Multi-module fusion development base design method and system based on credential management and service
By building a multi-module integrated development base for trusted innovation management and services, and adopting domestic software and hardware adaptation and automatic interception mechanisms, the problem of low development efficiency in the trusted innovation environment has been solved, the automation of permission verification and data security have been achieved, and the efficient operation and compliance of the system in the domestic environment have been ensured.
Patent Information
- Application Number
- CN202511220255.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-29
- Publication Date
- 2025-09-30
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Existing technologies cannot simultaneously meet multiple requirements such as trusted computing adaptation, security compliance, and rapid development, resulting in long development cycles, high compliance costs, and high technical risks. Traditional development frameworks lack native support for trusted computing environments and require a large amount of resources for adaptation and transformation.
Build a multi-module integrated development base based on information technology management and services, including permission layer, audit layer, security layer and function layer, use domestic software and hardware adaptation, and implement declarative programming of permission definition through permission marking and automatic interception mechanism. Combined with domestic databases and hardware abstraction layers, ensure the efficient operation and security compliance of the system in a domestic environment.
It realizes the automated execution of permission verification, reduces the burden on developers, ensures that user permission adjustments take effect immediately, provides precise data isolation control and data security, improves development efficiency, and ensures the stability and security of the system in a domestic environment.
Smart Images

Figure CN120723213A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of information and communication technology systems, and specifically to a multi-module fusion development base design method and system based on information and communication technology management and services. Background Art
[0002] Against the backdrop of the rapid development of information technology, the emergence of the information and communication technology industry, and the acceleration of digital transformation, various industries are increasingly demanding software systems based on the information and communication technology environment, while at the same time putting forward higher requirements for the security, compliance, and adaptability of the software. Especially in state-owned enterprises and key industries such as medical care, education, and finance, information security and independent control are of vital importance.
[0003] Existing technologies cannot simultaneously meet the multiple requirements of trusted innovation adaptation, security compliance, rapid development, etc., resulting in problems such as long development cycle, high compliance costs, and high technical risks during the development process. The main technical limitations are as follows: although the traditional development framework provides basic development capabilities, it lacks native support for the trusted innovation environment, and security compliance functions require additional development. Most mainstream development platforms are based on the x86 architecture and foreign basic software, and cannot meet the trusted innovation industry's requirements for independent and controllable technology. In the traditional development framework, following the information security standards requires a lot of development resources for secondary implementation. When migrating to the trusted innovation environment, traditional development platforms need to carry out a lot of adaptation and transformation of the CPU architecture, operating system, database, etc. Each project needs to redevelop basic functions such as the permission system and log module, resulting in low development efficiency and uneven system quality. Summary of the Invention
[0004] The present invention provides a multi-module integrated development base design method and system based on information technology innovation management and services, which has the beneficial effects of high security compliance and adaptability, and solves the problems mentioned in the above background technology that it is difficult to meet the security compliance requirements, the adaptability of the domestic information technology innovation environment is poor, and the advantages of domestic hardware and software cannot be fully utilized.
[0005] The present invention provides the following technical solution: a multi-module integrated development base design method based on information innovation management and services and a system thereof, wherein the multi-module integrated development base design method based on information innovation management and services includes the following steps:
[0006] Building a system framework, wherein the system framework is adapted to domestic software and hardware;
[0007] Setting permission levels, including setting level permissions, different levels of permissions correspond to different levels of operators, and the level permissions correspond to the permissions for accessing data and modifying the system;
[0008] Setting up an audit layer, which includes recording information and monitoring information;
[0009] When an operator performs an operation, the audit layer records and monitors the operation behavior. If the operation behavior does not match the level of authority, the audit layer will mark and intercept the operation behavior.
[0010] Setting up a security layer, wherein the system architecture transmits data based on the operator's behavior, and uses the security layer to encrypt and desensitize the transmitted data;
[0011] According to the different transmission data corresponding to the level authority, the security layer is used to filter the data beyond the authority range on the same transmission data level by level according to the level authority.
[0012] As an optional solution of the multi-module fusion development base design method based on information innovation management and services described in the present invention, wherein: the permission layer also includes menu permissions, button permissions, data permissions and interface permissions;
[0013] The menu permissions include displaying menu options corresponding to different levels of permissions;
[0014] The button permissions include giving operators permissions to adjust data according to different levels of permissions;
[0015] The data permissions include filtering out data that is not accessible according to different levels of permissions;
[0016] The interface permissions include setting up token verification and signature mechanisms to protect the API and prevent illegal API calls.
