Action authorization method and device
By introducing action authorization methods in the AAA system, different business needs are handled according to pre-set filtering condition groups and action groups, the problem of poor flexibility in traditional AAA systems is solved, and higher business processing flexibility and user experience are achieved.
Patent Information
- Application Number
- CN202011521076.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-12-21
- Publication Date
- 2025-05-09
- Estimated Expiration
- 2040-12-21
AI Technical Summary
Traditional Certification Authorized Billing (AAA) systems have poor flexibility in dealing with different business needs and require frequent modifications and upgrades to meet multiple business needs.
By introducing an action authorization method in the AAA system, an action authorization list is obtained according to the first message, which includes a plurality of filter condition groups preset for different services and a plurality of action groups corresponding to the plurality of filter condition groups. Match at least one attribute with the filter condition group in the multiple filter condition groups and perform an exact matched action group.
It improves the flexibility of the AAA system to handle different services, reduces the number of changes and upgrades to the AAA system, meets the personalized business needs of operators or enterprises and improves the user experience.
Smart Images

Figure CN114650538B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technology, and in particular to a method and device for action authorization. Background Art
[0002] With the development of informatization, different enterprise users or operators have various business needs, such as international roaming services, non-roaming access to the entire network or local services, operators' own portal services, temporary or special authorization services for users, etc.
[0003] However, the traditional Authentication, Authorization, Accounting (AAA) system can only process a single service, or the AAA system needs to be frequently modified and upgraded to meet different service requirements, which makes the AAA system inflexible in processing different services. Summary of the invention
[0004] The embodiment of the present application provides a method and apparatus for action authorization, thereby effectively improving the flexibility of the AAA system in processing different services.
[0005] In a first aspect of an embodiment of the present application, an embodiment of the present application provides a method for action authorization, comprising: obtaining an action authorization list according to a first message, the action authorization list comprising multiple filter condition groups pre-set for different services and multiple action groups corresponding to the multiple filter condition groups, the first message comprising at least one attribute; matching the at least one attribute with a first filter condition group among the multiple filter condition groups; when the at least one attribute completely matches the first filter condition group, executing a first action group corresponding to the first filter condition group.
[0006] In one embodiment of the present application, the above-mentioned obtaining the action authorization list based on the first message includes: obtaining the action authorization list when receiving the first message; and / or obtaining the action authorization list during the authentication and authorization process of the first message; and / or obtaining the action authorization list before sending the first message.
[0007] In one embodiment of the present application, when obtaining an action authorization list when receiving a first message, and / or obtaining an action authorization list before sending the first message, the first action group includes one or more of an add attribute action, a delete attribute action, and a replace attribute action.
[0008] In an embodiment of the present application, when obtaining an action authorization list during authentication and authorization of a first message, the first action group includes one or more of a forwarding attribute action, a copying attribute action, an authorization attribute action, and a recording attribute action.
[0009] In one embodiment of the present application, the method of action authorization also includes: when at least one attribute does not completely match the first filter condition group among multiple filter condition groups, matching the at least one attribute with other filter condition groups among the multiple filter condition groups in sequence; when at least one attribute completely matches the second filter condition group among the other filter condition groups, executing a second action group corresponding to the second filter condition group.
[0010] In an embodiment of the present application, the action authorization method further includes: when at least one attribute does not completely match other filter condition groups, ending the matching process.
[0011] In one embodiment of the present application, the first filter condition group and the first action group both include an action authorization name. Before executing the first action group corresponding to the first filter condition group, the action authorization method also includes: obtaining the first action group corresponding to the first filter condition group according to the action authorization name.
[0012] In one embodiment of the present application, a first filter condition group includes a first filter condition, and the first filter condition includes a first attribute name, a first attribute value, and a first operator associated with the first attribute name and the first attribute value. The above-mentioned matching of at least one attribute with the first filter condition group in multiple filter condition groups includes: determining whether the first attribute name exists in at least one attribute; when the judgment result is that the first attribute name exists in at least one attribute, matching the second attribute value in at least one attribute with the first operator and the first attribute value in the first filter condition; wherein, when at least one attribute is completely matched with the first filter condition group, executing the first action group corresponding to the first filter condition group includes: when the second attribute value in at least one attribute is completely matched with the first operator and the first attribute value in the first filter condition, executing the first action group corresponding to the first filter condition group.
