Service platform role authority management method

By dynamically adjusting the role permissions of the service platform, the problem of low management efficiency caused by traditional static permission settings is solved, achieving flexible permission management and data security, and improving the platform's adaptability and efficiency.

CN121098527APending Publication Date: 2025-12-09HUANENG INFORMATION TECH CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510970018.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-14
Publication Date
2025-12-09

AI Technical Summary

Technical Problem

Traditional service platform role-based access control methods use static permission settings, which makes it difficult to adjust flexibly when business develops and needs change, reducing management efficiency and adaptability.

Method used

By acquiring the functional modules and business processes of the service platform, we can determine business characteristics and security requirements, configure roles and permission systems, make flexible adjustments based on user behavior and identity, use machine learning algorithms to classify operation permissions, and build a role permission tree to achieve dynamic permission management.

Benefits of technology

It improves the efficiency and flexibility of the service platform's permission management, enhances the adaptability of permissions, ensures data security and information confidentiality, and reduces the inefficiency caused by improper permission settings.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121098527A_ABST
    Figure CN121098527A_ABST
Patent Text Reader

Abstract

The invention provides a role authority management method for a service platform, which belongs to the technical field of role authority management, and comprises the following steps of: 1, acquiring functional modules and business processes in the service platform, and determining business characteristics and security requirements of the platform; 2, configuring roles and authority systems according to business characteristics and in combination with the function range of each function module; 3, defining responsibilities and accessible resources of different roles, formulating a detailed permission list, and obtaining a role permission control strategy at a server side in combination with the roles and a permission system; and step 4, according to the role permission control strategy and in combination with behaviors and identities of the users, performing elastic adjustment on the user permissions, and realizing permission management of the service platform roles according to an adjustment result. The problem that the service platform role permission management method adopts static permission setting, the permission setting of the role cannot be changed, the permission management efficiency of the service platform is greatly reduced, and meanwhile, the management flexibility and adaptability are reduced is solved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of role permission management, and particularly relates to a service platform role permission management method. BACKGROUND

[0002] With the continuous development of Internet technology, more and more enterprises and individuals begin to use online services to meet various needs, in order to ensure the stability and security of the service, role permission management has become an urgent problem to be solved.

[0003] However, the traditional service platform role permission management method adopts static permission setting, after assigning a user to a certain role, the permission setting of the role cannot be changed, however, with the development of business and the change of demand, this role may need more permissions, or need less permissions, greatly reducing the management efficiency of the service platform on the permission, at the same time, reducing the flexibility and adaptability of management.

[0004] Therefore, the present application provides a service platform role permission management method. SUMMARY

[0005] The present application provides a service platform role permission management method to solve the defects that the traditional service platform role permission management method in the prior art adopts static permission setting, after assigning a user to a certain role, the permission setting of the role cannot be changed, however, with the development of business and the change of demand, this role may need more permissions, or need less permissions, greatly reducing the management efficiency of the service platform on the permission, at the same time, reducing the flexibility and adaptability of management.

[0006] In one aspect, the present application provides a service platform role permission management method, comprising: Step 1: obtaining the function modules and business processes in the service platform, determining the business characteristics and security requirements of the platform according to the function modules and business processes; Step 2: configuring roles and permission systems according to the business characteristics and combining the function ranges of each function module; Step 3: defining the responsibilities and accessible resources of different roles, formulating a detailed permission list, and obtaining a role permission control strategy on the server side according to the permission list and combining the role and permission system; Step 4: flexibly adjusting the user permissions according to the role permission control strategy and the behavior and identity of the user, and realizing the role permission management of the service platform according to the adjustment result.

