Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

575 results about "User Privilege" patented technology

The operations and access levels which are allowed to a user (e.g Create, Read, Update, Delete).

Method for generating SQL (structured query language) from natural language based on bidirectional mapping and semantic analysis

The invention provides a method for generating an SQL (Structured Query Language) by a natural language based on bidirectional mapping and semantic parsing, which relates to the technical field of database query and comprises the following steps of: extracting natural language query elements and packaging the natural language query elements into structured data, and establishing a mapping relationship from a query field to a service attribute and a physical data table by adopting a bidirectional Hash index technology; and automatically identifying multi-table association keys, performing semantic extension and compliance verification, generating an abstract syntax tree, performing processing according to user permission, and finally converting the abstract syntax tree into an SQL statement conforming to a target database syntax specification. According to the method, the accuracy and the efficiency of converting the natural language into the SQL are improved, and the flexibility and the safety of the system are enhanced.
Owner:北京科杰科技有限公司

Large model-based unidirectional isolation network intelligent data analysis method and device, and medium

The invention provides a one-way isolation network intelligent data analysis method and device based on a large model and a medium, and belongs to the technical field of data processing and network security. Matching an accessible node area list according to a preset organization structure level; the system receives and analyzes the instruction to determine a query intention and an associated data range; the system converts a natural language query instruction into a cross-node SQL statement through a large model module, and verifies the legality of the SQL statement based on user permission; and the system unidirectionally transmits the encrypted SQL instruction to a target node area through a hardware optical shutter, triggers the node area to execute local statistical operation and returns a structured result. Dynamic data pulling in a one-way network environment is achieved through a hardware optical shutter and data pump technology, natural language query is converted into SQL in real time in combination with distributed query optimized by a large model, and the problems that data statistics is lagged and user operation intervention is needed in a traditional isolation network are solved.
Owner:INSPUR ZHUOSHU BIG DATA IND DEV CO LTD

Intelligent warehouse login verification method and system based on dynamic living body detection

The invention relates to the technical field of information security, provides an intelligent warehouse login verification method and system based on dynamic living body detection, and is used for realizing accurate generation of an identity label vector, enhanced authentication of a dynamic password and automatic matching of warehouse authority while accurately performing living body detection. And the security and convenience of warehousing system login are comprehensively improved. The method comprises the following steps: collecting real-time interaction action data of a warehousing system login user, calling a preset living body detection algorithm to carry out dynamic biological characteristic analysis on the real-time interaction action data, and generating a living body verification confidence coefficient and a user identity identification vector; performing dynamic password enhanced authentication according to the living body verification confidence coefficient and a preset security authentication threshold value, and generating a dynamic access token containing multiple layers of encryption identifiers; and based on the user identity identification vector and the dynamic access token, executing storage permission automatic matching processing, and outputting a login verification result associated with the user permission level to the storage system according to the permission matching label.
Owner:SHANDONG LUNENG SOFTWARE TECH

Sampling information management system for intelligent environment monitoring

The invention is suitable for the field of environment monitoring, and provides a sampling information management system for intelligent environment monitoring, which comprises a user authority management and control module for realizing multi-level authority management based on an RBAC (Role Based Access Control) model; the equipment full life cycle management module monitors the equipment state in real time through the Internet of Things and carries out early warning calibration; the standard dynamic adaptation module intelligently associates a standard with a sampling scene, and synchronously authorizes updating; the sampling closed-loop management module supports double-end cooperation, offline operation and block chain evidence storage; the data interaction and analysis module integrates the data and intelligently predicts the data; the auditing and tracing module records whole-process operation and gives an early warning for abnormity; and the multi-terminal collaborative interaction module is adapted to multiple systems. The monitoring efficiency and the data quality are improved, and support is provided for environmental protection decision making.
Owner:HEILONGJIANG LINGXIAO ENVIRONMENTAL MONITORING CO LTD

Multi-account safety management method and system based on mobile energy storage charging pile