[0013] In a second aspect of the embodiments of the present application, the embodiments of the present application provide an action authorization device. The action authorization device includes: an acquisition module, which is used to acquire an action authorization list according to a first message, the action authorization list includes multiple filter condition groups pre-set for different services and multiple action groups corresponding to the multiple filter condition groups, and the first message includes at least one attribute; a matching module, which is used to match at least one attribute with a first filter condition group in the multiple filter condition groups; and an execution module, which is used to execute a first action group corresponding to the first filter condition group when at least one attribute completely matches the first filter condition group.
[0014] In a third aspect of the embodiments of the present application, the embodiments of the present application provide a computer-readable storage medium having computer-executable instructions stored thereon, which, when executed by a processor, implement a method for action authorization provided in any one of the first aspects of the embodiments of the present application.
[0015] According to the technical solution provided in the embodiment of the present application, an action authorization list is obtained according to a first message, the action authorization list includes multiple filter condition groups pre-set for different services and multiple action groups corresponding to the multiple filter condition groups, and the first message includes at least one attribute; the at least one attribute is matched with the first filter condition group in the multiple filter condition groups; when the at least one attribute is completely matched with the first filter condition group, the first action group corresponding to the first filter condition group is executed, thereby effectively improving the flexibility of the AAA system in processing different services. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Figure 1 The figure shows an AAA system provided by an embodiment of the present application.
[0017] Figure 2 It is a flowchart of a method for action authorization provided in one embodiment of the present application.
[0018] Figure 3 It is a flowchart of a method for action authorization provided in another embodiment of the present application.
[0019] Figure 4 It is a structural diagram of an action authorization device provided in one embodiment of the present application.
[0020] Figure 5 This is a block diagram of an action authorization system provided by an embodiment of the present application. DETAILED DESCRIPTION
[0021] The following will combine the drawings required for use in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the drawings described below are only part of the embodiments of the present application, rather than all of the embodiments.
[0022] It should be noted that, based on the embodiments in this application, all related embodiments obtained by ordinary technicians in this field without making any creative work are within the scope of protection of this application.
[0023] It should also be noted that the "first", "second", etc. in the embodiments of the present application are merely for distinguishing each other and are not used to limit a fixed order or a fixed number.
[0024] The embodiments of the present application provide a method and device for action authorization, which are described in detail below.
[0025] Figure 1 The figure shows an AAA system provided by an embodiment of the present application. Figure 1As shown, the AAA system 100 includes an access server 110 and an AAA server 120 which are communicatively connected.
[0026] It should be understood that the AAA system 100 can be a system based on the RADIUS (Remote Authentication Dial InUser Service) protocol, or a system based on other protocols such as SIP (Session Initiation Protocol), etc., which is not specifically limited in this application. The AAA system 100 can also include other devices such as an Internet domain name server, an Internet exit firewall, etc., which is not specifically limited in this application. The access server 110 can use NAS (Network Access Server), or other access servers such as BRAS (Broadband Remote Access Server), which is not specifically limited in this application.
[0027] Figure 2 FIG. 1 is a flow chart of a method for action authorization provided by an embodiment of the present application. The method for action authorization can be performed by an AAA server in an AAA system based on the RADIUS protocol. Figure 2 As shown, the action authorization method includes the following steps.
[0028] S210: Acquire an action authorization list according to the first message, the action authorization list including a plurality of filter condition groups preset for different services and a plurality of action groups corresponding to the plurality of filter condition groups, and the first message including at least one attribute.
[0029] It should be understood that the first message can be an access request message, an authentication request message, a billing start message or a billing request message, etc.; the first message can be generated by an access server or an AAA server, and this application does not make specific restrictions on this. In addition to at least one attribute, the first message can also include other information, and this application does not make specific restrictions on this. At least one attribute can be obtained by the AAA server after parsing the first message, or it can be directly obtained from the first message, and this application does not make specific restrictions on this. At least one attribute can be a user name (User-Name), a request type (Request-Type), an address pool (Framed-Pool), etc. When the first message is different, at least one attribute will also be different, and this application does not make specific restrictions on this. The action authorization list can be pre-set by different enterprise users or operators according to their respective business needs, and this application does not make specific restrictions on this. Multiple filter condition groups and multiple action groups can directly establish a mapping relationship, or they can establish a mapping relationship through a common attribute such as an action authorization name, and this application does not make specific restrictions on this. Multiple filter condition groups can be set based on the RADIUS attribute dictionary to meet the filter condition groups corresponding to different services. The RADIUS attribute dictionary can be constructed by loading the RADIUS dictionaries of different operators or enterprises into the memory after the AAA server is started. The RADIUS attribute dictionary may include RADIUS standard attributes, attributes of various manufacturers, and internal extended attributes, etc. This application does not make specific restrictions on this. Different services may refer to personalized services required by different operators or enterprise users, etc., and may include international roaming services, non-roaming access to the entire network or local services, operators' own portal services, and temporary or special authorization services for users, etc. This application does not make specific restrictions on this.
