Method, device, medium and program product for sharing allocation of communication resources

By combining two-stage stochastic programming and the CUSUM control chart algorithm, ITSP achieves dynamic intelligent allocation and real-time security monitoring of shared communication resources, solving the problems of unreasonable resource allocation and insufficient security, improving resource utilization and security, and enhancing customer experience and revenue.

CN122179394APending Publication Date: 2026-06-09XIAMEN XINGZONG DIGITAL TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
XIAMEN XINGZONG DIGITAL TECH CO LTD
Filing Date
2025-11-12
Publication Date
2026-06-09

Smart Images

  • Figure CN122179394A_ABST
    Figure CN122179394A_ABST
Patent Text Reader

Abstract

This invention provides a method, device, medium, and program product for allocating shared communication resources. The allocation method includes: acquiring historical usage records of shared communication resources for each subordinate account; based on the historical usage records, using a pre-constructed demand stochastic model based on two-stage stochastic programming, periodically and dynamically calculating the optimal resource allocation quota for each subordinate account according to a pre-set period; in each period, creating resource credentials for the resources to be allocated based on the calculated optimal resource allocation quota for each subordinate account, and issuing the corresponding resource credentials to each subordinate account; using the above technical solution, dynamic and intelligent allocation of shared communication resources is realized; furthermore, by using the CUSUM control chart algorithm, a behavioral baseline is established for each subordinate account, and real-time detection is made to determine whether its resource usage pattern deviates from the normal pattern, which can proactively detect fraud and abuse, and achieve fine-grained security management of resources.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of communication network resource management technology, and in particular to a method, device, medium and program product for allocating shared communication resources. Background Technology

[0002] Large Internet Telephony Service Providers (ITSPs) commonly employ multi-level marketing (MLM) models to expand their business channels. Under this model, ITSPs need to allocate their shared trunk and DID (Direct Inward Dialing) number resources to downstream channel customers. Traditional resource allocation methods are often static, where ITSP administrators allocate a fixed number of resources to each downstream customer based on experience or contracts.

[0003] In actual business operations, this static allocation model has revealed many limitations: First, resource allocation is not rational enough. The actual business needs of lower-level customers are significantly random and volatile (for example, promotional activities lead to a surge in call volume). Static allocation cannot adapt to this dynamic change, resulting in two extreme situations: on the one hand, insufficient resources are allocated to high-demand customers, causing lost business opportunities and affecting customer experience; on the other hand, excessive resources are allocated to low-demand customers, resulting in idle valuable communication resources and reducing the overall resource utilization and revenue of ITSPs.

[0004] Second, the resource sales strategy lacks data support. When ITSPs sell resource packages to channel customers, they lack scientific quantitative data to determine the appropriate quantity to sell, making it difficult to maximize profits. Similarly, downstream customers also want to purchase the right amount of resources to meet their business needs at a reasonable cost, avoiding wasted funds.

[0005] Third, there is a lack of effective security risk control mechanisms. The static allocation model only focuses on "whether it can be used," lacking continuous monitoring of "how it is used." Sub-customers may use allocated resources for fraudulent calls, harassing calls, or other abnormal activities due to stolen accounts or their own violations, causing brand reputation damage and economic losses to ITSPs. Existing systems lack proactive, real-time means to detect and block such abnormal usage.

[0006] Therefore, there is an urgent need in the field for an innovative solution to overcome at least one of the aforementioned defects of existing static allocation models. Summary of the Invention

[0007] Embodiments of the present invention provide a method, device, medium, and program product for allocating shared communication resources, so as to realize dynamic and intelligent allocation of shared communication resources.

[0008] To achieve the above objectives, on the one hand, a method for allocating shared communication resources is provided, including: Obtain historical usage records of shared communication resources for each subordinate account, including historical resource allocation quotas for each subordinate account; Based on the historical usage records, a pre-built demand stochastic model based on two-stage stochastic programming is used to periodically and dynamically calculate the optimal resource allocation quota for each subordinate account according to a pre-set period. In each cycle, based on the calculated optimal resource allocation quota for each subordinate account, a resource certificate for the resource to be allocated is created, and the corresponding resource certificate is issued to each subordinate account. The resource certificate includes: the resource identifier authorized by the certificate, the expiration time of the certificate, and the resource creation permission flag; the resource creation permission flag is used to identify whether the account holding the certificate has the permission to apply for new resources. The input parameters of the demand stochastic model include: the total number of shared communication resources to be allocated, N, where N is a positive integer; the number of subordinate accounts, K; and the pre-estimated business volume of each subordinate account in the next period based on the historical usage records using the Monte Carlo sampling average approximation algorithm. probability distribution , Indicates the first A subordinate account, Unit revenue Unit penalty cost Unit idle cost ; The objective function of the demand stochastic model is:

