Usage permission management and control processing method and system based on data element right confirmation

By identifying related data elements in power trading data and calculating overlap coefficients, the authority responsible for access control can be determined. Static or dynamic access control strategies can be adopted to address the risk of data leakage caused by overlap in access control of power trading data, thereby improving data security and concealment.

CN121502784APending Publication Date: 2026-02-10STATE GRID HENAN INFORMATION & TELECOMM CO
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202511668665.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-14
Publication Date
2026-02-10

AI Technical Summary

Technical Problem

Existing technologies for access control of power trading data present significant risks of leakage due to overlapping encryption methods, making it difficult to effectively manage access control of data elements with other institutions.

Method used

By identifying the related data elements between institutions, calculating the overlap coefficient, determining the authority for access control, and based on the overlap and data volume, adopting static or dynamic access control strategies to dynamically adjust permissions and reduce the risk of leakage of overlapping data.

Benefits of technology

This approach reduces the difficulty of dynamically adjusting permissions while enhancing data security, minimizing the risk of data leakage between permission control agencies, and ensuring data confidentiality and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121502784A_ABST
    Figure CN121502784A_ABST
Patent Text Reader

Abstract

The invention provides a use permission control processing method and system based on data element right confirmation, and belongs to the technical field of permission management. The method specifically comprises the following steps: removing the coincidence condition of mechanisms except a permission control mechanism and associated data elements of the permission control mechanism; when it is determined that dynamic adjustment processing of the permissions of the mechanisms except the permission control mechanisms needs to be carried out, determining distribution data of associated data elements in the mechanisms in different permission control mechanisms, and determining permission adjustment targets in the mechanisms according to the distribution data; according to the invention, the permission adjustment control method of different permission adjustment targets is determined according to the association condition between the permission adjustment target data and the permission management and control mechanism of the permission management and control strategy of the target, and the data security is improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the technical field of authority management, and particularly relates to a use authority management and control processing method and system based on data element right confirmation. BACKGROUND

[0002] In the process of power transaction, power transaction data is crucial for government agencies, credit institutions and consulting institutions. Due to the privacy requirement of power transaction data, once it is leaked, it will cause great risk. Therefore, how to determine the use authority management and control processing scheme according to the identification processing result of the data elements of the power transaction in the target institution to ensure the concealment of the data elements becomes a technical problem to be solved.

[0003] In view of the above problems, in the invention patent application CN202510756376.3 "A blockchain security verification system and method for data element circulation", the user's on-chain frequency, delay and data entry are collected through a sliding time window, a standardized matrix is constructed and a risk state is clustered and determined, and when the risk is high, security verification is started. Combined with the user's identity and behavior characteristics, the data reliability is comprehensively evaluated, and dynamic authority adjustment is performed according to the interval, realizing the safety and data credibility control of the blockchain system, but there are the following defects: When performing data element security management and control processing, in order to improve the security of the data elements with high coincidence degree with other institutions, a dynamic adjustment encryption mode is adopted to improve the data security, but at the same time, how to determine the authority management and control processing method of other institutions which have the same data elements with the institution of dynamic adjustment encryption mode, so as to avoid the occurrence of the technical problem of excessive leakage risk caused by the coincidence of the dynamic adjustment encryption mode between the authority management and control institutions.

[0004] To solve the above technical problems, the application provides a use authority management and control processing method and system based on data element right confirmation. SUMMARY

[0005] To achieve the purpose of the application, the application adopts the following technical solutions: Specifically, the application provides a use authority management and control processing method based on data element right confirmation, which specifically comprises: S1 determining the associated data elements of the institution with the right confirmation result of the data elements in different institutions, determining the authority management and control institution and the authority management and control strategy of the institution according to the coincidence between the associated data elements of the institution and other institutions, removing the coincidence of the associated data elements of the institution and the authority management and control institution except the authority management and control institution, and determining the dynamic adjustment processing of the authority of the institution except the authority management and control institution, and then entering the next step. S2 determines distribution data of the associated data elements in the mechanism in different permission control mechanisms, determines a permission adjustment target in the mechanism according to the distribution data, determines a permission adjustment control method of different permission adjustment targets according to the permission adjustment target data and the association between the permission control mechanisms and the target permission control strategies.

[0006] The application has the following beneficial effects: The coincidence of the associated data elements between the mechanism except the permission control mechanism and the permission control mechanism is determined, and it is determined whether the dynamic adjustment processing of the permission of the mechanism except the permission control mechanism is needed, so that the number of the permission control mechanisms performing the dynamic adjustment processing of the encryption mode and the coincidence of the data elements between the mechanism except the permission control mechanism and the permission control mechanism are considered to perform the risk assessment processing of data leakage, and the dynamic adjustment processing of the permission of the mechanism except the permission control mechanism is performed in the case of a larger leakage risk, and the data security is further improved.

[0007] The permission adjustment control method in different permission adjustment targets is determined according to the permission adjustment target data and the association between the permission control mechanisms and the target permission control strategies, so that the difference in the difficulty of the dynamic adjustment processing of the permission caused by the number of the permission adjustment targets is considered, and the association between the data elements of the permission control mechanisms performing the dynamic adjustment processing of the encryption mode is further combined to determine the permission adjustment control method of the permission adjustment target from two aspects of the difficulty of the adjustment processing and the leakage risk, and the data security is further improved on the basis of reducing the difficulty of the dynamic adjustment processing of the permission.

[0008] Further, the associated data elements of the mechanism are data elements that the mechanism has access to.

[0009] Further, the mechanism includes government agencies, credit institutions and consulting institutions.

[0010] Further, the method for determining the permission control mechanism in the mechanism is: The associated data elements that coincide with other mechanisms are determined according to the coincidence of the associated data elements of the mechanism and other mechanisms, and the associated data elements are taken as the coincidence data elements; The coincidence coefficient of the data elements between the mechanism and other mechanisms is determined according to the coincidence data elements between the mechanism and other mechanisms; The mechanism is determined to be a permission control mechanism based on the coincidence coefficient of the data elements between the mechanism and other mechanisms.

