Unmanned device group authority hierarchical management and control method and system

By constructing a hierarchical permission mapping table and dynamically adjusting it, the dynamic adaptation problem of permission control for unmanned equipment groups is solved, improving the accuracy and adaptability of permission control and ensuring the stability and security of equipment operation.

CN121637533AInactive Publication Date: 2026-03-10ZHEJIANG ASIA PACIFIC INTELLIGENT NETWORK AUTOMOBILE INNOVATION CENT CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-04
Publication Date
2026-03-10
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The lack of dynamic adaptability in the access control of unmanned equipment groups makes it impossible to respond in a timely manner to changes in the environment and fluctuations in equipment status, resulting in chaotic task planning, decreased collaborative efficiency and increased safety risks.

Method used

By collecting device attribute data and environmental data, a permission level mapping table is constructed, feature analysis is performed to determine the risk level, permission levels are dynamically adjusted, and behavioral feedback is collected to optimize permission levels, thus forming a closed-loop control.

Benefits of technology

It achieves dynamic adaptation and continuous optimization of permission levels, improves the accuracy and adaptability of permission control, and ensures the stability and security of device operation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121637533A_ABST
    Figure CN121637533A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of equipment management, and discloses an unmanned equipment group authority hierarchical management and control method and system, and the method comprises the steps: collecting attribute data of all equipment in an unmanned equipment group, and constructing an authority hierarchical mapping table in combination with task details; performing feature analysis on the acquired environment data, judging a risk level according to an analysis result, and matching the risk level with a preset adjustment strategy in an authority grading mapping table so as to determine a dynamic authority adjustment factor; modifying the authority level in the authority grading mapping table by applying the dynamic authority adjustment factor, and forming an adjusted authority scheme after verifying the authority consistency; controlling the equipment group operation authority according to the adjusted authority scheme, collecting behavior feedback in the equipment execution process, and analyzing the behavior feedback to verify the authority control validity; according to the method, the stability of group cooperative task execution can be enhanced, and the security risk and efficiency loss caused by improper permission configuration are reduced.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of device management, in particular to a method and system for hierarchical management and control of permissions of a group of unmanned devices. BACKGROUND

[0002] A group of unmanned devices is usually composed of heterogeneous platforms in the air, water surface, underwater, etc., and needs to achieve function complementation and performance enhancement through cross-domain collaboration. However, the performance parameters and task adaptability of different devices are significantly different, and the cluster often faces uncertain factors such as communication delay and link switching. If there is no hierarchical permission, problems such as low adaptability devices executing high complexity operations beyond authority and conflicts of key task node permissions may occur, which not only leads to chaotic task planning and decreased collaboration efficiency, but also may cause safety risks due to uncontrolled operation, such as unmanned aerial vehicles interfering with airspace order and sensitive data being leaked due to lack of permission constraints.

[0003] In the prior art, the permission management of a group of unmanned devices is usually based on static allocation of pre-set rules, which fails to fully consider the dynamic changes of environmental parameters and the collaborative fluctuation relationship between parameters. For example, the associated disturbance of water temperature, water flow and communication signals in offshore operations may bring new operational risks, and static permissions cannot adapt to such risk changes in time. Moreover, after the permissions are allocated, there is no effective analysis and calibration mechanism for behavior feedback during device execution, making it difficult to identify the adaptability deviation of permissions and task stages and device states. The root cause lies in the lack of dynamic association logic between environmental state and permission configuration, and the lack of closed-loop permission verification and optimization path, resulting in insufficient precision and adaptability of permission management, and failing to effectively balance task execution efficiency and operational safety. SUMMARY

[0004] The present application provides a method and system for hierarchical management and control of permissions of a group of unmanned devices to solve the problems raised in the background.

[0005] To achieve the above-mentioned purpose, the present application provides a method for hierarchical management and control of permissions of a group of unmanned devices, comprising: S1, collecting attribute data of each device in the group of unmanned devices, and constructing a permission hierarchical mapping table in combination with task details; S2, performing feature analysis on the obtained environmental data, and determining a risk level according to the analysis result, matching the risk level with a pre-set adjustment strategy in the permission hierarchical mapping table to determine a dynamic permission adjustment factor; S3, modifying the permission level in the permission hierarchical mapping table by using the dynamic permission adjustment factor, and forming an adjusted permission scheme after verifying the permission consistency; S4, controlling the operation permission of the device group according to the adjusted permission scheme, and collecting behavior feedback during device execution; S5, analyze the behavior feedback to verify the effectiveness of the permission control, and optimize the permission hierarchical mapping table based on the verification result; S6, compile a permission hierarchical control report based on the optimized permission hierarchical mapping table.

[0006] Preferably, the attribute data of each device in the unmanned device group is collected, and the permission hierarchical mapping table is constructed in combination with the task details, including: Attribute data is extracted from the configuration file of each device in the unmanned device group, and the data integrity is verified to obtain a set of valid attribute data; Obtain task detail records from the task management system and parse the task key elements to obtain parsed task details; The set of valid attribute data is associated and matched with the parsed task details, and the permission level is assigned based on the preset permission rule, so as to form the permission hierarchical mapping table.

[0007] Preferably, the obtained environmental data is analyzed, including: Obtain the original environmental parameters from the external environment sensors and the internal device logs, and perform format standardization processing on the original environmental parameters, so as to obtain a set of standardized environmental data; Analyze the cooperative fluctuation relationship of different parameter change sequences in the set of standardized environmental data to obtain the strength of the correlation between parameters, and configure the environmental parameters to a matrix structure based on the parameter type according to the strength of the correlation, so as to construct a correlation matrix representing the environmental state; Compare the correlation matrix with the preset environmental safety benchmark to identify abnormal parameter combinations that exceed the safety threshold, and obtain the feature analysis result.

[0008] Preferably, the risk level is determined according to the analysis result, the risk level is matched with the preset adjustment strategy in the permission hierarchical mapping table, and the dynamic permission adjustment factor is determined, including: Compare the feature analysis result with the preset risk threshold, and divide the risk level according to the comparison result, so as to obtain the risk level determination result; Map the risk level determination result to the strategy index in the permission hierarchical mapping table, and retrieve the corresponding adjustment strategy set according to the strategy index; According to the current task stage and the device state, the applicable strategy in the adjustment strategy set is screened, and the dynamic permission adjustment factor is determined.

