A dynamic renewal system and method for non-permanent term permissions
The dynamic renewal system solves the problems of permission drift and ghost accounts in traditional permission management, realizes dynamic matching of permission status with business needs, reduces security risks, adapts to the continuous verification requirements of zero-trust architecture, and simplifies the compliance audit process.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SHANGHAI BEIRUI INFORMATION TECH CO LTD
- Filing Date
- 2026-03-17
- Publication Date
- 2026-07-10
AI Technical Summary
Traditional RBAC/ABAC permission management systems adopt a static authorization model with no fixed term, which leads to long-term fixed attack surfaces such as permission drift, ghost accounts, and credential leakage. This makes it difficult to meet the periodic review requirements of compliance regulations, and cannot adapt to the continuous verification requirements of zero-trust architecture. As a result, the system has high security risks, high compliance audit costs, and a disconnect between business permissions and actual needs.
Design a dynamic permission renewal system with no fixed time limit, including a business gateway, permission database, renewal decision engine, and approval adaptation module. Through the collaborative work of permission renewal verification hook program, renewal decision engine, and approval adaptation module, dynamic permission renewal and continuous verification are realized. Combining a dual-track mode of manual and system self-approval, hierarchical risk control and automated permission review are carried out.
It achieves dynamic matching of permission status with users' actual business access needs, prevents permission drift, dynamically shrinks the attack surface, reduces security risks, simplifies compliance auditing processes, adapts to the continuous verification needs of zero-trust architecture, and realizes the automation and normalization of permission management.
Smart Images

Figure CN122365530A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of access control technology, specifically to a dynamic renewal system and method for access rights without fixed expiration dates. Background Technology
[0002] Access control generally refers to the system's security rules or policies, which allow users to access only the resources they are authorized to access, no more and no less. Access control is present in almost any system with users and passwords. Its core principles include the principle of least privilege, the principle of separation of duties, and the principle of auditing. Its purpose is to improve system security, prevent accidental operations, and improve work efficiency. Access control in a system is generally divided into access permissions and data permissions.
[0003] Traditional RBAC / ABAC permission management systems employ a static authorization model where permissions are granted once and remain effective indefinitely. Permission cleanup relies solely on manual auditing or when staff leave the company. Consequently, continuous verification and dynamic control of permissions are impossible, leading to permission drift, ghost accounts, and persistent attack surfaces after credential leaks. Furthermore, these systems struggle to meet the periodic review requirements of compliance regulations and cannot adapt to the continuous verification needs of a zero-trust architecture. Ultimately, this results in a complex situation characterized by persistently high system security risks, exorbitant compliance audit costs, and a severe disconnect between business permissions and actual needs. Summary of the Invention
[0004] To address the shortcomings of existing technologies, this invention provides a dynamic renewal system and method for permissions without fixed time limits, thus solving the problems mentioned in the background art.
[0005] To achieve the above objectives, the present invention provides the following technical solution: a dynamic renewal system for permissions without fixed time limits, comprising a business gateway, a permission database, a renewal decision engine, and an approval adaptation module, wherein the business gateway is communicatively connected to the permission database, the renewal decision engine, and the approval adaptation module, and the renewal decision engine is communicatively connected to the approval adaptation module. The business gateway has a built-in permission renewal verification hook program, which is used to intercept user access requests to protected resources of the business system and trigger the permission renewal verification hook program to start the renewal process. The business gateway is also used to initiate permission query requests to the permission database, perform type verification and status marking on the returned permission records, perform hierarchical renewal control operations according to the risk level returned by the renewal decision engine, and complete the final update of the permission status according to the approval results synchronized by the approval adaptation module. The permission database is used to store all user permission data, including permission type, preset permission validity period, and permission status information. It is used to respond to and execute all permissions query, deletion, validity period extension, and permission regeneration instructions sent by the business gateway. The renewal decision engine is used to receive the pending renewal permission information, the corresponding user's identity and access behavior information synchronized by the business gateway, complete the comprehensive risk calculation and output the corresponding risk level, and provide a basis for judgment for the hierarchical renewal management of the business gateway. The approval adaptation module is used to connect with the manual approval process, generate and push manual approval tasks, receive the approval results of the approval management personnel and synchronize them to the business gateway, and at the same time complete the information push of renewal notification, risk alarm and approval reminder.
[0006] Preferably, the permission database is constructed based on the RBAC or ABAC permission model, and only two fields, permission validity period and permission status, are added to the original permission table without changing the primary key, foreign key and core table structure of the original permission table.