[0011] Further, the method for determining the permission adjustment control method of the permission adjustment target is: determine the number of the permission adjustment targets based on the permission adjustment target data; determine the risk mechanism belonging to dynamic permission control among the permission control mechanisms according to the association between the permission control mechanisms and the permission control policy of the target, and take it as a dynamic control mechanism; determine the permission adjustment control method of the permission adjustment target according to the number of the permission adjustment targets and the coincidence of the association data elements between the permission adjustment targets and different dynamic control mechanisms.

[0012] In a second aspect, the present application provides a computer system, comprising a memory and a processor connected in communication, and a computer program stored on the memory and capable of running on the processor, wherein the processor executes the computer program to perform the above-mentioned use permission control processing method based on data element right.

[0013] Other features and advantages will be set forth in the descriptions that follow, and in part will be apparent from the description, or can be learned by practice of the application. The purposes and other advantages of the application will be realized and attained by the structure particularly pointed out in the written description and claims.

[0014] In order to make the above objectives, features and advantages of the present application more apparent, the following will specifically describe a preferred embodiment, and combine with the accompanying drawings, and make a detailed description as follows. BRIEF DESCRIPTION OF DRAWINGS

[0015] The above and other features and advantages of the present application will become more apparent by describing in detail exemplary embodiments thereof with reference to the attached drawings.

[0016] Figure 1 is a flowchart of a use permission control processing method based on data element right; Figure 2 is a flowchart of a method for determining the permission control mechanism in the mechanism; Figure 3 is a flowchart of a method for determining the permission control policy of the permission control mechanism. DETAILED DESCRIPTION

[0017] Example embodiments now will be described more fully hereinafter with reference to the accompanying drawings. Example embodiments, however, can be implemented in many different forms and should not be construed as limited to the implementations set forth herein; rather, these implementations are provided as example embodiments so that this disclosure will be thorough and complete, and will fully convey the scope thereof to those skilled in the art. Like reference numerals refer to like elements throughout the several views of the drawings, and thus description of the same will be simplified or omitted.

[0018] The terms "one", "a", "an", "the", "said", are used to denote the presence of one or more elements / components / etc.; the terms "include" and "have" are used to indicate an open-ended inclusion and refer to additional elements / components / etc. that can be present in addition to the listed elements / components / etc.

[0019] Embodiment 1 To solve the above problems, according to one aspect of the present application, as shown in the accompanying drawings, a specific use permission control processing method based on data element right is provided, and the present application provides a use permission control processing method based on data element right, which specifically comprises: Figure 1 S1, determining the associated data elements of the institution in different institutions according to the right of the data elements, determining the permission control institution and the permission control strategy in the institution according to the coincidence of the associated data elements of the institution and other institutions, removing the coincidence of the associated data elements of the institutions other than the permission control institution and the permission control institution, and determining the dynamic adjustment processing of the permission of the institutions other than the permission control institution, and entering the next step; S2, determining the distribution data of the associated data elements in different permission control institutions in the institution, determining the permission adjustment target in the institution according to the distribution data, and determining the permission adjustment control method in different permission adjustment targets according to the associated data of the permission adjustment target data and the permission control strategy of the target.

[0020] Further, the associated data elements of the institution are data elements that the institution has access to.

[0021] Further, the institution includes government agencies, credit institutions and consulting institutions.

[0022] Further, as shown in the accompanying drawings, the method for determining the permission control institution in the institution is: Figure 2 S11, determining the associated data elements that exist in coincidence with other institutions according to the coincidence of the associated data elements of the institution and other institutions, and taking them as coincidence data elements; Associated data elements: refer to specific business data that an institution is authorized to access in the power transaction chain according to its functions, contracts or regulations. For example, institution 2 has the right to access the electricity revenue right pledge contract because it uses it as the basis for lending. In the above steps, the cornerstone of data sharing relationship is built. By identifying the coincidence elements, the potential data interface and dependency relationship between institutions can be clearly defined. For example, it is identified that institution 1 and institution 2 both focus on "renewable energy enterprises", which is the first step to promote green financial cooperation.

[0023] In the above steps, the cornerstone of data sharing relationship is built. By identifying the coincidence elements, the potential data interface and dependency relationship between institutions can be clearly defined. For example, it is identified that institution 1 and institution 2 both focus on "renewable energy enterprises", which is the first step to promote green financial cooperation. In the above steps, the cornerstone of data sharing relationship is built. By identifying the coincidence elements, the potential data interface and dependency relationship between institutions can be clearly defined. For example, it is identified that institution 1 and institution 2 both focus on "renewable energy enterprises", which is the first step to promote green financial cooperation.

[0024] Take institution 1 as the target institution, and compare it with institution 2 and institution 3 respectively. The coincident data elements of institution 1 and institution 2 are: Comparison: The power generation enterprise license number of institution 1 and the enterprise unified social credit code of institution 2 can be associated with the same power generation enterprise. The renewable energy portfolio standard (RPS) completion amount and subsidy issuance status of institution 1 are directly related to the value and security of the electricity bill rights held by institution 2.

[0025] Coincidence result: [enterprise identification (license number / credit code), renewable energy related data (quota, subsidy)]. These are data that both are concerned about and can be associated.

[0026] Coincident data elements of institution 1 and institution 2: Comparison: The enterprise name of institution 2 can be associated with the power generation enterprise license number or power purchase subject record number of institution 1 to the same market subject. The unit output performance data analysis done by institution 2 for customers may be related to the compliance audit records of institution 1.

[0027] S12 determines the coincidence coefficient of data elements between the target institution and other institutions according to the coincident data elements between them; Step S12: Determine the coincidence coefficient of data elements. Coincidence coefficient: a quantitative index for accurately measuring the degree of data association between the target institution and another institution. The calculation formula is: (the number of records covered by the data elements coinciding with the target institution) / (the total number of data records of another institution).

[0028] Convert the qualitative relationship in S11 into a measurable numerical value. This avoids subjective judgments of "feeling very coincident" and provides an objective and fair basis for subsequent decision-making of authority control institutions. In the field of power trading, which has very high requirements for data accuracy, quantitative analysis is crucial.

[0029] Example (S12): Data volume (in enterprise or transaction record number) needs to be introduced for calculation. The total data volume of the credit institution (institution 2) is: Institution 2 provides credit services for 500 power-related enterprises, and the total data volume of institution 2 is 500 enterprise records.

