Dynamic authorization and authority management system applied to agent application system
By introducing a dynamic authorization and rights management system into the intelligent application system and utilizing virtual roles and dynamic rights adjustment mechanisms, the flexibility and real-time problems of rights management in the existing technology are solved, and safe and efficient rights management is achieved.
Patent Information
- Application Number
- CN202510692572.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-27
- Publication Date
- 2025-09-05
AI Technical Summary
Existing technologies cannot flexibly manage permissions in intelligent application systems, especially in complex business scenarios, where it is difficult to quickly respond to dynamic changes in permissions, and it is difficult to achieve accurate allocation and real-time synchronization of permissions in a multi-source data environment.
A dynamic authorization and permission management system is designed, which includes user agent module, authentication and authorization module, role management module, dynamic permission adjustment module, data resource management module, model management module and intelligent agent management module. Through the collaborative work of these modules, the resources and permissions of the intelligent application system are managed separately. The virtual role mechanism and dynamic permission adjustment mechanism are adopted to ensure the flexibility and security of permissions.
It achieves precise control and flexible management of permissions, ensures the security and real-time performance of the system, reduces the workload of manual configuration, ensures the consistency of permission settings with system status, and adapts to complex and changing application scenarios.
Smart Images

Figure CN120597247A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of rights management, and in particular to a dynamic authorization and rights management system applied to an intelligent application system. Background Art
[0002] Agent-based application systems primarily consist of agents, large-scale language models, data resources, retrieval mechanisms, and tools. Existing approaches for managing data permissions in agent-based application systems are mostly based on role-based access control (RBAC). While these approaches can optimize permissions management to a certain extent, they lack sufficient flexibility for dynamically adjusting vector library permissions in complex business scenarios. For example, when multiple business modules are involved and data operation permissions frequently change, the maintenance cost of the role permission table is high, making it difficult to quickly respond to dynamic changes in permissions.
[0003] Existing approaches also design general software control models based on role-based access control. These models categorize data resources through an authorization resource module, display data through a menu / button module, and match operations with menu buttons through an operation permission module. Internal roles are then introduced to optimize differentiated authorization. In the context of vector library permissions management, different roles can be assigned access rights to different parts of the vector library, and permissions can be granted expiration dates. However, this model is not sufficiently detailed when managing vector library permissions after integrating vector library data from different data sources. For example, when an enterprise integrates vector data from multiple external data sources, it is difficult to accurately assign users vector library operation permissions across these data sources.
[0004] At the same time, existing methods have also designed object-level data permission management for search platforms with non-unified permission systems and multi-source data. This method classifies multi-source data, formulates permission standards and specifications, and performs data processing and permission configuration to achieve object-level data permission management. In terms of vector library permission management, if the vector library data comes from multiple data sources with different permission systems, effective integration and permission management can also be performed. However, there are deficiencies in the permission control of vector library data in real-time interactive scenarios. For example, in a real-time updated geographic information vector library, it is difficult to synchronize data updates and permission changes in real time, which may lead to inconsistencies between data operations and permissions. Summary of the Invention
[0005] In view of the above-mentioned deficiencies in the prior art, the present invention provides a dynamic authorization and rights management system applied to an intelligent agent application system, which is used to solve the defect of the existing method that it cannot flexibly manage the rights of intelligent agents.
[0006] In order to achieve the above-mentioned object of the invention, the technical solution adopted by the present invention is:
[0007] A dynamic authorization and rights management system applied to an intelligent agent application system, comprising:
[0008] The user agent module is used to receive the user's operation access request for the resource, transmit it to the authentication and authorization module, and receive the result returned by the authentication and authorization module, and allow or deny the user's operation access request for the resource;
[0009] The authentication and authorization module is used to receive the operation access request transmitted by the user agent module, call the role management module to verify the user identity information, role or virtual role, and authority, and transmit the result of allowing or denying the operation access to the user agent module;
[0010] The role management module is responsible for the creation, storage, and management of user information, roles or virtual roles, and permissions, and also assigns roles or virtual roles corresponding permissions to resources and assigns different roles or virtual roles to users;
[0011] The dynamic permission adjustment module is used to monitor the creation, update, and deletion of resources in the intelligent agent application system, trigger the permission adjustment of the corresponding role or virtual role according to the permission inheritance rules or permission restriction rules, and transmit it to the role management module;
[0012] The data resource management module is used to manage the data resources in the intelligent application system, receive and implement the operation access request of the user agent module to allow the user to access the resources, and transmit the operation access including creation, update and deletion of the data resources to the dynamic permission adjustment module;
[0013] The model management module is used to manage the model resources in the intelligent agent application system, receive and implement the operation access request of the user agent module to allow the user to access the resources, and transmit the operation access including creation, update and deletion of the model resources to the dynamic permission adjustment module;
[0014] The intelligent agent management module is used to manage the intelligent agent resources in the intelligent agent application system, receive and implement the user agent module's operation access request to the resources, and after performing operations including creation, update, deletion, and call on the intelligent agent resources, transmit it to the dynamic permission adjustment module to establish an association relationship between the intelligent agent resources and the virtual role.
[0015] The present invention has the following beneficial effects:
[0016] 1. This paper proposes a dynamic authorization and rights management system for an agent application system. By designing seven core modules—a role management module, an authentication and authorization module, a dynamic rights adjustment module, a data resource management module, a model management module, an agent management module, and a user agent module—it manages the resources and rights of the main components of the agent application system (including models, data resources, and agents) independently, thus achieving the decomposition of rights.
[0017] 2. A temporary association mechanism is established between users and virtual characters to resolve the conflict between users' temporary needs for related permissions when accessing intelligent entities and security management, ensuring flexible access while ensuring overall security.
[0018] 3. The proposed virtual role mechanism enables intelligent agents to be precisely controlled within the permission framework, which not only ensures the security of the system but also improves the flexibility of permission management;
[0019] 4. Design a dynamic permission adjustment mechanism to address the real-time permission issue. This mechanism automatically triggers permission updates by monitoring changes in data resources, models, and agent states. Furthermore, the dynamic permission adjustment mechanism introduces inheritance and restriction rules, allowing permission configurations to be dynamically adjusted as resource states change. This reduces manual configuration workload and ensures consistency between permission settings and system status.
[0020] 5. At key operation points such as resource creation, update, and deletion, the system can automatically perform permission evaluation and adjustment to ensure that each resource status change triggers the corresponding permission update;
[0021] 6. Combining the virtual role mechanism with dynamic permission adjustment forms an adaptive and efficient permission management system, providing a solid security foundation for the intelligent application system, enabling it to function safely and efficiently in complex and changing application scenarios. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] Figure 1 This is a flow chart of a dynamic authorization and rights management system applied to an intelligent application system proposed by the present invention;
[0023] Figure 2 Schematic diagram of the data transmission relationship between the model and data resource modules under dynamic permission adjustment in the embodiment;
[0024] Figure 3 Schematic diagram of the data transmission relationship between the intelligent agent module under dynamic permission adjustment in the embodiment;
[0025] Figure 4 Schematic diagram of the data transmission relationship between modules in the intelligent agent calling scenario in the embodiment. DETAILED DESCRIPTION
[0026] The specific embodiments of the present invention are described below to facilitate understanding of the present invention by those skilled in the art. However, it should be clear that the present invention is not limited to the scope of the specific embodiments. For those skilled in the art, as long as various changes are within the spirit and scope of the present invention as defined and determined by the appended claims, these changes are obvious, and all inventions and creations utilizing the concepts of the present invention are protected.