[0009] Preferably, the risk level is matched with the preset adjustment strategy in the permission hierarchical mapping table, and the dynamic permission adjustment factor is determined, including: Compare the key nodes of the current task stage with the running indicators in the device state report, and locate the applicable strategy that meets the current context from the adjustment strategy set; parsing the permission adjustment rules and constraint conditions contained in the applicable policy to form a policy parsing framework; quantifying the rules in the policy parsing framework into permission modification coefficients, and taking the permission modification coefficients as dynamic permission adjustment factors.

[0010] Preferably, the application of the dynamic permission adjustment factor to modify the permission levels in the permission hierarchical mapping table comprises: mapping the dynamic permission adjustment factor to the corresponding permission entries in the permission hierarchical mapping table, adjusting the numerical values of the permission levels according to the mapping relationship, and thus obtaining a preliminary updated permission table; checking the logical dependency relationship between different permission levels in the preliminary updated permission table, identifying and marking the conflicting permission settings, and thus forming a permission conflict report; re-calibrating the numerical values of the permission levels in conflict according to the permission conflict report, and obtaining an adjusted permission scheme.

[0011] Preferably, the control of the device group operation permission according to the adjusted permission scheme and the collection of the behavior feedback in the execution process of the device comprise: distributing the adjusted permission scheme to each device in the device group, making each device load the corresponding permission configuration, and thus forming a permission-controlled device running environment; monitoring the operation records and running state data of the device group when performing tasks, and summarizing to form a raw behavior data set; extracting permission-related operation events and state change events from the raw behavior data set to form a behavior event sequence; statistically analyzing the permission usage mode and the abnormal operation frequency based on the behavior event sequence, and compiling into a structured behavior feedback report.

[0012] Preferably, the analysis of the behavior feedback to verify the effectiveness of the permission control and the optimization of the permission hierarchical mapping table based on the verification result comprise: comparing the operation records in the behavior feedback with the authorized range in the adjusted permission scheme, identifying the operation events that exceed or do not reach the authorized range, and obtaining the difference points in the permission execution process; associating the difference points with the task critical nodes, and determining the influence level of the difference on the task target according to the preset influence evaluation rule; filtering the difference points with an influence level exceeding a threshold according to the preset security policy library, and classifying them as permission configuration items to be optimized; based on the permission configuration items to be optimized and their corresponding influence levels, correcting the permission levels and constraint conditions in the permission hierarchical mapping table, and forming an optimized permission hierarchical mapping table.

[0013] Preferably, the optimized permission level mapping table compiles a permission level management report, including: Extracting permission level change records and associated constraint conditions from the optimized permission level mapping table to form a permission change data set; Comparing the permission change data set with the difference of the historical permission scheme, analyzing the trend and distribution characteristics of the permission adjustment, and obtaining the permission adjustment analysis result; Integrating the permission change data set and the permission adjustment analysis result, and structurally organizing according to the preset report format to form a permission level management report.

[0014] In order to solve the above problems, the present application also provides a group of unmanned equipment permission level management system, the system comprises: The mapping table construction module is used for collecting attribute data of each device in the group of unmanned equipment, and constructing a permission level mapping table in combination with task details; The dynamic permission adjustment factor determination module is used for analyzing the characteristics of the obtained environmental data, and determining the risk level according to the analysis result, and matching the risk level with the preset adjustment strategy in the permission level mapping table, so as to determine the dynamic permission adjustment factor; The permission modification module is used for modifying the permission level in the permission level mapping table by applying the dynamic permission adjustment factor, and forming an adjusted permission scheme after verifying the permission consistency; The behavior feedback collection module is used for controlling the operation permission of the device group according to the adjusted permission scheme, and collecting the behavior feedback in the execution process of the device; The mapping table optimization module analyzes the behavior feedback to verify the effectiveness of the permission control, and optimizes the permission level mapping table based on the verification result; The management report output module is used for compiling a permission level management report based on the optimized permission level mapping table.

[0015] Compared with the prior art, the present application has the following beneficial effects: 1. A closed loop of permission level management based on device attributes, task details and environmental risks is constructed, which can realize dynamic adaptation and continuous optimization of permission levels, greatly improve the precision and adaptability of permission management of the group of unmanned equipment, effectively guarantee the high matching of device operation permission, task demand and environmental state, and then strengthen the stability of group collaborative task execution, and reduce the security risks and efficiency loss caused by improper permission configuration.

[0016] 2. Through the verification of data collection integrity, the in-depth analysis of environmental parameter correlation, the accurate identification of permission conflicts, and the system evaluation of behavior feedback, the construction of the permission hierarchical mapping table, the determination of the dynamic adjustment factor, and the subsequent optimization provide solid data support and rigorous logical basis, making the permission adjustment more scientific, the permission optimization more in line with actual operation needs, and further improving the reliability and landability of the entire permission hierarchical control system. BRIEF DESCRIPTION OF DRAWINGS

[0017] Figure 1 A flowchart of a method for group permission hierarchical control of unmanned equipment according to an embodiment of the present application is shown in FIG. 1. Figure 2 A function module diagram of a system for group permission hierarchical control of unmanned equipment according to an embodiment of the present application is shown in FIG. 2. The implementation, functional features, and advantages of the present application will be further described with reference to the embodiments and the accompanying drawings. DETAILED DESCRIPTION

[0018] It should be understood that the specific embodiments described herein are merely intended to explain the present application and are not intended to limit the present application.

[0019] Embodiments of the present application provide a method for group permission hierarchical control of unmanned equipment. The execution subject of a method for group permission hierarchical control of unmanned equipment includes at least one of electronic devices that can be configured to execute the method provided by the embodiments of the present application, such as a server and a terminal. In other words, a method for group permission hierarchical control of unmanned equipment can be executed by software or hardware installed in a terminal device or a server device. The server includes but is not limited to a single server, a server cluster, a cloud server, or a cloud server cluster. The server can be a standalone server or a cloud server that provides cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDN), and big data and artificial intelligence platforms, etc.

