Integrated authority management method and device based on integrated architecture and medium
Through the integrated permission management method under the integrated architecture, the problems of identity data dispersion and chaotic permission management in a multi-system environment are solved, centralized and unified management of users, applications and permissions is achieved, system security and operation and maintenance efficiency are improved, compliance requirements are met, flexible menu configuration and single sign-on are provided, and the user experience is improved.
Patent Information
- Application Number
- CN202510818812.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-18
- Publication Date
- 2025-09-26
AI Technical Summary
In a multi-system environment, user identity data is scattered, resulting in complex identity management, chaotic authority management, high security risks and insufficient compliance. Existing systems find it difficult to achieve unified management and flexible control.
Adopting an integrated permission management method under an integrated architecture, we build an integrated collaborative architecture mechanism through unified application, user, authorization, authentication and audit strategies to achieve centralized and unified management of users, applications and permissions. Combined with strict password policies and permission control, we prevent unauthorized access and data leakage.
It improves system security, simplifies management processes, reduces management costs, improves operation and maintenance efficiency, meets compliance requirements of regulations and industry standards, and enhances user experience.
Smart Images

Figure CN120705892A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data resource authorization, and in particular to an integrated rights management method, device, and medium based on an integrated architecture. Background Art
[0002] In today's multi-system environment, user identity data is scattered across independent systems such as HR, OA, and CRM, creating "identity silos." Enterprises generally face inefficient account lifecycle management due to complex identity types and frequent employee turnover. Different identity storage standards across different systems lead to data inconsistencies. For example, the same user's account information in the HR system and the OA system may conflict.
[0003] In traditional data rights management, there are still problems such as lagging rights management mechanisms, security certification system defects, and compliance technology gaps. For example: 1. Identity management challenges: In a multi-system, multi-platform environment, user identity information is dispersed, and user data is inconsistent across different systems, making identity management complex and inefficient.
[0004] 2. Permission management dilemma: Traditional permission management methods are difficult to meet the needs of complex business scenarios. They suffer from problems such as redundant permissions and inaccurate allocation, and cannot achieve flexible permission control and dynamic adjustment.
[0005] 3. Significant security risks: The system faces security risks such as unauthorized access and data leakage. The lack of effective security authentication and auditing mechanisms makes it difficult to ensure the security of sensitive data.
[0006] 4. Compliance Challenges: The existing system has shortcomings in terms of compliance, as it needs to meet the requirements of numerous regulations and industry standards for unified auditing and rights management. Summary of the Invention
[0007] The present invention provides an integrated rights management method, device, and medium based on an integrated architecture. The method is used to address the following technical issues: In existing data authorization management, there are problems such as difficulty in managing identity data, confusion in rights management, and difficulty in unifying audit management.
[0008] The embodiments of this application adopt the following technical solutions: On the one hand, an embodiment of the present application provides an integrated permission management method based on an integrated architecture, including: managing and configuring application data in the operation and maintenance monitoring system in relation to application users and application permission data to obtain a unified application management strategy; managing and configuring user data in the operation and maintenance monitoring system under the user subject to obtain a unified user management strategy; managing and configuring authorization data in the operation and maintenance monitoring system in relation to a unified authorization management strategy under the role management architecture to obtain a unified authorization management strategy; managing and configuring login data in the operation and maintenance monitoring system in relation to an authentication strategy to obtain a unified authentication management strategy; managing and configuring audit data in the operation and maintenance monitoring system in relation to recording and tracking to obtain a unified audit management strategy; integrating and constructing an integrated collaborative architecture mechanism based on the unified application management strategy, the unified user management strategy, the unified authorization management strategy, the unified authentication management strategy and the unified audit management strategy to achieve integrated management of business data in the operation and maintenance monitoring system.
[0009] The embodiments of this application effectively prevent unauthorized access and data leakage through a unified authentication and authorization mechanism, combined with strict password policies and permission control, to ensure system and data security. It enables centralized and unified management of users, applications, and permissions, simplifies management processes, reduces management costs, and improves operation and maintenance efficiency. It also meets the requirements of various laws and industry standards for auditing and permission management, ensuring compliance with business regulations. It provides single sign-on and personalized login jumps, as well as flexible menu configuration, to enhance user convenience and satisfaction in using the system.
