Front-end-oriented multi-tenant security isolation and authority control method and system

By combining dynamic routing isolation and a sandbox environment with RBAC and ABAC models, the problems of cross-tenant data leakage and permission logic coupling in front-end multi-tenant applications are solved, fine-grained security isolation and flexible permission control are achieved, and security and resource utilization are improved.

CN120658434APending Publication Date: 2025-09-16INSPUR COMM TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510736001.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-04
Publication Date
2025-09-16

AI Technical Summary

Technical Problem

Existing technologies lack a front-end runtime tenant isolation mechanism in enterprise-level SaaS applications, resulting in cross-tenant data leakage, strong coupling of permission logic and UI that makes dynamic adjustment difficult, and global state management that is easily contaminated, resulting in resource redundancy and high maintenance costs.

Method used

It adopts dynamic routing isolation, component-level permission control and sandbox operating environment, combined with RBAC and ABAC models, and achieves fine-grained security isolation and permission control through tenant identity injection, dynamic desensitization and behavior auditing.

Benefits of technology

It achieves dynamic isolation of front-end multi-tenant applications, prevents cross-tenant data leakage, improves security and resource utilization, supports flexible permission management and low-cost operation and maintenance, and is suitable for highly sensitive data scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120658434A_ABST
    Figure CN120658434A_ABST
Patent Text Reader

Abstract

The invention discloses a front-end-oriented multi-tenant security isolation and authority control method and system, and relates to the technical field of front-end security. Comprising the steps of 1, deploying a dynamic isolation route and a sandboxed UI environment, 2, fusing RBAC and ABAC to carry out fine-grained authority control, 3, carrying out safety management on a request link, 4, deploying a lightweight authentication gateway and carrying out behavior auditing, and 5, carrying out behavior auditing. According to the invention, through dynamic routing isolation, component-level authority control and a sandbox operation environment, security isolation and fine-grained access control of different tenants in front-end applications are realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention discloses a front-end oriented multi-tenant security isolation and authority control method and system, relating to the field of front-end security technology. Background Art

[0002] In current enterprise-level SaaS applications, multi-tenant architectures must ensure that different tenants share the same set of front-end code while also achieving secure isolation of data, functions, and UI. Existing solutions mainly rely on back-end isolation methods, such as database sharding and API permission verification, while the front-end usually adopts coarse-grained permission control, such as role-based page access control, which is difficult to meet the dynamic and fine-grained multi-tenant requirements. Therefore, the existing technology still has the following defects: (1) The front-end lacks a runtime tenant isolation mechanism, which may lead to cross-tenant data leakage; (2) The permission logic is strongly coupled with the UI, making it difficult to adjust dynamically; (3) Global state management is easily contaminated, leading to security risks. In addition, existing solutions often require building separate front-ends for different tenants, resulting in resource redundancy and increased maintenance costs. Summary of the Invention

[0003] This invention addresses the challenges of the existing technology by providing a front-end multi-tenant security isolation and permission control method and system. This method, through dynamic routing isolation, component-level permission control, and a sandboxed runtime environment, enables secure isolation and fine-grained access control for different tenants in front-end applications. This method supports dynamic configuration of tenant policies at runtime, eliminating the problem of strong coupling between permissions and the UI in existing solutions. While ensuring system performance, it effectively prevents cross-tenant data leakage and unauthorized access, providing a secure and flexible front-end multi-tenant solution for SaaS platforms.

[0004] The specific scheme proposed by the present invention is:

[0005] The present invention provides a front-end-oriented multi-tenant security isolation and authority control method, comprising:

[0006] Step 1: Deploy dynamic isolated routing and sandbox UI environment:

[0007] Bind the tenant ID to the route to dynamically embed a unique identifier in the URL path of each tenant.

[0008] Use metadata to drive the UI, where the front end dynamically renders the interface based on tenant permission metadata, hiding or disabling unauthorized components.

[0009] Use sandbox environment to isolate tenants' JavaScript execution environment, combine with content security policy CSP to limit external script loading, and defend against XSS attacks.

[0010] Step 2: Integrate RBAC and ABAC for fine-grained permission control:

[0011] Use role inheritance RBAC to define the role hierarchy, and the child role automatically inherits the basic permissions of the parent role.

