Risk compliance-based access control methods, systems, computer equipment, and media

The risk compliance-based authorization management method addresses conflicts in enterprise permission systems by using an authorization risk dictionary to process requests, preventing operational and financial risks, and enhancing compliance and sustainability.

JP7853439B2Active Publication Date: 2026-04-28CHINA THREE GORGES INT CORP
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
CHINA THREE GORGES INT CORP
Filing Date
2024-06-12
Publication Date
2026-04-28

AI Technical Summary

Technical Problem

Existing enterprise permission management systems face challenges in managing conflicts between authority levels, leading to operational and financial risks due to excessive, incorrect, or incompatible authorizations, which are not adequately addressed by current risk compliance control methods.

Method used

A risk compliance-based authorization management method and system that includes obtaining an applicant's permission request, determining conflict risk relationships using an authorization risk dictionary, and processing requests based on risk assessment results to prevent conflicts and ensure compliance, thereby reducing fraudulent operations and improving operational stability and sustainability.

Benefits of technology

The method effectively prevents excessive or incorrect authority granting, reduces operational and financial risks, and enhances compliance by identifying and managing conflicts in authority management, ensuring timely risk mitigation and improved business operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007853439000001
    Figure 0007853439000001
  • Figure 0007853439000002
    Figure 0007853439000002
  • Figure 0007853439000003
    Figure 0007853439000003
Patent Text Reader

Abstract

This application relates to the computer technical field and provides a risk-compliance-based rights management method, system, computer device, and medium. The risk-compliance-based rights management method includes the steps of: acquiring an applicant's rights request and at least one first right, where the rights request includes a second right, the second right being the right requested by the applicant, and the first right being the right granted to the applicant; acquiring an rights risk dictionary, where the rights risk dictionary includes conflict risk relationships between multiple rights; determining whether the rights request has a conflict risk according to each first right, each second right, and each conflict risk relationship in the rights risk dictionary, obtaining a risk judgment result for the rights request; and processing the rights request according to the risk judgment result. This application prevents the occurrence of phenomena such as excessive rights assignment, erroneous rights assignment, and conflicting responsibilities, timely avoids business risks and financial risks caused by rights management, and meets risk compliance control requirements.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of computers, and particularly to a permission management method, system, computer device, and medium based on risk compliance.

Background Art

[0002] In recent years, enterprises have been increasingly emphasizing the importance of risk management and internal risk management compliance. Requirements for the management and control of informationization, digitalization, and intelligentization of risks, such as "accelerating the construction of risk management and control systems," have been gradually proposed. In enterprise risk management and control, business risks and financial risks often occur due to problems such as excessive authorization, incorrect authorization, and incompatible responsibilities. Therefore, how to solve the enterprise's permission management problems and meet the risk compliance control requirements has become increasingly urgent.

Summary of the Invention

Problems to be Solved by the Invention

[0003] In order to meet the risk compliance control requirements and achieve permission management, this application proposes a permission management method, system, computer device, and medium based on risk compliance.

Means for Solving the Problems

[0004] In a first aspect, this application includes: Steps of obtaining an applicant's permission application and at least one first permission, where the permission application includes a second permission, the second permission is the permission required by the applicant, and the first permission is the permission granted to the applicant; and Steps of obtaining a permission risk dictionary, where the permission risk dictionary includes the collision risk relationships between multiple permissions; and The steps include determining whether there is a conflict risk in the authorization application, according to each first authorization, second authorization, and conflict risk relationship in the authorization risk dictionary, and obtaining the risk assessment result for the authorization application, This provides a risk compliance-based authorization management method, which includes a step of processing authorization requests in accordance with the results of a risk assessment.

[0005] Considering the conflict risk relationships between multiple authority levels, if two conflicting authority levels are granted to the same applicant, a conflict of responsibility risk arises, which can further lead to operational and financial risks for the company. By using the method described above, in the process of an applicant requesting authority, it is possible to determine whether there is a conflict risk in the authority request, in addition to the conflict risk relationship between the authority level granted to the applicant and the requested authority level. By processing the authority request according to the risk assessment result, it is possible to prevent phenomena such as excessive authority leveling, incorrect authority leveling, and incompatible responsibilities, thereby avoiding operational and financial risks arising from authority management in a timely manner, effectively reducing fraudulent operations instead of retroactive avoidance or risk burdening, better managing and responding to risk compliance issues, and improving the stability, sustainability, and compliance of business operations.