[0017] As an optional solution to the multi-module integrated development base design method based on information innovation management and services described in the present invention, wherein: the audit layer includes login audit, operation audit and interface audit;
[0018] The login audit includes recording the operator's login time, IP address and device information when the operator logs in, generating a registration file, and tracing the source by querying the record file when a security incident occurs;
[0019] The operation audit includes recording the operation time, operator and operation content after the operator performs an operation, and generating an operation file to monitor and review the operation behavior;
[0020] The interface audit includes monitoring API calls;
[0021] The API call includes call parameters and return results, and abnormal API call behavior is determined based on interface audit monitoring.
[0022] As an optional solution of the multi-module integrated development base design method based on information innovation management and services described in the present invention, wherein: the security layer includes transmission encryption, storage encryption and desensitization processing;
[0023] The transmission encryption includes adopting national secret algorithm to prevent tampering of the transmission data obtained after the operator performs the operation;
[0024] The storage encryption includes encrypting and storing sensitive fields in the transmitted data;
[0025] The desensitization processing includes desensitizing and replacing sensitive fields in the transmitted data.
[0026] As an optional solution of the multi-module integrated development base design method based on information innovation management and services described in the present invention, it also includes setting a functional layer, which is used to build and manage the organizational structure;
[0027] The functional layer includes establishing a plurality of tree structures according to the associated organizational structure, and marking and classifying each of the tree structures according to the business type;
[0028] The tree structure is divided into levels according to units, departments and positions, and each unit, department and position corresponds to a corresponding level of authority.
[0029] As an optional solution to the multi-module fusion development base design method based on information innovation management and services described in the present invention, wherein: the functional layer also includes RBAC permission model, ABAC attribute control and dynamic permission adjustment;
[0030] The RBAC permission model includes an operator-based access control model, which assigns roles to operators and grants corresponding permissions based on hierarchical permissions;
[0031] The ABAC attribute control includes making authority judgments based on the attributes of operators, resources, and environments;
[0032] The dynamic authority adjustment includes dynamically adjusting the authority of an operator who does not meet the authority requirements by making a request.
[0033] As an optional solution of the multi-module integrated development base design method based on information innovation management and services described in the present invention, it also includes setting a service layer, which is used to assist personnel operations;
[0034] The service layer includes task engine, data dictionary, file management, message notification, Excel processing and open API authorization;
[0035] The task engine includes configuring scheduled tasks and automatically executing tasks, including data synchronization, report generation and data cleaning;
[0036] The data dictionary includes unified management and standardized transmission data;
[0037] The file management includes supporting upload, download, storage and deletion operations of transmitted data using multiple protocols;
[0038] The message notification includes timely pushing system messages and business notifications to users via email, SMS and internal messages;
[0039] The Excel processing includes encapsulating the import and export functions of Excel files using a unified interface to automatically read, write and convert formats;
[0040] The open API authorization includes providing external API interface authorization services, automatically generating corresponding document descriptions based on the published API, and supporting dynamic configuration and management of access token expiration time and IP whitelist security policies.
[0041] As an optional solution to the multi-module integrated development base design method based on information innovation management and services described in the present invention, wherein: by identifying the tree structure of operators, the corresponding superior and subordinate relationships are locked according to the tree structure, thereby locking data permissions, thereby filtering the transmitted data step by step;
[0042] The level of authority is used to determine whether the transmitted data exceeds the authority. When the authority is exceeded, interception is initiated and the access to the transmitted data is controlled based on the unit information in the context of the user behavior.
[0043] As an optional solution to the multi-module fusion development base design method based on information technology management and services described in the present invention, it also includes building a unified hardware abstraction layer and using the hardware abstraction layer to adapt to domestic software and hardware platforms.
[0044] The present invention also provides a system for applying a multi-module integrated development base design method based on information innovation management and services, including:
[0045] The authority module is used to set the level of authority of the operator. Different levels of authority correspond to different levels of operators. The level of authority corresponds to the permission to access data and modify the system.