[0027] like Figure 1 As shown, a dynamic authorization and rights management system applied to an intelligent agent application system includes:
[0028] The user agent module is used to receive the user's operation access request for the resource, transmit it to the authentication and authorization module, and receive the result returned by the authentication and authorization module, and allow or deny the user's operation access request for the resource.
[0029] In this embodiment, roles include data administrators, model administrators, agent administrators, and regular users. Virtual roles are assigned to each agent. These roles are associated with permissions and control the resources the agent can access. This is similar to treating agents as virtual users and creating virtual roles for them. Actual users can be associated with virtual roles to invoke agents. Resource access requests include creating, updating, deleting, or invoking data resources, models, agents, and other resources within the agent application system.
[0030] The authentication and authorization module is used to receive the operation access request transmitted by the user agent module, and call the role management module to verify the user identity information, role or virtual role, and authority, and transmit the result of allowing or denying operation access to the user agent module.
[0031] Specifically, the authentication and authorization module is used to receive the operation access request transmitted by the user agent module, call the role management module to verify the user identity information, role or virtual role, and authority, and transmit the result of allowing or denying the operation access to the user agent module. The specific process is as follows:
[0032] First, receive the operation access request transmitted by the user agent module, and call the role management module to authenticate the user identity information to determine whether the user identity is legal. If so, the user identity is legal, and perform role or virtual role and authority verification. Otherwise, the user identity is illegal and any operation access is denied.
[0033] Secondly, obtain the role or virtual role and permission information corresponding to the user identity, including the role list, virtual role list, and permission list.
[0034] Then, based on the user's role list, virtual role list, and permission list, determine whether the user has the permission to perform the corresponding operation. If so, return a result of allowing the operation access; otherwise, return a result of denying the operation access.
[0035] Specifically, the specific process of determining whether the user has the authority to perform the corresponding operation is as follows:
[0036] According to the user's role list and permission list, find the permissions possessed by the role and determine whether the operation requested by the user is in the permission list possessed by the role. If so, the user has the permission to perform the operation and returns to allow operation access; otherwise, returns to deny operation access.
[0037] According to the user's virtual role list and permission list, find the permissions of the virtual role and determine whether the user's current role meets the permissions required by the virtual role. If so, the user has the permissions required by the virtual role and returns the result of allowing access. Otherwise, it returns a result of denying access.
[0038] In this embodiment, when determining whether a user has permission to perform a corresponding operation, the virtual role involved is predicated on the user invoking an agent; therefore, without an agent, there is no virtual role. Therefore, when a user invokes an agent, the corresponding permissions can be searched in the user's role list. If the permissions are insufficient, the user is directly associated with the virtual role corresponding to the agent. Once the virtual role is associated, the user's permission to access the agent is guaranteed. Therefore, when the authentication module receives an operation access request transmitted by the user agent module, it first calls the role management module to determine whether the user is legitimate and has permission to perform the operation.
[0039] The role management module is responsible for the creation, storage and management of user information, roles or virtual roles, and permissions, and at the same time assigns roles or virtual roles corresponding permissions to resources and assigns users different roles or virtual roles.
[0040] Specifically, when a user is associated with a role or a virtual role, one user corresponds to one role or multiple virtual roles.
[0041] The dynamic permission adjustment module is used to monitor the creation, update, and deletion of resources in the intelligent application system, trigger the permission adjustment of the corresponding role or virtual role according to the permission inheritance rules or permission restriction rules, and transmit it to the role management module.
[0042] Specifically, the permission inheritance rules are to adjust the permissions of the corresponding role or virtual role for resource creation and update, as follows:
[0043] Determine whether the resource is an intelligent entity. If so, when the intelligent entity is created, it inherits the permission association relationship between the specific parent resource permissions and the corresponding virtual role. When the intelligent entity is updated, it inherits the permission association relationship between the resource permissions before the update and the corresponding virtual role. Otherwise, if the resource is a data resource or a model resource, if it is a creation operation, it inherits the permission association relationship between the specific parent resource permissions and the corresponding role. If it is an update operation, it inherits the permission association relationship between the resource permissions before the update and the corresponding role. Among them, the specific parent is the parent specified by the user.
[0044] In this embodiment, the intelligent agent needs to be listed separately in the inheritance rule definition, that is, if the intelligent agent is created, it inherits the permission association relationship between the specific parent resource permissions and the virtual role; if the intelligent agent is updated, it inherits the permission association relationship between the resource permissions before the update and the virtual role; and for data resources and model resources, if it is an update operation, the inheritance rule is reflected in inheriting the permission association relationship between the resource permissions before the update and the role; if it is a creation operation, it inherits the permission association relationship between the specific parent resource permissions and the role; and there is no inheritance rule for the deletion operation.
[0045] Specifically, the permission restriction rules include system restriction rules predefined by users with the highest authority and rules customized by each resource administrator for the resources they manage; among them, the system restriction rules predefined by users with the highest authority are adjustments to the general permissions of resources; the rules customized by each resource administrator for the resources they manage are adjustments to the personalized permissions of resources.
[0046] Specifically, if the resource status changes, each resource administrator can choose to dynamically adjust permissions based on predefined system restriction rules or customized rules.
[0047] In this embodiment, the restriction rules only apply to the user with the highest authority. For example, the system administrator can predefine system restriction rules, which are mainly for adjusting general resource permissions. In addition, each resource administrator can also customize restriction rules for the resources they manage to adjust personalized resource permissions. Therefore, when the resource status changes, each resource administrator can not only choose to adjust permissions according to predefined restriction rules, but also choose to customize restriction rules to dynamically adjust permissions.
[0048] In summary, this module implements a dynamic linkage between permissions and resources. By monitoring changes (creation, update, and deletion) to key resources (data, models, and agents) in the system, it triggers adjustments to relevant role permissions based on inheritance or restriction rules, ensuring the timeliness, accuracy, and security of permission configuration. Resource change event monitoring includes identifying triggers for change events such as the creation, update, and deletion of models, data resources, and agents. It also allows system administrators and individual resource administrators to define permission inheritance and restriction rules based on resource types, attributes, and relationships. When a resource change event occurs, the dynamic permission adjustment module evaluates whether permission adjustments are necessary based on the defined rules. For example, system administrators can predefine system restriction rules to adjust general resource permissions. For example, when a resource is disabled, all roles' permissions to operate on it are revoked. Individual resource administrators can also customize restriction rules for the resources they manage. When resource status changes, each resource administrator can choose to dynamically adjust permissions based on predefined or customized restriction rules.
[0049] The data resource management module is used to manage the data resources in the intelligent application system, receive and implement the user agent module's operation access request to the resources, and after performing operations including creation, update and deletion on the data resources, transmit it to the dynamic permission adjustment module.
