A private deployment and permission control method for data security of a bidding service

By constructing a dynamic permission mapping model based on business scenarios and a semantic parsing dynamic desensitization engine, combined with distributed permission nodes and incremental update mechanisms, the problems of response delay and operational risks in dynamic permission adjustments of bidding business data have been solved, achieving field-level differentiated desensitization and efficient permission management.

CN122133173APending Publication Date: 2026-06-02LUZHOU DEVELOPMENT INTERNATIONAL PROJECT CONSULTING CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
LUZHOU DEVELOPMENT INTERNATIONAL PROJECT CONSULTING CO LTD
Filing Date
2025-10-23
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

In the existing technology, the dynamic permission adjustment of bidding business data relies on manual configuration, which leads to high response delays and operational risks. It cannot achieve field-level dynamic desensitization, resulting in low system efficiency when business processes change.

Method used

A dynamic permission mapping model based on business scenarios is constructed. Combined with a temporary permission set generation mechanism, a field sensitivity level matrix and a semantic parsing dynamic desensitization engine are used to achieve differentiated desensitization at the field level within the same document. Furthermore, the system response speed is improved through distributed permission nodes and an incremental update mechanism.

Benefits of technology

It has achieved deep integration of bidding business data security control with business processes, significantly improving data confidentiality, integrity and system operating efficiency, and reducing manual decision-making costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122133173A_ABST
    Figure CN122133173A_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of data security and authority management, in particular to a private deployment and authority control method for bidding business data security. The present application solves the problems of response delay and operation risk caused by manual configuration of authority adjustment in traditional schemes by constructing a dynamic mapping model of business scenarios and authorities and combining a temporary authority set generation mechanism. Through a field sensitivity level matrix and a semantic analysis dynamic desensitization engine, the present application realizes differentiated desensitization at the field level within the same document, avoids information redundancy of full document encryption and maintenance difficulties of application layer hard coding. A distributed authority node and an incremental update mechanism improve the response speed and stability of the system when the business process changes. A machine learning prediction model optimizes authority configuration recommendation through historical data, reducing the cost of manual decision-making. The overall scheme realizes deep coupling of bidding business data security control and business process, significantly improving data confidentiality, integrity and system operation efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data security and access control technology, specifically a method for the private deployment and access control of bidding business data security. Background Technology

[0002] Bidding data typically contains sensitive information such as bidder qualifications, quotations, and technical solutions, and its flow involves multiple parties including bidding platforms, evaluation experts, and regulatory agencies. To ensure data confidentiality and integrity, traditional solutions often employ public cloud encrypted storage or basic access control isolation. However, the business logic of bidding data is highly dynamic, including scenarios such as temporary access control during the evaluation phase and field-level data anonymization in multi-level approvals. This necessitates a security architecture that is deeply coupled with business processes, rather than simply relying on static encryption or role-based classification.

[0003] Current mainstream private deployment solutions suffer from the following problems when dealing with dynamic access control requirements: During the bidding process, the system frequently needs to adjust the data access scope of expert group members. However, due to the separation of access policies from business logic, each change requires manual reconfiguration of encryption keys or modification of database ACL rules, leading to response delays and increased operational risks. Furthermore, existing technologies cannot achieve dynamic anonymization at the field level within the same document. For example, in the same tender document, commercial quotations and technical parameters need to be displayed in real-time according to the differences in review roles. Existing methods either encrypt the entire document, causing information redundancy, or rely on hard-coded rules at the application layer, which are difficult to maintain. This architecture of decoupling business logic from security control has become a major bottleneck for accurate access control of bidding data. Summary of the Invention

[0004] To address the shortcomings of existing technologies, this invention provides a method for the secure private deployment and access control of bidding business data. This method solves the problems of response delays, high operational risks, and the inability to achieve field-level dynamic desensitization that arise from the reliance on manual configuration for dynamic access control of bidding data compared to existing technologies.

[0005] To achieve the above objectives, the present invention provides the following technical solution: a method for secure private deployment and access control of bidding business data, comprising the following steps:

[0006] Construct a dynamic permission mapping model based on business scenarios, and abstract the bid evaluation stage and multi-level approval nodes in the bidding process into permission trigger events;

[0007] When identifying business scenario parameters, a temporary permission set is generated in real time according to the preset scenario and permission mapping rules;

[0008] Establish a sensitivity level matrix for bidding data fields, and classify and label the bidder's qualifications, quotations, and technical solutions data in the bidding data according to their sensitivity.

[0009] Develop a dynamic de-identification engine based on semantic parsing, and link the de-identification engine with the business role permission system;

[0010] When different roles access the same document, the desensitization engine analyzes the role permission level of the accessing subject in real time and performs differentiated desensitization processing on different fields in the document based on the field sensitivity level matrix.

[0011] Store the de-identification rules in a configurable rule base;

[0012] Deploy distributed permission nodes in a private deployment environment, with each permission node maintaining real-time communication with the business process engine;

[0013] When a business process changes, the permission node receives the change information through the event bus and uses an incremental permission calculation method to synchronously update the changed permission items.

[0014] A machine learning module is introduced to analyze historical permission adjustment records and the frequency of business scenario changes, and a permission adjustment prediction model is built.

[0015] When the system detects that a similar business scenario reappears, the prediction model recommends a permission configuration scheme.

[0016] The model parameters are continuously optimized based on actual operational feedback.

[0017] Furthermore, the specific process of constructing a dynamic permission mapping model based on business scenarios, which abstracts the bid evaluation stage and multi-level approval nodes in the bidding process into permission-triggered events, is as follows:

[0018] Analyze each stage and key operation of the bidding process to identify business scenarios that require dynamic adjustment of permissions;

[0019] For each business scenario, define scenario-related business parameters, including the expert's field of expertise, the type of review object, and the approval level.

[0020] Key operational nodes in the abstract bidding process, such as the bid evaluation stage and multi-level approval, are authorized trigger events, which are then associated with business scenarios.