[0046] Audit module: When an operator performs an operation, the audit module records and monitors the operation behavior, and marks and intercepts the operation behavior that does not match the level of authority;
[0047] Security module: When an operator takes action to obtain transmission data, the obtained transmission data is encrypted and desensitized through the security module;
[0048] A functional module for recording all units and generating a tree structure for each unit, and assigning corresponding level permissions to operators within the tree structure;
[0049] The service module is used to assist operators in completing tasks.
[0050] The present invention has the following beneficial effects:
[0051] 1. The multi-module integrated development base design method and system based on information technology management and services adopts permission marking and automatic interception mechanism, defines interface permission requirements through annotations, automatically intercepts requests and performs permission verification when the system is running, and realizes declarative programming of permission definition. It only needs to add annotations to the code to define permissions. The automated execution of permission verification reduces the burden of manual permission verification on developers. The real-time effectiveness of permission changes ensures that user permission adjustments can be immediately reflected in the system.
[0052] 2. This multi-module integrated development platform design method and system based on trusted innovation management and services achieves precise data isolation control by matching the hierarchical relationship between units and the units to which users belong. The system only needs to pass the corresponding unit attribute name when querying to automatically complete data permission filtering and return data that is within the current user's unit permission range. The calling method is simple, flexible, and agile. The underlying layer uses a unified interception mechanism to control data access based on the unit information in the user context. It supports database field-level identification and application layer parameter injection to ensure data security and access compliance.
[0053] 3. The multi-module integrated development base design method and system based on information technology management and services ensures data operation performance and stability in the domestic database environment through customized extension of modules such as SQL dialect, paging plug-in, primary key strategy, and ensures that the business system has controllable and efficient operation capabilities in the domestic basic software and hardware environment. BRIEF DESCRIPTION OF THE DRAWINGS
[0054] Figure 1 Schematic diagram of the overall method of the present invention.
[0055] Figure 2 Schematic diagram of the architecture of the permission module of the present invention.
[0056] Figure 3 This is a schematic diagram of the architecture of the audit module of the present invention.
[0057] Figure 4 Schematic diagram of the security module of the present invention.
[0058] Figure 5 Schematic diagram of the architecture of the functional modules of the present invention.
[0059] Figure 6 Schematic diagram of the architecture of the service module of the present invention. DETAILED DESCRIPTION
[0060] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0061] Example 1
[0062] See also Figure 1-Figure 3 , one of the multi-module integrated development base design methods based on information innovation management and services includes the following steps:
[0063] Build a system framework to adapt to domestic software and hardware;
[0064] Set up permission levels. Permission levels include setting up level permissions. Different levels of permissions correspond to different levels of operators. Level permissions correspond to permissions for accessing data and modifying the system.
[0065] Set up an audit layer, which includes recording information and monitoring information;
[0066] When an operator performs an operation, the audit layer records and monitors the operation behavior. If the operation behavior does not match the level of authority, the audit layer will mark and intercept the operation behavior.
[0067] Set up a security layer. The system architecture transmits data based on the operator's behavior, and uses security layer encryption and desensitization to transmit data;
[0068] Different transmission data corresponds to different levels of authority, and the security layer is used to filter out data that exceeds the authority range from the same transmission data level by level.
[0069] In response to the country's requirements for innovative development of information technology applications, it is developed based on the highly portable Java platform, with good cross-platform compatibility and adaptability to domestic hardware. The program core is written in Java and encapsulated as a standard JAR package. During execution, it relies on the Java virtual machine rather than native binary instructions bound to a specific CPU architecture. This fundamentally ensures platform independence, thereby achieving comprehensive adaptation to mainstream domestic CPU architectures and domestic operating systems, achieving "the same set of code, running on multiple domestic platforms;
[0070] Furthermore, the system core is written in Java, and during runtime, the bytecode is dynamically converted to machine instructions through a standardized Java virtual machine, shielding the differences in the underlying operating system and ensuring stable operation in various domestic Linux kernel operating system environments;
[0071] It should be noted that the system strictly adheres to POSIX specifications and domestic operating system compatibility guidelines during development. It does not rely on any platform-specific local dynamic libraries. All functional modules are implemented through Java standard class libraries, with the "zero local dependency" feature, effectively avoiding compatibility issues caused by underlying ABI differences.
