Risk compliance-based permission management method and system, computer device, and medium

By introducing a risk-compliance-based authority management method in enterprise authority management, combining the conflict risk relationship in the authority risk dictionary, and judging and processing authority applications, the business and financial risks caused by authority management in enterprise risk control are solved, and higher risk compliance management capabilities and business stability are achieved.

WO2025102701A1PCT designated stage expired Publication Date: 2025-05-22CHINA THREE GORGES INT CORP
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/098590
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-11-16
Filing Date
2024-06-12
Publication Date
2025-05-22

AI Technical Summary

Technical Problem

In risk control, enterprises often lead to business and financial risks due to problems such as excessive authorization, misauthorization and incompatible responsibilities. It is difficult for existing technology to effectively solve the compliance problems in authority management.

Method used

A permission management method based on risk compliance is proposed. By obtaining the applicant's permission application and the permissions that have been granted, combining the conflict risk relationship in the permission risk dictionary, we can judge whether there is a conflict risk in the permission application, and process the permission application based on the risk judgment results to prevent excessive authorization and misauthorization.

Benefits of technology

It effectively reduces business risks and financial risks caused by authority management, improves the risk compliance management capabilities of the enterprise, and enhances the stability, sustainability and compliance of business operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024098590_22052025_PF_FP_ABST
    Figure CN2024098590_22052025_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of computers, and provides a risk compliance-based permission management method and system, a computer device, and a medium. The risk compliance-based permission management method comprises: acquiring a permission application of an applicant and at least one first permission, wherein the permission application comprises a second permission, the second permission is a permission requested by the applicant, and the first permission is a permission that has been granted to the applicant; acquiring a permission risk dictionary, wherein the permission risk dictionary comprises conflict risk relationships between a plurality of permissions; on the basis of each first permission, the second permission, and each conflict risk relationship in the permission risk dictionary, determining whether there is a conflict risk in the permission application to obtain a risk determination result of the permission application; and processing the permission application on the basis of the risk determination result. The present application prevents the phenomena such as excessive authorization, misauthorization, and incompatible responsibilities, avoids in a timely manner the occurrence of service risks and financial risks caused by permission management, and meets risk compliance control requirements.
Need to check novelty before this filing date? Find Prior Art

Description

Risk-compliant authority management methods, systems, computer equipment, and media Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a risk compliance-based permission management method, system, computer device, and medium. Background Art

[0002] In recent years, enterprises have increasingly emphasized the importance of risk management and internal risk control compliance. Requirements for risk management, such as "accelerating the development of risk management systems," have gradually been put forward, emphasizing the need for information-based, digital, and intelligent risk management. In enterprise risk management, issues such as over-authorization, mis-authorization, and incompatible responsibilities often lead to business and financial risks. Therefore, addressing enterprise authority management issues and meeting risk compliance requirements has become increasingly urgent.

[0003] Summary of the Invention

[0004] In order to meet the risk compliance control requirements and realize permission management, this application proposes a permission management method, system, computer equipment and medium based on risk compliance.

[0005] In a first aspect, this application provides a method for rights management based on risk compliance, the method comprising:

[0006] Obtaining an applicant's permission application and at least one first permission, where the permission application includes a second permission, where the second permission is the permission requested by the applicant and the first permission is the permission that has been granted to the applicant;

[0007] Obtain the permission risk dictionary, which includes the conflict risk relationships between multiple permissions;

[0008] According to each first permission, second permission, and each conflict risk relationship in the permission risk dictionary, determine whether there is a conflict risk in the permission application, and obtain a risk determination result of the permission application;

[0009] Process permission applications based on risk assessment results.

[0010] Taking into account the conflict risk relationship between multiple permissions, if two permissions with conflict risk are granted to the same applicant, there will be a risk of conflict of responsibilities, which will in turn lead to business risks and financial risks for the enterprise. Through the above method, in the process of the applicant requesting permission, combined with the conflict risk relationship between the applicant's already granted permissions and the requested permissions, it is judged whether there is a conflict risk in the permission application. According to the risk judgment result, the permission application is processed to prevent excessive authorization, wrong authorization, incompatible duties and other phenomena, and promptly avoid the occurrence of business risks and financial risks caused by permission management, effectively reducing illegal operations, rather than avoiding or assuming risks afterwards, which can better manage and respond to risk compliance issues and improve the stability, sustainability and compliance of business operations.