[0021] Establish a mapping relationship between business scenarios and permission rules. The mapping relationship defines the set of permission rules that should be generated under a specific business scenario.

[0022] The dynamic permission mapping model includes business scenarios, business parameters, permission triggering events, and mapping relationships.

[0023] Furthermore, when identifying business scenario parameters, a temporary permission set is generated in real time using preset scenario and permission mapping rules. The specific process is as follows:

[0024] When the system detects that a preset permission-triggered event has occurred, it automatically obtains the context information of the current business process;

[0025] Parse the context information to identify the specific parameters of the current business scenario. The business scenario parameters include the current user role, the composition information of the bidding expert group, the confidentiality level of the bidding project, and the current approval status.

[0026] Based on business scenario parameters, retrieve scenario and permission mapping rules that match the current business scenario from the dynamic permission mapping model;

[0027] Based on the retrieved mapping rules, a set of temporary permissions is generated in real time. The temporary permission set includes data access permissions, operation execution permissions, and time range limits.

[0028] Once the temporary permission set is generated, it is distributed to the relevant data access control components or permission enforcement points.

[0029] Furthermore, the specific process of establishing the sensitivity level matrix of the bidding data fields, and classifying and marking the bidder qualifications, quotations, and technical solutions data in the bidding data according to their sensitivity, is as follows:

[0030] Identify all potentially sensitive fields in the bidding business data, including the bidder's identity information, contact information, historical performance, and core innovations in the technical solution;

[0031] Conduct risk assessments on identified sensitive fields and determine their sensitivity level based on the potential damage caused by information leakage. Sensitivity levels include public, restricted, confidential, and top secret.

[0032] Construct a sensitivity level matrix for bidding data fields. The rows of the matrix represent sensitive fields, the columns represent sensitivity levels, and the matrix cells store the sensitivity levels corresponding to the fields.

[0033] The bidding data, including bidder qualifications, quotations, and technical solutions, are classified and labeled according to their sensitivity, based on a field sensitivity level matrix.

[0034] Furthermore, the specific process of developing a dynamic de-identification engine based on semantic parsing and linking the de-identification engine with the business role permission system is as follows:

[0035] Develop a semantic parsing module that can identify different field types and their contextual meanings in bidding documents;

[0036] Build a de-identification algorithm library to complement the semantic parsing module. The algorithm library includes partial masking, complete hiding, data encryption, and format-preserving de-identification algorithms.

[0037] The architecture of the dynamic de-identification engine is designed, which includes a data interception layer, a semantic parsing layer, an access control layer, and a de-identification processing layer.

[0038] The data masking engine is deployed on the data access path to intercept all access requests to bidding business data;

[0039] The de-identification engine is integrated with the business role and permission system via an interface. This interface integration is used to obtain real-time role and permission information of the access subject.

[0040] Furthermore, when different roles access the same document, the desensitization engine analyzes the role permission level of the accessing subject in real time, and performs differentiated desensitization processing on different fields in the document based on the field sensitivity level matrix. The specific process is as follows:

[0041] The de-identification engine obtains the access subject identifier and the requested document identifier from the access request;

[0042] The de-identification engine queries the current role and permission level of the access subject from the business role and permission system through interface integration;

[0043] The de-identification engine locates the content of the document based on the document identifier and uses the semantic parsing module to identify the various fields contained in the document;

[0044] For each field identified in the document, the desensitization engine looks up the sensitivity level corresponding to that field in the field sensitivity level matrix.

[0045] The de-identification engine compares the access subject's role and permission level with the field's sensitivity level, and selects a suitable de-identification algorithm from the de-identification algorithm library according to the preset de-identification strategy.

[0046] Apply desensitization algorithms to the fields and perform differentiated desensitization processing. For example, partially mask the business quotation field and fully display the technical parameter field.

[0047] Furthermore, the specific process of storing the de-identification rules in a configurable rule base is as follows:

[0048] A configurable rule base is used to store the policy rules that the de-identification engine uses when performing field-level dynamic de-identification processing;

[0049] The masking rules define the specific masking methods for fields with different sensitivity levels under different role permission levels. The masking methods include mask length, replacement characters, and display format.

[0050] The rule base supports adding, deleting, modifying, and querying de-identification rules, and these operations can be configured through the management interface.

[0051] The de-identification engine dynamically loads de-identification rules from the rule base at runtime, without requiring modification to the application code.

[0052] Furthermore, the specific process of deploying distributed permission nodes in a private deployment environment, with each permission node maintaining real-time communication with the business process engine, is as follows:

[0053] Deploy independent permission node instances on multiple servers or virtual machines in a private deployment environment;

[0054] A real-time communication channel based on a message queue or event bus is established between the permission node and the business process engine.

[0055] The permission node has a local permission caching mechanism to store recently accessed permission data;

[0056] A data synchronization mechanism is established between each permission node to maintain the consistency of permission data among the nodes.

[0057] Furthermore, when the business process changes, the permission node receives the change information through the event bus and uses an incremental permission calculation method to synchronously update the changed permission items. The specific process is as follows:

[0058] When the status of a business process changes, such as when the members of the expert group are adjusted or the approval process is redirected, the business process engine publishes a permission change event to the event bus.

[0059] Distributed permission nodes subscribe to the event bus to receive permission change events in real time.

[0060] The permission node identifies the specific permission items that need to be adjusted based on the type and content of the change event;

[0061] The permission nodes use an incremental permission calculation method, which only calculates and updates the identified permission items, avoiding the need to recalculate all permissions.

[0062] The permission node will synchronize the incrementally updated permission items to the relevant data access control components and update the local cache.

[0063] Furthermore, when the system detects that a similar business scenario recurs, the predictive model recommends a permission configuration scheme, and the specific process of continuously optimizing the model parameters based on actual operational feedback is as follows:

[0064] The machine learning module collects historical permission adjustment records, including business scenario identifiers, configurations before and after the permission adjustment, and adjustment time.

