Rights management method, system, device and computer-readable storage medium

Through remote control of the mobile communication system, the problem of inflexible permission granting is solved, and the flexibility and security of permission management without logging into the business system are achieved.

CN115622717BActive Publication Date: 2025-10-03CHINA MOBILE COMM LTD RES INST +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202110782999.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-07-12
Publication Date
2025-10-03
Estimated Expiration
2041-07-12

AI Technical Summary

Technical Problem

Existing technologies cannot flexibly grant permissions when users are unable to log in to the business system, resulting in inflexible permission management.

Method used

Through the communication function of the mobile communication system, network equipment is used to remotely control the business system to perform permission management, including permission granting and cancellation, to avoid logging into the business system to directly perform permission management.

Benefits of technology

It enables flexible granting and revoking of permissions without logging into the business system, improving the flexibility and security of permission management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115622717B_ABST
    Figure CN115622717B_ABST
Patent Text Reader

Abstract

The present application discloses a permission management method, system, device and computer-readable storage medium, which belongs to the field of information security technology. The specific implementation scheme includes: the business system receives the first identifier of the permission grantor, the second identifier of the permission grantee and the permission granting identifier from the network device; wherein, the first identifier, the second identifier and the permission granting identifier are sent by the network device after receiving the permission granting trigger request from the terminal of the permission grantor; the first system account of the permission grantor is determined according to the first identifier, and the second system account of the permission grantee is determined according to the second identifier; according to the permission granting identifier, the second system account is granted the permission to use the first system account. According to the scheme in the present application, it is not necessary to log in to the business system for permission management, so that the permission granting of the business system can be flexibly performed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application belongs to the field of information security technology, and specifically relates to a permission management method, system, device and computer-readable storage medium. Background Art

[0002] Permission granting is a common feature in business systems. This allows user B to temporarily grant user A's permissions, granting them temporary business operation permissions, allowing them to perform certain operations on behalf of user A. After the operation is completed, the temporarily granted permissions are revoked to isolate permissions and prevent user B from unauthorized access to permissions held by user A. Currently, granting user B's permissions from user A must be done within the business system. If the business system is inaccessible, permission granting cannot be configured, resulting in inflexible permission granting within the business system. Summary of the Invention

[0003] The purpose of the embodiments of the present application is to provide a permission management method, system, device and computer-readable storage medium to solve the problem that permission granting for business systems cannot be flexibly performed at present.

[0004] In order to solve the above technical problems, this application is implemented as follows:

[0005] In a first aspect, a rights management method is provided, which is applied to a business system and includes:

[0006] Receiving a first identifier of an authority grantor, a second identifier of an authority grantee, and an authority granting identifier from a network device; wherein the first identifier, the second identifier, and the authority granting identifier are sent by the network device after receiving an authority granting trigger request from a terminal of the authority grantor;

[0007] Determining a first system account of the authority grantor according to the first identifier, and determining a second system account of the authority granted according to the second identifier;

[0008] According to the permission granting identifier, the second system account is granted permission to use the first system account.

[0009] Optionally, the permission grant trigger request includes: the second identifier and the permission grant identifier; the first identifier is determined by the network device according to the wireless channel corresponding to the permission grant trigger request.

[0010] Optionally, the receiving port address of the permission grant trigger request corresponds to the business system.

[0011] Optionally, the permission granting trigger request includes: the system login password of the permission granter;

[0012] The method further comprises:

[0013] receiving the system login password from the network device;

[0014] authenticating the permission grantor based on the first system account and the system login password;

[0015] The step of granting the second system account permission to use the first system account according to the permission granting identifier includes:

[0016] When the identity authentication of the authority granter is successful, the second system account is granted the authority to use the first system account according to the authority granting identifier.

[0017] Optionally, the permission grant trigger request includes: permission grant time;

[0018] The method further comprises:

[0019] receiving the permission granting time from the network device;

[0020] After granting the second system account permission to use the first system account according to the permission granting identifier, the method further includes:

[0021] When the time for the second system account to use the permission of the first system account reaches the permission granting time, the permission of the second system account to use the first system account is revoked.

