A security access method and device based on an industrial Internet platform
By managing the identity and permissions of enterprise users based on the blockchain platform on the industrial Internet platform, the security issues of identity and permission management in the cloud environment are solved, and data privacy protection and user experience are improved.
Patent Information
- Application Number
- CN202111578179.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-22
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2041-12-22
AI Technical Summary
The existing technology is difficult to effectively manage the identity and permissions of enterprise users in the cloud environment of industrial Internet platforms, resulting in the inability to ensure data privacy and security.
By determining the identity information of enterprise users on the industrial Internet platform, and generating corresponding identity databases and platform permissions based on the user authorization information of the blockchain platform, secure access to industrial application software is achieved.
Effectively manage the identity and permissions of corporate users, ensure the data privacy and security of corporate users on the industrial Internet platform, and improve users' experience of industrial Internet.
Smart Images

Figure CN114491435B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of industrial Internet, and in particular, to a secure access method and device based on an industrial Internet platform. Background Art
[0002] As a product of the deep integration of the new generation of information technology and manufacturing industry, the industrial Internet provides cloud-based industrial APPs for manufacturing enterprises in fields such as R & D design, process optimization, energy consumption optimization, and operation management by building an industrial Internet platform, which can help enterprises improve quality, reduce costs, and increase efficiency. The industrial Internet platform has become an important carrier for enterprise digital transformation. With the development of the industrial Internet and the acceleration of enterprise cloud adoption and digital transformation, the scenarios faced by application identity management and the problems to be solved are becoming increasingly complex.
[0003] Currently, in addition to traditional requirements such as unified user management and single sign-on, it is also necessary to solve problems such as the access security of enterprise users in the cloud environment of the industrial Internet platform. In the prior art for application identity management, identity and access management (IAM) is built locally in the enterprise to integrate existing local systems of the enterprise to help manage user identities. The existing identity management service methods have poor effects on the identity management and permission management of enterprise users in the cloud environment suitable for the industrial Internet, and the data privacy and security of enterprise users using the industrial Internet cannot be guaranteed. Summary of the Invention
[0004] Embodiments of this application provide a secure access method and device based on an industrial Internet platform, which are used to achieve good identity management and permission management of the industrial Internet platform and ensure the data privacy and security of enterprise users using the industrial Internet.
[0005] On the one hand, this application provides a secure access method based on an industrial Internet platform, and the method includes:
[0006] Determine the identity information of enterprise users. The identity information of enterprise users includes at least a login account. According to the identity information of enterprise users, determine the corresponding identity database of the current enterprise user. Among them, the identity database is generated according to the user type. The user type is the identity type for registering an industrial Internet platform, including a first type and a second type. According to the identity database and the user authorization information of a preset blockchain platform, determine the platform permissions of the current enterprise user. Among them, the preset blockchain platform includes a number of enterprise user terminals for data transmission. The platform permissions are used to obtain a predetermined service of an application database. The predetermined service is generated based on the user type. Based on the platform permissions and the operations of the current enterprise user, determine the accessible information corresponding to the predetermined service to achieve secure access of the current enterprise user to the industrial application software of the industrial Internet platform.
[0007] In an implementation manner of the present application, determine the user storage data corresponding to the enterprise user identity information in the identity database. Among them, the user storage data includes platform usage permissions. The platform usage permissions are generated according to the user authorization information. Through the user storage data, determine whether there is a corresponding mapping relationship for the application software in the application database. The mapping relationship is used to establish an association relationship between the users in the identity database and the application software in the application database. In the case where there is a corresponding mapping relationship in the application database, determine the platform permissions corresponding to the user storage data.
[0008] In an implementation manner of the present application, receive enterprise terminal registration information. According to the enterprise terminal registration information, determine the first-level nodes of the enterprise users in the identity database. Among them, the number of the first-level nodes corresponds to the number of enterprises in the identity database. According to the first-level nodes, generate a corresponding blockchain platform. Among them, the blockchain platform is used for information interaction between the first-level nodes and each second-level node information in a pre-generated single sign-on list. Based on the asymmetric encryption algorithm, through the blockchain platform, perform public key encryption processing on the user data of the second-level nodes after hash operation, and send the user data after asymmetric encryption processing to the first-level nodes. Through the private key of the first-level nodes, decrypt the user data after asymmetric encryption processing and parse the user data to perform user authorization on the second-level nodes to obtain the user authorization information of the second-level nodes.
