Software resource operation authorization method and device, equipment and storage medium
Through user identity feature vector mapping and blockchain consensus mechanism, the problems of opaque trust mechanism and tamperable permission records in the authorization process in a distributed environment are solved, and transparent and reliable authorization record storage and real-time instruction execution are achieved, adapting to the security and flexibility requirements of complex application scenarios.
Patent Information
- Application Number
- CN202510939695.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-08
- Publication Date
- 2025-10-17
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
When faced with cross-domain collaboration in a distributed environment, existing authorization methods have problems such as opaque trust mechanisms, tamperable permission records, and difficult audit traceability. They are unable to meet the dual needs of security and flexibility in complex and changing application scenarios.
By extracting the user identity feature vector of the software resource operation request initiated by the user terminal, permission mapping and dynamic permission level assessment are performed, a user permission attribute mapping table is generated, and the blockchain consensus mechanism is used to store tamper-proof authorization records to achieve distributed authorization confirmation.
It realizes a transparent and trusted authorization process in a distributed environment, ensures that the authorization records cannot be tampered with and are traceable, and improves the transparency and credibility of the authorization process.
Smart Images

Figure CN120811652A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of software, in particular to a software resource operation authorization method, device and equipment and storage medium. BACKGROUND
[0002] With the rapid development of information technology, the use and sharing of software resources are becoming more frequent, and the traditional static authorization mechanism has been difficult to meet the dual needs of security and flexibility in complex and variable application scenarios. Existing systems usually rely on fixed identity authentication and pre-set permission allocation methods, lack of dynamic adaptability to user behavior characteristics and real-time environmental factors, leading to over or insufficient permission granting, thereby affecting the overall security and user experience of the system.
[0003] In addition, most current authorization methods often have problems such as opaque trust mechanism, tamperable permission records, and difficult audit traceability when facing cross-domain collaboration in a distributed environment. Due to the lack of unified and trusted authorization data sharing mechanism, efficient permission mutual recognition between different systems is difficult to achieve, thereby limiting the openness and interoperability of resources. At the same time, the centralized authorization management mode is also easy to become the target of attack, increasing the risk of data leakage and illegal access.
[0004] In order to solve the above problems, it is necessary to propose a new operation authorization method that integrates user identity feature recognition, dynamic permission evaluation, intelligent strategy matching, and decentralized evidence. This method should be able to ensure security while improving the flexibility and traceability of the authorization process, especially in multi-agent collaborative and high-security scenarios, providing more refined and trusted permission management support, thereby promoting the evolution of software resource sharing mechanisms towards more efficient and more reliable direction. SUMMARY
[0005] The main purpose of the present application is to provide an operation authorization method for software resources, which solves the technical problems that most current authorization methods often have opaque trust mechanisms, tamperable permission records, and difficult audit traceability when facing cross-domain collaboration in a distributed environment.
[0006] To achieve the above purpose, the present application provides an operation authorization method for software resources, comprising the following steps: Extracting the user identity feature vector of the software resource operation request initiated by the user terminal, and mapping the user's permissions based on the user identity feature vector to obtain a user permission attribute mapping table; Based on the user permission attribute mapping table, the user's dynamic permission level is evaluated to obtain user dynamic permission level data; Perform access control policy matching on the software resource operation request based on the user dynamic permission level data to obtain a resource access control instruction; Perform tamper-proof authorization record storage on the resource access control instruction through a blockchain consensus mechanism to obtain a distributed authorization confirmation voucher; Based on the distributed authorization confirmation voucher, perform real-time instruction issuance and execution state monitoring on the software resource operation request.
[0007] Further, the user is mapped based on the user identity feature vector to obtain a user permission attribute mapping table, including: The user identity feature vector is decomposed in multiple dimensions to generate a user behavior feature sequence, and time series correlation analysis is performed on the user behavior feature sequence to obtain a user operation mode feature map, including resource access time distribution, operation instruction sequence features, and access address space distribution; Based on the user operation mode feature map, identity trustworthiness of the user is calculated to obtain a user identity trustworthiness result, and the user identity trustworthiness result is divided into multiple levels of threshold to obtain a user trust level evaluation result; The user's permissions are mapped by the user trust level evaluation result to obtain a permission hierarchical mapping matrix, and the permission hierarchical mapping matrix is analyzed for permission attributes to obtain a user permission attribute mapping table, wherein the user permission attribute mapping table includes a resource operation permission set, an access control policy group, and a permission validity period limit.
[0008] Further, the user is dynamically evaluated for permission level based on the user permission attribute mapping table to obtain user dynamic permission level data, including: The user permission attribute mapping table is analyzed for permission correlation degree to obtain a permission correlation degree matrix, and the permission correlation degree matrix is processed for hierarchical clustering to obtain a user permission hierarchical structure diagram, including a permission inheritance relationship tree, a permission dependency network diagram, and a permission conflict detection matrix; The user permission hierarchical structure diagram is calculated for dynamic weight to obtain a permission value time decay curve, and the permission value time decay curve is used for permission timeliness evaluation to obtain a permission timeliness evaluation result, including a permission freshness indicator, a permission aging coefficient, and a permission urgency score; Based on the permission timeliness evaluation result, the user permission attribute mapping table is calculated for dynamic adjustment to obtain a dynamically adjusted permission attribute, and the dynamically adjusted permission attribute is used for permission risk quantization analysis to obtain a permission risk quantization matrix, including a permission abuse risk index, a permission leakage risk coefficient, and a permission overreach risk value; The permission risk quantification matrix is subjected to multi-dimensional risk level evaluation to obtain user dynamic permission level data.
[0009] Further, the software resource operation request is subjected to access control strategy matching based on the user dynamic permission level data to obtain a resource access control instruction, which comprises: The user dynamic permission level data is subjected to permission level mapping conversion to obtain a permission level vector, and the permission level vector is subjected to multi-dimensional feature space projection to obtain a permission level feature space. The permission level feature space is subjected to strategy retrieval matching to obtain a matched set of access control strategies, and the matched set of access control strategies is subjected to strategy conflict detection and exclusion to obtain a non-conflict access control strategy. The software resource operation request is subjected to permission resolution based on the non-conflict access control strategy to obtain a permission resolution result set, and the permission resolution result set is subjected to permission verification preprocessing to obtain a permission verification preprocessing result. The permission verification preprocessing result is subjected to permission compliance verification to obtain a permission compliance verification report, and the permission compliance verification report is subjected to permission risk scoring to obtain a permission risk scoring result. Based on the permission risk scoring result, a dynamic permission instruction is generated for the non-conflict access control strategy to obtain a resource access control instruction.