[0030] S220: Match at least one attribute with a first filtering condition group among the multiple filtering condition groups.
[0031] Specifically, the AAA server compares at least one attribute with each filter condition in the first filter condition group.
[0032] It should be understood that multiple filter condition groups can be arranged in order, and the order can be adjusted by enterprise users or operators, etc., and multiple filter condition groups can also be arranged in disorder, and this application does not make specific restrictions on this. The first filter condition group can be any filter condition group among the multiple filter condition groups, and the first filter condition group can also be the filter condition group ranked first among the multiple filter condition groups, and this application does not make specific restrictions on this.
[0033] S230: When at least one attribute completely matches the first filtering condition group, executing a first action group corresponding to the first filtering condition group.
[0034] Specifically, when the AAA server matches at least one attribute with a first filtering condition group among the multiple filtering condition groups and the matching result is a complete match, the AAA server executes all actions in a first action group corresponding to the first filtering condition group.
[0035] According to the technical solution provided in the embodiment of the present application, by setting the action authorization list to include multiple filter condition groups pre-set for different services and multiple action groups corresponding to the multiple filter condition groups, different services can be distinguished according to the multiple filter condition groups. Regardless of which attributes are included in the first message, by matching at least one attribute in the first message with the first filter condition group in the multiple filter condition groups and the matching result is a complete match, the AAA server can determine the type of service, and the AAA server executes the first action group corresponding to the first filter condition group, thereby completing the action authorization for the service. The embodiment of the present application can use the action authorization list to realize the same AAA system to flexibly handle multiple services, and reduce the number of changes and upgrades to the AAA system, thereby meeting the personalized service needs in applications such as operators or enterprises, and improving the user experience.
[0036] Figure 3 Shown is a flow chart of a method for action authorization provided in another embodiment of the present application. Figure 3 The embodiment shown is Figure 2 A variation of the embodiment shown. Figure 3 As shown, Figure 2 The difference of the embodiment shown is that step S211 may correspond to Figure 2 In the embodiment shown, step S210, steps S221-S222 may correspond to Figure 2 Steps S220 and S231 in the illustrated embodiment may correspond to Figure 2 Step S230 in the illustrated embodiment.
[0037] S211: acquiring an action authorization list when receiving a first message, and / or acquiring an action authorization list during authentication and authorization of the first message, and / or acquiring an action authorization list before sending the first message.
[0038] Specifically, when the AAA server receives the first message, it can trigger the AAA server to obtain the action authorization list, and this process can be called entry matching; and / or, when the AAA server performs authentication and authorization on the first message, it can trigger the AAA server to obtain the action authorization list, and this process can be called process matching; and / or, when the AAA server can trigger the AAA server to obtain the action authorization list before sending the first message, this process can be called exit matching, and this application does not make specific limitations on this.
[0039] It should be understood that the multiple filter condition groups in the action authorization list can be set for the services corresponding to multiple entry matches, multiple process matches or multiple exit matches, or can be set for the services corresponding to any combination of one or more entry matches, process matches or exit matches. This application does not make specific limitations on this.
[0040] S221: Determine whether the first attribute name in the first filter condition exists in at least one attribute, wherein the first filter condition group includes the first filter condition, and the first filter condition includes the first attribute name, the first attribute value, and the first operation symbol associating the first attribute name and the first attribute value.
[0041] It should be understood that the first operation symbol can be a complete match (equal to), a complete mismatch (not equal to), a fuzzy match (partial match), greater than (for numerical attributes) and less than (for numerical attributes), etc., and this application does not make specific limitations on this.
[0042] S222: When the judgment result is that the first attribute name exists in the at least one attribute, the second attribute value in the at least one attribute is matched with the first operation symbol and the first attribute value in the first filtering condition.
[0043] Specifically, the AAA server may first determine whether the first attribute name in the first filtering condition exists in at least one attribute, and if so, determine whether the second attribute value in the at least one attribute matches the first filtering condition according to the first operation symbol and the first attribute value.