[0009] In an implementation manner of the present application, determine the user type corresponding to the enterprise user identity information. In the case where the user type is the first type, determine the first database as the corresponding identity database of the current enterprise user. Among them, the first database is used to store platform service provider data. In the case where the user type is the second type, determine the second database as the corresponding identity database of the current enterprise user. The second database includes the platform service provider data and enterprise management data in the first database.
[0010] In an implementation manner of the present application, when the identity database is the second database, the usage permissions of the current enterprise user for each application software in the application database are determined through a preset IDaaS identity management protocol. When the identity database is the second database, the usage permissions of the current enterprise user for each application software in the application database and the application software listing permissions are determined through a preset IDaaS identity management protocol. Among them, the application software listing permissions are used to manage and / or list the application software of the current enterprise user on the industrial Internet platform.
[0011] In an implementation manner of the present application, the identity information of the enterprise user is authenticated through a preset IDaaS identity management protocol. Among them, the preset IDaaS identity management protocol includes at least one or more of the following: Central Authentication Service (CAS), Security Assertion Markup Language (SAML), Open Authorization (OAuth2.0), and OpenID Connect (OIDC). According to the authentication result of the authentication of the enterprise user identity information, the corresponding identity database of the current enterprise user is determined.
[0012] In an implementation manner of the present application, enterprise user data from the enterprise management terminal is obtained based on the Lightweight Directory Access Protocol (LDAP). According to the enterprise user data, a number of nodes of a preset blockchain platform are generated. Among them, the number of nodes of the preset blockchain platform includes the enterprise management terminal and the corresponding number of enterprise user terminals.
[0013] In an implementation manner of the present application, it is determined whether the operation of the current enterprise user matches the platform permissions. When the operation of the current enterprise user matches the platform permissions, in response to the operation of the current enterprise user, the accessible information is determined.
[0014] In an implementation manner of the present application, the user terminal pre-bound to the currently logged-in login account is determined. Through a two-factor authentication mechanism, a login verification code is generated and sent to the user terminal. Based on the feedback operation of the user on the user terminal, the identity information of the enterprise user is verified, so that the login account of the enterprise user identity information logs in to the industrial Internet platform, and the identity information of the enterprise user is determined.
[0015] On the other hand, an embodiment of the present application provides a secure access device based on an industrial Internet platform. The device includes:
[0016] At least one processor, and a memory communicatively connected to the at least one processor. Among them, the memory stores instructions executable by the at least one processor. The instructions are executed by the at least one processor, so that the at least one processor can:
[0017] Determine the enterprise user's identity information. The enterprise user's identity information includes at least a login account. Based on the enterprise user's identity information, determine the identity database corresponding to the current enterprise user. The identity database is generated according to the user type. The user type is the identity type for registering the industrial Internet platform, including the first type and the second type. According to the identity database and the user authorization information of the preset blockchain platform, determine the platform authority of the current enterprise user. The preset blockchain platform includes several enterprise user terminals for data transmission. The platform authority is used to obtain the scheduled service of the application database. The scheduled service is generated based on the user type. Based on the platform authority and the operation of the current enterprise user, determine the accessible information corresponding to the scheduled service to achieve the current enterprise user's secure access to the industrial application software of the industrial Internet platform.