[0011] In an optional implementation, the step of obtaining the permission risk dictionary includes:

[0012] Get at least one business activity;

[0013] Determine the business operations in each business activity based on each business activity;

[0014] Determine multiple permissions based on each business operation;

[0015] According to preset rules, the conflict risk relationship between each permission is obtained.

[0016] Through the above implementation method, the various permissions in the enterprise are determined according to the business operations in each business activity, and the conflict risk relationship between the permissions is determined through preset rules, so as to construct a permission risk dictionary, identify incompatible job responsibilities, and provide a basis for controlling permission management.

[0017] In an optional implementation, judging whether a permission application has a conflict risk based on each first permission, the second permission, and each conflict risk relationship in the permission risk dictionary, and obtaining a risk judgment result of the permission application includes:

[0018] Determine whether there is a conflict risk between each first permission and each second permission based on each conflict risk relationship in the permission risk dictionary;

[0019] When there is a risk of conflict between at least one first permission and a second permission, it is determined that the permission application has a risk of conflict.

[0020] In an optional implementation, processing the permission application based on the risk assessment result includes:

[0021] Determine the first processing result based on the risk assessment result;

[0022] Obtaining a second processing result;

[0023] Determine a third processing result based on the first processing result and the second processing result;

[0024] Process the permission application based on the third processing result.

[0025] In an optional implementation, obtaining the second processing result includes:

[0026] Obtain applicants' job information;

[0027] Determine the second processing result based on job information and authority application.

[0028] Through the above implementation method, combined with the applicant's job information, it is determined whether the permission application matches the job information, ensuring the adaptability of the applicant's job information and permissions, avoiding the authorization of permissions that do not match the job information, ensuring the compliance of permission risk control, and further reducing the possibility of risks caused by authorization.

[0029] In an optional embodiment, the method further includes:

[0030] A risk control report is generated according to the first processing result and the second processing result.

[0031] Through the above implementation, a risk control report is generated by combining the first processing result and the second processing result, and the risk control report is incorporated into the risk compensation control process to provide a basis for subsequent risk compliance evaluation and risk investigation.

[0032] In a second aspect, the present application also provides a permission management system based on risk compliance, the system comprising: a permission risk dictionary and a permission management platform;

[0033] Permission risk dictionary, used to obtain the conflict risk relationship between multiple permissions;

[0034] The permission management platform is used to obtain the applicant's permission application and at least one first permission, where the permission application includes a second permission, the second permission is the permission requested by the applicant, and the first permission is the permission that the applicant has been granted; based on the first permissions, second permissions, and the conflict risk relationships in the permission risk dictionary, it is judged whether there is a conflict risk in the permission application and a risk judgment result of the permission application is obtained; based on the risk judgment result, the permission application is processed.

[0035] Taking into account the conflict risk relationship between multiple permissions, if two permissions with conflict risk are granted to the same applicant, there will be a risk of conflict of responsibilities, which will in turn lead to business and financial risks for the enterprise. Through the above system, in the process of the applicant requesting permission, combined with the conflict risk relationship between the applicant's already granted permissions and the requested permissions, it is judged whether there is a conflict risk in the permission application. According to the risk judgment results, the permission application is processed to prevent excessive authorization, misauthorization, incompatible responsibilities, etc., and promptly avoid the occurrence of business risks and financial risks caused by permission management, effectively reducing illegal operations, rather than avoiding or assuming risks afterwards, which can better manage and respond to risk compliance issues and improve the stability, sustainability and compliance of business operations.

[0036] In an optional embodiment, the system further includes a permissions data dictionary;

[0037] The permission data dictionary is used to store the permission data corresponding to each permission.

[0038] Through the above implementation, the permission data dictionary is used to manage the permission data corresponding to each permission.

[0039] In a third aspect, the present application also provides a computer device comprising a memory and a processor, the memory and the processor being communicatively connected to each other, computer instructions being stored in the memory, and the processor executing the steps of the risk compliance-based permission management method of the first aspect or any embodiment of the first aspect by executing the computer instructions.

