A system and method for restricting modification of system basic data
Through the coordinated work of data management, system management and data supervision modules, temporary online authorization and data recovery are realized, and the system instability caused by users' own modification of the basic data of the system is solved, ensuring the correctness and security of the system in the unauthorized situation.
Patent Information
- Application Number
- CN202111427460.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-26
- Publication Date
- 2025-07-29
- Estimated Expiration
- 2041-11-26
AI Technical Summary
In the project-specific operation and maintenance environment, users manage the basic data of the system by themselves, resulting in the data accuracy being unable to be guaranteed, which may cause system crashes and the cost of problem investigation and recovery is high.
Through the coordinated work of the data management module, system management module and data supervision module, a temporary online authorization and encryption mechanism is realized to ensure that the basic data modified by the user takes effect within the authorization period and automatically restore the data to the backup state when the period expires or has no right to be modified.
Without restricting the user's permission to manage the basic data, ensure the correctness and stability of the system data, prevent system crashes, and reduce the risk of unauthorized modifications.
Smart Images

Figure CN114091000B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of system deployment, and particularly to a system and method for restricting the modification of system basic data. Background Art
[0002] Currently, after a software system is deployed to a project site, some system basic data will be initialized. These basic data must be absolutely correct to ensure the normal operation of the system. Therefore, these basic data are generally managed by specialized operation and maintenance personnel and are not directly open to users. However, in certain specific operation and maintenance environments of projects, the existing system inevitably needs to open the management function of basic data to some users, and these users can perform operation and maintenance on the basic data by themselves. In this way, the accuracy of the system basic data cannot be guaranteed, and in severe cases, it may even lead to a systematic collapse, and the troubleshooting and recovery of problem data also require relatively high costs. Summary of the Invention
[0003] In order to solve the above technical problems, the purpose of the present invention is to provide a system and method for restricting the modification of basic data at a project site, which can ensure the effectiveness of the basic data modified by users without restricting the user's permission to manage the basic data through a temporary online authorization method, and without affecting the accuracy and stability of the system.
[0004] In a first aspect, the present invention provides a system for restricting the modification of basic data, the system comprising:
[0005] A data management module, a system management module, and a data supervision module connected in sequence;
[0006] The data management module is configured to send user identity information and application modification information to the system management module, apply for an authorization certificate for modifying the system basic data, and modify the system basic data;
[0007] The system management module includes a certificate generation module and an encryption module. The certificate generation module is configured to verify the user identity information and the application modification information sent by the data management module, generate a corresponding authorization certificate according to the verification result, and the encryption module is configured to encrypt the authorization certificate and send the authorization certificate to the data supervision module;
[0008] The data supervision module is configured to monitor the system basic data and verify the authorization certificate corresponding to the modification of the system basic data. If the verification is passed, it is confirmed that the modified system basic data takes effect. If the verification fails, the modified system basic data is restored.
[0009] Further, the authorization certificate includes a user identity ID, a corresponding unique permission token, and a certificate private key. The permission token is signed using the user identity ID, and the permission token includes a user private key, user modification permissions, and a permission time limit.
[0010] Further, the data supervision module includes a verification module. The verification module is used to verify the certificate private key of the authorization certificate using the public key of the pre-stored system management module, verify the user private key in the permission token using the public key of the pre-stored data management module, and judge the permission time limit in the permission token.
[0011] Further, the data supervision module includes:
[0012] A data backup module, which is used to regularly back up the system basic data and store it according to the version information of the system basic data;
[0013] A data recovery module, which is used to restore the system basic data modified without authorization and the system basic data modified outside the permission time limit to the data version stored by the data backup module.
[0014] Further, the data supervision module further includes a log recording module, which is used to record all operations on the system basic data, generate log records, and regularly back up and store the log records.
[0015] In a second aspect, the present invention provides a method for restricting the modification of system basic data. The method includes:
[0016] The data management module sends user identity information and application modification information to the system management module, applies for an authorization certificate for modifying the system basic data, and modifies the system basic data;
[0017] The system management module verifies the user identity information and the application modification information sent by the data management module, generates a corresponding authorization certificate according to the verification result, encrypts the authorization certificate, and sends the authorization certificate to the data supervision module;
[0018] The data supervision module monitors the system basic data and verifies the authorization certificate corresponding to the modification of the system basic data. If the verification passes, it confirms that the modified system basic data takes effect. If the verification fails, it restores the modified system basic data.