[0020] Embodiment 1, refer to Figure 1 A flowchart of a method for group permission hierarchical control of unmanned equipment according to an embodiment of the present application is shown in FIG. 1. In this embodiment, a method for group permission hierarchical control of unmanned equipment includes: S1, attribute data of each device in the group of unmanned equipment is collected, and a permission hierarchical mapping table is constructed in combination with task details; S2, feature analysis is performed on the acquired environmental data, and the risk level is determined according to the analysis result, the risk level is matched with the preset adjustment strategy in the permission hierarchical mapping table, and the dynamic permission adjustment factor is determined. S3. Apply dynamic permission adjustment factors to modify the permission levels in the permission hierarchy mapping table, and after verifying permission consistency, form the adjusted permission scheme. S4. Control the operation permissions of device groups according to the adjusted permission scheme, and collect behavioral feedback of devices during the execution process; S5. Analyze behavioral feedback to verify the effectiveness of access control, and optimize the access hierarchy mapping table based on the verification results; S6. Compile a permission level control report based on an optimized permission level mapping table.

[0021] In a preferred embodiment, attribute data of each device in the unmanned equipment group is collected, and combined with task details, a permission hierarchy mapping table is constructed, including: Extract attribute data from the configuration files of each device in the unmanned equipment group, verify the data integrity, and obtain a valid set of attribute data; Retrieve task detail records from the task management system, parse the key elements of the task, and obtain the parsed task details; The effective attribute data set is associated and matched with the parsed task details, and permission levels are assigned based on preset permission rules, thereby forming a permission hierarchy mapping table.

[0022] Specifically, attribute data such as device model, device number, hardware performance, communication module model, and historical execution records are extracted from the built-in configuration files of each device in the unmanned equipment group, including drones and unmanned vehicles. The integrity of the data is verified by comparing each field with a preset attribute list. If a device is missing any field data in the list, all attribute data of that device is directly removed. Finally, all the remaining complete attribute data are integrated into a valid attribute data set.

[0023] The system retrieves complete records of currently pending tasks from the task management system's database, including task name, execution time, execution area, task priority, and required equipment functions. Key task elements are analyzed through a combination of manual screening and system field identification extraction, resulting in a detailed task profile. The hardware performance and functional types of each device in the valid attribute data set are compared one by one with the required equipment functions and execution requirements in the analyzed task details. Pre-defined permission rules assign corresponding permission levels only to successfully matched devices. For example, drones with aerial photography capabilities are assigned Level 1 operation permission when matched for reconnaissance tasks, while those without are assigned Level 2 viewing permission. The device numbers, matching results, and corresponding permission levels are compiled into a table, forming a hierarchical permission mapping table.

[0024] In summary, the system extracts attribute data from device configuration files and verifies its integrity to ensure data validity. It also obtains and parses key task elements from the task management system to clarify task requirements. The system associates and matches valid attribute data with the parsed task details and accurately assigns permission levels based on preset permission rules. The resulting permission hierarchy mapping table clearly presents the correspondence between devices and permissions, avoiding unauthorized access by incompatible devices or permission conflicts at critical task nodes. This ensures that permission allocation aligns with device performance and task requirements, providing a solid foundation for subsequent dynamic permission adjustments. This improves the initial accuracy of permission control for unmanned device groups, facilitates the orderly execution of tasks in group collaboration, and reduces efficiency losses and security risks caused by chaotic permission configurations.

[0025] In a preferred embodiment, feature analysis is performed on the acquired environmental data, including: Raw environmental parameters are obtained from external environmental sensors and internal device logs. The raw environmental parameters are then standardized to obtain a standardized set of environmental data. The coordinated fluctuation relationship of different parameter change sequences in a standardized environmental dataset is analyzed to obtain the strength of the correlation between parameters. Based on the strength of the correlation, environmental parameters are configured into a matrix structure based on parameter type, thereby constructing a correlation matrix that characterizes the environmental state. The correlation matrix is ​​compared with the preset environmental safety benchmark to identify abnormal parameter combinations that exceed the safety threshold, and the feature analysis results are obtained.

[0026] Specifically, real-time values ​​of temperature, humidity, and wind speed are obtained from external environmental sensors deployed in the unmanned equipment's operating area. The original environmental parameters of environmental vibration and power supply voltage during operation are extracted from the equipment's internal operation logs. The parameters are standardized by manually setting a uniform format for each parameter. Temperature is uniformly retained to one decimal place and the unit is degrees Celsius. Wind speed is uniformly in meters per second. The timestamps of all parameters are uniformly accurate to the second level. After processing, a standardized set of environmental data is obtained.

[0027] One-hour change sequences of different parameters such as temperature and humidity, wind speed and vibration in a standardized environmental dataset are observed synchronously. If two parameters show an upward or downward trend at the same time point, the correlation is determined to be strong. If the change trends show no synchronicity, the correlation is determined to be weak. Using the parameter types such as temperature and humidity as the rows and columns of the matrix, the correlation strength level is filled in the corresponding cells to construct a correlation matrix representing the environmental state.

[0028] The correlation level of each parameter combination in the constructed correlation matrix is ​​compared one by one with the standard correlation range of the corresponding parameter combination in the preset environmental safety benchmark. If the correlation level of a parameter combination exceeds the standard range, the combination is identified as an abnormal parameter combination. All abnormal parameter combinations are summarized to obtain the feature analysis results.

[0029] In this embodiment, the risk level is determined based on the analysis results, and the risk level is matched with the preset adjustment strategy in the permission level mapping table to determine the dynamic permission adjustment factor, including: The feature analysis results are compared with the preset risk thresholds, and the risk levels are classified based on the comparison results to obtain the risk level determination results. Map the risk level determination results to the policy index in the permission level mapping table, and retrieve the corresponding set of adjustment policies based on the policy index; Based on the current task stage and device status, select applicable strategies from the set of adjustment strategies to determine the dynamic permission adjustment factor.

[0030] Specifically, the number and type of abnormal parameter combinations are extracted from the feature analysis results. A risk threshold is preset to clearly define the classification criteria, namely, one single abnormal parameter combination is low risk, two to three related abnormal parameter combinations are medium risk, and four or more related abnormal parameter combinations are high risk. The abnormal parameter combinations in the feature analysis results are statistically analyzed and their types are determined manually. The statistical determination results are compared with the preset risk thresholds one by one, and the corresponding risk level is determined according to the comparison results, thus obtaining the risk level determination result.