[0009] in, The expectation operator is used to... Calculate the expected value of the target value within the range. This indicates maximizing the expected value of the obtained mathematical expression. In the optimal resource allocation quota output by the demand stochastic model, the quota allocated to the first... Resource quotas for each subordinate account; among which... ; in, Indicates the first The volume of business that a single subordinate account can successfully complete; This indicates the amount of business lost due to insufficient resources; This indicates the amount of resources that have been allocated but are currently idle.

[0010] Preferably, the allocation method further includes using the CUSUM control chart algorithm to establish a behavioral baseline for each subordinate account, judging whether the resource usage pattern of each subordinate account deviates from the normal pattern by real-time monitoring of the call frequency or call destination entropy; and when the usage pattern of a subordinate account deviates from the normal pattern, freezing the resource credentials of the subordinate account in real time through the resource access gateway to terminate the resource access rights of the subordinate account.

[0011] Preferably, in the allocation method, when the call destination entropy of a lower-level account experiences a predetermined sudden decrease, it is determined that the resource usage pattern of the lower-level account deviates from the normal pattern.

[0012] Preferably, the allocation method, which uses the CUSUM control chart algorithm to establish behavioral baselines for each lower-level account, and determines whether its resource usage pattern deviates from the normal pattern by real-time monitoring of the call destination entropy of each lower-level account, includes the following steps: For real-time monitoring indicator observations To obtain updated cumulative and statistical values. ,t represents time t, where: ; This is the cumulative sum statistic at time t-1. This is the predefined allowed offset parameter; The baseline mean of the monitoring indicators; The baseline standard deviation of the monitoring indicators; When the updated cumulative sum statistics When the resource usage pattern exceeds the predetermined control limit threshold, it is determined that the resource usage pattern deviates from the normal pattern.

[0013] Preferably, in the allocation method, when the resource creation permission marker indicates that the account holding the credential does not have the permission to apply for new resources, this permission cannot be elevated during credential derivation.

[0014] Preferably, in the allocation method, the shared communication resource is a number resource for direct inward dialing.

[0015] On the other hand, an electronic device is provided, including a memory and a processor, the memory storing at least one program, the at least one program being executed by the processor to implement the steps of the shared communication resource allocation method as described in any of the above.

[0016] In another aspect, a computer-readable storage medium is provided, wherein at least one program is stored therein, the at least one program being executed by a processor to implement the steps of the method for allocating shared communication resources as described in any of the above descriptions.

[0017] In another aspect, a computer program product is provided, comprising a computer program that, when executed by a processor, implements the steps of the method for allocating shared communication resources as described above.

[0018] The above technical solution has the following technical effects: This invention employs a demand stochastic model based on two-stage stochastic programming to achieve periodic dynamic calculation of the optimal resource allocation quota for each subordinate account. By incorporating revenue, penalty cost (opportunity loss), and idle cost into the objective function of the demand stochastic model, it addresses specific problems encountered in the prior art ITSP field when using static models for communication resource allocation. Furthermore, when using two-stage stochastic programming for resource allocation, the Monte Carlo Sampled Average (SAA) approximation algorithm is used to pre-estimate the traffic volume of each subordinate account for the next period. probability distribution This transforms complex stochastic problems into large-scale but deterministic linear programming problems, ensuring the engineering feasibility of the present invention. In a further embodiment, the CUSUM control chart algorithm is used to establish a behavioral baseline for each subordinate account, and to detect in real time whether its resource usage pattern deviates from the normal pattern. This can proactively detect fraud and abuse, and achieve fine-grained security management of resources. Attached Figure Description

[0019] Figure 1 This is a flowchart illustrating a method for allocating shared communication resources according to an embodiment of the present invention; Figure 2 This is a flowchart illustrating a method for allocating shared communication resources according to another embodiment of the present invention; Figure 3 This is a schematic diagram of the structure of an electronic device according to an embodiment of the present invention. Detailed Implementation

[0020] To further illustrate the various embodiments, the present invention provides accompanying drawings. These drawings are part of the disclosure of the present invention, primarily used to illustrate the embodiments and to explain the operating principles of the embodiments in conjunction with the relevant descriptions in the specification. With reference to these drawings, those skilled in the art should be able to understand other possible implementations and the advantages of the present invention. Components in the drawings are not drawn to scale, and similar component symbols are generally used to represent similar components.