[0072] In the adaptation test, the system has been successfully deployed and stably runs on mainstream domestic operating system versions such as Tongxin UOS and Kylin Operating System, covering a wide range of Linux kernel versions, and showing good compatibility and stability when running under different systems;
[0073] During the ICT adaptation process, we integrate with domestic system services through standardized service management mechanisms. Through comprehensive unit testing and system call verification, we ensure that core functional modules such as file system access, network communication, and logging are consistently available on all platforms. With platform decoupling, interface standardization, and cross-kernel environment operation capabilities, we achieve seamless adaptation to various domestic operating systems, providing solid software support and compatibility guarantees for widespread deployment in ICT environments.
[0074] Furthermore, the data access layer adopts the widely used persistence framework MyBatis in the industry. This framework has good scalability and database adaptability. Through flexible configuration of XML mapping files and annotations, it decouples the application logic from the underlying database, greatly improving the database compatibility and portability. MyBatis follows the JDBC standard working mechanism and accesses the database through a standardized JDBC driver at the bottom layer. Therefore, as long as the domestic database middleware provides a driver that complies with the JDBC standard, seamless docking can be achieved.
[0075] It should be noted that the system was designed based on the database-neutral principle, avoiding the use of any SQL extension syntax specific to a single database vendor. All database operation statements are written based on the ANSI SQL standard and are checked for compatibility in multiple database environments.
[0076] We have completed compatibility adaptation and testing with domestic database middleware such as DM and KingbaseES. All key scenarios such as data reading and writing, consistency verification, transaction management, and connection pool management have been verified, and the core functions are running stably and the data operation consistency is good.
[0077] The system implements highly parameterized and dynamic configuration capabilities in connection configuration, SQL mapping, and multi-data source management based on the driver characteristics of different databases. This ensures that during actual deployment, adaptation can be completed quickly according to the target database type without extensive modifications to business logic code, significantly reducing migration costs.
[0078] The pluggable database access layer built on MyBatis can flexibly connect to various domestic database middleware, providing strong support for data storage, security auditing and independent control capabilities in the information innovation environment;
[0079] Through localized adaptation, a complete localized development ecosystem has been built, promoting the application and development of domestic technologies. A powerful permission control system and security mechanism ensure the security of the system and the confidentiality of data.
[0080] It also includes building a unified hardware abstraction layer and using the hardware abstraction layer to adapt to domestic software and hardware platforms;
[0081] A unified hardware abstraction layer has been built to deeply adapt mainstream domestic software and hardware platforms. By abstracting underlying hardware differences, it shields inconsistencies in instruction sets and peripheral interfaces among domestic CPUs (such as Kunpeng and Feiteng), provides a unified calling interface to upper-level systems, and improves platform compatibility and portability. At the database access layer, an efficient ORM framework is adopted to adapt to domestic databases (such as DAMO and Renmin University of China Jincang). Combined with automatic code generation and flexible query encapsulation capabilities, it provides non-invasive support for domestic database drivers and SQL features. Through customized extensions of modules such as SQL dialects, paging plugins, and primary key strategies, data operation performance and stability are guaranteed in domestic database environments, ensuring that business systems have controllable and efficient operation capabilities within domestic foundational software and hardware environments.
[0082] Among them, in order to improve security compliance, by setting up permission layers;
[0083] The permission layer also includes menu permissions, button permissions, data permissions, and interface permissions;
[0084] Menu permissions include different user roles can only see the corresponding menu options according to the permission settings, preventing unauthorized users from accessing sensitive functions;
[0085] Button permissions include granting operators the authority to adjust data based on different levels of permissions. For example, only users with specific roles can click key operation buttons such as "Delete" and "Modify", ensuring the security of system operations.
[0086] Data permissions include automatically filtering out data rows that are not accessible when querying data based on user roles and permissions, ensuring the security and privacy of data access;
[0087] Interface permissions include ensuring API-level security, preventing illegal API calls through token verification, signature mechanisms, and other means to protect the security of system interfaces;
[0088] The audit layer includes login audit, operation audit and interface audit;
[0089] Login auditing includes recording the operator's login time, IP address, and device information when the operator logs in, generating a registration file, and tracing the source by querying the record file when a security incident occurs;
[0090] Operation audit includes recording the operation time, operator and operation content after the operator performs an operation, and generating an operation file to monitor and review the operation behavior;
[0091] Interface auditing includes monitoring all API calls, including call parameters, return results, etc., to promptly detect abnormal API call behavior;
[0092] In summary, by setting up permission and audit layers, we can achieve automated recording and analysis of audit logs throughout the entire process, reducing the cost of security compliance transformation. Furthermore, by adopting standardized data management and comprehensive logging and auditing capabilities, we improve the maintainability and stability of the system, providing solid and reliable technical support for application development and operation.