[0031] The permission level mapping table has a preset policy index column, with low risk corresponding to index 1, medium risk corresponding to index 2, and high risk corresponding to index 3. The risk level judgment results are matched one by one with the index column. Based on the matched policy index, all adjustment rules corresponding to the index are retrieved in the permission level mapping table and organized into an adjustment policy set.

[0032] Obtain information that the current task stage is the data acquisition and execution stage and the device status is normal operation. Check each rule in the adjustment strategy set one by one, and only retain the rules that are compatible with the data acquisition and execution stage and the normal operation status of the device. The permission adjustment value corresponding to the compatible rule is the dynamic permission adjustment factor.

[0033] In this embodiment, the risk level is matched with the preset adjustment strategy in the permission level mapping table to determine the dynamic permission adjustment factor, which includes: By comparing the key nodes of the current task phase with the operating indicators in the equipment status report, the appropriate strategy that fits the current context can be located from the set of adjustment strategies. The rules and constraints for adjusting permissions contained in the applicable policies are analyzed to form a policy analysis framework; The rules in the policy parsing framework are quantified into permission modification coefficients, and these permission modification coefficients are used as dynamic permission adjustment factors.

[0034] Specifically, the task stage conditions and device status conditions corresponding to each strategy are extracted from the set of adjustment strategies. The key node of the current task stage is the data transmission node. The operating indicators in the device status report include a communication module signal strength of 85% and a battery level of 60%. Each strategy in the set of adjustment strategies is manually checked one by one, and only the strategy marked "data transmission node" and requiring "signal strength ≥ 80% and battery level ≥ 50%" is retained. This strategy is the applicable strategy that fits the current context.

[0035] The applicable policy content is "allowing temporary escalation of data upload permissions, with the constraint that it is only valid at the data transmission node and the duration of a single escalation does not exceed 30 minutes". The policy is manually broken down sentence by sentence, and the permission adjustment rule is extracted as "temporarily escalate data upload permissions" with the constraint of "data transmission node, single duration ≤ 30 minutes". The rules and constraints are organized into a "adjustment rule - constraint scope" structure to form a policy parsing framework.

[0036] A preset rule-coefficient mapping table is used, where "temporarily elevate data upload permissions" corresponds to a permission modification coefficient of 0.2. By manually referring to this table, the "temporarily elevate data upload permissions" rule in the policy parsing framework is matched to 0.2, and this permission modification coefficient is directly used as the dynamic permission adjustment factor.

[0037] Specifically, as a preferred implementation, the permission modification coefficient is obtained using the following formula:

[0038] Indicates the permission modification coefficient. Indicates the first The rule strength value of the permission adjustment rule; : indicates the rule strength value of the first permission adjustment rule. Rule of permission adjustment The corresponding weights; : Indicates the total number of rules involved in the strategy parsing framework; : Indicates the degree of constraint violation; The constraint adjustment factor is a constant greater than zero.

[0039] It should be noted that the rule strength value in the formula comes from each permission adjustment rule in the policy parsing framework. The specific value is set manually according to the degree of influence of the rule on permission adjustment. For example, the strength value corresponding to the "temporarily upgrade data upload permission" rule is 0.5.

[0040] The weights come from a preset rule weight table, which predetermines the weight value of each rule for various permission adjustment rules that may be involved in the policy parsing framework. For example, the weight of core rules is set to 0.6, and the weight of secondary rules is set to 0.4.

[0041] The total number of rules is the number of all permission adjustment rules contained in the statistical strategy parsing framework. During the statistics, the rule entries in the framework are traversed one by one, and the specific value is obtained directly by counting.

[0042] Constraint violation rate is calculated by comparing the actual task stage, equipment status, and other conditions with the constraints of the applicable strategy one by one, and counting the proportion of the number of constraints that are violated to the total number of constraints. For example, if one of the three constraints is violated, the violation rate is 1 / 3.

[0043] The constraint adjustment factor is a fixed constant preset by the system. The specific value is determined by technical personnel based on historical permission adjustment data, and this value is always greater than zero.

[0044] The calculation process involves first calculating the weighted sum of all permission adjustment rules, then dividing it by the larger of the weighted sum and 1 to avoid calculation errors caused by the weighted sum being zero, thus obtaining the basic permission adjustment coefficient without considering constraints.

[0045] Then, the basic permission adjustment coefficient is corrected by multiplying the constraint adjustment factor by the constraint violation degree and adding 1 to the reciprocal of the result. The corrected result is the permission modification coefficient.

[0046] The entire calculation process integrates the strength and weight of all rules in the policy parsing framework, while also taking into account the violation of constraints, and finally obtains a value that accurately reflects the degree of permission adjustment in the current context. This value is directly used as the dynamic permission adjustment factor.

[0047] In general, as the rule strength value increases, the total weighted strength also increases, the basic permission adjustment coefficient increases, and the final permission modification coefficient also increases.

[0048] When the weight increases, the corresponding rule contributes more to the total weighted strength. If the strength value of the rule is positive, the basic permission adjustment coefficient will increase, and thus the permission modification coefficient will increase.

[0049] When the total number of rules increases, if the weighting strength of the newly added rules is positive, the sum of the weighting strengths will increase, the basic permission adjustment coefficient may increase, and the permission modification coefficient may increase accordingly.

[0050] When the degree of constraint violation increases, the product of the constraint adjustment factor and the degree of violation increases, and the reciprocal of the product will decrease. This increases the correction magnitude of the basic permission adjustment coefficient, and ultimately the permission modification coefficient decreases.

[0051] When the constraint adjustment factor increases, under the same constraint violation degree, the product of the constraint adjustment factor and the violation degree increases, and the reciprocal of the product after adding 1 decreases. The permission modification coefficient will further decrease. That is, the larger the constraint adjustment factor, the stronger the inhibition effect of the constraint on the permission modification coefficient.

[0052] In summary, when performing feature analysis on the acquired environmental data, the standardized format processing and correlation matrix construction can accurately identify the cooperative fluctuation relationships between environmental parameters, and capture risks that are easily overlooked by static access control, such as the correlation disturbances between water temperature, water flow and communication signals in offshore operations. Further comparison with environmental safety benchmarks identifies abnormal parameter combinations, providing a precise basis for risk assessment. Determining the risk level based on the analysis results clarifies the specific degree of environmental risk. When matching the risk level with the preset adjustment strategies in the access control mapping table, the applicable strategies are selected based on the current task stage and equipment status, ensuring that the determined dynamic access control factors closely match the actual scenario requirements. This provides a scientific quantitative basis for subsequent dynamic access control modifications, effectively solving the problem that existing static access control cannot adapt to changes in environmental risks in a timely manner, and improving the adaptability of access control to dynamic environmental changes.