[0018] Through the above solution, the data of the industrial Internet platform is isolated from the user data, ensuring the data privacy and security of enterprise users using the industrial Internet. It can manage user identities and permissions, and provide secure access to industrial application software on the industrial Internet, thus improving the user experience of the industrial Internet. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0020] Figure 1 A schematic diagram of a flow chart of a secure access method based on an industrial Internet platform in an embodiment of the present application;
[0021] Figure 2 This is another flow chart of a secure access method based on an industrial Internet platform in an embodiment of the present application;
[0022] Figure 3 This is a schematic diagram of a secure access method based on an industrial Internet platform in an embodiment of the present application;
[0023] Figure 4 This is a structural diagram of a secure access device based on an industrial Internet platform in an embodiment of the present application. DETAILED DESCRIPTION
[0024] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below in conjunction with the specific embodiments of this application and the corresponding drawings. Apparently, the described embodiments are only a part of the embodiments of this application, rather than all of them. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this application without creative efforts shall fall within the scope of protection of this application.
[0025] The embodiments of this application provide a security access method and device based on an industrial Internet platform to achieve good identity management and permission management of the industrial Internet platform and ensure the data privacy security of enterprise users using the industrial Internet.
[0026] The following will describe each embodiment of this application in detail with reference to the drawings.
[0027] The embodiments of this application provide a security access method based on an industrial Internet platform, as Figure 1 shown, this method may include steps S101 - S104:
[0028] S101, the server determines the identity information of the enterprise user.
[0029] The identity information of the enterprise user includes at least the login account.
[0030] In the embodiments of this application, the identity information of the enterprise user may include a login account such as the user name XXX, password 111, and may also include a bound personal email, mobile phone number, chat software account such as WeChat ID, etc. This application does not make specific limitations on this.
[0031] In the embodiments of this application, the server determines the identity information of the enterprise user, specifically including:
[0032] First, the server determines the user terminal pre - bound to the currently logged - in login account.
[0033] In the embodiments of this application, the user can log in to the industrial Internet platform through the terminal and use the industrial application software deployed on the industrial Internet platform. The process of the server determining the user terminal pre - bound to the currently logged - in login account can be during the process of the user logging in to the industrial Internet platform. For example, after the user enters the account password and clicks the login button, the server determines the pre - bound user terminal. The terminal used by the user can be a device such as a mobile phone or a computer, and the user terminal can be the user's own mobile phone or someone else's mobile phone.
[0034] Then, the server generates a login verification code through a two - factor authentication mechanism and sends it to the user terminal.
[0035] The server verifies the login account by means of the two - factor authentication mechanism with the help of the user terminal device.
[0036] Next, the server verifies the enterprise user identity information based on the user's feedback operation on the user terminal, so that the login account of the enterprise user identity information logs into the industrial Internet platform and determines the enterprise user identity information.
[0037] Through the above solution, a two-factor authentication mechanism is used to assist in authenticating login accounts, thereby ensuring data access security on the industrial Internet platform and preventing account thefts from illegally using the industrial Internet platform.
[0038] It should be noted that the server, as the executor of the security access method based on the industrial Internet platform, is only an example. The executor is not limited to the server, and this application does not make any specific limitations on this.
[0039] S102: The server determines the identity database corresponding to the current enterprise user according to the enterprise user identity information.
[0040] The identity database is generated according to the user type. The user type is the identity type for registering the industrial Internet platform, including the first type and the second type.
[0041] In the embodiment of the present application, according to the enterprise user identity information, determining the identity database corresponding to the current enterprise user specifically includes:
[0042] The server determines the user type corresponding to the enterprise user identity information.
[0043] In the embodiment of the present application, user types include service provider users and manufacturing enterprise users.
[0044] When the user type is the first type, the server determines the first database as the identity database corresponding to the current enterprise user.
[0045] The first database is used to store platform service provider data. The first database corresponds to the user data of service provider users, such as user login account data, service provider employee user data, and industrial application software information listed on the industrial Internet platform.
[0046] When the user type is the second type, the server determines the second database as an identity database corresponding to the current enterprise user.
[0047] The second database includes the platform service provider data and enterprise management data in the first database. The enterprise management data corresponds to the data generated by enterprise administrators and corresponding enterprise users. For example, when an enterprise administrator adds a new enterprise user, the data of this new user. The second database is for producing enterprise user data. The second database can include the user data of service provider users, which can facilitate service provider users to purchase industrial application software. The enterprise users in the second database cannot list industrial application software for sale.