[0012] Use attribute extension ABAC to introduce environment attributes to dynamically adjust permissions.

[0013] Step 3: Manage the request link securely:

[0014] Inject tenant ID: embed tenant ID in HTTP request header or JWT token, and use interceptor to verify tenant data ownership through backend microservices.

[0015] Data desensitization: Dynamically desensitize sensitive fields in the response based on roles, and superimpose the tenant ID on the front-end watermark to prevent screenshot leakage.

[0016] Perform secondary verification: verify tenant permissions for key operations through the backend separately.

[0017] Step 4: Deploy a lightweight authentication gateway and conduct a behavior audit:

[0018] Deploy front-end authentication gateway: encapsulate unified permission SDK at the application layer, intercept illegal API requests and return forged responses to confuse attackers.

[0019] Perform operation tracking: record user behavior in the log system, associate tenant ID and timestamp, and perform visual audit through ELK.

[0020] Real-time interception: Trigger secondary authentication and intercept high-risk operations.

[0021] Furthermore, in step 1 of the front-end-oriented multi-tenant security isolation and permission control method, a sandbox environment is used to isolate the tenant's JavaScript execution environment using Web Worker or iframe.

[0022] Furthermore, in step 1 of the front-end multi-tenant security isolation and permission control method, front-end component-level instructions are used to hide or disable unauthorized components in Vue / React.

[0023] Furthermore, in step 2 of the front-end multi-tenant security isolation and authority control method, when role inheritance RBAC is used to define the role hierarchy, the role hierarchy includes super administrators, tenant administrators and ordinary users in sequence.

[0024] The present invention also provides a front-end multi-tenant security isolation and authority control system, including a deployment module, an authority control module, a security management module and a behavior audit module.

[0025] Deploy the module to deploy dynamic isolated routing and sandbox UI environment:

[0026] Bind the tenant ID to the route to dynamically embed a unique identifier in the URL path of each tenant.

[0027] Use metadata to drive the UI, where the front end dynamically renders the interface based on tenant permission metadata, hiding or disabling unauthorized components.

[0028] Use sandbox environment to isolate tenants' JavaScript execution environment, combine with content security policy CSP to limit external script loading, and defend against XSS attacks.

[0029] The permission control module integrates RBAC+ABAC to perform fine-grained permission control:

[0030] Use role inheritance RBAC to define the role hierarchy, and the child role automatically inherits the basic permissions of the parent role.

[0031] Use attribute extension ABAC to introduce environment attributes to dynamically adjust permissions.

[0032] The security management module performs security management on the request link:

[0033] Inject tenant ID: embed tenant ID in HTTP request header or JWT token, and use interceptor to verify tenant data ownership through backend microservices.

[0034] Data desensitization: Dynamically desensitize sensitive fields in the response based on roles, and superimpose the tenant ID on the front-end watermark to prevent screenshot leakage.

[0035] Perform secondary verification: verify tenant permissions for key operations through the backend separately.

[0036] The behavior audit module deploys a lightweight authentication gateway and performs behavior auditing:

[0037] Deploy front-end authentication gateway: encapsulate unified permission SDK at the application layer, intercept illegal API requests and return forged responses to confuse attackers.

[0038] Perform operation tracking: record user behavior in the log system, associate tenant ID and timestamp, and perform visual audit through ELK.

[0039] Real-time interception: Trigger secondary authentication and intercept high-risk operations.

[0040] Furthermore, the deployment module of the front-end multi-tenant security isolation and permission control system utilizes a sandbox environment to adopt Web Worker or iframe to isolate the JavaScript execution environment of the tenant.

[0041] Furthermore, the deployment module of the front-end multi-tenant security isolation and permission control system utilizes front-end component-level instructions to hide or disable unauthorized components in Vue / React.

[0042] Furthermore, when the permission control module of the front-end multi-tenant security isolation and permission control system uses role inheritance RBAC to define the role hierarchy, the role hierarchy includes super administrators, tenant administrators and ordinary users in sequence.

[0043] The benefits of the present invention are:

[0044] (1) Dynamic fine-grained isolation to improve resource utilization and security: Dynamic routing isolation + sandbox UI is used to achieve logical isolation between tenants, avoiding resource waste in existing VLAN / virtual machine solutions and improving resource utilization.