[0040] In a fourth aspect, the present application also provides a computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, the steps of the risk-compliance-based permission management method of the first aspect or any embodiment of the first aspect are implemented. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] In order to more clearly illustrate the specific implementation methods of the present application or the technical solutions in the prior art, the following is a brief introduction to the drawings required for use in the specific implementation methods or the description of the prior art. Obviously, the drawings described below are some implementation methods of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0042] FIG1 is a flowchart of a method for risk compliance-based rights management according to an exemplary embodiment;

[0043] FIG2 is a schematic structural diagram of a risk compliance-based rights management system according to an exemplary embodiment;

[0044] FIG3 is a general framework diagram of a risk compliance-based rights management system application in an example;

[0045] FIG4 is a schematic diagram of a permission data dictionary in an example;

[0046] FIG5 is a framework diagram of a rights management process and an authorization management process in an example;

[0047] FIG6 is a schematic diagram of a scenario in which data in a risk-compliance-based rights management system is encrypted in an example;

[0048] FIG7 is a schematic diagram of a hardware structure of a computer device according to an exemplary embodiment. DETAILED DESCRIPTION

[0049] The following will clearly and completely describe the technical solution of this application in conjunction with the accompanying drawings. Obviously, the embodiments described are only part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making any creative efforts are within the scope of protection of this application.

[0050] In addition, the technical features involved in the different embodiments of the present application described below can be combined with each other as long as they do not conflict with each other.

[0051] In order to meet the risk compliance control requirements and realize permission management, this application proposes a permission management method, system, computer equipment and medium based on risk compliance.

[0052] Figure 1 is a flow chart of a risk compliance-based rights management method according to an exemplary embodiment. As shown in Figure 1 , the risk compliance-based rights management method includes the following steps S101 to S104.

[0053] Step S101: Obtaining the applicant's permission application and at least one first permission, where the permission application includes a second permission, the second permission being the permission requested by the applicant, and the first permission being the permission already granted to the applicant.

[0054] In an optional embodiment, the applicant's permission application may be for adding permissions, changing permissions, etc., which is not specifically limited here.

[0055] Step S102: Obtain a permission risk dictionary, where the permission risk dictionary includes conflict risk relationships between multiple permissions.

[0056] In an optional embodiment, the conflict risk relationship between permissions includes conflict relationships and non-conflict relationships. For example, if the cashier position permission and the accounting position permission are granted to the same applicant at the same time, it will generate financial fraud risk. In this case, the conflict risk relationship between the cashier position permission and the accounting position permission is a conflict relationship.

[0057] In an optional embodiment, the authority may be determined by business operations corresponding to multiple business activities, and different authorities may correspond to business operations under different business activities.

[0058] In an optional embodiment, business operations under different business activities may have responsibility conflicts. Accordingly, the permissions corresponding to the business operations under different business activities may also have responsibility conflict risks. Therefore, the conflict risk relationship between the permissions can be determined by whether the business operations corresponding to the permissions have responsibility conflicts.

[0059] In an optional embodiment, the authority risk dictionary may be represented by a responsibility conflict risk matrix, and the values ​​in the responsibility conflict risk matrix represent the conflict risk relationships between the various authorities.

[0060] Step S103: judging whether there is a conflict risk in the permission application based on the first permissions, the second permissions, and the conflict risk relationships in the permission risk dictionary, and obtaining a risk judgment result of the permission application.

[0061] In an optional embodiment, the risk judgment result includes whether the permission application has a conflict risk or whether the permission application does not have a conflict risk.

[0062] In an optional embodiment, when there is a risk of conflict between any one of the first permission and the second permission, it is determined that the permission application has a risk of conflict.

[0063] In an optional embodiment, when there is no conflict risk between the second permission and each first permission, it is determined that there is no conflict risk for the permission application.

[0064] Step S104: Process the permission application based on the risk assessment result.

[0065] In an optional embodiment, the permission application may be processed based on the risk assessment result, including approving the permission application or rejecting the permission application.

[0066] Taking into account the conflict risk relationship between multiple permissions, if two permissions with conflict risk are granted to the same applicant, there will be a risk of conflict of responsibilities, which will in turn lead to business risks and financial risks for the enterprise. Through the above method, in the process of the applicant requesting permission, combined with the conflict risk relationship between the applicant's already granted permissions and the requested permissions, it is judged whether there is a conflict risk in the permission application. According to the risk judgment result, the permission application is processed to prevent excessive authorization, wrong authorization, incompatible duties and other phenomena, and promptly avoid the occurrence of business risks and financial risks caused by permission management, effectively reducing illegal operations, rather than avoiding or assuming risks afterwards, which can better manage and respond to risk compliance issues and improve the stability, sustainability and compliance of business operations.

[0067] In one example, in step S102 above, the permission risk dictionary is obtained in the following manner:

[0068] First, obtain at least one business activity.

[0069] In an optional embodiment, business activities can be divided according to function or process. According to function, business activities include operation activities, marketing activities, financial activities, etc., which are not specifically limited here.

