A system and method for managing data for forensic purposes
By using a multi-dimensional permission model and permission sharing module, the problem of fine-grained permission isolation and flexible data sharing in the management of audit data in the investment advisory industry has been solved, realizing secure and convenient cross-departmental data sharing and compliance management.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- ZHEJIANG BEICAI ZHISHEN NETWORK TECH CO LTD
- Filing Date
- 2026-04-23
- Publication Date
- 2026-07-31
AI Technical Summary
Existing logistic tracking, access control, and sharing systems cannot achieve fine-grained access control and flexible, secure data sharing, leading to data leakage risks and compliance issues.
A multi-dimensional permission model is adopted, which realizes fine-grained management of user permissions and cross-dimensional data sharing through data storage module, permission management module and permission control module, and provides a controlled sharing access interface in combination with permission sharing module.
It enables secure and convenient data sharing across departments and business lines, reduces the risk of data leakage, improves compliance management efficiency, and provides complete operation records and evidence chains.
Smart Images

Figure CN122490553A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of record-keeping and auditing, and in particular to a management system and method for record-keeping and auditing data. Background Technology
[0002] In the investment advisory industry, regulatory agencies explicitly require service providers to maintain records of all information related to communication with clients and to conduct internal audits based on these records to generate audit reports that ensure compliance in business operations. However, the requirements for access control and information sharing regarding record keeping vary depending on the role of the service provider and the regulatory agency, and in different scenarios.
[0003] The existing record-keeping access control and sharing system has significant defects. For example, (1) the access control is crude: the existing access management is usually based on simple user roles, which cannot meet the needs of the complex organizational structure of investment advisory institutions. For example, it cannot finely control the data isolation between different business departments (such as the investment advisory department, intelligent software department), different business lines, and different product lines. This leads to the possibility that employees of one department may access the sensitive audit results of other departments, which poses a risk of data leakage. (2) the data sharing is rigid: when performing their duties, relevant personnel need to view the overall or specific audit results across multiple business lines. At present, this needs to be achieved through non-systematic methods such as offline export and email, which is inefficient and cannot record and monitor the sharing operation itself, forming a new compliance risk point. At the same time, due to the lack of access control and sharing mechanisms, Therefore, existing technologies cannot address the issue of managing audit data that requires precise access control and flexible, secure data sharing. Summary of the Invention
[0004] This application provides a management system and method for audit data to at least solve the problem in related technologies where fine-grained access control and flexible, secure data sharing cannot be achieved in audit data management.
[0005] In a first aspect, embodiments of this application provide a management system for audit data retention, including: Data storage module: used to store audit data, which is associated with multiple data dimension attributes; The permission management module is used to define and manage user permissions through a multi-dimensional permission model, which configures user permissions as the operation permissions of data within the data dimension attributes to which the user belongs. Access control module: used to communicate with the data storage module and the access management module, and to obtain the target user's access permissions from the access management module and the target data dimension attributes from the data storage module according to the user's data access request, and to determine the request result based on the target user's access permissions and the target data dimension attributes; Permission sharing module: Used to provide a sharing access interface based on the sharing policy set by the user with the operation permissions, including sharing permissions.
[0006] In one embodiment, the data dimension attributes include: the service personnel to which the data belongs, the customer to which the data belongs, the business department to which the data belongs, the business line to which the data belongs, and the product line to which the data belongs.
[0007] In one embodiment, the access control module is used to receive a user's data access request for the audit data, obtain the target user's permissions from the access management module according to the data access request, and obtain the target data dimension attributes from the data storage module; The access control module is used to match the target user's permissions with the target data dimension attributes, and in response to the intersection between the target user's permissions and the target data dimension attributes, to determine the request result from the audit data.
[0008] In one embodiment, the sharing strategy is configured to include a sharing target, a data range, target operation permissions, and a validity period, wherein the data range is determined based on the configured data dimension attributes.