[0010] In a feasible implementation, the application data in the operation and maintenance monitoring system is managed and configured with respect to application users and application permission data to obtain a unified application management strategy, which specifically includes: identifying the type of the accessed application data; if the application data is already accessed application data, directly generating an application token and a key; if the application data is newly added and not accessed application data, configuring the corresponding modification data parameters, and generating an application access management strategy; controlling the application user's permission application and direct access to application permission data according to the preset application permissions and access whitelist, and formulating an application store strategy; approving and updating the authorization period of the user application information in the application data to determine the application application strategy; displaying and recording the user access information in the application data and counting the number of visits to determine the application access audit strategy; combining the application access management strategy, the application store strategy, the application access audit strategy, and the application application strategy to obtain the unified application management strategy.
[0011] In a feasible implementation manner, the user data in the operation and maintenance monitoring system is managed and configured under the user subject to obtain a unified user management strategy, which specifically includes: performing account management control on the user data to obtain a user management strategy; wherein the account management control includes at least: account binding, role assignment, and permission configuration; performing message tracking flow under the synchronous message sending and receiving records on the user data, and configuring message distribution rules under the synchronous message distribution settings on the user data to determine the user synchronization strategy; performing functional association configuration on the organizational structure corresponding to the user data to determine the organizational management strategy; performing approval display configuration on the user data for user account application information to determine the user approval strategy; combining the user management strategy, the user synchronization strategy, the organizational management strategy, and the user approval strategy to obtain the unified user management strategy.
[0012] In a feasible implementation manner, the authorization data in the operation and maintenance monitoring system is subjected to unified authorization management configuration under the relevant role management architecture to obtain a unified authorization management strategy, which specifically includes: performing permission allocation and user authorization control on the assigned role data corresponding to the authorization data to determine the role management strategy; performing functional configuration on the system menu hierarchy structure corresponding to the authorization data to determine the functional management strategy; wherein the functional management strategy at least includes: adding and managing menus, functions, operations and URLs at different levels; performing functional configuration on the role group under the organizational structure of the assigned role data to determine the role group management strategy; wherein the role group management strategy at least includes: viewing role information, role authorization and adding roles to groups; performing temporary transfer control on the authorization data to determine the authority delegation strategy; performing functional configuration on the management menu corresponding to the authorization data to determine the menu classification management strategy; performing priority configuration on the menu homepage corresponding to the assigned role data to determine the role menu mapping strategy; and combining the role management strategy, function management strategy, role group management strategy, authority delegation strategy, menu classification management strategy and role menu mapping strategy to obtain the unified authorization management strategy.
[0013] In a feasible implementation, the authentication policy management and configuration is performed on the login data in the operation and maintenance monitoring system to obtain a unified authentication management policy, which specifically includes: customizing the login page corresponding to the login data to determine the login page configuration policy; automatically jumping the login data according to the user authority type matching to determine the login jump management configuration policy; performing hierarchical management rule control on the management policy of the login data to determine the hierarchical management policy; combining the login page configuration policy, the login jump management configuration policy and the hierarchical management policy to obtain the unified authentication management policy.
[0014] In a feasible implementation, the audit data in the operation and maintenance monitoring system is recorded and tracked under management configuration to obtain a unified audit management strategy, which specifically includes: configuring the audit data into visual charts to determine the operation overview strategy; recording and processing the user login information in the audit data according to preset query conditions and statistical overviews to determine the user login audit strategy; recording and tracking the security operation data in the audit data to determine the operation log strategy; and combining the operation overview strategy, the user login audit strategy and the operation log strategy to obtain the unified audit management strategy.
[0015] In a feasible implementation, based on the unified application management policy, the unified user management policy, the unified authorization management policy, the unified authentication management policy and the unified audit management policy, an integrated collaborative architecture mechanism is integrated and constructed, specifically including: collaboratively controlling the unified application management policy, the unified user management policy, the unified authorization management policy, the unified authentication management policy and the unified audit management policy on the same platform, and obtaining a business integration center management platform; based on the business integration center management platform, constructing the integrated collaborative architecture mechanism for visually managing the operation and maintenance monitoring system.
[0016] In a feasible implementation, each user is assigned a role through a role-based access control mechanism, and each role is granted corresponding permissions to drive the execution of the unified authorization management strategy; through the management identity of the strategy, the permission management mode in each strategy in the integrated collaborative architecture mechanism is driven and controlled.