[0010] Further, the resource access control instruction is subjected to tamper-proof authorization record storage through a blockchain consensus mechanism to obtain a distributed authorization confirmation voucher, which comprises: The resource access control instruction is structured and encapsulated to generate a resource access control instruction transaction data package, and the resource access control instruction transaction data package is subjected to hash operation to obtain a transaction data package hash digest. The transaction data package hash digest is subjected to intra-block data structure organization through a Merkle tree construction algorithm to obtain a Merkle tree root hash value, and the resource access control instruction transaction data package is subjected to block header information synthesis based on the Merkle tree root hash value to obtain a to-be-consensus block data structure. Through a blockchain consensus mechanism, candidate verifier nodes in the to-be-consensus block data structure are verified and screened, and the candidate verifier nodes are sorted according to a preset weight strategy to obtain an ordered verification node list. The to-be-consensus block data structure is subjected to step-by-step digital signature verification through the ordered verification node list to obtain a verifier signature set, and the block validity is confirmed based on the verifier signature set and a preset verifier signature threshold to obtain a consensus-confirmed block data. Distributed authorization confirmation is performed on the resource access control instruction transaction data packet based on the block data of the consensus confirmation, and a distributed authorization confirmation voucher is obtained.
[0011] Further, the transaction data packet hash digest is organized into an intra-block data structure through a Merkel tree construction algorithm, and a Merkel tree root hash value is obtained, including: The transaction data packet hash digest is mapped to a hierarchical leaf node to obtain an initial leaf node sequence set, and the initial leaf node sequence set is padded with even numbers to obtain a balanced leaf node set; The adjacent leaf nodes in the balanced leaf node set are subjected to hash concatenation operation to obtain a set of intermediate layer node hash values, and the set of intermediate layer node hash values is subjected to node integrity verification to obtain an effective intermediate layer node hash tree; The effective intermediate layer node hash tree is iteratively calculated upwards through a recursive hash aggregation mechanism to obtain a multi-level hash tree structure, and the multi-level hash tree structure is subjected to tree height balance analysis to obtain a hash tree balance degree evaluation report; Based on the hash tree balance degree evaluation report, the root node hash of the multi-level hash tree structure is calculated to obtain the Merkel tree root hash value.
[0012] Further, the resource access control instruction transaction data packet is broadcasted based on the block data of the consensus confirmation to obtain a distributed ledger node confirmation record, including: The cross-node data format conversion is performed on the cross-node compatible data format to obtain a node address space mapping table, and the node address space mapping table is broadcasted through a gossip protocol-based node broadcast to obtain a set of broadcast node confirmation messages, and the set of broadcast node confirmation messages is subjected to broadcast message validity verification to obtain an effective broadcast node confirmation message; Based on the effective broadcast node confirmation message, the node storage path allocation result is obtained, and the node storage permission verification report is obtained based on the node storage path allocation result; Based on the node storage permission verification report, a distributed ledger is generated to obtain a distributed ledger node confirmation record.
[0013] The application also provides a software resource operation authorization system, including: The extraction module is used for extracting a user identity feature vector of a software resource operation request initiated by a user terminal, and performing permission mapping on the user based on the user identity feature vector to obtain a user permission attribute mapping table. The evaluation module is used for performing dynamic permission level evaluation on the user based on the user permission attribute mapping table to obtain user dynamic permission level data. The matching module is used for performing access control strategy matching on the software resource operation request based on the user dynamic permission level data to obtain a resource access control instruction. The storage module is used for performing tamper-proof authorization record storage of the resource access control instruction through a blockchain consensus mechanism to obtain a distributed authorization confirmation voucher. The execution module is used for performing real-time instruction issuing and execution state monitoring on the software resource operation request based on the distributed authorization confirmation voucher.
[0014] The application further provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, and the processor implements the steps of the method according to any one of the preceding embodiments when executing the computer program.
[0015] The application further provides a computer readable storage medium, which stores a computer program, and the computer program implements the steps of the method according to any one of the preceding embodiments when executed by a processor.
[0016] The application provides a software resource operation authorization method, which comprises the following steps: extracting a user identity feature vector of a software resource operation request initiated by a user terminal, and performing permission mapping on the user based on the user identity feature vector to obtain a user permission attribute mapping table; performing dynamic permission level evaluation on the user based on the user permission attribute mapping table to obtain user dynamic permission level data; performing access control strategy matching on the software resource operation request based on the user dynamic permission level data to obtain a resource access control instruction; performing tamper-proof authorization record storage of the resource access control instruction through a blockchain consensus mechanism to obtain a distributed authorization confirmation voucher; and performing real-time instruction issuing and execution state monitoring on the software resource operation request based on the distributed authorization confirmation voucher. BRIEF DESCRIPTION OF DRAWINGS
[0017] Figure 1 is a step schematic diagram of the software resource operation authorization method in an embodiment of the application. Figure 2 This is a structural block diagram of a software resource operation authorization system according to one embodiment of the present invention; Figure 3 It is a schematic block diagram of the structure of a computer device according to an embodiment of the present invention.
[0018] The purpose, features and advantages of the present invention will be further described with reference to the accompanying drawings and in conjunction with the embodiments. DETAILED DESCRIPTION
[0019] In order to make the purpose, technical solutions and advantages of the present invention more clearly understood, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.
[0020] like Figure 1 As shown, Figure 1 A method for authorizing the operation of a software resource in one embodiment of the present invention includes the following steps: Step S1: extracting a user identity feature vector of a software resource operation request initiated by a user terminal, and performing permission mapping on the user based on the user identity feature vector to obtain a user permission attribute mapping table.
[0021] Specifically, in this step, the system first extracts the user identity feature vector in the software resource operation request initiated by the user terminal. This process is achieved by comprehensively collecting and structuredly representing the multi-dimensional data such as identity information, device fingerprints, and behavior patterns carried by the user during the access process; these feature vectors are used as the user's digital identity identification and are used in the subsequent permission mapping process. At this stage, the system matches the user identity feature vector with the existing permission model based on the preset permission rule engine and user historical behavior database, thereby generating a user permission attribute mapping table, which contains the specific permissions corresponding to the user's current request Attributes, such as access level, operation type, resource scope, etc.; for example, in an enterprise's internal document management system, when an employee initiates a read operation on a sensitive folder through his terminal, the system will extract the employee's account information, login device model, IP address, timestamp, and historical access records from the operation request, and combine them into a set of user identity feature vectors. Subsequently, the system searches and compares the feature vectors in the permission rule library to determine whether the user has the preliminary qualifications to access such resources, and generates a corresponding permission attribute mapping table based on this, providing basic data support for subsequent dynamic permission evaluation.
[0022] Step S2: performing a dynamic authority level assessment on the user based on the user authority attribute mapping table to obtain user dynamic authority level data.