[0050] Specifically, the data resource management module is also used to provide permission control for data resources together with the dynamic permission adjustment module and the role management module, and provide data resources for the intelligent body management module.
[0051] The model management module is used to manage the model resources in the intelligent application system, receive and implement the operation access request to the resource allowed by the user agent module, and transmit it to the dynamic permission adjustment module after performing operations including creation, update and deletion on the model resources.
[0052] Specifically, the model management module is also used to provide permission control for the model together with the dynamic permission adjustment module and the role management module, provide model resources for the data resource management module and the intelligent agent management module, and can perform data processing corresponding to the model resources on the data resources.
[0053] In this embodiment, a dependency exists between the model management module and the data resource management module. Specifically, the model resources in the model management module can perform corresponding data processing on the data resources in the data resource management module. For example, the vectorized model in the model management module can perform vectorized processing on the data resources. Furthermore, the model management module can also provide model support for the agent management module, effectively creating a dependency between the two modules.
[0054] The intelligent agent management module is used to manage the intelligent agent resources in the intelligent agent application system, receive and implement the user agent module's operation access request to the resources, and after performing operations including creation, update, deletion, and call on the intelligent agent resources, transmit it to the dynamic permission adjustment module to establish an association relationship between the intelligent agent resources and the virtual role.
[0055] Specifically, the intelligent agent management module is also used to provide permission control for the intelligent agent together with the dynamic permission adjustment module and the role management module.
[0056] In this embodiment, there is a dependency relationship between the agent management module and the data resource management module and the model management module, that is, the agent of the agent module needs to rely on data resources and model resources.
[0057] In addition, in order to clearly describe the functions of the dynamic authorization and rights management system proposed by the present invention for an intelligent agent application system, the tables and corresponding fields of the role management module, authentication and authorization module, user agent module, dynamic rights adjustment module, data resource management module, model management module, and intelligent agent management module are defined as follows:
[0058] (1) The role management module of the present invention defines the user table (users), the user role association table (user_roles), the user virtual role association table (user_vir_roles), the role / virtual role table (roles), the role / virtual role table permission association table (role_permissions), and the permission table (peimissions);
[0059] The user table includes the user's unique identifier (user_id, primary key), username (unsername, unique name), password hash value (password_pash, encrypted storage), user status (status, such as activated, disabled, locked, etc.), account creation time (created_at), and account information update time (updated_at);
[0060] The user role association table includes the primary key (user_role_id), user ID (user_id, a foreign key pointing to the user table), associated role ID (role_id, a foreign key pointing to the role / virtual role table), whether it is a virtual role (virtual, yes or no), assigned time (assigned_at), and status (status, such as enabled or disabled);
[0061] The user virtual role association table includes the primary key (vir_user_role_id), user ID (user_id, a foreign key pointing to the user table), associated virtual role ID (role_id, a foreign key pointing to the role / virtual role table), whether it is a virtual role (virtual, yes or no), assignment time (assigned_at), and status (status, such as enabled or disabled);
[0062] The role / virtual role table includes the role unique identifier (role_id, which is the primary key), role name (role_name, such as administrator, ordinary user, etc.), role description (role_description), whether it is a virtual role (virtual, yes or no), role status (status, such as enabled, disabled, etc.), role creation time (created_at), and role update time (updated_at);
[0063] The role / virtual role table and permission association table include the primary key (role_permission_id), role ID (role_id is a foreign key pointing to the role / virtual role table), whether it is a virtual role (virtual, yes or no), permission ID (permission_id is a foreign key pointing to the permission table), assigned time (assigned_at), and status (status, such as enabled or disabled);
[0064] The permission table includes the permission unique identifier (permission_id, primary key), permission name (permission_name, such as: view data, delete model, etc.), permission description (permission_description), resource type (resource_type, such as: data resource, model, intelligent body), resource ID (resource_id, resource unique identifier), operation type (operation_type, such as: read, modify, delete), permission creation time (created_at), and permission update time (updated_at).
[0065] (2) The user proxy module includes the primary key (proxy_id), user ID (user_id, which is a foreign key pointing to the user table), the resource requested by the user (resource_id, such as data resource, model, agent), the operation requested by the user (operation_type, such as: read, create, update, delete), the authorization decision result (decision_result, such as: allow, deny), and the status (status, success, failure);
[0066] (3) The authentication and authorization module includes the primary key (decision_id), user ID (user_id, which is a foreign key pointing to the user table), the resource requested by the user (resource_id, such as data resources, models, and intelligent agents), the operation requested by the user (operation_type, such as: read, create, update, delete), the authorization decision (decision, such as allow, deny), and whether the user role permissions meet the requirements (permission_match, yes or no).
[0067] (4) The dynamic permission adjustment module includes the resource change event table (resource_change_events), the temporary association virtual role event table, and the inheritance and restriction rule table (inheritance_and_restriction_rules);
[0068] The resource change event table includes the event unique identifier (event_id, which is the primary key), resource type (module, such as data, model, or agent), changed resource type (model / resource_type), changed resource ID (model / resource_id), changed resource name (model / resource_name), event type (event_type, such as create, delete, update, etc.), user ID that triggered the event (changed_by, which is a foreign key pointing to the user table), and event occurrence time (event_time);
[0069] The temporary associated virtual role event table includes the temporary associated virtual role event unique identifier (time_event_id, which is the primary key), the virtual role ID (role_id), the virtual role name (role_name), the user ID of the temporary associated virtual role (time_changed_by, which is the foreign key pointing to the user table), and the event occurrence time (time_event_time);
[0070] The inheritance and restriction rule table includes the rule unique identifier (rule_id, primary key), user ID (user_id, foreign key, pointing to the user table), rule type (rule_type, inheritance or restriction), resource type (module, dataset, model or agent), trigger event (trigger_event, such as: create, update), parent role ID (parent_model / resource_id, if any), parent role name (parent_model / resource_name, if any), parent role type (parent_model / resource_type, if any), rule status (status, enabled, disabled), rule creation time (created_at), rule update time (updated_at).
[0071] (5) The data resource management module includes a data resource table (data_resources), which includes a data resource unique identifier (resource_id, primary key), a data resource name (resource_name), a data resource type (resource_type, such as a knowledge base document or a data set), a data resource status (status, enabled or disabled), a data resource default permission (default_power, public or restricted), a creation time (created_at), an update time (updated_at), and a resource owner ID (owner_id, a foreign key pointing to the user table).
[0072] (6) The model management module includes a model table (models), which includes a model unique identifier (model_id, primary key), a model name (model_name, such as: pre-trained model, fine-tuned model), a model type (model_type, such as: large language model, embedded model), a model version (model_version), a model status (status, enabled, disabled), a model default permission (default_power, public, restricted), a model owner ID (owner_id, foreign key, pointing to the user table), a model creation time (created_at), and a model update time (updated_at).
[0073] (7) The agent management module includes an agent table (agents) and an agent virtual role association table;
[0074] The agent table includes the agent unique identifier (agent_id, primary key), agent name (agent_name), model ID (model_id, foreign key), data resource ID (data_resource_id, foreign key), agent version (agent_version), agent status (status, enabled, disabled), owner ID (owner_id), creation time (created_at), and update time (updated_at);
[0075] The agent virtual role association table includes the primary key (agent_vir_role_id), agent ID (agent_vir_role_id, a foreign key pointing to the agent table), associated role ID (role_id, a foreign key pointing to the role / virtual role table), assigned time (assigned_at), and status (status, such as enabled or disabled).