[0006] In one selectable embodiment, the step of obtaining the authorization risk dictionary is: Steps to acquire at least one business activity, The steps include determining the operational procedures for each business activity, according to each business activity, The steps involve determining multiple permissions according to each business operation, This includes the step of obtaining the conflict risk relationship between each authority according to pre-configured rules.

[0007] According to the above embodiment, each authority within the company is determined according to each business operation in each business activity, the conflict risk relationships between each authority are determined by pre-set rules, an authority risk dictionary is constructed, incompatible job responsibilities are identified, and a basis is provided for the control of authority management.

[0008] In one selectable embodiment, the steps of determining whether there is a conflict risk in the authorization application and obtaining the risk determination result for the authorization application are as follows: The steps include determining whether there is a conflict risk between each first and second authority, according to each conflict risk relationship in the authority risk dictionary, The procedure includes the step of determining that there is a conflict risk in the authorization request if there is at least one first authorization that has a conflict risk with the second authorization.

[0009] In one selectable embodiment, the step of processing authorization requests in accordance with the risk assessment results is: A step to determine the first processing result based on the risk assessment results, The second step is to obtain the processing result, A step of determining a third processing result based on the first processing result and the second processing result, The third step includes processing the authorization request in accordance with the processing result.

[0010] In one selectable embodiment, the step of obtaining a second processing result is: Steps to obtain the applicant's job information, This includes the step of determining a second processing result in accordance with job information and authority requests.

[0011] According to the above embodiment, in addition to the applicant's job information, it is determined whether the authorization request matches the job information, ensuring the suitability of the applicant's job information and the authorization, avoiding the granting of authorizations that do not match the job information, ensuring compliance with authorization risk management, and further reducing the potential risks associated with the granting of authorizations.

[0012] In one selectable embodiment, the method is The process further includes the step of generating a risk management report based on the results of the first and second processing steps.

[0013] According to the above embodiment, a risk management report is generated in conjunction with the first and second processing results, and this risk management report is incorporated into the risk compensation control process to provide a basis for subsequent risk compliance evaluations and risk investigations.

[0014] In a second aspect, the present application includes an authority risk dictionary and an authority management platform. The authority risk dictionary is used to obtain conflict risk relationships between multiple authority levels. The authorization management platform further provides a risk compliance-based authorization management system used to obtain an applicant's authorization request and at least one first authorization, wherein the authorization request includes a second authorization, the second authorization being the authorization requested by the applicant and the first authorization being the authorization granted to the applicant; to determine whether there is a conflict risk in the authorization request according to each first authorization, second authorization, and conflict risk relationship in the authorization risk dictionary, to obtain a risk assessment result for the authorization request, and to process the authorization request according to the risk assessment result.

[0015] Considering the conflict risk relationships between multiple authority levels, if two conflicting authority levels are granted to the same applicant, a conflict of responsibility risk arises, which can further lead to operational and financial risks for the company. The system described above, in the process of an applicant requesting authority, determines whether there is a conflict risk in the authority request, in addition to the conflict risk relationship between the authority level granted to the applicant and the requested authority level. By processing the authority request according to the risk assessment result, it prevents phenomena such as excessive authority granting, incorrect authority granting, and incompatible responsibilities, thereby avoiding operational and financial risks arising from authority management in a timely manner, effectively reducing fraudulent operations instead of retroactive avoidance or risk burdening, better managing and responding to risk compliance issues, and improving the stability, sustainability, and compliance of business operations.

[0016] In one selectable embodiment, the system further includes an authorization data dictionary. The authority data dictionary is used to store the authority data corresponding to each authority.

[0017] According to the above embodiment, the management of the authority data corresponding to each authority is realized by using the authority data dictionary.