[0022] Optionally, the method further includes:

[0023] Receiving the first identifier, the second identifier, and the permission cancellation identifier from the network device; wherein the first identifier, the second identifier, and the permission cancellation identifier are sent by the network device after receiving the permission cancellation trigger request from the terminal of the permission grantor;

[0024] Determining a first system account of the authority grantor according to the first identifier, and determining a second system account of the authority granted according to the second identifier;

[0025] The permission of the second system account to use the first system account is revoked according to the permission revocation identifier.

[0026] In a second aspect, a rights management system is provided, comprising: a network device and a business system;

[0027] The network device is configured to: receive a permission granting trigger request from a terminal of a permission granter, and send a first identifier of the permission granter, a second identifier of the permission grantee, and a permission granting identifier to the business system;

[0028] The business system is used to: receive the first identifier, the second identifier and the permission granting identifier from the network device; determine the first system account of the permission granter based on the first identifier, and determine the second system account of the permission grantee based on the second identifier; and grant the second system account permission to use the first system account based on the permission granting identifier.

[0029] Optionally, the permission grant trigger request includes: the second identifier and the permission grant identifier; the network device is further used to: determine the first identifier according to the wireless channel corresponding to the permission grant trigger request.

[0030] Optionally, the network device is further used to: determine the business system according to the receiving port address of the permission grant trigger request.

[0031] Optionally, the permission granting trigger request includes: the system login password of the permission granter;

[0032] The business system is also used to: receive the system login password from the network device; authenticate the identity of the authority granter based on the first system account and the system login password; when the identity authentication of the authority granter is successful, grant the second system account the authority to use the first system account based on the authority granting identifier.

[0033] Optionally, the permission grant trigger request includes: permission grant time;

[0034] The business system is further configured to: receive the permission granting time from the network device; and cancel the permission of the second system account to use the first system account when the time during which the second system account uses the permission of the first system account reaches the permission granting time.

[0035] Optionally, the network device is configured to: receive a permission cancellation trigger request from the terminal of the permission grantor, and send the first identifier, the second identifier, and a permission cancellation identifier to the business system;

[0036] The business system is used to: receive the first identifier, the second identifier and the permission cancellation identifier from the network device; determine the first system account of the permission grantor based on the first identifier, and determine the second system account of the permission grantee based on the second identifier; and cancel the permission of the second system account to use the first system account based on the permission granting identifier.

[0037] In a third aspect, a rights management device is provided, which is applied to a business system and includes:

[0038] A receiving module, configured to receive a first identifier of an authority grantor, a second identifier of an authority grantee, and an authority granting identifier from a network device; wherein the first identifier, the second identifier, and the authority granting identifier are sent by the network device after receiving an authority granting trigger request from a terminal of the authority grantor;

[0039] a parsing module, configured to determine a first system account of the authority granter based on the first identifier, and to determine a second system account of the authority granted based on the second identifier;

[0040] The authority management module is used to grant the second system account the authority to use the first system account according to the authority granting identifier.

[0041] Optionally, the permission grant trigger request includes: the second identifier and the permission grant identifier; the first identifier is determined by the network device according to the wireless channel corresponding to the permission grant trigger request.

[0042] Optionally, the receiving port address of the permission grant trigger request corresponds to the business system.

[0043] Optionally, the permission granting trigger request includes: the system login password of the permission granter;

[0044] The receiving module is further configured to: receive the system login password from the network device;

[0045] The authority management module is further configured to: authenticate the authority grantor based on the first system account and system login password; and when the authority grantor's identity authentication is successful, grant the second system account the authority to use the first system account based on the authority granting identifier.

[0046] Optionally, the permission grant trigger request includes: permission grant time;

[0047] The receiving module is further configured to: receive the permission granting time from the network device;

[0048] The authority management module is further configured to cancel the authority of the second system account to use the first system account when the time for the second system account to use the authority of the first system account reaches the authority granting time.

[0049] Optionally, the receiving module is further configured to: receive the first identifier, the second identifier, and the permission cancellation identifier from the network device; wherein the first identifier, the second identifier, and the permission cancellation identifier are sent by the network device after receiving the permission cancellation trigger request from the terminal of the permission grantor;

[0050] The parsing module is used to: determine a first system account of the authority granter according to the first identifier, and determine a second system account of the authority granted according to the second identifier;

[0051] The authority management module is further configured to cancel the authority of the second system account to use the first system account according to the authority cancellation identifier.