[0007] According to the service platform role permission management method provided by the present application, before configuring roles and permission systems according to business characteristics and combining the function ranges of each function module, it further comprises: obtain the related business tags and operation role levels of each function module, determine the identity permission bits of each function module according to the related business tags and operation role levels; determine the platform allocation resources of each function module, and determine the resource permission bits of each function module according to the platform allocation resources; configure the identity authentication identifier for each function module based on the resource permission bits and the identity permission bits of each function module; generate the signature file of each function module according to the identity authentication identifier, and determine the privacy permission set of each function module according to the signature file; determine the accessible sensitive data flow paths of each function module using static analysis; quantize the sensitive data flow paths into a first feature vector of benign service and a second feature vector of malignant service; determine the difference vector of the first feature vector and the second feature vector, and construct a feature sample matrix according to the difference vector; classify the operation permissions of each function module based on the feature sample matrix through a machine learning algorithm, and determine the benign operation permission and the malignant operation permission according to the classification result; obtain the target role levels of the benign operation permission and the malignant operation permission respectively, and configure the corresponding review rules according to the target role levels; determine the characteristic review parameters and the basic review parameters of the target role levels according to the review rules, and configure the role and permission system for each function module according to the characteristic review parameters and the basic review parameters.

[0008] According to the service platform role permission management method provided by the application, the function modules and business processes in the service platform are obtained, and the business characteristics and security requirements of the platform are determined according to the function modules and business processes, including: obtain the working process and running mode of the service platform, and obtain the function modules and business processes in the service platform according to the working process and running mode and in combination with user requirements; obtain the associated dependencies between the function modules and the specific steps of the business processes; determine the flow direction of data and information according to the associated dependencies between the modules; determine the key decision points and control points according to the specific steps of the processes, and determine the decision rules and security measures according to the key decision points and control points; determine the business characteristics and security requirements of the platform according to the flow direction of data and information, the decision rules and the security measures.

[0009] According to the service platform role permission management method provided by the application, the flow direction of data and information is determined according to the associated dependencies between the modules, including: By tracking the implementation of the code, analyzing the calling relationship between the various modules, and according to the calling relationship, obtaining the relationship and dependency between the various modules; According to the relationship and dependency between the various modules, determine the data flow graph, and according to the data flow graph, obtain the logical relationship between the data elements in the service platform; According to the logical relationship between the data elements, determine the inflow point and outflow point of the data, and according to the inflow point and outflow point of the data, determine the flow direction of the data and information; According to the flow direction, determine the mapping of the database table structure and the field, and realize the correct flow of the data.

[0010] According to the service platform role permission management method provided by the application, the role and permission system are configured according to the business characteristics and the function range of each function module, including: The business characteristics are analyzed, and the specific operation content of each function module is determined according to the analysis result; According to the specific operation content, determine the operation type required by each module, and according to the operation type, obtain the function range of each function module; According to the function range of each function module, each function module is allocated with corresponding role and permission; Get the operation behavior of each role on the service platform, and set the role state and behavior limit, and configure the role and permission system according to the role state and behavior limit.

[0011] According to the service platform role permission management method provided by the application, the responsibilities and accessible resources of different roles are defined, a detailed permission list is made, and the role permission control strategy is obtained on the server side according to the permission list and in combination with the role and permission system, including: The responsibilities and responsibility range of each role are determined, the accessible resources are determined according to the responsibilities and responsibility range, and a detailed permission list is made; According to the role and permission system, obtain the permission relationship between the roles, and construct the permission tree of the roles according to the permission relationship between the roles; Map the permission tree and the roles in the system to construct a role tree mapping table; Traverse the role tree mapping table, concatenate the permission set of each role as a string, form a permission code, and add the permission code to the attribute of the role, and obtain the role permission control strategy on the server side according to the permission set of the role after adding the code.

[0012] According to the service platform role permission management method provided by the application, the role permission tree is constructed according to the permission relationship between the roles, including: According to the permission information required by each role according to the actual operation condition of the existing service platform, the permission tree structure is determined according to the permission information; The permission inheritance rule is determined according to the responsibility and function of the role; The permission tree is constructed according to the permission tree structure and the permission inheritance rule and in combination with the graphical tool.