[0053] In a preferred embodiment, applying a dynamic permission adjustment factor to modify the permission level in the permission hierarchy mapping table includes: The dynamic permission adjustment factor is mapped to the corresponding permission entry in the permission hierarchy mapping table, and the value of the permission level is adjusted according to the mapping relationship to obtain the initially updated permission table. Examine the logical dependencies between different permission levels in the initially updated permission table, identify and mark conflicting permission settings, and thus generate a permission conflict report; Based on the permission conflict report, the values ​​of the conflicting permission levels are recalibrated to obtain the adjusted permission scheme.

[0054] Specifically, the dynamic permission adjustment factor is 0.2. The permission level mapping table contains the original permission level entries corresponding to each device number. The dynamic permission adjustment factor is mapped to the corresponding permission entries one by one according to the device number. The original permission level value is directly added to the factor. For example, the original first-level permission value of device 1 is 1, and it becomes 1.2 after being added. After all device entries are adjusted, they are integrated to form a preliminary updated permission table.

[0055] The pre-defined logical dependencies in the initially updated permission table were reviewed. For example, the device control permission level must be higher than the data viewing permission level. The permission level values ​​of each dependent device in the table were compared one by one. It was found that the control permission value of device 2 (1.1) was lower than the data viewing permission value of its associated device 3 (1.2). This situation was recorded and marked in detail, and a permission conflict report was generated.

[0056] Extract the conflict entries marked in the permission conflict report. For the permission conflict between device 2 and device 3, recalibrate the control permission value of device 2 to 1.3 to ensure that it is higher than the data viewing permission value of device 3, which is 1.2. After all conflict entries are calibrated, the adjusted permission scheme is obtained by integrating them.

[0057] In summary, when using dynamic permission adjustment factors to modify permission levels in the permission hierarchy mapping table, it provides a scientific and quantitative basis for permission adjustments based on pre-determined environmental risks and task requirements. This ensures that permission values ​​are updated accurately to fit the actual scenario. After the initial update of the permission table, by checking the logical dependencies between different permission levels, conflicting permission settings can be identified and marked in a timely manner, preventing device operation chaos or abnormal function execution due to permission conflicts. Then, by recalibrating conflicting permission values ​​based on permission conflict reports, logical loopholes in the permission system can be eliminated, ensuring the consistency and rationality of permission configuration. The final adjusted permission scheme retains the adaptability of dynamic adjustment factors to the environment and tasks, and ensures the feasibility of the scheme through consistency verification. This lays a precise and reliable foundation for subsequent device group operation permission control, further reducing operational risks caused by improper permission configuration.

[0058] In a preferred embodiment, the device group operation permissions are controlled according to the adjusted permission scheme, and behavioral feedback during device execution is collected, including: The adjusted permission scheme is distributed to each device in the device group, so that each device loads the corresponding permission configuration, thereby forming a device operating environment with controlled permissions. The operation records and operational status data of the monitoring equipment group during task execution are summarized to form a raw behavioral data set; Extract permission-related operation events and status change events from the original behavior data set to form a behavior event sequence; Based on the statistical analysis of permission usage patterns and the frequency of abnormal operations according to behavioral event sequences, a structured behavioral feedback report is compiled.

[0059] Specifically, through a dedicated communication gateway for the device group, the adjusted permission scheme is pushed to all devices in the group one by one in the form of encrypted instructions. After receiving the instruction, each device automatically verifies the unique device number in the instruction. After confirming that it matches its own number, it reads the corresponding permission configuration information in the scheme and overwrites the original configuration. For example, device 1 loads level 1.2 data upload permission, device 2 loads level 1.3 control permission, and finally all devices complete the permission configuration loading, forming a device operating environment with controlled permissions.

[0060] Enable the built-in operation log module and status monitoring module of each device to record operation records such as permission opening / closing operations and function call operations when the device performs tasks in real time, as well as operation status data such as permission execution duration and whether permission call is successful. Manually summarize the recorded data of all devices once an hour, and sort them by device number to form a raw behavior data set.

[0061] Each record in the original behavioral data set is traversed one by one, and operation events containing permission-related keywords such as "permission enabled", "permission invoked", and "permission execution failed" are filtered out, as well as status change events such as permission level change and permission effective status change. These events are arranged in chronological order to form a behavioral event sequence.

[0062] Each event in the behavioral event sequence is classified and statistically analyzed to determine the daily usage frequency, usage time period, and other permission usage patterns for each device with different permissions. At the same time, the frequency of abnormal operations such as attempting to call functions without permission or operating beyond the scope of permissions is also analyzed. All statistical results are organized into a structured behavioral feedback report according to a fixed structure of "device number - permission usage pattern - frequency of abnormal operation".

[0063] In summary, distributing the adjusted permission scheme to each device in the device group, enabling each device to load the corresponding permission configuration, creates a permission-controlled operating environment. This ensures that device operations are strictly limited to the authorized scope, preventing low-compatibility devices from unauthorizedly performing highly complex operations or causing permission conflicts at critical task nodes. It also guarantees the orderly execution of tasks within the group. By monitoring the operation records and operational status data of devices during task execution and summarizing them into a raw behavioral data set, permission-related operation events and status change events can be extracted from this set. This allows for a complete capture of the actual usage of permissions. The permission usage patterns based on these data statistics can intuitively reflect the matching degree between permission configuration and actual device needs. The frequency of abnormal operations can promptly expose potential vulnerabilities or execution deviations in permission control, providing real and comprehensive actual operational data support for subsequent analysis of the effectiveness of permission control and optimization of the permission hierarchy mapping table, thus avoiding a disconnect between permission configuration and actual execution requirements.

