Authority policy-based token validity period differentiation management system and method
Through a differentiated management system for token validity period based on permission policy, the token validity period is dynamically adjusted, which solves the security risks and high maintenance costs caused by the fixed validity period of traditional tokens, and achieves a balance between security and user experience.
Patent Information
- Application Number
- CN202510347427.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-24
- Publication Date
- 2025-06-17
AI Technical Summary
Traditional tokens use a fixed validity period for all users and cannot be dynamically adjusted according to user roles, resulting in long-term exposure risks of high-privileged accounts or frequent reauthentication of low-privileged users, and the existing system maintenance costs are high and error-prone.
Design a differentiated management system for token validity period based on permission policies, including role management module, policy engine module, dynamic risk assessment module, token generator and token validator. By dynamically adjusting the validity period of the token, differentiated allocation is made according to user role, IP address, device fingerprint and context risk.
It realizes dynamic allocation of tokens with different validity periods according to user roles and security policies, improves security, optimizes user experience, and is suitable for scenarios such as identity authentication, access control, API security, etc., and achieves a balance between security and user experience.
Smart Images

Figure CN120165854A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer security technology, and particularly to a differential management system and method for token validity periods based on permission policies. Background Art
[0002] Traditional tokens (such as JWT, OAuth Token) adopt a fixed validity period for all users and cannot be dynamically adjusted according to user roles, resulting in the risk of long-term exposure of high-privilege accounts or frequent re-authentication of low-privilege users. Although some systems support multiple validity periods, they rely on manual configuration, cannot automatically associate roles with security policies, and have high maintenance costs and are error-prone.
[0003] To solve the above problems, the present invention proposes a differential management system and method for token validity periods based on permission policies. Summary of the Invention
[0004] The present invention provides a simple and efficient differential management system and method for token validity periods based on permission policies to make up for the deficiencies of the prior art.
[0005] The present invention is realized by the following technical solutions:
[0006] A differential management system for token validity periods based on permission policies includes a role management module, a policy engine module, a dynamic risk assessment module, a token generator, and a token validator;
[0007] The role management module is used to define the roles of users and the corresponding permission levels, and the roles include administrators, ordinary users, and visitors;
[0008] The policy engine module is responsible for storing the mapping rules between roles and token validity periods;
[0009] The dynamic risk assessment module is responsible for analyzing the login IP and device fingerprint in real time and dynamically adjusting the validity period;
[0010] The token generator is responsible for issuing tokens carrying role identifiers and dynamic validity periods;
[0011] The token validator is responsible for intercepting requests, verifying the validity of tokens, and checking role permissions.
[0012] When the dynamic risk assessment module dynamically adjusts the validity period, it first queries the policy engine, obtains the basic validity period according to the user role, and then superimposes the custom adjustment rules to calculate the actual validity period.
[0013] The custom adjustment rules are as follows:
[0014] If it is detected that the user is logging in from a different location, the validity period is shortened by 50%;
[0015] If it is detected that the user logs in on a trusted device, add 100% validity period to the custom role.
[0016] A method for differential management of token validity period based on permission policy, comprising the following steps:
[0017] Step S1, user authentication
[0018] When the user registers, define the user's role and the corresponding permission level through the role management module. The roles include administrator, ordinary user, and visitor;
[0019] Step S2, user login
[0020] The user performs a login operation using the account password. The system verifies the credentials and obtains the role information;
[0021] Step S3, policy engine
[0022] Determine the user's basic token parameters, including the basic validity period of the token, according to the user role through the policy engine module;
[0023] Step S4, dynamic risk assessment
[0024] The dynamic risk assessment module analyzes the login IP and device fingerprint in real time and dynamically adjusts the validity period;
[0025] Step S5, issue token
[0026] When the token generator issues a token, generate a token containing the role, dynamic validity period timestamp, and signature;
[0027] Step S6, access control
[0028] When the access request arrives, the token validator verifies the token signature and validity period, and compares the role permissions with the resource requirements;
[0029] Step S7, token refresh
[0030] Automatically refresh the token for the custom-configured role according to the policy engine.
[0031] In the step S4, when the dynamic risk assessment module dynamically adjusts the validity period, first query the policy engine, obtain the basic validity period according to the user role (such as the role is 30 minutes), and then superimpose the custom adjustment rule to calculate the real validity period.
