Hierarchical authority dynamic control method based on distributed identity
By using a hierarchical permission dynamic control method based on distributed identity, the issuance of identity identifiers for trading entities is optimized, which solves the problems of user permission discrepancies and busy issuance processing in power data transactions, and improves data security and transaction security.
Patent Information
- Application Number
- CN202511813489.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-04
- Publication Date
- 2026-03-03
AI Technical Summary
Existing technologies fail to effectively determine the method for issuing and processing identity identifiers during power data transactions, leading to discrepancies in data permissions for transaction users and excessively high processing busyness, which affects transaction security.
A hierarchical dynamic access control method based on distributed identity is adopted. The viewing permissions of the transaction entity are determined by a preset scheme, the transaction entity under control is divided into the transaction entity under control and other transaction entities, the identity identification of other transaction entities is optimized, and the risk of leakage and the busyness of the identification processing are reduced.
It enables the filtering of other transaction entities with lower risk of leakage and more concentrated data elements, reduces the workload of identity issuance and processing, and improves data security and transaction security.
Smart Images

Figure CN121598355A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of data security technology, and in particular relates to a hierarchical dynamic permission control method based on distributed identity. Background Technology
[0002] In the process of trading electricity data elements, there are typical users of electricity market data trading, such as power grids, power generation companies, export-oriented enterprises, and banks. Therefore, how to achieve security control over different electricity data trading users has become an urgent technical problem to be solved.
[0003] To achieve secure control over data permissions for different trading users, existing technical solutions utilize identity verification technology to control the security permissions of different trading users. This means that the security access permissions of their identity verification have a certain time limit and data access permission. Once the time limit is exceeded, the access permission becomes invalid, thereby ensuring the transaction security of trading users.
[0004] When using identity issuance technology to process identity issuance, existing technical solutions neglect to determine the method for issuing identity based on the transaction data of the transaction user. Specifically, different transaction users have different transaction permissions. Therefore, how to determine the issuance method and avoid excessive busyness in the identity issuance process has become an urgent technical problem to be solved.
[0005] To address the aforementioned technical issues, this application provides a hierarchical dynamic permission control method based on distributed identity. Summary of the Invention
[0006] To achieve the objectives of this invention, the following technical solution is adopted: Specifically, this application provides a hierarchical permission dynamic control method based on distributed identity, which includes: S1 uses a preset scheme to process the issuance of identity tokens, determines the viewing permissions of data elements of different transaction entities, uses the viewing permissions to divide the transaction entities into control transaction entities and other transaction entities, and determines the issuance method of identity tokens of control transaction entities based on the viewing permissions of control transaction entities. S2, based on the method for issuing the identity token of the controlled transaction entity, determines that when it is necessary to optimize the method for issuing the identity token of other transaction entities, it determines the other transaction entities and the access control method for issuing the identity token with permanent permissions based on the viewing data of the data elements of other transaction entities and the similarity of the data elements with the controlled transaction entity. S3 uses monitoring data of data elements of the controlled transaction entities to determine the optimized results of the permanent permission identity identifiers of other transaction entities under different permission control methods.
[0007] The beneficial effects of this invention are as follows: Based on the viewing data of other trading entities and the similarity of data elements with those of the controlled trading entities, other trading entities are identified for the issuance of permanent access identity tokens. This takes into account the frequency of viewing data elements of other trading entities, as well as the risk of leakage of permanent access identity tokens due to other alternating entities caused by similar data elements with the controlled trading entities. This achieves the screening of other trading entities with lower leakage risk and more concentrated data element viewing, and reduces the workload of identity token issuance processing when there are a large number of trading entities by issuing permanent access identity tokens.
[0008] By utilizing monitoring data of the data elements of the controlled transaction entities, the optimization results of the permanent permission identity identifiers of other transaction entities under different access control methods are determined. This avoids the technical problem of excessive leakage risk caused by the failure to optimize the permanent permission identity identifiers of other transaction entities when the data elements of the controlled transaction entities change. Furthermore, by combining the busy level of identity identifier issuance and processing, the optimization of permanent permission identity identifiers is achieved from the perspectives of leakage risk and issuance and processing busyness, thereby improving data security.