[0013] According to the service platform role permission management method provided by the application, the user permission is flexibly adjusted according to the role permission control strategy and the behavior and identity of the user, and the permission management of the service platform role is realized according to the adjustment result, which comprises: The behavior data of the user in the service platform is acquired and analyzed and processed, the habit mode and abnormal behavior information of the user are extracted according to the analysis and processing result; The behavior data of the user is matched with the role permission strategy, and it is judged whether the user has the permission to access the current page and execute the current operation according to the matching result; The user permission is flexibly adjusted according to the judgment result, and the permission management of the service platform role is realized according to the adjustment result.

[0014] Compared with the prior art, the application has the following beneficial effects: The role and permission system and the role permission control strategy are determined according to the business characteristics and security requirements of the platform, and the permission is dynamically adjusted in combination with the behavior and identity of the user, which can ensure that the user is assigned to a certain role and the permission setting of the role can be changed, greatly improving the management efficiency of the service platform on the permission, and enhancing the flexibility and adaptability of the management. BRIEF DESCRIPTION OF DRAWINGS

[0015] In order to more clearly illustrate the technical solutions in the application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or the prior art description. Obviously, the drawings in the following description are some embodiments of the application, and other drawings can be obtained by those skilled in the art without creative labor.

[0016] Figure 1 is a flowchart of the service platform role permission management method provided by the embodiment of the application; Figure 2 is a flowchart of determining the business characteristics and security requirements of the platform according to the function module and business process provided by the embodiment of the application. DETAILED DESCRIPTION

[0017] In order to make the objects, technical solutions and advantages of the present application clearer, the following will clearly and completely describe the technical solutions in the present application with reference to the drawings in the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the protection scope of the present application.

[0018] Embodiment 1 The service platform role permission management method provided by the embodiment of the present application comprises the following steps: Figure 1 As shown in the figure, the method mainly comprises the following steps: Step 1: Obtain the function modules and business processes in the service platform, and determine the business characteristics and security requirements of the platform according to the function modules and business processes; Step 2: Configure the role and permission system according to the business characteristics and in combination with the function ranges of the function modules; Step 3: Define the responsibilities and accessible resources of different roles, make a detailed permission list, and obtain the role permission control strategy on the server side according to the permission list and in combination with the role and permission system; Step 4: According to the role permission control strategy, the behavior and identity of the user are combined to adjust the user permission flexibly, and the role permission management of the service platform is realized according to the adjustment result.

[0019] In this embodiment, the business characteristics of the service platform generally refer to the specific functions and services provided by the platform.

[0020] In this embodiment, the role and permission system refers to a mechanism for classifying and dividing different functions, responsibilities and access permissions.

[0021] In this embodiment, the permission list is a list used to define and control the operations that the user can access and execute on the application program or website.

[0022] In this embodiment, the role permission control strategy refers to the method and rule for managing the role permission settings in the software system, which is used to determine the ability of each role to access and execute which tasks and operations.

[0023] In this embodiment, the flexible adjustment of the user permission refers to changing the permission level of the user in a specific situation so as to complete a specific task or access a specific function.

[0024] The beneficial effects of the above technical solutions are that the role and permission system and the role permission control strategy are determined according to the business characteristics and security requirements of the platform, and the permissions are dynamically adjusted in combination with the behaviors and identities of users, so that the permissions of a role can be changed after the user is assigned to the role, the management efficiency of the permissions of the service platform is greatly improved, and the flexibility and adaptability of management are enhanced.

[0025] Embodiment 2 Based on the basis of embodiment 1, the embodiment of the application further includes the following before the role and permission system is configured according to the business characteristics and in combination with the function ranges of the various function modules: obtaining relevant business tags and operation role levels of the various function modules, determining the identity permission bits of each function module according to the relevant business tags and operation role levels; determining platform allocation resources of each function module, determining the resource permission bits of each function module according to the platform allocation resources; configuring an identity authentication identifier for each function module based on the resource permission bits and the identity permission bits of each function module; generating a signature file of each function module according to the identity authentication identifier, determining a privacy permission set of each function module according to the signature file; determining the accessible sensitive data flow paths of each level of privacy permission in each function module using static analysis; quantifying the sensitive data flow paths into a first feature vector of benign service and a second feature vector of malignant service; determining a difference vector of the first feature vector and the second feature vector and constructing a feature sample matrix according to the difference vector; classifying the operation permissions of each function module based on the feature sample matrix through a machine learning algorithm, and determining benign operation permissions and malignant operation permissions according to the classification results; obtaining target role levels of the benign operation permissions and the malignant operation permissions respectively, and configuring responsive review rules according to the target role levels; determining characteristic review parameters and basic review parameters of the target role levels according to the review rules, and configuring the role and permission system for each function module according to the characteristic review parameters and the basic review parameters.