[0007] Preferably, the renewal decision engine has a built-in risk rules submodule and an AI submodule; The risk rule sub-engine is used to output rule risk scores based on preset static risk rules, and the AI sub-engine is used to output model risk scores based on user history behavior and permission usage data. The renewal decision engine combines the rule risk score and the model risk score to obtain a comprehensive risk score, and outputs the risk level by comparing the comprehensive risk score with a preset threshold. The AI sub-engine also has a built-in incremental training unit that can automatically adjust and optimize the value of preset thresholds based on historical feedback data of erroneous rejections and releases during manual approval.
[0008] Preferably, the business gateway also has a built-in gray-scale control unit, which performs gray-scale release and one-click rollback of the triggering scope of the permission renewal verification hook program according to the user, role, department or business system dimensions.
[0009] A dynamic renewal method for permissions without a fixed term includes the following steps: S1. When a user initiates an access request for a protected resource of a business system, the business gateway intercepts the access request, triggers the built-in permission renewal verification hook program, and starts the permission renewal verification process. S2. Based on the initiated renewal verification process, the business gateway sends a query command to the permission database to query the permission records of the user corresponding to this access request that have expired the preset permission validity period; after receiving the query command, the permission database retrieves the matching permission records and returns them to the business gateway. S3. After receiving the returned permission records, the business gateway verifies the permission type of each permission record. If the verification determines that the permission is not a permission without a fixed term, the business gateway sends a permission deletion instruction to the permission database to complete the closed loop of reclaiming the expired permission. If the verification determines that the permission is a permission without a fixed term, the permission without a fixed term is marked as pending renewal and proceeds to the subsequent risk assessment steps. S4. The business gateway will synchronously send the user's identity information and access behavior information of the user with the non-fixed-term permission marked as pending renewal to the renewal decision engine. The renewal decision engine will perform a comprehensive risk calculation on the received information, output the corresponding risk level, and return the risk level result to the business gateway. S5. After receiving the risk level result, the business gateway executes the corresponding renewal control operation according to the preset risk classification rules. S6. For manual approval tasks generated at the medium risk level, after the approval management personnel complete the approval operation, the approval adaptation module will synchronize the approval result to the business gateway. If the approval result is passed, the business gateway sends an instruction to the permission database to regenerate the permission without a fixed term and extend the validity period of the permission by a full preset period, and restore the permission status to the normal effective state. If the approval result is rejection, the indefinite-term permission will remain permanently invalid, completing the closed loop of this renewal process.
[0010] Preferably, in step S5, after the service gateway receives the risk level result, it performs the corresponding renewal control operation according to the preset risk classification rules, specifically as follows: If the risk level is determined to be low, the business gateway will execute the system's self-approval process. After approval, the pending unlimited period of the permission will be extended for a full preset permission validity period, and the permission status will be restored to the normal effective status. If the risk level is determined to be medium, the business gateway will generate a corresponding manual approval task, and simultaneously temporarily revoke the pending non-fixed-term permissions, suspend its access permissions and wait for the approval result. If the risk level is determined to be high, the business gateway will immediately and permanently revoke the pending, indefinite-term permission, mark the permission status as permanently invalid, and send a risk warning notification to the preset approval management personnel through the approval adaptation module.
[0011] Preferably, the protected resource access request initiated by the user in step S1 includes: Any one of the following: user login request to business system, protected business interface call request, or protected data resource access operation request.
[0012] Preferably, the specific process of comprehensive risk calculation and level output in step S4 is as follows: The rule risk score output by the comprehensive risk rule sub-engine of the renewal decision engine and the model risk score output by the AI sub-engine are combined to obtain the comprehensive risk score R. The comprehensive risk score R is compared with the preset first risk threshold T1 and second risk threshold T2, where T1 < T2. When R ≤ T1, it is determined to be a low risk level; when T1 < R ≤ T2, it is determined to be a medium risk level; and when R > T2, it is determined to be a high risk level.
[0013] Preferably, the AI sub-engine supports online incremental training, adjusting and optimizing the values of the first risk threshold T1 and the second risk threshold T2 based on historical feedback data of false rejections and false releases in manual approval, and updating the accuracy of risk level determination.
[0014] Preferably, in step S5, after the system completes the permission renewal process through the self-approval process, it simultaneously sends an automatic renewal notification for the permission without a fixed term to the preset approval management personnel through the approval adaptation module. After temporarily revoking permissions without a fixed term, if a user initiates another request to access protected resources, the business gateway will return a message to the user indicating that the permission is pending approval. At the same time, it will push an approval reminder to the approval administrator through the approval adaptation module.