[0045] The front-end sandbox completely blocks cross-tenant data leakage, improving security compared to existing solutions.

[0046] (2) RBAC+ABAC integrated permission model supports complex dynamic authorization: The RBAC+ABAC integrated model achieves triple breakthroughs in the flexibility, security, and ease of use of permission management through static role foundation and dynamic attribute empowerment, becoming the best practice for permission control in modern multi-tenant systems.

[0047] (3) Enhanced security across the entire chain to resist in-depth attacks: Through three layers of protection, namely tenant tag injection, dynamic desensitization, and secondary verification, the present invention achieves breakthroughs in the three key dimensions of data ownership, privacy protection, and operational security, balancing security and ease of use, and is suitable for multi-tenant scenarios with highly sensitive data.

[0048] (4) Lightweight authentication and high-performance auditing, balancing efficiency and compliance: Lightweight authentication gateway: adopts distributed deployment, supports two-way authentication and dynamic policy issuance, and reduces resource consumption. Behavioral auditing: real-time monitoring of user operations, such as file access and network requests, combined with AI anomaly detection, to achieve risk blocking and traceability.

[0049] (5) Flexible expansion and low-cost operation and maintenance: The software-defined isolation solution does not require hardware modification, reducing deployment costs. The dynamic policy model can adapt to multiple scenarios such as edge computing and AI training, reducing management complexity. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] Figure 1 It is a schematic flow chart of the method of the present invention. DETAILED DESCRIPTION

[0051] The present invention will be further described below with reference to the accompanying drawings and specific embodiments so that those skilled in the art can better understand the present invention and implement it. However, the embodiments are not intended to limit the present invention.

[0052] Example 1

[0053] The present invention provides a front-end-oriented multi-tenant security isolation and authority control method, comprising:

[0054] Step 1: Deploy dynamic isolated routing and sandbox UI environment:

[0055] Bind the tenant ID to the route to dynamically embed a unique identifier in each tenant's URL path, such as / tenant / {tenant_id} / dashboard. Code example:

[0056]

[0057] Use metadata to drive the UI, where the front-end dynamically renders the interface based on tenant permission metadata, such as functional modules and field visibility, and uses front-end component-level instructions to implement it in Vue / React<SecureComponent:role="'admin'":env="time> 9:00">, to hide or disable unauthorized components, code example:

[0058]

[0059]

[0060] Leverage a sandboxed environment to use Web Workers or iframes to isolate tenants' JavaScript execution environments, and combine them with Content Security Policy (CSP) to restrict external script loading and defend against XSS attacks.

[0061] Step 2: Integrate RBAC and ABAC for fine-grained permission control:

[0062] Use role inheritance RBAC to define the role hierarchy, which includes super administrators, tenant administrators, and ordinary users. Child roles automatically inherit the basic permissions of the parent role.

[0063] Use attribute extension ABAC to introduce environment attributes to dynamically adjust permissions.

[0064] Step 3: Manage the request link securely:

[0065] Inject tenant ID: embed tenant ID in HTTP request header such as X-Tenant-ID or JWT token, and use interceptors to verify tenant data ownership through backend microservices.

[0066] Data desensitization: For sensitive fields in the response, such as mobile phone numbers, dynamic desensitization is performed based on the role, and the tenant ID is superimposed on the front-end watermark to prevent screenshot leakage.

[0067] Perform secondary verification: For key operations such as deletion, verify tenant permissions separately through the backend.

[0068] Step 4: Deploy a lightweight authentication gateway and conduct a behavior audit:

[0069] Deploy a front-end authentication gateway: encapsulate a unified permission SDK at the application layer, intercept illegal API requests such as unauthorized POST / api / v1 / delete and return a forged response such as 404 Not Found to confuse attackers.

[0070] Perform operation tracking: record user behaviors such as button clicks and data exports to the log system, associate tenant IDs with timestamps, and perform visual audits through ELK.

[0071] Real-time interception: Intercept high-risk operations such as batch export and trigger secondary authentication such as SMS verification code.

[0072] Example 2

[0073] The present invention also provides a front-end multi-tenant security isolation and authority control system, including a deployment module, an authority control module, a security management module and a behavior audit module.

[0074] Deploy the module to deploy dynamic isolated routing and sandbox UI environment:

[0075] Bind the tenant ID to the route to dynamically embed a unique identifier in the URL path of each tenant.