[0009] Furthermore, the issuance of identity verification is processed using a pre-defined scheme, specifically including: Based on the user's needs and permissions, an identity identifier with a preset validity period is issued to the user corresponding to their user permissions.
[0010] Furthermore, the viewing permissions for the data elements include the amount of data elements for which viewing permissions are granted, as well as the source of the data elements.
[0011] Furthermore, the method for determining the entities responsible for controlling transactions is as follows: The viewing permissions are used to determine the amount of data elements for which the transaction entity has viewing permissions after obtaining its identity, as well as the source of the data elements. Based on the sources of different data elements, determine whether the transaction entity is a controlled transaction entity.
[0012] Furthermore, the method for determining the optimization result of the identity identifier of the permanent permissions of the other transaction entities is as follows: By monitoring data of data elements of the controlled transaction entities, the changes in the amount of data elements of the controlled transaction entities from different sources are determined, and based on the changes in the data sources of leakage risk for different controlled transaction entities are determined; Based on the aforementioned changes, determine the number of entities responsible for controlling different sources of leakage risk; Based on the number of control entities for different sources of leakage risk and the issuance data of the aforementioned identity identifiers, the optimization results of the identity identifiers for permanent permissions of other transaction entities under different access control methods are determined.
[0013] Other features and advantages will be set forth in the description which follows, and will be apparent in part from the description, or may be learned by practicing the invention. The objects and other advantages of the invention are realized and obtained through the structures particularly pointed out in the description and the drawings.
[0014] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, preferred embodiments are described below in detail with reference to the accompanying drawings. Attached Figure Description
[0015] The above and other features and advantages of the present invention will become more apparent from a detailed description of exemplary embodiments thereof with reference to the accompanying drawings.
[0016] Figure 1 This is a flowchart of a hierarchical dynamic access control method based on distributed identity; Figure 2 It is a flowchart of the method for determining the main parties involved in a transaction; Figure 3 It is a flowchart of the method for determining the issuance method of the identity identifier of the transaction entity; Figure 4 This is a flowchart for optimizing the method of issuing identity verification documents for other transaction entities. Detailed Implementation
[0017] Exemplary embodiments will now be described more fully with reference to the accompanying drawings. However, these exemplary embodiments can be implemented in many forms and should not be construed as limited to the embodiments set forth herein; rather, they are provided so that the invention will be thorough and complete, and the concept of the exemplary embodiments will be fully conveyed to those skilled in the art. The same reference numerals in the drawings denote the same or similar structures, and therefore their detailed description will be omitted.
[0018] The terms “a,” “one,” “the,” and “the” are used to indicate the existence of one or more elements / components / etc.; the terms “including” and “having” are used to indicate an open-ended meaning of inclusion and that other elements / components / etc. may exist in addition to the listed elements / components / etc.
[0019] To solve the above problems, according to one aspect of the present invention, such as Figure 1 As shown, a hierarchical dynamic access control method based on distributed identity is provided, specifically including: S1 uses a preset scheme to process the issuance of identity tokens, determines the viewing permissions of data elements of different transaction entities, uses the viewing permissions to divide the transaction entities into control transaction entities and other transaction entities, and determines the issuance method of identity tokens of control transaction entities based on the viewing permissions of control transaction entities. Furthermore, the issuance of identity verification is processed using a pre-defined scheme, specifically including: Based on the user's needs and permissions, an identity identifier with a preset validity period is issued to the user corresponding to their user permissions.
[0020] It is understood that the preset validity period is determined based on the user's needs or a pre-set validity period, and in one possible embodiment it is set to between 2 hours and 3 days.
[0021] Furthermore, the viewing permissions for the data elements include the amount of data elements for which viewing permissions are granted, as well as the source of the data elements.
[0022] It should be noted that the sources of the data elements include trading users in the electricity spot trading market, electricity users, and the power grid.