[0030] The coincident data volume of institution 1 and institution 2: Institution 1's database contains power trading data for 450 of the 500 enterprises, and the coincident data volume is 450 records. Calculate the coincidence coefficient of institution 1 to institution 2: Coincidence coefficient (institution 1 -> institution 2) = 450 / 500 = 0.90 S13 determines whether the institution is an authority control institution based on the coincidence coefficient of data elements between the target institution and other institutions.

[0031] Specifically, this step determines the access control organization based on the overlap coefficient. The maximum overlap coefficient is the largest among the overlap coefficients calculated between the target organization and all other organizations. It represents the "broadest" extent of the target organization's data coverage.

[0032] Preset overlap threshold: A threshold value (e.g., 0.7) pre-set by the management committee or security policy. It defines the minimum level of data coverage required to become an access control authority.

[0033] This is the final automated decision-making stage. Through a simple rule of "finding the maximum value" and "comparing it to a threshold," the system can unambiguously identify the core hubs within the entire power trading data network. This ensures that data governance responsibility is assigned to the institution with the greatest global influence, thereby achieving effective and unified security control.

[0034] In a specific embodiment, for the target institution (institution 1), the overlap coefficient (institution 1 -> institution 2) is 0.90, and the overlap coefficient between institution 1 and institution 2 is 0.7. Then, it is compared with the preset threshold and determined: Assuming that according to the regulations on the security management of power transaction data, the preset overlap coefficient threshold is 0.75, the determination is: the maximum value (0.9) > the threshold (0.75). The final conclusion is: institution 1 is determined to be an access control institution.

[0035] Access control agency: In the complex power trading data sharing network, this is the agency identified as being at the core of data convergence. It needs to be given more stringent access control measures to ensure the security, compliance, and consistency of data when it flows across agencies.

[0036] It should be noted that the overlap coefficient of data elements between the institution and other institutions is determined based on the proportion of the data volume of the overlapping data elements in the related data volume of the other institutions.

[0037] It is understandable that determining whether an organization is an access control organization is based on the overlap coefficient of its data elements with those of other organizations, specifically including: Determine the maximum value of the overlap coefficient between data elements and other institutions based on the overlap coefficient between data elements and other institutions. The institution is determined to be an access control institution based on the maximum value of the overlap coefficient of data elements between it and other institutions.

[0038] It is understood that when the maximum value of the overlap coefficient of data elements between the institution and other institutions is greater than the preset overlap coefficient threshold, the institution is determined to be an access control institution.

[0039] Specifically, such as Figure 3 As shown, the method for determining the access control strategy of the access control organization is as follows: S21 determines the data volume of the associated data elements in the access control organization based on the associated data elements in the access control organization; In the steps described above, the data volume of related data elements within the access control organization is determined. The data volume of related data elements refers to the total number of all data records owned by the access control organization. These records contain all data entities generated, collected, and managed by the organization in its business operations.

[0040] This step is fundamental to assessing the complexity and security requirements of data management. The size of the data directly determines the scale and cost of data management, and is the first objective indicator to consider when selecting an access control strategy.

[0041] Example: Organization 1, acting as the access control organization, counts the total number of records in all data tables in its database. The count shows that Organization 1 has 20,000 valid data records, which include various data elements such as basic enterprise information, transaction records, and audit logs.

[0042] S22 determines the proportion of data elements belonging to overlapping data elements in the access control organization based on the overlapping data elements with other organizations, and uses it as an overlap correlation factor. The overlap factor specifically refers to the proportion of records containing data elements that overlap with those of other organizations within an access control organization, out of the organization's total data volume. It reflects the "outward orientation" of the organization's data and provides a key basis for selecting access control strategies by quantifying the degree of data sharing. A higher overlap factor indicates more frequent data interaction between the organization and the outside world, requiring a more flexible access control mechanism.

[0043] Example: In the 20,000 total records of Institution 1, data elements that overlap with those of Institution 2 and Institution 3 were identified. It was found that 19,000 records contained data elements that overlapped with those of other institutions (such as enterprise identification codes, transaction numbers, etc.). The overlap correlation factor was calculated as: 19,000 ÷ 20,000 = 0.95. This means that 95% of the data in Institution 1 is shared with other institutions.

[0044] S23 determines the access control strategy of the access control agency based on the overlap correlation factor of the access control agency, the data volume of the associated data elements, and the overlap coefficient of the data elements with other agencies.

[0045] It is understood that, based on the overlap and correlation factors of the access control agency, the data volume of related data elements, and the overlap coefficient of data elements with other agencies, the access control agency's access control strategy is determined, specifically including: S231 Obtain the data volume of the associated data elements in the permission control organization, and determine whether the data volume of the associated data elements in the permission control organization is greater than the preset data volume threshold. If yes, proceed to the next step; if no, determine that the permission control strategy of the permission control organization is static permission control, that is, fixedly adopting multiple permission restriction schemes to control permissions. In the above steps, a data volume threshold is determined. This involves comparing the organization's actual data volume with a preset scale standard to determine whether a higher level of security protection is needed. If the data volume is too small, there is no need or significance for access control. This establishes a basic threshold for data management to ensure that large-scale data receives the necessary security protection.

[0046] In one specific embodiment, a preset data volume threshold of 10,000 records is set, and the actual data volume of Organization 1 is 20,000 records. The determination is made that 20,000 > 10,000, and then proceeds to the next step of the determination.

[0047] S232 obtains the overlap correlation factor of the permission control agency, and determines whether the overlap correlation factor of the permission control agency is greater than the preset correlation factor threshold. If so, the permission control strategy of the permission control agency is determined to be static permission control, that is, dynamic use of multiple permission restriction schemes to control permissions. If not, proceed to the next step. In the above steps, the correlation factor threshold judgment is to compare the actual overlapping correlation factors with the preset standards to assess whether the degree of data sharing of an institution has reached the level that requires dynamic control, identify institutions that are highly dependent on data sharing, and ensure that they adopt appropriate security strategies.

[0048] Example: Preset correlation factor threshold: 0.85, actual overlap correlation factor of organization 1: 0.95, judgment: 0.95>0.85, then determine to adopt dynamic permission control strategy.