[0076] Use metadata to drive the UI, where the front end dynamically renders the interface based on tenant permission metadata, hiding or disabling unauthorized components.

[0077] Use sandbox environment to isolate tenants' JavaScript execution environment, combine with content security policy CSP to limit external script loading, and defend against XSS attacks.

[0078] The permission control module integrates RBAC+ABAC to perform fine-grained permission control:

[0079] Use role inheritance RBAC to define the role hierarchy, and the child role automatically inherits the basic permissions of the parent role.

[0080] Use attribute extension ABAC to introduce environment attributes to dynamically adjust permissions.

[0081] The security management module performs security management on the request link:

[0082] Inject tenant ID: embed tenant ID in HTTP request header or JWT token, and use interceptor to verify tenant data ownership through backend microservices.

[0083] Data desensitization: Dynamically desensitize sensitive fields in the response based on roles, and superimpose the tenant ID on the front-end watermark to prevent screenshot leakage.

[0084] Perform secondary verification: verify tenant permissions for key operations through the backend separately.

[0085] The behavior audit module deploys a lightweight authentication gateway and performs behavior auditing:

[0086] Deploy front-end authentication gateway: encapsulate unified permission SDK at the application layer, intercept illegal API requests and return forged responses to confuse attackers.

[0087] Perform operation tracking: record user behavior in the log system, associate tenant ID and timestamp, and perform visual audit through ELK.

[0088] Real-time interception: Trigger secondary authentication and intercept high-risk operations.

[0089] The information interaction, execution process and other contents between the modules in the above system are based on the same concept as the embodiment of the method of the present invention. For specific contents, please refer to the description in the embodiment of the method of the present invention and will not be repeated here.

[0090] Likewise, the system of the present invention is beneficial in that:

[0091] (1) Dynamic fine-grained isolation to improve resource utilization and security: Dynamic routing isolation + sandbox UI is used to achieve logical isolation between tenants, avoiding resource waste in existing VLAN / virtual machine solutions and improving resource utilization.

[0092] The front-end sandbox completely blocks cross-tenant data leakage, improving security compared to existing solutions.

[0093] (2) RBAC+ABAC integrated permission model supports complex dynamic authorization: The RBAC+ABAC integrated model achieves triple breakthroughs in the flexibility, security, and ease of use of permission management through static role foundation and dynamic attribute empowerment, becoming the best practice for permission control in modern multi-tenant systems.

[0094] (3) Enhanced security across the entire chain to resist in-depth attacks: Through three layers of protection, namely tenant tag injection, dynamic desensitization, and secondary verification, the present invention achieves breakthroughs in the three key dimensions of data ownership, privacy protection, and operational security, balancing security and ease of use, and is suitable for multi-tenant scenarios with highly sensitive data.

[0095] (4) Lightweight authentication and high-performance auditing, balancing efficiency and compliance: Lightweight authentication gateway: adopts distributed deployment, supports two-way authentication and dynamic policy issuance, and reduces resource consumption. Behavioral auditing: real-time monitoring of user operations, such as file access and network requests, combined with AI anomaly detection, to achieve risk blocking and traceability.

[0096] (5) Flexible expansion and low-cost operation and maintenance: The software-defined isolation solution does not require hardware modification, reducing deployment costs. The dynamic policy model can adapt to multiple scenarios such as edge computing and AI training, reducing management complexity.

[0097] It should be noted that not all steps and modules in the above-mentioned processes and system structures are required, and certain steps or modules can be omitted according to actual needs. The execution order of each step is not fixed and can be adjusted as needed. The system structure described in the above-mentioned embodiments can be a physical structure or a logical structure, that is, some modules may be implemented by the same physical entity, or some modules may be implemented by multiple physical entities, or may be implemented by certain components in multiple independent devices.

[0098] The above embodiments are merely preferred embodiments for the purpose of fully illustrating the present invention, and the scope of protection of the present invention is not limited thereto. Equivalent substitutions or modifications made by those skilled in the art based on the present invention are within the scope of protection of the present invention. The scope of protection of the present invention shall be subject to the claims.