The invention relates to a multi-account security management method and system based on a mobile energy storage charging pile. According to the method, a multi-level user account system and a dynamic authority management mechanism are established, a dynamic token carrying authority attributes is generated through encryption verification to achieve access control, user operation is captured in real time to generate log data with an identity label, the log data are synchronized with a cloud end, and an equipment control instruction is generated in combination with Internet of Things data collection and authority verification. Meanwhile, authority rules are dynamically updated, whole-course tracing of operation behaviors of the charging pile system, real-time effectiveness of authority change and linkage management and control of equipment states and user authorities are achieved, and the problem that potential safety hazards are caused by extensive authority control, difficult operation tracing and authority strategy lagging of a traditional charging pile management system is effectively solved.
Owner:ZHONGDE CENTURY (TIANJIN) NEW ENERGY TECHNOLOGY CO LTD +2

Electric vehicle interconnection, intercommunication and sharing charging operation method and device and storage medium

The invention relates to the field of new energy automobile power supply, and provides an electric automobile interconnection sharing charging operation method and device and a storage medium, the method comprises the following steps: realizing heterogeneous system interconnection of a multi-source charging platform and a supervision platform through a standardized interface protocol, and establishing a cross-platform data channel; a dynamic user authentication system is constructed based on a cross-platform data channel, user registration and authority distribution of the electric vehicle are completed in a multi-mode identity authentication mode to obtain a user authority level, and an authentication result is fed back to the supervision platform; performing intelligent charging pile matching based on the real-time multi-dimensional charging resource atlas according to the user permission level, and generating a dynamic service instruction containing a navigation path and charging parameters; and in a charging service execution process, a bidirectional supervision data flow is created through a cross-platform data channel, full-life-cycle supervision of the charging process is executed in real time, and a service strategy is dynamically adjusted based on a feedback instruction of a supervision platform. According to the technical scheme, the electric vehicle can be cooperatively charged.
Owner:深圳市友电物联科技有限公司

Permission verification method and system applied to OA examination and approval

The invention discloses a permission verification method and system applied to OA examination and approval, and relates to the technical field of permission verification, and the method comprises the steps: receiving an examination and approval request triggered by an OA system, carrying out the extraction according to the examination and approval request, and obtaining user identity information and an examination and approval content label set; triggering a multi-level permission verification mechanism based on the user identity information, and generating a dynamic verification rule set; performing permission verification on the approval content label according to the dynamic verification rule set, and formulating a target verification rule; and executing the target verification rule to perform multi-level cross verification on the user permission, generating a permission verification report according to a verification result, and feeding back the permission verification report to the OA system to trigger a subsequent approval process. The technical problems of low approval process efficiency and inaccurate authority control caused by fixed static rule configuration in the authority verification process in the prior art are solved, and the technical effects of improving the authority verification flexibility and accuracy and enhancing the approval process safety and intelligent level are achieved.
Owner:SHENZHEN ZHONGKE SHUJIAN TECH CO LTD

Method and system for encrypting and isolating storage data of credential mobile terminal

The invention relates to a method and system for encrypting and isolating storage data of a credential mobile terminal, and belongs to the technical field of information. The method comprises the following steps: encrypting and partitioning the whole storage area, and setting an access strategy according to user permission; when a user requests to access, executing multi-factor authentication containing a password and an external hardware certificate, and adding biological characteristic authentication; after the authentication is passed, an encryption key is taken from the domestic security chip; and encrypting and decrypting data by using the secret key, and opening corresponding partition access according to authority. The system comprises a storage partition module, an identity authentication module, a key management module, an encryption and decryption module and an authority control module and is used for executing the method. The method also comprises the steps of equipment startup trusted boot and firmware upgrade verification, is based on a custom curing system, and is compatible with Android 10 +. The problems of poor hardware controllability and positioning security risk of the creative mobile terminal are solved, and full-link data security protection is realized.
Owner:JINAN UNIV IND TECH RES INST CO LTD +1