[0049] S233 uses the overlap coefficient of data elements between the permission control agency and other agencies to determine the number of other agencies whose overlap coefficient is within a preset overlap coefficient range. It then determines whether the number of other agencies whose overlap coefficient is within the preset overlap coefficient range is greater than a preset agency number threshold. If so, it determines that the permission control strategy of the permission control agency is static permission control, that is, dynamically adopting multiple permission restriction schemes to control permissions. If not, it proceeds to the next step. Specifically, the number of highly related institutions is determined by the number of cooperative institutions whose data overlap with that of the statistics and access control institutions reaches a certain standard, thus assessing the complexity of data sharing from the perspective of the breadth of cooperation.

[0050] Example: Preset overlap coefficient range: [0.3, 1.0], preset threshold for the number of institutions: 10, statistics: Institution 2 (0.7) and Institution 3 (0.6) both fall within the range → 2 institutions. At this time, the number of overlapping institutions is small, so it is determined to proceed to the next step.

[0051] S234 Based on the maximum value of the data overlap coefficient between the permission control agency and other agencies, and based on the average value of the overlap correlation factor of the maximum value and the permission control agency, determine whether the average value is greater than a preset threshold. If so, determine that the permission control strategy of the permission control agency is static permission control, that is, dynamically adopting multiple permission restriction schemes for permission control processing. If not, determine that the permission control strategy of the permission control agency is static permission control, that is, fixedly adopting multiple permission restriction schemes for permission control processing.

[0052] Specifically, the comprehensive indicator assessment is conducted by calculating the maximum value of the overlap coefficient and the average value of the overlap correlation factors to perform a final comprehensive security assessment. This enables a comprehensive assessment and processing of the overlap risk of the access control agency itself and its correlation with other agencies, providing a basis for final security decision-making and ensuring the comprehensiveness and accuracy of the decision.

[0053] In one possible specific embodiment, assume the calculated average value is (0.7 + 0.95) ÷ 2 = 0.825, and the preset threshold is 0.8. Therefore, dynamic permission control will be selected.

[0054] It is understood that the static permission control includes using multiple encryption methods to encrypt data elements in a fixed manner, thereby realizing permission control measures. The dynamic permission control, in addition to the encryption methods of the static permission control, also needs to introduce other encryption algorithms for dynamic use. Each time, two or more encryption methods are randomly used and adjusted in combination with the encryption methods of the static permission control.

[0055] For example, static access control uses AES and RSA in tandem to encrypt data elements. In addition to the above methods, dynamic access control also needs to introduce encryption methods such as SHA-256 and ECC. By combining dual encryption methods, one or more of the encryption methods such as SHA-256 and ECC can be dynamically introduced for collaborative encryption processing.

[0056] Specifically, when Institution 1 obtains data from the power trading center, it consistently follows this process: encrypting the data using the AES-256 algorithm, encrypting the AES key using the RSA public key, and then packaging and transmitting the encrypted data and key together. This consistent process is strictly followed for each transmission.

[0057] Dynamic permission control implementation example Definition: Dynamic access control refers to the dynamic combination of various encryption algorithms and security measures, which are randomly applied on top of basic security measures.

[0058] Implementation Example: Scenario 1: Introducing integrity verification, the system randomly selects the SHA-256 hash algorithm for enhancement. Transmission process: Perform basic AES+RSA encryption, calculate the SHA-256 hash value of the original data, and transmit the encrypted data, encryption key, and hash value together. Result: The receiver can verify data integrity through the hash value. Scenario 2: The system randomly selects the ECC algorithm for enhancement. Transmission process: Perform basic AES+RSA encryption, then use the ECC algorithm to encrypt the AES key a second time. Transmit the encrypted data along with the double-encrypted key. Effect: Provides a higher level of key protection. Through this dynamically changing access control strategy, Organization 1 can provide unique security protection for each data interaction, greatly improving the overall security of the system.

[0059] Specifically, this involves determining whether dynamic adjustments to the permissions of organizations other than those responsible for access control are necessary. This includes: S31. Other institutions, excluding the authority control agency, are designated as other institutions. Based on the overlap of the associated data elements between the other institutions and the authority control agency, other institutions with associated data elements of the authority control agency are identified and designated as associated institutions. Related organizations refer to other organizations in the data network that share data elements with any access control organization, excluding the access control organization that serves as the core of the perspective (organization P1 in this example).

[0060] This step aims to identify all participants throughout the access control network. This forms the basis for a comprehensive risk assessment, and only entities associated with the access control network need to be included in the monitoring and adjustment efforts.

[0061] Scenario Setting and Prerequisites: Access Control Organizations: Organizations P1, P2, P3, P4, P5, P6, P7, P8, P9, P10 (all have been identified as access control organizations), Other Organizations: Organizations A, B, C, D, E, F, G, H, I, J, Core Access Control Organization (from the perspective of this process): Organization P1, Control Strategies of Each Access Control Organization: Dynamic Access Control Organizations: P1, P2, P3, P4, P5, P7, P9 (7 in total), Static Access Control Organizations: P6, P8, P10 (3 in total); Preset thresholds: Preset threshold for the number of risky institutions: 3, Preset threshold for the number of related institutions: 6, Preset threshold for the number of institutions (S334): 2.

[0062] In one possible embodiment, the other set of agencies is: [Agencies A, B, C, D, E, F, G, H, I, J] Determination Process: The data elements of each institution are compared with those of the core institution (P1). Institutions A, B, C, D, E, F, and G have overlapping data elements with P1 (such as electricity trading contract IDs and market participant codes). Institutions H, I, and J have no overlapping data with P1. Therefore, the associated institutions are determined as: [Institutions A, B, C, D, E, F, G]. Institutions H, I, and J are excluded.

[0063] S32 Based on the overlap of associated data elements between the associated institutions and the authority control institutions, determine the authority control institutions with overlapping associated data elements among the associated institutions, and designate them as risk institutions; Risky institutions refer to those institutions within the access control system that share data elements with related institutions. These institutions are the access control nodes that actually exchange data within the network.

[0064] This step is used to identify the access control nodes that actually participate in data exchange in the network, laying the foundation for subsequent assessment of the risk characteristics of these nodes.