[0015] This invention provides a dynamic renewal system and method for permissions without a fixed term. It has the following beneficial effects: (1) By building dynamic renewal and continuous verification triggered when access is granted for permissions without fixed time limits, the traditional static authorization mode is replaced. It can trigger risk assessment and status control of permissions in real time based on user access behavior, so that the permission status keeps dynamically matched with the user's actual business access needs. This avoids the problem of permission drift forming ghost accounts from the root, realizes the accurate adaptation of business permissions to actual needs, prevents the drawback of long-term disconnect between permissions and business needs in the traditional mode, and makes permission management fit the actual business usage scenario.
[0016] (2) By setting an effective period for permissions without a fixed term and implementing a graded risk control strategy, the permanently open access point is transformed into a periodically verified dynamic access point. Even if account credentials are leaked, attackers cannot use the permissions to carry out malicious operations for a long time. At the same time, permissions can be permanently revoked directly in high-risk scenarios, thereby achieving dynamic shrinkage of the system attack surface and greatly reducing the security risks of illegal access. This effectively curbs the growth of system security risks from a mechanism perspective.
[0017] (3) The manual periodic audit of permissions is transformed into automated real-time renewal verification. The dual-track mode of system self-approval and manual approval is combined to complete the permission review. There is no need for manual full permission verification. At the same time, the entire process of permission renewal is traceable and auditable, which fully meets the periodic review requirements of compliance regulations and is also compatible with the core principle of continuous verification of zero trust architecture. This realizes the automation and normalization of permission compliance management, greatly simplifies the compliance audit process, and allows permission management to meet both compliance requirements and the adaptation needs of zero trust architecture. Attached Figure Description
[0018] Figure 1 This is a flowchart illustrating the steps of the dynamic renewal method for non-fixed-term rights according to the present invention. Figure 2 This is a system flowchart illustrating the dynamic renewal of rights without a fixed term, as described in this invention. Detailed Implementation
[0019] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0020] Example 1 Please see Figure 1-2 This invention provides a dynamic renewal system and method for permissions without fixed time limits. To achieve the above objectives, this invention is implemented through the following technical solution: including a business gateway, a permission database, a renewal decision engine, and an approval adaptation module. The business gateway is communicatively connected to the permission database, the renewal decision engine, and the approval adaptation module, respectively. The renewal decision engine is communicatively connected to the approval adaptation module. The business gateway has a built-in permission renewal verification hook program, which is used to intercept user access requests to protected resources of the business system and trigger the permission renewal verification hook program to start the renewal process. The business gateway is also used to initiate permission query requests to the permission database, perform type validation and status marking on the returned permission records, perform hierarchical renewal control operations based on the risk level returned by the renewal decision engine, and complete the final update of permission status based on the approval results synchronized by the approval adaptation module. The permission database is used to store all user permission data, including permission type, preset permission validity period, and permission status information. It is used to respond to and execute all permission query, deletion, validity period extension, and permission regeneration instructions sent by the business gateway. The renewal decision engine receives the pending permission information, the corresponding user's identity and access behavior information synchronized by the business gateway, completes comprehensive risk calculation and outputs the corresponding risk level, providing a basis for judgment for the hierarchical renewal management of the business gateway. The approval adaptation module is used to connect with manual approval processes, generate and push manual approval tasks, receive approval results from approval managers and synchronize them to the business gateway, and push information such as renewal notifications, risk alerts and approval reminders.
[0021] In this embodiment, the business gateway is deployed as a reverse proxy service that is completely decoupled from the business application service. The permission renewal verification hook program is embedded in the request processing link of the gateway in the form of an aspect. It is fixed at the execution node after the user identity authentication is completed and before the business request is forwarded to the upstream application service. This ensures that all access requests for protected resources that have been authenticated can complete the renewal verification before reaching the business system. This achieves full coverage of the control logic at the link level and does not intrude on the service code of the business system at all. The business gateway and the permission database use pre-compiled structured query statements to complete data interaction. At the same time, a read-write separation strategy is configured. Permission query operations access the read-only slave database, while write operations such as permission status updates, deletions, and regenerations access the master database, balancing query performance and data consistency in high-concurrency scenarios. The business gateway communicates with the renewal decision engine via a RESTful API interface. The interface is configured with a timeout circuit breaker mechanism. When the renewal decision engine service is unavailable, it automatically degrades to the default medium-risk manual approval process to avoid blocking business requests. The business gateway and the approval adaptation module, as well as the renewal decision engine and the approval adaptation module, use message queues to complete asynchronous communication. The transmission of all notifications, approval tasks, and approval results does not occupy the main business request link. At the same time, the reliability and consistency of information transmission are ensured through message retry and idempotent processing mechanisms.