[0076] Therefore, based on the tables of all the above modules and the fields contained in each table, an example of the corresponding relationship between roles, permissions, and resources is given, as shown in Table 1:
[0077] Table 1 is an example table of role settings
[0078]
[0079] As can be seen from the example in Table 1, each role has corresponding permissions, and these permissions are permissions on resources.
[0080] Therefore, based on the functions and fields of each module mentioned above, dynamic monitoring and adjustment of permissions are performed to clearly describe the functions of a dynamic authorization and permission management system applied to an intelligent application system proposed by the present invention, specifically:
[0081] (1) Dynamic permission adjustment of model and data resource modules
[0082] 1) Applicable scenarios: When administrators create, update, and delete models and data resources, the dynamic permission adjustment module promptly adjusts the relevant permissions of the corresponding roles to ensure the safe operation of the system.
[0083] 2) Module coordination: Role management module, provides user information and its associated role information and authority information, and coordinates with dynamic authority adjustment module to adjust authority; Resource management module (data resource management module, model management module), provides resource information and corresponding operation interface; Authentication and authorization module, performs user identity authentication and corresponding authority judgment; User agent module, accepts user access request, and according to the result returned by authentication and authorization module, allows or denies user access request, and performs access control of user operation; Dynamic authority adjustment module, according to the inheritance and restriction rules of authority adjustment, calls role management module to adjust the user authority and resource association relationship; And the data transmission relationship between each module is as follows Figure 2 As shown;
[0084] 3) Model and data resource creation process
[0085] Trigger event: The model / data administrator sends a request to the user agent module to create access to the corresponding resources of the model / data resource management module; the user agent module passes the relevant information to the authentication and authorization module, which calls the role management module to verify the user identity information and the corresponding role and permission information, and returns the permission judgment result to the user agent module; if the verification is successful, access to the relevant operations is allowed; otherwise, access is denied; the dynamic permission adjustment module monitors the occurrence of resource change events and calls the role management module to dynamically adjust the permissions of the newly added resources according to the inheritance and restriction rules. The specific process is as follows:
[0086] 1.1. The model / data administrator sends a create operation request for the model / data resource to the user agent module, passing in user_id, resource_id, and operation_type;
[0087] 1.2. The user agent module passes the administrator's creation request to the authentication and authorization module, including the user_id, resource_id, and operation_type fields.
[0088] 2.1. The authentication and authorization module passes the above-mentioned user information to the role management module;
[0089] 2.2. The role management module queries the permission information of the corresponding user role through the above-mentioned user information and sends it to the authentication and authorization module;
[0090] 2.3. The authentication and authorization module determines whether the permission information corresponding to the user-associated role meets the permission of the operation requested by the user, and returns the judgment result to the decision_result field of the user agent module;
[0091] 2.4. If the user agent module determines that the permissions are met based on the judgment result, the model / data administrator is allowed to trigger a create event for the model / data resource management module. The administrator passes the information of the new model / data resource to the model / data resource management module, including model / resource_name, model / resource_type, model_version, status, and default_power. At the same time, the corresponding module automatically generates the model / resource_id, owner_id, created_at, and updated_at corresponding field information. If the permissions are not met, the access request is denied.
[0092] 3.1. The dynamic permission adjustment module monitors the resource creation event triggered by the model and data resource management modules. The model and data resource management modules pass the resource creation module, model / resource_id, model / resource_name, model / resource_type, event_type, and event_details fields to the dynamic permission adjustment module. The dynamic permission adjustment module automatically generates event_id and event_time, and records the current user_id in the changed_by field.
[0093] 4.1. The dynamic permission adjustment module formulates the permission inheritance rules: If the administrator wants the new model / data resource to inherit the role permission information of a parent model / data resource, the inheritance rules are formulated. The dynamic permission adjustment module obtains the resource list from the corresponding resource management module for the administrator to select the parent resource to be inherited. The administrator passes the user_id, rule_type, module, trigger_event, and status to the dynamic adjustment module, and selects the relevant information of the parent resource to be inherited in the dynamic permission adjustment module, including the parent_model / resource_id, parent_model / resource_name, and parent_model / resource_type fields; the dynamic permission adjustment module uses the user_id and parent_model / resource_id to query the role management module for the permissions and permission-associated role information of the corresponding parent resource, and then calls the role management module to create a new permission_id for the newly added resource, and assigns the permissions and permission-associated role information of the parent resource to the newly added resource, so that the user's newly added resource inherits the parent resource role permission information.
[0094] 5.1. Dynamic permission adjustment module defines permission restriction rules: If the administrator wants to grant default role permission information to new models / data resources according to restriction rules, use predefined or customized restriction rules to grant default access rights of models / data resources to corresponding roles; predefined restriction rules are set by the system administrator.
[0095] For example, grant the "Model Trainer" role the ability to train new models by default. Or grant the "Data Administrator" role the ability to read and write new data resources by default.
[0096] The process of customizing restriction rules is as follows: the dynamic permission adjustment module obtains the role name list from the role management module so that the administrator can add permissions for corresponding resources to the role. The model / data resource administrator passes the user_id, rule_type, module, trigger_event, and status fields to the dynamic adjustment module; then the role management module is called through the dynamic permission adjustment module, and the id of the corresponding resource is passed in as resource_i to define the permission table of the newly added resources and the permission association table of the role / virtual role; and permissions and role permission association relationships are created for the newly added resources.
[0097] 4) Model and data resource update process
[0098] Triggering event: The model / data administrator sends an update access request to the user agent module for the corresponding resources of the model / data resource management module; the user agent module passes the relevant information to the authentication and authorization module, which calls the role management module to verify the user identity information and the corresponding role and permission information, and returns the permission judgment result to the user agent module; if the verification is successful, access to the relevant operation is allowed; otherwise, access is denied; the dynamic permission adjustment module monitors resource change events, and then calls the role management module to dynamically adjust the permissions of the updated resources according to the inheritance and restriction rules. The specific process is as follows:
[0099] 1.1. The model / data administrator sends an update operation request for the model / data resource to the user agent module, passing in user_id, resource_id, and operation_type.
[0100] 1.2. The user agent module passes the administrator's update request to the authentication and authorization module, including the user_id, resource_id, and operation_type fields.
[0101] 2.1. The authentication and authorization module passes the above-mentioned user information to the role management module;
[0102] 2.2. The role management module queries the permission information of the corresponding user role through the above-mentioned user information and sends it to the authentication and authorization module;
[0103] 2.3. The authentication and authorization module determines whether the permission information corresponding to the user-associated role meets the permission of the operation requested by the user, and returns the judgment result to the decision_result field of the user agent module;
[0104] 2.4. If the user agent module determines that the permissions are met based on the judgment result, the model / data administrator is allowed to trigger an update event for the model / data resource management module. The administrator updates the model / data resource information to the model and data resource management module based on the model / resource_id, including model / resource_name, model / resource_type, model_version, status, and default_power. At the same time, the corresponding module automatically updates the updated_at corresponding field information. If the permissions are not met, the access request is denied.