[0044] It should be understood that when the first filtering condition group also includes a second filtering condition, and the second filtering condition includes a second attribute name, a second attribute value, and a second operation symbol associating the second attribute name and the second attribute value, the AAA server can first determine whether the first attribute name in the first filtering condition exists in at least one attribute, and if so, determine whether the second attribute value in at least one attribute matches the first filtering condition based on the first operation symbol and the first attribute value, and then determine whether the second attribute name in the second filtering condition exists in at least one attribute, and if so, determine whether the third attribute value in at least one attribute matches the second filtering condition based on the second operation symbol and the second attribute value; the AAA server can also first determine whether the first attribute name in the first filtering condition and the second attribute name in the second filtering condition exist in at least one attribute, and if so, determine whether the second attribute value in at least one attribute matches the first filtering condition based on the first operation symbol and the first attribute value, and determine whether the third attribute value in at least one attribute matches the second filtering condition based on the second operation symbol and the second attribute value. The present application does not make specific restrictions on this.
[0045] S231: When the judgment result is that the second attribute value in the at least one attribute completely matches the first operation symbol and the first attribute value in the first filtering condition, execute the first action group corresponding to the first filtering condition group.
[0046] It should be understood that when the second filter condition group also includes other filter conditions, steps S221-S222 can be repeated multiple times until the judgment result is that at least one attribute completely matches all the filter conditions in the first filter condition group, and the first action group corresponding to the first filter condition group is executed, which will not be repeated here.
[0047] According to the technical solution provided by the embodiment of the present application, by obtaining the action authorization list when receiving the first message, and / or obtaining the action authorization list during the authentication and authorization process of the first message, and / or obtaining the action authorization list before sending the first message, the AAA server can use the action authorization list to match different services and execute the actions corresponding to the services, so that the same AAA system can flexibly handle multiple services, and reduce the number of changes and upgrades to the AAA system, thereby meeting the personalized service requirements in applications such as operators or enterprises, and improving the user experience. In addition, by judging whether the first attribute name in the first filtering condition exists in at least one attribute, when the judgment result is that the first attribute name does not exist in at least one attribute, the matching process of the next filtering condition group can be entered, saving the matching time and improving the matching efficiency. When the judgment result is that the first attribute name exists in at least one attribute, the second attribute value in at least one attribute is matched with the first operator and the first attribute value in the first filtering condition. Since the first operator can be a complete match, a complete mismatch, etc., the matching method is diversified, which is more conducive to finding the conditions corresponding to the service, making the setting of the filtering condition group more accurate, and improving the ability to distinguish different services using the action authorization list.
[0048] In one embodiment of the present application, when obtaining an action authorization list when receiving a first message, and / or obtaining an action authorization list before sending the first message, the first action group includes one or more of an add attribute action, a delete attribute action, and a replace attribute action.
[0049] For example, the action authorization list stores filter condition group 1 and action group 1 corresponding to a C2G service (ie, a service for converting a GSM (Global System for Mobile Communications) network to a CDMA (Code Division Multiple Access) network). Among them, filtering condition group 1 includes filtering condition 1: User-Name=ctnet and filtering condition 2: Request-Type=AccessRequest, wherein "User-Name (user name)" and "Request-Type (request type)" are attribute names, "=" represents the complete matching method in the operation symbol, "ctnet (attribute value of access network)" and "AccessRequest (authentication request)" are attribute values, action group 1 includes action 1 and action 2, wherein action 1: chgattr 3GPP-IMSI:=*>Calling-Station-Id:=* (converting the 3GPP-IMIS (3rd Generation Partnership Project-International Mobile Subscriber Identity) attribute in the GSM network to the Calling-Station-Id (user identity) in the CDMA network), action 2: addattr 3GPP2-Correlation-ID:=1o7HUiYO (adding attributes used in the CDMA network), wherein "chgattr" represents the attribute replacement action and "addattr" represents the attribute addition action.
[0050] The first message is an authentication request message, which includes attribute 1 and attribute 2. Attribute 1 includes attribute name 1 (User-Name) and attribute value 1 (ctnet), and attribute 2 includes attribute name 2 (Request-Type) and attribute value 2 (AccessRequest).
[0051] When the AAA server receives the authentication request message, the AAA server obtains the action authorization list (corresponding to step S211). The AAA server determines whether the authentication request message contains an attribute name such as User-Name in the filtering condition 1 (corresponding to step S221). When the judgment result is that the attribute name 1 contains User-Name, the attribute value 1 (ctnet) is matched with the operator (=) and the attribute value (ctnet) in the filtering condition 1 (corresponding to step S222), that is, it is determined whether the attribute value 1 satisfies the filtering condition 1 (User-Name=ctnet). When the judgment result is that the attribute value 1 (ctnet) completely matches the operator (=) and the attribute value (ctnet) in the filtering condition 1, the filtering condition 2 is matched, and the same matching process as steps S221 and S222 is performed. When the judgment result is that the attribute value 2 (AccessRequest) completely matches the operator (=) and the attribute value (AccessRequest) in the filtering condition 2, the entire matching process of the filtering condition group 1 is completed, and actions 1 and 2 are executed, thereby completing the action authorization process of the C2G service.