[0026] In this embodiment, the relevant business tags of the function modules can be content management and user management.

[0027] In this embodiment, the operation role level refers to the permission level and access range of different operation roles in the same module.

[0028] In this embodiment, the identity permission bits of a function module refer to the permissions that can be granted to users for each function module, which can include access to certain specific functions, the ability to manipulate certain data, for example, in a sales management system, there may be different types of permission bits such as "view customer information", "add customer information", "modify customer information", "delete customer information".

[0029] In this embodiment, the resource permission bits of a function module refer to the permissions that can access which resources for each function module, these resources can include files, database records, network connections.

[0030] In this embodiment, the identity authentication identifier refers to a marker used to verify the identity of a user and determine whether the user has permission to access a particular resource or perform a particular operation.

[0031] In this embodiment, the signature file of a function module is a file used to record and manage the metadata of a function module, containing information about each function module, such as module name, version number, author, dependencies.

[0032] In this embodiment, the privacy permission set of a function module is a set of access control rules related to a specific function module, defining the operations and access permissions that users can perform on the function module, including: view, edit, delete, etc. operations, and specific security policies such as access restrictions and identity verification requirements.

[0033] In this embodiment, static analysis is a technique for in-depth inspection of compiled programs or code.

[0034] In this embodiment, the accessible sensitive data flow path refers to a path in the platform that can be used to obtain, process or leak sensitive data.

[0035] In this embodiment, quantifying the sensitive data flow path into a first feature vector of benign service and a second feature vector of malignant service refers to quantitatively describing and classifying certain properties or behaviors of the platform in order to identify the normal operating state and abnormal conditions of the system.

[0036] In this embodiment, the benign operation permission refers to the permission level of a group of users authorized to perform specific tasks.

[0037] In this embodiment, the malignant operation permission refers to the permission level of a group of users authorized to perform destructive tasks or dangerous behaviors.

[0038] In this embodiment, the characteristic audit parameters and the basic audit parameters of the role hierarchy refer to parameters for setting and managing the permissions and functions of each role in the franchising process. The characteristic audit parameters can be role description and operation permission, and the basic audit parameters can be role name.

[0039] The beneficial effects of the above technical solution are: determining the characteristic audit parameters and the basic audit parameters of the target role hierarchy according to the audit rules, and configuring roles and permission systems for each function module. Through the explicit setting of the audit rules and the permission systems, data security and information confidentiality can be ensured. At the same time, by configuring roles and permission systems for each function module, each user can only access the functions they have permission to, thereby avoiding low work efficiency caused by improper permission settings.

[0040] Embodiment 3 Based on the basis of embodiment 2, the service platform in the embodiment of the application obtains function modules and business processes, determines the business characteristics and security requirements of the platform according to the function modules and business processes, as shown in the following formula: Figure 2 The formula includes: S01: obtaining the workflow and running mode of the service platform, and obtaining the function modules and business processes in the service platform according to the workflow and running mode and in combination with user requirements; S02: obtaining the association dependency between the function modules and the specific steps of the business processes; S03: determining the flow direction of data and information according to the association dependency between the modules; S04: determining the key decision points and control points according to the specific steps of the processes, and determining the decision rules and security measures according to the key decision points and control points; S05: determining the business characteristics and security requirements of the platform according to the flow direction of data and information, the decision rules and the security measures.