[0017] In the second aspect, an embodiment of the present application also provides an integrated permission management device based on an integrated architecture, the device comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions that can be executed by the at least one processor so that the at least one processor can execute an integrated permission management method based on an integrated architecture as described in any of the above embodiments.
[0018] In a third aspect, an embodiment of the present application also provides a non-volatile computer storage medium, which is a non-volatile computer-readable storage medium. The non-volatile computer-readable storage medium stores at least one program, each of which includes instructions. When the instructions are executed by the terminal, the terminal executes an integrated permission management method based on an integrated architecture as described in any of the above embodiments.
[0019] This application provides an integrated rights management method, device, and medium based on an integrated architecture. Compared with the existing technology, the embodiments of this application have the following beneficial technical effects: 1. Improved security: Through a unified authentication and authorization mechanism, combined with strict password policies and permission control, unauthorized access and data leakage are effectively prevented, ensuring system and data security.
[0020] 2. Improve management efficiency: Implement centralized and unified management of users, applications, and permissions, simplify management processes, reduce management costs, and improve operation and maintenance efficiency.
[0021] 3. Enhanced compliance: Meet the audit and authority management requirements of various regulations and industry standards to ensure business compliance.
[0022] 4. Optimize user experience: Provide single sign-on and personalized login jump, as well as flexible menu configuration, to improve user convenience and satisfaction in using the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments described in the present application. For those skilled in the art, other drawings can be obtained based on these drawings without creative work. In the drawings: Figure 1 A flowchart of an integrated rights management method based on an integrated architecture provided in an embodiment of the present application; Figure 2 An interface display diagram of a 5A architecture provided in an embodiment of the present application; Figure 3 A schematic diagram of the structure of an integrated rights management device based on an integrated architecture provided in an embodiment of the present application. DETAILED DESCRIPTION
[0024] In order to enable those skilled in the art to better understand the technical solutions in this application, the following will clearly and completely describe the technical solutions in the embodiments of this application in conjunction with the drawings in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments of this specification, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of this application.
[0025] It should be noted that this application discloses a permission management and auditing method for a business integration center based on the 5A architecture. This method implements full lifecycle management of applications through a unified application module, including application access, store management, application approval, and access auditing; a unified user module manages and synchronizes users and organizations; a unified authorization module implements precise permission management based on RBAC and PMI; a unified authentication module provides single sign-on and flexible authentication strategies; and a unified audit module collects and analyzes logs to ensure system security. This method solves problems such as identity dispersion, complex permission management, and security vulnerabilities in a multi-system environment, improves system security and operation and maintenance efficiency, meets compliance requirements, and provides strong support for the efficient operation of the business integration center.
[0026] The present invention provides an integrated rights management method based on an integrated architecture. Figure 1 As shown, the integrated rights management method based on the integrated architecture specifically includes steps S101-S106: S101: Manage and configure application user and application permission data in the operation and maintenance monitoring system to obtain a unified application management strategy.
[0027] Specifically, the type of the accessed application data is first identified.
[0028] Furthermore, if the application data is already connected, an application token and key are directly generated. If the application data is newly added and not yet connected, relevant modified data parameters are configured and an application access management policy is generated.
[0029] Furthermore, based on the preset application permissions and access whitelist, the application users are controlled in terms of permission application and direct access to application permission data, and an application store strategy is formulated.
[0030] Furthermore, the authorization period of the user application information in the application data is reviewed and updated to determine the application application strategy.
[0031] Furthermore, the user access information in the application data is displayed and recorded, and the number of accesses is counted to determine the application access audit strategy.
[0032] Furthermore, the application access management policy, application store policy, application access audit policy and application application policy are combined to obtain a unified application management policy.
[0033] In one embodiment, Figure 2 This is an interface display diagram of a 5A architecture provided in an embodiment of the present application, such as Figure 2As shown in the figure, in the unified application management strategy, you can configure (1) Application Access: maintain and display information about connected applications, and issue application tokens and keys. When adding a new application, fill in basic information and subsequently complete other information; when editing an application, you can modify various configurations. (2) Application Store: centrally manage application data. Administrators set application permissions and access whitelists. Users apply for permissions or directly access applications. (3) Application Application: manage user application information. Administrators can approve and update the authorization period. Click the application name to view detailed information. (4) Application Access Audit: record and display user access information, and count the number of visits to each application to facilitate the understanding of application usage.