[0070] Secondly, based on each business activity, determine the business operations in each business activity.

[0071] In an optional embodiment, different business activities correspond to different business operations. For example, business operations in financial activities include report operations, tax management, etc., and business operations in marketing activities include customer service management, etc.

[0072] Again, multiple permissions are determined based on each business operation.

[0073] In an optional embodiment, different business operations correspond to different permissions.

[0074] Finally, according to the preset rules, the conflict risk relationship between each permission is obtained.

[0075] In an optional embodiment, the preset rules can be set based on specific circumstances. For example, there is a risk of conflict between the permissions corresponding to business operations of financial activities and the permissions corresponding to business operations of other business activities, or there is a risk of conflict between the permissions corresponding to master data maintenance operations and the permissions corresponding to business operations of other business activities, etc.

[0076] In an embodiment of the present application, the various permissions in the enterprise are determined based on the various business operations in each business activity, and the conflict risk relationship between the various permissions is determined through preset rules, so as to construct a permission risk dictionary, identify incompatible job responsibilities, and provide a basis for controlling permission management.

[0077] In one example, in the above step S103, whether there is a conflict risk in the permission application is determined by the following method to obtain a risk determination result of the permission application:

[0078] According to the conflict risk relationships in the permission risk dictionary, determine whether there is a conflict risk between each first permission and the second permission; when there is a conflict risk between at least one first permission and the second permission, determine that there is a conflict risk in the permission application.

[0079] In one example, in step S103 above, the permission request is processed through the following steps:

[0080] Step a1: Determine the first processing result based on the risk judgment result.

[0081] In an optional embodiment, the first processing result includes approving the permission application or rejecting the permission application.

[0082] In an optional embodiment, when it is determined that there is a risk of conflict between the second permission and at least one first permission, the first processing result is determined as not passing the permission application, that is, the second permission will not be granted to the applicant.

[0083] Step a2: Obtain the second processing result.

[0084] In an optional embodiment, the second processing result also includes approving the permission application or rejecting the permission application.

[0085] In an optional embodiment, the second processing result is obtained in the following manner:

[0086] First, obtain the applicant's job information.

[0087] Then, the second processing result is determined based on the position information and permission application.

[0088] In the embodiment of the present application, combined with the applicant's job information, it is determined whether the permission application matches the job information, ensuring the compatibility of the applicant's job information and permissions, avoiding the authorization of permissions that do not match the job information, ensuring the compliance of permission risk control, and further reducing the possibility of risks caused by authorization.

[0089] Step a3: Determine a third processing result based on the first processing result and the second processing result. For example, when both the first processing result and the second processing result are approval of the permission application, the third processing result may be determined as approval of the permission application.

[0090] Step a4: Process the permission application based on the third processing result.

[0091] In this embodiment of the present application, the first processing result is determined by considering whether the second permission conflicts with the authorized first permission. The second processing result is determined by considering whether the second permission matches the applicant's position information. The first and second processing results are combined to form a third processing result. This third processing result avoids the possibility of conflict risk while also incorporating the applicant's position information, meeting risk compliance requirements.

[0092] In one example, the method provided in the embodiments of the present application further includes:

[0093] A risk control report is generated according to the first processing result and the second processing result.

[0094] In the embodiment of the present application, the risk control report is incorporated into the risk compensation control process to provide a basis for subsequent risk compliance evaluation and risk investigation, reduce the error rate of the risk control compliance system, and achieve organic linkage between risk control management and supervision systems.

[0095] FIG2 is a schematic diagram of a structure of a rights management system based on risk compliance according to an exemplary embodiment. The system includes: a rights risk dictionary 1 and a rights management platform 2.

[0096] The permission risk dictionary 1 is used to obtain the conflict risk relationship between multiple permissions.

[0097] The permission management platform 2 is used to obtain the applicant's permission application and at least one first permission, where the permission application includes a second permission, the second permission is the permission requested by the applicant, and the first permission is the permission that the applicant has been granted; based on the first permissions, the second permissions, and the conflict risk relationships in the permission risk dictionary 1, it is judged whether there is a conflict risk in the permission application, and a risk judgment result of the permission application is obtained; based on the risk judgment result, the permission application is processed.