[0023] Specifically, after obtaining the user permission attribute mapping table, the system will conduct dynamic permission level assessment on the user based on the mapping table, thereby generating user dynamic permission level data; this process is based on comprehensive consideration of multiple factors such as the user's current identity characteristics, historical behavior patterns, operation environment context, and resource sensitivity, and through a set of evaluation models and weight algorithms, the actual permission requirements and risk levels of the user are calculated and adjusted in real time; in specific implementation, the system will combine each permission attribute in the user permission attribute mapping table, such as access level, operation type, resource range, etc., with real-time operation scene data (such as geographic location, device trustworthiness, access time period) for fusion analysis, and use machine learning or rule engine to make dynamic judgments on the user's current permission level; for example, in an enterprise internal document management system, when an employee attempts to initiate an access request to a highly sensitive folder from a non-regular device during non-working hours, the system will re-evaluate the user's permission level according to the basic permission information in his user permission attribute mapping table, combined with the risk factors of the current operation environment, and may temporarily downgrade his originally high access permission, thereby generating corresponding user dynamic permission level data to ensure that the authorization decision can adapt to changing security needs and usage scenarios.
[0024] Step S3, performing access control policy matching on the software resource operation request based on the user dynamic permission level data to obtain resource access control instructions.
[0025] Specifically, after obtaining the user dynamic permission level data, the system will perform access control policy matching on the current software resource operation request based on the data to generate corresponding resource access control instructions; this process relies on a pre-set policy rule library and permission decision engine, and the system will compare the user dynamic permission level data with the access control policies of various resources to filter out the most suitable control policy and generate specific resource access control instructions accordingly; this matching mechanism not only considers the user's current permission level, but also combines the classification, sensitivity, usage scenario, etc. of the resource itself to achieve fine-grained access control; for example, in an enterprise internal document management system, when an employee attempts to access a highly sensitive folder, the system will determine whether he has the qualifications to perform such an operation at that time and place based on his user dynamic permission level data; if the system detects that the user has high basic permissions but the current login device has not passed security authentication or is in an abnormal geographic location, it will automatically reduce the scope of executable operations and generate corresponding resource access control instructions, such as allowing only to view part of the content or prohibiting downloading, etc., thereby ensuring that each resource access behavior complies with the system's security policy and real-time risk assessment results.
[0026] Step S4, the resource access control instruction is recorded by the blockchain consensus mechanism for non-tamperable authorization record storage, and a distributed authorization confirmation voucher is obtained.
[0027] Specifically, the non-tamperable authorization record storage of the resource access control instruction by the blockchain consensus mechanism means that after the generation of the resource access control instruction, the system submits the related authorization information of the instruction in the form of structured data to the distributed ledger network constructed based on the blockchain technology, and ensures that the record is agreed upon among multiple participants through the consensus algorithm between nodes, thereby forming an authorization storage record with legal effect and being unable to be tampered with, and finally obtaining a distributed authorization confirmation voucher; this process relies on the decentralization, traceability and tamper-proofing features of the blockchain, ensures that each authorization operation has complete historical records and multi-party verification mechanism, and enhances the credibility and auditability of the authorization behavior; for example, in the document management system of an enterprise, when an employee initiates an access request for a sensitive folder and passes the dynamic permission evaluation and policy matching, the system will package and upload the finally generated access control instruction and the corresponding user permission attribute, dynamic permission level and other key information to the blockchain network, and after being verified and confirmed by multiple nodes, it is written into the block to generate a unique distributed authorization confirmation voucher for subsequent audit or abnormal tracking, thereby realizing the whole life cycle traceable management of the entire authorization process and guaranteeing the security and transparency of the authorization behavior.
[0028] Step S5, based on the distributed authorization confirmation voucher, the software resource operation request is monitored in real time for instruction issuing and execution state.
[0029] Specifically, based on the distributed authorization confirmation voucher, the software resource operation request is monitored in real time for instruction issuing and execution state, which means that after completing the blockchain storage and obtaining the distributed authorization confirmation voucher, the system sends the corresponding access control instruction to the execution node or user terminal of the target resource according to the authorization information carried by the voucher, and continuously tracks and feeds back the execution state of the instruction during the operation process; this process dynamically binds the authorization identification, permission level, policy rule and other information in the distributed authorization confirmation voucher with the actual execution environment, ensures that each operation is within the authorized scope, and can be recorded and audited in real time; for example, in the document management system of an enterprise, when the access request of an employee passes the complete permission evaluation and policy matching process, and a distributed authorization confirmation voucher has been generated on the blockchain, the system issues an instruction to allow or restrict specific operations to the file server according to the content of the voucher, and at the same time, the system continuously monitors whether the operation behavior of the employee in accessing the sensitive folder is within the authorized scope, and if abnormal downloading or unauthorized access behavior is found, an alarm or interruption response mechanism is triggered immediately, thereby realizing closed-loop control and whole-process traceable management of the software resource operation request.
[0030] In specific embodiments, the user is mapped to the authority based on the user identity feature vector, and a user authority attribute mapping table is obtained, comprising: The user identity feature vector is decomposed in multiple dimensions to generate a user behavior feature sequence, and a time series correlation analysis is performed on the user behavior feature sequence to obtain a user operation mode feature map, which includes resource access time distribution, operation instruction sequence feature, and access address space distribution; Based on the user operation mode feature map, the identity credibility of the user is calculated to obtain a user identity credibility result, and the user identity credibility result is divided into multiple levels of threshold to obtain a user trust level evaluation result; The user's authority is mapped by the user trust level evaluation result, and a permission hierarchical mapping matrix is obtained, and the permission hierarchical mapping matrix is parsed for authority attributes to obtain a user authority attribute mapping table, wherein the user authority attribute mapping table includes a resource operation authority set, an access control policy group, and a permission validity period limit.
[0031] Specifically, in the process of mapping user permissions based on user identity feature vectors to obtain a user permission attribute mapping table, the system first performs a multi-dimensional decomposition on the extracted user identity feature vectors to generate a user behavior feature sequence that can reflect the user's behavior pattern. This process involves extracting behavioral data in multiple dimensions such as time, space, and operation type from the original identity features, and arranging them into a time series according to the chronological order of the operations, thereby constructing a user behavior feature sequence with dynamic characteristics. Subsequently, the system performs a time series correlation analysis on the user behavior feature sequence to identify the user's resource access habits, operation instruction usage frequency, and spatial distribution of access addresses in different time periods, thereby forming a user operation pattern feature map. The map includes but is not limited to key information such as resource access time distribution, operation instruction sequence characteristics, and access address spatial distribution, which is used to characterize the user's typical behavior pattern. For example, in an enterprise's internal document management system, if an employee frequently accesses financial report files between 9:00 and 10:00 a.m. on weekdays, mainly logs in through a PC, and the IP address is stably within the company's intranet, the system can construct an operation pattern feature map for the user based on this information. On this basis, the system further calculates the user's identity credibility based on the user's operation pattern feature map, and evaluates the authenticity and stability of the user's identity by comparing the consistency of the current operation behavior with the historical behavior pattern, thereby obtaining the user's identity credibility result; in order to achieve more fine-grained control, the system divides the identity credibility result into multi-level thresholds, and divides users into different trust levels, such as high, medium and low, to obtain the user's trust level evaluation result; this evaluation mechanism not only takes into account the legitimacy of the user's identity information itself, but also combines the rationality of its behavior pattern, effectively improving the accuracy and robustness of identity authentication; for example, if a user's current login location suddenly changes to overseas and the operation time deviates from the norm, the system will lower its identity credibility score and lower its trust level.Finally, the system grades the user's permissions through the user trust level evaluation result, i.e., sets the corresponding permission range according to different trust levels, and constructs a permission grading mapping matrix; the matrix takes the trust level as input and outputs the corresponding permission configuration rules, including key parameters such as operable resource types, access strategies, and permission validity periods; then, the system performs permission attribute analysis on the permission grading mapping matrix, extracts the specific resource operation permission set, access control strategy group, and permission validity period limit from it, and forms a structured user permission attribute mapping table; for example, for a user with a high trust level, the system may grant him complete read-write permissions and allow long-term access to specific resources, while for a user with a low trust level, only read-only permissions are opened and a shorter validity period is set, or even secondary authentication is required to continue operation; this dynamic permission mapping mechanism based on user behavior and trust level makes the authorization process more intelligent, secure, and adaptive in real time, meeting the fine-grained permission management needs in complex application scenarios.