[0065] The machine learning module analyzes the frequency of business scenario changes and historical permission adjustment patterns, and builds a permission adjustment prediction model based on historical data.

[0066] When the system detects that the current business scenario matches a similar business scenario in the historical scenario library, the prediction model outputs a recommended permission configuration scheme based on the matching result.

[0067] The system collects feedback data based on the adoption of recommended solutions and their operational effects in actual applications;

[0068] The machine learning module uses feedback data to retrain the prediction model and continuously optimize the model parameters. The optimization goals include improving the accuracy of permission recommendations and the applicability of the recommendation scheme.

[0069] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0070] This invention solves the response delay and operational risks caused by manual configuration for permission adjustments in traditional solutions by constructing a dynamic mapping model between business scenarios and permissions, combined with a temporary permission set generation mechanism. Through a field-sensitive matrix and a semantic parsing dynamic desensitization engine, it achieves differentiated desensitization at the field level within the same document, avoiding information redundancy from full-document encryption and the maintenance difficulties of application-layer hard-coding. Distributed permission nodes and incremental update mechanisms improve the system's response speed and stability during business process changes. Machine learning prediction models optimize permission configuration recommendations using historical data, reducing the cost of manual decision-making. The overall solution achieves deep coupling between the security management of bidding business data and business processes, significantly improving data confidentiality, integrity, and system operating efficiency. Attached Figure Description

[0071] Figure 1 This is a flowchart of the method of the present invention;

[0072] Figure 2 Flowchart of dynamic permission generation driven by business scenarios for this invention

[0073] Figure 3 This is a sequence diagram of the semantic parsing-based differential desensitization method of the present invention;

[0074] Figure 4 The self-optimizing state machine diagram for permission configuration in this invention. Detailed Implementation

[0075] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0076] Please see Figures 1-4This invention provides a method for the secure private deployment and access control of bidding business data, comprising the following steps:

[0077] Construct a dynamic permission mapping model based on business scenarios, and abstract the bid evaluation stage and multi-level approval nodes in the bidding process into permission trigger events;

[0078] When identifying business scenario parameters, a temporary permission set is generated in real time according to the preset scenario and permission mapping rules;

[0079] Establish a sensitivity level matrix for bidding data fields, and classify and label the bidder's qualifications, quotations, and technical solutions data in the bidding data according to their sensitivity.

[0080] Develop a dynamic de-identification engine based on semantic parsing, and link the de-identification engine with the business role permission system;

[0081] When different roles access the same document, the desensitization engine analyzes the role permission level of the accessing subject in real time and performs differentiated desensitization processing on different fields in the document based on the field sensitivity level matrix.

[0082] Store the de-identification rules in a configurable rule base;

[0083] Deploy distributed permission nodes in a private deployment environment, with each permission node maintaining real-time communication with the business process engine;

[0084] When a business process changes, the permission node receives the change information through the event bus and uses an incremental permission calculation method to synchronously update the changed permission items.

[0085] A machine learning module is introduced to analyze historical permission adjustment records and the frequency of business scenario changes, and a permission adjustment prediction model is built.

[0086] When the system detects that a similar business scenario reappears, the prediction model recommends a permission configuration scheme.

[0087] The model parameters are continuously optimized based on actual operational feedback.

[0088] Specifically, this embodiment addresses the issues in the background technology where dynamic permission adjustments for bidding data rely on manual configuration, leading to response delays, high operational risks, and the inability to achieve field-level dynamic desensitization. It implements security control through the following steps:

[0089] When constructing a dynamic permission mapping model based on business scenarios, the entire bidding process is first analyzed. Key nodes in the bid evaluation stage, such as expert selection and review scoring, and departmental preliminary review and director review in multi-level approvals, are abstracted into permission trigger events. For example, in the bid evaluation stage, when the system triggers the "expert selection completed" event, it is automatically associated with the "bid evaluation permission allocation" scenario; when the approval process enters the "director review" node, the "advanced approval permission activation" event is triggered.

[0090] When identifying business scenario parameters, the system generates a temporary permission set in real time based on preset mapping rules. For example, in a project bidding scenario, after the system detects the "expert selection completed" event, it automatically obtains the current context information, parsing that the expert's field is "construction engineering," the type of bid being reviewed is "general contracting," and the project's confidentiality level is "confidential." Based on the mapping rules, the generated temporary permission set includes: allowing the expert to access the project's technical solution (excluding core parameters), view the bidder's qualifications (with contact information hidden), and perform scoring operations. The validity period of these permissions is limited to 24 hours from the start to the end of the bidding process.

[0091] When establishing a sensitivity level matrix for bidding data fields, first identify all sensitive fields, such as the bidder's business license number, project manager's qualification certificate number, price quotation details, and patented technologies in the technical solution. Determine the sensitivity level through risk assessment: business license number is "Restricted," project manager's qualification certificate number is "Restricted," price quotation details are "Confidential," and patented technologies are "Top Secret." Matrix rows are named after the fields, columns are divided by sensitivity level, and matrix cells clearly define the correspondence; for example, the intersection of the "Price Quotation Details" row and the "Confidential" column is marked as "Yes."

[0092] When developing a dynamic data masking engine based on semantic parsing, the semantic parsing module uses natural language processing technology to identify document fields, such as extracting the "quotation" field and its value from "quotation: 12 million yuan" in a tender document. The data masking algorithm library includes: partial masking algorithms (e.g., retaining the first 4 characters and replacing the last N characters with *), complete hiding algorithms (directly replacing with ***), AES encryption algorithms, and format-preserving data masking algorithms (e.g., converting 1385678 to 1396789). In the dynamic data masking engine architecture, the data interception layer captures all data access requests; the semantic parsing layer parses document fields; the permission judgment layer calls the business role permission system interface to obtain the access subject's permission level; and the data masking layer applies algorithms based on the judgment results.