[0009] In one embodiment, the sharing access interface provided by the permission sharing module is communicatively connected to the permission control module. The data storage module is also used to store data operation records of the sharing access interface, including data access, sharing, viewing, and exporting; The access control module is also used to define and manage user data operation records.
[0010] In one embodiment, the multidimensional permission model is configured as an extension of an attribute-based access control model or a role-based access control model, and the extended multidimensional permission model performs permission control based on data dimension attributes.
[0011] Secondly, embodiments of this application provide a method for managing audit data in the investment advisory industry. The method is implemented based on the audit data management system described in the first aspect, and includes: Store audit data that leaves a trace, and the audit data is associated with multiple data dimension attributes; User permissions are defined and managed through a multidimensional permission model, which is used to configure user permissions as operation permissions for data within the data dimension attributes to which the user belongs; Based on the user's data access request, the target user's permissions are obtained from the audit data, the target data dimension attributes are obtained from the user's permissions, and the request result is determined based on the target user's permissions and the target data dimension attributes. Provide a sharing access interface based on the sharing policy set by the user with the operation permissions, including sharing permissions.
[0012] In one embodiment, the method further includes storing the data operation records of the shared access interface as audit data.
[0013] Thirdly, embodiments of this application provide a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement a method for managing audit data as described in the second aspect.
[0014] Fourthly, embodiments of this application provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements a method for managing audit data as described in the second aspect.
[0015] The management system and method for audit data retention provided in this application have at least the following technical effects.
[0016] This application refines access control granularity from "user" or "role" to "data dimension" through a data storage module, a multi-dimensional permission model, and a permission control module. This perfectly aligns with the complex matrix organizational structure of investment advisory institutions, effectively preventing unauthorized data access. It allows users to create sharing access points based on sharing policies to achieve cross-dimensional data sharing. Through dedicated permission sharing, cross-departmental and cross-business line data sharing can be completed securely and conveniently within the system. The sharing policy is precisely controlled by the initiator, avoiding the risk of secondary data dissemination. This systematizes and standardizes previously offline and informal sharing processes, reducing communication costs and management loopholes, and improving the overall efficiency of compliance management.
[0017] Details of one or more embodiments of this application are set forth in the following drawings and description to make other features, objects and advantages of this application more readily apparent. Attached Figure Description
[0018] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings: Figure 1 This is a structural block diagram of a management system for record-keeping audit data according to an embodiment of this application; Figure 2 This is a schematic diagram illustrating a system for managing audit data according to an exemplary embodiment; Figure 3 This is a flowchart illustrating a method for managing audit data based on embodiments of this application; Figure 4 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0019] To make the objectives, technical solutions, and advantages of this application clearer, the application is described and illustrated below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application. All other embodiments obtained by those skilled in the art based on the embodiments provided in this application without inventive effort are within the scope of protection of this application.
[0020] Obviously, the accompanying drawings described below are merely some examples or embodiments of this application. Those skilled in the art can apply this application to other similar scenarios based on these drawings without any inventive effort. Furthermore, it is understood that although the efforts made in this development process may be complex and lengthy, for those skilled in the art related to the content disclosed in this application, any changes to design, manufacturing, or production based on the technical content disclosed in this application are merely conventional technical means and should not be construed as insufficient disclosure of the content of this application.
[0021] In this application, the reference to "embodiment" means that a specific feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment that is mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described in this application may be combined with other embodiments without conflict.