[0032] In specific embodiments, the dynamic permission level evaluation of the user based on the user permission attribute mapping table includes: Performing permission correlation degree analysis on the user permission attribute mapping table to obtain a permission correlation degree matrix, and performing hierarchical clustering processing on the permission correlation degree matrix to obtain a user permission hierarchical structure diagram, wherein the user permission hierarchical structure diagram includes a permission inheritance relationship tree, a permission dependency network diagram, and a permission conflict detection matrix; Performing dynamic weight calculation on the user permission hierarchical structure diagram to obtain a permission value time decay curve, and performing permission timeliness evaluation based on the permission value time decay curve to obtain a permission timeliness evaluation result; wherein the permission timeliness evaluation result includes a permission freshness indicator, a permission aging coefficient, and a permission urgency score; Performing dynamic adjustment calculation on the user permission attribute mapping table based on the permission timeliness evaluation result to obtain a dynamically adjusted permission attribute, and performing permission risk quantization analysis based on the dynamically adjusted permission attribute to obtain a permission risk quantization matrix, wherein the permission risk quantization matrix includes a permission abuse risk index, a permission leakage risk coefficient, and a permission overreach risk value; Performing multi-dimensional risk level evaluation on the permission risk quantization matrix to obtain user dynamic permission level data.
[0033] Specifically, in the process of dynamically evaluating the user's permission level based on the user permission attribute mapping table, the system first analyzes the permission correlation degree of each permission attribute in the mapping table, which already contains structured information such as resource operation permission set, access control strategy group, and permission validity period limit. By analyzing the internal relationship and dependency between these permissions, the system constructs a permission correlation degree matrix, which reflects the coupling degree, sharing frequency, and logical dependency between different permissions. Then, the system performs hierarchical clustering on the permission correlation degree matrix to identify permission sets with similar functions or usage scenarios and further generates a user permission hierarchy structure diagram. This diagram includes key elements such as permission inheritance relationship tree, permission dependency network diagram, and permission conflict detection matrix, which are used to describe the organization structure, dependency path, and potential conflict points of user permissions. For example, in an enterprise internal document management system, if an employee has both "read financial statements" and "export customer list" permissions, the system can determine whether they belong to the same permission domain through the permission inheritance relationship tree and identify the risk of unauthorized operations using the permission conflict detection matrix. Based on this, the system further calculates the dynamic weights of the user permission hierarchy structure diagram to evaluate the actual value of each permission in the current time window. This process is achieved by introducing a permission value time decay curve model, which dynamically adjusts the weight values of each permission based on factors such as usage frequency, last usage time, and permission validity period, thereby reflecting the time effectiveness trend. The system performs permission time effectiveness evaluation based on the permission value time decay curve and obtains the permission time effectiveness evaluation results, including permission freshness indicator, permission aging coefficient, and permission urgency score in multiple dimensions. For example, if an employee frequently accesses a project document in the past week, but the permission for that document is about to expire, the system will increase the permission urgency score based on this and prompt the administrator to confirm whether to renew or adjust the permission configuration in time. Then, the system dynamically adjusts the user permission attribute mapping table based on the permission time effectiveness evaluation results, updates the operation permission set, control strategy group, and validity period limit fields, and forms the dynamically adjusted permission attributes. Based on this, the system further performs permission risk quantification analysis on the adjusted permission attributes to evaluate the potential security threats. This analysis process is achieved by establishing a permission risk quantification matrix, which contains multiple risk dimensions such as permission abuse risk index, permission leakage risk coefficient, and permission unauthorized risk value, to measure the security level of the current permission configuration. For example, if an employee is temporarily granted high permissions to complete a specific task, the system will automatically increase the permission abuse risk index and judge whether there is a possibility of unauthorized access based on the employee's historical behavior.Finally, the system performs multi-dimensional risk level evaluation on the permission risk quantization matrix, comprehensively considers the usage frequency, timeliness, sensitivity and potential harm of the permission, and calculates the overall dynamic permission level data of the user; the data not only reflects the strength of the permission currently possessed by the user, but also integrates the behavior pattern, risk tendency and real-time environmental influence, providing accurate decision basis for subsequent access control policy matching; for example, in a document management system, if an employee obtains high permission due to a temporary task, but shows abnormal download behavior in the use process, the system will reduce the dynamic permission level of the employee accordingly and trigger the corresponding access restriction mechanism, ensuring that the authorized behavior is always controllable and reliable. The dynamic permission level evaluation method based on the combination of permission structure analysis and risk assessment can effectively improve the intelligent level and security of permission management, and adapt to complex and changing application requirements.
[0034] In specific embodiments, the access control policy matching based on the user dynamic permission level data is performed on the software resource operation request to obtain a resource access control instruction, including: mapping and converting the user dynamic permission level data to obtain a permission level vector, and performing multi-dimensional feature space projection on the permission level vector to obtain a permission level feature space; performing policy retrieval matching on the permission level feature space to obtain a candidate set of access control policies that match successfully, and performing policy conflict detection and exclusion on the candidate set of access control policies to obtain a non-conflict access control policy; performing permission analysis on the software resource operation request based on the non-conflict access control policy to obtain a permission analysis result set, and performing permission verification preprocessing based on the permission analysis result set to obtain a permission verification preprocessing result; performing permission compliance verification on the permission verification preprocessing result to obtain a permission compliance verification report, and performing permission risk scoring on the permission compliance verification report to obtain a permission risk scoring result; generating a dynamic permission instruction based on the non-conflict access control policy based on the permission risk scoring result to obtain a resource access control instruction.