[0021] The present invention will now be further described in conjunction with the accompanying drawings and specific embodiments.

[0022] Example 1: Figure 1 This is a flowchart illustrating a method for allocating shared communication resources according to an embodiment of the present invention. Figure 1The method for allocating shared communication resources in this embodiment includes: Obtain the historical usage records of shared communication resources for each subordinate account. The historical usage records include: the historical resource allocation quotas for each subordinate account. Based on historical usage records, a pre-built demand stochastic model based on two-stage stochastic programming is used to periodically and dynamically calculate the optimal resource allocation quota for each subordinate account according to a pre-set period. In each cycle, based on the calculated optimal resource allocation quota for each subordinate account, resource credentials for the allocated resources are created and issued to each subordinate account. The resource credentials include: the resource identifier (resource ID) authorized for access, the credential's expiration time, and a resource creation permission flag. The resource creation permission flag indicates whether the account holding the credential has the permission to apply for new resources. In practice, the resource identifier authorized for access is a list of resource identifiers. Specifically, when the resource creation permission flag indicates that the account holding the credential does not have the permission to apply for new resources, the account holding the credential cannot apply for new resources from the system; it can only be allocated resources by its superior and can only use the resources included in the resource ID list within the credential. The input parameters of the demand stochastic model include: the total number of shared communication resources to be allocated, N, where N is a positive integer; the number of subordinate accounts, K; and the pre-estimated business volume of each subordinate account in the next period based on historical usage records using a Monte Carlo sampling average approximation algorithm. probability distribution , Indicates the first A subordinate account, Unit revenue Unit penalty cost Unit idle cost ; The objective function of the demand stochastic model is:

[0023] in, The expectation operator is used to... Calculate the expected value of the target value within the range; In the optimal resource allocation quota output by the demand stochastic model, the quota allocated to the first... Resource quotas for each subordinate account; in, Indicates the first The volume of business that a single subordinate account can successfully complete; This indicates the amount of business lost due to insufficient resources; This indicates the amount of resources that have been allocated but are currently idle.

[0024] The objective function described above considers: revenue from successful calls; opportunity loss, specifically order loss due to insufficient resources, which directly impacts customer satisfaction and potential revenue loss; and idle cost: waste resulting from excessive resource allocation, which translates to direct profit reduction in the case of per-line billing communication resources. This embodiment of the invention achieves dynamic and intelligent allocation of shared communication resources through a two-stage stochastic programming model.

[0025] Example 2: The inventors of this application discovered in their research on communication resource allocation methods that a decrease in entropy value means that the call destination becomes more concentrated, which is a typical characteristic of fraudulent calls, such as making a large number of calls to a payable number to collect fees, or marketing bombing. By using the CUSUM control chart to monitor the real-time calculated destination entropy value to detect whether it suddenly deviates from the historical baseline, it can be applied to communication resource risk control.

[0026] Based on Embodiment 1, this embodiment of the present invention further includes using the CUSUM (cumulative sum) control chart algorithm to establish a behavioral baseline for each lower-level account, and judging whether the resource usage pattern of each lower-level account deviates from the normal pattern by real-time monitoring of the call destination entropy of each lower-level account; and when the usage pattern of a lower-level account deviates from the normal pattern, freezing the resource credentials of the lower-level account in real time through the resource access gateway to terminate the resource access rights of the lower-level account.

[0027] In one specific implementation, when the usage pattern of a lower-level account deviates from the normal pattern, an instruction is directly sent to the resource access gateway upon detection of the anomaly. The resource access gateway then freezes the account's credentials in real time, immediately terminating its resource access permissions. This tight linkage of real-time detection, real-time decision-making, and real-time execution directly transforms the algorithm's detection results into high-privilege system actions, forming a powerful proactive defense capability. Therefore, this embodiment of the invention utilizes the CUSUM algorithm to monitor call destination entropy, realizing it as a core decision trigger for an automated resource reclamation system.

[0028] In practice, when the call destination entropy of a lower-level account suddenly decreases as planned, it is determined that the resource usage pattern of that lower-level account deviates from the normal pattern.

[0029] Preferably, when the resource creation permission flag indicates that the account holding the credential does not have the permission to apply for new resources, this permission cannot be elevated during credential derivation; that is, when the subordinate account is derived from the credential, its subordinates can only use the resources allocated in the credential of its superior, that is, the resources allocated by the superior of the derived subordinate, and cannot apply for new resources.