[0034] S102: Perform management configuration on user data in the operation and maintenance monitoring system under the user subject to obtain a unified user management strategy.
[0035] Specifically, account management and control are performed on user data to obtain a user management policy, wherein account management and control at least include: account binding, role allocation, and permission configuration.
[0036] Furthermore, the message tracking flow under the synchronization message sending and receiving record is performed on the user data, and the message distribution rule configuration under the synchronization message distribution setting is performed on the user data to determine the user synchronization strategy.
[0037] Furthermore, the organizational structure corresponding to the user data is functionally associated and configured to determine the organizational management strategy.
[0038] Furthermore, the user data is configured for approval and display of user account application information to determine the user approval strategy.
[0039] Furthermore, the user management policy, user synchronization policy, organization management policy and user approval policy are combined to obtain a unified user management policy.
[0040] In one embodiment, if Figure 2 As shown in the figure, in the unified user management strategy, you can configure (1) User Management: unified maintenance of user accounts, profiles, functions and data permissions, and other information, and can perform operations such as account binding, role assignment, and permission configuration. (2) User Synchronization: consists of synchronizing message sending and receiving records and distribution settings. The former tracks message flow, and the latter configures message distribution rules. (3) Organization Management: includes organization type maintenance, organization management, organizational structure rule maintenance, and job level information maintenance, supporting flexible adjustment of organizational structure. (4) User Approval: Displays user account application information, and administrators perform approval operations.
[0041] S103: Perform unified authorization management configuration under the relevant role management architecture on the authorization data in the operation and maintenance monitoring system to obtain a unified authorization management strategy.
[0042] Specifically, permission allocation and user authorization control are performed on the assigned role data corresponding to the authorization data to determine a role management strategy.
[0043] Furthermore, the system menu hierarchy structure corresponding to the authorization data is functionally configured to determine a function management strategy, wherein the function management strategy at least includes: adding and managing menus, functions, operations, and URLs at different levels.
[0044] Furthermore, the assigned role data is used to configure the functions of the role group under the organization to determine the role group management strategy, wherein the role group management strategy at least includes: viewing role information, role authorization, and adding roles to the group.
[0045] Furthermore, the authorization data is temporarily transferred and controlled to determine the authority delegation strategy.
[0046] Furthermore, the management menu corresponding to the authorization data is functionally configured to determine a menu classification management strategy.
[0047] Furthermore, the menu homepage corresponding to the assigned role data is prioritized to determine a role menu mapping strategy.
[0048] Furthermore, the role management strategy, function management strategy, role group management strategy, authority delegation strategy, menu classification management strategy and role menu mapping strategy are combined to obtain a unified authorization management strategy.
[0049] In one embodiment, Figure 2 As shown, the unified authorization management strategy can be configured to: (1) Role management: comprehensively manage system roles, support batch authorization, add, edit and delete roles, and assign permissions and user authorization to roles. (2) Function management: maintain the menu hierarchy structure of the application system, add and manage menus, functions, operations and URLs at different levels. (3) Role group management: manage role groups under the organization, view role information, perform role authorization and add roles to group operations. (4) Authority delegation: users can temporarily grant authority to others, specify agents, agent types and time ranges. (5) Menu category management: centrally manage menus, provide multiple ways to add and edit menu items, and enhance operational flexibility. (6) Role menu mapping: configure the default menu homepage displayed after the role logs in, set priority to achieve a personalized experience. (7) Management delegation: the current user can delegate some permissions to other users, create delegation events and authorize.
[0050] S104: Perform management and configuration of authentication policies on the login data in the operation and maintenance monitoring system to obtain a unified authentication management policy.
[0051] Specifically, the login page corresponding to the login data is customized and configured to determine a login page configuration strategy.
[0052] Furthermore, according to the user authority type matching, the login data is automatically redirected to determine the login redirection management configuration strategy.
[0053] Furthermore, the login data is controlled by hierarchical management rules of the management strategy to determine the hierarchical management strategy.
[0054] Furthermore, the login page configuration policy, the login jump management configuration policy and the hierarchical management policy are combined to obtain a unified authentication management policy.