[0093] The "permission tag + automatic interception" mechanism is adopted to define interface permission requirements through annotations. When the system is running, requests are automatically intercepted and permission verification is performed, thereby realizing declarative programming of permission definition. Developers only need to add annotations in the code to define permissions. The automated execution of permission verification reduces the burden of manual permission verification on developers. The real-time effectiveness of permission changes ensures that adjustments to user permissions can be immediately reflected in the system.
[0094] Example 2
[0095] This embodiment is an improvement made on the basis of embodiment 1. For details, please refer to Figure 1-Figure 4 ,The security layer includes transmission encryption, storage encryption and desensitization processing;
[0096] Transmission encryption includes the use of national secret algorithms to prevent tampering of the transmission data obtained after the operator performs an operation;
[0097] Storage encryption includes encrypting and storing sensitive fields in transmitted data;
[0098] Desensitization processing includes desensitizing and replacing sensitive fields in transmitted data.
[0099] Among them, transmission encryption uses national secret algorithms to ensure data transmission security, such as SM2, SM3, SM4 and other algorithms to prevent data from being stolen or tampered with during network transmission;
[0100] Storage encryption uses encrypted storage for sensitive fields, such as user passwords and ID numbers, to ensure the security of data on the storage medium;
[0101] Desensitization processing uses automatic desensitization when displaying sensitive information, such as replacing the middle digits of the ID number with "*" to protect user privacy.
[0102] Example 3
[0103] This embodiment is an improvement made on the basis of embodiment 2. For details, please refer to Figure 1-Figure 5 , also includes setting up functional layers, which are used to build and manage organizational structures;
[0104] The functional layer includes establishing several tree structures based on the associated organizational structure, and labeling and classifying each tree structure according to business type;
[0105] The tree structure is divided into levels according to units, departments and positions, and each unit, department and position corresponds to the corresponding level of authority.
[0106] By identifying the tree structure of operators, the corresponding superior-subordinate relationships are locked according to the tree structure, thereby locking data permissions and filtering the transmitted data level by level;
[0107] The level of authority is used to determine whether the transmitted data exceeds the authority. When the authority is exceeded, interception is initiated and the access to the transmitted data is controlled based on the unit information in the context of the user behavior.
[0108] It adopts a tree-structured management system with unlimited levels of units, adapting to various complex organizational structures and facilitating the construction and management of organizational structures by users. It also provides a unit label classification function, which allows for classification and labeling of units according to business needs, facilitating quick retrieval and management, and enabling multi-dimensional management of units, departments, and positions. It also clearly defines the relationships between levels and provides a basis for user authority allocation.
[0109] By matching the hierarchical relationship between units and the user's affiliated units, precise data isolation control is achieved. The system automatically filters data permissions and returns data within the current user's unit permissions simply by passing the corresponding unit attribute name during querying. This allows for simple, flexible, and agile invocation. A unified underlying interception mechanism controls data access based on unit information within the user context. Support for database field-level identification and application-layer parameter injection ensures data security and access compliance.
[0110] Example 4
[0111] This embodiment is an improvement made on the basis of embodiment 3. For details, please refer to Figure 1-Figure 5 ,The functional layer also includes RBAC permission model, ABAC attribute control and dynamic permission adjustment;
[0112] The RBAC permission model includes an operator-based access control model, which assigns roles to operators and grants corresponding permissions based on hierarchical permissions;
[0113] ABAC attribute control includes making permission judgments based on the attributes of operators, resources, and environments;
[0114] Dynamic permission adjustment includes dynamically adjusting the permissions of an operator who does not meet the permissions requirements by making a request.
[0115] The RBAC permission model is a role-based access control model that simplifies the permission management process by assigning roles to users and granting corresponding permissions to roles.
[0116] ABAC attribute control is attribute-based access control, which makes permission judgment based on multiple attributes such as user, resource, and environment, making permission control more flexible;
[0117] Dynamic permission configuration supports dynamic adjustment of user permissions during system operation to meet the needs of business changes.