[0098] Taking into account the conflict risk relationship between multiple permissions, if two permissions with conflict risk are granted to the same applicant, there will be a risk of conflict of responsibilities, which will in turn lead to business and financial risks for the enterprise. Through the above system, in the process of the applicant requesting permission, combined with the conflict risk relationship between the applicant's already granted permissions and the requested permissions, it is judged whether there is a conflict risk in the permission application. According to the risk judgment results, the permission application is processed to prevent excessive authorization, misauthorization, incompatible responsibilities, etc., and promptly avoid the occurrence of business risks and financial risks caused by permission management, effectively reducing illegal operations, rather than avoiding or assuming risks afterwards, which can better manage and respond to risk compliance issues and improve the stability, sustainability and compliance of business operations.

[0099] In one example, the system further includes a permission data dictionary, which is used to store permission data corresponding to each permission.

[0100] In an optional embodiment, the authority data includes a business operation list (transaction code), specific business data opened by the authority, and the like.

[0101] In an optional embodiment, in the permission data dictionary, a unified permission technical standard (such as permission naming specifications, permission embodiment structure, etc.) can be formulated according to the business operations corresponding to each permission, so as to manage each permission itself, avoid the increasing confusion of permission data, reduce the pressure of permission operation and maintenance, and improve the identifiability and maintainability of permissions.

[0102] In one example, the system further includes a data encryption and decryption device, which is used to encrypt and decrypt data transmitted in the system to improve the security of the data in the system.

[0103] Figure 3 illustrates the overall framework for the application of a risk-compliant permissions management system. This system includes a permissions risk dictionary 1, a permissions management platform 2, and a permissions data dictionary. The permissions management maintenance team establishes permissions risk dictionary 1 and permissions data dictionary, thereby building permissions management platform 2. This risk-compliant permissions management system manages both on-premises and public cloud systems, enabling the development of self-service permissions functionality for headquarters and regional users. During the application of this risk-compliant permissions management system, risk compliance management is achieved through permissions management and authorization management processes.

[0104] Figure 4 is a schematic diagram of a permission data dictionary, which includes permission data corresponding to the permissions of multiple applicants.

[0105] Figure 5 is a framework diagram of the permissions management process and the authorization management process. The permissions management process domain includes the role management process, which manages each permission and its data. The authorization management process domain includes the permission addition application process, permission change application process, risk compensation control process, major permission application process, account addition application process, account freeze application process, and account thawing application process. The major permission application process refers to the application process for major permissions. Major permissions are system-level permissions that can significantly impact the system, such as permissions to delete system base tables and permissions to modify critical global system configurations.

[0106] Figure 6 illustrates a scenario for encrypting data in a risk-based, compliance-based rights management system. In this risk-based, compliance-based rights management system, the SAP UI Data Protection Masking for SAP S / 4 HANA suite is used to implement encrypted display of user access to sensitive system data. The SAP UI Data Protection Masking for SAP S / 4 HANA suite includes a rule engine domain configurator and processors. These domain configurators and processors help hide specific data (fields / columns) to prevent sensitive data leakage. Sensitive values ​​are masked by default, requiring explicit authorization for access. System administrators must also be assigned permissions to view data.

[0107] Figure 7 is a schematic diagram of the hardware structure of a computer device according to an exemplary embodiment. As shown in Figure 7 , the device includes one or more processors 710 and memory 720. Memory 720 includes persistent memory, volatile memory, and a hard disk. Figure 7 uses one processor 710 as an example. The device may also include an input device 730 and an output device 740.

[0108] The processor 710 , the memory 720 , the input device 730 , and the output device 740 may be connected via a bus or other means. FIG. 7 takes the bus connection as an example.

[0109] The processor 710 may be a central processing unit (CPU). The processor 710 may also be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, or a combination of the above chips. The general-purpose processor may be a microprocessor or any conventional processor.

[0110] Memory 720, as a non-transitory computer-readable storage medium, includes persistent memory, volatile memory, and a hard disk, and can be used to store non-transitory software programs, non-transitory computer executable programs, and modules, such as the program instructions / modules corresponding to the risk-compliance-based permissions management method in the embodiments of the present application. Processor 710 executes the non-transitory software programs, instructions, and modules stored in memory 720 to execute various functional applications and data processing of the server, thereby implementing any of the risk-compliance-based permissions management methods described above.

[0111] The memory 720 may include a program storage area and a data storage area, wherein the program storage area may store an operating system, an application required for at least one function; the data storage area may store data used as needed, etc. In addition, the memory 720 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, or other non-volatile solid-state storage device. In some embodiments, the memory 720 may optionally include a memory remotely located relative to the processor 710, and these remote memories may be connected to the data processing device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0112] The input device 730 can receive input digital or character information and generate signal input related to user settings and function control. The output device 740 can include a display device such as a display screen.