[0032] The custom adjustment rule is as follows:
[0033] If it is detected that the user logs in from a different location, shorten the validity period by 50%;
[0034] If it is detected that the user logs in on a trusted device, add 100% validity period to the custom role.
[0035] In step S1, the role management module defines whether each role is allowed to automatically refresh the token and customizes high-risk roles.
[0036] In step S7, according to the definition of the role management module, the policy engine module automatically refreshes the token for the corresponding role and re-authenticates the corresponding high-risk role.
[0037] A device for differential management of token validity period based on permission policy, characterized in that it includes a memory and a processor; the memory is used to store a computer program, and the processor is used to implement the above method steps when executing the computer program.
[0038] A readable storage medium, characterized in that a computer program is stored on the readable storage medium, and the computer program implements the above method steps when executed by a processor.
[0039] The beneficial effects of the present invention are: the differential management system and method for token validity period based on permission policy allocate the token validity period differently according to user roles, IP addresses, device fingerprints, context risks and business requirements, improving security while optimizing the user experience, and being applicable to scenarios such as identity authentication, access control, and API security, achieving a balance between security and user experience. Brief Description of the Drawings
[0040] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0041] Appendix Figure 1 It is a schematic diagram of the architecture of the differential management system for token validity period based on permission policy of the present invention. Detailed Embodiments
[0042] In order to enable those skilled in the art to better understand the technical solutions in the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0043] The token validity period differential management system based on permission policies includes a role management module, a policy engine module, a dynamic risk assessment module, a token generator, and a token validator;
[0044] The role management module is used to define the roles of users and the corresponding permission levels. The roles include administrators, ordinary users, and visitors;
[0045] The policy engine module is responsible for storing the mapping rules between roles and token validity periods;
[0046] The dynamic risk assessment module is responsible for analyzing the login IP and device fingerprint in real time and dynamically adjusting the validity period;
[0047] The token generator is responsible for issuing tokens carrying role identifiers and dynamic validity periods;
[0048] The token validator is responsible for intercepting requests, verifying the validity of tokens, and checking role permissions.
[0049] When the dynamic risk assessment module dynamically adjusts the validity period, it first queries the policy engine, obtains the base validity period according to the user role (for example, a certain role = 30 minutes), and then superimposes the custom adjustment rules to calculate the actual validity period.
[0050] The custom adjustment rules are as follows:
[0051] If it is detected that the user is logging in from a different location, the validity period is shortened by 50%;
[0052] If it is detected that the user is logging in on a trusted device, the validity period for the custom role is increased by 100%.
[0053] The method for differential management of token validity periods based on permission policies includes the following steps:
[0054] Step S1, user authentication
[0055] When the user registers, the role management module defines the user's role and the corresponding permission level. The roles include administrators, ordinary users, and visitors;
[0056] Step S2, user login
[0057] The user performs a login operation using the account password. The system verifies the credentials and obtains the role information;
[0058] Step S3, policy engine
[0059] The policy engine module determines the user's basic token parameters according to the user role, including the basic validity period of the token;
[0060] Step S4, dynamic risk assessment
[0061] The dynamic risk assessment module analyzes the login IP and device fingerprint in real time and dynamically adjusts the validity period;
[0062] Step S5, issue a token
[0063] When the token generator issues a token, it generates a token containing the role, dynamic validity period timestamp, and signature;
[0064] Step S6, access control
[0065] When an access request arrives, the token validator verifies the token signature and validity period, and compares the role permissions with the resource requirements;
[0066] Step S7, token refresh
[0067] According to the policy engine, tokens are automatically refreshed for custom-configured roles.
[0068] In step S4, when the dynamic risk assessment module dynamically adjusts the validity period, it first queries the policy engine to obtain the base validity period according to the user role (for example, the base validity period for a certain role is 30 minutes), and then superimposes the custom adjustment rules to calculate the actual validity period.
[0069] The custom adjustment rules are as follows:
[0070] If it is detected that the user is logging in from a different location, the validity period is shortened by 50%;
[0071] If it is detected that the user is logging in on a trusted device, the validity period is increased by 100% for the custom role.
[0072] In step S1, the role management module defines whether each role is allowed to automatically refresh tokens and customizes high-risk roles;
[0073] In step S7, the policy engine module automatically refreshes tokens for the corresponding roles according to the definition of the role management module and re-authenticates the corresponding high-risk roles.