[0052] For another example, the action authorization list stores filter condition group 2 and action group 2 corresponding to different address pools for different services. Filter condition group 2 includes filter condition 3: Framed-Pool=public, where "Framed-Pool (address pool)" is the attribute name, "=" is the complete matching method in the operator, and "public (public address pool)" is the attribute value. Action group 2 includes action 3, where action 3: addattr ZTE-Virtual-VR:=1 (add the ZTE equipment vendor attribute ZTE-Virtual-VR and set the action value to 1), where "addattr" represents the action of adding attributes.
[0053] The first message is a network use authorization message, which includes attribute 3, and attribute 3 includes attribute name 3 (Framed-Pool) and attribute value 3 (public).
[0054] Before the AAA server sends a network use authorization message, the AAA server obtains an action authorization list (corresponding to step S211), and the AAA server determines whether the attribute name Framed-Pool in the filter condition group 2 exists in the network use authorization message (corresponding to step S221). When the judgment result is that attribute 3 exists Framed-Pool, the attribute value 3 (public) is matched with the operator (=) and the attribute value (public) in the filter condition 3 (corresponding to step S222), that is, it is determined whether the attribute value 3 satisfies the filter condition 3 (Framed-Pool=public). When the judgment result is that the attribute value 3 (public) completely matches the operator (=) and the attribute value (public) in the filter condition 3, the entire matching process of the filter condition group 2 is completed, and action 3 is executed, thereby realizing the action authorization process of matching different services with different address pools.
[0055] It should be understood that the action authorization list also stores filter condition groups and action groups corresponding to other services. The AAA server can achieve complete matching of the attributes in the authentication request message with a filter condition group during the first match, or it can achieve complete matching of the attributes in the authentication request message with a filter condition group after multiple matches. This application does not make specific restrictions on this. The first action group includes but is not limited to one or more of the add attribute action, delete attribute action, and replace attribute action, which can be set according to actual business needs, and this application does not make specific restrictions on this.
[0056] In an embodiment of the present application, by setting the first action group to include one or more of an add attribute action, a delete attribute action, and a replace attribute action, an action authorization process is implemented for the service corresponding to the first filter condition group, so that the AAA server can perform corresponding action authorization processes for different service requirements, thereby improving the flexibility of the AAA server in handling different service requirements.
[0057] In an embodiment of the present application, when obtaining an action authorization list during authentication and authorization of a first message, the first action group includes one or more of a forwarding attribute action, a copying attribute action, an authorization attribute action, and a recording attribute action.
[0058] For example, the action authorization list stores filter condition group 4 and action group 4 corresponding to the service of forwarding the billing request message to the ctwap.com domain. Among them, filter condition group 4 includes filter condition 4: User-Name = *ctwap, where "User-Name (user name)" is the attribute name, "= *" represents the fuzzy matching method in the operator, and different methods in the operator can also be identified by other methods, "ctwap (attribute value of access network)" is the attribute value, and action group 4 includes action 4, where action 4: proxygateway = ctwap.com (forwarding network use authorization message to ctwap.com domain), where "proxygateway" represents the forwarding attribute action.
[0059] The first message is a charging request message. The website query message includes attribute 4. Attribute 4 includes attribute name 4 (User-Name) and attribute value 4 (ctwap1).
[0060] When the AAA server is authenticating and authorizing the billing request message, the AAA server obtains the action authorization list (corresponding to step S211), and the AAA server determines whether the attribute name User-Name in the filter condition group 4 exists in the billing request message (corresponding to step S221). When the judgment result is that the attribute name User-Name exists in attribute 4, the attribute value 4 (ctwap1) is matched with the operation symbol (=*) and the attribute value (ctwap) in the filter condition 4 (corresponding to step S222), that is, it is determined whether the attribute value 4 satisfies the filter condition 4 (User-Name=*ctwap). When the judgment result is that the attribute value 4 (ctwap1) completely matches the operation symbol (=*) and the attribute value (ctwap) in the filter condition 4, the entire matching process of the filter condition group 4 is completed, and action 4 is executed, thereby realizing the action authorization process of forwarding the billing request message to the ctwap.com domain.
[0061] It should be understood that the first action group includes but is not limited to one or more of forwarding attribute actions, copying attribute actions, authorizing attribute actions and recording attribute actions, and may also include other attribute actions such as ignoring attribute actions, etc., which can be set specifically according to actual business needs, and this application does not make any specific limitations on this.