[0065] Specifically, the set of access control institutions is: [P1, P2, P3, P4, P5, P6, P7, P8, P9, P10]. The determination process is as follows: check whether each access control institution has data overlap with the set of related institutions [A, B, C, D, E, F, G]. P2, P3, P5, P7, and P9 have data overlap with multiple related institutions, while P1, P4, and P6 have data overlap with a few related institutions. The risk institutions are determined as: [P1, P2, P3, P4, P5, P6, P7, P9] (a total of 8). Based on the data of the associated institutions and the permission restriction scheme of the risk institutions, S33 determines whether it is necessary to dynamically adjust the permissions of institutions other than the permission control institution.

[0066] It is understandable that, based on the data of the associated institutions and the access control scheme of the risk institutions, it is determined whether dynamic adjustment of the permissions of institutions other than the access control institution is required, specifically including: S331 Based on the permission restriction scheme of the risk institution, determine the risk institution with dynamic permission control, and determine whether there is a risk institution with dynamic permission control. If yes, proceed to the next step; if no, determine that it is not necessary to perform dynamic adjustment of the permissions of institutions other than the permission control institution. Specifically, determining whether there are risky organizations with dynamic access control involves identifying individuals within those organizations that employ dynamic access control strategies. Dynamic access control strategies are inherently more complex and variable, and when multiple such strategies coexist on the same network, the likelihood of mutual interference and conflicts is far higher than with static strategies.

[0067] Significance of this step: This is the first step in risk identification. If such an institution does not exist, the network structure is relatively simple and no global adjustment is required. If it does exist, it means that a high-risk assessment process has begun.

[0068] Specifically, the risk institution set is: [P1, P2, P3, P4, P5, P6, P7, P9]. Check their permission policies: dynamic permission control: P2, P3, P5, P7, P9; static permission control: P1, P4, P6. At this point, there are risk institutions with dynamic permission control. Proceed to the next step S332.

[0069] S332 obtains the number of risky organizations under dynamic access control, and determines whether the number of risky organizations under dynamic access control is greater than the preset threshold for the number of risky organizations. If so, it is determined that dynamic adjustment of the permissions of organizations other than those under access control is required. If not, proceed to the next step. Specifically, determining the number of dynamic risk institutions quantifies the scale of institutions managing dynamic access control risks. Quantity is a key indicator for measuring risk complexity.

[0070] A single dynamic risk agency may be managed through bilateral consultations, but multiple such agencies will create a complex situation of "multiple power centers," which is very likely to lead to policy conflicts, thus requiring a global adjustment of authority to unify and coordinate.

[0071] Example: Risk institutions with dynamic access control: [P2, P3, P5, P7, P9], quantity: 5, preset risk institution quantity threshold: 4, then it is determined that dynamic adjustment of the permissions of institutions other than the access control institutions is required.

[0072] S333 obtains the number of associated institutions and determines whether the number of associated institutions is greater than a preset threshold for the number of associated institutions. If so, it is determined that dynamic adjustment of the permissions of institutions other than the permission control institution is required. If not, proceed to the next step. This step determines the number of associated organizations and assesses the scale of the entire data network. The more associated organizations there are, the more complex the data interaction paths become, and the more difficult access control becomes.

[0073] Even if there aren't many dynamic risk entities, if the network itself is very large (with numerous associated entities), then any risk point may have an amplified effect through complex network paths, thus requiring a global adjustment to ensure overall security.

[0074] Specifically, the associated organization set is [A, B, C, D, E, F, G], with a quantity of 7. The preset threshold for the number of associated organizations is 5. If this step is executed, adjustments will also be triggered.

[0075] S334 obtains the number of associated institutions that have overlapping associated data elements with the risk institution belonging to dynamic access control, and determines whether the average number of associated institutions with overlapping associated data elements with the risk institution belonging to dynamic access control is greater than a preset number threshold. If so, it is determined that dynamic adjustment processing of the permissions of institutions other than the access control institution is required; otherwise, it is determined that dynamic adjustment processing of the permissions of institutions other than the access control institution is not required.

[0076] Specifically, to determine the average breadth of association of risk institutions, this step calculates the "influence" or "breadth of association" of each dynamic risk institution in the network of associated institutions, that is, how many other associated institutions each risk institution has data overlap with on average.

[0077] This is the most sophisticated risk assessment. It identifies risk entities that are not only risk points themselves, but also occupy pivotal positions throughout the network and have a wide-ranging impact. Even if their number is small, their extensive influence is sufficient to justify initiating a global adjustment.

[0078] Example: Dynamic risk institutions: [P2, P3, P5, P7, P9], number of associated institutions for each institution: P2 association: [A, B, C, D] → 4, P3 association: [A, C, E, F] → 4, P5 association: [B, D, G] → 3, P7 association: [C, E, F, G] → 4, P9 association: [A, B, F] → 3.

[0079] Calculate the average value: (4+4+3+4+3) / 5 = 18 / 5 = 3.6. The preset quantity threshold is 3. Therefore, if this step is executed, the adjustment will also be triggered.

[0080] The five dynamic access control risk mechanisms (P2, P3, P5, P7, P9) existing in the network far exceed the preset threshold of 4. This means that: the access control policies are highly complex: multiple nodes adopt dynamically changing access control policies, which greatly increases the possibility of access control conflicts; coordination is difficult: the coordination of policies among the five dynamic nodes requires a higher level of unified management; and the risk spreads strongly: the unpredictability of dynamic policies will have a cumulative effect among multiple nodes.

[0081] This approach ensures that systemic access control risks can be identified in a timely manner in complex multi-authority network environments, and that corresponding global adjustment measures can be taken to safeguard data security and access control consistency across the entire network.

[0082] Furthermore, the method for determining the target of permission adjustment within the organization is as follows: S41 uses the distribution data of related data elements in other institutions in different access control institutions to determine that there are overlapping data elements in other institutions, which are risk institutions under dynamic access control, and regards them as related dynamic institutions. Related dynamic organizations refer to those organizations among all access control organizations that have overlapping data elements with related organizations (i.e., other organizations that have overlapping data elements with access control organizations) and that themselves adopt dynamic access control strategies. They are active and complex data exchange nodes in the network.

[0083] This step involves identifying the most potentially risky subset from the entire group of access control agencies. These agencies, due to the dynamic nature of their policies and their data sharing with affiliated agencies, are the primary sources of access conflicts and data breaches, serving as the benchmark for subsequent assessments.