[0105] 3.1 The dynamic permission adjustment module monitors the triggering of resource update events corresponding to the model and data resource management modules. The model and data resource management modules pass the module, model / resource_id, model / resource_name, model / resource_type, event_type, and event_details field information of the changed resource to the dynamic permission adjustment module. The dynamic permission adjustment module automatically generates event_id and event_time, and records the current user_id in the changed_by field.
[0106] 4.1. The dynamic permission adjustment module formulates permission inheritance rules: If the administrator wants to update the model / data resource to inherit the role permission information before the model / data resource is updated, no operation is required. The updated model / data resource defaults to the previous role permission information.
[0107] 5.1. Dynamic Permission Adjustment Module defines permission restriction rules: If an administrator wants to update the default role permission information of a model / data resource based on the restriction rules, the default access rights of the model / data resource will be granted to the corresponding role using predefined or custom restriction rules. Predefined restriction rules are set by the system administrator.
[0108] For example: If the default permission (default_power) of a resource is set from public to restricted, revoke access to that model for all roles. Or if the resource status is set to disabled, revoke access to that resource for all roles.
[0109] Among them, the process of custom restriction rules is as follows: the dynamic permission adjustment module obtains the role name list from the role management module in preparation for the administrator to add permissions for corresponding resources to the role, and the model / data resource administrator passes the user_id, rule_type, module, trigger_event, and status fields to the dynamic adjustment module; then the role management module is called through the dynamic permission adjustment module, and the id of the corresponding resource is passed in as the resource_id; the permission table corresponding to the resource_id and the role / virtual role permission association table are updated to update the permissions and role permission association relationship for the updated resources.
[0110] 6.1. Permission warning of dynamic permission adjustment module: The dynamic permission adjustment module analyzes resource dependencies and checks whether there are any intelligent agents that depend on the model. If so, it will give an alarm to the intelligent agent management module.
[0111] For example: If the model / data resource status is updated to "disabled" and all users' access rights to the model are revoked, an alarm needs to be triggered to notify the agent administrator.
[0112] 5) Model and data resource deletion process
[0113] Triggering event: The model / data administrator sends a request to the user agent module to delete access to the corresponding resources of the model / data resource management module; the user agent module passes the relevant information to the authentication and authorization module, which calls the role management module to verify the user identity information and the corresponding role and permission information, and returns the permission judgment result to the user agent module; if the verification is successful, access to the relevant operation is allowed; otherwise, access is denied; the dynamic permission adjustment module monitors resource change events, and then calls the role management module to dynamically adjust the permissions for deleting resources based on inheritance and restriction rules. The specific process is as follows:
[0114] 1.1. The model / data administrator sends a delete operation request for the model / data resource to the user agent module, passing in user_id, resource_id, and operation_type;
[0115] 1.2. The user agent module passes the administrator's deletion request to the authentication and authorization module, including the user_id, resource_id, and operation_type fields.
[0116] 2.1. The authentication and authorization module passes the above-mentioned user information to the role management module;
[0117] 2.2. The role management module queries the permission information of the corresponding user role through the above-mentioned user information and sends it to the authentication and authorization module;
[0118] 2.3. The authentication and authorization module determines whether the permission information corresponding to the user-associated role meets the permission of the operation requested by the user, and returns the judgment result to the decision_result field of the user agent module;
[0119] 2.4. If the user agent module determines that the permissions are met, the model / data administrator is allowed to trigger a deletion event on the model / data resource management module. The administrator transmits the information of deleting the model / data resource to the model / data resource management module, including model / resource_id, model / resource_name, model / resource_type, and model_version. If the permissions are not met, the access request is rejected.
[0120] 3.1. The dynamic permission adjustment module monitors the triggering of resource deletion events corresponding to the model and data resource management modules. The model and data resource management modules pass the module, model / resource_id, model / resource_name, model / resource_type, event_type, and event_details fields of the changed resource to the dynamic permission management module. The dynamic permission adjustment module automatically generates event_id and event_time, and records the current user_id in the changed_by field.
[0121] 4.1. The dynamic permission adjustment module does not need to define inheritance rules for deletion operations.
[0122] 5.1. The dynamic permission adjustment module defines permission restriction rules: If a user deletes a model / data resource, the access rights of all roles to the model / data resource are revoked according to the predefined restriction rules; the model / data resource administrator passes the user_id, rule_type, module, trigger_event, and status fields to the dynamic adjustment module; then the dynamic permission adjustment module calls the role management module, passing the ID of the corresponding resource as the resource_id, deletes the permission table and role / virtual role permission association table corresponding to the resource_id, and revokes the access rights of all roles to the deleted resource.
[0123] 6.1. Permission warning of dynamic permission adjustment module: The dynamic permission adjustment module analyzes resource dependencies and checks whether there are intelligent agents that depend on the model. If so, an alarm needs to be triggered to notify the intelligent agent administrator.
[0124] (2) Dynamic authority adjustment design of intelligent agent module
[0125] 1) Applicable scenarios: When administrators create, update, and delete intelligent entities, the dynamic permission adjustment module promptly adjusts the relevant permissions of the corresponding roles / virtual roles to ensure the safe operation of the system.
[0126] 2) Core concept changes: Virtual role: Assign an independent virtual role to each agent, and the virtual role is associated with permissions to control the resources that the agent can access; Agent mapping: Establish a mapping relationship between the agent and its virtual role.
[0127] 3) Module coordination: Role management module: provides user information and its associated role information and permission information, coordinates with the dynamic permission adjustment module to adjust permissions, creates virtual roles and assigns permissions, coordinates with the intelligent agent management module to establish the association between intelligent agents and virtual roles; Resource management module (data resource management, model management, intelligent agent management): provides resource information and corresponding operation interfaces; Authentication and authorization module: performs user and virtual role identity authentication and corresponding permission judgment; User agent module: accepts user access requests, and according to the results returned by the authentication and authorization module, allows or denies user access requests, and performs access control for user operations; Dynamic permission adjustment module: according to the permission adjustment inheritance and restriction rules, calls the role management module to adjust the user's permissions and resource associations. At the same time, temporary virtual role permissions are assigned to users; and the data transmission relationship between each module is as follows: Figure 3 As shown;
[0128] 4) Agent creation and configuration process
[0129] Triggering event: The agent administrator sends an agent creation access request to the agent management module to the user agent module; the user agent module passes the relevant information to the authentication and authorization module, the authentication and authorization module calls the role management module to verify the user identity information and the corresponding role and permission information, and returns the permission judgment result to the user agent module; if the verification is passed, access to the relevant operations is allowed, otherwise access is denied; the dynamic permission adjustment module calls the role management module to create a virtual role according to actual needs, and the agent administrator establishes a mapping relationship between the agent and the virtual role in the agent management module; the dynamic permission adjustment module monitors the occurrence of resource change events, and dynamically adjusts the permissions of the newly added resources according to the inheritance and restriction rules.