[0064] In a preferred embodiment, behavioral feedback is analyzed to verify the effectiveness of access control, and the access hierarchy mapping table is optimized based on the verification results, including: By comparing the operation records in the behavior feedback with the authorization scope in the adjusted permission scheme, we can identify operation events that exceed or fail to reach the authorization scope, and obtain the differences in the permission execution process. The differences are associated with key task nodes, and the impact level of the differences on the task objectives is determined according to the preset impact assessment rules. Based on the preset security policy library, filter out the differences whose impact level exceeds the threshold and classify them as permission configuration items to be optimized; Based on the permission configuration items to be optimized and their corresponding impact levels, the permission levels and constraints in the permission hierarchy mapping table are corrected to form an optimized permission hierarchy mapping table.

[0065] Specifically, the operation records of each device were extracted from the structured behavior feedback report and compared with the authorization scope of each device in the adjusted permission scheme. The operation record of device 1 showed that it attempted to call the control function. However, in the adjusted permission scheme, the authorization scope of device 1 is only level 1.2 data upload. This operation belongs to the event of exceeding the authorization scope. Device 2 did not call the basic function corresponding to its level 1.3 control permission, which belongs to the event of not reaching the authorization scope. These two types of events were sorted into the differences in the permission execution process.

[0066] The key nodes of the task include data acquisition, equipment control, and result uploading. All discrepancies are matched with these nodes one by one. The operation of device 1 that exceeds the authorization is associated with the key node of equipment control. According to the preset impact assessment rules, the discrepancies affecting the core key node are judged as high impact level. The operation of device 2 that does not meet the authorization is associated with the secondary node of data acquisition and is judged as low impact level. The impact level corresponding to each discrepancy point is obtained.

[0067] The preset impact level threshold is high impact level. The policy of "only filtering difference points with impact level higher than the threshold as objects to be optimized" is retrieved from the security policy library. High impact level difference points of device 1 that are outside the authorized scope are filtered out, and the permission configuration of device 1 corresponding to the difference point is classified as permission configuration items to be optimized.

[0068] For the permission configuration item to be optimized, Device 1's permission configuration and its high-impact level, check the permission hierarchy mapping table. Device 1's original permission level is 1.2 and the constraint is "prohibit control operations". Correct its permission level to 1.5 and the constraint to "only allow basic control operations, prohibit advanced control". After all corrections are completed, the optimized permission hierarchy mapping table is formed.

[0069] Specifically, as a preferred implementation, the impact level of the difference on the task objective is determined by the following formula:

[0070] This represents the quantified value of the impact level. Indicates the severity of the difference. Indicates the key factors of the task. The balance coefficient is a preset constant between 0 and 1. : Indicates the frequency of occurrence of differences.

[0071] It should be noted that the severity of the difference points in the formula comes from the differences during the permission execution process. The specific value is determined manually based on the type of difference point. Difference points that exceed the authorized range are judged as high severity with a score of 0.8, while difference points that do not reach the authorized range are judged as low severity with a score of 0.3.

[0072] The task criticality factor comes from the task critical nodes associated with the differences. Core critical nodes, such as equipment control nodes, correspond to a high criticality factor of 0.9, while secondary critical nodes, such as data acquisition nodes, correspond to a low criticality factor of 0.4. The factors are set manually by referring to the task node importance list.

[0073] The balance coefficient is a fixed constant preset by the system between 0 and 1. Technicians determine the specific value based on historical permission execution data, for example, setting it to 0.6 to emphasize the impact of the severity of the difference.

[0074] The frequency of difference points is derived from the sequence of behavioral events. All difference point events recorded in the sequence are traversed one by one, and the number of times the same type of difference point occurs is counted. The specific value is obtained by directly counting.

[0075] The entire calculation process takes into account the severity of the discrepancy itself, the criticality of the task node it belongs to, and the frequency of the discrepancy, so as to accurately quantify the impact of the discrepancy on the task objective and provide a basis for subsequent screening of permission configuration items to be optimized.

[0076] In general, as the severity of discrepancies increases, the overall weighted value also increases, and the quantitative value of the impact level also increases accordingly. When the task criticality factor increases, the overall weighted value will increase accordingly, and the final quantitative value of the impact level will also increase. When the balance coefficient increases, the weight of the severity of discrepancies in the overall weighted value increases. If the severity of discrepancies is high, the quantitative value of the impact level will increase accordingly. When the frequency of discrepancies increases, the logarithm of 1 plus that frequency will increase, and the quantitative value of the impact level will also increase. However, as the frequency continues to increase, the growth rate of the logarithm will gradually slow down, resulting in a slower growth rate of the quantitative value of the impact level.

[0077] In summary, by comparing the operation records in the behavioral feedback with the authorization scope in the adjusted permission scheme, it can accurately identify operation events that exceed or fall short of the authorization scope, find the differences in the permission execution process, associate the differences with key task nodes, and determine the impact level according to preset impact assessment rules. This clarifies the degree of impact of the differences on task objectives, avoiding excessive optimization resources for non-critical issues. By filtering differences with impact levels exceeding the threshold based on the preset security policy library and classifying them as permission configuration items to be optimized, it can focus on core optimization needs and ensure that the optimization direction aligns with actual management pain points. Based on the permission configuration items to be optimized and their corresponding impact levels, the permission levels and constraints in the permission hierarchy mapping table are modified, allowing the mapping table to continuously adapt to device operating status and task changes. This compensates for the lack of closed-loop optimization in existing static permissions, further improves the accuracy of permission control, and provides reliable support for the effective implementation of subsequent permission schemes.

[0078] In a preferred embodiment, a permission level control report is compiled based on an optimized permission level mapping table, including: Extract permission level change records and associated constraints from the optimized permission hierarchy mapping table to form a permission change data set; By comparing the differences between the permission change dataset and the historical permission scheme, the trend and distribution characteristics of permission adjustments are analyzed, and the results of permission adjustment analysis are obtained. Integrate the data set of permission changes and the analysis results of permission adjustments, and organize them in a structured manner according to the preset report format to form a permission hierarchical control report.

[0079] Specifically, the permission level change records of each device are extracted row by row from the optimized permission hierarchy mapping table, including device number, permission level before change, and permission level after change. At the same time, the related constraint condition change content corresponding to each permission is extracted. For example, the constraint condition of device 1 before change is "prohibit control operation" and after change is "only allow basic control operation, prohibit advanced control". The change records of all devices are organized according to the structure of "device number - permission change information - constraint condition change information" to form a permission change data set.