Role-based authority management method and device

The embodiment of the invention provides a role-based authority management method and device, and the method comprises the steps: binding a basic authority to a preset basic role, and determining a basic role template library; constructing a user-defined role, endowing the user-defined role with a user-defined permission, and binding the user-defined role to the basic role template library according to a permission inheritance rule to determine a role permission template library; when a user is endowed with multiple roles and performs permission operation, constructing a directed acyclic graph based on the multiple roles and corresponding permissions, traversing the directed acyclic graph, executing permission union set operation according to a preset role weight value, and determining a corresponding user permission result; the method comprises the steps of collecting user operation behavior data flow in real time, inputting the operation behavior data flow into a pre-trained abnormal operation detection model for data processing, determining a corresponding abnormal probability value, correcting a permission result according to the abnormal probability value, and authorizing a user according to the corrected permission result. The team management efficiency can be improved through role permission optimization.
Owner:BEIJING HUAHANG WEISHI IND SOFTWARE TECH CO LTD

Dynamic form generation and cross-database adaptation method based on metadata driving

The invention discloses a dynamic form generation and cross-database adaptation method based on metadata driving, and belongs to the technical field of data architectures. The method comprises the steps that an original metadata attribute graph is established; on the basis of the original metadata attribute graph and user roles and equipment parameters for calling the forms, generating an optimal equipment form interaction data graph corresponding to each user permission; verifying an interaction path between the forms and a cross-database demand of a target database type to carry out cross-database mapping adaptation analysis, and generating an optimal form data adaptation database of the corresponding equipment of each user permission; and performing rule compiling based on multi-source heterogeneous data input by a user in real time and execution logic in the original metadata attribute graph, marking an incremental propagation path in the optimal form interaction data graph of the corresponding equipment of each user permission, and updating the optimal form data adaptation database of the corresponding equipment of each user permission. The method has the advantages that the data interaction efficiency is improved, and the interaction round-trip times and redundant data transmission are reduced.
Owner:NANJING LAICHEN TECH CO LTD +1

Data retrieval method, system and equipment

The invention provides a data retrieval method, system and device, and relates to the technical field of big data processing, the method comprises the following steps: obtaining a search text of a user; performing data permission assembly according to the search text to obtain a user permission set of the user; according to the user permission set, generating a retrieval filtering condition of the search text; according to the retrieval filtering condition, performing multi-source data search in combination with the search text to obtain an initial retrieval result corresponding to the search text; and performing unauthorized rejection operation on the initial retrieval result to obtain a final retrieval result of the search text. According to the method, the range is defined through permission assembly, the condition focusing target is filtered, the efficiency is improved through pre-matching, and the precision is guaranteed through post-removing, so that the retrieval data volume is compressed to improve the efficiency, and the matching pertinence is enhanced to improve the precision.
Owner:SUPCON TECH CO LTD

Large model gateway security protection system and security protection method

The invention discloses a large model gateway security protection system and a security protection method, and relates to the field of large model information security protection, and the system comprises the following steps: a gateway input and output module carries out compliance verification on a user request, sends a non-compliance request to a blocking isolation module, and inputs a compliance request to a called large model; the filtering and cleaning module is used for screening the original response content generated by the large model in real time; the classification and grading module identifies and marks the cleaned response content and determines a classification and grading result; the authority control module is used for verifying the access authority of the requesting user; the data desensitization module is used for desensitizing the sensitive fields according to the classification and grading result of the classification and grading module and the user permission; the desensitization data is output to a target application system through the gateway input and output module; and the blocking and isolating module is used for blocking and isolating the non-compliance requests, the high-proportion non-compliance responses and the requests corresponding to the high-risk behaviors, and has a multi-dimensional safety protection capability.
Owner:NAT IND INFORMATION SECURITY DEV RES CENT

Method and system for realizing large model access authentication and flow control based on APISIX gateway

The invention relates to the technical field of artificial intelligence, in particular to a method and system for achieving large model access authentication and flow control based on an APISIX gateway, and the method comprises the following steps: a client generates an HTTPS request containing an APIKey, and sends the HTTPS request to an APISIX gateway cluster; the gateway extracts the APIKey and forwards the APIKey to an authentication service, and the validity of the key is verified; after the verification is passed, the authentication service returns a user permission matrix, and the gateway verifies whether the request is within a permission range; after the permission verification is passed, the flow control plug-in detects a flow index according to a preset strategy; when the flow index does not exceed the limit, the gateway forwards the request to the large model service and returns a result; when the flow index exceeds the limit, the gateway executes flow limiting / fusing processing and returns a corresponding error response; the method has the beneficial effects that the gateway executes request forwarding or flow limiting control based on the preset strategy, the problems of illegal access risk and resource allocation imbalance faced by the large model service are effectively solved, the service stability and the resource utilization efficiency are improved, and the method is suitable for security operation and maintenance of the large model service in multiple scenes.
Owner:SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD

Row-level data permission authorization method and device, equipment and medium

The invention discloses a row-level data permission authorization method and device, equipment and a medium, and relates to the technical field of computers. Comprising the following steps: registering basic data into a preset database; configuring a corresponding field management user with a field management authority for the preset service field; creating or updating a record in a user data permission table based on the user permission application to determine a permission relationship between the user identifier and the entity data; registering a service data table and a mapping relation between an entity column and an entity type in the service data table in a preset service field based on a user instruction of a field management user; and dynamically generating a permission filtering condition based on the query SQL and the user identifier so as to generate an SQL statement with permission filtering, and querying corresponding service data from the service data table based on the mapping relationship so as to generate a corresponding query result based on the service data. Therefore, the efficiency and flexibility of line-level data permission authorization can be improved on the premise of ensuring data security.
Owner:SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD

Vehicle electronic control fault cloud automatic diagnosis system and method

The invention provides a vehicle electric control fault cloud automatic diagnosis system and method. The vehicle electric control fault cloud automatic diagnosis system comprises a user service end, a management end, a cloud diagnosis engine module, a vehicle intelligent network connection terminal, a vehicle condition verification module and a data security and user authority management module. Comprising the following steps: S1, inputting corresponding information in a user server interface; s2, performing a diagnosis test on the to-be-diagnosed vehicle and obtaining a diagnosis test conclusion; s3, configuring and managing the diagnosis related data; s4, performing data security and user authority management; according to the method, the fault diagnosis process is highly automatic, accurate diagnosis can be provided based on the specific fault phenomenon of the vehicle, the method does not completely depend on the personal ability of technicians any more, the dependence on high-skill technicians is reduced, and the problem of shortage of industrial technicians is relieved; the accuracy and one-time repair rate of fault diagnosis are improved, and the repair cost is reduced.
Owner:YUKUAI CHUANGLING INTELLIGENT TECH (NANJING) CO LTD

Method and system for automatically arranging process engine of Internet of Things based on large model

The invention discloses an Internet of Things process engine automatic arrangement method and system based on a large model. The method comprises the steps of obtaining a process demand described by a natural language of a user; the method comprises the following steps: analyzing a natural language of a user through a first-layer large model, and identifying related equipment, variables, conditions and action information; information identified by the first-layer large model serves as input of a second-layer large model, and the second-layer large model matches actual corresponding equipment and variable information under the user permission based on the user token, the equipment and the variable information; transmitting actual corresponding equipment, variables, conditions and action information under the user permission to a third-layer large model; and the third-layer large model matches the corresponding flow nodes according to the received information, the matched flow nodes are connected in series through a connecting line, and a structured flow JSON is generated. According to the method, the fuzzy natural language intention is gradually converted into an accurate and executable structured process through the three-layer large model, and the accuracy of an output result of each link is improved.
Owner:SHANDONG YOU INTERNET OF THINGS CO LTD

Webpage project construction and access control method and device

The invention relates to the technical field of computer networks, in particular to a webpage project construction and access control method, which comprises the following steps: acquiring a Web project source code file, packaging the Web project source code file, configuring a root directory to correspond to the action of a rendering page, and generating a packaged resource file; uploading the packaged resource file to a code warehouse for code hosting, triggering an assembly line execution process, and storing the packaged resource file in a workpiece generated in the assembly line execution process; receiving an access request of a user, and determining item positioning information through a unique identifier in the access request; verifying the user access authority; if the user permission state indicates that the user permission verification is passed, requesting a corresponding resource file from a workpiece, and generating rendering page information containing API basic address information; and sending the rendering page information to a browser for page rendering.
Owner:BEIJING ETERNAL CREATIVE TECH CO LTD