[0052] In a fourth aspect, an embodiment of the present application provides a business system, which includes a processor, a memory, and a program or instruction stored in the memory and executable on the processor, wherein the program or instruction, when executed by the processor, implements the steps of the method described in the first aspect.

[0053] In a fifth aspect, an embodiment of the present application provides a computer-readable storage medium, on which a program or instruction is stored. When the program or instruction is executed by a processor, the steps of the method described in the first aspect are implemented.

[0054] In an embodiment of the present application, after receiving a permission granting trigger request from the permission granting terminal, the network device can send the permission granting terminal's first identifier, the permission granting terminal's second identifier, and the permission granting identifier to the business system, so that the business system determines the permission granting terminal's first system account based on the first identifier, determines the permission granting terminal's second system account based on the second identifier, and grants the second system account permission to use the first system account based on the permission granting identifier. In this way, the communication function of the mobile communication system can be utilized to remotely control the business system for permission granting with the help of the network device, thereby eliminating the need to log in to the business system for permission management, thereby flexibly granting permission to the business system. BRIEF DESCRIPTION OF THE DRAWINGS

[0055] Figure 1 This is a flowchart of a rights management method provided by an embodiment of the present application;

[0056] Figure 2 This is a schematic diagram of the rights management process in an embodiment of the present application;

[0057] Figure 3 This is a schematic diagram of the structure of a rights management system provided by an embodiment of the present application;

[0058] Figure 4 This is a schematic diagram of the structure of a rights management device provided in an embodiment of the present application;

[0059] Figure 5 This is a structural diagram of a business system provided in an embodiment of the present application. DETAILED DESCRIPTION

[0060] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0061] The terms "first," "second," and the like in the specification and claims of this application are used to distinguish similar objects, and are not used to describe a specific order or precedence. It should be understood that the terms used in this manner are interchangeable where appropriate, so that the embodiments of this application can be implemented in an order other than that illustrated or described herein, and that the objects distinguished by "first," "second," and the like are generally of the same type, and do not limit the number of objects; for example, the first object can be one or more. In addition, the term "and / or" in the specification and claims refers to at least one of the connected objects, and the character " / " generally indicates that the objects connected are in an "or" relationship.

[0062] In order to solve the current problem of being unable to flexibly grant permissions to business systems, an embodiment of the present application provides a permission management method, which utilizes the communication function of the mobile communication system to remotely control the business system for permission management, such as granting or canceling permissions, so that there is no need to log in to the business system for permission management, thereby flexibly granting permissions to the business system.

[0063] The following, in conjunction with the accompanying drawings, describes in detail the rights management method, system, device, and computer-readable storage medium provided in the embodiments of the present application through specific embodiments and their application scenarios.

[0064] See Figure 1 , Figure 1 This is a flowchart of a rights management method provided by an embodiment of the present application, which is applied to a business system, such as Figure 1 As shown, the method includes the following steps:

[0065] Step 101: Receive a first identifier of a permission grantor, a second identifier of a permission grantee, and a permission granting identifier from a network device.

[0066] In this embodiment, the first identifier, the second identifier, and the permission granting identifier may be sent by the network device after receiving the permission granting trigger request from the permission granting terminal. The network device may be, for example, a base station, and the terminal may be, for example, a mobile phone, a tablet computer, an in-vehicle electronic device, a wearable device, etc.

[0067] Optionally, the permission granting trigger request may be a text message, phone call, data plane request, etc. The first identifier is used to uniquely identify the permission grantor and may be a mobile phone number, etc. The second identifier is used to uniquely identify the permission granted and may be a mobile phone number, etc.

[0068] Optionally, in order to avoid leakage of content transmitted between network devices and business systems, network devices and business systems can be interconnected by enabling public lines encrypted by Transport Layer Security (TLS) through a Virtual Private Network (VPN), thereby protecting the transmitted content and avoiding information leakage.

[0069] Step 102: Determine a first system account of the authority granter based on the first identifier, and determine a second system account of the authority granted based on the second identifier.

[0070] It is understandable that the first system account is the account used by the authority grantor to log in to the business system, and the second system account is the account used by the authority granted to log in to the business system. In specific implementation, the business system can use the first identifier of the authority grantor to query and obtain the first system account of the authority grantor based on pre-registration information, and use the second identifier of the authority granted to query and obtain the second system account of the authority granted to.