[0018] In the third aspect, the present application further provides a computer device, which includes a memory and a processor, the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the computer instructions to execute the steps of the authority management method based on the risk compliance of any one of the first aspect or the embodiments of the first aspect.

[0019] In the fourth aspect, the present application further provides a computer-readable storage medium, in which a computer program is stored, and when the computer program is executed by a processor, the steps of the authority management method based on the risk compliance of any one of the first aspect or the embodiments of the first aspect are realized.

[0020] In order to more clearly illustrate the specific embodiments of the present application or the technical solutions of the prior art, the following briefly describes the drawings required for the description of the specific embodiments or the prior art. Obviously, the drawings described below are some embodiments of the present application, and those skilled in the art can obtain other drawings based on these drawings without creative labor.

Brief Description of the Drawings

[0021] [Figure 1] It is a flowchart of an authority management method based on risk compliance according to an exemplary embodiment. [Figure 2] It is a structural schematic diagram of an authority management system based on risk compliance according to an exemplary embodiment. [Figure 3] It is an overall framework diagram of applying an authority management system based on risk compliance in an example. [Figure 4]This is a schematic diagram of an authority data dictionary in one example. [Figure 5] This is a framework diagram of an example of an access control process and an access granting process. [Figure 6] This is a schematic diagram illustrating a scenario in which data is encrypted in a risk compliance-based access control system, as an example. [Figure 7] This is a schematic diagram of the hardware structure of a computer device according to one exemplary embodiment. [Modes for carrying out the invention]

[0022] The technical solutions of the present application will be described clearly and completely below with reference to the drawings, and it will be clear that the embodiments described are some, but not all, embodiments of the present application. Any other embodiments that a person skilled in the art can obtain without creative work based on the embodiments of the present application are all within the scope of protection of the present application.

[0023] Furthermore, the technical features of the different embodiments of the present application described below can be combined with each other, insofar as they do not contradict each other.

[0024] To meet risk compliance control requirements and achieve authority management, this application proposes a risk compliance-based authority management method, system, computer equipment, and media.

[0025] Figure 1 is a flowchart of a risk compliance-based access control method according to one exemplary embodiment. As shown in Figure 1, the risk compliance-based access control method includes the following steps S101 to S104.

[0026] Step S101: Obtain the applicant's authorization request and at least one first authorization, the authorization request including a second authorization, the second authorization being the authorization requested by the applicant and the first authorization being the authorization granted to the applicant.

[0027] In one possible embodiment, the applicant's authorization request may be, but is not specifically limited, an authorization addition or authorization modification.

[0028] Step S102: Obtain the authorization risk dictionary, which contains conflict risk relationships between multiple authorizations.

[0029] In one possible embodiment, the conflict risk relationship between each authority includes both conflicting and non-conflicting relationships. For example, if both cashier and accounting authority are granted to the same applicant simultaneously, a financial fraud risk arises, and in this case, the conflict risk relationship between cashier and accounting authority is a conflicting relationship.

[0030] In one possible embodiment, authorization may be determined by business operations corresponding to multiple business activities. Different authorizations correspond to business operations in different business activities.

[0031] In one possible embodiment, there is a conflict of responsibility in business operations across different business activities, and correspondingly, there is a risk of conflict of responsibility in the authorities corresponding to business operations across different business activities. Therefore, the conflict risk relationship between each authority may be determined by whether or not there is a conflict of responsibility in the business operations corresponding to each authority.

[0032] In one possible embodiment, the authority risk dictionary may be represented by a responsibility conflict risk matrix, where the values ​​in the responsibility conflict risk matrix represent the conflict risk relationships between each authority.

[0033] Step S103: Determine whether there is a conflict risk in the authorization application, according to each first authorization, second authorization, and conflict risk relationship in the authorization risk dictionary, and obtain the risk assessment result for the authorization application.

[0034] In one selectable embodiment, the risk assessment result includes whether the authorization application has a conflict risk and whether the authorization application does not have a conflict risk.

[0035] In one possible embodiment, if there is any first authority that has a risk of conflict with the second authority, it is determined that the authority application has a risk of conflict.