Multi-modal interaction method, system and device based on intelligent cabin and vehicle

The invention provides a multi-mode interaction method, system and device based on an intelligent cabin and a vehicle, and relates to the technical field of intelligent cabins, and the method comprises the steps: displaying a main interface comprising a multi-mode interaction instruction setting control, a user authority management control and a real-time feedback display area; and flexible configuration and real-time feedback of the interaction mode of the intelligent cabin are realized. According to the method, the safety and personalized setting of operation authorities of different users are ensured by utilizing cross validation binding of the biological characteristic data and the authority levels. Meanwhile, through fusion processing of multi-mode input signals such as voice, gestures, eye movement and facial expressions, the weight of each signal is dynamically adjusted according to a signal priority rule, an interaction instruction conforming to the intention of the user is generated, and the naturalness and efficiency of interaction are improved. Finally, the execution mechanism is controlled to complete the corresponding operation by performing matching verification on the interaction intention instruction and the user permission level, and the safety and accuracy of the operation are further ensured.
Owner:CHINA FAW CO LTD

Data dynamic exporting method and system based on templated configuration

The invention provides a data dynamic exporting method and system based on template configuration. The method comprises the steps that a data exporting request for exporting data in a data source in a report form is obtained; verifying the user permission data in the request to generate a verification result; when the verification result is that the verification is passed, generating a dynamic SQL statement according to template metadata corresponding to the template classification data; executing paging query according to the dynamic SQL statement, and performing data processing and streaming writing on data acquired from a data source to which data to be exported belongs in batches; and when the paging query is finished and data processing and streaming writing of the data obtained in the last batch are completed, generating a temporary file, and returning a downloading link to the client for triggering downloading of the data in the temporary file and generating a report corresponding to the data export request. According to the method and the system, the template adjustment efficiency is improved, the memory consumption is reduced, and the big data export success rate is greatly improved.
Owner:CHINA SOUTHERN POWER GRID INTERNET SERVICE CO LTD

Systems and methods for end user privilege elevation

Systems and methods for end user elevation and anonymous administrative login are disclosed. An agent executing on a client device can provide a graphical element within a user interface presented by the client device upon detection of a request for elevated user privileges. Upon an interaction with the graphical element, the agent transmits, to a server, data corresponding to the request for elevated user privileges, and receives, from the server, a message indicating approval of the request for elevated user privileges. The agent provides, to the operating system of the client device, an indication that the request for elevated user privileges is approved.
Owner:CONNECTWISE LLC

Natural language query method and system for rail transit field

The invention discloses a natural language query method and system for the field of rail transit, and relates to the field of data query, and the method comprises the steps: constructing a candidate data table based on an ElasticSearch database, a Milvus vector database and a user permission dictionary, extracting entities in a user query problem by using a large model in combination with a cue word template, and obtaining a query result; in combination with the Milvus vector database and the candidate data table, constructing an MQL statement based on the basic index library; generating sample data, an MQL statement and a candidate data table in combination with SQL, calling a large model, generating a first SQL statement in combination with a cue word template, performing data query in combination with a synonym mapping dictionary of retrieval conditions constructed by rail transit field experts, writing data of the whole interaction process into a Mysql database, and storing the Mysql database into a database. Accurate, safe and efficient natural language query service can be provided for non-technical personnel.
Owner:BEIJING LE MA SHI INTELLIGENT TECH CO LTD

Systems and methods for immersive data management in spatial computing

Systems and methods for immersive data management in spatial computing are disclosed. A method may include: (1) requesting from an identity and access management service executed in a cloud environment, an access token; (2) receiving, from an identity and access management service, the access token comprising user entitlements to access a plurality of elements in a plurality of scenes; (3) requesting one of the plurality of scenes from a scene filtering service, the request comprising the access token; (4) identifying the user entitlements from the access token; (5) retrieving the requested scene comprising a subset of the elements; (6) adding the elements that the user is entitled to based on the user entitlements to a scene to be displayed; (7) returning the scene to be displayed to the computer program; and (8) displaying the scene to be displayed.
Owner:JPMORGAN CHASE BANK NA