[0035] Specifically, in the process of matching the software resource operation request with the access control policy based on the user dynamic permission level data to obtain the resource access control instruction, the system first converts the user dynamic permission level data into a structured representation form that can be used for policy matching. Specifically, the system generates a permission level vector with numerical characteristics by mapping and converting the user dynamic permission level data, which can reflect the user's current permission level, resource access range, and operation restrictions, and other key attributes. Then, the system further maps the permission level vector into a multi-dimensional feature space to construct a permission level feature space, which represents the user's permission state and behavior pattern in the form of high-dimensional coordinates, thereby providing a mathematical basis for subsequent policy retrieval. On this basis, the system uses the permission level feature space as input to perform policy retrieval and matching operations in the pre-set access control policy library, identifies all access control policies that meet the user's current permission level, and forms a candidate set of access control policies. In order to ensure the consistency and executability of the selected policy, the system also needs to perform conflict detection and exclusion processing on the logical relationships between the policies in the candidate set, eliminate policies that have contradictions or mutual restrictions, and obtain a conflict-free access control policy. For example, in an enterprise internal document management system, when an employee tries to access a folder containing sensitive financial information, the system will match the policy combination of "read but prohibit export" from the policy library based on the permission level feature space of the employee, and exclude the conflict situation that "allow editing" and "prohibit downloading" may exist at the same time, to ensure the stability and security of the policy execution process. Next, the system performs permission analysis on the current software resource operation request based on the above conflict-free access control policy, that is, by analyzing the permission boundaries and operation restrictions defined by the policy, it extracts specific access rules such as allowed operation types, target resource paths, and access frequency upper limits, and forms a permission analysis result set. In order to ensure that these permission rules can be correctly executed in the actual environment, the system also performs permission verification preprocessing on the permission analysis result set to check whether it is compatible with the current system's running environment, resource state, and user identity characteristics, and generates a permission verification preprocessing result. For example, if a policy stipulates that only during office hours can access certain resources, and the current time is non-working hours, the system will mark the policy as inapplicable in the preprocessing stage and trigger the corresponding alarm mechanism.Subsequently, the system performs a permission compliance check on the permission verification preprocessing results, evaluates whether the current policy meets the compliance standards based on the organization's internal security specifications and industry regulatory requirements, and generates a permission compliance verification report; the report records in detail the match between the policy content and compliance clauses, and marks any potential violation risk points; to further improve the scientific nature of policy decisions, the system will also perform a permission risk score on the verification report, comprehensively considering factors such as the policy's usage scenarios, resource sensitivity, and user historical behavior, and calculate the permission risk score results to guide the subsequent instruction generation process. Finally, the system generates dynamic permission instructions for the conflict-free access control policy based on the permission risk score results, that is, converting the policy content into specific operation instructions that can be executed on the resource node, such as "allow reading", "restrict copying", "mandatory auditing", etc., thereby forming a complete resource access control instruction; this process not only ensures the accurate implementation of the authorization behavior, but also realizes the organic combination of policy execution and risk control; for example, in the document management system, if an employee's permission risk score is high, the system will automatically add additional logging and operation monitoring measures when generating access control instructions to prevent potential data leakage risks; this access control policy matching method driven by user dynamic permission level data not only improves the intelligence level of permission management, but also effectively ensures the security and controllability of the system in complex application scenarios.
[0036] In a specific embodiment, the resource access control instruction is recorded and recorded in an unalterable manner through a blockchain consensus mechanism to obtain a distributed authorization confirmation certificate, including: The structured data encapsulates the resource access control instruction to generate a resource access control instruction transaction data packet, and performs a hash operation on the resource access control instruction transaction data packet to obtain a transaction data packet hash summary; Organizing the transaction data packet hash summary into a block data structure using a Merkle tree construction algorithm to obtain a Merkle tree root hash value, and synthesizing the block header information of the resource access control instruction transaction data packet based on the Merkle tree root hash value to obtain a block data structure to be reached consensus; Verify and screen candidate validator nodes in the consensus block data structure through the blockchain consensus mechanism, and sort the candidate validator nodes according to a preset weight strategy to obtain an ordered list of validator nodes; Performing step-by-step digital signature verification on the block data structure to be reached through the ordered verification node list to obtain a validator signature set, and performing block validity confirmation based on the validator signature set and a preset validator signature threshold to obtain consensus-confirmed block data; The resource access control instruction transaction data packet is distributedly authorized and confirmed based on the block data of the consensus confirmation, and a distributed authorization confirmation voucher is obtained.
[0037] Specifically, first, the resource access control instruction is structured and encapsulated into a transaction data packet. For example, in a medical data sharing platform, a doctor A wants to access the electronic medical record of a patient, and this access request is a resource access control instruction. The instruction contains the requester's identity, target resource identification, access timestamp, and other metadata, and is serialized and encapsulated in a uniform format to form a resource access control instruction transaction data packet. Then, the system performs a hash operation on the transaction data packet to generate a unique transaction data packet hash digest as the data fingerprint for subsequent block construction. This hash value is unique and irreversible, and any modification to the original data will cause the hash value to change, thereby ensuring data integrity. Next, the system uses the Merkle tree construction algorithm to organize and process the transaction data packet hash digest. Assuming there are 10 similar resource access control instruction transaction data packets, the system will pair the hash digests of these transaction data packets two by two and hash them again, finally generating a binary tree structure, and the root node is the Merkle tree root hash value. The Merkle tree root hash value represents the overall fingerprint of all transactions in the current block, which is used to efficiently verify the consistency of the block content. On this basis, the system combines the Merkle tree root hash value with the timestamp, previous block hash, nonce, and other fields to generate the block header information, and then synthesizes the complete consensus block data structure. Then it enters the consensus mechanism phase. The system verifies and selects qualified candidate validator nodes from the nodes in the blockchain network based on their state. For example, in a consortium chain environment, there are 50 nodes participating in network maintenance, of which only 20 nodes have verification authority. The system sorts the 20 candidate validator nodes according to the preset weight strategy, such as node credit score, historical verification contribution, online stability, etc., to get an ordered list of verification nodes. Assuming that node A scores 95 points, node B scores 88 points, and node C scores 90 points, after sorting, node A is ranked first, node C second, and node B last, and so on, forming a weighted and sorted verification node queue. Next, the system performs a hierarchical digital signature verification on the consensus block data structure according to the ordered verification node list. Each verification node receives the new block and first checks whether the transaction data in the block is legal, the hash calculation is correct, and the Merkle tree structure is complete. If the verification is passed, the node signs the block header using its private key and broadcasts the signature result to the network. The system collects all the signatures of the verification nodes to form a verifier signature set. For example, when 15 nodes complete the signature, the system checks whether the signatures meet the preset verifier signature threshold, such as 12 valid signatures to confirm the block as valid. At this time, since there are 15 valid signatures exceeding the threshold, the system determines that the block passes the consensus verification and becomes a consensus-confirmed block data.Finally, the system performs distributed authorization confirmation on the resource access control instruction transaction data packet based on the consensus-confirmed block data, and generates a distributed authorization confirmation credential. The credential contains information such as original transaction data, block position, verification path, and signature set, and can be used for subsequent audit, traceability, or legal evidence. Still taking the above medical data sharing scenario as an example, the access request of doctor A has been successfully chained and obtained 15 signature confirmations of the verification nodes, and the system will generate an authorization credential with timestamp and signature path for it, indicating that the access behavior has been officially authorized and cannot be tampered with. Even if there is a dispute in the future, the credential can be submitted as authoritative evidence to the corresponding responsible agency.