[0023] Specifically, such as Figure 2 As shown, the method for determining the controlling transaction entity is as follows: The viewing permissions are used to determine the amount of data elements for which the transaction entity has viewing permissions after obtaining its identity, as well as the source of the data elements. Based on the sources of different data elements, determine whether the transaction entity is a controlled transaction entity.
[0024] It should be noted that when the number of sources of the data elements does not meet the requirements, the transaction entity is determined to be a control transaction entity.
[0025] In one possible embodiment, if the number of data element sources is more than 10, then if the identity of the transaction entity is leaked, the data elements from multiple sources will be at risk of being leaked. Therefore, based on this, it is determined that the transaction entity belongs to the control transaction entity and cannot be issued a permanent permission identity identifier, thereby ensuring the data security of the transaction entity.
[0026] Specifically, other trading entities are those that are not subject to regulatory control.
[0027] Specifically, such as Figure 3 As shown, the method for determining the issuance method of the identity identifier of the controlled transaction entity is as follows: Based on the viewing permissions of the controlled transaction entities, the sources of leakage risk for the controlled transaction entities are determined; Based on the sources of leakage risk of the controlled transaction entity, a method for issuing the identity identifier of the controlled transaction entity is determined.
[0028] It should be noted that when the number of sources of leakage risk for the controlled transaction entity is not within the preset range, the method for determining the issuance of the identity identifier of the controlled transaction entity is to determine the validity period of the identity identifier of the controlled transaction entity based on the amount of data for which the controlled transaction entity has viewing permissions in different data elements. However, when the number of sources of leakage risk for the controlled transaction entity is within the preset range, a fixed duration is used to determine the validity period of the identity identifier of the controlled transaction entity.
[0029] In one possible embodiment, if the number of sources of leakage risk for the controlled transaction entity is greater than 7, then it is determined that the number of sources of leakage risk for the controlled transaction entity is not within a preset range.
[0030] Additionally, it should be noted that the average proportion of the amount of data for which the controlled transaction entity has viewing permissions in different data elements to the total amount of data in those data elements is used as the base value. The difference between 1 and 0.9 times the base value is multiplied by a fixed duration to determine the effective duration of the identity identifier of the controlled transaction entity. In one possible embodiment, the fixed duration is between 2 hours and 3 days.
[0031] S2, based on the method for issuing the identity token of the controlled transaction entity, determines that when it is necessary to optimize the method for issuing the identity token of other transaction entities, it determines the other transaction entities and the access control method for issuing the identity token with permanent permissions based on the viewing data of the data elements of other transaction entities and the similarity of the data elements with the controlled transaction entity. Specifically, such as Figure 4As shown, optimization of the issuance method for the identity identifiers of other transaction entities is required, specifically including: Based on the method for issuing the identity identifier of the controlled transaction entity, the controlled transaction entity that needs to use the amount of data with viewing permissions in different data elements to determine the validity period of the identity identifier of the controlled transaction entity is identified, and it is used as the data analysis entity; By utilizing the number of data analysis subjects, it can be determined whether the method for issuing identity tokens for other transaction subjects needs to be optimized.
[0032] It is understandable that when the number of data analysis subjects does not meet the requirements, such as more than 500 in one possible embodiment, the data processing volume when issuing identity tokens is large. Therefore, it is determined that the method for issuing identity tokens for other transaction subjects needs to be optimized.
[0033] Specifically, the method for determining other transaction entities that issue permanent authorization credentials is as follows: Based on the viewing data of other trading entities' data elements, determine the historical viewing associations of the other trading entities' data elements from different sources; Based on the similarity between the data elements of the other trading entities and the data elements of the controlling trading entity, the controlling trading entity with overlapping data elements from different sources of the other trading entities is identified. By utilizing historical viewing of data elements from different sources and identifying overlapping control transaction entities based on data elements from different sources, it can be determined whether the other transaction entities are the entities that issue identity tokens for permanent permissions.
[0034] It is understood that the historical viewing association is determined based on the ratio of the number of times the identity token of the source data element was issued to the number of times the identity token of the other trading entity was issued after the identity token was issued. The value ranges from 0 to 1. The ratio is used as the viewing association value. The higher the viewing association value, the higher the viewing association between the other trading entity and the source data element.