[0113] One or more modules are stored in the memory 720 , and when executed by one or more processors 710 , the method shown in FIG. 1 is performed.

[0114] The above-mentioned product can execute the method provided in the embodiment of this application, and has the functional modules and beneficial effects corresponding to the execution method. For technical details not fully described in this embodiment, please refer to the relevant description in the embodiment shown in Figure 1.

[0115] The present application also provides a non-transitory computer storage medium, which stores computer-executable instructions that can execute the method in any of the above method embodiments. The storage medium can be a magnetic disk, an optical disk, a read-only memory (ROM), a random access memory (RAM), a flash memory, a hard disk drive (HDD), or a solid-state drive (SSD); the storage medium can also include a combination of the above types of memory.

[0116] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device that includes a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or device that includes the element.

[0117] The above are merely specific embodiments of the present application to enable those skilled in the art to understand or implement the present application. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to the embodiments shown herein, but rather is intended to conform to the widest scope consistent with the principles and novel features of the present application.

Claims

1. A permission management method based on risk compliance, characterized in that: The method comprises: Obtaining a permission application and at least one first permission from an applicant, wherein the permission application includes a second permission, the second permission is a permission requested by the applicant, and the first permission is a permission that has been granted to the applicant; Obtaining a permission risk dictionary, wherein the permission risk dictionary includes conflict risk relationships between multiple permissions; According to each of the first permissions, the second permissions, and each of the conflict risk relationships in the permission risk dictionary, determining whether the permission application has a conflict risk, and obtaining a risk determination result of the permission application; Process the permission application based on the risk assessment result.

2. The method according to claim 1, characterized in that The step of obtaining the permission risk dictionary includes: Get at least one business activity; According to each of the business activities, determining the business operations in each of the business activities; Determining multiple permissions based on each of the business operations; According to preset rules, the conflict risk relationship between the permissions is obtained.

3. The method according to claim 1, characterized in that Judging whether there is a conflict risk in the permission application according to each of the first permission, the second permission, and each of the conflict risk relationships in the permission risk dictionary, and obtaining a risk judgment result of the permission application, including: According to each of the conflict risk relationships in the permission risk dictionary, determining whether there is a conflict risk between each of the first permissions and the second permissions; When there is a risk of conflict between at least one first permission and the second permission, it is determined that the permission application has a risk of conflict.

4. The method according to claim 1, characterized in that: Processing the permission application according to the risk assessment result includes: Determine a first processing result according to the risk judgment result; Obtaining a second processing result; Determine a third processing result according to the first processing result and the second processing result; The permission application is processed according to the third processing result.

5. The method according to claim 4, characterized in that Obtaining the second processing result, including: Obtaining the job information of the applicant; The second processing result is determined according to the position information and the permission application.

6. The method according to claim 4, characterized in that The method further comprises: A risk control report is generated according to the first processing result and the second processing result.

7. A risk compliance-based rights management system, characterized in that: The system includes: a permission risk dictionary and a permission management platform; The permission risk dictionary is used to obtain the conflict risk relationship between multiple permissions; The permission management platform is used to obtain an applicant's permission application and at least one first permission, where the permission application includes a second permission, the second permission is the permission requested by the applicant, and the first permission is the permission that the applicant has been granted; based on each of the first permissions, the second permissions, and the conflict risk relationships in the permission risk dictionary, determine whether the permission application has a conflict risk, and obtain a risk judgment result for the permission application; and process the permission application based on the risk judgment result.

8. The system according to claim 7, characterized in that The system further comprises a permission data dictionary; the permission data dictionary is used to store the permission data corresponding to each of the permissions.

9. A computer device, characterized in that: It includes a memory and a processor, the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the steps of the risk compliance-based permission management method described in any one of claims 1 to 6 by executing the computer instructions.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the risk compliance-based rights management method as described in any one of claims 1 to 6 are implemented.

Citation Information

Patent Citations

  • Permission application examination and approval method and authorization management platform

    CN107679749A

  • Business system authority management method and device, electronic equipment and storage medium

    CN112529524A

  • Post authority risk judgment method and device based on business architecture

    CN116150720A

  • Risk compliance-based authority management method and system, computer equipment and medium

    CN117808486A

  • Access rights management in enterprise digital rights management systems

    US20130036475A1