[0041] In this embodiment, the flow direction of data and information can be from the collection source to the processing, storage, analysis and presentation stages, for example, the collected data may pass through multiple steps and finally be presented to the user.

[0042] In this embodiment, the key decision point refers to a step that has the greatest influence and decisiveness in a decision-making process.

[0043] In this embodiment, the control point refers to a point at which some variables can be controlled and adjusted to make the platform run in the expected way.

[0044] In this embodiment, the decision rule refers to the guiding principle or standard used when making decisions.

[0045] The beneficial effects of the above technical solutions are: obtaining the function modules and business processes in the service platform, determining the business characteristics and security requirements of the platform according to the function modules and business processes, more clearly understanding the business requirements of the platform, determining the platform that is more in line with actual requirements, improving the usability and practicality of the platform, and at the same time, through the analysis of the business process, the performance bottleneck and potential problems of the platform can be found, and the performance and running efficiency of the platform can be improved.

[0046] Embodiment 4: Based on the basis of Embodiment 3, the flow direction of data and information is determined according to the association dependency between modules, including: By tracking the implementation of the code, the calling relationship between each module is analyzed, and the relationship and dependency between each module are obtained according to the calling relationship; According to the relationship and dependency between each module, a data flow graph is determined, and the logical relationship between each data element in the service platform is obtained according to the data flow graph; According to the logical relationship between each data element, the data inflow point and outflow point are determined, and the flow direction of data and information is determined according to the data inflow point and outflow point; According to the flow direction, the mapping of the database table structure and the field is determined, and the correct flow of data is realized.

[0047] In this embodiment, the calling relationship between modules generally refers to how one module depends on another module to complete its function, and such dependency can be realized through interfaces, inheritance, combination, etc., including single dependency, multiple dependency, and combination dependency.

[0048] In this embodiment, the data flow graph is a graphical tool for describing the data processing process of a software system, which shows the input, conversion and output process of data in a graphical manner.

[0049] In this embodiment, the data inflow point refers to the first source of data, which is usually an external entity or a user interface.

[0050] In this embodiment, the data outflow point refers to the final destination of data, indicating where the processed data is to be sent.

[0051] In this embodiment, the database table structure refers to the structure of the table defined in the database, and each table has its specific name, field and data type, which describes the structure of the data stored in the table.

[0052] The beneficial effects of the above technical solutions are: determining the flow direction of data and information according to the correlation dependency between modules, the flow direction of data between different modules can be defined through explicit interfaces and data formats, thereby avoiding additional workload and time caused by unclear data transmission mode, and since the flow direction of data and information between different modules is determined, the correctness and integrity of data can be ensured, and the risk of data and information loss caused by data transmission errors is reduced.

[0053] Embodiment 5: Based on the basis of Embodiment 4, the present embodiment configures a role and permission system according to the service characteristics and the functional range of each functional module, including: Analyzing the service characteristics, determining the specific operation content of each functional module according to the analysis result; Determining the operation type required to be executed by each module according to the specific operation content, obtaining the functional range of each functional module according to the operation type; Assigning the corresponding role and permission to each functional module according to the functional range of each functional module; Obtaining the operation behavior of each role on the service platform, setting the role state and behavior limit, and configuring the role and permission system according to the role state and behavior limit.

[0054] In this embodiment, the service characteristics of the service platform generally refer to the specific functions and services provided by the platform.

[0055] In this embodiment, the operation type generally refers to the operation type of each module on the platform, such as registration, login, and browsing.

[0056] In this embodiment, different functional modules have different functional ranges, such as registering a new account: allowing users to input personal information and create a new account, possible functions including: username / email address selection, password setting, confirming subscription email, filling in personal information (name, gender, date of birth, etc.).

[0057] In this embodiment, the role state refers to the identity and permission state of a user in a specific application or website, such as a normal user, an advanced user, an administrator, and an auditor.

[0058] In this embodiment, the behavior limit is used to track, monitor, and limit the behavior of users when using the application or website, such as: Prohibiting specific actions: by limiting users from performing certain inappropriate or unsafe actions, such as uploading malicious files or attempting to crack passwords.