[0062] In an embodiment of the present application, by setting the first action group to include one or more of a forwarding attribute action, a copying attribute action, an authorization attribute action, and a recording attribute action, the AAA server can perform corresponding action authorization processes for different business requirements, thereby improving the flexibility of the AAA server in handling different business requirements.
[0063] In an embodiment of the present application, the first filter condition group and the first action group both include an action authorization name. Before step S230, the action authorization method further includes step S240.
[0064] S240: Acquire a first action group corresponding to the first filtering condition group according to the action authorization name.
[0065] For example, the first filter condition group and the first action group are both identified by the action authorization name 1. The first filter condition group and the first action group are associated with the action authorization name 1. The AAA server first obtains the action authorization name 1 from the first filter condition group. Since the first action group also includes the action authorization name 1, the AAA server can obtain the first action group corresponding to the first filter condition group according to the action authorization name 1.
[0066] It should be understood that the action authorization name is an identifier, which can be presented in digital form, such as 1, 2, etc., or in text form, or in other forms, and this application does not make specific limitations on this.
[0067] In an embodiment of the present application, the first filtering condition group is associated with the first action group by adopting an action authorization name, so that the AAA server can obtain the first action group corresponding to the first filtering condition group according to the action authorization name, which is conducive to correctly executing the corresponding action for the service corresponding to the first filtering condition group.
[0068] In an embodiment of the present application, the method for action authorization further includes the following steps S250 - S260 .
[0069] S250: When the at least one attribute does not completely match the first filtering condition group among the multiple filtering condition groups, sequentially match the at least one attribute with other filtering condition groups among the multiple filtering condition groups.
[0070] For example, multiple filter condition groups are arranged in order and include a first filter condition group, a third filter condition group, and a second filter condition group in sequence. When at least one attribute does not completely match the first filter condition group among the multiple filter condition groups, the AAA server first matches the at least one attribute with the third filter condition group among the multiple filter condition groups. When at least one attribute does not completely match the third filter condition group, the AAA server then matches the at least one attribute with the second filter condition group among the multiple filter condition groups.
[0071] It should be understood that the number of multiple filter condition groups can be 2, 3 or even more, and this application does not make any specific limitation on this.
[0072] S260: When at least one attribute completely matches a second filtering condition group in the other filtering condition groups, executing a second action group corresponding to the second filtering condition group.
[0073] It should be understood that the second filtering condition group may be any one of the multiple filtering condition groups except the first filtering condition group, and the present application does not specifically limit the order of the second filtering condition group in the multiple filtering condition groups.
[0074] In the embodiment of the present application, by sequentially matching at least one attribute with other filter condition groups in the plurality of filter condition groups, the matching process is made orderly, thereby avoiding repeated matching of the same filter condition group in the plurality of filter condition groups, and also avoiding missing a certain filter condition group. In addition, by executing the second action group corresponding to the second filter condition group when at least one attribute completely matches the second filter condition group in the other filter condition groups, the filter condition group matching at least one attribute is matched, which is conducive to executing the authorization action of the service corresponding to the at least one attribute.
[0075] In an embodiment of the present application, the action authorization method may further include step S270.
[0076] S270: When at least one attribute does not completely match any of the other filter condition groups, the matching process ends.
[0077] It should be understood that after the matching process is completed, the AAA server may continue to perform its actions before the matching, or directly send a rejection request message, etc. This application does not make specific limitations on this.
[0078] In the embodiment of the present application, when at least one attribute does not completely match other filter condition groups, the matching process is terminated, so that when the action authorization list does not include a service corresponding to at least one attribute, the action authorization for the user to perform the service is terminated.
[0079] Figure 4 The structure diagram of an action authorization device provided by an embodiment of the present application is shown. The action authorization device 400 includes: an acquisition module 410, which is used to acquire an action authorization list according to a first message, the action authorization list includes multiple filter condition groups pre-set for different services and multiple action groups corresponding to the multiple filter condition groups, and the first message includes at least one attribute; a matching module 420, which is used to match at least one attribute with a first filter condition group among the multiple filter condition groups; and an execution module 430, which is used to execute a first action group corresponding to the first filter condition group when at least one attribute completely matches the first filter condition group.