[0036] In one possible embodiment, if there is no risk of conflict between the second authority and each of the first authorities, it is determined that there is no risk of conflict in the authority application.

[0037] Step S104: Process authorization requests based on the risk assessment results.

[0038] In one selectable embodiment, the authorization application may be processed in accordance with the risk assessment result, including approving the authorization application and rejecting the authorization application.

[0039] Considering the conflict risk relationships between multiple authority levels, if two conflicting authority levels are granted to the same applicant, a conflict of responsibility risk arises, which can further lead to operational and financial risks for the company. By using the method described above, in the process of an applicant requesting authority, it is possible to determine whether there is a conflict risk in the authority request, in addition to the conflict risk relationship between the authority level granted to the applicant and the requested authority level. By processing the authority request according to the risk assessment result, phenomena such as excessive authority leveling, incorrect authority leveling, and incompatible responsibilities can be prevented, operational and financial risks arising from authority management can be avoided in a timely manner, fraudulent operations can be effectively reduced instead of retroactive avoidance or risk burdening, risk compliance issues can be better managed and addressed, and the stability, sustainability, and compliance of business operations can be improved.

[0040] In one example, in step S102 above, the authority risk dictionary is obtained by the following method.

[0041] First, acquire at least one business activity.

[0042] In one possible embodiment, business activities may be divided by function or by process. If divided by function, business activities include, but are not specifically limited to, operational activities, marketing activities, and financial activities.

[0043] Next, the operational procedures for each business activity are determined according to that activity.

[0044] In one selectable example, different business operations correspond to different business activities. For example, business operations in financial activities include reporting and tax management, while business operations in marketing activities include customer service management.

[0045] Next, multiple permissions are determined according to each business operation.

[0046] In one selectable example, different business operations correspond to different permissions.

[0047] Finally, the conflict risk relationships between each authority are obtained according to pre-configured rules.

[0048] In one possible embodiment, the pre-configured rules may be set according to the specific circumstances. For example, there may be a risk of conflict between the authority to perform operations in financial activities and the authority to perform operations in other business activities, or between the authority to perform master data maintenance operations and the authority to perform operations in other business activities.

[0049] In the embodiments of this invention, each authority within the company is determined according to each business operation in each business activity, and the conflict risk relationships between each authority are determined by pre-set rules, thereby constructing an authority risk dictionary, identifying incompatible job responsibilities, and providing a basis for controlling authority management.

[0050] In one example, in step S103 above, the following method is used to determine whether or not there is a risk of conflict in the authorization request and to obtain the risk assessment result for the authorization request.

[0051] Based on the conflict risk relationships in the authority risk dictionary, it is determined whether there is a conflict risk between each first authority and second authority. If there is at least one first authority with which a conflict risk exists with a second authority, it is determined that there is a conflict risk in the authority request.

[0052] In one example, step S103 above processes the authorization request using the following steps.

[0053] Step a1: Determine the first processing result based on the risk assessment result.

[0054] In one selectable embodiment, the first processing result includes allowing the authorization request to pass and not allowing the authorization request to pass.

[0055] In one possible embodiment, if it is determined that there is a risk of conflict between the second authority and at least one of the first authorities, the first processing result is to decide not to approve the authority application, that is, the second authority is not granted to the applicant.

[0056] Step a2: Obtain the second processing result.

[0057] In one selectable embodiment, the second processing result similarly includes allowing the authorization request to pass and not allowing the authorization request to pass.

[0058] In one selectable embodiment, the second processing result is obtained by the following method.

[0059] First, obtain the applicant's job information.

[0060] Next, the second processing result is determined based on the job information and authority request.

[0061] In the embodiment of this application, along with the applicant's job information, it is determined whether the authorization request matches the job information, ensuring the suitability of the applicant's job information and the authorization, avoiding the granting of authorizations that do not match the job information, ensuring compliance with authorization risk management, and further reducing the potential risks associated with the granting of authorizations.

[0062] Step a3: Determine the third processing result based on the first and second processing results. For example, if both the first and second processing results result in the approval of the authorization application, the third processing result may be determined to be the approval of the authorization application.

[0063] Step a4: Process the authorization request according to the result of the third processing.

