Risk compliance-based authority management method, system, computer device, and medium

The risk compliance-based authority management method and system address issues of excessive and incorrect authorization by using an authority risk dictionary to ensure compatibility and generate reports, thereby preventing risks and improving operational compliance.

JP2026500058AActive Publication Date: 2026-01-06CHINA THREE GORGES INT CORP
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
JP2024557810
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-16
Filing Date
2024-06-12
Publication Date
2026-01-06
Estimated Expiration
2044-06-12

AI Technical Summary

Technical Problem

Existing enterprise authority management systems face issues such as excessive authorization, incorrect authorization, and conflicting responsibilities, leading to operational and financial risks.

Method used

A risk compliance-based authority management method and system that utilizes an authority risk dictionary to determine conflict risk relationships between authorities, ensuring compatibility with job information and business operations, and generates a risk management report to prevent excessive or erroneous authorization.

Benefits of technology

Prevents business and financial risks by timely identifying and addressing potential conflicts in authority grants, enhancing compliance and stability in enterprise operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026500058000001_ABST
    Figure 2026500058000001_ABST
Patent Text Reader

Abstract

This application relates to the computer technical field and provides a risk-compliance-based rights management method, system, computer device, and medium. The risk-compliance-based rights management method includes the steps of: acquiring an applicant's rights request and at least one first right, where the rights request includes a second right, the second right being the right requested by the applicant, and the first right being the right granted to the applicant; acquiring an rights risk dictionary, where the rights risk dictionary includes conflict risk relationships between multiple rights; determining whether the rights request has a conflict risk according to each first right, each second right, and each conflict risk relationship in the rights risk dictionary, obtaining a risk judgment result for the rights request; and processing the rights request according to the risk judgment result. This application prevents the occurrence of phenomena such as excessive rights assignment, erroneous rights assignment, and conflicting responsibilities, timely avoids business risks and financial risks caused by rights management, and meets risk compliance control requirements.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present application relates to the field of computer technology, and more particularly to a method, system, computer device, and medium for managing privileges based on risk compliance. [Background technology]

[0002] In recent years, enterprises have increasingly placed importance on risk management and internal risk management compliance. The requirements for informationized, digitalized, and intelligent risk management and control, such as "accelerating the construction of risk management and control systems," have gradually been put forward. In enterprise risk management and control, problems such as excessive authorization, incorrect authorization, and conflicting responsibilities often lead to operational and financial risks. Therefore, how to resolve enterprise authority management issues and meet risk compliance control requirements has become increasingly urgent. Summary of the Invention [Problem to be solved by the invention]

[0003] In order to meet the risk compliance control requirements and realize the authority management, this application proposes a risk compliance-based authority management method, system, computer device and medium. [Means for solving the problem]

[0004] In a first aspect, the present application provides a method for manufacturing a pharmaceutical composition comprising: obtaining an authority request and at least one first authority from an applicant, the authority request including a second authority, the second authority being an authority requested by the applicant, and the first authority being an authority granted to the applicant; obtaining an authority risk dictionary, the authority risk dictionary including conflict risk relationships between multiple authorities; According to each first authority, each second authority, and each collision risk relationship in the authority risk dictionary, determining whether the authority application has a collision risk, and obtaining a risk determination result of the authority application; and processing the authority application according to the risk determination result.

[0005] Considering that there is a risk of conflict between multiple authorities, if two authorities with a risk of conflict are granted to the same applicant, a risk of liability conflict will occur, which will further lead to business risks and financial risks for the enterprise. By using the above method, in the process of an applicant requesting authority, the conflict risk relationship between the applicant's granted authority and the requested authority is taken into consideration to determine whether the authority application has a risk of conflict, and the authority application is processed according to the risk assessment result, thereby preventing the occurrence of phenomena such as excessive authorization, erroneous authorization, and conflicting responsibilities, and timely avoiding the occurrence of business risks and financial risks caused by authority management, effectively reducing fraudulent manipulation instead of post-facto avoidance and risk-bearing, better managing and responding to risk compliance issues, and improving the stability, sustainability, and compliance of business operations.