[0022] Unless otherwise defined, the technical or scientific terms used in this application shall have the ordinary meaning understood by one of ordinary skill in the art to which this application pertains. The terms “a,” “an,” “an,” “the,” and similar words used in this application do not indicate quantity limitation and may indicate singular or plural. The terms “comprising,” “including,” “having,” and any variations thereof used in this application are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or device that includes a series of steps or modules (units) is not limited to the listed steps or units, but may also include steps or units not listed, or may include other steps or units inherent to these processes, methods, products, or devices. The terms “connected,” “linked,” “coupled,” and similar words used in this application are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect. “Multiple” used in this application refers to two or more. “And / or” describes the relationship between related objects, indicating that three relationships may exist; for example, “A and / or B” can represent: A alone, A and B simultaneously, and B alone. The character " / " generally indicates that the preceding and following objects are in an "or" relationship. The terms "first," "second," and "third" used in this application are merely to distinguish similar objects and do not represent a specific ordering of the objects.
[0023] Firstly, embodiments of this application provide a management system for audit data retention. Figure 1 This is a structural block diagram of a management system for audit data retention according to an embodiment of this application, such as... Figure 1 As shown, the system includes: Data storage module 100: Used to store audit data, which is associated with multiple data dimension attributes.
[0024] Optionally, the data storage module 100 is used to store audit data. Each audit result is associated with multiple data dimension attributes, which include at least: the service personnel to which the data belongs, the customer to which the data belongs, the business department to which the data belongs, the business line to which the data belongs, and the product line to which the data belongs.
[0025] In one example, data dimension attributes include: service personnel, customer, business department, business line, and product line. Optionally, the data storage module 100 is used to store audit result data with multi-dimensional attribute labels, such as customer, employee, position, business department, business line, and product line—data dimension attributes closely related to the securities industry. This method stores multi-dimensional audit data for record-keeping purposes.
[0026] Permission Management Module 200: Used to define and manage user permissions through a multi-dimensional permission model. The multi-dimensional permission model is used to configure user permissions as the operation permissions of data within the data dimension attributes to which the user belongs.
[0027] Optionally, the permission management module 200 is used to define a user's multi-dimensional permission set based on the organizational dimension (corresponding to data dimension attributes). Specifically, it is used to define and manage user access permissions. The core of the permission management module 200 is a multi-dimensional permission model, which defines a user's permissions as a combination of operation permissions on data within one or more attribute dimensions. Here, the attribute dimensions correspond to data dimension attributes, such as employee, customer, position, business group, business department, business line, and product line. Operation permissions include viewing, editing, exporting, and sharing.
[0028] In one example, the multidimensional permission model in the permission management module 200 is configured as an extension of an attribute-based access control model or a role-based access control model. The extended multidimensional permission model controls permissions based on data dimension attributes. Optionally, the attribute-based access control model, or the extension of the role-based access control model, can support permission management based on organization dimension attributes.
[0029] In this way, through the multi-dimensional permission model in the permission management module 200, the granularity of permission control is refined from "user" or "role" to "data dimension", which can better fit the complex matrix organizational structure of investment advisory institutions and help prevent unauthorized access to data.
[0030] Access control module 300: It is used to communicate with the data storage module and the access management module, and to obtain the target user's permissions from the access management module and the target data dimension attributes from the data storage module according to the user's data access request, and to determine the request result based on the target user's permissions and the target data dimension attributes.
[0031] Optionally, the access control module 300 connects to the data storage module 100 and the access management module 200 to handle user data access requests for audit data. Access requests can be authorized when the user's multidimensional permission set intersects with the data's multidimensional attribute tags in at least one dimension. This approach achieves fine-grained data isolation, refining access control granularity from "user" or "role" to "data dimension" through a multidimensional permission model. This perfectly aligns with the complex matrix organizational structure of investment advisory institutions, effectively preventing unauthorized data access.
[0032] In one example, the access control module 300 is used to receive a user's data access request for the audit data, obtain the target user's permissions from the access management module 200 according to the data access request, and obtain the target data dimension attributes from the data storage module 100.
[0033] The access control module 300 is used to match the target user's permissions with the target data dimension attributes. In response to the intersection between the target user's permissions and the target data dimension attributes, the request result is determined from the audit data.