[0048] Illustrate the above embodiment with an example. User a registers as a service provider. After connecting the industrial application software to the Alibaba Cloud Identity as a Service (IDaaS), through the service provider management background of the IDaaS application center, the user shelves and manages cloud-based industrial APPs. The platform service provider data is stored in the first database A; User b registers as an enterprise and becomes an enterprise administrator. The enterprise management data is stored in the second database B. The service provider users in the first database A are synchronized to the second database B, enabling platform service provider users to purchase industrial application software.
[0049] In an embodiment of the present application, when the identity database of the server is the second database, through IDaaS, the usage permissions of the current enterprise user for each application software in the application database are determined.
[0050] When the identity database of the server is the second database, through IDaaS, the usage permissions of the current enterprise user for each application software in the application database and the application software listing permissions are determined.
[0051] Among them, the application software listing permission is used to manage and / or list the application software of the current enterprise user on the industrial Internet platform.
[0052] In an embodiment of the present application, determining the corresponding identity database of the current enterprise user according to the enterprise user identity information further specifically includes:
[0053] The server authenticates the enterprise user identity information through a preset IDaaS identity management protocol. Among them, the preset IDaaS identity management protocol includes at least one or more of the following: Central Authentication Service CAS, Security Assertion Markup Language SAML, Open Authorization OAuth2.0, OIDC.
[0054] The server determines the corresponding identity database of the current enterprise user according to the authentication result of authenticating the enterprise user identity information.
[0055] Through the above preset IDaaS identity management protocol, single sign-on for enterprise users is realized, improving the user experience of using the industrial Internet platform.
[0056] S103, the server determines the platform authority of the current enterprise user according to the identity database and the user authorization information of the preset blockchain platform.
[0057] The preset blockchain platform includes several enterprise user terminals for data transmission. The platform authority is used to obtain the scheduled services of the application database. The scheduled services are generated based on the user type.
[0058] In the embodiment of the present application, the scheduled service includes at least: purchase, sale and user use of industrial application software services.
[0059] In the embodiment of the present application, before the server determines the platform authority of the current enterprise user based on the identity database and the user authorization information of the preset blockchain platform, such as Figure 2 As shown, the following steps are also included:
[0060] S201, the server receives enterprise terminal registration information.
[0061] S202, the server determines the primary node of the enterprise user in the identity database according to the enterprise terminal registration information.
[0062] Among them, the number of first-level nodes corresponds to the number of enterprises in the identity database.
[0063] In the embodiment of the present application, the industrial Internet platform can set a first-level node for each enterprise as an enterprise administrator, through which the enterprise administrator can purchase industrial application software, distribute the use rights of terminal industrial application software to employees, etc. The enterprise administrator can be a service provider user or a production enterprise user.
[0064] S203, the server generates a corresponding blockchain platform based on the first-level node.
[0065] Among them, the blockchain platform is used for the first-level node to interact with the second-level nodes in the pre-generated single sign-on list.
[0066] The single sign-on list can store the login accounts of multiple employees' terminals. In the single sign-on list, the login accounts can correspond to a variety of different login methods, such as WeChat login, QQ login, etc. The server establishes a blockchain platform with the enterprise's first-level node and each second-level node.
[0067] S204, based on the asymmetric encryption algorithm, the server performs public key encryption processing on the user data of the secondary node after hash operation through the blockchain platform, and sends the user data after asymmetric encryption processing to the primary node.
[0068] The blockchain platform generates a hash value based on the user data of the secondary node through hash operation, encrypts the hash value with the public key using an asymmetric encryption algorithm, and sends the hash value encrypted with the public key to the primary node.
[0069] S205, the server decrypts the user data after asymmetric encryption processing through the private key of the primary node, and parses the user data to perform user authorization on the secondary node, obtaining the user authorization information of the secondary node.
[0070] The primary node can decrypt the hash value encrypted with the public key through the corresponding private key. Among them, if the decryption fails, the data sent by the secondary node is not processed. If the decryption is successful, the user data can be parsed, and the user data can be managed, such as adding user permissions, deleting user data, modifying user data, etc., and authorizing the secondary node to use the industrial application software purchased by the primary node.