[0035] It should be noted that by utilizing historical viewing of data elements from different sources and identifying overlapping control transaction entities among data elements from different sources, it is possible to determine whether the other transaction entities are other transaction entities that have issued identity tokens for permanent permissions. Specifically, this includes: By utilizing the historical viewing associations of data elements from different sources, the viewing association values of data elements from different sources are determined, and the viewing association values are used to determine the data elements from the associated sources; If the number of controlled transaction entities with data elements from the associated sources does not meet the requirements, then it is determined that the other transaction entities do not belong to the other transaction entities that issue identity tokens for permanent permissions.
[0036] It is understood that the data elements with the associated source refer to the data elements with an association value greater than 0.4. It should be noted that when the number of controlling transaction entities for the data elements with the associated source is more than 10, that is, when it is determined that the number of controlling transaction entities for the data elements does not meet the requirements, the issuance of permanent permission identity tokens will lead to a certain risk of data leakage. Therefore, based on this, it is determined that the other transaction entities are not other transaction entities that issue permanent permission identity tokens.
[0037] It should be noted that the number of entities controlling the data elements refers to the number of entities that have viewing permissions for the data elements.
[0038] Furthermore, the access control method is to control the data elements of associated sources for a transaction subject with a certain number of related entities, that is, to set the viewing permission to only be able to view the data elements of associated sources for a transaction subject with a certain number of related entities, that is, to view the data elements of associated sources for which there are fewer than 10 controlled transaction subjects.
[0039] S3 uses monitoring data of data elements of the controlled transaction entities to determine the optimized results of the permanent permission identity identifiers of other transaction entities under different permission control methods.
[0040] Furthermore, the method for determining the optimization result of the identity identifier of the permanent permissions of the other transaction entities is as follows: By monitoring data of data elements of the controlled transaction entities, the changes in the amount of data elements of the controlled transaction entities from different sources are determined, and based on the changes in the data sources of leakage risk for different controlled transaction entities are determined; Based on the aforementioned changes, determine the number of entities responsible for controlling different sources of leakage risk; Based on the number of control entities for different sources of leakage risk and the issuance data of the aforementioned identity identifiers, the optimization results of the identity identifiers for permanent permissions of other transaction entities under different access control methods are determined.
[0041] It is understandable that the source of the leakage risk data is a source in which the amount of data of the modified data element in the controlled transaction entity is greater than 0.5% of the amount of data of the data element in the source.
[0042] It should be noted that when the average processing delay of identity identifiers of different transaction entities does not meet the requirements during the issuance of the identity identifier, that is, when the average processing delay of identity identifiers of different transaction entities is greater than 1 minute, the delay in the issuance of identity identifiers is relatively high. Therefore, in order to reduce the issuance processing delay, the access control method is optimized for identity identifiers with permanent permissions for other transaction entities with different access control methods. That is, for other transaction entities that do not have more than 7 sources of leakage risk under the control of other entities, all data elements with viewing permissions are set to be viewable only under identity identifiers with permanent permissions. The access control methods of other transaction entities with other access control methods do not need to be processed.
[0043] Additionally, it is understandable that when the average processing delay of the identity tokens of different transaction entities meets the requirements during the issuance of the identity token, if the average processing delay of the identity tokens of different transaction entities is not within the preset range, i.e. less than 10 seconds, then the frequency of identity token issuance is low. Therefore, based on this, the identity tokens of permanent permissions of other transaction entities under different access control methods are deleted, and the identity token issuance is processed using the same preset scheme. Furthermore, it is understandable that if the average processing delay of the identity identifiers of different transaction entities is within a preset range, it is necessary to further determine whether there are data elements among the transaction entities that have more than 7 sources of leakage risk. If the number of data elements with more than 7 sources of leakage risk is more than 4, then the identity identifiers of the other transaction entities with permanent permissions will be deleted, and the identity identifiers will be issued using a preset scheme. In other cases, there is no need to optimize the permission control method.