[0022] All modules of this system adopt a microservice-based pluggable design. The modules interact with each other through standardized interfaces. The corresponding gateway components, database services, approval systems and risk control engines can be replaced and adapted according to the enterprise's existing IT architecture without reconstructing the overall system architecture, making it flexible and convenient to use. The business gateway is implemented using an enterprise-grade commercial API gateway. The permission renewal verification hook program is developed and deployed as a custom plugin built into the gateway, without modifying the gateway's core code. The permission database directly reuses the enterprise's existing production environment's permission management database and interfaces with the business gateway through a standardized database access interface. The renewal decision engine is deployed as an independent risk control microservice, enabling data sharing and integration with the enterprise's existing risk control system. The approval adaptation module interfaces with the enterprise's existing unified approval platform, completing approval task push and result callback through a standardized open interface. The entire system is fully compatible with the enterprise's existing IT architecture, requiring no intrusive modifications to the service code or core architecture of the existing business systems.
[0023] Example 2 Specifically: The permission database is built based on the RBAC or ABAC permission model. Only two fields, permission validity period and permission status, are added to the original permission table. The primary key, foreign key and core table structure of the original permission table are not changed.
[0024] The renewal decision engine has a built-in risk rules submodule and an AI submodule. The risk rule sub-engine is used to output rule risk scores based on preset static risk rules, and the AI sub-engine is used to output model risk scores based on user history behavior and permission usage data. The renewal decision engine combines the rule risk score and the model risk score to obtain a comprehensive risk score, and outputs the risk level by comparing the comprehensive risk score with a preset threshold. The AI sub-engine also has a built-in incremental training unit that can automatically adjust and optimize the value of preset thresholds based on historical feedback data of erroneous rejections and releases during manual approval.
[0025] The business gateway also has a built-in grayscale control unit. The grayscale control unit can perform grayscale release and one-click rollback of the triggering scope of the permission renewal verification hook program according to the user, role, department or business system. In this embodiment, the newly added permission validity period field in the permission database is stored as an integer value in natural days. It supports three levels of configuration: global default value, role-level configuration, and single-permission personalized configuration. The configuration priority increases progressively, with single-permission personalized configuration having a higher priority than role-level configuration, and role-level configuration having a higher priority than global default configuration. Differentiated control periods can be set for permissions of different security levels. The newly added permission status field is stored as an enumerated value, corresponding to three states: normal effective, pending renewal, and expired. At the same time, a joint index is established in the permission table for the permission status field and the expiration time field of the permission validity period, which greatly improves the query efficiency of expired permission records and reduces the database performance overhead in high-concurrency scenarios. For historical permissions that existed before the upgrade but had no fixed expiration period, the database has built-in automatic compatibility logic that automatically fills in the global default permission validity period for historical permissions and marks them as being in normal effective status. This eliminates the need for manual batch processing of historical data and achieves seamless compatibility of historical permissions. The risk rule sub-engine of the renewal decision engine has built-in four categories of static risk rule system: user identity, access behavior, permission matching and environment security. Each rule category has detailed and configurable rule items. Each rule item corresponds to a fixed risk score and triggering conditions. It supports enabling, disabling and adjusting the score of rule items. Iterative optimization of risk rules can be completed without modifying the engine code. The AI sub-engine uses an online learning binary classification model. The input features cover multiple time-series features such as the frequency of user access permissions, access time distribution, access resource range, login location dispersion, device change frequency, and historical approval results over the past 30 days. The model output is the probability of an anomaly in the current renewal request, which is converted into a model risk score of 0-100 points and then used for access permission risk assessment. The incremental training unit is equipped with two training mechanisms: fixed period triggering and event triggering. The fixed period is the early morning business off-peak period every day, and the event triggering mechanism is automatically triggered after the preset number of manual approval samples are accumulated. The training samples are manual approval data as negative samples and approval rejection data as positive samples. After training is completed, the model performance is automatically evaluated. When the performance of the new model is better than the online model, the gray scale upper limit and threshold are automatically optimized. The grayscale control unit has a built-in multi-level grayscale rule configuration system, supporting blacklist and whitelist configuration. Whitelisted entities skip the renewal verification process, while blacklisted entities trigger the highest level of control. Grayscale deployment adopts a hash-consistent traffic distribution strategy based on the user's unique identifier, ensuring that requests from the same user always fall into the same grayscale group, avoiding inconsistencies in control logic. It supports adjustments to the deployment ratio in increments of 0.1%, and also has a one-click full rollback switch that takes effect within seconds. After rollback, all requests are directly restored to the original permission control logic, enabling rapid emergency recovery in abnormal scenarios.