[0059] Time limit: By setting a time limit for user access to the website, it prevents users from overusing the service or abusing resources.

[0060] The beneficial effects of the above technical solutions are: configuring the role and permission system according to the business characteristics and the functional range of each functional module, configuring the role and permission system can make the service platform system more modularized, componentized and standardized, can reduce the coupling degree of the system, and improve the maintainability and scalability of the system.

[0061] Embodiment 6: Based on the basis of embodiment 5, the responsibilities and accessible resources of different roles are defined, a detailed permission list is made, and a role permission control strategy is obtained on the server side according to the permission list and in combination with the role and permission system, including: The responsibilities and responsibility ranges of each role are determined, the accessible resources are determined according to the responsibilities and responsibility ranges, and a detailed permission list is made; According to the role and permission system, the permission relationship between roles is obtained, and a permission tree of the role is constructed according to the permission relationship between the roles; Map the permission tree with the roles in the system to construct a role tree mapping table; Traverse the role tree mapping table, concatenate the permission set of each role as a string, form a permission code, and add the permission code to the attribute of the role, and obtain the role permission control strategy on the server side according to the permission set of the role after adding the code.

[0062] In this embodiment, the permission list is a list used to define and control the operations that users can access and execute on an application or website.

[0063] In this embodiment, the role and permission system refers to a mechanism for classifying and dividing different functions, responsibilities and access permissions.

[0064] In this embodiment, the permission code is a way to encode the access permissions of a specific resource, so that the administrator can control and limit the user's access to the resource. This way usually uses characters or numbers to represent the access level to determine whether the user has the right to access a specific resource.

[0065] In this embodiment, the attributes of the role are a set of characteristics and attributes that describe a role, which determine which resources the role can access, which functions and permissions the role has, etc. For example, a role may be given the permission to "edit" a document, while another role may only be granted the permission to "view" the document.

[0066] In this embodiment, the role permission control strategy refers to the method and rules for managing the role permission settings in the software system, which is used to determine the ability of each role to access and perform which tasks and operations.

[0067] The above technical solution has the beneficial effects that: the permission relationship between roles is obtained according to the role and permission system, and a permission tree of roles is constructed, the role tree mapping table is constructed by mapping the roles in the system, the role permission control strategy is obtained, the permissions can be better managed and controlled, the permission strategy can be defined and managed on the server side, the consistency and correctness of the permission settings are ensured, and business problems caused by improper permission configuration are avoided.

[0068] Embodiment 7: Based on the basis of embodiment 6, the role permission tree is constructed according to the permission relationship between the roles, including: According to the actual running status of the existing service platform, the permission information required by each role, the permission tree structure is determined according to the permission information; The permission inheritance rules are determined according to the responsibilities and functions of the roles; The permission tree is constructed according to the permission tree structure and the permission inheritance rules and combined with the graphical tool.

[0069] In this embodiment, the permission information is a set of attributes that describe who can access and modify a certain object (such as a document, image, video, etc.), which can control the content and appearance of the object and determine whether the object can be edited, deleted or downloaded, etc., including: read, write, modify, delete, share.

[0070] In this embodiment, the permission tree structure is a way to organize permissions, which combines a group of related permissions into a node, and this node can contain other child nodes and attributes.

[0071] In this embodiment, the permission inheritance rule means that when a user has a parent permission, its permission will automatically inherit the parent's permission, that is, if a user is authorized to perform a task and the task is a subtask of the parent task, the user does not need to obtain the permission of the parent task separately, because the permission of the parent task has been automatically passed to the subtask.

[0072] In this embodiment, the graphical tool is a software development method that uses graphical interfaces to design and build applications.

[0073] In this embodiment, the permission tree is a tree structure used to represent a group of resources, each resource has a parent node and one or more child nodes, for example, in a company's permission tree, the root node may be "company" or "administration department", and "sales department" and "human resources department" may appear as subordinate departments under the tree.