[0030] The following is combined Figure 2A specific implementation of this embodiment of the present invention will be described.

[0031] This specific implementation of the invention solves the problem of intelligent and secure allocation of shared communication resources (Trunk / DID) in a multi-level account system. This implementation upgrades resource allocation from an experience-based static operation to a data-driven, dynamic, and intelligent process by introducing two major mathematical models and an algorithm engine, including: Dynamic quota allocation is achieved through a stochastic optimization engine, which is based on two-stage stochastic programming and Monte Carlo sampling average approximation (SAA) algorithm to construct a demand stochastic model and solve for the optimal resource allocation scheme that maximizes expected revenue or minimizes expected cost. Anomaly detection is achieved through an anomaly detection engine. Based on statistical process control (SPC) theory, it uses the CUSUM (cumulative sum) control chart algorithm to establish a behavioral baseline for each subordinate account and detect in real time whether its resource usage pattern deviates from the normal pattern, thereby proactively discovering fraudulent and abusive behaviors.

[0032] 1. Stochastic Optimization Engine Function: Periodically calculates the optimal resource allocation quota.

[0033] Input parameters: N: Total resources; representing the total number of shared resources (such as DID numbers) to be allocated owned by the parent account; it is a positive integer constant, N ∈ Z. + ; K: Number of subordinate accounts; represents the number of direct subordinate accounts that need to be allocated resources; K ∈ Z + ; :No. The business needs of each account are random variables; representing the random variable of the first account within a future period. The business volume of each subordinate account is as expected in terms of the number of calls; it is a non-negative random variable. ≥ 0; its probability distribution P( The Monte Carlo sampling average approximation algorithm (SAA) is used to approximate historical data such as historical usage records. The estimate is obtained from a pre-estimated sample average approximation; in specific implementations, it can be fitted to a Poisson distribution or a normal distribution. Unit revenue; represents the revenue generated from successfully using a resource unit, such as the revenue generated from completing a call using a DID; ∈ R + ; Unit penalty cost; indicates that due to insufficient resources, at this time... Greater than the allocation amount The loss resulting from the loss of a business opportunity; ∈ R + ;generally > ; Unit idle cost; represents the cost incurred when a resource unit is allocated but not used, i.e., idle; ∈ R + ;generally < Decision variables: The output is the resource allocation quota allocated to the i-th account in the optimal resource allocation quota; it is a non-negative integer. ∈ Z + And the constraints must be satisfied. Objective function:

[0034] in, The expectation operator is used to... The expected value of the target value within the range is calculated to account for random variables. All possible scenarios, This indicates maximizing the expected value of the obtained mathematical expression. in, Indicates the first The volume of business that a single subordinate account can successfully complete; This indicates the amount of business lost due to insufficient resources; This indicates the amount of resources that have been allocated but are currently idle.

[0035] 2. Anomaly Detection Engine Function: Analyzes resource usage behavior of subordinate accounts in real time to detect fraud and abuse.

[0036] Monitoring indicators : The observed value of the monitoring indicator at time t; it is a real number. ∈ R; a specific implementation, For the destination entropy of the call, i.e. ,in Is the call directed to the destination? The frequency of entropy; a sudden decrease in entropy may indicate fraud, i.e., a focus on targets.

[0037] In another specific implementation, For call frequency, i.e. = The number of calls within the time window, This is the scheduled time window.

[0038] Baseline parameters: μ: Baseline mean of monitoring metrics; Calculated during the training period when the account is running normally. The sample mean, μ∈R; : Standard deviation of the baseline for monitoring metrics; during the training period, calculate the monitoring metrics. The sample standard deviation ∈ R + CUSUM algorithm parameters: The cumulative sum statistic at time t; it is the core state variable of the CUSUM algorithm. ≥ 0. Initial value =0; k: Allowable offset parameter; a pre-set reference value used to filter out small, meaningless fluctuations; preferably, k = 0.5 (normalized value), k ∈ R + ; h: Control limit threshold; a pre-defined decision boundary. When the threshold value is greater than h, an anomaly is determined in the system. In practice, the value of the threshold h directly affects the sensitivity and false alarm rate of the alarm. Preferably, a balance is achieved through design, where h ∈ R. + For example, h=5.