[0118] Example 5
[0119] This embodiment is an improvement made on the basis of embodiment 4. For details, please refer to Figures 1-6 , also includes setting up a service layer, which is used to assist personnel operations;
[0120] The service layer includes task engine, data dictionary, file management, message notification, Excel processing and open API authorization;
[0121] Task engine: You can configure scheduled tasks to automatically execute periodic tasks such as data synchronization, report generation, and data cleanup, thereby improving the degree of system automation.
[0122] Data dictionary: Unified management of various dictionary data within the system, providing standardized data support for each module of the system, and ensuring data consistency and accuracy.
[0123] File Management: This module provides unified file management capabilities, supports core operations such as file upload, download, storage, and deletion, and has the ability to process multiple file formats compatibly. Through an abstract file interface, it shields the differences in underlying storage implementations, facilitating system integration of third-party file services (such as MinIO and other object storage systems). It supports multiple access protocols, has good scalability and adaptability, and can meet the file management needs in complex business scenarios, while improving the stability and maintainability of file services.
[0124] Message notification: supports multiple message notification methods, such as email, SMS, station message, etc., to push system messages and business notifications to users in a timely manner.
[0125] Excel processing: By encapsulating the import and export functions of Excel files through a unified interface, users only need to focus on the specific business processing logic without having to worry about the underlying Excel data operations. It automatically handles complex operations such as reading, writing, and format conversion of Excel files, thereby simplifying business processes. Through this technical solution, developers can effectively reduce their dependence on Excel operations, improve system development efficiency, and reduce the risk of errors caused by manual operations, ensuring the accurate realization of business goals.
[0126] Open API Authorization: Used to provide external API interface authorization services, supporting interface access control by application or user dimension. The system can automatically generate corresponding documentation based on the published API to improve developer access efficiency. It supports dynamic configuration and management of security policies such as access token expiration time and IP whitelist, thereby achieving flexible and open interfaces while ensuring security. Through a unified API registration, authentication, current limiting and document generation mechanism, the controllability, scalability and security of the system's external services are improved.
[0127] Example 6
[0128] The present invention also provides a system for designing a multi-module integrated development base based on information innovation management and services, including:
[0129] Permission module, which is used to set the level of permissions of operators. Different levels of permissions correspond to different levels of operators. Level permissions correspond to data access permissions and system modification permissions.
[0130] Audit module: When an operator performs an operation, the audit module records and monitors the operation behavior, and marks and intercepts the operation behavior that does not match the level of authority;
[0131] Security module: When an operator takes action to obtain transmission data, the obtained transmission data is encrypted and desensitized through the security module;
[0132] Functional module: The functional module is used to record all units and generate a tree structure for each unit, and grant corresponding level permissions to operators within the tree structure;
[0133] Service module: The service module is used to assist operators in completing their tasks.
[0134] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that includes a list of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus.
[0135] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the technical principles of the present invention. These improvements and modifications should also be regarded as within the scope of protection of the present invention.
Claims
1. A multi-module integrated development base design method based on information innovation management and services, characterized in that: The following steps are involved: Building a system framework, wherein the system framework is adapted to domestic software and hardware; Permission layer, the permission layer includes setting level permissions, different levels of permissions correspond to different levels of operators, and the level permissions correspond to the permission to access data and the permission to modify the system; An audit layer, which includes recording information and monitoring information; When an operator performs an operation, the audit layer records and monitors the operation behavior. If the operation behavior does not match the level of authority, the audit layer will mark and intercept the operation behavior. Security layer: the system architecture transmits data based on the operator's behavior, and uses the security layer to encrypt and desensitize the transmitted data; According to the different transmission data corresponding to the level authority, the security layer is used to filter the data beyond the authority range on the same transmission data level by level according to the level authority.
2. The multi-module integrated development base design method based on information innovation management and services according to claim 1 is characterized by: The permission layer also includes menu permission, button permission, data permission and interface permission; The menu permissions include displaying menu options corresponding to different levels of permissions; The button permissions include giving operators permissions to adjust data according to different levels of permissions; The data permissions include filtering out data that is not accessible according to different levels of permissions; The interface permissions include setting up token verification and signature mechanisms to protect the API and prevent illegal API calls.