[0026] Example 3 A dynamic renewal method for permissions without a fixed term includes the following steps: S1. When a user initiates an access request for a protected resource of a business system, the business gateway intercepts the access request, triggers the built-in permission renewal verification hook program, and starts the permission renewal verification process. S2. Based on the initiated renewal verification process, the business gateway sends a query command to the permission database to query the permission records of the user corresponding to this access request that have expired the preset permission validity period; after receiving the query command, the permission database retrieves the matching permission records and returns them to the business gateway. S3. After receiving the returned permission records, the business gateway verifies the permission type of each permission record. If the verification determines that the permission is not a permission without a fixed term, the business gateway sends a permission deletion instruction to the permission database to complete the closed loop of reclaiming the expired permission. If the verification determines that the permission is a permission without a fixed term, the permission without a fixed term is marked as pending renewal and proceeds to the subsequent risk assessment steps. S4. The business gateway will synchronously send the user's identity information and access behavior information of the user with the non-fixed-term permission marked as pending renewal to the renewal decision engine. The renewal decision engine will perform a comprehensive risk calculation on the received information, output the corresponding risk level, and return the risk level result to the business gateway. S5. After receiving the risk level result, the business gateway executes the corresponding renewal control operation according to the preset risk classification rules. S6. For manual approval tasks generated at the medium risk level, after the approval management personnel complete the approval operation, the approval adaptation module will synchronize the approval result to the business gateway. If the approval result is passed, the business gateway sends an instruction to the permission database to regenerate the permission without a fixed term and extend the validity period of the permission by a full preset period, and restore the permission status to the normal effective state. If the approval result is rejection, the indefinite-term permission will remain permanently invalid, completing the closed loop of this renewal process. In this embodiment, when a user accesses the service, the service gateway intercepts the request and first verifies the user's identity. If the verification passes, the user's unique identifier is extracted, and then the permission renewal verification hook program is triggered. The hook program has a maximum execution timeout. After the timeout, the renewal verification process is automatically skipped and the request is allowed. At the same time, an exception log is recorded to prevent the business request from being blocked due to hook program exceptions. The hook program has built-in request filtering rules. For requests for unprotected resources such as static resources and public interfaces, the renewal verification process is skipped directly. Verification is only performed on requests for protected resources, reducing unnecessary performance overhead. Based on the user's unique identifier, the system retrieves all permission records under the user whose expiration dates are earlier than the current request time. The system uses a pre-defined composite index to perform fast retrieval. At the same time, a maximum limit is set on the number of query results to avoid query performance issues caused by too many permission records for a single user. When the permission database returns results, it synchronously returns all fields of each permission record, including permission type, expiration period, current status, authorization time, and historical renewal records, providing complete data support for subsequent verification and evaluation. Based on the preset permission type identifiers in the permission database, permissions without fixed time limits use a fixed and unique type identifier, which is completely distinguished from temporary permissions, timed permissions, and other permissions that are not without fixed time limits. The deletion of permissions that are not without fixed time limits is done in a soft deletion manner, which only marks the permission status as expired, and synchronously records the operator, operation time, and operation reason, retaining complete permission records and operation logs, rather than physically deleting data. The pending renewal status marking of permissions without fixed time limits is completed in the same database transaction as the permission query operation, ensuring the atomicity of status updates and avoiding status abnormalities caused by concurrent requests. The business gateway synchronizes data to the renewal decision engine, including user identity information, job information, department, access time of the current request, access IP, device information, authorization information of the permissions to be renewed, and full context data of historical renewal and access records. The risk calculation process of the renewal decision engine is set with a maximum processing time. After the timeout, it returns the default medium risk level and records the exception log to avoid the risk control engine from blocking the business process. All control operations are completed in independent database transactions to ensure the atomicity and consistency of permission status updates. At the same time, an immutable operation audit log is generated synchronously. The log content includes user ID, permission information, risk level, operation content, operation time, and operation result, and is permanently stored in the audit database. After receiving the approval result, the approval adaptation module first performs an idempotency check to avoid abnormal permission status caused by duplicate approval results. After the check passes, it pushes the result to the business gateway through an asynchronous message. The business gateway completes the permission status update in the transaction and pushes the approval result notification to the user. The reasons for the rejection of the approval are recorded synchronously and stored in the permission history operation record to provide data support for subsequent risk assessment. Permissions in a normal effective state will automatically transition to a pending renewal state upon expiration of their validity period. Permissions in a pending renewal state will automatically renew if the risk level is low and the renewal is approved, then transition back to a normal effective state. Permissions in a medium-risk state will remain in a pending renewal state after temporary revocation, and will transition back to a normal effective state if approved by manual review. If the review is rejected, the permissions will transition to an expired state. Permissions with a high risk level will directly transition from a pending renewal state to an expired state. The expired state is the final state and can only be restored through the reauthorization process, not through the renewal process, ensuring the rigor of permission control.