[0038] In specific embodiments, the block-in data structure organization of the transaction data packet hash digest through the Merkle tree construction algorithm includes: Layered leaf node mapping is performed on the transaction data packet hash digest to obtain an initial leaf node sequence set, and even padding is performed on the initial leaf node sequence set to obtain a balanced leaf node set; Hash concatenation operation is performed on adjacent leaf nodes in the balanced leaf node set to obtain a set of intermediate layer node hash values, and node integrity verification is performed on the set of intermediate layer node hash values to obtain an effective intermediate layer node hash tree; Through a recursive hash aggregation mechanism, the effective intermediate layer node hash tree is iteratively calculated upwards layer by layer to obtain a multi-level hash tree structure, and tree height balance analysis is performed based on the multi-level hash tree structure to obtain a hash tree balance degree evaluation report; Based on the hash tree balance degree evaluation report, root node hash calculation is performed on the multi-level hash tree structure to obtain a Merkle tree root hash value.
[0039] Specifically, in the process of organizing the hash digest of the resource access control instruction transaction data packet into an intra-block data structure by the Merkel tree construction algorithm, the system first constructs the leaf nodes of the Merkel tree by taking the hash digest of each transaction data packet as the basic element. Specifically, the system calculates the hash value of each transaction data packet to be packaged into the block one by one, and arranges them into an initial leaf node sequence set according to the transaction order. Since the construction of the Merkel tree requires an even number of nodes at each level to ensure the feasibility of pairwise pairing operations, the system performs even padding on the initial leaf node sequence set, that is, when the number of leaf nodes is odd, the system will copy the last leaf node and append it to the end of the sequence, thereby generating a balanced leaf node set. This operation ensures the integrity and consistency of subsequent hierarchical operations. Subsequently, based on the balanced leaf node set, the system performs hash concatenation operations on adjacent two leaf nodes one by one, that is, it concatenates the hash values of the two leaf nodes and calculates the hash value again to generate the corresponding intermediate layer node hash value. This process progresses from the bottom up layer by layer, and each layer is calculated by combining two nodes from the next layer, forming a bottom-up hash aggregation chain. In order to ensure the correctness of the entire hash tree structure, the system performs node integrity verification after each layer calculation, checks for abnormal hash values, format errors, or logical conflicts, and only keeps the valid intermediate layer node hash tree that passes the verification. For example, in an enterprise internal document management system, if a certain authorization operation involves multiple users simultaneously initiating access requests, the system will generate independent transaction data packets for each request, calculate their hash digests to form a leaf node set, and construct a valid intermediate layer hash tree with complete structure through the above mechanism. On this basis, the system further adopts a recursive hash aggregation mechanism to iteratively calculate the valid intermediate layer node hash tree upwards layer by layer, continuously merging two nodes from the previous layer until a top-level node is generated, which is the Merkel tree root node. In this process, the hash value of each layer is derived from the combined hash of the next layer of nodes, forming a multi-level hash tree structure. To ensure that the generated Merkel tree has good structural stability and verification efficiency, the system also performs tree height balance analysis on the entire hash tree structure to evaluate the height difference and node distribution of each branch, and generates a hash tree balance evaluation report. This report records the height of the tree, the length of the leftmost path, the length of the rightmost path, and the number of nodes at each layer, etc., which are used to determine whether the Merkel tree meets the requirements of efficient verification and storage. For example, when a certain authorization batch contains a large number of transaction data packets, causing the height of the Merkel tree to increase significantly, the system can identify potential performance bottlenecks through the evaluation report and provide a basis for subsequent optimization.Finally, the system evaluates the results of the hash tree balance report based on the current multi-level hash tree structure, confirms that the block construction standard is met, and starts the root node hash calculation process, i.e. the last layer (i.e. the last layer) of the two node hash values is subjected to the last hash concatenation operation to generate a unique Merkle tree root hash value; this root hash value represents the encrypted summary of all transaction data in the entire block, and is an important part of the block header information. Any modification of the block content will result in a change in the Merkle tree root hash value, which will be quickly detected by the network nodes; for example, in a document management system, when an employee initiates an access request for a sensitive folder and generates a corresponding resource access control instruction transaction data packet, the system will include the transaction in the Merkle tree construction process, and the final Merkle tree root hash value will be embedded in the new block header, participating in consensus verification and block broadcast, ensuring that the authorized behavior has non-tamperability and traceability in the entire distributed ledger. In summary, the process of organizing transaction data packet hash summaries into block data structures through the Merkle tree construction algorithm not only realizes efficient organization and integrity protection of transaction data, but also provides a solid technical support for block verification, lightweight auditing, cross-chain interoperability and other functions of the blockchain system; this data organization method based on hash tree structure enables each authorized behavior to have an efficient verification path while ensuring security, thereby improving the trust strength and operational efficiency of the entire software resource operation authorization system.
[0040] In specific embodiments, the block data confirmed by the consensus is broadcasted to the distributed ledger nodes based on the resource access control instruction transaction data packet, and a distributed ledger node confirmation record is obtained, including: Converting the consensus-confirmed block data into a cross-node compatible data format through cross-node data format conversion, and mapping the cross-node compatible data format to a node address space to obtain a node address space mapping table; Distributing the node address space mapping table through node broadcast based on the gossip protocol to obtain a set of broadcast node confirmation messages, and verifying the validity of the broadcast messages based on the set of broadcast node confirmation messages to obtain valid broadcast node confirmation messages; Based on the valid broadcast node confirmation messages, the resource access control instruction transaction data packet is allocated to a node storage path to obtain a node storage path allocation result, and the node storage permission is verified based on the node storage path allocation result to obtain a node storage permission verification report; Based on the node storage permission verification report, a distributed ledger is generated to obtain a distributed ledger node confirmation record.