[0006] In one alternative embodiment, the step of obtaining an authority risk dictionary comprises: obtaining at least one business activity; determining a business operation for each business activity according to each business activity; determining a plurality of permissions according to each business operation; and obtaining a collision risk relationship between each authority according to a preset rule.

[0007] In the above embodiment, each authority in the enterprise is determined according to each business operation in each business activity, and the conflict risk relationship existing between each authority is determined according to a preset rule, thereby constructing an authority risk dictionary, identifying incompatible job responsibilities, and providing a basis for authority management control.

[0008] In one alternative embodiment, the step of determining whether the authority application has a collision risk according to each first authority, each second authority, and each collision risk relationship in the authority risk dictionary, and obtaining a risk determination result for the authority application, includes: determining whether there is a collision risk between each first authority and each second authority according to each collision risk relationship in the authority risk dictionary; and determining that there is a collision risk in the authority application if there is at least one first authority that has a collision risk with the second authority.

[0009] In one alternative embodiment, the step of processing the authorization request in response to the risk determination includes: determining a first processing result according to the risk assessment result; obtaining a second processing result; determining a third processing result according to the first processing result and the second processing result; and processing the authorization request according to the third processing result.

[0010] In one alternative embodiment, the step of obtaining the second processing result comprises: obtaining job information of the applicant; and determining a second processing result according to the job information and the authority application.

[0011] In the above embodiment, it is determined whether the authority application matches the job information of the applicant, in addition to the job information of the applicant, thereby ensuring compatibility between the applicant's job information and the authorities, avoiding the granting of authorities that do not match the job information, ensuring compliance with authority risk management, and further reducing the possibility of risks due to the granting of authorities.

[0012] In one alternative embodiment, the method comprises: The method further includes generating a risk management report according to the first processing result and the second processing result.

[0013] According to the above embodiment, a risk management report is generated in accordance with the first processing result and the second processing result, and the risk management report is incorporated into the risk compensation control process to provide a basis for subsequent risk compliance assessment and risk investigation.

[0014] In a second aspect, the present application includes an authority risk dictionary and an authority management platform; The authority risk dictionary is used to obtain the conflict risk relationship between multiple authorities; The authority management platform further provides a risk compliance-based authority management system used for obtaining an applicant's authority application and at least one first authority, where the authority application includes a second authority, the second authority being the authority requested by the applicant and the first authority being the authority granted to the applicant; determining whether the authority application has a collision risk according to each first authority, the second authority, and each collision risk relationship in the authority risk dictionary, obtaining a risk judgment result for the authority application; and processing the authority application according to the risk judgment result.

[0015] Considering that there is a risk of conflict between multiple authorities, if two authorities with a risk of conflict are granted to the same applicant, a risk of liability conflict will occur, which will further lead to business risks and financial risks for the enterprise. With the above system, in the process of an applicant requesting authority, the system determines whether there is a risk of conflict in the authority application based on the risk of conflict between the authority granted to the applicant and the authority requested, and processes the authority application according to the risk judgment result, thereby preventing the occurrence of phenomena such as excessive authorization, erroneous authorization, and incompatible responsibilities, and timely avoiding the occurrence of business risks and financial risks caused by authority management, effectively reducing fraudulent manipulation instead of post-facto avoidance and risk bearing, better managing and responding to risk compliance issues, and improving the stability, sustainability, and compliance of business operations.

[0016] In one alternative embodiment, the system further includes an authorization data dictionary; The authority data dictionary is used to store authority data corresponding to each authority.

[0017] According to the above embodiment, the authority data dictionary is used to realize management of the authority data corresponding to each authority.