[0130] The specific process is:
[0131] 1.1. The agent administrator sends a request to the user agent module to create an agent, passing in user_id, resource_id, and operation_type;
[0132] 1.2. The user agent module passes the administrator's creation request to the authentication and authorization module, including the user_id, resource_id, and operation_type fields.
[0133] 2.1. The authentication and authorization module passes the above-mentioned user information to the role management module;
[0134] 2.2. The role management module queries the permission information of the corresponding user role through the above-mentioned user information and sends it to the authentication and authorization module;
[0135] 2.3. The authentication and authorization module determines whether the permission information corresponding to the user-associated role meets the permission of the operation requested by the user, and returns the judgment result to the decision_result field of the user agent module;
[0136] 2.4. If the permissions are met based on the judgment result, the user agent module allows the agent administrator to trigger a creation event on the agent management module. The administrator passes the information of the new agent to the agent management module, including agent_name, model_id, data_resource_id, agent_version, status, and default_power. At the same time, the agent management module automatically generates the corresponding field information of agent_id, owner_id, created_at, and updated_at. If the permissions are not met, the access request will be rejected.
[0137] 3.1. The dynamic permission adjustment module listens to the creation event triggered by the intelligent agent management module. The intelligent agent management module passes in the agent_id, agent_name, model_id, data_resource_id, agent_version, status, and default_power of the created resource. The dynamic permission adjustment module automatically generates event_id and event_time, and records the current user_id in the changed_by field.
[0138] 4.1. The creation operation does not require the dynamic permission adjustment module to perform dependency analysis on the intelligent agent management module.
[0139] 5.1. The dynamic permission adjustment module calls the role management module to create virtual roles and assign permissions, and defines the virtual role table and the virtual role permission association table.
[0140] 6.1. The agent administrator establishes a mapping relationship between the agent and its virtual role in the agent management module, establishes an agent and virtual role association table, assigns role_id to agent_id, and the agent management module automatically generates agent_vir_role_id and records assigned_at and status.
[0141] 5) Agent Update
[0142] Trigger event: The agent administrator sends an agent update access request to the agent management module to the user agent module; the user agent module passes the relevant information to the authentication and authorization module, which calls the role management module to verify the user identity information and the corresponding role and permission information, and returns the permission judgment result to the user agent module; if the verification is passed, access to the relevant operations is allowed; otherwise, access is denied; the dynamic permission adjustment module monitors the occurrence of resource change events, analyzes resource dependencies, and then calls the role management module to dynamically adjust the permissions of the updated resources according to the inheritance and restriction rules; the specific process is as follows:
[0143] 1.1. The agent administrator sends an update operation request to the user agent module, passing in user_id, resource_id, and operation_type;
[0144] 1.2. The user agent module passes the administrator's update request to the authentication and authorization module, including the user_id, resource_id, and operation_type fields.
[0145] 2.1. The authentication and authorization module passes the above-mentioned user information to the role management module;
[0146] 2.2. The role management module queries the permission information of the corresponding user role through the above-mentioned user information and sends it to the authentication and authorization module;
[0147] 2.3. The authentication and authorization module determines whether the permission information corresponding to the user-associated role meets the permission of the operation requested by the user, and returns the judgment result to the decision_result field of the user agent module;
[0148] 2.4. If the permissions are met based on the judgment result, the user agent module allows the agent administrator to trigger an update event on the agent management module. The administrator updates the agent information to the agent management module based on the agent_id, including agent_name, model_id, data_resource_id, and status. At the same time, the agent management module automatically updates the corresponding field information of updated_at; if the permissions are not met, the access request will be rejected.
[0149] 3.1. The dynamic permission adjustment module monitors the triggering of the resource update event corresponding to the intelligent agent management module, and the intelligent agent management module passes the module, agent_id, agent_name, model_id, data_resource_id, event_type and event_details fields of the changed resource; the dynamic permission adjustment module automatically generates event_id and event_time, and records the current user_id to the changed_by field.
[0150] 4.1. The dynamic permission adjustment module performs resource dependency analysis: it analyzes whether the model list and data resource list used by the agent have changed based on model_id and data_resource_id; then queries the virtual role corresponding to the agent in the agent management module through agent_id, and then calls the role management module to adjust and evaluate the permissions of the virtual role corresponding to the agent, including: model list changes; the dynamic permission adjustment module evaluates whether it is necessary to add or revoke the access rights of the agent virtual role to certain models; data resource list changes: the dynamic permission adjustment module evaluates whether it is necessary to add or revoke the access rights of the agent virtual role to certain data resources.
[0151] 5.1. The update operation does not require the dynamic permission adjustment module to call the role management module to create a virtual role.
[0152] 6.1. The update operation does not require the agent management module to establish a mapping relationship between the agent and the virtual role.
[0153] 7.1. The dynamic permission adjustment module formulates the permission inheritance rules: If the model and data resources that the updated intelligent agent depends on are not adjusted, the virtual role permission information before the intelligent agent is updated will be inherited without any operation.
[0154] 8.1. Dynamic Permission Adjustment Module Defines Permission Restriction Rules: If the models and data resources that the updated agent relies on are adjusted, custom restriction rules are required to grant new permission information to the virtual role corresponding to the updated agent. The process of customizing restriction rules is as follows:
[0155] The model / data resource administrator passes the user_id, rule_type, module, trigger_event, and status fields to the dynamic adjustment module; then the role management module is called through the dynamic permission adjustment module, and the virtual role role_id corresponding to the agent_id is passed in, and the corresponding virtual role permission association table is updated to update the virtual role permission association relationship for the updated intelligent agent.
[0156] 6) Agent deletion
[0157] Trigger event: The agent administrator sends a request to the user agent module to delete access to the agent in the agent management module; the user agent module passes the relevant information to the authentication and authorization module, the authentication and authorization module calls the role management module to verify the user identity information and the corresponding role and permission information, and returns the permission judgment result to the user agent module; if the verification is passed, access to the relevant operations is allowed; otherwise, access is denied; at the same time, the agent administrator deletes the association between the agent and the virtual role in the agent management module, and the dynamic permission adjustment module monitors resource change events, and no dynamic adjustment of permissions is required; the specific process is as follows:
[0158] 1.1. The agent administrator sends a delete operation request to the user agent module, passing in user_id, resource_id, and operation_type;
[0159] 1.2. The user agent module passes the administrator's deletion request to the authentication and authorization module, including the user_id, resource_id, and operation_type fields.
[0160] 2.1. The authentication and authorization module passes the above-mentioned user information to the role management module;
[0161] 2.2. The role management module queries the permission information of the corresponding user role through the above-mentioned user information and sends it to the authentication and authorization module;
[0162] 2.3. The authentication and authorization module determines whether the permission information corresponding to the user-associated role meets the permission of the operation requested by the user, and returns the judgment result to the decision_result field of the user agent module;
[0163] 2.4. If the permissions are met based on the judgment result, the user agent module allows the agent administrator to trigger a deletion event on the agent management module. The agent administrator transmits the information of deleting the agent to the agent management module, including agent_id, agent_name, and agent_type; if the permissions are not met, the access request is rejected.