[0055] In one embodiment, Figure 2 As shown in the figure, the unified authentication management policy can be configured as follows: (1) Login page configuration: Centrally manage the login page, support custom design and preview, and improve user experience. (2) Login jump management: Match the user's permission type to automatically jump to the preset address after login. (3) Policy management: Divided into global policy and user policy, respectively set password strength, account lockout and user-specific management rules.
[0056] S105. Record and track the audit data in the operation and maintenance monitoring system and configure management to obtain a unified audit management strategy.
[0057] Specifically, the audit data is visualized and configured into charts to determine the operational overview strategy.
[0058] Furthermore, based on the preset query conditions and statistical overview, the user login information in the audit data is recorded and processed to determine the user login audit strategy.
[0059] Furthermore, security operation data in audit data is recorded and tracked to determine the operation log strategy.
[0060] Furthermore, the operation overview policy, user login audit policy and operation log policy are combined to obtain a unified audit management policy.
[0061] In one embodiment, Figure 2 As shown, the unified audit management strategy can be configured as follows: (1) Operation Overview: This uses visual charts to display the system operation status, helping users quickly understand the overall system situation. (2) User Login Audit: This records user login information, allows conditional queries and generates statistical overviews, and helps users understand user activity. (3) Operation Log: This records security-related operations, displays them in a list, and allows users to view details to prevent and track illegal operations.
[0062] S106. Based on the unified application management strategy, unified user management strategy, unified authorization management strategy, unified authentication management strategy and unified audit management strategy, an integrated collaborative architecture mechanism is integrated and constructed to achieve integrated management of business data in the operation and maintenance monitoring system.
[0063] Specifically, unified application management strategy, unified user management strategy, unified authorization management strategy, unified authentication management strategy, and unified audit management strategy are collaboratively controlled on the same platform, resulting in a business integration center management platform. In other words, these five strategies are not isolated; they are deeply integrated and linked in real time on the business integration center management platform. For example: (1) Data flow coordination: User management provides user identity information for authentication and authorization. Application management provides application object information for authorization and auditing. After the user logs in, the authentication service passes the authentication assertion / token to the authorization service and the application that needs access. The authorization service makes access decisions based on the user identity (from user management / authentication), application information (from application management), and policy rules, and passes the results (allow / deny) to the application (PEP) and audit. All key operations (user creation, policy changes, login attempts, authorization decisions, application access) send events to the audit service.
[0064] (2) Policy collaboration: Policies can reference each other. For example, authorization policies can dynamically make decisions based on user attributes (from user management), authentication strength (from authentication management), and the accessed application (from application management). Audit policies can define which events (from all other modules) need to be recorded and the conditions that trigger alarms.
[0065] (3) Lifecycle Collaboration: User resignation (disabled in user management): automatically triggers session termination in the authentication service, permission revocation in the authorization service, and access disabling in application management (via provisioning synchronization), all of which are audited and recorded. New application launch (registered in application management): automatically triggers initial configuration of authorization policies and subscription configuration for audit events. Policy changes (modified in authorization management): immediately impact subsequent access decisions, and the changes themselves are audited and recorded.
[0066] Furthermore, based on the business integration center management platform, an integrated collaborative architecture mechanism for visual management, operation and maintenance monitoring system is constructed.
[0067] As a feasible implementation method, Figure 2As shown, role-based access control mechanisms can be used to assign roles to each user and grant corresponding permissions to each role, thereby driving the execution of unified authorization management policies. Policy management identities can also be used to drive and control the permission management models within each policy within the integrated collaborative architecture mechanism. In other words, the collaborative working mechanism of various modules within the 5A architecture mechanism (integrated collaborative architecture mechanism) enables integrated management of identity, permissions, authentication, and auditing. Furthermore, permission management models based on RBAC (Role-Based Access Control) and PMI (Privilege Management Infrastructure) are available, along with flexible permission delegation and menu mapping capabilities. Finally, a unified audit module's log collection, analysis, and display mechanisms ensure secure system operation.