[0034] Optionally, the system receives user access requests for audit data (such as viewing, sharing, exporting, etc.), calls the permission management module 200, obtains the user's multi-dimensional permission set, matches and calculates the user's permission set with the data dimension attributes of the audit data, and authorizes the access request when there is an intersection between the user's permission set and the data dimension attributes (i.e., the user has operation permissions for the data in at least one dimension), and determines the request result from the audit data.
[0035] In this way, dynamic access control of data is achieved by matching and calculating the user's multidimensional permission set with the multidimensional attribute tags of the data. This enables fine-grained data isolation, refining the granularity of permission control from "user" or "role" to "data dimension" through a multidimensional permission model. This perfectly matches the complex matrix organizational structure of investment advisory institutions and effectively prevents unauthorized data access.
[0036] Permission sharing module 400: Used to provide a sharing access interface based on the sharing policy set by users with operation permissions, including sharing permissions.
[0037] Optionally, the permission sharing module 400 generates a unique, controlled sharing access point for handling cross-dimensional data sharing operations. The permission sharing module 400 allows users with sharing permissions to dynamically set sharing policies when initiating a sharing session. These policies include: sharing target, data scope, target operation permissions, and validity period. In this way, cross-dimensional data sharing is achieved, enabling secure and convenient data sharing across departments and business lines within the system.
[0038] In one example, the sharing strategy in the permission sharing module 400 is configured to include the sharing target, data scope, target operation permissions, and validity period, with the data scope determined based on the configured data dimension attributes.
[0039] Optionally, the sharing policy is configured to achieve at least one of the following: sharing objective, data scope, target operation permissions, and validity period. The sharing objective specifies at least one user, user group, or role to be shared with (e.g., "All Compliance Personnel," "Vice President Zhang"). The data scope is filtered based on multi-dimensional attributes or risk levels (e.g., "Share all audit results of 'high-risk' levels under Business Line A and Business Line B"). Operation permissions refer to the actions that the recipient can perform on the shared data (e.g., "View only," "Export but not edit," "Comment allowed," etc.). The validity period refers to the automatic expiration time of the set sharing link or permissions.
[0040] This approach allows users to create controlled sharing access points based on sharing policies, enabling cross-dimensional data sharing. A dedicated permission-based sharing module ensures secure and convenient data sharing across departments and business lines within the system. Sharing policies are precisely controlled by the initiator, avoiding the risk of secondary data dissemination. This systematizes and standardizes previously offline and informal sharing processes, reducing communication costs and management loopholes, and improving the overall efficiency of compliance management.
[0041] In one example, the sharing access interface provided by the permission sharing module 400 is communicatively connected to the permission control module. The data storage module 100 is also used to store data operation records of the sharing access interface, including data access, sharing, viewing, and exporting. The permission control module 300 is also used to define and manage user data operation records.
[0042] Optionally, for the sharing access interface of the permission sharing module, all access behaviors through the interface are recorded. The data storage module 100 records all user access, sharing, viewing, and export operations of the audit result data to ensure that all behaviors are traceable. Moreover, the behavior traces themselves are also managed by the permission management module 300 and the permission sharing module 400.
[0043] In this way, all access, viewing, sharing, and export operations of the audit data are recorded, and an operation audit log is generated. This provides a complete and clear chain of evidence for internal compliance reviews and responses to external regulatory inspections, enabling "re-auditing of shared audit activities" and enhancing the convenience and reliability of compliance reviews.
[0044] Figure 2 This is a schematic diagram illustrating a management system for audit data retention according to an exemplary embodiment, such as... Figure 2 As shown, the system includes a data storage module 10, a permission management module 20, a permission control module 30, and a permission sharing module 40.
[0045] As an example, suppose an investment advisory company has an "Investment Advisory Department" (departmental dimension) and an "Intelligent Software Department" (departmental dimension). The Intelligent Software Department has two business lines: "AAAA" (business line dimension) and "BBB" (business line dimension).