[0084] Specifically, suppose the set of access control agencies is [P1, P2, P3, P4, P5, P6, P7, P8, P9, P10], and the set of related agencies (from S31) is [Agency A, B, C, D, E, F] (these agencies have overlapping data elements with the access control agencies). Judgment process: From the access control agencies, identify the agencies that have overlapping data elements with any associated agency (AF), let's say: [P2, P3, P5, P7, P9]. Check the access control policies of these agencies, all of which are dynamic access control. The associated dynamic agencies are determined to be: [P2, P3, P5, P7, P9].

[0085] S42 determines the associated dynamic mechanisms that have overlapping data elements with different associated dynamic mechanisms based on the data element data that overlap with the data elements in the other mechanisms. Specifically, overlapping related dynamic entities are identified. These overlapping related dynamic entities refer to other entities (the target to be evaluated) that share at least one data element with a given entity in the "Related Dynamic Entities" list. This identifies the direct data link between that entity and the high-risk dynamic node.

[0086] This step aims to precisely map the "risk sources" for each ordinary institution to be evaluated. By identifying all dynamic institutions with which it has data interactions, the institution's data exposure and potential risk entry points within a complex network can be quantified.

[0087] Example: We need to perform this step for each of the other organizations to be evaluated (A, B, C, D, E, F, G, H, I, J). For organization A, the analysis is as follows: Organization A's data elements: [Transaction Serial Number, Enterprise Credit Code], compared with related dynamic organizations: P2 also has [Transaction Serial Number, Electricity Load Curve] -> Overlapping element: Transaction Serial Number -> Overlap exists; P3 also has [Enterprise Credit Code] -> Overlapping element: Enterprise Credit Code -> Overlap exists; P5 also has [Electricity Load Curve] -> No overlapping element -> No overlap exists; P7 also has [Transaction Serial Number] -> Overlapping element: Transaction Serial Number -> Overlap exists; P9 also has [Energy Management Contract Number] -> No overlapping element -> No overlap exists. The "Related Dynamic Organizations with Overlapping Entities" for organization A are: [P2, P3, P7]. S43 determines whether the other organizations are the target of permission adjustment based on the overlapping dynamic organizations in different related data elements.

[0088] Specifically, the target of permission adjustments refers to ordinary organizations that require additional permission restrictions or monitoring. The criteria for determining this are: they have data overlap with too many dynamic permission control organizations, thus placing them at a high-risk data flow intersection, and their permission status needs to be reassessed and strengthened.

[0089] This is the final decision-making step. It is based on a core security concept: if an organization can obtain data from multiple independent data centers with complex and ever-changing policies, then it is a potential point of risk for unauthorized access or a data aggregation point, and its permissions must be closely monitored and dynamically adjusted.

[0090] The preset threshold for the number of dynamic organizations is 2. This means that if a regular organization has data overlap with 2 or more dynamic access control organizations, it will be identified as a target for access control adjustment. For organization A: List: [P2, P3, P7], Quantity: 3, organization A is determined to be a target for access control adjustment.

[0091] Specifically, the overlapping dynamic mechanisms are those whose associated data elements are the same as those of the other mechanisms.

[0092] It is understandable that when the number of associated dynamic mechanisms with overlapping relationships does not meet the requirement of associated data elements, that is, when the number of associated dynamic mechanisms with the associated data elements is greater than the preset threshold for the number of dynamic mechanisms, then the other mechanisms are determined as the target for permission adjustment.

[0093] Specifically, the method for determining the permission adjustment control method for the permission adjustment target is as follows: S51 determines the number of permission adjustment targets based on the permission adjustment target data; In the above steps, the number of permission adjustment targets is determined. The number of permission adjustment targets refers to the total number of organizations that were identified in the preceding process and need to have their permissions adjusted.

[0094] This step serves as the macro-level entry point for selecting and adjusting strategies. By assessing the size of the target group, the system can decide whether to adopt a "one-size-fits-all" batch processing approach or proceed with a more refined individual assessment process. This helps to strike a balance between efficiency and accuracy.

[0095] Example: Set of permission adjustment targets: [Organization A, B, C, D], Quantity count: 4, Record: The number of permission adjustment targets is 4, for subsequent decision-making.

[0096] S52 determines the risk institution that belongs to dynamic access control among the access control institutions based on the association between the access control institutions and the access control institutions of the target's access control strategy, and designates it as a dynamic control institution. Dynamic control organizations refer to those organizations within the access control system that are identified as "risk organizations" and employ dynamic access control strategies. They are the most complex and highest-risk data sources in the network.

[0097] This step clarifies the sources of risk that need to be referenced and avoided when adjusting permissions. One of the core purposes of permission adjustment is to address the risks arising from data interaction with these dynamic organizations; therefore, these risks are key factors in determining the adjustment method.

[0098] Example: Input: All access control institutions and their attributes; Filtering process: Filter out institutions that are both "risk institutions" and adopt "dynamic access control"; Dynamic control institutions are determined as: [P2, P3, P5, P7, P9].

[0099] S53 determines the permission adjustment control method for the permission adjustment target based on the number of permission adjustment targets and the overlap of associated data elements between the permission adjustment targets and different dynamic management and control agencies.

[0100] It is understood that, based on the number of permission adjustment targets and the overlap of associated data elements between the permission adjustment targets and different dynamic management and control agencies, the permission adjustment control method for the permission adjustment targets is determined, specifically including: S531 Obtain the number of the permission adjustment targets, and determine whether the number of the permission adjustment targets is less than the preset threshold for the number of adjustment targets. If yes, determine that the permission adjustment method for all permission adjustment targets is to process all permission adjustment targets according to the preset scheme. If no, proceed to the next step. Specifically, determining whether the number of targets to be adjusted is small involves checking if the total number of institutions requiring adjustment is below a certain threshold. If the number is small, a preset solution can be applied uniformly to all targets to improve efficiency.

[0101] Optimization strategies for small target groups are easy to implement, even with pre-defined permission adjustments, while also ensuring data security.