[0068] In addition, the embodiment of the present application also provides an integrated rights management device based on an integrated architecture, such as Figure 3 As shown, the integrated rights management device based on the integrated architecture specifically includes: At least one processor 301. And a memory 302 in communication with the at least one processor 301. The memory 302 stores instructions that can be executed by the at least one processor 301, so that the at least one processor 301 can execute: Manage and configure application user and application permission data in the operation and maintenance monitoring system to obtain a unified application management strategy; Perform management configuration on user data in the operation and maintenance monitoring system under the user subject to obtain a unified user management strategy; Perform unified authorization management configuration under the relevant role management architecture for the authorization data in the operation and maintenance monitoring system to obtain a unified authorization management strategy; Manage and configure authentication strategies for login data in the operation and maintenance monitoring system to obtain a unified authentication management strategy; Record and track the management configuration of audit data in the operation and maintenance monitoring system to obtain a unified audit management strategy; Based on unified application management strategy, unified user management strategy, unified authorization management strategy, unified authentication management strategy and unified audit management strategy, an integrated collaborative architecture mechanism is integrated and constructed to achieve integrated management of business data in the operation and maintenance monitoring system.
[0069] The embodiments of this application effectively prevent unauthorized access and data leakage through a unified authentication and authorization mechanism, combined with strict password policies and permission control, to ensure system and data security. It enables centralized and unified management of users, applications, and permissions, simplifies management processes, reduces management costs, and improves operation and maintenance efficiency. It also meets the requirements of various laws and industry standards for auditing and permission management, ensuring compliance with business regulations. It provides single sign-on and personalized login jumps, as well as flexible menu configuration, to enhance user convenience and satisfaction in using the system.
[0070] The various embodiments in this application are described in a progressive manner. Similar portions between the various embodiments can be referred to in conjunction with each other. Each embodiment focuses on the differences between the other embodiments. In particular, the device and medium embodiments are generally similar to the method embodiments, so their descriptions are relatively simple. For relevant portions, refer to the descriptions of the method embodiments.
[0071] The devices and media provided in the embodiments of the present application correspond one-to-one to the methods. Therefore, the devices and media also have similar beneficial technical effects to their corresponding methods. Since the beneficial technical effects of the methods have been described in detail above, the beneficial technical effects of the devices and media will not be repeated here.
[0072] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0073] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0074] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0075] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 The steps for the function specified in one or more boxes.
[0076] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.
[0077] Memory may include non-permanent storage in a computer-readable medium, in the form of random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of a computer-readable medium.
[0078] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can be implemented using any method or technology for information storage. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change RAM (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic disk storage or other magnetic storage devices, or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media, such as modulated data signals and carrier waves.
[0079] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.
[0080] The foregoing is merely an embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application may have various modifications and variations. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application should all be included within the scope of the specification of the present application.
Claims
1. An integrated rights management method based on an integrated architecture, characterized in that: The method comprises: Manage and configure application user and application permission data in the operation and maintenance monitoring system to obtain a unified application management strategy; Perform management configuration on user data in the operation and maintenance monitoring system under the user subject to obtain a unified user management strategy; Performing unified authorization management configuration under the relevant role management architecture on the authorization data in the operation and maintenance monitoring system to obtain a unified authorization management strategy; Performing management and configuration of authentication strategies on the login data in the operation and maintenance monitoring system to obtain a unified authentication management strategy; Record and track the audit data in the operation and maintenance monitoring system to obtain a unified audit management strategy; Based on the unified application management strategy, the unified user management strategy, the unified authorization management strategy, the unified authentication management strategy and the unified audit management strategy, an integrated collaborative architecture mechanism is integrated and constructed to achieve integrated management of business data in the operation and maintenance monitoring system.
2. The integrated authority management method based on an integrated architecture according to claim 1 is characterized in that: Manage and configure application user and application permission data in the operation and maintenance monitoring system to obtain a unified application management strategy, including: Identifying the type of the accessed application data; If the application data is already connected application data, an application token and key are directly generated; if the application data is newly added and not yet connected application data, relevant modification data parameters are configured accordingly, and an application access management policy is generated; According to the preset application permissions and access whitelist, control the application user's permission application and direct access to application permission data, and formulate an application store strategy; Approving and updating the authorization period of the user application information in the application data to determine the application application strategy; Display and record user access information in the application data and count the number of visits to determine the application access audit strategy; The application access management policy, the application store policy, the application access audit policy, and the application application policy are combined to obtain the unified application management policy.