[0046] User permissions are configured in the permission management module 20: Assume that user A is a regular employee of the "AAAA" business line and his permission set is: {Department: Intelligent Software Department, Business Line: AAAA, Operation: View}. Then user A can only view the audit data of this business line.
[0047] Suppose User B is a compliance specialist in the investment banking department, and their permission set is: {Department: Intelligent Software Department, Business Line: *, Operation: View, Share} (* represents a wildcard, i.e., all business lines). Then User B can view and share all audit data under the entire Intelligent Software Department.
[0048] Assume user C is the company's Chief Compliance Officer, with the following permission set: {Department: *, Business Line: *, Operations: View, Export, Manage}. Then C can view and manage all dimensions of audit data across the entire company.
[0049] When User A attempts to access audit data belonging to the "BBB" business line, the access control module 30 matches User A's access set (business line: AAAA) with the target data's attributes (business line: Intelligent Software Department), and there is no overlap, so User A's access is denied.
[0050] When User B accesses data in the "AAAA" business line, the engine matches successfully (business line matching), so User B is allowed to access.
[0051] When requested to review all recent "high-risk" audit data, Chief Compliance Officer C does not need to export the data. Instead, they can create a sharing strategy through the data sharing and control module: Sharing Target: CSRC Inspector User D; Data Scope: Risk Level = "High Risk"; Operation Permission: View Only; Validity Period: 72 hours. The system then generates an encrypted link or temporary account for User D. Within 72 hours, User D can view all audit results marked "high-risk" across the entire company through this entry point, but cannot see other data or perform export operations. After 72 hours, this entry point automatically expires. User C's sharing behavior is also recorded by the data storage module 10.
[0052] In summary, this application achieves dynamic data access control by matching and calculating the multidimensional permission sets of users with the multidimensional attribute tags of data. It achieves fine-grained data isolation, refining the granularity of permission control from "user" or "role" to "data dimension" through a multidimensional permission model. This perfectly aligns with the complex matrix organizational structure of investment advisory institutions, effectively preventing unauthorized data access. It allows users to create controlled sharing access points based on sharing policies to achieve cross-dimensional data sharing. A dedicated permission sharing module enables secure and convenient data sharing across departments and business lines within the system. The sharing policy is precisely controlled by the initiator, avoiding the risk of secondary data dissemination. This systematizes and standardizes previously offline and informal sharing processes, reducing communication costs and management loopholes, and improving the overall efficiency of compliance management. Furthermore, it records all access, viewing, sharing, and export operations of audit data, providing a complete and clear chain of evidence for internal compliance reviews and external regulatory inspections, enhancing the convenience and reliability of compliance reviews.
[0053] Secondly, embodiments of this application provide a method for managing audit data with a record, which is based on a management system for audit data with a record in the first aspect. Figure 3 This is a flowchart illustrating a method for managing audit data based on embodiments of this application, such as... Figure 3 As shown, the method includes: Step S101: Store the audit data, which is associated with multiple data dimension attributes.
[0054] Step S102: Define and manage user permissions through a multi-dimensional permission model. The multi-dimensional permission model is used to configure user permissions as operation permissions for data within the data dimension attributes to which the user belongs.
[0055] Step S103: Obtain the target user's permissions from the audit data based on the user's data access request, obtain the target data dimension attributes from the user's permissions, and determine the request result based on the target user's permissions and the target data dimension attributes.
[0056] Step S104: Provide a sharing access interface based on the sharing policy set by the user whose operation permissions include sharing permissions.
[0057] In one example, the data dimension attributes include: service personnel, customer, business department, business line, and product line.
[0058] In one example, step S103 includes: receiving a user's data access request for the audit data, obtaining the target user's permissions from the permission management module according to the data access request, and obtaining the target data dimension attributes from the data storage module.
[0059] Match the target user's permissions with the target data dimension attributes. If there is an intersection between the target user's permissions and the target data dimension attributes, determine the request result from the audit data.