[0027] Through a complete process sequence design and a full-link exception handling mechanism, the renewal verification process is ensured not to block the processing of normal business requests, guaranteeing the availability and response performance of the business system. Transactional state updates and a rigorous permission state machine design prevent permission state anomalies in concurrent scenarios, ensuring the accuracy and consistency of permission control. Full-process soft deletion and tamper-proof audit logs enable full traceability and auditability of the permission lifecycle, fully meeting the audit requirements of domestic and international compliance standards for permission management. The user access-triggered renewal process design transforms traditional static permission control into dynamic control based on actual business needs, achieving real-time alignment between permission validity and actual business necessity.
[0028] Example 4 Specifically: In step S5, after the service gateway receives the risk level result, it performs the corresponding renewal control operation according to the preset risk classification rules, as follows: If the risk level is determined to be low, the business gateway will execute the system's self-approval process. After approval, the pending unlimited period of the permission will be extended for a full preset permission validity period, and the permission status will be restored to the normal effective status. If the risk level is determined to be medium, the business gateway will generate a corresponding manual approval task, and simultaneously temporarily revoke the pending non-fixed-term permissions, suspend its access permissions and wait for the approval result. If the risk level is determined to be high, the business gateway will immediately and permanently revoke the pending, indefinite-term permission, mark the permission status as permanently invalid, and send a risk warning notification to the preset approval management personnel through the approval adaptation module.
[0029] The protected resource access request initiated by the user in step S1 includes: Any one of the following: user login request to business system, protected business interface call request, or protected data resource access operation request.
[0030] The specific process of comprehensive risk calculation and level output in step S4 is as follows: The rule risk score output by the comprehensive risk rule sub-engine of the renewal decision engine and the model risk score output by the AI sub-engine are combined to obtain the comprehensive risk score R. The comprehensive risk score R is compared with the preset first risk threshold T1 and second risk threshold T2, where T1 < T2. When R ≤ T1, it is determined to be a low risk level; when T1 < R ≤ T2, it is determined to be a medium risk level; and when R > T2, it is determined to be a high risk level.
[0031] The AI sub-engine supports online incremental training, adjusting and optimizing the values of the first risk threshold T1 and the second risk threshold T2 based on historical feedback data of false rejections and false releases in manual approvals, thereby updating the accuracy of risk level determination.
[0032] In step S5, after the system completes the permission renewal process through the self-approval process, it simultaneously sends an automatic renewal notification for the permission without a fixed term to the preset approval management personnel through the approval adaptation module. After temporarily revoking permissions without a fixed term, if a user initiates another request to access protected resources, the business gateway will return a message to the user indicating that the permission is pending approval, and at the same time push an approval reminder to the approval management personnel through the approval adaptation module. In this embodiment, the low-risk system self-approval process sets multiple mandatory verification rules, including secondary verification of user identity legitimacy, verification of permission and job matching, and verification of the security of the current access environment. Self-approval can only be completed after all verification rules are passed. Once approved, the start time for extending the validity period of the permission will be the current moment when the approval is completed, rather than the original expiration time. This ensures that the validity period of each renewal is the full preset duration, avoiding the problem that the renewal period will be shortened when the user accesses the site again after a long period of inactivity following the expiration of the permission. After the approval is completed, all information for this renewal will be added to the permission history renewal record, including the renewal time, comprehensive risk score, approval type, and operating entity. For manual approval processes at medium risk levels, the system automatically matches the corresponding approver based on the user's department and the level of access permissions when the task is generated. It supports multi-level approval configurations, and high-security permissions can be configured with two or more levels of approval processes. Renewal can only be completed after all approvers have approved the process. After temporary revocation of permissions, user access requests for resources corresponding to those permissions will be blocked by the gateway and a unified prompt page will be returned. The page displays the approval progress, approver information, and a reminder button. Users can trigger reminder notifications through the reminder button. Approval tasks have a timeout period set. Tasks that are not approved within the timeout period are automatically rejected, and the permissions remain permanently invalid. The user and approver are notified simultaneously. After the high-risk level permission permanent revocation operation is executed, the high-risk event will be pushed to the enterprise security operation platform at the same time, triggering the corresponding security event handling