[0064] In the embodiment of this application, the first processing result is determined in conjunction with whether or not there is a risk conflict between the second authority and the first authority that has already been granted, and the second processing result is determined in conjunction with whether or not the second authority matches the applicant's job information, and the first and second processing results are combined to finally form the third processing result. The obtained third processing result not only avoids the possibility of a conflict risk but also satisfies the risk compliance requirements in conjunction with the applicant's job information.

[0065] For example, the method according to the embodiment of the present application is The process further includes the step of generating a risk management report based on the results of the first and second processing steps.

[0066] In the embodiments of this invention, the risk management report is incorporated into the risk compensation control process, providing a basis for subsequent risk compliance assessments and risk investigations, reducing the error rate of the risk management compliance system, and achieving organic linkage between the risk management control and oversight systems.

[0067] Figure 2 is a schematic diagram of the structure of a risk compliance-based access control system according to one exemplary embodiment. The system includes an access risk dictionary 1 and an access control platform 2.

[0068] The authority risk dictionary 1 is used to obtain conflict risk relationships between multiple authority levels.

[0069] The authorization management platform 2 is used to obtain an applicant's authorization request and at least one first authorization, where the authorization request includes a second authorization, the second authorization being the authorization requested by the applicant and the first authorization being the authorization granted to the applicant; to determine whether there is a conflict risk in the authorization request according to each first authorization, second authorization, and conflict risk relationship in the authorization risk dictionary 1, to obtain a risk assessment result for the authorization request, and to process the authorization request according to the risk assessment result.

[0070] Considering the conflict risk relationships between multiple authority levels, if two conflicting authority levels are granted to the same applicant, a conflict of responsibility risk arises, which can further lead to operational and financial risks for the company. The system described above, in the process of an applicant requesting authority, determines whether there is a conflict risk in the authority request, in addition to the conflict risk relationship between the authority level granted to the applicant and the requested authority level. By processing the authority request according to the risk assessment result, it prevents phenomena such as excessive authority granting, incorrect authority granting, and incompatible responsibilities, thereby avoiding operational and financial risks arising from authority management in a timely manner, effectively reducing fraudulent operations instead of retroactive avoidance or risk burdening, better managing and responding to risk compliance issues, and improving the stability, sustainability, and compliance of business operations.

[0071] In one example, the system further includes a privilege data dictionary. The privilege data dictionary is used to store privilege data corresponding to each privilege.

[0072] In one possible implementation, the authorization data includes a list of business operations (transaction codes) and specific business data that is exposed by the authorization.

[0073] In one possible embodiment, the authorization data dictionary can establish a unified authorization technical standard (authority naming specification, authorization representation structure, etc.) according to the business operations corresponding to each authorization, enable the management of each authorization itself, avoid the gradual confusion of authorization data, reduce the pressure of authorization operation and maintenance, and improve the identifiability and maintainability of authorizations.

[0074] In one example, the system further includes a data encryption and decryption device. The data encryption and decryption device is used to encrypt and decrypt data transmitted in the system and to improve data security in the system.

[0075] Figure 3 is an overall framework diagram illustrating the application of a risk compliance-based access control system. The risk compliance-based access control system includes an access risk dictionary 1, an access control platform 2, and an access data dictionary. The access control maintenance group establishes the access risk dictionary 1 and the access data dictionary, thereby constructing the access control platform 2. The risk compliance-based access control system manages on-premises and public cloud systems and enables the creation of access self-service functionality available to users at headquarters and regional companies. In the application process of the risk compliance-based access control system, risk compliance management and control are achieved through the access control process and the access granting management process.

[0076] Figure 4 is a schematic diagram of the authorization data dictionary. The authorization data dictionary contains authorization data corresponding to the authorizations of multiple applicants.

[0077] Figure 5 is a framework diagram of the authorization management process and authorization granting management process. The authorization management process domain includes the management of each authorization and its authorization data, which are role management processes. The authorization granting management process domain includes the authorization addition request process, authorization change request process, risk compensation control process, broad authorization request process, account addition request process, account freeze request process, and account freeze unfreezing request process. The broad authorization request process refers to the request process for broad authorizations. Broad authorizations are system-level authorizations that can have a significant impact on the system, such as the authorization to delete the system's base table or the authorization to change critical global configurations of the system.