[0060] In one example, the sharing strategy is configured to be implemented based on the sharing target, data scope, target operation permissions, and validity period, with the data scope determined based on the configured data dimension attributes.
[0061] In one example, the method further includes: storing data operation records of the shared access interface through a data storage module; data operations include data access, sharing, viewing, and exporting. User data operation records are defined and managed through an access control module.
[0062] In one example, the multidimensional permission model is derived from an attribute-based access control model or a role-based access control model. The extended multidimensional permission model controls permissions based on data dimension attributes.
[0063] In one example, the method also includes storing data operation records of the shared access interface as audit data.
[0064] In summary, this application achieves dynamic data access control by matching and calculating the multidimensional permission sets of users with the multidimensional attribute tags of data. It achieves fine-grained data isolation, refining the granularity of permission control from "user" or "role" to "data dimension" through a multidimensional permission model. This perfectly aligns with the complex matrix organizational structure of investment advisory institutions, effectively preventing unauthorized data access. It allows users to create controlled sharing access points based on sharing policies to achieve cross-dimensional data sharing. Through dedicated permission sharing, cross-departmental and cross-business line data sharing can be completed securely and conveniently within the system. The sharing policy is precisely controlled by the initiator, avoiding the risk of secondary data dissemination. This systematizes and standardizes the previously offline and informal sharing process, reducing communication costs and management loopholes, and improving the overall efficiency of compliance management. Furthermore, it records all access, viewing, sharing, and export operations of audit data, providing a complete and clear chain of evidence for internal compliance reviews and responses to external regulatory inspections, enhancing the convenience and reliability of compliance reviews.
[0065] Thirdly, embodiments of this application provide an electronic device, Figure 4 This is a schematic diagram of an electronic device provided in an embodiment of this application. The electronic device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, it implements the method for managing trace audit data provided in the second aspect. Figure 4The electronic device 60 shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of this application.
[0066] Electronic device 60 may be in the form of a general-purpose computing device, such as a server device. Components of electronic device 60 may include, but are not limited to: at least one processor 61, at least one memory 62, and a bus 63 connecting different system components (including memory 62 and processor 61).
[0067] Bus 63 includes a data bus, an address bus, and a control bus.
[0068] The memory 62 may include volatile memory, such as random access memory (RAM) 621 and / or cache memory 622, and may further include read-only memory (ROM) 623.
[0069] The memory 62 may also include a program / utility 625 having a set (at least one) of program modules 624, including but not limited to: an operating system, one or more application programs, other program modules, and program data, each or some combination of these examples may include an implementation of a network environment.
[0070] The processor 61 executes various functional applications and data processing by running computer programs stored in the memory 62, such as the method for managing audit data provided in the second aspect of this application.
[0071] Electronic device 60 can also communicate with one or more external devices 64 (e.g., keyboard, pointing device, etc.). This communication can be performed via input / output (I / O) interface 65. Furthermore, the model-generated electronic device 60 can also communicate with one or more networks (e.g., local area network (LAN), wide area network (WAN), and / or public networks, such as the Internet) via network adapter 66. Figure 4 As shown, network adapter 66 communicates with other modules of the model-generated electronic device 60 via bus 63. It should be understood that, although not shown in the figure, other hardware and / or software modules can be used in conjunction with the model-generated electronic device 60, including but not limited to: microcode, device drivers, redundant processors, external disk drive arrays, RAID (disk array) systems, tape drives, and data backup storage systems.
[0072] It should be noted that although several units / modules or sub-units / modules of the electronic device have been mentioned in the detailed description above, this division is merely exemplary and not mandatory. In fact, according to embodiments of the present invention, the features and functions of two or more units / modules described above can be embodied in one unit / module. Conversely, the features and functions of one unit / module described above can be further divided and embodied by multiple units / modules.