[0102] Example (judged from a global perspective): Number of permission adjustment targets: 4, preset threshold for the number of adjustment targets: 5, then the permission adjustment method for all permission adjustment targets (A, B, C, D) is determined to be to perform permission adjustment processing according to the preset scheme.

[0103] S532 determines the dynamic management agencies that have the same associated data elements as the permission adjustment target based on the overlap of associated data elements between the permission adjustment target and different dynamic management agencies, and determines whether the number of dynamic management agencies that have the same associated data elements as the permission adjustment target is greater than a preset threshold for the number of dynamic management agencies. If yes, the permission adjustment method for the permission adjustment target is to perform permission adjustment processing on the permission adjustment target according to a preset scheme. If no, proceed to the next step. Specifically, this step involves determining whether the number of associated dynamic control agencies is excessive. This step assesses the risk of a single permission adjustment target being associated with too many dynamic control agencies. The more dynamic sources associated, the more complex the environment, and the greater the need for mandatory unified adjustments.

[0104] Identify adjustment targets located at the center of complex data interaction networks; these targets must be reinforced using the most reliable pre-set solutions.

[0105] Example (assuming evaluation of organization D): "Related dynamic organizations with overlapping situations" of organization D: [P2, P3, P5, P7, P9], quantity: 5, preset threshold for the number of dynamic control organizations: 4. If this step is executed, it will be determined that the preset scheme will be adopted for organization D.

[0106] S533 determines the data element association factor between the permission adjustment target and the dynamic management and control agency based on the amount of data of the overlapping associated data elements between the permission adjustment target and the dynamic management and control agency, and the proportion of the data of the associated data elements in the dynamic management and control agency. It then determines whether the average value of the data element association factor between the permission adjustment target and the dynamic management and control agency is greater than a preset factor threshold. If so, it determines that the permission adjustment method for the permission adjustment target is to perform permission adjustment processing on the permission adjustment target according to a preset scheme. If not, it proceeds to the next step. Specifically, to determine whether the average data correlation strength is too high, the data element correlation factor refers to the proportion of overlapping data between the permission adjustment target and a certain dynamic management agency within the total data volume of that dynamic management agency. The average value reflects the closeness of the connection between the adjustment target and all related dynamic agencies.

[0107] Assess risk from the perspective of data volume. Even if the number of related dynamic institutions is not large, if the data is closely linked (accounting for a high percentage), it means that the dependence is high and the risk is concentrated, requiring strict control through pre-set plans.

[0108] Example (assuming evaluation of organization B): Related dynamic organizations of organization B: [P2, P5], calculate data element correlation factor: the proportion of overlapping data with P2 to the total data of P2: 0.75, the proportion of overlapping data with P5 to the total data of P5: 0.50, calculate the average value: (0.75 + 0.50) / 2 = 0.625, preset factor threshold: 0.6. If this step is executed, it will be determined that the preset scheme is adopted for organization B.

[0109] S534 determines the permission adjustment method for the permission adjustment target based on the amount of data of the associated data elements that overlap with the dynamic management and control agency in the permission adjustment target, and in combination with the average value of the data element association factors with different dynamic management and control agencies.

[0110] Furthermore, based on the amount of data of the overlapping associated data elements between the permission adjustment target and the dynamic management and control agency, and combined with the average value of the data element association factors between the target and different dynamic management and control agencies, the permission adjustment method for the permission adjustment target is determined, specifically including: Based on the amount of data of the associated data elements that overlap with the dynamic management and control agency in the permission adjustment target, and the proportion of the data amount of the associated data elements in the permission adjustment target, the overlap ratio is determined. Based on the average of the overlap ratio and the average of the data element association factors between different dynamic management and control agencies, a comprehensive association coefficient is determined. It is determined whether the comprehensive association coefficient is greater than a preset association coefficient threshold. If it is, the permission adjustment method for the permission adjustment target is determined to be to adjust the permission of the permission adjustment target according to a preset scheme. If not, the permission adjustment method for the permission adjustment target is determined to be to adjust the permission of the permission adjustment target according to a second preset scheme.

[0111] S534: Final decision based on comprehensive correlation coefficient, overlap ratio: the proportion of the total amount of data overlapping between the target of the permission adjustment and all dynamic management agencies in its own total data volume. This reflects the "outward orientation" of the target's data.

[0112] Comprehensive correlation coefficient: the average of the overlap ratio and the correlation factor of average data elements. This is an ultimate evaluation indicator that combines the characteristics of the target itself and the strength of external correlations. This is the most refined decision-making step, used to handle "middle ground" cases where the previous steps could not clearly determine the situation. It integrates internal and external factors to provide the fairest adjustment strategy.

[0113] Example (assuming an evaluation of organization C, and all previous judgments were "No"): Calculate the overlap ratio: The amount of overlapping data between organization C and all dynamic organizations: 8000 records; the total amount of data for organization C itself: 15000 records; overlap ratio = 8000 / 15000 ≈ 0.533; calculate the average data element correlation factor: 0.55; calculate the comprehensive correlation coefficient: (0.533 + 0.55) / 2 = 0.5415; preset correlation coefficient threshold: 0.5. If this step is reached, it will determine whether the preset scheme is used for mechanism C. If the determination is "no", that is, if it is less than the preset correlation coefficient threshold, then the second preset scheme will be used.

[0114] Furthermore, the preset scheme involves dynamically identifying the encryption methods of dynamic management agencies that share the same associated data elements as the permission adjustment target, selecting the encryption method with the fewest number of dynamic management agencies that share the same associated data elements as the permission adjustment target, and then adjusting the encryption method of the permission adjustment target.

[0115] All permission adjustment targets (A, B, C, D) will have their permissions adjusted according to the "preset scheme". 1. Implementation of the preset scheme, the core strategy is: dynamically identify the encryption methods of dynamic management agencies that have the same related data elements as the target, and select the encryption method that is used the least frequently as the adjusted encryption method for the target.

[0116] Objective: To avoid using the same encryption method as the main data source, thereby reducing the risk of simultaneous leakage of data from multiple sources due to the breach of a single encryption algorithm.