[0041] Specifically, in the process of distributing the block data confirmed by the consensus mechanism to the distributed ledger nodes for broadcasting the resource access control instruction transaction data packet, the system first performs a cross-node data format conversion operation on the block data that has been verified and confirmed by the blockchain consensus mechanism to ensure that the block can be correctly parsed and processed by different types of nodes in a heterogeneous network environment. Specifically, the system will convert the original block data into a universal and highly compatible cross-node compatible data format according to the data protocols, encoding methods, and communication interface specifications supported by each node. This format usually encapsulates core information such as block headers, Merkle tree root hash values, and transaction data packets using standardized data structures (such as JSON or Protobuf). Subsequently, the system further performs a node address space mapping operation on the cross-node compatible data format, which matches the target transmission path of the block data with the address space of each distributed ledger node in the network to generate a node address space mapping table. This mapping table explicitly indicates the receiving priority, network topology location, and communication channel configuration of each node in the current broadcasting process. On this basis, the system initiates the network-wide propagation process of the block data through a gossip protocol-based node broadcasting mechanism. This mechanism simulates the spread of information in the network, enabling the block data to cover the entire distributed network in an efficient and low-latency manner. The system sends the block data to each target node in turn according to the node address space mapping table and returns a broadcast node confirmation message upon successful reception at each node. These confirmation messages are collected by the system to form a broadcast node confirmation message set, which records which nodes have successfully received and preliminarily verified the block. To ensure the security and integrity of the broadcasting process, the system also performs a broadcast message validity verification operation on the broadcast node confirmation message set. It checks whether each confirmation message is sent by a legal node, whether it contains a complete digital signature, whether it conforms to the preset message format specification, and eliminates invalid or fake confirmation messages. Finally, it generates valid broadcast node confirmation messages, which serve as an important basis for subsequent node storage operations.Subsequently, the system dynamically allocates the storage path of the resource access control instruction transaction data packet on each node based on the valid broadcast node confirmation message, which combines network load balancing strategy, node storage capacity, historical storage efficiency and other factors to ensure that the distribution of transaction data in the entire network is both safe and efficient; the system generates a node storage path allocation result to specify which nodes each transaction data packet should be stored in and define its specific physical or logical storage path; in order to prevent unauthorized nodes from tampering with or accessing sensitive data, the system further performs a node storage permission verification operation on the node storage path allocation result, that is, by calling the smart contract or access control module, it verifies whether the target node has the permission to store such data; for example, in an enterprise internal document management system, if a node is only authorized for log auditing and has no right to directly access authorization credentials, the system will prevent the node from storing related transaction data in the verification stage and generate a corresponding node storage permission verification report detailing the reasons for the verification failure, the involved node ID and data packet identifier. Finally, based on the above node storage permission verification report, the system starts the generation process of the distributed ledger, formally writes all transaction data packets that have passed the effective broadcast and storage verification into the local ledger copy of each node, thereby forming a unified distributed ledger node confirmation record; this record not only indicates that the transaction data has been synchronized in the entire network, but also marks that the resource access control instruction has obtained the trust endorsement of multiple nodes and has the characteristics of non-tamperability and traceability; for example, in a document management system, when an employee initiates an access request for a highly sensitive folder and passes through the complete permission evaluation, policy matching and consensus verification process, the corresponding resource access control instruction transaction data packet will be submitted to the consortium chain network, after multi-node broadcast, storage path allocation and permission verification, it will finally be written into the distributed ledger of each participant, generating a distributed ledger node confirmation record as important technical evidence for future security audit, responsibility tracing or compliance review. In summary, through a series of operations such as cross-node data format conversion, node address space mapping, broadcast based on gossip protocol, broadcast message validity verification, node storage path allocation and permission verification, the system realizes the efficient propagation and trusted landing of resource access control instruction transaction data packets in the distributed ledger network; this process not only ensures the integrity and consistency of transaction data in the entire network, but also provides a solid technical support for the software resource operation authorization system, enhancing the transparency, security and auditability of authorized behavior.
[0042] The above describes the operation authorization method of the software resource in the embodiment of the application. The operation authorization system of the software resource in the embodiment of the application is described below. Please refer to Figure 2 The operation authorization system of the software resource in the embodiment of the application includes one embodiment: The extraction module 21 is configured to extract a user identity feature vector of a software resource operation request initiated by a user terminal, and perform permission mapping on the user based on the user identity feature vector to obtain a user permission attribute mapping table. The evaluation module 22 is configured to perform dynamic permission level evaluation on the user based on the user permission attribute mapping table to obtain user dynamic permission level data. The matching module 23 is configured to perform access control strategy matching on the software resource operation request based on the user dynamic permission level data to obtain a resource access control instruction. The storage module 24 is configured to store the resource access control instruction in an authorized record that is tamper-proof through a block chain consensus mechanism to obtain a distributed authorization confirmation voucher. The execution module 25 is configured to perform real-time instruction issuing and execution state monitoring on the software resource operation request based on the distributed authorization confirmation voucher.
[0043] In the embodiment, the specific implementation of each unit in the above device embodiment can be referred to the description of the above method embodiment, and will not be repeated here.
[0044] Reference Figure 3 In the embodiment of the present application, a computer device is also provided, and the internal structure of the computer device can be as shown in the figure. Figure 3 The computer device includes a processor, a memory, a display screen, an input device, a network interface and a database connected through a system bus. The processor of the computer device is configured to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operating system and the computer program in the non-volatile storage medium. The database of the computer device is configured to store the corresponding data in the embodiment. The network interface of the computer device is configured to communicate with an external terminal through a network connection. The computer program is executed by the processor to implement the above method.
[0045] Those skilled in the art can understand that Figure 3 The structure shown in the figure is only a block diagram of part of the structure related to the present application scheme, and does not constitute a limitation on the computer device to which the present application scheme is applied.
[0046] The embodiment of the present application also provides a computer readable storage medium having a computer program stored thereon, and the computer program is executed by the processor to implement the above method. It can be understood that the computer readable storage medium in the embodiment can be a volatile readable storage medium or a non-volatile readable storage medium.
[0047] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer readable storage medium, and when executed, can include the processes of the above-mentioned embodiment methods. Any reference to memory, storage, database or other medium provided by the present application and used in the embodiments can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. As an illustration but not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (SSRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM, etc.
[0048] It should be noted that in this document, the terms "comprising", "including", or any other variant thereof are intended to cover a non-exclusive inclusion, such that a process, device, article or method that comprises a list of elements does not only include those elements, but can also include other elements not expressly listed or inherent to such process, device, article or method. Without more limitations, the element defined by the statement "comprising a" does not exclude the presence of additional identical elements in the process, device, article or method that includes the element.
[0049] The above description is only the preferred embodiment of the present application, and does not limit the patent scope of the present application. Any equivalent structure or equivalent process transformation, or direct or indirect application in other related technical fields, based on the content of the present application specification and drawings, are also included in the patent protection scope of the present application.
Claims
1. A method for authorizing the operation of software resources, characterized in that: The following steps are involved: Extracting a user identity feature vector of a software resource operation request initiated by a user terminal, and performing permission mapping on the user based on the user identity feature vector to obtain a user permission attribute mapping table; Performing a dynamic authority level assessment on the user based on the user authority attribute mapping table to obtain user dynamic authority level data; Performing access control policy matching on the software resource operation request based on the user dynamic permission level data to obtain a resource access control instruction; The resource access control instructions are recorded and recorded in an unalterable manner through the blockchain consensus mechanism to obtain a distributed authorization confirmation certificate; Based on the distributed authorization confirmation credentials, real-time instruction issuance and execution status monitoring are performed on the software resource operation request.