[0039]

[0040] : Indicates the current observation value Standardization, such as Z-score standardization, can be performed to make the mean 0 and the standard deviation 1, which makes it easier to uniformly handle indicators of different magnitudes.

[0041] 3. Resource Credential Generator Function: Serves as a carrier for resource allocation and access control.

[0042] Key fields: resource_list: A list of resource identifiers; in one specific implementation, it is implemented as an array containing the specific resource IDs authorized for access by this credential, such as the Trunk DID number, which is the DID number used in the trunk line. expiry_time: The voucher's expiry time; a timestamp, after which the voucher automatically expires. `is_creatable`: Resource creation permission flag; a boolean value; when `is_creatable = False`, meaning the user cannot create a trunk, the account holding this credential cannot request new resources from the system, but can only be assigned resources by its superior, i.e., can only use resources contained in the `resource_list` of this credential. Furthermore, this permission cannot be elevated during credential derivation; if the superior is False, the subordinate must also be False.

[0043] The workflow of the allocation method in this embodiment includes: 1) Intelligent allocation of resource quotas, which is cyclical: Input: (N, K, P) ), revenue, penalty, cost); Process: The stochastic optimization engine runs the SAA algorithm to solve the two-stage model; Output: The optimal quota for allocating communication resources to the first to Kth lower-level users. ; Action: The credential generator creates and issues credentials containing... 1) Transfer the voucher for each resource to the corresponding subordinate account. 2) Anomaly detection, this step is continuously looped: Input: Real-time stream baseline ( , ), parameters (k, h); Process: For each According to the above The calculation formula for updating the CUSUM statistic ; Output: Binary decision, judgment Check if the condition is met; if so, an abnormality is detected and an alarm is triggered, i.e., "Alarm" is output; otherwise, a normal condition is detected and "Normal" is output. Action: If an alarm is triggered, the gateway will be notified to freeze the account's credential access permissions. 3) Access Control: The resource creation permission flag field, i.e., the is_creatable field, in the credentials enforces the account's behavioral capabilities, thus achieving separation of powers and security delegation. With is_creatable=False for the sub-account itself, all its actions are confined to the allocated resources. Monitoring its usage patterns rather than the total amount used becomes the most effective risk control method. In particular, it can solve the specific problem of how to stop losses in time when resources are illegally resold or abused.

[0044] This embodiment of the invention, through the aforementioned parameterized model and algorithm, achieves automation, optimization, and security in system resource allocation. Specifically, this embodiment of the invention defines matching inputs, outputs, and objective functions for the specific problem of maximizing ITSP benefits under the permission constraint of prohibiting subordinates from creating resources independently; the shared communication resource allocation method, which links random optimization, security permissions, and resource credentials in a closed loop, enables dynamic intelligent allocation and refined security management of shared communication resources.

[0045] Example 3: The present invention also provides an electronic device, such as... Figure 3 As shown, the device includes a processor 301, a memory 302, a bus 303, and a computer program stored in the memory 302 and executable on the processor 301. The processor 301 includes one or more processing cores. The memory 302 is connected to the processor 301 via the bus 303. The memory 302 is used to store program instructions. When the processor executes the computer program, it implements the steps in the above-described method embodiment of Embodiment 1 of the present invention.

[0046] Furthermore, as an executable solution, the electronic device can be a computer unit, which can be a desktop computer, laptop, handheld computer, cloud server, or other computing device. The computer unit may include, but is not limited to, a processor and memory. Those skilled in the art will understand that the above-described structure of the computer unit is merely an example and does not constitute a limitation on the computer unit. It may include more or fewer components, or combine certain components, or use different components. For example, the computer unit may also include input / output devices, network access devices, buses, etc., and this embodiment of the invention does not limit this.

[0047] Furthermore, as an executable solution, the processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor, etc. The processor is the control center of the computer unit, connecting various parts of the entire computer unit via various interfaces and lines.

[0048] The memory can be used to store the computer programs and / or modules. The processor implements various functions of the computer unit by running or executing the computer programs and / or modules stored in the memory and by calling data stored in the memory. The memory may mainly include a program storage area and a data storage area. The program storage area may store the operating system and at least one application program required for a function; the data storage area may store data created based on the use of the mobile phone, etc. In addition, the memory may include high-speed random access memory and may also include non-volatile memory, such as hard disk, RAM, plug-in hard disk, smart media card (SMC), secure digital card (SD card), flash card, at least one disk storage device, flash memory device, or other volatile solid-state storage device.

[0049] Example 4: The present invention also provides a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the steps of the method described in the embodiments of the present invention.