[0080] By retrieving the historical permission scheme, i.e. the permission level mapping table before optimization, and comparing the permission level and constraints in the permission change data set for each device, the differences were identified: the permission level of device 1 was upgraded from level 1.2 to level 1.5, and the constraints included the addition of basic control permissions. Statistical analysis revealed that permission adjustments were concentrated on data upload and basic control permissions. The permissions of core operating devices were generally upgraded, while there were no changes to non-core devices. Based on this analysis, the permission adjustment trend is tilted towards core devices, and the distribution characteristic is that functionally related permissions are concentratedly adjusted.

[0081] The specific change records in the permission change data set are used as the first part of the report, "Permission Change Details," and the permission adjustment analysis results are used as the second part, "Permission Adjustment Analysis." The reports are structured according to the preset report format of "Details-Analysis-Summary." The summary section briefly explains the core purpose and effect of permission optimization. The whole report is logically coherent and complete in terms of content, forming a hierarchical permission control report.

[0082] In summary, extracting permission level change records and associated constraints from the optimized permission hierarchy mapping table to form a permission change data set can completely retain key details of permission optimization, avoid omissions or confusion of change information, and provide a clear basis for subsequent traceability of permission adjustment processes. Comparing the permission change data set with historical permission schemes and analyzing adjustment trends and distribution characteristics can intuitively present the core direction of permission adjustments, such as whether it is tilted towards core operating equipment or whether it is concentrated on specific function-related permissions, making the permission adjustment logic more transparent. Integrating the data set and analysis results into a structured report in a preset format can make the report content clear, well-organized, and easy to understand. This allows relevant personnel to quickly grasp the specific situation and inherent rules of permission optimization, providing accurate and easy-to-understand references for subsequent permission control strategy adjustments, system iterations, or task planning, and further ensuring the traceability and scientific decision-making of the unmanned equipment group permission control system.

[0083] Example 2, as Figure 2 The diagram shown is a functional block diagram of a hierarchical management system for unmanned equipment groups provided in an embodiment of the present invention.

[0084] This invention discloses a hierarchical access control system 100 for unmanned equipment groups, which can be installed in an electronic device. Depending on the functions implemented, the hierarchical access control system 100 may include a mapping table construction module 101, a dynamic access control factor determination module 102, an access control modification module 103, a behavior feedback collection module 104, a mapping table optimization module 105, and a control report output module 106. The modules of this invention can also be referred to as units, which are a series of computer program segments that can be executed by the processor of an electronic device and perform a fixed function, stored in the memory of the electronic device.

[0085] In this embodiment, the functions of each module / unit are as follows: The mapping table construction module 101 is used to collect attribute data of each device in the unmanned equipment group and, in combination with task details, construct a permission hierarchical mapping table. The dynamic permission adjustment factor determination module 102 is used to perform feature analysis on the acquired environmental data, determine the risk level based on the analysis results, and match the risk level with the preset adjustment strategy in the permission level mapping table to determine the dynamic permission adjustment factor. The permission modification module 103 is used to modify the permission level in the permission hierarchy mapping table by applying dynamic permission adjustment factors, and to form the adjusted permission scheme after verifying permission consistency. The behavior feedback collection module 104 is used to control the operation permissions of device groups according to the adjusted permission scheme and collect behavior feedback during the execution of the device. The mapping table optimization module 105 analyzes behavioral feedback to verify the effectiveness of access control, and optimizes the hierarchical access mapping table based on the verification results. The control report output module 106 is used to compile a permission level control report based on an optimized permission level mapping table.

[0086] In the several embodiments provided by this invention, it should be understood that the disclosed methods and systems can be implemented in other ways. For example, the system embodiments described above are merely illustrative; for instance, the division of modules is only a logical functional division, and other division methods may be used in actual implementation.

[0087] The modules described as separate components may or may not be physically separate. The components shown as modules may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.

[0088] Furthermore, the functional modules in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or in the form of hardware plus software functional modules.

[0089] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention.

[0090] The embodiments of this application can acquire and process relevant data based on artificial intelligence technology. Artificial intelligence is the theory, method, technology, and application system that uses digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use that knowledge to obtain optimal results.

[0091] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention.

Claims

1. A method for hierarchical management and control of unmanned device group permissions, characterized in that, The method comprises: S1, collecting attribute data of each device in the unmanned device group, and combining task details to construct a permission hierarchical mapping table; S2, performing feature analysis on the obtained environmental data, and determining the risk level according to the analysis result, matching the risk level with the preset adjustment strategy in the permission hierarchical mapping table to determine the dynamic permission adjustment factor; S3, applying the dynamic permission adjustment factor to modify the permission level in the permission hierarchical mapping table, and forming an adjusted permission scheme after verifying the permission consistency; S4, controlling the operation permission of the device group according to the adjusted permission scheme, and collecting behavior feedback in the device execution process; S5, analyzing the behavior feedback to verify the effectiveness of the permission control, and optimizing the permission hierarchical mapping table based on the verification result; S6, compiling a permission hierarchical management and control report based on the optimized permission hierarchical mapping table.

2. The method of claim 1, wherein the group authority of the unmanned device is determined according to the following formula: Group Authority = Group Authority of the first unmanned device + Group Authority of the second unmanned device + Group Authority of the third unmanned device. The collection of attribute data of each device in the unmanned device group and the combination of task details to construct a permission hierarchical mapping table comprises: Extract attribute data from the configuration file of each device in the unmanned device group, and verify the data integrity to obtain a set of valid attribute data; Obtain task detail records from the task management system, and parse the task key elements to obtain parsed task details; Associate and match the set of valid attribute data with the parsed task details, assign permission levels based on preset permission rules, and form a permission hierarchical mapping table. 3.The method of claim 1, wherein, The feature analysis on the obtained environmental data comprises: Obtain original environmental parameters from external environmental sensors and internal device logs, and perform format standardization processing on the original environmental parameters to obtain a set of standardized environmental data; Analyze the cooperative fluctuation relationship of different parameter change sequences in the set of standardized environmental data to obtain the strength of the correlation between parameters, and configure the environmental parameters to a matrix structure based on the parameter type to construct a correlation matrix representing the environmental state; Compare the correlation matrix with the preset environmental safety benchmark to identify abnormal parameter combinations that exceed the safety threshold, and obtain the feature analysis result.