[0018] In a third aspect, the present application further provides a computer device including a memory and a processor, the memory and processor being communicatively coupled to each other, the memory having computer instructions stored therein, the processor executing the computer instructions to perform the steps of the risk compliance based privilege management method of the first aspect or any of the embodiments of the first aspect.

[0019] In a fourth aspect, the present application further provides a computer-readable storage medium having stored thereon a computer program that, when executed by a processor, implements the steps of the risk compliance based privilege management method of the first aspect or any of the embodiments of the first aspect.

[0020] In order to more clearly describe the specific embodiments of the present application or the technical solutions of the prior art, the drawings necessary for describing the specific embodiments or the prior art will be briefly described below. It is obvious that the drawings described below are some embodiments of the present application, and those skilled in the art can obtain other drawings based on these drawings without any creative work. [Brief explanation of the drawings]

[0021] [Figure 1] 1 is a flowchart of a risk compliance-based authority management method according to an exemplary embodiment. [Figure 2] FIG. 1 is a structural schematic diagram of a risk compliance-based authority management system according to an exemplary embodiment; [Figure 3] FIG. 1 is an overall framework diagram of an application of a risk compliance-based authority management system in one example. [Figure 4]FIG. 1 is a schematic diagram of an authorization data dictionary in one example. [Figure 5] FIG. 1 is a framework diagram of a rights management process and an entitlement management process in one example. [Figure 6] FIG. 1 is a schematic diagram illustrating a scenario of encrypting data in a risk compliance-based rights management system according to an example. [Figure 7] FIG. 1 is a hardware structural schematic diagram of a computer device according to an exemplary embodiment; DETAILED DESCRIPTION OF THE INVENTION

[0022] The technical solutions of the present application will be described below clearly and completely with reference to the drawings, and it is obvious that the described embodiments are only some of the embodiments of the present application, not all of the embodiments, and other embodiments that a person skilled in the art can obtain without creative efforts based on the embodiments of the present application all fall within the scope of protection of the present application.

[0023] Furthermore, the technical features according to different embodiments of the present application described below can be combined with each other unless they contradict each other.

[0024] In order to meet the risk compliance control requirements and realize the authority management, this application proposes a risk compliance-based authority management method, system, computer device and medium.

[0025] 1 is a flowchart of a method for managing rights based on risk compliance according to an exemplary embodiment. As shown in FIG. 1, the method for managing rights based on risk compliance includes the following steps S101 to S104.

[0026] Step S101: Obtain an applicant's authority request and at least one first authority, where the authority request includes a second authority, the second authority is the authority requested by the applicant, and the first authority is the authority granted to the applicant.

[0027] In one alternative embodiment, the applicant's authority request may be authority addition, authority change, etc., and is not specifically limited herein.

[0028] Step S102: Obtain an authority risk dictionary, which includes conflict risk relationships between multiple authorities.

[0029] In one alternative embodiment, the conflict risk relationship between each authority includes a conflict relationship and a non-conflict relationship. For example, when a teller job authority and an accounting job authority are simultaneously granted to an applicant, a financial fraud risk occurs, and in this case, the conflict risk relationship between the teller job authority and the accounting job authority is a conflict relationship.

[0030] In one alternative embodiment, the authority may be determined by business operations corresponding to multiple business activities, with different authorities corresponding to business operations in different business activities.

[0031] In one alternative embodiment, there are responsibility conflicts between business operations in different business activities, and correspondingly, there are responsibility conflict risks between the authorities corresponding to the business operations in different business activities. Therefore, the conflict risk relationship between each authority may be determined according to whether there are responsibility conflicts between the business operations corresponding to each authority.

[0032] In one alternative embodiment, the authority risk dictionary may be represented by a responsibility collision risk matrix, where the values ​​in the responsibility collision risk matrix represent the collision risk relationships between each authority.

[0033] Step S103: According to each first authority, second authority, and each collision risk relationship in the authority risk dictionary, determine whether the authority application has a collision risk, and obtain a risk determination result of the authority application.