3. The integrated authority management method based on an integrated architecture according to claim 1 is characterized in that: Perform management configuration on the user data in the operation and maintenance monitoring system under the user subject to obtain a unified user management strategy, specifically including: Performing account management control on the user data to obtain a user management policy; wherein the account management control includes at least: account binding, role assignment, and permission configuration; Tracking the message flow under the synchronization message sending and receiving records for the user data, and configuring the message distribution rules under the synchronization message distribution settings for the user data to determine the user synchronization strategy; Performing functional association configuration on the organizational structure corresponding to the user data to determine an organizational management strategy; Performing approval display configuration on the user data related to the user account application information to determine the user approval strategy; The user management policy, the user synchronization policy, the organization management policy, and the user approval policy are combined to obtain the unified user management policy.
4. The integrated authority management method based on an integrated architecture according to claim 1 is characterized in that: Perform unified authorization management configuration under the relevant role management architecture on the authorization data in the operation and maintenance monitoring system to obtain a unified authorization management strategy, specifically including: Performing authority allocation and user authorization control on the assigned role data corresponding to the authorization data to determine a role management strategy; Performing functional configuration on the system menu hierarchy structure corresponding to the authorization data to determine a functional management strategy; wherein the functional management strategy at least includes: adding and managing menus, functions, operations, and URLs at different levels; Performing functional configuration of the role group under the organizational structure on the assigned role data to determine a role group management strategy; wherein the role group management strategy at least includes: viewing role information, role authorization, and adding roles to a group; Temporarily transfer the authorization data and determine the authority delegation strategy; Perform functional configuration on the management menu corresponding to the authorization data to determine a menu classification management strategy; Prioritize the menu homepage corresponding to the assigned role data to determine a role menu mapping strategy; The role management policy, function management policy, role group management policy, authority delegation policy, menu classification management policy and role menu mapping policy are combined to obtain the unified authorization management policy.
5. The integrated authority management method based on an integrated architecture according to claim 1 is characterized in that: Perform authentication policy management and configuration on the login data in the operation and maintenance monitoring system to obtain a unified authentication management policy, specifically including: Customize the login page corresponding to the login data to determine the login page configuration strategy; According to the user authority type matching, the login data is automatically redirected to determine the login jump management configuration strategy; Performing hierarchical management rule control on the login data to determine a hierarchical management strategy; The login page configuration policy, the login jump management configuration policy and the hierarchical management policy are combined to obtain the unified authentication management policy.
6. The integrated authority management method based on an integrated architecture according to claim 1 is characterized in that: The management configuration under recording and tracking of audit data in the operation and maintenance monitoring system is used to obtain a unified audit management strategy, which specifically includes: Configure visualization charts for the audit data to determine an operational overview strategy; According to the preset query conditions and statistical overview, the user login information in the audit data is recorded and processed to determine the user login audit policy; Record and track security operation data in the audit data and determine an operation log strategy; The operation overview policy, the user login audit policy and the operation log policy are combined to obtain the unified audit management policy.
7. The integrated authority management method based on an integrated architecture according to claim 1 is characterized in that: Based on the unified application management strategy, the unified user management strategy, the unified authorization management strategy, the unified authentication management strategy, and the unified audit management strategy, an integrated collaborative architecture mechanism is integrated and constructed, specifically including: The unified application management policy, the unified user management policy, the unified authorization management policy, the unified authentication management policy and the unified audit management policy are collaboratively controlled on the same platform to obtain a business integration center management platform; Based on the business integration center management platform, the integrated collaborative architecture mechanism for visually managing the operation and maintenance monitoring system is constructed.
8. The integrated authority management method based on an integrated architecture according to claim 1 is characterized in that: Through the role-based access control mechanism, each user is assigned a role and each role is given corresponding permissions to achieve the driving execution of the unified authorization management strategy; Through the management identity of the strategy, the authority management mode in each strategy in the integrated collaborative architecture mechanism is driven and controlled.
9. An integrated rights management device based on an integrated architecture, characterized in that: The device comprises: at least one processor; and, a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, so that the at least one processor can execute the integrated permission management method based on an integrated architecture according to any one of claims 1 to 8.
10. A non-volatile computer storage medium, characterized in that The storage medium is a non-volatile computer-readable storage medium, which stores at least one program. Each of the programs includes instructions. When the instructions are executed by the terminal, the terminal executes the integrated authority management method based on the integrated architecture according to any one of claims 1 to 8.