process, including additional control measures such as temporary account locking, forced password modification, and strong verification of login environment. At the same time, a high-risk event report will be generated and pushed to security management personnel to achieve closed-loop handling of high-risk events. The comprehensive risk score R is calculated using a weighted summation method. The weights of the rule risk score and the model risk score can be flexibly configured according to the business scenario. The default weights are 60% for the rule risk score and 40% for the model risk score. For administrator privileges with high security levels, the weight of the rule risk score can be increased to strengthen the control of static rules. For ordinary business privileges, the weight of the model risk score can be increased to improve the flexibility of control. The risk thresholds T1 and T2 range from 0 to 100, and it is possible to configure differentiated thresholds for different permission types and roles. During the incremental training process of the AI sub-engine, the sample data is first preprocessed, including abnormal sample filtering, feature normalization, and sample balancing to avoid model bias caused by sample imbalance. After the model training is completed, the offline test set and the latest online approval samples are used to complete the performance evaluation. The evaluation indicators include precision, recall, and F1 score. Only when the F1 score of the new model is better than the current online model will it enter the gray-scale deployment process. During the gray-scale deployment stage, the new model and the online model infer in parallel. Only the inference results are recorded and they do not participate in actual management. When the online performance meets the expectations, the full deployment is completed to ensure the stability of model iteration. Notifications and reminders adopt a tiered push strategy. Low-risk automatic renewal notifications are only pushed to the corresponding approval management personnel and are pushed in a daily summary form. Medium-risk approval task notifications and reminders are pushed to the approvers in real time. If they are not approved within the preset time, they are pushed repeatedly at fixed intervals. High-risk alarm notifications are pushed to security management personnel and approval management personnel in real time, and strong reminders are also sent through multiple channels. All notification push records are stored in the audit log to ensure that the notification process is traceable.
[0033] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention.
Claims
1. A dynamic renewal system with no fixed-term permission, characterized in that: It includes a business gateway, a permission database, a renewal decision engine, and an approval adaptation module. The business gateway is communicatively connected to the permission database, the renewal decision engine, and the approval adaptation module, respectively. The renewal decision engine is communicatively connected to the approval adaptation module. The business gateway has a built-in permission renewal verification hook program, which is used to intercept user access requests to protected resources of the business system and trigger the permission renewal verification hook program to start the renewal process. The business gateway is also used to initiate permission query requests to the permission database, perform type verification and status marking on the returned permission records, perform hierarchical renewal control operations according to the risk level returned by the renewal decision engine, and complete the final update of the permission status according to the approval results synchronized by the approval adaptation module. The permission database is used to store all user permission data, including permission type, preset permission validity period, and permission status information. It is used to respond to and execute all permissions query, deletion, validity period extension, and permission regeneration instructions sent by the business gateway. The renewal decision engine is used to receive the pending renewal permission information, the corresponding user's identity and access behavior information synchronized by the business gateway, complete the comprehensive risk calculation and output the corresponding risk level, and provide a basis for judgment for the hierarchical renewal management of the business gateway. The approval adaptation module is used to connect with the manual approval process, generate and push manual approval tasks, receive the approval results of the approval management personnel and synchronize them to the business gateway, and at the same time complete the information push of renewal notification, risk alarm and approval reminder.
2. The dynamic renewal system for unlimited term permissions according to claim 1, characterized in that: The permission database is built based on the RBAC or ABAC permission model. It only adds two fields, permission validity period and permission status, to the original permission table, without changing the primary key, foreign key and core table structure of the original permission table.
3. The dynamic renewal system for unlimited term permissions according to claim 1, characterized in that: The renewal decision engine has a built-in risk rules submodule and an AI submodule. The risk rule sub-engine is used to output rule risk scores based on preset static risk rules, and the AI sub-engine is used to output model risk scores based on user history behavior and permission usage data. The renewal decision engine combines the rule risk score and the model risk score to obtain a comprehensive risk score, and outputs the risk level by comparing the comprehensive risk score with a preset threshold. The AI sub-engine also has a built-in incremental training unit that can automatically adjust and optimize the value of preset thresholds based on historical feedback data of erroneous rejections and releases during manual approval.