4. The method of claim 3, wherein the group authority of the unmanned device is determined according to the following formula: Group Authority = Group Authority of the first unmanned device + Group Authority of the second unmanned device + Group Authority of the third unmanned device. The determination of the risk level according to the analysis result, the matching of the risk level with the preset adjustment strategy in the permission hierarchical mapping table, and the determination of the dynamic permission adjustment factor comprise: Compare the feature analysis result with the preset risk threshold, divide the risk level according to the comparison result, and obtain the risk level determination result; Map the risk level determination result to the strategy index in the permission hierarchical mapping table, retrieve the corresponding adjustment strategy set according to the strategy index; Filter the applicable strategy in the adjustment strategy set according to the current task stage and device state to determine the dynamic permission adjustment factor.

5. The method of claim 4, wherein the group permission hierarchy is determined based on a group hierarchy of the unmanned devices. The matching of the risk level with the preset adjustment strategy in the permission hierarchical mapping table to determine the dynamic permission adjustment factor comprises: Compare the key nodes of the current task stage with the running indicators in the device state report to locate the applicable strategy that meets the current context from the adjustment strategy set; Analyze the permission adjustment rules and constraints contained in the applicable strategy to form a strategy analysis framework; Quantify the rules in the policy analysis framework into permission modification coefficients, and take the permission modification coefficients as dynamic permission adjustment factors.

6. The method of claim 1, wherein, The application modifies the permission levels in the permission hierarchical mapping table by using the dynamic permission adjustment factors, including: Map the dynamic permission adjustment factors to the corresponding permission entries in the permission hierarchical mapping table, adjust the numerical values of the permission levels according to the mapping relationship, and thus obtain a preliminary updated permission table; Check the logical dependency relationship between different permission levels in the preliminary updated permission table, identify and mark the conflicting permission settings, and thus form a permission conflict report; According to the adjusted permission scheme, control the device group operation permission, collect the behavior feedback in the device execution process, including:

7. The method of claim 1, wherein the method further comprises: Distribute the adjusted permission scheme to each device in the device group, make each device load the corresponding permission configuration, and thus form a permission controlled device running environment; Monitor the operation records and running state data of the device group when performing tasks, and aggregate to form an original behavior data set; Extract the permission related operation events and state change events from the original behavior data set to form a behavior event sequence; Based on the behavior event sequence, statistics the permission usage mode and abnormal operation frequency, and compile into a structured behavior feedback report. The analysis of behavior feedback is to verify the effectiveness of permission control, and based on the verification result, the permission hierarchical mapping table is optimized, including: 8.The method of claim 7, wherein, Compare the operation records in the behavior feedback with the authorized range in the adjusted permission scheme, identify the operation events that exceed or do not reach the authorized range, and obtain the difference points in the permission execution process; Associate the difference points with the task critical nodes, and determine the influence level of the difference on the task target according to the preset influence evaluation rule; According to the preset security policy library, filter the difference points with influence level exceeding the threshold, and classify them as permission configuration items to be optimized; Based on the permission configuration items to be optimized and their corresponding influence level, correct the permission levels and constraint conditions in the permission hierarchical mapping table, and form an optimized permission hierarchical mapping table. Based on the optimized permission hierarchical mapping table, compile the permission hierarchical control report, including: 9.The method of claim 1, wherein, Extract the permission level change records and associated constraint conditions from the optimized permission hierarchical mapping table to form a permission change data set; Compare the difference between the permission change data set and the historical permission scheme, analyze the trend and distribution characteristics of the permission adjustment, and obtain the permission adjustment analysis result; Integrate the permission change data set and the permission adjustment analysis result, and structure according to the preset report format to form the permission hierarchical control report. The system includes:

10. An unmanned device group authority hierarchical management system, characterized in that, The mapping table construction module is used for collecting the attribute data of each device in the unmanned device group, and constructing the permission hierarchical mapping table combined with the task details; The dynamic permission adjustment factor determination module is used for performing feature analysis on the obtained environment data, determining the risk level according to the analysis result, matching the risk level with the preset adjustment strategy in the permission hierarchical mapping table, and thus determining the dynamic permission adjustment factor; The behavior feedback analysis module is used for collecting the behavior feedback in the device execution process according to the adjusted permission scheme, including: Distribute the adjusted permission scheme to each device in the device group, make each device load the corresponding permission configuration, and thus form a permission controlled device running environment; Monitor the operation records and running state data of the device group when performing tasks, and aggregate to form an original behavior data set; Extract the permission related operation events and state change events from the original behavior data set to form a behavior event sequence; Based on the behavior event sequence, statistics the permission usage mode and abnormal operation frequency, and compile into a structured behavior feedback report. The analysis of behavior feedback is to verify the effectiveness of permission control, and based on the verification result, the permission hierarchical mapping table is optimized, including: Compare the operation records in the behavior feedback with the authorized range in the adjusted permission scheme, identify the operation events that exceed or do not reach the authorized range, and obtain the difference points in the permission execution process; Associate the difference points with the task critical nodes, and determine the influence level of the difference on the task target according to the preset influence evaluation rule; According to the preset security policy library, filter the difference points with influence level exceeding the threshold, and classify them as permission configuration items to be optimized; Based on the permission configuration items to be optimized and their corresponding influence level, correct the permission levels and constraint conditions in the permission hierarchical mapping table, and form an optimized permission hierarchical mapping table. Based on the optimized permission hierarchical mapping table, compile the permission hierarchical control report, including: Extract the permission level change records and associated constraint conditions from the optimized permission hierarchical mapping table to form a permission change data set; Compare the difference between the permission change data set and the historical permission scheme, analyze the trend and distribution characteristics of the permission adjustment, and obtain the permission adjustment analysis result; Integrate the permission change data set and the permission adjustment analysis result, and structure according to the preset report format to form the permission hierarchical control report. The permission modification module is configured to apply a dynamic permission adjustment factor to modify the permission levels in the permission level mapping table, and to form an adjusted permission scheme after verifying the consistency of the permissions. The behavior feedback collection module is configured to control the operation permissions of the device group according to the adjusted permission scheme, and to collect behavior feedback during execution of the device. The mapping table optimization module is configured to analyze the behavior feedback to verify the effectiveness of the permission control, and to optimize the permission level mapping table based on the verification result. The management and control report output module is configured to compile a permission level management and control report based on the optimized permission level mapping table.