[0019] Further, the authorization certificate includes a user identity ID, a corresponding unique permission token, and a certificate private key. The permission token is signed using the user identity ID, and the permission token includes a user private key, a user modification permission, and a permission time limit.
[0020] Further, the data supervision module verifies the certificate private key of the authorization certificate using the public key of the pre-stored system management module, verifies the user private key in the permission token using the public key of the pre-stored data management module, and determines the permission time limit in the permission token.
[0021] Further, the data supervision module periodically backs up the system basic data and stores it according to the version information of the system basic data, and restores the system basic data modified without authorization and the system basic data modified outside the permission time limit to the data version stored in the data backup module.
[0022] Further, the data supervision module records all operations on the system basic data, generates a log record, and periodically backs up and stores the log record.
[0023] The present invention provides a system and method for restricting modification of system basic data. Through the system, without restricting the user's permission to manage basic data, the basic data modified by the user is automatically backed up and restored, ensuring the correctness of the basic data of the system in an unauthorized situation, and through a temporary online authorization method, only the basic data modified within the authorization period will take effect in the system, ensuring the security and stability of the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] Figure 1 is a schematic structural diagram of the system for restricting modification of system basic data in an embodiment of the present invention;
[0025] Figure 2 is Figure 1 the schematic structural diagram of the system management module in
[0026] Figure 3 is Figure 1 the schematic structural diagram of the data supervision module in
[0027] Figure 4 is a schematic flowchart of the method for restricting modification of system basic data in an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0028] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all of them. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0029] Please refer to Figure 1 , a system for restricting the modification of system basic data proposed in the first embodiment of the present invention includes: a data management module 1, a system management module 2, and a data supervision module 3 that are connected in sequence. Among them, the user can modify the system basic data through the data management module 1. However, to prevent problems such as system data errors or even system crashes caused by the user's random modification of the system basic data, we limit that the data management module 1 needs to apply for modification permission online to the system management module 2 before modifying the system basic data.
[0030] The data management module 1 sends the user identity information and the application modification information to the system management module 2 to apply for the permission to modify the system basic data. The system management module 2 will perform online real-time verification on the authorization application sent by the data management module 1. To ensure the security of authorization, preferably, as Figure 2 shown, the system management module 2 is provided with a certificate generation module 21 and an encryption module 22.
[0031] The certificate generation module 21 confirms the verification by generating an authorization certificate. In this embodiment, the authorization certificate verifies the user's identity based on the user identity information and the application modification information sent by the data management module 1, generates the corresponding modification permission according to the application modification information. At the same time, to prevent the authorized user from randomly modifying the system basic data, we also set a time limit for the user's modification permission.
[0032] For the verified user information, in order to further ensure the security of the authorization certificate and prevent malicious tampering of the authorization certificate, the encryption module 22 encrypts the generated authorization certificate. The content of the encrypted authorization certificate includes the user identity ID, the unique permission token corresponding to this identity ID, and the private key of the authorization certificate. Among them, the permission token is signed with the user identity ID to ensure its uniqueness, and the permission token also includes the user private key, the user modification permission, and the time limit of the permission. If the data management module 1 still needs to modify the basic data at other times, it needs to re-apply for authorization to the system management module 2 according to the modification information. In the newly generated authorization certificate, after being encrypted by the encryption module 22, the certificate private key will be updated, the signature of the permission token remains unchanged, but the user private key, the user modification permission, and the time limit of the permission included in the permission token will be updated accordingly to ensure the timeliness of authorization and the security of modification. After encrypting the authorization certificate, the encryption module 22 sends the authorization certificate to the data supervision module 3 for storage. It should be understood that the content and encryption method of the authorization certificate can be flexibly configured according to the actual situation. The preferred method is used in this embodiment rather than the only limited method.
[0033] As Figure 3 shown, the data supervision module 3 monitors the system basic data in real time and regularly backs up the system basic data through the data backup module 31. For the detected modification of the system basic data, the data supervision module 3 verifies whether there is a corresponding authorization certificate for this modification.
[0034] From the above description, it can be seen that in order to ensure the security of the authorization certificate, we use methods such as the certificate private key and the user private key to encrypt the authorization certificate. In order to verify the authenticity of the authorization certificate, the verification module 34 needs to pre-store the public keys of the system management module 2 and the data management module 1 in advance. During verification, the verification module 34 first verifies whether the private key of the authorization certificate matches the pre-stored public key of the system management module 2, and then verifies whether the signature of the permission token is the user identity ID. After determining the authorization certificate and the user identity ID, the verification module 34 also reads the user private key in the permission token and verifies whether it matches the pre-stored public key of the data management module 1, thus ensuring that the source and content of the authorization certificate have not been tampered with or replaced, and guaranteeing the security of the authorization certificate.