[0164] 3.1. The dynamic permission adjustment module monitors the triggering of the resource deletion event corresponding to the intelligent agent management module, and the intelligent agent management module passes the module, agent_id, agent_name, agent_type, event_type and event_details fields of the changed resource; the dynamic permission adjustment module automatically generates event_id and event_time, and records the current user_id to the changed_by field.
[0165] 4.1. The deletion operation does not require the dynamic permission adjustment module to perform dependency analysis on the intelligent agent management module.
[0166] 5.1. The deletion operation does not require the dynamic permission adjustment module to call the role management module to create a virtual role.
[0167] 6.1. Mapping between intelligent agents and virtual roles: The intelligent agent administrator deletes the association table between intelligent agents and virtual roles in the intelligent agent management module and cancels the mapping relationship between intelligent agents and virtual roles.
[0168] (3) Agent call
[0169] 1) Applicable scenarios: Ordinary users call the intelligent agent, and the dynamic permission adjustment module promptly adjusts the relationship between the user and the virtual role to ensure the safe operation of the system.
[0170] 2) Module coordination: Role management module: provides user information and its associated role information and authority information, agent-associated virtual role information and authority information, and cooperates with the dynamic authority adjustment module to adjust the authority; Resource management module (data resource management module, model management module, agent management module): provides resource information and corresponding operation interface; Authentication and authorization module: performs user identity authentication and corresponding authority judgment, and performs virtual role authority judgment; User agent module: accepts user access requests, and allows or denies user access requests based on the results returned by the authentication and authorization module, and performs access control for user operations; Dynamic authority adjustment module: calls the role management module to adjust the user's authority and resource association relationship based on the inheritance and restriction rules of authority adjustment; creates a temporary association relationship between the user and the virtual role; and the data transmission relationship between each module is as follows Figure 4 As shown;
[0171] 3) Trigger event: An ordinary user sends an access request to the user agent module to call a certain agent of the agent management module; the user agent module passes the relevant information to the authentication and authorization module, the authentication and authorization module calls the role management module to verify the user's identity information and the corresponding role and permission information, and returns the permission judgment result to the user agent module; after the verification is passed, it is further verified whether the existing permissions of the user's corresponding role and the permissions required by the virtual role of the agent match. If they match, access to related operations is allowed. Otherwise, the user needs to apply for temporary permissions from the system administrator, and the dynamic permission adjustment module calls the role management module to temporarily associate the current user with the virtual role corresponding to the agent, and grant the current user temporary agent call permissions. After the agent call is completed, the temporary association between the user and the virtual role is revoked; the specific process is as follows:
[0172] 1.1. A normal user sends a request to the user agent module to call an agent, including user information and agent information, and passes in the user_id and agent_id fields;
[0173] 1.2. The user agent module transmits the agent information to the agent management module and queries whether the agent has any alarm information through the agent_id;
[0174] 1.3. The agent management module transmits the agent's alarm information to the user agent module. If the user agent module finds that there is alarm information, it will reject all call requests to the agent.
[0175] 2.1. If there is no alarm information, the agent management module transmits the virtual role information corresponding to the agent obtained by querying agent_id to the user agent module;
[0176] 2.2. The user agent module transmits the user's call request and the information of the virtual role corresponding to the intelligent agent to the authentication and authorization module.
[0177] 3.1. The authentication and authorization module transfers the above-mentioned user information and virtual role information to the role management module;
[0178] 3.2. The role management module obtains the permission information of the user's corresponding role and the permission information required by the corresponding virtual role through the above-mentioned information and sends it to the authentication and authorization module;
[0179] 3.3. The authentication and authorization module determines whether the permissions of the user's current role meet the permissions required by the virtual role corresponding to the intelligent agent, and returns the judgment result to the decision_result field of the user agent module;
[0180] 3.4. The user agent module allows the user to trigger a call event to the agent management module if the authority is met according to the judgment result. If the authority is not met, the call request is rejected.
[0181] 4.1. If the call is rejected because the permissions of the user's current role do not meet the permissions required by the virtual role corresponding to the agent, the user can apply for temporary access rights from the system administrator;
[0182] 4.2. The system administrator calls the dynamic permission adjustment module to grant temporary access rights to ordinary users;
[0183] 4.3. The system administrator uses the dynamic permission adjustment module to call the role management module to create a temporary user and virtual role association table, add temporary permissions for the virtual role corresponding to the agent to the user, and successfully call the agent. After the agent call is completed, the corresponding association table is automatically deleted.
[0184] In summary, the present invention proposes a dynamic authorization and permission management system for intelligent application systems. First, by designing seven core modules, namely, role management module, authentication and authorization module, dynamic permission adjustment module, data resource management module, model management module, intelligent agent management module and user agent module, the system can manage the resources and permissions of the main components of the intelligent application system (including models, data resources and intelligent agents) separately, thus realizing the decomposition of permissions. Among them, the role management module is based on the idea of RBAC, inherits the definition and association relationship of user-role-permission in RBAC, and adds virtual roles on this basis. As the core of permission management, this module provides user registration, role definition and permission allocation functions. It can establish a user table, role table, virtual role table, permission table and their related tables to store permission configuration information and perform permission management on the entire intelligent application system; the authentication and authorization module and the user agent module implement user identity authentication and permission judgment, and control user access to resources according to the results returned by the role management module; the dynamic permission adjustment module monitors changes in resource status and adjusts relevant permissions according to inheritance and restriction rules; therefore, this modular design enables the system to effectively separate permission control from resource management, while maintaining close collaboration, ensuring that each resource access is subject to strict permission verification, effectively preventing unauthorized access and data leakage risks, and is particularly suitable for large model + intelligent agent application scenarios that process sensitive data and have complex access patterns. Secondly, the present invention innovatively expands on the traditional RBAC model and solves the unique challenges of agent permission management by introducing virtual roles; wherein, virtual roles are identified by the virtual field in the role table and are managed separately from ordinary user roles; each agent is assigned an independent virtual role, and a one-to-one correspondence is established through the agent and virtual role mapping table; virtual roles are associated with permissions, and agents obtain permissions to access resources through their corresponding virtual roles; this design enables agents to be subject to unified permission control within the RBAC framework while maintaining the independence of permission configuration; when an agent requests access to system resources, the system first obtains the corresponding virtual role through the mapping relationship, and then determines whether the user's existing permissions meet the permissions required by the virtual role; the virtual role mechanism implements the "least privilege principle", ensuring that agents can only access the resources necessary to perform tasks, effectively preventing unauthorized operations, and providing a flexible and secure permission management mechanism for agent application systems.At the same time, the present invention also implements a complete dynamic permission adjustment process, allowing users to flexibly adjust the permission configuration of the intelligent application system according to actual needs; among them, at key operation points such as resource (data, model, intelligent agent) creation, update and deletion, the dynamic permission adjustment module automatically monitors the triggering of change events and adjusts permissions; users can customize the permission change logic through inheritance rules and restriction rules, that is: inheritance rules allow resources to inherit the permission configuration of parent resources, reducing repeated configuration work; restriction rules customize the adjustment of permissions according to changes in resource status; the system also provides permission warnings, and timely analyzes resource dependencies during the permission adjustment process and alerts related modules; if it is detected that changes in resource dependencies may affect existing intelligent agents, the system automatically triggers an alarm; this dynamic adjustment capability greatly reduces the burden of permission management, while improving system security, so that the permission configuration of the intelligent application system is always synchronized with actual business needs. Finally, the present invention also focuses on the security management of users' temporary access needs and designs a temporary permission application and management process; when a user requests to call an intelligent agent, the system performs permission verification to compare the user's permissions with the permissions required by the intelligent agent's virtual role; if there is no complete match, the temporary permission application process is initiated, and the user needs to submit a temporary permission application to the system administrator; the system administrator creates a temporary user virtual role association table through the dynamic permission adjustment module and grants time-limited temporary permissions, and the dynamic permission adjustment module records the relevant information of the temporary permission adjustment; after the intelligent agent access ends, the temporary permission is automatically withdrawn to avoid security risks caused by the continued existence of permissions; this strict protection mechanism not only meets the flexible access needs, but also minimizes the risks of unauthorized access and data leakage through the temporary nature and automatic withdrawal mechanism of permissions, providing all-round security protection for the intelligent agent application system.