[0034] In one alternative embodiment, the risk determination result includes that the authority application is a collision risk and that the authority application is not a collision risk.

[0035] In one alternative embodiment, if there is any one first authority that has a collision risk with a second authority, it is determined that the authority application has a collision risk.

[0036] In one alternative embodiment, if there is no collision risk between the second authority and each first authority, it is determined that there is no collision risk for the authority application.

[0037] Step S104: The authority application is processed according to the risk assessment result.

[0038] In one alternative embodiment, the authorization request can be processed according to the risk judgment result, including passing the authorization request and not passing the authorization request.

[0039] Considering that there is a risk of conflict between multiple authorities, if two authorities with a risk of conflict are granted to the same applicant, a risk of liability conflict will occur, which will further lead to business risks and financial risks for the enterprise. By using the above method, in the process of an applicant requesting authority, the conflict risk relationship between the authority granted to the applicant and the authority requested is taken into consideration to determine whether the authority application has a risk of conflict, and the authority application is processed according to the risk judgment result, thereby preventing the occurrence of phenomena such as excessive authority granting, erroneous authority granting, and incompatible responsibilities, and timely avoiding the occurrence of business risks and financial risks caused by authority management, effectively reducing fraudulent manipulation instead of post-facto avoidance and risk bearing, better managing and responding to risk compliance issues, and improving the stability, sustainability, and compliance of business operations.

[0040] In one example, in the above step S102, the authority risk dictionary is obtained by the following method.

[0041] First, obtain at least one business activity.

[0042] In one alternative embodiment, the business activities may be divided by function or by process. When divided by function, the business activities may include, but are not limited to, operations, marketing, and financial activities.

[0043] Next, the business operations for each business activity are determined according to each business activity.

[0044] In one alternative embodiment, the business operations corresponding to different business activities are different. Illustratively, business operations in financial activities include reporting operations and tax management, etc., and business operations in marketing activities include customer service management, etc.

[0045] Next, a plurality of authorities are determined according to each business operation.

[0046] In one alternative embodiment, different business operations correspond to different permissions.

[0047] Finally, the conflict risk relationship between each authority is obtained according to a preset rule.

[0048] In one alternative embodiment, the pre-defined rules may be set according to specific circumstances, such as a conflict risk between the authority corresponding to the business operations in financial activities and the authority corresponding to the business operations in other business activities, a conflict risk between the authority corresponding to the master data maintenance operation and the authority corresponding to the business operations in other business activities, etc.

[0049] In the embodiment of the present application, each authority in an enterprise is determined according to each business operation in each business activity, and the conflict risk relationship existing between each authority is determined according to a preset rule, thereby constructing an authority risk dictionary, identifying incompatible job responsibilities, and providing a basis for authority management control.

[0050] In one example, in the above step S103, it is determined whether or not there is a collision risk in the authority application by the following method, and a risk determination result of the authority application is obtained.

[0051] According to each collision risk relationship in the authority risk dictionary, it is determined whether there is a collision risk between each first authority and second authority, and if there is at least one first authority that has a collision risk with a second authority, it is determined that there is a collision risk in the authority application.

[0052] In one example, in step S103 above, the authorization request is processed by the following steps.

[0053] Step a1: Determine a first processing result according to the risk judgment result.

[0054] In one alternative embodiment, the first processing result includes passing the authorization request and not passing the authorization request.

[0055] In one optional embodiment, if it is determined that there is a risk of conflict between the second authority and at least one first authority, the first processing result is to decide not to pass the authority application, i.e., the second authority is not granted to the applicant.

[0056] Step a2: Obtain the second processing result.

[0057] In one alternative embodiment, the second processing result also includes passing the authorization request and not passing the authorization request.

[0058] In one alternative embodiment, the second processing result is obtained by the following method.

[0059] First, the job information of the applicant is obtained.

[0060] Next, a second processing result is determined according to the job information and the authority application.