[0035] After the verification module 34 verifies the accuracy of the corresponding authorization certificate, the data supervision module 3 reads the modification permissions and permission time limits in the permission token, determines whether the modification of the basic data is within the modification permissions, and whether the permission is still within the valid time limit. For modifications that exceed the permissions and those that exceed the time limit, the data supervision module 3 will restore the system basic data through the data recovery module 32 to further ensure the accuracy of the system basic data and the stability of the system. If there is no corresponding authorization certificate for this modification, the data recovery module 32 will also restore the system basic data.
[0036] In this embodiment, it is preferably set that the data backup module 31 not only backs up the system basic data regularly but also backs up the data before the modification of the system basic data, and stores the backups according to the version numbers of the basic data. When the data recovery module 32 performs data recovery on the system, it can either restore the system basic data to the state before modification or restore the system to the data state of other versions stored in the data backup module 31 according to needs. The data recovery in this embodiment can be flexibly configured according to the actual situation and will not be further restricted here.
[0037] Meanwhile, to ensure the security of the system and facilitate future responsibility tracing, the data supervision module 3 also includes a log recording module 33. The log recording module 33 records all operations on the system basic data, generates log records regularly, and backs up and stores the log records regularly. At the same time, the log records can also be encrypted and stored, and only users with corresponding permissions can operate on the log records. Additionally, blockchain technology can be used to store the logs, ensuring the security of the log records and thus the stability of the system.
[0038] A system for restricting the modification of system basic data provided in this embodiment, compared with the problem of traditional systems being unable to restrict users from modifying system basic data, which may cause system errors or even crashes, the present invention automatically backs up and restores the basic data modified by users without restricting users' permissions to manage basic data, ensures the correctness of the basic data in the system under unauthorized circumstances, and through the method of temporary online authorization, makes the basic data modified by the system effective only within the authorization period, ensuring the security and stability of the system.
[0039] Please refer to Figure 4 , based on the same inventive concept, a method for restricting the modification of system basic data proposed in the second embodiment of the present invention includes steps S10 to S30:
[0040] Step S10, the data management module sends the user identity information and application modification information to the system management module, applies for an authorization certificate for modifying the system basic data, and modifies the system basic data.
[0041] Step S20: The system management module verifies the user identity information and the application modification information sent by the data management module, generates a corresponding authorization certificate according to the verification result, encrypts the authorization certificate, and sends the encrypted authorization certificate to the data supervision module.
[0042] Step S30: The data supervision module monitors the system basic data and verifies the authorization certificate corresponding to the modification of the system basic data. If the verification is passed, it confirms that the modified system basic data takes effect. If the verification fails, it restores the modified system basic data.
[0043] In this embodiment, the authorization certificate includes a user identity ID, a corresponding unique permission token, and a certificate private key. The permission token is signed using the user identity ID. The permission token includes a user private key, user modification permissions, and a permission time limit. The data supervision module verifies the certificate private key of the authorization certificate using the public key of the pre-stored system management module, verifies the user private key in the permission token using the public key of the pre-stored data management module, and judges the permission time limit in the permission token.
[0044] And the data supervision module also periodically backs up the system basic data, stores it according to the version information of the system basic data, and restores the unauthorized modified system basic data and the system basic data modified outside the permission time limit to the data version stored in the data backup module. And for all operations on the system basic data, it generates a log record and periodically backs up and stores the log record.
[0045] The technical features and technical effects of the method for restricting the modification of system basic data proposed in the embodiment of the present invention are the same as those of the system proposed in the embodiment of the present invention, and will not be elaborated here. Each module in the above system for restricting the modification of system basic data can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in or independent of the processor in the computer device in the form of hardware, or stored in the memory of the computer device in the form of software, so as to facilitate the processor to call and execute the operations corresponding to the above modules.