[0071] Through the above solution, the user data of enterprise users can be securely encrypted and authorized to access industrial application software. Using the blockchain platform, the security and reliability of identity recognition and permission management can be ensured.
[0072] In the embodiment of the present application, the server determines the platform permissions of the current enterprise user according to the identity database and the user authorization information of the preset blockchain platform, specifically including:
[0073] First, the server determines the user storage data corresponding to the enterprise user identity information in the identity database.
[0074] Among them, the user storage data includes platform usage permissions. The platform usage permissions are generated according to the user authorization information.
[0075] In the embodiment of the present application, the platform usage permissions of enterprise users can be stored in the identity database, and the platform usage permissions can be obtained by enterprise administrators for enterprise employees through the above steps S201 - S205.
[0076] Then, the server determines whether there is a corresponding mapping relationship between the application software in the application database through the user storage data.
[0077] The mapping relationship is used to establish an association relationship between the users in the identity database and the application software in the application database.
[0078] In the embodiment of the present application, there is a corresponding application database in the industrial Internet platform. This application database is used to store industrial application software put on the shelf by service provider users. After an enterprise administrator purchases industrial application software, an association relationship corresponding to the enterprise administrator for the industrial application software can be established in the application database. Moreover, when the enterprise administrator gives an enterprise employee X the platform usage permission to use industrial application software A, the application database can establish the association relationship between enterprise employee X and industrial application software A, thereby generating a mapping relationship.
[0079] Finally, when there is a corresponding mapping relationship in the application database, the server determines the platform permission corresponding to the user's stored data.
[0080] The platform permission is the usage permission of the corresponding industrial application software for the terminal where the user stores data. In the embodiment of the present application, the application scenario diagram of the security access method based on the industrial Internet platform is as Figure 3 shown. The service provider user 301 puts on the shelf industrial application software 303 through the application center 302, and IDaaS304 manages user identities and application software. The enterprise user 305 purchases industrial application software 303 through IDaaS304, and manages and authorizes the use of the purchased industrial application software 303 through the enterprise center 306. Among them, before the enterprise user 305 uses the industrial application software 303 in the application center 302 through the enterprise center 306, it is necessary to pass the user identity verification of IDaaS304 and determine whether there is a corresponding mapping relationship for the enterprise user 305. The enterprise center 306 can store the user data of the enterprise user 305. Among them, the application center 302 is Software as a Service (SaaS) built on the industrial Internet platform, and the enterprise center 306 is SaaS built on the industrial Internet platform.
[0081] In an embodiment of the present application, the server can also execute the following method:
[0082] The server obtains enterprise user data from the enterprise management terminal based on the Lightweight Directory Access Protocol LDAP.
[0083] The enterprise management terminal corresponds to the enterprise administrator.
[0084] The server generates several nodes of a preset blockchain platform according to the enterprise user data.
[0085] Among them, several nodes of the preset blockchain platform include the enterprise management terminal and corresponding several enterprise user terminals.
[0086] Through the above solution, the enterprise management terminal can use LDAP to quickly import the user data of enterprise users into the corresponding identity database of the industrial Internet platform.
[0087] S104, the server determines the accessible information corresponding to the predetermined service based on the platform permissions and the operations of the current enterprise user, so as to enable the current enterprise user to securely access the industrial application software on the industrial Internet platform.
[0088] Wherein, the accessible information is the access information to the industrial application software on the industrial Internet platform.
[0089] In the embodiments of the present application, the server determines the accessible information corresponding to the predetermined service based on the platform permissions and the operations of the current enterprise user, specifically including:
[0090] First, the server determines whether the operations of the current enterprise user match the platform permissions.
[0091] Secondly, when the operations of the current enterprise user match the platform permissions, the server responds to the operations of the current enterprise user and determines the accessible information.