Trusted data dynamic desensitization access method and system based on federal learning

The invention relates to a credible data dynamic desensitization access method and system based on federated learning, and relates to the field of data processing, and the method comprises the steps: obtaining a data desensitization processing agent based on federated learning training; according to the number proportion of K types of desensitized data in the multiple sample desensitized data sets and the number proportion of desensitized data of P types of user permissions, a plurality of static contribution degrees of the multiple subjects are obtained through distribution; and obtaining a real-time trusted access data set and an access user set in the trusted data space, dynamically adjusting the plurality of static contribution degrees to obtain a plurality of dynamic contribution degrees, adjusting the user permissions of the plurality of subjects to obtain an access user permission set, and performing data desensitization processing and display when the user accesses the trusted data space. The technical problems that data desensitization processing is not accurate, and access control lacks flexibility and dynamics are solved, and fine management and security improvement of data desensitization access are achieved.
Owner:LINGSHU TECH CO LTD

Geofence-based real-time coexisting user social system and method

The invention belongs to the technical field of geo-fences and real-time social contact, and discloses a real-time coexistence user social contact system and method based on geo-fences, and the method comprises the steps: collecting the multi-dimensional multi-modal original data of a user through a dynamic sampling strategy and an energy efficiency balance mechanism, and generating an information-desensitized four-dimensional data set; constructing four layers of fences, evaluating the value attribute of each fence, carrying out life cycle management, dynamically adjusting the fence state, and forming a four-dimensional fence value network; identifying a basic event, a composite event and a cooperative event in a grading manner, constructing a real-time value flow through event value quantification, and generating a dynamic rule set adaptive to a scene; user permissions are distributed through the three-dimensional value permission matrix, the multi-dimensional value point system is linked to complete point generation and transaction, and a value circulation record including permission states, point changes and transaction records is formed; the value health degree is analyzed through a real-time, short-term and long-term three-level optimization mechanism, optimization parameters are generated, and the optimization parameters are reversely iterated to corresponding preorder links.
Owner:SHANGHAI XIANGYUE JIANGFENG DIGITAL TECHNOLOGY CO LTD

Business data query reconstruction method and device, equipment and storage medium

The invention discloses a business data query reconstruction method and device, equipment and a storage medium. Comprising the steps of obtaining a query task list constructed by a user, and performing permission verification on the query task list; after the verification is passed, reconstructing the query task list to generate a standard query command; executing the standard query command to obtain original query data, desensitizing the original query data to generate safe query data, and displaying the safe query data to a user. The user permission is verified through the permission verification process, the unauthorized query is intercepted from the source, and illegal access to the production database is avoided. By generating the standard query command, the row-level permission condition can be embedded into the query logic, so that the generated query command is ensured to be compliant, permission bypassing is avoided, errors and performance risks of manual writing are avoided, and meanwhile, the development efficiency is improved. By dynamically desensitizing the original query data, on the premise of guaranteeing the service continuity, the data can be available and invisible, the compliance requirement is accurately met, and the data leakage risk is reduced.
Owner:PICC INFORMATION TECH CO LTD +1

Method and system for dynamically adjusting user permission based on multi-dimensional perception

The invention discloses a user permission dynamic adjustment method and system based on multi-dimensional perception, and the method comprises the steps: obtaining multi-dimensional operation data of a to-be-accessed device, multi-dimensional behavior data of a current user in the to-be-accessed device, and multi-dimensional permission change data corresponding to the current user, obtaining a multi-dimensional perception feedback matrix between the current user and the to-be-accessed device; acquiring an elastic permission adjustment factor corresponding to the current user according to the multi-dimensional perception feedback matrix; adjusting a pre-constructed permission adjustment grid model according to the multi-dimensional perception feedback matrix to obtain a multi-dimensional permission adjustment grid model corresponding to the current user; according to the multi-dimensional perception feedback matrix, the elastic permission adjustment factor and the multi-dimensional permission adjustment grid model, the current permission value of the current user is dynamically adjusted, a real-time permission value corresponding to the current user is obtained, and the flexibility and accuracy of permission adjustment are improved.
Owner:CHINA SOUTHERN POWER GRID DIGITAL GRID GRP CO LTD