[0080] According to the technical solution provided in the embodiment of the present application, by setting the action authorization list to include multiple filter condition groups pre-set for different services and multiple action groups corresponding to the multiple filter condition groups, different services can be distinguished according to the multiple filter condition groups. Regardless of which attributes are included in the first message, by matching at least one attribute in the first message with the first filter condition group in the multiple filter condition groups and the matching result is a complete match, the AAA server can determine the type of service, and the AAA server executes the first action group corresponding to the first filter condition group, thereby completing the action authorization for the service. The embodiment of the present application can use the action authorization list to realize the same AAA system to flexibly handle multiple services, and reduce the number of changes and upgrades to the AAA system, thereby meeting the personalized service needs in applications such as operators or enterprises, and improving the user experience.
[0081] In one embodiment of the present application, the acquisition module 410 is also used to obtain the action authorization list when receiving the first message; and / or obtain the action authorization list during the authentication and authorization process of the first message; and / or obtain the action authorization list before sending the first message.
[0082] In one embodiment of the present application, when obtaining an action authorization list when receiving a first message, and / or obtaining an action authorization list before sending the first message, the first action group includes one or more of an add attribute action, a delete attribute action, and a replace attribute action.
[0083] In an embodiment of the present application, when obtaining an action authorization list during authentication and authorization of a first message, the first action group includes one or more of a forwarding attribute action, a copying attribute action, an authorization attribute action, and a recording attribute action.
[0084] In one embodiment of the present application, the matching module 420 is also used to match at least one attribute with other filter condition groups in sequence when at least one attribute does not completely match the first filter condition group in multiple filter condition groups; the execution module 430 is also used to execute a second action group corresponding to the second filter condition group when at least one attribute completely matches the second filter condition group in other filter condition groups.
[0085] In an embodiment of the present application, the action authorization apparatus further includes an ending module 440, which is used to end the matching process when at least one attribute does not completely match other filter condition groups.
[0086] In one embodiment of the present application, the first filter condition group and the first action group both include an action authorization name. Before executing the first action group corresponding to the first filter condition group, the acquisition module 410 is also used to acquire the first action group corresponding to the first filter condition group according to the action authorization name.
[0087] In one embodiment of the present application, the first filter condition group includes a first filter condition, the first filter condition includes a first attribute name, a first attribute value and a first operator associated with the first attribute name and the first attribute value, and the matching module 420 includes: a judgment module 421, used to judge whether the first attribute name exists in at least one attribute; a first matching module 422, used to match the second attribute value in at least one attribute with the first operator and the first attribute value in the first filter condition when the judgment result is that the first attribute name exists in at least one attribute; the execution module 430 is also used to execute the first action group corresponding to the first filter condition group when the second attribute value in at least one attribute completely matches the first operator and the first attribute value in the first filter condition.
[0088] Figure 5 This is a block diagram of an action authorization system provided by an embodiment of the present application.
[0089] Reference Figure 5 , the system 500 includes a processing component 510, which further includes one or more processors, and a memory resource represented by a memory 520 for storing instructions executable by the processing component 510, such as an application. The application stored in the memory 520 may include one or more modules, each corresponding to a set of instructions. In addition, the processing component 510 is configured to execute instructions to perform the above-mentioned action authorization method.
[0090] The system 500 may also include a power supply component configured to perform power management of the system 500, a wired or wireless network interface configured to connect the system 500 to a network, and an input / output (I / O) interface. The system 500 may operate based on an operating system stored in the memory 520, such as Windows Server 2000. TM , Mac OS X TM , Unix TM , Linux TM , FreeBSD TM or similar.
[0091] A non-temporary computer-readable storage medium, when the instructions in the storage medium are executed by the processor of the above-mentioned system 500, enables the above-mentioned system 500 to execute a method for action authorization, the method being executed by an agent program, the method comprising: obtaining an action authorization list according to a first message, the action authorization list comprising a plurality of filter condition groups pre-set for different businesses and a plurality of action groups corresponding to the plurality of filter condition groups, the first message comprising at least one attribute; matching the at least one attribute with a first filter condition group among the plurality of filter condition groups; and executing a first action group corresponding to the first filter condition group when the at least one attribute completely matches the first filter condition group.
[0092] Those of ordinary skill in the art will appreciate that the algorithmic steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0093] In the several embodiments provided in this application, it should be understood that the disclosed methods, devices and systems can be implemented in other ways. For example, the device embodiments described above are only schematic, for example, the division of the modules is only a logical function division, and there may be other division methods in actual implementation, for example, multiple modules can be combined or integrated into another system, or some features can be ignored or not executed.
[0094] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application can be essentially or partly embodied in the form of a software product that contributes to the prior art. The computer software product is stored in a storage medium, including several instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), disk or optical disk, etc., various media that can store program check codes.
[0095] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the above-described device and system can refer to the corresponding process in the aforementioned method embodiment, and will not be repeated here.