[0117] Example (Choosing an encryption method for organization A): Investigation: Identify dynamic control organizations [P2, P3, P7] that have overlapping data with organization A. Statistics: Query the encryption methods currently used by P2, P3, and P7. P2 uses: SM4, P3 uses: SM4, P7 uses: ECC-SECP256K1. Analysis: SM4 is used by 2 organizations, and ECC-SECP256K1 is used by 1 organization. Decision: Select SHA-256, which has the fewest usages, as the new mandatory encryption method for organization A.

[0118] Furthermore, the second preset scheme involves selecting an encryption method that is inconsistent with the dynamic management agency that has the largest correlation factor with the data element of the permission adjustment target, and then adjusting the encryption method of the permission adjustment target.

[0119] The second pre-set plan is implemented (assuming that agency C is applicable to this plan). The core strategy is to select an encryption method that is inconsistent with the encryption method used by the dynamic control agency with the largest correlation factor with the target data element.

[0120] Objective: To avoid using the same encryption methods as the most important and closely related data sources, thereby achieving key risk isolation.

[0121] Example (Choosing an encryption method for organization C): Investigation: The associated dynamic organizations of organization C are [P3, P9]. Calculation shows that the association factor with P3 is 0.8, and the association factor with P9 is 0.4. Therefore, P3 is the most closely associated organization. Query: The encryption method currently used by P3 is SM4.

[0122] Decision: From the encryption method library [SM4, ECC-SECP256K1, SHA-256, ECC], select any algorithm that is not SM4, such as ECC-SECP256K1, as the new mandatory encryption method for Organization C.

[0123] Example 2 Secondly, the present invention provides a computer system, comprising: a memory and a processor connected in communication, and a computer program stored in the memory and capable of running on the processor, wherein the processor executes the above-described method for managing usage rights based on data element ownership confirmation when running the computer program.

[0124] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the embodiments of apparatus, devices, and non-volatile computer storage media are basically similar to the method embodiments, so the descriptions are relatively simple; relevant parts can be referred to the descriptions of the method embodiments.

[0125] The foregoing has described specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than that shown in the embodiments and may still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require the specific or sequential order shown to achieve the desired result. In some embodiments, multitasking and parallel processing are possible or may be advantageous.

[0126] The above description is merely one or more embodiments of this specification and is not intended to limit this specification. Various modifications and variations can be made to the one or more embodiments of this specification by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principle of one or more embodiments of this specification should be included within the scope of the claims of this specification.

Claims

1. A method for managing usage rights based on data element ownership confirmation, characterized in that, Specifically, it includes: Based on the data element ownership confirmation results in different institutions, the associated data elements of the institution are determined. Based on the overlap between the associated data elements of the institution and other institutions, the access control institution and access control strategy in the institution are determined. When it is determined that the access control institution needs to dynamically adjust the permissions of the institutions other than the access control institution, the process proceeds to the next step, based on the overlap between the associated data elements of the institutions other than the access control institution and the access control institution. The distribution data of related data elements in the organization in different permission control organizations is determined. Based on the distribution data, permission adjustment targets in the organization are determined. Based on the permission adjustment target data and the association between the permission control target data and the permission control organizations of the permission control strategy of the target, permission adjustment control methods for different permission adjustment targets are determined.

2. The method for managing usage rights based on data element ownership as described in claim 1, characterized in that, The associated data elements of the organization are the data elements for which the organization has access permissions.

3. The method for managing usage rights based on data element ownership as described in claim 1, characterized in that, The institutions mentioned include government agencies, credit institutions, and consulting firms.

4. The method for managing usage rights based on data element ownership as described in claim 1, characterized in that, The method for determining the authority control body within the aforementioned organization is as follows: Based on the overlap between the associated data elements of the institution and other institutions, identify the associated data elements that overlap with other institutions and treat them as overlapping data elements. Based on the overlapping data elements with other institutions, determine the overlap coefficient of data elements with other institutions; Based on the overlap coefficient of data elements with other institutions, it is determined whether the institution is an access control institution.

5. The method for managing usage rights based on data element ownership as described in claim 4, characterized in that, The overlap coefficient of data elements between the institution and other institutions is determined based on the proportion of the data volume of the overlapping data elements in the data volume of the related data elements of the other institutions.

6. The method for managing usage rights based on data element ownership as described in claim 4, characterized in that, Based on the overlap coefficient of data elements with other institutions, it is determined whether the institution is an access control institution, specifically including: Determine the maximum value of the overlap coefficient between data elements and other institutions based on the overlap coefficient between data elements and other institutions. The institution is determined to be an access control institution based on the maximum value of the overlap coefficient of data elements between it and other institutions.

7. The method for managing usage rights based on data element ownership as described in claim 1, characterized in that, The process involves determining which organizations, excluding those with access control mechanisms, require dynamic adjustment of their permissions. This includes: The institutions other than the authority control agency are designated as other institutions. Based on the overlap of the associated data elements of the other institutions and the authority control agency, other institutions that have associated data elements of the authority control agency are identified and designated as associated institutions. Based on the overlap of related data elements between the associated institutions and the access control institutions, determine the access control institutions to which the overlapping related data should go and designate them as risk institutions. Based on the data of the associated institutions and the permission restriction scheme of the risk institutions, it is determined whether dynamic adjustment of the permissions of institutions other than the permission control institution is required.

8. The method for managing usage rights based on data element ownership as described in claim 1, characterized in that, The method for determining the target of permission adjustment in the aforementioned organization is as follows: Based on the distribution data of related data elements in other institutions in different access control institutions, it is determined that institutions with overlapping data elements in other institutions belong to risk institutions under dynamic access control, and these institutions are identified as related dynamic institutions. Based on the data elements that overlap with those in different associated dynamic mechanisms, identify the associated dynamic mechanisms in the other mechanisms that have overlapping data elements. Based on the overlapping dynamic organizations in different related data elements, determine whether the other organizations are the targets for permission adjustment.

9. The method for managing usage rights based on data element ownership as described in claim 8, characterized in that, The overlapping dynamic mechanism refers to the dynamic mechanism and the other mechanisms having the same data elements in their associated data elements.

10. A computer system, comprising: A memory and a processor connected in communication, and a computer program stored in the memory and capable of running on the processor, characterized in that, when the processor runs the computer program, it executes a method for managing usage rights based on data element ownership as described in any one of claims 1-9.

Citation Information

Patent Citations

  • Block chain security verification system and method for data element circulation

    CN120257262A