[0074] The beneficial effects of the above technical solution are: according to the role permission tree constructed according to the permission relationship between the roles, the relationship between the roles and the permission structure of the roles can be clearly and easily understood, the relationship and permission setting between the roles can be more easily understood and mastered, so as to avoid errors and unnecessary conflicts, and at the same time, the permission management of the platform can be more flexible and adaptive.

[0075] Embodiment 8: Based on the basis of embodiment 7, the embodiment of the application adjusts the user permission flexibly according to the role permission control strategy combined with the behavior and identity of the user, and realizes the permission management of the service platform role according to the adjustment result, including: Obtain and analyze and process the behavior data of the user in the service platform, extract the habit pattern and abnormal behavior information of the user according to the analysis processing result; Match the behavior data of the user with the role permission strategy, and judge whether the user has permission to access the current page and execute the current operation according to the matching result; According to the judgment result, the user permission is flexibly adjusted, and the permission management of the service platform role is realized according to the adjustment result.

[0076] In this embodiment, the behavior data can be: login time, login frequency, login location, operation behavior of the user.

[0077] In this embodiment, the abnormal behavior information can be: multiple incorrect input of login password, out-of-place login.

[0078] In this embodiment, the role permission strategy is a way to manage the user permissions of an application or website, which defines which functions and resources the user can access, and allows the administrator to assign different permissions according to the user's role.

[0079] In this embodiment, the flexible adjustment of user permission means changing the permission level of the user in a specific situation so that the user can complete a specific task or access a specific function.

[0080] The beneficial effects of the above technical solution are: by obtaining the habit pattern and abnormal behavior information of the user and matching with the role permission strategy, the user permission is flexibly adjusted, by adjusting the user permission in real time, there is no need to manually assign permissions for each user, the platform will automatically recommend appropriate permissions for the user according to the user's access behavior and identity, thereby saving a lot of time and human resources, at the same time, by flexibly adjusting the user permission, more fine-grained control and protection can be provided for the user, thereby improving the security of the service platform.

[0081] Those skilled in the art can clearly understand the technical solutions of the various embodiments from the above description of the embodiments, and the various embodiments can be implemented by means of software with the necessary general hardware platforms, and of course, can also be implemented by hardware. Based on such understanding, the above technical solutions, essentially or in other words, the part of the prior art that makes a contribution, can be embodied in the form of a software product, which can be stored in a computer readable storage medium, such as a ROM / RAM, a magnetic disk, an optical disk, and the like, and includes a number of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.

[0082] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present application, rather than limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that: it can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacement for some technical features therein; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application.

Claims

1. A method for managing role-based access permissions on a service platform, characterized in that, include: Step 1: Obtain the functional modules and business processes within the service platform, and determine the platform's business characteristics and security requirements based on the functional modules and business processes; Step 2: Configure roles and permission systems based on business characteristics and the functional scope of each module; Step 3: Define the responsibilities and accessible resources of different roles, formulate a detailed permission list, and obtain the role permission control policy on the server side based on the permission list and in combination with the role and permission system; Step 4: Based on the role-based access control strategy and the user's behavior and identity, flexibly adjust the user's permissions, and implement the service platform role-based access management based on the adjustment results.

2. The service platform role and permission management method according to claim 1, characterized in that, Before configuring roles and permission systems based on business characteristics and the functional scope of each module, the following is also included: Obtain the relevant business tags and operation role levels of each functional module, and determine the identity and permission bits of each functional module based on the relevant business tags and operation role levels; Determine the platform-allocated resources for each functional module, and determine the resource permission bits for each functional module based on the platform-allocated resources; Configure an identity authentication identifier for each functional module based on its resource permission bits and identity permission bits; A signature file for each functional module is generated based on the identity authentication identifier, and the set of privacy permissions for each functional module is determined based on the signature file. Static analysis was used to determine the accessible sensitive data flow paths within each functional module for each level of privacy permissions. Sensitive data flow paths are quantified into a first feature vector for benign services and a second feature vector for malicious services; Determine the difference vector between the first and second eigenvectors and construct a feature sample matrix based on the difference vector; The operation permissions of each functional module are classified based on the feature sample matrix using machine learning algorithms, and benign operation permissions and malicious operation permissions are determined based on the classification results. Obtain the target role level for both benign and malicious operation permissions, and configure corresponding review rules based on the target role level; Based on the audit rules, determine the characteristic audit parameters and basic audit parameters for the target role level, and configure roles and permission systems for each functional module based on the characteristic audit parameters and basic audit parameters.