[0044] Example 2 Optionally, the method for determining the controlling transaction entity is as follows: The viewing permissions are used to determine the amount of data elements for which the transaction entity has viewing permissions after obtaining its identity, as well as the source of the data elements. Based on the amount of data from different data element sources, determine the sources of leakage risk within those sources; By using the data on the source of the leaked risk, it can be determined whether the trading entity is a controlled trading entity.
[0045] It is understood that the source of leakage risk is a source from which the transaction entity has viewing rights and whose data volume is at least 0.7 times the proportion of the data elements in the source. When the number of sources of leakage risk does not meet the requirements, the transaction entity is determined to be a controlled transaction entity.
[0046] It should be noted that when the number of sources of leakage risk is more than three, the transaction entity is identified as a controlled transaction entity.
[0047] Example 3 Furthermore, the method for determining other transaction entities that issue permanent authorization credentials is as follows: Based on the similarity between the data elements of the other trading entities and the data elements of the controlling trading entities, the controlling trading entities whose data elements from different sources overlap are identified, and the number of controlling trading entities whose data elements from different sources overlap determines the risk-controllable data elements. Based on the viewing data of risk-controllable data elements of other trading entities, determine the number of times the other trading entities viewed risk-controllable data elements after the issuance and processing of identity identifiers; By utilizing the number of times the other transaction entities viewed data elements with controllable risks after the issuance and processing of identity identifiers, it can be determined whether the other transaction entities are the other transaction entities that issued identity identifiers with permanent permissions.
[0048] It is understood that the risk-controllable data element refers to the data element for which the number of controlled transaction entities with the data element from the source meets the requirements.
[0049] It should be noted that if the number of times the other transaction entities view risk-controllable data elements after the issuance of identity tokens accounts for less than 0.5% of the number of times their identity tokens are issued, it indicates that the correlation between the other transaction entities viewing risk-controllable data elements after the issuance of their identity tokens is not high. Therefore, it is determined that the other transaction entities do not belong to the other transaction entities that have issued identity tokens with permanent permissions.
[0050] Example 4 Optionally, the method for determining the optimized result of the identity identifier of the permanent permissions of the other transaction entities is as follows: By monitoring data of data elements of the controlled transaction entities, the changes in the amount of data elements of the controlled transaction entities from different sources are determined, and based on the changes in the data sources of leakage risk for different controlled transaction entities are determined; Based on the aforementioned changes, the number of control entities for different sources of leakage risk is determined. The number of sources of leakage risk that other transaction entities have viewing permissions is determined using the permission control method for the other alternating entities. Based on the number of sources of leakage risk that have viewing permissions, the data element association value of the other transaction entities is determined. The optimization result of the identity identifier for permanent permissions of the other transaction entities is determined by using the data element association values of the other transaction entities and the issuance data of the identity identifier.
[0051] It should be noted that the data element association value is determined based on the ratio of the number of leakage risk sources that other alternating subjects have viewing permissions to the total number of leakage risk sources.
[0052] Optionally, when the average processing delay of the identity tokens of different transaction entities does not meet the requirements during the issuance of the identity token, that is, for other transaction entities whose data element association value is less than the preset association threshold, all data elements with viewing permissions are set to be viewable under the identity token with permanent permissions, while the permission control method for other transaction entities whose data element association value is not less than the preset association threshold does not need to be processed.
[0053] Specifically, when the average processing delay of the identity identifiers of different transaction entities meets the requirements during the issuance of the identity identifier, if the data element association value is greater than the second preset association threshold, then the identity identifiers of the other transaction entities with permanent permissions are deleted, and the identity identifier issuance is carried out using a preset scheme. In other cases, there is no need to optimize the permission control method. The value of the second preset association threshold is greater than the preset association threshold. In one possible embodiment, its values are 0.4 and 0.3, respectively.
[0054] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, the embodiments of apparatus, devices, and non-volatile computer storage media are basically similar to the method embodiments, so the descriptions are relatively simple; relevant parts can be referred to the descriptions of the method embodiments.