[0092] In the embodiments of the present application, the operation of the current enterprise user may be an operation of clicking to open a certain industrial application software, and the server will determine whether the current enterprise user can click to open the industrial application software in the platform permissions. If there is a permission to click to open the industrial application software in the platform permissions of the current enterprise user, then the server responds to the click operation of the enterprise user and determines the industrial application software as the accessible information.
[0093] Then, the server displays the accessible information on the terminal display interface of the current enterprise user.
[0094] Through the identity database of the above solution, the user data can be isolated from the data of the industrial Internet platform, ensuring data security, and providing good identity management services and permission management for enterprise users to use industrial application software, realizing secure access to the industrial application software on the industrial Internet. At the same time, it can improve the user experience of using the industrial Internet.
[0095] Figure 4 A security access device based on an industrial Internet platform provided by the embodiments of the present application, as Figure 4 shown, the device includes:
[0096] At least one processor; and a memory communicatively connected to the at least one processor. Wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor, so that the at least one processor can:
[0097] Determine the enterprise user's identity information. The enterprise user's identity information includes at least a login account. Based on the enterprise user's identity information, determine the identity database corresponding to the current enterprise user. The identity database is generated according to the user type. The user type is the identity type for registering the industrial Internet platform, including the first type and the second type. According to the identity database and the user authorization information of the preset blockchain platform, determine the platform authority of the current enterprise user. The preset blockchain platform includes several enterprise user terminals for data transmission. The platform authority is used to obtain the scheduled service of the application database. The scheduled service is generated based on the user type. Based on the platform authority and the operation of the current enterprise user, determine the accessible information corresponding to the scheduled service to achieve the current enterprise user's secure access to the industrial application software of the industrial Internet platform.
[0098] Each embodiment in this application is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.
[0099] The device and method provided in the embodiments of the present application correspond one to one, and therefore, the device also has similar beneficial technical effects as the corresponding method. Since the beneficial technical effects of the method have been described in detail above, the beneficial technical effects of the device will not be repeated here.
[0100] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.
[0101] The above is only an embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included in the scope of the claims of the present application.
Claims
1. A secure access method based on an industrial Internet platform, characterized in that, The method includes: Determine the identity information of enterprise users; the identity information of enterprise users includes at least a login account; According to the identity information of enterprise users, determine the corresponding identity database of the current enterprise user; wherein, the identity database is generated according to the user type; the user type is the identity type for registering the industrial Internet platform, including a first type and a second type; specifically including: Determine the user type corresponding to the identity information of the enterprise user; In the case where the user type is the first type, determine a first database as the corresponding identity database of the current enterprise user; wherein, the first database is used to store platform service provider data; In the case where the user type is the second type, determine a second database as the corresponding identity database of the current enterprise user; the second database includes the platform service provider data and enterprise management data in the first database; According to the identity database and the user authorization information of the preset blockchain platform, determine the platform permissions of the current enterprise user; wherein, the preset blockchain platform includes a number of enterprise user terminals for data transmission; the platform permissions are used to obtain the predetermined services of the application database; the predetermined services are generated based on the user type; Based on the platform permissions and the operations of the current enterprise user, determine the accessible information corresponding to the predetermined services, so as to realize the secure access of the current enterprise user to the industrial application software of the industrial Internet platform.
2. The method according to claim 1, characterized in that, According to the identity database and the user authorization information of the preset blockchain platform, determining the platform permissions of the current enterprise user specifically includes: Determine the user storage data corresponding to the enterprise user identity information in the identity database; wherein, the user storage data includes platform usage permissions; the platform usage permissions are generated according to the user authorization information; Through the user storage data, determine whether there is a corresponding mapping relationship for the application software in the application database; the mapping relationship is used to establish an association relationship between the users in the identity database and the application software in the application database; In the case where there is a corresponding mapping relationship in the application database, determine the platform permissions corresponding to the user storage data.