[0093] When different roles access the same document, such as a "review expert" and a "regulatory personnel" accessing the same tender document: After obtaining the access subject's identifier, the de-identification engine determines that the "review expert" has a "Level 2" access level, while the "regulatory personnel" has a "Level 3" access level. After parsing the document fields, based on the sensitivity level matrix, "Quotation Details" is classified as "Confidential." In the default strategy, Level 2 access performs partial masking on "Confidential" fields (e.g., 12 million yuan → 12** million yuan), while Level 3 access displays them completely. Therefore, the expert sees the partially masked quotation, while the regulator sees the complete quotation.

[0094] The de-identification rules are stored in a configurable rule base. In the rule base, the de-identification rule for "confidential" level fields under level 2 permissions is "keep the first 2 digits and replace the rest with *". Administrators can modify this rule to "keep the first 3 digits" through the interface without modifying the engine code.

[0095] In a private deployment environment, distributed permission nodes are deployed on three servers. These nodes communicate with the business process engine via a RabbitMQ message queue. Each node caches permission data from the last 24 hours, and data synchronization between nodes is achieved using the Raft protocol to ensure consistency of permission information.

[0096] When a business process changes, such as when the number of members in the evaluation expert group increases from 5 to 7, the business process engine publishes an "Expert Group Member Change" event to the event bus. Upon receiving the event, the permission node identifies the permission items that need adjustment as the access permissions for the two newly added experts. An incremental permission calculation method is used, generating permission sets only for the new experts, rather than recalculating the permissions for all five existing experts. After the update is complete, it is synchronized to the data access control component and the local cache is refreshed.

[0097] When introducing the machine learning module, permission adjustment records from the past three years are collected, including data such as the timing of expert permission adjustments and the permission items involved in the "construction project bidding" scenario. A predictive model is built using a collaborative filtering algorithm. When the similarity between the current "municipal engineering bidding" scenario and the historical "road engineering bidding" scenario reaches 85%, a similar expert permission configuration scheme is recommended. Based on the actual adoption rate, for example, if the recommended scheme is adopted 70%, the model parameters are optimized using a gradient descent algorithm to improve the accuracy of subsequent recommendations.

[0098] This embodiment solves the problem of delay in manual configuration by using a dynamic permission mapping model, achieves field-level desensitization by using a dynamic desensitization engine, and improves the system's response speed and intelligence level by using distributed nodes and machine learning.

[0099] In this embodiment, a dynamic permission mapping model based on business scenarios is constructed. The specific process of abstracting the bid evaluation stage and multi-level approval nodes in the bidding process into permission triggering events is as follows:

[0100] Analyze each stage and key operation of the bidding process to identify business scenarios that require dynamic adjustment of permissions;

[0101] For each business scenario, define scenario-related business parameters, including the expert's field of expertise, the type of review object, and the approval level.

[0102] Key operational nodes in the abstract bidding process, such as the bid evaluation stage and multi-level approval, are authorized trigger events, which are then associated with business scenarios.

[0103] Establish a mapping relationship between business scenarios and permission rules. The mapping relationship defines the set of permission rules that should be generated under a specific business scenario.

[0104] The dynamic permission mapping model includes business scenarios, business parameters, permission triggering events, and mapping relationships.

[0105] Specifically, when analyzing the bidding process, the focus is on the expert check-in, review initiation, and objection handling stages in the bid evaluation phase, as well as the departmental review, legal review, and final review stages in the multi-level approval process, identifying that the permissions for each of these stages need to be dynamically adjusted.

[0106] For the above business scenarios, the following business parameters are defined: the expert's field of expertise includes "information technology", "civil engineering", "mechanical and electrical equipment", etc.; the types of review targets are divided into "service", "goods", and "engineering"; and the approval levels are divided into "department level", "company level", and "group level".

[0107] Abstract permission trigger events, such as the "Expert check-in completed" event associated with the "Bidding permission activated" scenario, and the "Legal review passed" event associated with the "Final review permission opened" scenario.

[0108] When establishing mapping relationships, for example, the set of permission rules corresponding to the scenario of "engineering target + departmental approval" is: allow department managers to view the bidder's qualifications and technical solutions, and prohibit access to quotation details.

[0109] The dynamic permission mapping model is stored in a relational database, using the scenario ID as the primary key, and associates business parameters, trigger events, and permission rule sets to achieve precise binding between scenarios and permissions.

[0110] This implementation method clarifies the relationship between business scenarios and permissions, providing a foundation for dynamic permission generation and reducing the randomness of permission configuration.

[0111] In this embodiment, when identifying business scenario parameters, a temporary permission set is generated in real time according to preset scenario and permission mapping rules. The specific process is as follows:

[0112] When the system detects that a preset permission-triggered event has occurred, it automatically obtains the context information of the current business process;

[0113] Parse the context information to identify the specific parameters of the current business scenario. The business scenario parameters include the current user role, the composition information of the bidding expert group, the confidentiality level of the bidding project, and the current approval status.

[0114] Based on business scenario parameters, retrieve scenario and permission mapping rules that match the current business scenario from the dynamic permission mapping model;

[0115] Based on the retrieved mapping rules, a set of temporary permissions is generated in real time. The temporary permission set includes data access permissions, operation execution permissions, and time range limits.

[0116] Once the temporary permission set is generated, it is distributed to the relevant data access control components or permission enforcement points.

[0117] Specifically, when the system detects the "review start" preset permission trigger event, it automatically obtains the context information of the current business process, including the current time, participants, project number, etc.

[0118] The context information was analyzed, and the current user role was identified as "Chief Review Expert". The evaluation expert group consisted of 3 experts in the field of "Civil Engineering". The confidentiality level of the bidding project was "Secret" and the current approval status was "Under Review".

[0119] Based on the above parameters, the matching mapping rules are retrieved from the permission dynamic mapping model, such as the rules corresponding to "chief reviewer + confidential project + review status".