[0061] In the embodiment of the present application, in addition to the job information of the applicant, it is determined whether the authority application matches the job information, ensuring the compatibility between the applicant's job information and the authority, avoiding the granting of authority that does not match the job information, ensuring compliance with authority risk management, and further reducing the possibility of risks due to the granting of authority.

[0062] Step a3: Determine a third processing result according to the first processing result and the second processing result. For example, if both the first processing result and the second processing result indicate that the authorization request is to be passed, the third processing result may indicate that the authorization request is to be passed.

[0063] Step a4: Process the authority application according to the third processing result.

[0064] In the embodiment of the present application, the first processing result is determined based on whether there is a risk conflict between the second authority and the authorized first authority, and the second processing result is determined based on whether the second authority matches the job information of the applicant, and the first processing result and the second processing result are combined to finally form a third processing result, which not only avoids the possibility of a conflict risk but also meets the risk compliance requirements in combination with the job information of the applicant.

[0065] In one example, the method according to the present embodiments comprises: The method further includes generating a risk management report according to the first processing result and the second processing result.

[0066] In the embodiment of the present application, the risk management report is incorporated into the risk compensation control process to provide a basis for subsequent risk compliance assessment and risk investigation, reduce the error rate of the risk management compliance system, and achieve organic linkage between risk management management and the supervision system.

[0067] 2 is a structural schematic diagram of a risk compliance-based rights management system according to an exemplary embodiment, which includes: a rights risk dictionary 1 and a rights management platform 2.

[0068] The authority risk dictionary 1 is used to obtain the conflict risk relationship between multiple authorities.

[0069] The authority management platform 2 is used for obtaining an applicant's authority application and at least one first authority, where the authority application includes a second authority, the second authority is the authority requested by the applicant, and the first authority is the authority granted to the applicant; determining whether the authority application has a collision risk according to each first authority, second authority, and each collision risk relationship in the authority risk dictionary 1, obtaining a risk judgment result for the authority application; and processing the authority application according to the risk judgment result.

[0070] Considering that there is a risk of conflict between multiple authorities, if two authorities with a risk of conflict are granted to the same applicant, a risk of liability conflict will occur, which will further lead to business risks and financial risks for the enterprise. With the above system, in the process of an applicant requesting authority, the system determines whether there is a risk of conflict in the authority application based on the risk of conflict between the authority granted to the applicant and the authority requested, and processes the authority application according to the risk judgment result, thereby preventing the occurrence of phenomena such as excessive authorization, erroneous authorization, and incompatible responsibilities, and timely avoiding the occurrence of business risks and financial risks caused by authority management, effectively reducing fraudulent manipulation instead of post-facto avoidance and risk bearing, better managing and responding to risk compliance issues, and improving the stability, sustainability, and compliance of business operations.

[0071] In one example, the system further includes an authority data dictionary, which is used to store authority data corresponding to each authority.

[0072] In one alternative embodiment, the authorization data includes a business operation list (transaction code) and specific business data disclosed by the authorization.

[0073] In one optional embodiment, the authority data dictionary establishes unified authority technical standards (such as authority naming specifications and authority expression structures) according to the business operations corresponding to each authority, realizes the self-management of each authority, avoids the gradual confusion of authority data, relieves the pressure of authority operation and maintenance, and improves the identifiability and maintainability of authorities.

[0074] In one example, the system further includes a data encryption and decryption device, which is used to encrypt and decrypt data transmitted in the system, thereby improving the security of the data in the system.

[0075] Figure 3 is an overall framework diagram for applying a risk-compliance-based privilege management system. The risk-compliance-based privilege management system includes a privilege risk dictionary 1, a privilege management platform 2, and a privilege data dictionary. The privilege management maintenance group establishes the privilege risk dictionary 1 and the privilege data dictionary to build the privilege management platform 2. The risk-compliance-based privilege management system manages on-premise systems and public cloud systems, and realizes the creation of a privilege self-service function available to users of the head office and regional companies. In the application process of the risk-compliance-based privilege management system, risk compliance management and control are realized through the privilege management process and the authorization management process.