[0055] The foregoing has described specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than that shown in the embodiments and may still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require the specific or sequential order shown to achieve the desired result. In some embodiments, multitasking and parallel processing are possible or may be advantageous.
[0056] The above description is merely one or more embodiments of this specification and is not intended to limit this specification. Various modifications and variations can be made to the one or more embodiments of this specification by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principle of one or more embodiments of this specification should be included within the scope of the claims of this specification.
Claims
1. A hierarchical dynamic access control method based on distributed identity, characterized in that, Specifically, it includes: The system uses a preset scheme to process the issuance of identity identifiers, determines the viewing permissions of data elements of different transaction entities, and uses the viewing permissions to classify the transaction entities into control transaction entities and other transaction entities. Based on the viewing permissions of control transaction entities, the system determines the method for issuing identity identifiers of control transaction entities. Based on the method for issuing identity tokens of the controlled transaction entity, when it is determined that the method for issuing identity tokens of other transaction entities needs to be optimized, the other transaction entities to be issued identity tokens with permanent permissions and the permission control method are determined based on the viewing data of the data elements of other transaction entities and the similarity of the data elements with the controlled transaction entity. By utilizing monitoring data of data elements of the controlled transaction entities, the optimization results of the permanent permission identity identifiers of other transaction entities under different permission control methods are determined.
2. The hierarchical permission dynamic control method based on distributed identity as described in claim 1, characterized in that, The issuance of identity verification documents is processed using a pre-defined scheme, specifically including: Based on the user's needs and permissions, an identity identifier with a preset validity period is issued to the user corresponding to their user permissions.
3. The hierarchical permission dynamic control method based on distributed identity as described in claim 2, characterized in that, The preset validity period is determined based on the user's needs or a pre-set validity period.
4. The hierarchical permission dynamic control method based on distributed identity as described in claim 1, characterized in that, The viewing permissions for the data elements include the amount of data elements for which viewing permissions are granted, as well as the source of the data elements.
5. The hierarchical permission dynamic control method based on distributed identity as described in claim 4, characterized in that, The data elements come from trading users in the electricity spot market, electricity users, and the power grid.
6. The hierarchical permission dynamic control method based on distributed identity as described in claim 1, characterized in that, The method for determining the entities responsible for controlling transactions is as follows: The viewing permissions are used to determine the amount of data elements for which the transaction entity has viewing permissions after obtaining its identity, as well as the source of the data elements. Based on the sources of different data elements, determine whether the transaction entity is a controlled transaction entity.
7. The hierarchical permission dynamic control method based on distributed identity as described in claim 6, characterized in that, When the number of sources of the data elements does not meet the requirements, the transaction entity is determined to be a control transaction entity.
8. The hierarchical permission dynamic control method based on distributed identity as described in claim 1, characterized in that, Other trading entities are those that are not subject to regulatory control.
9. The hierarchical permission dynamic control method based on distributed identity as described in claim 1, characterized in that, The method for determining other transaction entities that issue identity tokens with permanent permissions is as follows: Based on the viewing data of other trading entities' data elements, determine the historical viewing associations of the other trading entities' data elements from different sources; Based on the similarity between the data elements of the other trading entities and the data elements of the controlling trading entity, the controlling trading entity with overlapping data elements from different sources of the other trading entities is identified. By utilizing historical viewing of data elements from different sources and identifying overlapping control transaction entities based on data elements from different sources, it can be determined whether the other transaction entities are the entities that issue identity tokens for permanent permissions.
10. The hierarchical permission dynamic control method based on distributed identity as described in claim 1, characterized in that, The method for determining the optimized result of the identity identifier of the permanent permissions of the other transaction entities is as follows: By monitoring data of data elements of the controlled transaction entities, the changes in the amount of data elements of the controlled transaction entities from different sources are determined, and based on the changes in the data sources of leakage risk for different controlled transaction entities are determined; Based on the aforementioned changes, determine the number of entities responsible for controlling different sources of leakage risk; Based on the number of control entities for different sources of leakage risk and the issuance data of the aforementioned identity identifiers, the optimization results of the identity identifiers for permanent permissions of other transaction entities under different access control methods are determined.