[0120] Temporary permission sets are generated in real time according to the rules: data access permissions include viewing all bidders' technical solutions and qualification documents; operation execution permissions include initiating review comments and modifying scoring results; the time range is limited to 48 hours from the start of the review to the end of the review.

[0121] Temporary permission sets are sent to the data access control component in JSON format. The component then uses these permission sets to intercept or allow user actions in real time.

[0122] This implementation method automates the generation and issuance of temporary permissions, avoiding manual intervention and improving the timeliness of permission adjustments.

[0123] In this embodiment, the specific process of establishing a sensitivity level matrix for bidding data fields and classifying and labeling the bidder qualifications, quotations, and technical solutions data in the bidding data according to their sensitivity is as follows:

[0124] Identify all potentially sensitive fields in the bidding business data, including the bidder's identity information, contact information, historical performance, and core innovations in the technical solution;

[0125] Conduct risk assessments on identified sensitive fields and determine their sensitivity level based on the potential damage caused by information leakage. Sensitivity levels include public, restricted, confidential, and top secret.

[0126] Construct a sensitivity level matrix for bidding data fields. The rows of the matrix represent sensitive fields, the columns represent sensitivity levels, and the matrix cells store the sensitivity levels corresponding to the fields.

[0127] The bidding data, including bidder qualifications, quotations, and technical solutions, are classified and labeled according to their sensitivity, based on a field sensitivity level matrix.

[0128] Specifically, when identifying sensitive fields, in addition to the bidder's identity information and contact information, it also includes the amount of the bid bond, the performance commitment terms, the equipment model and parameters in the technical solution, and the contract amount in historical performance.

[0129] Risk assessments were conducted on sensitive fields: disclosure of the bid bond amount could lead to speculation about the bidder's financial situation, so it was classified as "restricted"; performance commitment terms involved commercial commitments, so they were classified as "confidential"; disclosure of equipment models and parameters could be used by competitors, so they were classified as "top secret".

[0130] When constructing the sensitivity level matrix for bidding data fields, a two-dimensional table format is used. The row headings are the specific sensitive fields, and the column headings are "Public," "Restricted," "Confidential," and "Top Secret." Matrix cells are marked with a "√" to indicate the sensitivity level of the corresponding field. For example, the "Contract Amount" row is marked with a "√" in the "Confidential" column.

[0131] When classifying and labeling bidding data, the system uses field matching technology to automatically add tags to sensitive fields in the document. For example, in the quotation file, a "confidential" tag is added to "Total price: 5 million yuan".

[0132] This implementation method provides a basis for differentiated desensitization by clearly defining the sensitivity level of fields, ensuring that sensitive information is accurately protected.

[0133] In this embodiment, a dynamic de-identification engine based on semantic parsing is developed. The specific process of linking the de-identification engine with the business role permission system is as follows:

[0134] Develop a semantic parsing module that can identify different field types and their contextual meanings in bidding documents;

[0135] Build a de-identification algorithm library to complement the semantic parsing module. The algorithm library includes partial masking, complete hiding, data encryption, and format-preserving de-identification algorithms.

[0136] The architecture of the dynamic de-identification engine is designed, which includes a data interception layer, a semantic parsing layer, an access control layer, and a de-identification processing layer.

[0137] The data masking engine is deployed on the data access path to intercept all access requests to bidding business data;

[0138] The de-identification engine is integrated with the business role and permission system via an interface. This interface integration is used to obtain real-time role and permission information of the access subject.

[0139] Specifically, when developing the semantic parsing module, the BERT model was used to train the bidding document so that it could recognize fields such as "quotation", "qualification certificate number" and "core technical indicators" and understand the relationship between "quotation" and time in "quotation validity period is 30 days".

[0140] In the desensitization algorithm library: some masking algorithm formulas are as follows ,in This is the result after masking. The original string, To preserve length, The length of the original string, for example , At that time, the mobile phone number 13812345678 was converted to 1381**678; the completely hidden algorithm returned directly; the AES encryption algorithm was used. , It is a ciphertext. For the key, This is plaintext; the format-preserving desensitization algorithm is implemented by replacing the character mapping table, such as 0→5, 1→6, etc.

[0141] In the dynamic de-identification engine architecture, the data interception layer adopts the interceptor pattern to capture HTTP requests and database queries; the semantic parsing layer calls the BERT model interface; the permission judgment layer queries the role permission service through the RESTful interface; and the de-identification processing layer selects an appropriate algorithm based on the algorithm library.

[0142] The data masking engine is deployed in the middleware layer between the application server and the database. All data access requests must be processed by the engine. The engine and the business role permission system maintain a long connection through WebSocket to obtain permission updates in real time.

[0143] This implementation method combines semantic parsing with an algorithm library to achieve both accuracy and flexibility in desensitization, meeting the needs of different scenarios.

[0144] In this embodiment, when different roles access the same document, the desensitization engine analyzes the role permission level of the accessing subject in real time, and performs differentiated desensitization processing on different fields in the document based on the field sensitivity level matrix. The specific process is as follows:

[0145] The de-identification engine obtains the access subject identifier and the requested document identifier from the access request;

[0146] The de-identification engine queries the current role and permission level of the access subject from the business role and permission system through interface integration;

[0147] The de-identification engine locates the content of the document based on the document identifier and uses the semantic parsing module to identify the various fields contained in the document;

[0148] For each field identified in the document, the desensitization engine looks up the sensitivity level corresponding to that field in the field sensitivity level matrix.

[0149] The de-identification engine compares the access subject's role and permission level with the field's sensitivity level, and selects a suitable de-identification algorithm from the de-identification algorithm library according to the preset de-identification strategy.

[0150] Apply desensitization algorithms to the fields and perform differentiated desensitization processing. For example, partially mask the business quotation field and fully display the technical parameter field.