[0074] The device for differential management of token validity period based on permission policy includes a memory and a processor; the memory is used to store computer programs, and the processor is used to implement the above method steps when executing the computer programs.
[0075] A computer program is stored on the readable storage medium, and when the computer program is executed by the processor, the above method steps are implemented.
[0076] Compared with the prior art, the differential management system and method for token validity period based on permission policy have the following characteristics:
[0077] First, according to user roles, IP addresses, device fingerprints, contextual risks, and business requirements, the token validity period is differentially allocated, enhancing security while optimizing the user experience.
[0078] Second, tokens with different validity periods are dynamically allocated based on user roles and security policies, applicable to scenarios such as identity authentication, access control, and API security, achieving a balance between security and user experience.
[0079] The above-described embodiments are only one of the specific implementation manners of the present invention. Any ordinary changes and substitutions made by those skilled in the art within the scope of the technical solution of the present invention should be included within the protection scope of the present invention.
Claims
1. A token validity period differentiation management system based on permission strategy, characterized by: Including role management module, Policy engine module, dynamic risk assessment module, token generator and token validator; The role management module is used to define the user's role and corresponding authority level, and the roles include administrator, ordinary user and visitor; The policy engine module is responsible for storing the mapping rules between roles and token validity periods; The dynamic risk assessment module is responsible for real-time analysis of login IP and device fingerprints, and dynamically adjusting the validity period; The token generator is responsible for issuing a token carrying a role identifier and a dynamic validity period; The token validator is responsible for intercepting requests, verifying token validity, and checking role permissions.
2. The token validity period differentiation management system based on authority policy according to claim 1 is characterized by: When the dynamic risk assessment module dynamically adjusts the validity period, it first queries the policy engine, obtains the basic validity period according to the user role, and then superimposes the custom adjustment rules to calculate the real validity period.
3. The token validity period differentiation management system based on authority policy according to claim 2 is characterized in that: The custom adjustment rules are as follows: If it is detected that the user is logging in from a different location, the validity period will be shortened by 50%; If it is detected that the user is logged in from a trusted device, the validity period of the custom role is increased by 100%.
4. A token validity period differentiated management method based on permission strategy, characterized by: The following steps are involved: Step S1: User authentication When a user registers, the user's role and corresponding permission level are defined through the role management module. The roles include administrator, ordinary user and visitor. Step S2: User login The user logs in using his account and password, the system verifies the credentials, and obtains the role information; Step S3, policy engine Determine the basic user token parameters according to the user role through the policy engine module, including the basic validity period of the token; Step S4, dynamic risk assessment The dynamic risk assessment module analyzes login IP and device fingerprints in real time and dynamically adjusts the validity period; Step S5, issuing a token When the token generator issues a token, it generates a token containing the role, dynamic validity period timestamp and signature; Step S6: Access Control When an access request arrives, the token validator verifies the token signature and validity period, and compares the role permissions with the resource requirements; Step S7: Token refresh Automatically refresh tokens for custom configured roles based on the policy engine.
5. The token validity period differentiation management method based on authority policy according to claim 4 is characterized by: In step S4, when the dynamic risk assessment module dynamically adjusts the validity period, it first queries the policy engine to obtain the basic validity period according to the user role, and then superimposes the custom adjustment rules to calculate the real validity period.
6. The token validity period differentiation management method based on authority policy according to claim 5 is characterized by: The custom adjustment rules are as follows: If it is detected that the user is logging in from a different location, the validity period will be shortened by 50%; If it is detected that the user is logged in from a trusted device, the validity period of the custom role is increased by 100%.
7. The differentiated token validity management method based on authority policy according to claim 4 is characterized by: In step S1, the role management module is used to define whether each role is allowed to automatically refresh the token, and customize high-risk roles; In step S7, the policy engine module automatically refreshes the token for the corresponding role according to the definition of the role management module, and re-authenticates the corresponding high-risk role.
8. A token validity period differentiation management device based on permission policy, characterized in that: The method comprises a memory and a processor; the memory is used to store a computer program, and the processor is used to implement the method steps described in any one of claims 4 to 7 when executing the computer program.
9. A readable storage medium, characterized in that: The readable storage medium stores a computer program, and when the computer program is executed by a processor, the method steps described in any one of claims 4 to 7 are implemented.
Citation Information
Cited By
Authority management method and system for double-token decoupling and dynamic token mapping
CN120768687A