3. The multi-module integrated development base design method based on information innovation management and services according to claim 2 is characterized by: The audit layer includes login audit, operation audit and interface audit; The login audit includes recording the operator's login time, IP address and device information when the operator logs in, generating a registration file, and tracing the source by querying the record file when a security incident occurs; The operation audit includes recording the operation time, operator and operation content after the operator performs an operation, and generating an operation file to monitor and review the operation behavior; The interface audit includes monitoring API calls and determining abnormal API call behaviors based on the interface audit monitoring.
4. The multi-module integrated development base design method based on information innovation management and services according to claim 3 is characterized by: The security layer includes transmission encryption, storage encryption and desensitization processing; The transmission encryption includes adopting national secret algorithm to prevent tampering of the transmission data obtained after the operator performs the operation; The storage encryption includes encrypting and storing sensitive fields in the transmitted data; The desensitization processing includes desensitizing and replacing sensitive fields in the transmitted data.
5. The multi-module integrated development base design method based on information innovation management and services according to claim 2 is characterized by: It also includes setting up a functional layer, which is used to build an organizational structure and management; The functional layer includes establishing a plurality of tree structures according to the associated organizational structure, and marking and classifying each of the tree structures according to the business type; The tree structure is divided into levels according to units, departments and positions, and each unit, department and position corresponds to a corresponding level of authority.
6. The multi-module integrated development base design method based on information innovation management and services according to claim 5 is characterized by: The functional layer also includes RBAC permission model, ABAC attribute control and dynamic permission adjustment; The RBAC permission model includes an operator-based access control model, which assigns roles to operators and grants corresponding permissions based on hierarchical permissions; The ABAC attribute control includes making authority judgments based on the attributes of operators, resources, and environments; The dynamic authority adjustment includes dynamically adjusting the authority of an operator who does not meet the authority requirements by making a request.
7. The multi-module integrated development base design method based on information innovation management and services according to claim 6 is characterized by: It also includes setting a service layer, wherein the service layer is used to assist personnel operations; The service layer includes task engine, data dictionary, file management, message notification, Excel processing and open API authorization; The task engine includes configuring scheduled tasks and automatically executing tasks, including data synchronization, report generation and data cleaning; The data dictionary includes unified management and standardized transmission data; The file management includes supporting upload, download, storage and deletion operations of transmitted data using multiple protocols; The message notification includes timely pushing system messages and business notifications to users via email, SMS and internal messages; The Excel processing includes encapsulating the import and export functions of Excel files using a unified interface to automatically read, write and convert formats; The open API authorization includes providing external API interface authorization services, automatically generating corresponding document descriptions based on the published API, and supporting dynamic configuration and management of access token expiration time and IP whitelist security policies.
8. The multi-module integrated development base design method based on information innovation management and services according to claim 5 is characterized by: By identifying the tree structure of the operator, the corresponding superior-subordinate relationship is locked according to the tree structure, thereby locking the data authority, thereby filtering the transmitted data level by level; The level of authority is used to determine whether the transmitted data exceeds the authority. When the authority is exceeded, interception is initiated and the access to the transmitted data is controlled based on the unit information in the context of the user behavior.
9. The multi-module integrated development base design method based on information innovation management and services according to claim 1 is characterized by: It also includes building a unified hardware abstraction layer and using the hardware abstraction layer to adapt to domestic software and hardware platforms.
10. A system for designing a multi-module integrated development base based on information innovation management and services is applied, characterized in that: include: The authority module is used to set the level of authority of the operator. Different levels of authority correspond to different levels of operators. The level of authority corresponds to the permission to access data and modify the system. Audit module: When an operator performs an operation, the audit module records and monitors the operation behavior, and marks and intercepts the operation behavior that does not match the level of authority; Security module: When an operator takes action to obtain transmission data, the obtained transmission data is encrypted and desensitized through the security module; A functional module for recording all units and generating a tree structure for each unit, and assigning corresponding level permissions to operators within the tree structure; The service module is used to assist operators in completing tasks.
Citation Information
Patent Citations
Right control method, device, electronic device and storage medium
CN109242420A
Authority management method based on information system
CN116484425A
Method, system and equipment for realizing localization transformation of database based on SpringBoot and mybatis frameworks and storage medium
CN118363569A
Commercial password cloud supervision and management information system and method based on credential environment
CN119939571A
Application development method and device, electronic equipment and storage medium
CN120010835A