[0050] If the modules / units integrated in the computer unit are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments can also be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording media, USB flash drives, portable hard drives, magnetic disks, optical disks, computer memory, read-only memory (ROM), random access memory (RAM), and software distribution media, etc. It should be noted that the content contained in the computer-readable medium can be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction.

[0051] Example 5: The present invention also provides a computer program product, including a computer program that, when executed by a processor, implements the steps described above.

[0052] Although the invention has been specifically shown and described in conjunction with preferred embodiments, those skilled in the art should understand that various changes in form and detail may be made to the invention without departing from the spirit and scope of the invention as defined in the appended claims, all of which shall be within the scope of protection of the invention.

Claims

1. A method for allocating shared communication resources, characterized in that, include: Obtain historical usage records of shared communication resources for each subordinate account, including historical resource allocation quotas for each subordinate account; Based on the historical usage records, a pre-built demand stochastic model based on two-stage stochastic programming is used to periodically and dynamically calculate the optimal resource allocation quota for each subordinate account according to a pre-set period. In each cycle, based on the calculated optimal resource allocation quota for each subordinate account, a resource certificate for the resource to be allocated is created, and the corresponding resource certificate is issued to each subordinate account. The resource certificate includes: the resource identifier authorized by the certificate, the expiration time of the certificate, and the resource creation permission flag; the resource creation permission flag is used to identify whether the account holding the certificate has the permission to apply for new resources. The input parameters of the demand stochastic model include: the total number of shared communication resources to be allocated, N, where N is a positive integer; the number of subordinate accounts, K; and the pre-estimated business volume of each subordinate account in the next period based on the historical usage records using the Monte Carlo sampling average approximation algorithm. probability distribution , Indicates the first A subordinate account, Unit revenue Unit penalty cost Unit idle cost ; The objective function of the demand stochastic model is: in, The expectation operator is used to... Calculate the expected value of the target value within the range. This indicates that the expected value of the obtained mathematical result is maximized; In the optimal resource allocation quota output by the demand stochastic model, the quota allocated to the first... Resource quotas for each subordinate account; among which... ; in, Indicates the first The volume of business that a single subordinate account can successfully complete; This indicates the amount of business lost due to insufficient resources; This indicates the amount of resources that have been allocated but are currently idle.

2. The method for allocating shared communication resources according to claim 1, characterized in that, It also includes using the CUSUM control chart algorithm to establish behavioral baselines for each subordinate account, and judging whether the resource usage pattern deviates from the normal pattern by real-time monitoring of the call frequency or call destination entropy of each subordinate account. Furthermore, when the usage pattern of a subordinate account deviates from the normal pattern, the resource credentials of that subordinate account are frozen in real time through the resource access gateway to suspend the resource access permissions of that subordinate account.

3. The method for allocating shared communication resources according to claim 2, characterized in that, When the call destination entropy of a lower-level account suddenly decreases as expected, it is determined that the resource usage pattern of that lower-level account deviates from the normal pattern.

4. The method for allocating shared communication resources according to claim 2, characterized in that, The steps for establishing behavioral baselines for each subordinate account using the CUSUM control chart algorithm, and determining whether resource usage patterns deviate from normal patterns by real-time monitoring of the call destination entropy of each subordinate account, include: For real-time monitoring indicator observations To obtain updated cumulative statistics ,t represents time t, where: ; The cumulative sum statistic at time t-1, This is the predefined allowed offset parameter; The baseline mean of the monitoring indicators; The baseline standard deviation of the monitoring indicators; When the updated cumulative sum statistics When the resource usage pattern exceeds the predetermined control limit threshold, it is determined that the resource usage pattern deviates from the normal pattern.

5. The method for allocating shared communication resources according to claim 1, characterized in that, When the resource creation permission marker indicates that the account holding the credential does not have the permission to apply for new resources, this permission cannot be elevated during credential derivation.

6. The method for allocating shared communication resources according to claim 1, characterized in that, The shared communication resources are number resources for direct inward dialing.

7. An electronic device, characterized in that, It includes a memory and a processor, the memory storing at least one program, the at least one program being executed by the processor to implement the steps of the method for allocating shared communication resources as described in any one of claims 1 to 6.

8. A computer-readable storage medium, characterized in that, The storage medium stores at least one program segment, which is executed by a processor to implement the steps of the shared communication resource allocation method as described in any one of claims 1 to 6.

9. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method for allocating shared communication resources as described in any one of claims 1 to 6.