permission arrangement stage, and the flexible adaptation permission arrangement stage; The second dimension includes the permission initialization stage, the permission association configuration stage, the permission level review stage, the permission dynamic adjustment stage, and the permission expiration and cancellation stage.

Citation Information

Patent Citations

  • Method and system for authorization linkage of work ticket handling system and access control system

    CN117935413A

  • Method and system for dynamically adjusting user permission based on multi-dimensional perception

    CN120805158A

  • Permission dynamic management system based on integrated system

    CN120822234A