Intelligent community management system based on cloud service

The invention relates to the technical field of community management, and discloses an intelligent community management system based on cloud service. The system comprises a community basic data management module, a building structure information module, a public equipment monitoring module, a cloud data interaction module and a user authority management module. The community basic data management module maintains community static information and dynamic records; the building structure information module stores building physical attribute data and resident association information; the public equipment monitoring module collects real-time operation state data and historical performance indexes of public equipment; the cloud data interaction module realizes local and cloud data transmission synchronization; and the user permission management module allocates operation permissions according to preset role types. The system realizes data integration, equipment monitoring, authority specification and cloud interaction in a community management process through multi-module cooperation, and is suitable for efficient operation of a community management background.
Owner:MIDA CLOUD COMPUTING (HANGZHOU) CO LTD

Authority control method and device based on fine granularity

The embodiment of the invention provides an authority control method and device based on fine granularity, and the method comprises the steps: carrying out the node relation extraction of a mapping database, obtaining a role node and a product node, and introducing a user node and a context node; the method comprises the following steps: constructing a hyperedge structure, performing hyperedge linking on role nodes, product nodes, user nodes and service context nodes, determining a corresponding hyperedge relationship, performing dynamic weight endowing on the hyperedge relationship according to a time decay factor and a context risk coefficient, determining a dynamic graph structure, and constructing a directed acyclic graph based on the role inheritance relationship. Fusing the dynamic graph structure and the directed acyclic graph according to a graph algorithm, and determining a corresponding product permission layer graph database; the method comprises the steps of receiving a user operation instruction, performing context-aware query based on the operation instruction according to a graph traversal algorithm, determining a user permission, and performing permission control on a user according to the user permission. The method can improve the efficiency and the refinement degree of permission allocation.
Owner:BEIJING HUAHANG WEISHI IND SOFTWARE TECH CO LTD

Security cooperative processing method based on chip technology, medium and product

The invention discloses a security cooperative processing method based on a chip technology, a medium and a product, and relates to the field of data security, and the method comprises the steps: embedding a security chip in chip equipment, and presetting a chip-level security suite corresponding to the security chip; when a user starts the chip-level security suite through the chip equipment, a handshake request is initiated to the equipment management platform through an HTTP protocol; before data is written into the storage medium, plaintext data is encrypted into a ciphertext by using an SM4 encryption algorithm engine in the security chip, and data writing is carried out according to different types of storage protocols; during data transmission, a legal receiver list is generated based on user permission by using an equipment management platform, and after a user authorizes a receiver, a public key corresponding to the receiver is distributed by using the equipment management platform. According to the application, the security chip, the U-Key, the tablet / all-in-one machine and the equipment management platform can be organically fused to form a security protection entirety, so that a user is assisted, and the data security is improved.
Owner:ZHEJIANG LANDUN ELECTRONICS CO LTD

Anti-leakage encryption system and method based on power grid data

The invention discloses an anti-leakage encryption system and method based on power grid data, and relates to the technical field of power grid data security encryption, and the method comprises the steps: dividing encryption levels according to power grid data sensitivity levels, and matching algorithms; during service operation, generating a dynamic key seed based on a real-time scene, and binding the dynamic key seed with data transfer node information to generate an initial dynamic key; user permission change is monitored, and the secret key is automatically updated according to the newest role and node information when conditions are met; encrypting each level of data by adopting a corresponding algorithm and a dynamic key to form a ciphertext; and performing permission verification during access, and decrypting the ciphertext by using the corresponding key and algorithm according to the authorized decryption hierarchy. According to the method, the real-time linkage of encryption protection, the data flow state and the user permission change is realized, so that a security mechanism can dynamically adapt to the service scene change, and the active defense capability of power grid data leakage prevention and the immediate effectiveness of permission control are enhanced.
Owner:INFORMATION & COMMNUNICATION BRANCH STATE GRID JIANGXI ELECTRIC POWER CO