[0078] Figure 6 is a schematic diagram of a scenario in a risk compliance-based authorization management system where data is encrypted. In a risk compliance-based authorization management system, the SAP UI Data Protection Masking for SAP S / 4 HANA suite is used to encrypt and display user access to sensitive data in the system. The SAP UI Data Protection Masking for SAP S / 4 HANA suite includes a rule engine domain configurator and processor. The rule engine domain configurator and processor hide specific data (fields / columns), prevent the leakage of sensitive data, hide sensitive values ​​by default, require explicit authorization for access, and also require authorization to examine administrative accounts in the system.

[0079] Figure 7 is a schematic diagram of the hardware structure of a computer device according to one exemplary embodiment. As shown in Figure 7, the device includes one or more processors 710 and memory 720, the memory 720 including persistent memory, volatile memory and hard disk, and in Figure 7, one processor 710 is used as an example. The device may further include an input device 730 and an output device 740.

[0080] The processor 710, memory 720, input device 730, and output device 740 may be connected by a bus or by other means; Figure 7 shows a bus connection as an example.

[0081] The processor 710 may be a Central Processing Unit (CPU). The processor 710 may be other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, or a combination of the above chips. The general-purpose processor may be a microprocessor, or the processor may be any conventional processor.

[0082] Memory 720 includes persistent memory, volatile memory, and a hard disk as a non-temporary computer-readable storage medium and can be used to store non-temporary software programs, non-temporary computer executable programs, and modules such as program instructions / modules corresponding to the risk compliance-based access control method in the embodiments of this application. The processor 710 executes various functional applications and data processing of the server by executing the non-temporary software programs, instructions, and modules stored in memory 720, thereby realizing one of the above risk compliance-based access control methods.

[0083] The memory 720 may include a program storage area capable of storing an operating system and application programs required for at least one function, and a data storage area capable of storing data used as needed. The memory 720 may also include high-speed random-access memory and may further include non-temporary memory such as at least one disk storage device, flash memory device, or other non-temporary solid-state storage device. In some embodiments, the memory 720 may optionally include memory remotely installed relative to the processor 710, and these remote memories may be connected to a data processing device via a network. Examples of such networks include, but are not limited to, the Internet, intranets, local area networks, mobile communication networks, and combinations thereof.

[0084] The input device 730 can receive input numerical or character information and generate signal inputs related to user settings and function control. The output device 740 may include a display device such as a display.

[0085] One or more modules are stored in memory 720 and, when executed by one or more processors 710, perform the method shown in Figure 1.

[0086] The above-described product is capable of performing the method according to the embodiment of this application and has a corresponding functional module for performing the method and beneficial effects. For technical details not described in detail in this embodiment, refer specifically to the relevant description of the embodiment shown in Figure 1.

[0087] Embodiments of the present invention further provide a non-temporary computer storage medium in which computer executable instructions are stored, and which can execute the method in any one of the above embodiments of the method. The storage medium may be a magnetic disk, an optical disk, a read-only memory (ROM), a random access memory (RAM), a flash memory, a hard disk drive (HDD), or a solid-state drive (SSD), and the storage medium may include a combination of the above types of memory.

[0088] In this specification, relational terms such as “first” and “second” are used solely to distinguish one entity or operation from another, and do not necessarily require or imply that there is an actual relationship or order between these entities or operations. Furthermore, in this specification, the terms “include,” “incorporate,” or any other variation thereof are intended to cover non-exclusive inclusion, thereby including not only those elements but also other elements not explicitly enumerated, or elements specific to this process, method, article, or equipment. Unless otherwise specified, an element limited by the phrase “includes one…” does not preclude the presence of another identical element in a process, method, article, or equipment that includes the element.

[0089] The above are merely specific embodiments of the Application that enable those skilled in the art to understand or implement the Application. Various modifications of these embodiments will be obvious to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the Application. Accordingly, the Application is not limited to these embodiments shown herein, but will conform to the broadest scope that is consistent with the principles and novelty features filed herein.