[0073] Fourthly, embodiments of this application provide a computer-readable storage medium having a program stored thereon, which, when executed by a processor, implements a method for managing audit data provided in the second aspect.
[0074] The readable storage medium may be more specifically adopted, including but not limited to: portable disk, hard disk, random access memory, read-only memory, erasable programmable read-only memory, optical storage device, magnetic storage device, or any suitable combination thereof.
[0075] In a possible implementation, the present invention can also be implemented as a program product comprising program code, which, when the program product is run on a terminal device, is used to cause the terminal device to execute a method for managing trace audit data provided in the second aspect.
[0076] The program code for executing the present invention can be written in any combination of one or more programming languages. The program code can be executed entirely on the user device, partially on the user device, as a standalone software package, partially on the user device and partially on a remote device, or entirely on a remote device.
[0077] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0078] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the invention patent. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this patent application should be determined by the appended claims.
Claims
1. A management system for leaving traceable data, characterized by, include: Data storage module: used to store audit data, which is associated with multiple data dimension attributes; The permission management module is used to define and manage user permissions through a multi-dimensional permission model, which configures user permissions as the operation permissions of data within the data dimension attributes to which the user belongs. Access control module: used to communicate with the data storage module and the access management module, and to obtain the target user's access permissions from the access management module and the target data dimension attributes from the data storage module according to the user's data access request, and to determine the request result based on the target user's access permissions and the target data dimension attributes; Permission sharing module: Used to provide a sharing access interface based on the sharing policy set by the user with the operation permissions, including sharing permissions.
2. The management system for leaving trace inquiring data according to claim 1, wherein, The data dimension attributes include: the service personnel to which the data pertains, the customer to which the data pertains, the business department to which the data pertains, the business line to which the data pertains, and the product line to which the data pertains.
3. The management system for audit data recording according to claim 1, characterized in that, The access control module is used to receive data access requests from users for the traceability audit data, obtain target user permissions from the access management module according to the data access requests, and obtain target data dimension attributes from the data storage module. The access control module is used to match the target user's permissions with the target data dimension attributes, and in response to the intersection between the target user's permissions and the target data dimension attributes, to determine the request result from the audit data.
4. The system for managing traceable data according to claim 1, wherein, The sharing strategy is configured to be determined based on the sharing target, data range, target operation permissions, and validity period, wherein the data range is determined based on the configured data dimension attributes.
5. The management system for audit data retention according to claim 1, characterized in that, The sharing access interface provided by the permission sharing module is communicatively connected to the permission control module. The data storage module is also used to store data operation records of the sharing access interface, including data access, sharing, viewing, and exporting; The access control module is also used to define and manage user data operation records.
6. The management system for audit data recording according to claim 1, characterized in that, The multidimensional permission model is configured as an extension of an attribute-based access control model or a role-based access control model. The extended multidimensional permission model performs permission control based on data dimension attributes.
7. A method for managing audit data in the investment advisory industry, characterized in that, The method is implemented based on a data management system for auditing and recording data as described in any one of claims 1 to 6, and the method includes: Store audit data that leaves a trace, and the audit data is associated with multiple data dimension attributes; User permissions are defined and managed through a multidimensional permission model, which is used to configure user permissions as operation permissions for data within the data dimension attributes to which the user belongs; Based on the user's data access request, the target user's permissions are obtained from the audit data, the target data dimension attributes are obtained from the user's permissions, and the request result is determined based on the target user's permissions and the target data dimension attributes. Provide a sharing access interface based on the sharing policy set by the user with the operation permissions, including sharing permissions.
8. A method for managing audit data in the investment advisory industry according to claim 7, characterized in that, The method also includes storing the data operation records of the shared access interface as audit data.
9. An electronic device, characterized in that, It includes a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein the processor, when executing the computer program, implements a method for managing audit data as described in any one of claims 7 to 8.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, it implements a method for managing audit data as described in any one of claims 7 to 8.