[0046] In summary, a system and method for restricting the modification of system basic data proposed in the embodiments of the present invention. The system includes a data management module, a system management module, and a data supervision module connected in sequence. The data management module is used to send user identity information and application modification information to the system management module, apply for an authorization certificate for modifying the system basic data, and modify the system basic data. The system management module includes a certificate generation module and an encryption module. The certificate generation module is used to verify the user identity information and the application modification information sent by the data management module, generate a corresponding authorization certificate according to the verification result, and the encryption module is used to encrypt the authorization certificate and send the authorization certificate to the data supervision module. The data supervision module is used to monitor the system basic data and verify the authorization certificate corresponding to the modification of the system basic data. If the verification passes, it is confirmed that the modified system basic data takes effect. If the verification fails, the modified system basic data is restored. Without restricting the user's permission to manage basic data, this system automatically backs up and restores the basic data modified by the user, ensures the correctness of the basic data of the system in the case of unauthorized access, and through the way of temporary online authorization, makes the basic data modified by the system take effect only within the authorization period, ensuring the security and stability of the system.
[0047] Each embodiment in this specification is described in a progressive manner. For parts that are the same or similar in each embodiment, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple. For related parts, reference can be made to the description of the method embodiment. It should be noted that the above technical features of each embodiment can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the above technical features in each embodiment are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.
[0048] The above embodiments only represent several preferred embodiments of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of the invention patent. It should be pointed out that for those of ordinary skill in the art in this technical field, without departing from the technical principle of the present invention, several improvements and replacements can still be made, and these improvements and replacements should also be regarded as the protection scope of the present application. Therefore, the protection scope of the patent of the present application should be subject to the protection scope of the claims.
Claims
1. A system for restricting the modification of basic data of a system, characterized in that, Including: A data management module, a system management module, and a data supervision module connected in sequence; The data management module is used to send user identity information and application modification information to the system management module, apply for an authorization certificate for modifying the system basic data, and modify the system basic data; the authorization certificate includes a user identity ID, a corresponding unique permission token, and a certificate private key, the permission token is signed using the user identity ID, and the permission token includes a user private key, a user modification permission, and a permission time limit; The system management module includes a certificate generation module and an encryption module. The certificate generation module is used to verify the user identity information and the application modification information sent by the data management module, generate a corresponding authorization certificate according to the verification result, and the encryption module is used to encrypt the authorization certificate and then send the authorization certificate to the data supervision module; The data supervision module is used to monitor the system basic data and verify the authorization certificate corresponding to the modification of the system basic data. If the verification passes, it confirms that the modified system basic data takes effect. If the verification fails, it restores the modified system basic data; The data supervision module includes a verification module, which is used to verify the certificate private key of the authorization certificate using the public key of the pre-stored system management module, verify the user private key in the permission token using the public key of the pre-stored data management module, and judge the permission time limit in the permission token.
2. The system for modifying system basic data according to claim 1, wherein The data supervision module includes: A data backup module, which is used to back up the system basic data regularly and store it according to the version information of the system basic data; A data recovery module, which is used to restore the system basic data modified without authorization and the system basic data modified outside the permission time limit to the data version stored in the data backup module.
3. The system for modifying system basic data according to the limitation described in claim 2, characterized in that, The data supervision module further includes a log recording module, which is used to record all operations on the system basic data, generate log records, and back up and store the log records regularly.
4. A method for restricting the modification of basic data of a system, characterized in that, Including: The data management module sends user identity information and application modification information to the system management module, applies for an authorization certificate for modifying the system basic data, and modifies the system basic data; the authorization certificate includes a user identity ID, a corresponding unique permission token, and a certificate private key, the permission token is signed using the user identity ID, and the permission token includes a user private key, a user modification permission, and a permission time limit; The system management module verifies the user identity information and the application modification information sent by the data management module, generates a corresponding authorization certificate according to the verification result, encrypts the authorization certificate, and then sends the authorization certificate to the data supervision module; The data supervision module monitors the system basic data and verifies the authorization certificate corresponding to the modification of the system basic data. If the verification passes, it confirms that the modified system basic data takes effect. If the verification fails, it restores the modified system basic data, including: The data supervision module uses the pre-stored public key of the system management module to verify the certificate private key of the authorization certificate, uses the pre-stored public key of the data management module to verify the user private key in the permission token, and judges the permission time limit in the permission token.
5. The method for modifying system basic data according to claim 4, characterized in that, The data supervision module periodically backs up the system basic data and stores it according to the version information of the system basic data, and restores the unauthorized modified system basic data and the system basic data modified outside the permission time limit to the data version stored in the data backup module.
6. The method for modifying system basic data according to claim 5, characterized in that, The data supervision module records all operations on the system basic data, generates log records, and periodically backs up and stores the log records.
Citation Information
Patent Citations
Online file permission control method and related product
CN113051611A
System for real-time healing of vital computer files
CN1823318A