[0151] Specifically, after receiving an access request, the de-identification engine extracts the access subject identifier (such as user ID=1001) and document identifier (such as document ID=2023) from the request header.

[0152] By querying the business role permission system through the interface, it was found that the role corresponding to user ID=1001 is "Purchasing Specialist" and the permission level is "Level 1".

[0153] Based on document ID=2023, the document content was located, and the semantic parsing module identified that the document contained fields such as "bidder's name", "quotation", "technical parameters" and "after-sales service commitment".

[0154] A query in the field sensitivity level matrix revealed that: "Bidder Name" is "Public", "Quotation" is "Confidential", "Technical Parameters" is "Restricted", and "After-sales Service Commitment" is "Public".

[0155] The default anonymization strategy is as follows: when the permission level matches the sensitivity level, the information is displayed in full; when the permission level is lower than the sensitivity level, the corresponding algorithm is applied. Since "Level 1" permission is lower than "Confidential" and "Restricted," "Quotation" is partially masked (keeping the first two digits), "Technical Parameters" is partially masked (keeping the parameter names but hiding the specific values), and "Bidder Name" and "After-Sales Service Commitment" are displayed in full.

[0156] After processing, the document displayed to the user changed "Quotation: 8.6 million yuan" to "Quotation: 860,000 yuan" and "Technical parameters: Power 200kW" to "Technical parameters: Power*".

[0157] This implementation method achieves field-level differential anonymization of the same document, which not only ensures information security but also meets the information needs of different roles.

[0158] In this embodiment, the specific process of storing the de-identification rules in a configurable rule base is as follows:

[0159] A configurable rule base is used to store the policy rules that the de-identification engine uses when performing field-level dynamic de-identification processing;

[0160] The masking rules define the specific masking methods for fields with different sensitivity levels under different role permission levels. The masking methods include mask length, replacement characters, and display format.

[0161] The rule base supports adding, deleting, modifying, and querying de-identification rules, and these operations can be configured through the management interface.

[0162] The de-identification engine dynamically loads de-identification rules from the rule base at runtime, without requiring modification to the application code.

[0163] Specifically, the configurable rule base is stored in a MySQL database, and the table structure includes fields such as rule ID, sensitivity level, role permission level, de-identification method, mask length, replacement character, and display format.

[0164] For example, the de-identification rules for a "Confidential" level field under "Level 2" permissions are: mask length = 4, replacement character =, and display format is the original format.

[0165] Administrators can manage rules through forms in the web management interface. When adding a new rule, they can select the sensitivity level, role permission level, and set the desensitization method and parameters. When deleting a rule, they can perform the deletion operation by rule ID. When modifying, they can directly edit field values. When querying, they can filter by sensitivity level or role permission level.

[0166] When the de-identification engine starts, it connects to the rule base via JDBC and loads all rules into the memory cache. During operation, the cache is automatically refreshed every 30 minutes to ensure that the latest rules are used without needing to restart the engine or modify the code.

[0167] This implementation method uses a configurable rule base to enable the de-identification strategy to flexibly adapt to business changes and reduce maintenance costs.

[0168] In this embodiment, the specific process of deploying distributed permission nodes in a private deployment environment and maintaining real-time communication between each permission node and the business process engine is as follows:

[0169] Deploy independent permission node instances on multiple servers or virtual machines in a private deployment environment;

[0170] A real-time communication channel based on a message queue or event bus is established between the permission node and the business process engine.

[0171] The permission node has a local permission caching mechanism to store recently accessed permission data;

[0172] A data synchronization mechanism is established between each permission node to maintain the consistency of permission data among the nodes.

[0173] Specifically, on five privately deployed physical servers, one permission node instance is deployed on each server. The nodes are deployed using Docker containers and orchestrated and managed using Kubernetes.

[0174] The permission node and the business process engine establish a communication channel using the Kafka event bus. The node acts as a consumer and subscribes to the "permission change" topic, while the business process engine acts as a producer and publishes events to this topic.

[0175] The local permission cache is implemented using Redis, with a key-value pair storage format. The key is "user ID + resource ID", and the value is the permission set. The cache expiration time is set to 1 hour.

[0176] Data synchronization between nodes adopts an incremental synchronization mechanism. When node A updates permission data, it generates a synchronization log and sends it to nodes B, C, D, and E. Other nodes only update the changed permission items according to the log, and the synchronization frequency is once per second.

[0177] This implementation improves the availability and response speed of the permission system through distributed deployment and real-time communication, meeting the needs of high-concurrency scenarios.

[0178] In this embodiment, when a business process changes, the permission node receives the change information through the event bus and uses an incremental permission calculation method to synchronously update the changed permission items. The specific process is as follows:

[0179] When the status of a business process changes, such as when the members of the expert group are adjusted or the approval process is redirected, the business process engine publishes a permission change event to the event bus.

[0180] Distributed permission nodes subscribe to the event bus to receive permission change events in real time.

[0181] The permission node identifies the specific permission items that need to be adjusted based on the type and content of the change event;

[0182] The permission nodes use an incremental permission calculation method, which only calculates and updates the identified permission items, avoiding the need to recalculate all permissions.

[0183] The permission node will synchronize the incrementally updated permission items to the relevant data access control components and update the local cache.

[0184] Specifically, when the business process engine detects that the number of expert group members has been adjusted from 3 to 5, it assembles an "Expert Group Member Change" event, which includes information such as event type "ADD_USER", project ID "XM2023001", and list of newly added user IDs "[U1004,U1005]", and publishes it to the "Permission Change" topic on the Kafka event bus.

[0185] The distributed permission node receives the event in real time through the Kafka consumer client. After parsing the event content, it identifies the permission items that need to be adjusted as the review permissions of users U1004 and U1005 for project XM2023001.

[0186] An incremental permission calculation method is adopted, based on the preset "review expert permission template", to generate permission sets for U1004 and U1005, including permissions such as viewing technical solutions and submitting review opinions, without recalculating the permissions of the original 3 experts.