[0076] 4 is a schematic diagram of an authority data dictionary, which contains authority data corresponding to the authorities of multiple applicants.

[0077] Figure 5 is a framework diagram of the authority management process and the authorization management process. The authority management process domain includes the role management process, which manages each authority and its authority data. The authority management process domain includes the authority addition request process, authority change request process, risk compensation control process, broad authority request process, account addition request process, account freeze request process, and account unfreeze request process. The broad authority request process refers to the application process for broad authorities. Broad authorities are system-level authorities that can have a significant impact on the system, such as the authority to delete system base tables or the authority to change important global configurations of the system.

[0078] Figure 6 is a schematic diagram of a scenario in which data is encrypted in a risk-compliance-based privilege management system. The risk-compliance-based privilege management system uses SAP UI Data Protection Masking for SAP S / 4 HANA Suite to encrypt and display user access to sensitive data in the system. The SAP UI Data Protection Masking for SAP S / 4 HANA Suite includes a rule engine domain configurator and processor. The rule engine domain configurator and processor hide specific data (fields / columns) to prevent sensitive data from leaking, hide sensitive values ​​by default, require explicit permission to access, and must assign permissions to check administrative accounts in the system.

[0079] 7 is a hardware structural diagram of a computer device according to an exemplary embodiment. As shown in FIG. 7, the device includes one or more processors 710 and memory 720. The memory 720 includes persistent memory, volatile memory, and a hard disk. In FIG. 7, one processor 710 is taken as an example. The device may further include an input device 730 and an output device 740.

[0080] The processor 710, memory 720, input device 730, and output device 740 may be connected by a bus or in other ways, and FIG. 7 illustrates the connection by a bus as an example.

[0081] The processor 710 may be a central processing unit (CPU). The processor 710 may also be other general-purpose processors, chips such as digital signal processors (DSPs), application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, or a combination of the various chips described above. The general-purpose processor may be a microprocessor, or the processor may be any conventional processor, etc.

[0082] The memory 720 is a non-transitory computer-readable storage medium, including persistent memory, volatile memory, and a hard disk, and can be used to store non-transitory software programs, non-transitory computer-executable programs, and modules, such as program instructions / modules corresponding to the risk-compliance-based privilege management method in the embodiments of the present application. The processor 710 executes the non-transitory software programs, instructions, and modules stored in the memory 720 to perform various functional applications and data processing of the server, i.e., to realize any one of the risk-compliance-based privilege management methods.

[0083] Memory 720 may include a program storage area capable of storing an operating system and application programs necessary for at least one function, and a data storage area capable of storing data, etc., as needed. Memory 720 may also include high-speed random access memory and may further include non-transitory memory, such as at least one disk storage device, flash memory device, or other non-transitory solid-state storage device. In some embodiments, memory 720 may optionally include memory located remotely from processor 710, and these remote memories may be connected to the data processing device via a network. Examples of such networks include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0084] The input device 730 can receive input numeric or textual information and generate signal inputs related to user settings and function control. The output device 740 can include a display device such as a display.

[0085] The one or more modules are stored in memory 720 and, when executed by one or more processors 710, perform the method illustrated in FIG.

[0086] The above product can implement the method according to the embodiment of the present application, and has corresponding functional modules for implementing the method and beneficial effects. For technical details not described in detail in the embodiment, please refer to the relevant description of the embodiment shown in FIG.

[0087] An embodiment of the present application further provides a non-transitory computer storage medium, the computer storage medium having computer-executable instructions stored thereon, the computer-executable instructions being capable of performing the method of any one of the method embodiments described above. The storage medium may be a magnetic disk, an optical disk, a read-only memory (ROM), a random access memory (RAM), a flash memory, a hard disk drive (HDD), a solid-state drive (SSD), etc., and the storage medium may include a combination of the above types of memory.