Claims

1. A risk compliance-based access control method, which is performed by an access control system including an access risk dictionary and an access control platform, The authority management platform takes the steps of obtaining an applicant's authority request and at least one first authority, wherein the authority request includes a second authority, the second authority is an authority requested by the applicant, and the first authority is an authority granted to the applicant. The access control platform includes the steps of obtaining conflict risk relationships between multiple accesses from the access risk dictionary, The access control platform determines whether there is a conflict risk in the access request according to each of the first access, the second access, and the conflict risk relationships in the access risk dictionary, and obtains a risk determination result for the access request. The access control platform includes the step of processing the access request in accordance with the risk assessment result, The steps by which the authorization management platform processes the authorization request in accordance with the risk assessment result are: The access control platform determines a first processing result according to the risk assessment result, The access control platform takes the step of obtaining the second processing result, The access control platform includes the step of determining a third processing result according to the first processing result and the second processing result, A risk compliance-based authorization management method characterized in that the authorization management platform includes the step of processing the authorization request in accordance with the third processing result.

2. The steps of the authority management platform obtaining conflict risk relationships between multiple authorities from the authority risk dictionary include: The access control platform includes the step of acquiring at least one business activity, The access control platform includes the steps of determining the business operations in each business activity according to each business activity, The access control platform includes the step of determining multiple permissions according to each of the aforementioned business operations, The method according to claim 1, characterized in that the access control platform includes the step of acquiring a conflict risk relationship between each of the accesses according to a pre-configured rule.

3. The steps of the authorization management platform determining whether there is a conflict risk in the authorization application according to each of the first authorizations, the second authorizations, and the conflict risk relationships in the authorization risk dictionary, and obtaining a risk determination result for the authorization application, are: The authority management platform includes the step of determining whether there is a conflict risk between each of the first authority and the second authority, according to each of the conflict risk relationships in the authority risk dictionary, The method according to claim 1, characterized in that the authority management platform determines that there is a conflict risk in the authority request if there is at least one first authority that has a conflict risk with the second authority.

4. The steps of the authorization management platform obtaining the second processing result are: The access control platform includes the step of obtaining the applicant's job information, The method according to claim 1, characterized in that the authority management platform includes the step of determining the second processing result in accordance with the job information and the authority request.

5. The method according to claim 1, further comprising the step of the authorization management platform generating a risk management report in accordance with the first processing result and the second processing result.

6. A risk compliance-based access control system, comprising an access risk dictionary and an access control platform, The aforementioned authority risk dictionary is used to obtain conflict risk relationships between multiple authority levels. The authority management platform is used to obtain an applicant's authority request and at least one first authority, wherein the authority request includes a second authority, the second authority is an authority requested by the applicant, and the first authority is an authority granted to the applicant; to determine whether there is a conflict risk in the authority request according to each of the first authority, the second authority, and each of the conflict risk relationships in the authority risk dictionary, to obtain a risk determination result for the authority request, and to process the authority request according to the risk determination result. The access control platform is used to determine a first processing result according to the risk assessment result, to obtain a second processing result, to determine a third processing result according to the first and second processing results, and to process the access request according to the third processing result, thereby providing a risk compliance-based access control system.

7. The system according to claim 6, further comprising a privilege data dictionary for storing privilege data corresponding to each of the aforementioned privileges.

8. A computer device comprising memory and a processor, wherein the memory and the processor are connected to each other in communication, computer instructions are stored in the memory, and the processor executes the steps of the risk compliance-based access control method described in any one of claims 1 to 5 by executing the computer instructions.

9. A computer-readable storage medium in which a computer program is stored, characterized in that when the computer program is executed by a processor, the steps of the risk compliance-based access control method described in any one of claims 1 to 5 are realized.

Citation Information

Patent Citations

  • Permission application examination and approval method and authorization management platform

    CN107679749A

  • Business system authority management method and device, electronic equipment and storage medium

    CN112529524A

  • Authority management method and device

    CN118071266A

  • Access rights management in enterprise digital rights management systems

    US20130036475A1