[0187] The permission node will synchronize the newly added permission items to the data access control component via REST API, and update the key-value pairs corresponding to “U1004+XM2023001” and “U1005+XM2023001” in the Redis cache.

[0188] This implementation reduces computing resource consumption, shortens the time required for permission adjustments, and improves system efficiency through incremental updates.

[0189] In this embodiment, when the system detects that a similar business scenario reappears, the prediction model recommends a permission configuration scheme, and the specific process of continuously optimizing the model parameters based on actual operational feedback is as follows:

[0190] The machine learning module collects historical permission adjustment records, including business scenario identifiers, configurations before and after the permission adjustment, and adjustment time.

[0191] The machine learning module analyzes the frequency of business scenario changes and historical permission adjustment patterns, and builds a permission adjustment prediction model based on historical data.

[0192] When the system detects that the current business scenario matches a similar business scenario in the historical scenario library, the prediction model outputs a recommended permission configuration scheme based on the matching result.

[0193] The system collects feedback data based on the adoption of recommended solutions and their operational effects in actual applications;

[0194] The machine learning module uses feedback data to retrain the prediction model and continuously optimize the model parameters. The optimization goals include improving the accuracy of permission recommendations and the applicability of the recommendation scheme.

[0195] Specifically, the machine learning module uses an ETL tool to extract historical permission adjustment records from the business database. The data includes the scenario identifier "SCENE_PINGBIAO_GONGCHENG", the permission set before adjustment "{View: Basic Information}", the permission set after adjustment "{View: Basic Information, Operation: Scoring}", and the adjustment time "2023-05-10 09:30".

[0196] The K-means algorithm is used to cluster business scenarios, and the cosine similarity formula is used when calculating scenario similarity:

[0197] ,

[0198] in and These are the feature vector components of the two scenes, respectively. The feature dimension includes project type, security level, number of participants, etc. When the similarity is greater than 0.8, the scenarios are considered similar.

[0199] A random forest-based permission adjustment prediction model is constructed. The input is a scene feature vector, and the output is a recommended permission configuration scheme. For example, when the similarity between the current scene and a historical scene is 0.85, the same permission adjustment scheme as the historical scene is recommended.

[0200] The system records "valid" when a recommendation is adopted and "invalid" when it is not adopted, collecting feedback data monthly. The system then uses this feedback data to optimize the decision tree weights of the model using a stochastic gradient descent algorithm, improving recommendation accuracy by 5%-10%.

[0201] This implementation method uses machine learning to achieve intelligent recommendations for permission configuration, reducing the cost of manual decision-making and improving the rationality of permission adjustments.

[0202] In summary, this invention solves the response delay and operational risks caused by manual configuration for permission adjustments in traditional solutions by constructing a dynamic mapping model between business scenarios and permissions, combined with a temporary permission set generation mechanism. Through a field-sensitive matrix and a semantic parsing dynamic desensitization engine, it achieves differentiated desensitization at the field level within the same document, avoiding information redundancy from full-document encryption and the maintenance difficulties of application-layer hard-coding. Distributed permission nodes and incremental update mechanisms improve the system's response speed and stability during business process changes. Machine learning prediction models optimize permission configuration recommendations using historical data, reducing the cost of manual decision-making. The overall solution achieves deep coupling between the security management of bidding business data and business processes, significantly improving data confidentiality, integrity, and system operating efficiency.

[0203] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus.

[0204] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.

Claims

1. A method for secure private deployment and access control of bidding business data, characterized in that, Includes the following steps: Construct a dynamic permission mapping model based on business scenarios, and abstract the bid evaluation stage and multi-level approval nodes in the bidding process into permission trigger events; When identifying business scenario parameters, a temporary permission set is generated in real time according to the preset scenario and permission mapping rules; Establish a sensitivity level matrix for bidding data fields, and classify and label the bidder's qualifications, quotations, and technical solutions data in the bidding data according to their sensitivity. Develop a dynamic de-identification engine based on semantic parsing, and link the de-identification engine with the business role permission system; When different roles access the same document, the desensitization engine analyzes the role permission level of the accessing subject in real time and performs differentiated desensitization processing on different fields in the document based on the field sensitivity level matrix. Store the de-identification rules in a configurable rule base; Deploy distributed permission nodes in a private deployment environment, with each permission node maintaining real-time communication with the business process engine; When a business process changes, the permission node receives the change information through the event bus and uses an incremental permission calculation method to synchronously update the changed permission items. A machine learning module is introduced to analyze historical permission adjustment records and the frequency of business scenario changes, and a permission adjustment prediction model is built. When the system detects that a similar business scenario reappears, the prediction model recommends a permission configuration scheme. The model parameters are continuously optimized based on actual operational feedback.

2. The method for private deployment and access control of bidding business data security according to claim 1, characterized in that, The specific process of constructing a dynamic permission mapping model based on business scenarios, which abstracts the bid evaluation stage and multi-level approval nodes in the bidding process into permission-triggered events, is as follows: Analyze each stage and key operation of the bidding process to identify business scenarios that require dynamic adjustment of permissions; For each business scenario, define scenario-related business parameters, including the expert's field of expertise, the type of review object, and the approval level. Key operational nodes in the abstract bidding process, such as the bid evaluation stage and multi-level approval, are authorized trigger events, which are then associated with business scenarios. Establish a mapping relationship between business scenarios and permission rules. The mapping relationship defines the set of permission rules that should be generated under a specific business scenario. The dynamic permission mapping model includes business scenarios, business parameters, permission triggering events, and mapping relationships.