[0088] It should be noted that, in this specification, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another and do not necessarily require or imply any actual relationship or order between those entities or operations. Furthermore, in this specification, the terms "comprise," "include," or any other variation thereof are intended to cover a non-exclusive inclusion, whereby a process, method, article, or device that includes a set of elements includes not only those elements but also other elements not expressly listed or elements inherent in the process, method, article, or device. Absent further limitations, an element qualified by the phrase "comprises ..." does not exclude the presence of other identical elements in the process, method, article, or device that includes the element.

[0089] The foregoing are merely specific embodiments of the present application to enable those skilled in the art to understand or realize the present application. Various modifications to these examples will be apparent to those skilled in the art, and the general principles defined herein may be implemented in other examples without departing from the spirit or scope of the present application. Therefore, the present application is not intended to be limited to the examples shown herein, but is to be accorded the widest scope consistent with the principles and novel features claimed herein.

Claims

1. A risk compliance-based authority management method, comprising: obtaining an applicant's authority request and at least one first authority, the authority request including a second authority, the second authority being a authority requested by the applicant, and the first authority being a authority granted to the applicant; obtaining an authority risk dictionary, the authority risk dictionary including conflict risk relationships between multiple authorities; According to each of the first authority, the second authority, and each of the collision risk relationships in the authority risk dictionary, determining whether the authority application has a collision risk, and obtaining a risk determination result of the authority application; and processing the authority application according to the risk assessment result.

2. The step of obtaining the authority risk dictionary includes: obtaining at least one business activity; determining a business operation for each of the business activities according to each of the business activities; determining a plurality of authorities according to each of the business operations; and obtaining a collision risk relationship between each of the authorities according to a preset rule.

3. The step of determining whether the authority application has a collision risk according to each of the first authority, the second authority, and each of the collision risk relationships in the authority risk dictionary, and obtaining a risk determination result for the authority application, determining whether there is a collision risk between each of the first authorities and the second authorities according to each of the collision risk relationships in the authority risk dictionary; 2. The method of claim 1, further comprising: determining that the authority application presents a collision risk if there is at least one first authority that presents a collision risk with the second authority.

4. The step of processing the authority application in accordance with the risk determination result includes: determining a first processing result in response to the risk assessment result; obtaining a second processing result; determining a third processing result according to the first processing result and the second processing result; and processing the authorization request according to the third processing result.

5. The step of acquiring the second processing result includes: obtaining job information of the applicant; and determining the second processing result in response to the job information and the authorization request.

6. The method of claim 4 , further comprising generating a risk management report in response to the first processing result and the second processing result.

7. A risk compliance-based authority management system, comprising: an authority risk dictionary; and an authority management platform; The authority risk dictionary is used to obtain conflict risk relationships between multiple authorities; A risk compliance-based rights management system, characterized in that the rights management platform is used for obtaining an applicant's rights application and at least one first right, wherein the rights application includes a second right, the second right is the right requested by the applicant, and the first right is the right granted to the applicant; determining whether the rights application has a collision risk according to each of the first rights, the second rights, and each of the collision risk relationships in the rights risk dictionary, obtaining a risk judgment result for the rights application; and processing the rights application according to the risk judgment result.

8. 8. The system of claim 7, further comprising an authority data dictionary for storing authority data corresponding to each said authority.

9. A computer device comprising a memory and a processor, the memory and the processor being communicatively connected to each other, the memory storing computer instructions, and the processor executing the computer instructions to perform the steps of the risk compliance-based authority management method described in any one of claims 1 to 6.

10. A computer-readable storage medium having a computer program stored therein, the computer program being characterized in that, when executed by a processor, the computer program implements the steps of the risk compliance-based authority management method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Permission application examination and approval method and authorization management platform

    CN107679749A

  • Business system authority management method and device, electronic equipment and storage medium

    CN112529524A

  • Authority management method and device

    CN118071266A

  • Access rights management in enterprise digital rights management systems

    US20130036475A1