3. The service platform role and permission management method according to claim 1, characterized in that, Obtain the functional modules and business processes within the service platform, and determine the platform's business characteristics and security requirements based on these modules and processes, including: Obtain the workflow and operation mode of the service platform, and based on the workflow and operation mode and combined with user needs, obtain the functional modules and business processes within the service platform; Obtain the dependencies between functional modules and the specific steps of the business process; The direction of data and information flow is determined based on the dependencies between modules; Based on the specific steps of the process, key decision points and control points are determined, and decision rules and security measures are determined based on the key decision points and control points. The platform's business characteristics and security requirements are determined based on the flow of data and information, decision-making rules, and security measures.

4. The service platform role and permission management method according to claim 2, characterized in that, Determine the direction of data and information flow based on the dependencies between modules, including: By tracing the implementation of the code, the call relationships between various modules are analyzed, and the relationships and dependencies between the modules are obtained based on the call relationships. The data flow diagram is determined based on the relationships and dependencies between the modules, and the logical relationships between the data elements within the service platform are obtained based on the data flow diagram. The inflow and outflow points of data are determined based on the logical relationships between data elements, and the flow direction of data and information is determined based on the inflow and outflow points of data. The mapping of database table structure and fields is determined based on the flow direction to achieve correct data flow.

5. The service platform role and permission management method according to claim 1, characterized in that, Configure roles and permission systems based on business characteristics and the functional scope of each functional module, including: Analyze the business characteristics and determine the specific operational content of each functional module based on the analysis results; Based on the specific operation content, determine the operation type that each module needs to perform, and obtain the functional scope of each functional module based on the operation type; Assign corresponding roles and permissions to each functional module according to its functional scope. Obtain the operational behavior of each role on the service platform, set the role status and behavior restrictions, and configure the role and permission system according to the role status and behavior restrictions.

6. The service platform role and permission management method according to claim 1, characterized in that, Define the responsibilities and accessible resources of different roles, formulate a detailed permission list, and obtain the role permission control policy on the server side based on the permission list and in conjunction with the role and permission system, including: Clearly define the responsibilities and scope of duties for each role, determine the accessible resources based on the defined responsibilities and scope of duties, and develop a detailed list of permissions; Obtain the permission relationships between roles based on the roles and permission system, and construct the permission tree for the roles based on the permission relationships between the roles; Map the permission tree to roles in the system to build a role tree mapping table; Traverse the role tree mapping table, concatenate the permission set of each role as a string to form a permission code, and add the permission code to the role's attributes. Based on the permission set of the role with the added code, obtain the role permission control policy on the server side.

7. The service platform role and permission management method according to claim 5, characterized in that, Construct a permission tree for the roles based on the permission relationships between them, including: Based on the actual operation of the existing service platform, the permission tree structure is determined according to the permission information required by each role. Determine the rules for permission inheritance based on the responsibilities and functions of the roles; The permission tree is constructed based on the permission tree structure and permission inheritance rules, combined with a graphical tool.

8. The service platform role and permission management method according to claim 1, characterized in that, Based on the role-based access control policy and user behavior and identity, user permissions are flexibly adjusted. The adjustment results enable access management for service platform roles, including: Acquire user behavior data on the service platform, analyze and process it, and extract user habit patterns and abnormal behavior information based on the analysis and processing results; The system matches user behavior data with role-based access control policies and determines whether a user has permission to access the current page and perform the current operation based on the matching results. Based on the judgment results, user permissions are flexibly adjusted, and the service platform role permission management is implemented based on the adjustment results.