3. The method for private deployment and access control of bidding business data security according to claim 2, characterized in that, When identifying business scenario parameters, a temporary permission set is generated in real time according to preset scenario and permission mapping rules. The specific process is as follows: When the system detects that a preset permission-triggered event has occurred, it automatically obtains the context information of the current business process; Parse the context information to identify the specific parameters of the current business scenario. The business scenario parameters include the current user role, the composition information of the bidding expert group, the confidentiality level of the bidding project, and the current approval status. Based on business scenario parameters, retrieve scenario and permission mapping rules that match the current business scenario from the dynamic permission mapping model; Based on the retrieved mapping rules, a set of temporary permissions is generated in real time. The temporary permission set includes data access permissions, operation execution permissions, and time range limits. Once the temporary permission set is generated, it is distributed to the relevant data access control components or permission enforcement points.

4. The method for private deployment and access control of bidding business data security according to claim 1, characterized in that, The specific process of establishing the sensitivity level matrix for the bidding data fields, and classifying and labeling the bidder qualifications, quotations, and technical solutions data in the bidding data according to their sensitivity, is as follows: Identify all potentially sensitive fields in the bidding business data, including the bidder's identity information, contact information, historical performance, and core innovations in the technical solution; Conduct risk assessments on identified sensitive fields and determine their sensitivity level based on the potential damage caused by information leakage. Sensitivity levels include public, restricted, confidential, and top secret. Construct a sensitivity level matrix for bidding data fields. The rows of the matrix represent sensitive fields, the columns represent sensitivity levels, and the matrix cells store the sensitivity levels corresponding to the fields. The bidding data, including bidder qualifications, quotations, and technical solutions, are classified and labeled according to their sensitivity, based on a field sensitivity level matrix.

5. The method for private deployment and access control of bidding business data security according to claim 4, characterized in that, The specific process of developing a dynamic de-identification engine based on semantic parsing and linking the de-identification engine with the business role permission system is as follows: Develop a semantic parsing module that can identify different field types and their contextual meanings in bidding documents; Build a de-identification algorithm library to complement the semantic parsing module. The algorithm library includes partial masking, complete hiding, data encryption, and format-preserving de-identification algorithms. The architecture of the dynamic de-identification engine is designed, which includes a data interception layer, a semantic parsing layer, an access control layer, and a de-identification processing layer. The data masking engine is deployed on the data access path to intercept all access requests to bidding business data; The de-identification engine is integrated with the business role and permission system via an interface. This interface integration is used to obtain real-time role and permission information of the access subject.

6. The method for private deployment and access control of bidding business data security according to claim 5, characterized in that, When different roles access the same document, the desensitization engine analyzes the access subject's role and permission level in real time, and performs differentiated desensitization processing on different fields within the document based on the field sensitivity level matrix. The specific process is as follows: The de-identification engine obtains the access subject identifier and the requested document identifier from the access request; The de-identification engine queries the current role and permission level of the access subject from the business role and permission system through interface integration; The de-identification engine locates the content of the document based on the document identifier and uses the semantic parsing module to identify the various fields contained in the document; For each field identified in the document, the desensitization engine looks up the sensitivity level corresponding to that field in the field sensitivity level matrix. The de-identification engine compares the access subject's role and permission level with the field's sensitivity level, and selects a suitable de-identification algorithm from the de-identification algorithm library according to the preset de-identification strategy. Apply desensitization algorithms to the fields and perform differentiated desensitization processing. For example, partially mask the business quotation field and fully display the technical parameter field.

7. The method for private deployment and access control of bidding business data security according to claim 1, characterized in that, The specific process of storing the de-identification rules in a configurable rule base is as follows: A configurable rule base is used to store the policy rules that the de-identification engine uses when performing field-level dynamic de-identification processing; The masking rules define the specific masking methods for fields with different sensitivity levels under different role permission levels. The masking methods include mask length, replacement characters, and display format. The rule base supports adding, deleting, modifying, and querying de-identification rules, and these operations can be configured through the management interface. The de-identification engine dynamically loads de-identification rules from the rule base at runtime, without requiring modification to the application code.

8. The method for private deployment and access control of bidding business data security according to claim 1, characterized in that, The specific process of deploying distributed permission nodes in a private deployment environment, with each permission node maintaining real-time communication with the business process engine, is as follows: Deploy independent permission node instances on multiple servers or virtual machines in a private deployment environment; A real-time communication channel based on a message queue or event bus is established between the permission node and the business process engine. The permission node has a local permission caching mechanism to store recently accessed permission data; A data synchronization mechanism is established between each permission node to maintain the consistency of permission data among the nodes.

9. A method for private deployment and access control of bidding business data security according to claim 8, characterized in that, When the business process changes, the permission node receives the change information through the event bus and uses an incremental permission calculation method to synchronously update the changed permission items. The specific process is as follows: When the status of a business process changes, such as when the members of the expert group are adjusted or the approval process is redirected, the business process engine publishes a permission change event to the event bus. Distributed permission nodes subscribe to the event bus to receive permission change events in real time. The permission node identifies the specific permission items that need to be adjusted based on the type and content of the change event; The permission nodes use an incremental permission calculation method, which only calculates and updates the identified permission items, avoiding the need to recalculate all permissions. The permission node will synchronize the incrementally updated permission items to the relevant data access control components and update the local cache.

10. A method for private deployment and access control of bidding business data security according to claim 1, characterized in that, When the system detects that a similar business scenario recurs, the predictive model recommends a permission configuration scheme, and the specific process of continuously optimizing the model parameters based on actual operational feedback is as follows: The machine learning module collects historical permission adjustment records, including business scenario identifiers, configurations before and after the permission adjustment, and adjustment time. The machine learning module analyzes the frequency of business scenario changes and historical permission adjustment patterns, and builds a permission adjustment prediction model based on historical data. When the system detects that the current business scenario matches a similar business scenario in the historical scenario library, the prediction model outputs a recommended permission configuration scheme based on the matching result. The system collects feedback data based on the adoption of recommended solutions and their operational effects in actual applications; The machine learning module uses feedback data to retrain the prediction model and continuously optimize the model parameters. The optimization goals include improving the accuracy of permission recommendations and the applicability of the recommendation scheme.