Claims

1. A front-end multi-tenant security isolation and permission control method, characterized by include: Step 1: Deploy dynamic isolated routing and sandbox UI environment: Bind the tenant ID to the route to dynamically embed a unique identifier in the URL path of each tenant. Use metadata to drive the UI, where the front end dynamically renders the interface based on tenant permission metadata, hiding or disabling unauthorized components. Use sandbox environment to isolate tenants' JavaScript execution environment, combine with content security policy CSP to limit external script loading, and defend against XSS attacks. Step 2: Integrate RBAC and ABAC for fine-grained permission control: Use role inheritance RBAC to define the role hierarchy, and the child role automatically inherits the basic permissions of the parent role. Use attribute extension ABAC to introduce environment attributes to dynamically adjust permissions. Step 3: Manage the request link securely: Inject tenant ID: embed tenant ID in HTTP request header or JWT token, and use interceptor to verify tenant data ownership through backend microservices. Data desensitization: Dynamically desensitize sensitive fields in the response based on roles, and superimpose the tenant ID on the front-end watermark to prevent screenshot leakage. Perform secondary verification: verify tenant permissions for key operations through the backend separately. Step 4: Deploy a lightweight authentication gateway and conduct a behavior audit: Deploy front-end authentication gateway: encapsulate unified permission SDK at the application layer, intercept illegal API requests and return forged responses to confuse attackers. Perform operation tracking: record user behavior in the log system, associate tenant ID and timestamp, and perform visual audit through ELK. Real-time interception: Trigger secondary authentication and intercept high-risk operations.

2. A front-end multi-tenant security isolation and authority control method according to claim 1, characterized in that In step 1, a sandbox environment is used to isolate the tenant's JavaScript execution environment using Web Workers or iframes.

3. A front-end multi-tenant security isolation and permission control method according to claim 1, characterized in that in step 1, front-end component-level instructions are used to hide or disable unauthorized components in Vue / React.

4. A front-end multi-tenant security isolation and authority control method according to claim 1, characterized in that When using role inheritance RBAC to define the role hierarchy in step 2, the role hierarchy includes super administrators, tenant administrators, and common users in that order.

5. A front-end multi-tenant security isolation and authority control system, characterized by Including deployment module, permission control module, security management module and behavior audit module, Deploy the module to deploy dynamic isolated routing and sandbox UI environment: Bind the tenant ID to the route to dynamically embed a unique identifier in the URL path of each tenant. Use metadata to drive the UI, where the front end dynamically renders the interface based on tenant permission metadata, hiding or disabling unauthorized components. Use sandbox environment to isolate tenants' JavaScript execution environment, combine with content security policy CSP to limit external script loading, and defend against XSS attacks. The permission control module integrates RBAC+ABAC to perform fine-grained permission control: Use role inheritance RBAC to define the role hierarchy, and the child role automatically inherits the basic permissions of the parent role. Use attribute extension ABAC to introduce environment attributes to dynamically adjust permissions. The security management module performs security management on the request link: Inject tenant ID: embed tenant ID in HTTP request header or JWT token, and use interceptor to verify tenant data ownership through backend microservices. Data desensitization: Dynamically desensitize sensitive fields in the response based on roles, and superimpose the tenant ID on the front-end watermark to prevent screenshot leakage. Perform secondary verification: verify tenant permissions for key operations through the backend separately. The behavior audit module deploys a lightweight authentication gateway and performs behavior auditing: Deploy front-end authentication gateway: encapsulate unified permission SDK at the application layer, intercept illegal API requests and return forged responses to confuse attackers. Perform operation tracking: record user behavior in the log system, associate tenant ID and timestamp, and perform visual audit through ELK. Real-time interception: Trigger secondary authentication and intercept high-risk operations.

6. A front-end multi-tenant security isolation and authority control system according to claim 5, characterized in that The deployment module utilizes a sandboxed environment to isolate the tenant's JavaScript execution environment using Web Workers or iframes.

7. A front-end multi-tenant security isolation and authority control system according to claim 5, characterized in that The deployment module uses front-end component-level instructions to hide or disable unauthorized components in Vue / React.

8. A front-end multi-tenant security isolation and authority control system according to claim 5, characterized in that When the permission control module uses role inheritance RBAC to define the role hierarchy, the role hierarchy includes super administrators, tenant administrators, and ordinary users in sequence.

Citation Information

Cited By

  • Hybrid authentication method based on gateway request

    CN121125361A