2. The method for authorizing the operation of software resources according to claim 1, characterized in that: The user rights mapping is performed based on the user identity feature vector to obtain a user rights attribute mapping table, including: Decomposing the user identity feature vector in multiple dimensions to generate a user behavior feature sequence, and performing time series correlation analysis on the user behavior feature sequence to obtain a user operation mode feature map, which includes resource access time distribution, operation instruction sequence characteristics, and access address space distribution; Calculating the user's identity credibility based on the user operation mode feature map to obtain a user identity credibility result, and performing multi-level threshold division on the user identity credibility result to obtain a user trust level evaluation result; The user's permissions are hierarchically mapped based on the user trust level assessment results to obtain a permission hierarchical mapping matrix, and the permission hierarchical mapping matrix is parsed for permission attributes to obtain a user permission attribute mapping table, wherein the user permission attribute mapping table includes a resource operation permission set, an access control policy group, and a permission validity period limit.
3. The method for authorizing the operation of software resources according to claim 1, wherein: The step of performing a dynamic authority level assessment on the user based on the user authority attribute mapping table to obtain user dynamic authority level data includes: Performing permission correlation analysis on the user permission attribute mapping table to obtain a permission correlation matrix, and hierarchically clustering the permission correlation matrix to obtain a user permission hierarchy diagram, which includes a permission inheritance relationship tree, a permission dependency network diagram, and a permission conflict detection matrix; Dynamically weighting the user authority hierarchy structure diagram to obtain a time-decay curve for authority value, and performing an authority timeliness evaluation based on the time-decay curve to obtain an authority timeliness evaluation result; wherein the authority timeliness evaluation result includes an authority freshness index, an authority aging coefficient, and an authority urgency score; Dynamically adjust and calculate the user authority attribute mapping table based on the authority timeliness assessment result to obtain dynamically adjusted authority attributes, and perform authority risk quantification analysis based on the dynamically adjusted authority attributes to obtain an authority risk quantification matrix, wherein the authority risk quantification matrix includes an authority abuse risk index, an authority leakage risk coefficient, and an authority exceeding risk value; Perform a multi-dimensional risk level assessment on the authority risk quantification matrix to obtain user dynamic authority level data.
4. The method for authorizing the operation of software resources according to claim 1, wherein: The performing access control policy matching on the software resource operation request based on the user dynamic permission level data to obtain a resource access control instruction includes: Performing permission level mapping conversion on the user dynamic permission level data to obtain a permission level vector, and performing multi-dimensional feature space projection on the permission level vector to obtain a permission level feature space; Performing policy retrieval and matching on the permission level feature space to obtain a successfully matched access control policy candidate set, and performing policy conflict detection and elimination on the access control policy candidate set to obtain a conflict-free access control policy; Performing permission parsing on the software resource operation request based on the non-conflicting access control policy to obtain a permission parsing result set, and performing permission verification preprocessing based on the permission parsing result set to obtain a permission verification preprocessing result; Performing a permission compliance check on the permission verification preprocessing result to obtain a permission compliance check report, and performing a permission risk score on the permission compliance check report to obtain a permission risk score result; Dynamic permission instructions are generated for the conflict-free access control policy based on the permission risk scoring result to obtain resource access control instructions.
5. The method for authorizing the operation of software resources according to claim 1, wherein: The resource access control instruction is recorded and recorded in an unalterable manner through the blockchain consensus mechanism to obtain a distributed authorization confirmation certificate, including: The structured data encapsulates the resource access control instruction to generate a resource access control instruction transaction data packet, and performs a hash operation on the resource access control instruction transaction data packet to obtain a transaction data packet hash summary; Organizing the transaction data packet hash summary into a block data structure using a Merkle tree construction algorithm to obtain a Merkle tree root hash value, and synthesizing the block header information of the resource access control instruction transaction data packet based on the Merkle tree root hash value to obtain a block data structure to be reached consensus; Verify and screen candidate validator nodes in the consensus block data structure through the blockchain consensus mechanism, and sort the candidate validator nodes according to a preset weight strategy to obtain an ordered list of validator nodes; Performing step-by-step digital signature verification on the block data structure to be reached through the ordered verification node list to obtain a validator signature set, and performing block validity confirmation based on the validator signature set and a preset validator signature threshold to obtain consensus-confirmed block data; Based on the block data confirmed by the consensus, distributed authorization confirmation is performed on the resource access control instruction transaction data packet to obtain a distributed authorization confirmation certificate.
6. The method for authorizing the operation of software resources according to claim 5, characterized in that: The method of organizing the transaction data packet hash summary into a block data structure by using a Merkle tree construction algorithm to obtain a Merkle tree root hash value includes: Performing hierarchical leaf node mapping on the hash digest of the transaction data packet to obtain an initial leaf node sequence set, and performing even-padded processing on the initial leaf node sequence set to obtain a balanced leaf node set; Performing a hash concatenation operation on adjacent leaf nodes in the balanced leaf node set to obtain a set of intermediate-layer node hash values, and performing node integrity verification on the set of intermediate-layer node hash values to obtain a valid intermediate-layer node hash tree; Performing an iterative calculation on the hash tree of the valid intermediate nodes through a recursive hash aggregation mechanism to obtain a multi-level hash tree structure, and performing a tree height balance analysis based on the multi-level hash tree structure to obtain a hash tree balance evaluation report; A root node hash calculation is performed on the multi-level hash tree structure based on the hash tree balance evaluation report to obtain a Merkle tree root hash value.
7. The method for authorizing the operation of software resources according to claim 5, characterized in that: The block data confirmed based on the consensus performs distributed ledger node broadcasting on the resource access control instruction transaction data packet to obtain a distributed ledger node confirmation record, including: Performing cross-node data format conversion on the consensus-confirmed block data to obtain a cross-node compatible data format, and performing node address space mapping on the cross-node compatible data format to obtain a node address space mapping table; Performing distributed broadcasting of the node address space mapping table by node broadcasting based on the gossip protocol to obtain a broadcast node confirmation message set, and performing broadcast message validity verification based on the broadcast node confirmation message set to obtain a valid broadcast node confirmation message; Performing node storage path allocation on the resource access control instruction transaction data packet based on the valid broadcast node confirmation message to obtain a node storage path allocation result, and performing node storage permission verification based on the node storage path allocation result to obtain a node storage permission verification report; A distributed ledger is generated based on the node storage permission verification report to obtain a distributed ledger node confirmation record.
8. A software resource operation authorization system, characterized in that: include: An extraction module is used to extract a user identity feature vector of a software resource operation request initiated by a user terminal, and perform permission mapping on the user based on the user identity feature vector to obtain a user permission attribute mapping table; An evaluation module, configured to evaluate the user's dynamic authority level based on the user authority attribute mapping table to obtain user dynamic authority level data; A matching module, configured to perform access control policy matching on the software resource operation request based on the user dynamic permission level data to obtain a resource access control instruction; The evidence storage module is used to store the resource access control instructions in an unalterable authorization record through the blockchain consensus mechanism to obtain a distributed authorization confirmation certificate; The execution module is used to issue real-time instructions and monitor the execution status of the software resource operation request based on the distributed authorization confirmation certificate.
9. A computer device comprising a memory and a processor, wherein a computer program is stored in the memory, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.
Citation Information
Cited By
Information asset management system and protection intensity evaluation method thereof
CN121146917A
System online and offline authorization scheme design and implementation method
CN121365384A