4. The dynamic renewal system with no fixed-term permission according to claim 1, characterized in that: The business gateway also has a built-in gray-scale control unit, which performs gray-scale release and one-click rollback of the triggering scope of the permission renewal verification hook program according to the user, role, department or business system dimensions.
5. A dynamic renewal method for permissions without a fixed term, characterized in that: Includes the following steps: S1. When a user initiates an access request for a protected resource of a business system, the business gateway intercepts the access request, triggers the built-in permission renewal verification hook program, and starts the permission renewal verification process. S2. Based on the initiated renewal verification process, the business gateway sends a query command to the permission database to query the permission records of the user corresponding to this access request that have expired the preset permission validity period. After receiving the query command, the permission database retrieves the matching permission record and returns it to the business gateway; S3. After receiving the returned permission records, the business gateway verifies the permission type of each permission record. If the verification determines that the permission is not without a fixed term, the business gateway sends a permission deletion instruction to the permission database to complete the closed loop of reclaiming the expired permission; If the verification determines that the permission has no fixed term, the permission with no fixed term is marked as pending renewal and proceeds to the subsequent risk assessment steps. S4. The business gateway will synchronously send the user's identity information and access behavior information of the user with the non-fixed-term permission marked as pending renewal to the renewal decision engine. The renewal decision engine will perform a comprehensive risk calculation on the received information, output the corresponding risk level, and return the risk level result to the business gateway. S5. After receiving the risk level result, the business gateway executes the corresponding renewal control operation according to the preset risk classification rules. S6. For manual approval tasks generated at the medium risk level, after the approval management personnel complete the approval operation, the approval adaptation module will synchronize the approval result to the business gateway. If the approval result is passed, the business gateway sends an instruction to the permission database to regenerate the permission without a fixed term and extend the validity period of the permission by a full preset period, and restore the permission status to the normal effective state. If the approval result is rejection, the indefinite-term permission will remain permanently invalid, completing the closed loop of this renewal process.
6. The method for dynamic renewal of rights without a fixed term as described in claim 5, characterized in that: In step S5, after receiving the risk level result, the service gateway performs the corresponding renewal control operation according to the preset risk classification rules, specifically as follows: If the risk level is determined to be low, the business gateway will execute the system's self-approval process. After approval, the pending unlimited period of the permission will be extended for a full preset permission validity period, and the permission status will be restored to the normal effective status. If the risk level is determined to be medium, the business gateway will generate a corresponding manual approval task, and simultaneously temporarily revoke the pending non-fixed-term permissions, suspend its access permissions and wait for the approval result. If the risk level is determined to be high, the business gateway will immediately and permanently revoke the pending, indefinite-term permission, mark the permission status as permanently invalid, and send a risk warning notification to the preset approval management personnel through the approval adaptation module.
7. The method for dynamic renewal of rights without a fixed term as described in claim 5, characterized in that: The protected resource access request initiated by the user in step S1 includes: Any one of the following: user login request to business system, protected business interface call request, or protected data resource access operation request.
8. The method for dynamic renewal of permissions without a fixed term as described in claim 5, characterized in that: The specific process of comprehensive risk calculation and level output in step S4 is as follows: The rule risk score output by the comprehensive risk rule sub-engine of the renewal decision engine and the model risk score output by the AI sub-engine are combined to obtain the comprehensive risk score R. The comprehensive risk score R is compared with the preset first risk threshold T1 and second risk threshold T2, where T1 < T2. When R ≤ T1, it is determined to be a low risk level; when T1 < R ≤ T2, it is determined to be a medium risk level; and when R > T2, it is determined to be a high risk level.
9. A dynamic renewal method for permissions without a fixed term as described in claim 8, characterized in that: The AI sub-engine supports online incremental training, adjusting and optimizing the values of the first risk threshold T1 and the second risk threshold T2 based on historical feedback data of false rejections and false releases in manual approvals, thereby updating the accuracy of risk level determination.
10. A dynamic renewal method for permissions without a fixed term as described in claim 5, characterized in that: In step S5, after the system completes the permission renewal process through the self-approval process, it simultaneously sends an automatic renewal notification for the permission without a fixed term to the preset approval management personnel through the approval adaptation module. After temporarily revoking permissions without a fixed term, if a user initiates another request to access protected resources, the business gateway will return a message to the user indicating that the permission is pending approval. At the same time, it will push an approval reminder to the approval administrator through the approval adaptation module.