[0096] It should also be noted that the combination of the various technical features in the embodiments of the present application is not limited to the combination recorded in the embodiments of the present application or the combination recorded in the specific embodiments, and all technical features recorded in this case can be freely combined or combined in any way unless there is a contradiction between them.
[0097] The above description is only a preferred embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent substitutions, etc. made within the spirit and principles of the present application shall be included in the protection scope of the present application.
Claims
1. A method for action authorization, characterized in that: include: Acquire an action authorization list according to the first message, wherein the action authorization list includes a plurality of filter condition groups pre-set for different services and a plurality of action groups corresponding to the plurality of filter condition groups, and the first message includes at least one attribute; matching the at least one attribute with a first filter condition group among the plurality of filter condition groups; When the at least one attribute completely matches the first filtering condition group, executing a first action group corresponding to the first filtering condition group, The method is applied in an AAA system. The step of obtaining the action authorization list according to the first message includes: acquiring the action authorization list when receiving the first message; and / or Acquiring the action authorization list during the authentication and authorization process of the first message; and / or before sending the first message, obtaining the action authorization list; The first filtering condition group includes a first filtering condition, the first filtering condition includes a first attribute name, a first attribute value, and a first operation symbol associating the first attribute name and the first attribute value, and matching the at least one attribute with the first filtering condition group in the multiple filtering condition groups includes: Determining whether the first attribute name exists in the at least one attribute; When the judgment result is that the first attribute name exists in the at least one attribute, the second attribute value in the at least one attribute is matched with the first operation symbol and the first attribute value in the first filtering condition.
2. The method according to claim 1, characterized in that When the action authorization list is obtained when the first message is received, and / or when the action authorization list is obtained before the first message is sent, the first action group includes one or more of an add attribute action, a delete attribute action, and a replace attribute action.
3. The method according to claim 1, characterized in that When the action authorization list is obtained during the authentication and authorization process of the first message, the first action group includes one or more of a forwarding attribute action, a copying attribute action, an authorization attribute action, and a recording attribute action.
4. The method according to claim 1, characterized in that Also includes: When the at least one attribute does not completely match the first filter condition group among the multiple filter condition groups, sequentially matching the at least one attribute with other filter condition groups among the multiple filter condition groups; When the at least one attribute completely matches a second filtering condition group in the other filtering condition groups, a second action group corresponding to the second filtering condition group is executed.
5. The method according to claim 4, characterized in that Also includes: When the at least one attribute does not completely match any of the other filter condition groups, the matching process ends.
6. The method according to any one of claims 1 to 5, characterized in that The first filtering condition group and the first action group both include an action authorization name, and before executing the first action group corresponding to the first filtering condition group, the method further includes: A first action group corresponding to the first filtering condition group is acquired according to the action authorization name.
7. The method according to any one of claims 1 to 5, characterized in that When the at least one attribute completely matches the first filtering condition group, executing a first action group corresponding to the first filtering condition group includes: When a second attribute value in the at least one attribute completely matches the first operation symbol and the first attribute value in the first filtering condition, a first action group corresponding to the first filtering condition group is executed.
8. An action authorization device, characterized in that: include: an acquisition module, configured to acquire an action authorization list according to a first message, wherein the action authorization list includes a plurality of filter condition groups preset for different services and a plurality of action groups corresponding to the plurality of filter condition groups, and the first message includes at least one attribute; a matching module, configured to match the at least one attribute with a first filtering condition group among the plurality of filtering condition groups; an execution module, configured to execute a first action group corresponding to the first filtering condition group when the at least one attribute completely matches the first filtering condition group, The action authorization device is applied in the AAA system. Wherein, the acquisition module is used to acquire the action authorization list when receiving the first message; and / or The acquisition module is used to acquire the action authorization list during the authentication and authorization process of the first message; and / or The acquisition module is used to acquire the action authorization list before sending the first message, Among them, the first filtering condition group includes a first filtering condition, the first filtering condition includes a first attribute name, a first attribute value and a first operation symbol associating the first attribute name and the first attribute value, and the matching module is specifically used to determine whether the first attribute name exists in the at least one attribute, and when the judgment result is that the first attribute name exists in the at least one attribute, the second attribute value in the at least one attribute is matched with the first operation symbol and the first attribute value in the first filtering condition.
9. A computer-readable storage medium having computer-executable instructions stored thereon, characterized in that: When the executable instructions are executed by a processor, the method for action authorization according to any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
Business data processing method and device, computer equipment and storage medium
CN111460298A
Charged information acquisition system and method, and charge realizing system and method
CN1937511A