[0185] Specific embodiments are used in the present invention to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core ideas. At the same time, for those skilled in the art, according to the ideas of the present invention, there may be changes in the specific implementation methods and application scopes. In summary, the contents of this specification should not be understood as limiting the present invention.
[0186] Those skilled in the art will appreciate that the embodiments described herein are intended to help readers understand the principles of the present invention, and it should be understood that the scope of protection of the present invention is not limited to such specific descriptions and embodiments. Those skilled in the art can make various other specific variations and combinations based on the technical teachings disclosed in the present invention without departing from the essence of the present invention, and such variations and combinations are still within the scope of protection of the present invention.
Claims
1. A dynamic authorization and rights management system applied to an intelligent agent application system, characterized in that: include: The user agent module is used to receive the user's operation access request for the resource, transmit it to the authentication and authorization module, and receive the result returned by the authentication and authorization module, and allow or deny the user's operation access request for the resource; The authentication and authorization module is used to receive the operation access request transmitted by the user agent module, call the role management module to verify the user identity information, role or virtual role, and authority, and transmit the result of allowing or denying the operation access to the user agent module; The role management module is responsible for the creation, storage, and management of user information, roles or virtual roles, and permissions, and also assigns roles or virtual roles corresponding permissions to resources and assigns different roles or virtual roles to users; The dynamic permission adjustment module is used to monitor the creation, update, and deletion of resources in the intelligent agent application system, trigger the permission adjustment of the corresponding role or virtual role according to the permission inheritance rules or permission restriction rules, and transmit it to the role management module; The data resource management module is used to manage the data resources in the intelligent application system, receive and implement the operation access request of the user agent module to allow the user to access the resources, and transmit the operation access including creation, update and deletion of the data resources to the dynamic permission adjustment module; The model management module is used to manage the model resources in the intelligent agent application system, receive and implement the operation access request of the user agent module to allow the user to access the resources, and transmit the operation access including creation, update and deletion of the model resources to the dynamic permission adjustment module; The intelligent agent management module is used to manage the intelligent agent resources in the intelligent agent application system, receive and implement the user agent module's operation access request to the resources, and after performing operations including creation, update, deletion, and call on the intelligent agent resources, transmit it to the dynamic permission adjustment module to establish an association relationship between the intelligent agent resources and the virtual role.
2. The dynamic authorization and rights management system for an intelligent agent application system according to claim 1, characterized in that: The data resource management module is also used to provide permission control for data resources together with the dynamic permission adjustment module and the role management module, and provide data resources for the intelligent body management module.
3. The dynamic authorization and rights management system for an intelligent agent application system according to claim 2, characterized in that: The model management module is also used to provide permission control for the model together with the dynamic permission adjustment module and the role management module, provide model resources for the data resource management module and the intelligent agent management module, and perform data processing corresponding to the model resources on the data resources.
4. The dynamic authorization and rights management system for an intelligent agent application system according to claim 3, characterized in that: The intelligent agent management module is also used to provide permission control for the intelligent agent together with the dynamic permission adjustment module and the role management module.
5. The dynamic authorization and rights management system for an intelligent agent application system according to claim 4, characterized in that: When associating a user with a role or a virtual role, one user corresponds to one role or multiple virtual roles.
6. The dynamic authorization and rights management system for an intelligent agent application system according to claim 5, characterized in that: The authentication and authorization module is used to receive the operation access request transmitted by the user agent module, call the role management module to verify the user identity information, role or virtual role, and permissions, and transmit the result of allowing or denying the operation access to the user agent module. The specific process is as follows: First, it receives the operation access request transmitted by the user agent module and calls the role management module to authenticate the user identity information and determine whether the user identity is legal. If so, the user identity is legal and the role or virtual role and permission verification is performed. Otherwise, the user identity is illegal and any operation access is denied. Secondly, obtain the role or virtual role and permission information corresponding to the user identity, including the role list, virtual role list, and permission list; Then, based on the user's role list, virtual role list, and permission list, determine whether the user has the permission to perform the corresponding operation. If so, return a result of allowing the operation access; otherwise, return a result of denying the operation access.
7. The dynamic authorization and rights management system for an intelligent agent application system according to claim 6, characterized in that: The specific process of determining whether the user has the authority to perform the corresponding operation is as follows: According to the user's role list and permission list, find the permissions possessed by the role, and determine whether the operation requested by the user is in the permission list possessed by the role. If so, the user has the permission to perform the operation and returns to allow the operation access; otherwise, returns to deny the operation access; According to the user's virtual role list and permission list, find the permissions of the virtual role and determine whether the user's current role meets the permissions required by the virtual role. If so, the user has the permissions required by the virtual role and returns the result of allowing access. Otherwise, it returns a result of denying access.
8. The dynamic authorization and rights management system for an intelligent agent application system according to claim 7, characterized in that: The permission inheritance rules are to adjust the permissions of the corresponding roles or virtual roles for resource creation and update, specifically: Determine whether the resource is an agent. If so, when creating the agent, it inherits the permission association relationship between the specific parent resource permissions and the virtual role. When updating the agent, it inherits the permission association relationship between the resource permissions before the update and the virtual role. Otherwise, if the resource is a data resource or model resource, if it is a create operation, it inherits the permission association relationship between the specific parent resource permissions and the role. If it is an update operation, it inherits the permission association relationship between the resource permissions before the update and the role. The specific parent is a parent specified by the user.
9. The dynamic authorization and rights management system for an intelligent agent application system according to claim 8, characterized in that: Permission restriction rules include system restriction rules predefined by users with the highest permissions and rules customized by each resource administrator for the resources they manage. Among them, system restriction rules predefined by users with the highest permissions are adjustments to general resource permissions; rules customized by each resource administrator for the resources they manage are adjustments to personalized resource permissions.
10. The dynamic authorization and rights management system for an intelligent agent application system according to claim 9, characterized in that: If the resource status changes, each resource administrator can choose to dynamically adjust permissions based on predefined system restriction rules or customized rules.
Citation Information
Cited By
Intelligent agent data dynamic matching method based on user authority
CN121278751A
An agent data dynamic matching method based on user authority
CN121278751B