3. The method according to claim 1, characterized in that, Before determining the platform permissions of the current enterprise user according to the identity database and the user authorization information of the preset blockchain platform, the method further includes: Receive enterprise terminal registration information; According to the enterprise terminal registration information, determine the first-level nodes of enterprise users in the identity database; wherein, the number of the first-level nodes corresponds to the number of enterprises in the identity database; Generate a corresponding blockchain platform according to the first-level nodes; wherein, the blockchain platform is used for information interaction between the first-level nodes and each second-level node information in the pre-generated single sign-on list; Based on the asymmetric encryption algorithm, through the blockchain platform, perform public key encryption processing on the user data of the second-level nodes after hash operation, and send the user data after asymmetric encryption processing to the first-level nodes; Decrypt the user data after asymmetric encryption processing through the private key of the first-level node, and parse the user data to perform user authorization on the second-level node to obtain the user authorization information of the second-level node.
4. The method according to claim 1, characterized in that, The method further includes: When the identity database is the second database, determine the usage permissions of the current enterprise user for each application software in the application database through a preset IDaaS identity management protocol; When the identity database is the second database, determine the usage permissions of the current enterprise user for each application software in the application database and the application software listing permissions through a preset IDaaS identity management protocol; wherein, the application software listing permissions are used to manage and / or list the application software of the current enterprise user on the industrial Internet platform.
5. The method according to claim 1, characterized in that, Determine the corresponding identity database of the current enterprise user according to the enterprise user identity information, specifically including: Authenticate the enterprise user identity information through a preset IDaaS identity management protocol; wherein, the preset IDaaS identity management protocol includes at least one or more of the following: Central Authentication Service CAS, Security Assertion Markup Language SAML, Open Authorization OAuth2.0, OIDC; Determine the corresponding identity database of the current enterprise user according to the authentication result of authenticating the enterprise user identity information.
6. The method according to claim 1, characterized in that, The method further includes: Obtain enterprise user data from the enterprise management end based on the Lightweight Directory Access Protocol LDAP; Generate several nodes of the preset blockchain platform according to the enterprise user data; wherein, the several nodes of the preset blockchain platform include the enterprise management end and corresponding several enterprise user terminals.
7. The method according to claim 1, characterized in that, Determine the accessible information corresponding to the predetermined service based on the platform permissions and the operations of the current enterprise user, specifically including: Determine whether the operations of the current enterprise user match the platform permissions; When the operations of the current enterprise user match the platform permissions, respond to the operations of the current enterprise user and determine the accessible information.
8. The method according to claim 1, characterized in that, Determine the enterprise user identity information, specifically including: Determine the user terminal pre-bound to the currently logged-in login account; Generate a login verification code through a two-factor authentication mechanism and send it to the user terminal; Verify the enterprise user identity information based on the feedback operation of the user on the user terminal, so that the login account of the enterprise user identity information logs in to the industrial Internet platform and determine the enterprise user identity information.
9. A secure access device based on an industrial Internet platform, characterized in that, The device includes: At least one processor; and, A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor, so that the at least one processor can: Determine the enterprise user identity information; the enterprise user identity information includes at least a login account; According to the enterprise user identity information, determine the identity database corresponding to the current enterprise user; wherein the identity database is generated according to the user type; the user type is the identity type for registering the industrial Internet platform, including the first type and the second type; specifically comprising: determining the user type corresponding to the enterprise user identity information; when the user type is the first type, determining the first database as the identity database corresponding to the current enterprise user; wherein the first database is used to store platform service provider data; when the user type is the second type, determining the second database as the identity database corresponding to the current enterprise user; the second database includes the platform service provider data and enterprise management data in the first database; Determine the platform authority of the current enterprise user according to the identity database and the user authorization information of the preset blockchain platform; wherein the preset blockchain platform includes several enterprise user terminals for data transmission; the platform authority is used to obtain a predetermined service of the application database; the predetermined service is generated based on the user type; Based on the platform permissions and the operations of the current enterprise user, the accessible information corresponding to the reserved service is determined to enable the current enterprise user to securely access the industrial application software of the industrial Internet platform.
Citation Information
Patent Citations
Cloud platform user identity authentication method and device
CN105227324A
Multi-functional Identification Recognition System Capable of Recognizing the Identity of Users
US20190075101A1