[0071] Step 103: According to the permission granting identifier, the second system account is granted permission to use the first system account.

[0072] In this embodiment, the permission granting identifier is used to indicate that the business system is granting permission to the permission grantee. This permission granting can be a temporary permission grant. The above-mentioned granting of permission to the second system account to use the first system account can be understood as: granting the permission grantee the permission to use the permission grantor, that is, the business system is granting permission to the permission grantee.

[0073] It should be noted that the specific form of the permission granting identifier can be selected based on actual needs, such as 1-bit information, etc., and this embodiment does not limit this.

[0074] In the permission management method of the embodiment of the present application, after receiving a permission granting trigger request from the permission granting terminal, the network device can send the permission granting terminal's first identifier, the permission grantee's second identifier, and the permission granting identifier to the business system, so that the business system determines the permission granting terminal's first system account based on the first identifier, determines the permission grantee's second system account based on the second identifier, and grants the second system account permission to use the first system account based on the permission granting identifier. In this way, the communication function of the mobile communication system can be utilized to remotely control the business system with the help of the network device to grant permissions, thereby eliminating the need to log in to the business system for permission management, thereby flexibly granting permissions to the business system.

[0075] In an embodiment of the present application, the permission granter and the permission recipient may be two fixed users in the business system. For example, the permission granter is a preset user 1, and the permission recipient is a preset user 2. In this case, after user 1 uses its terminal, such as a mobile phone, to send a permission grant trigger request to the network device, the network device may send the identifier of user 1, the identifier of user 2, and the permission grant identifier to the business system based on the received permission grant trigger request, so that the business system can determine the system accounts of user 1 and user 2, and grant the system account of user 2 the permission to use the system account of user 1, that is, user 2 grants permission to user 1.

[0076] In addition, in addition to performing permission management on fixed users, the embodiments of the present application can also perform permission management on any two users of the business system.

[0077] Optionally, when performing permission management on any two users of the business system, the permission granting trigger request sent by the permission granter may include the first identifier of the permission granter, the second identifier of the permission grantee and the permission granting identifier, so that the network device forwards the received first identifier, second identifier and permission granting identifier to the business system for permission management.

[0078] Optionally, when performing permission management for any two users of a business system, the permission granter may include the second identifier of the permission recipient and the permission granting identifier in the permission granting trigger request. Meanwhile, the first identifier of the permission granter is determined by the network device based on the wireless channel corresponding to the permission granting trigger request. This prevents the identity of the permission granter from being leaked, potentially leading to impersonation of a user to perform permission management operations.

[0079] In an embodiment of the present application, in order to ensure the implementation of permission management in the corresponding business system, a correspondence between the receiving port address of the permission grant trigger request and the business system can be pre-set so that after receiving the permission grant trigger request, the network device can determine the business system to which it belongs based on the receiving port address of the permission grant trigger request, that is, determine the business system to which the permission management triggered by the permission grant trigger request belongs. In other words, in this embodiment, the receiving port address of the permission grant trigger request corresponds to the business system to which the permission management triggered by the permission grant trigger request belongs.

[0080] Optionally, the permission granting trigger request may include the system login password of the permission granter. Accordingly, the business system may receive the system login password from the network device. The permission granter may then be authenticated based on the first system account and the system login password. If the permission granter's identity authentication is successful, the second system account may be granted permission to use the first system account based on the permission granting identifier. In this way, by authenticating the permission granter, the permission granted by the permission recipient to the permission granter can be securely granted.

[0081] Optionally, in order to prevent the permission temporarily granted by the permission grantor to the permission grantee from being used all the time, the permission grant trigger request may include: permission granting time; the permission granting time may be understood as the maximum time that the permission grantee can use the granted permission. Accordingly, the business system can receive the permission granting time from the network device. Afterwards, after granting the second system account permission to use the first system account, when the time that the second system account uses the permission of the first system account reaches the permission granting time, the business system may cancel the permission of the second system account to use the first system account. In this way, the permission grantor can take back the granted permission, prevent the permission temporarily granted by the permission grantor to the permission grantee from being used all the time, thereby protecting the rights and interests of the permission grantor.

[0082] It should be pointed out that in addition to the above-mentioned method of allowing the authority grantor to revoke the granted authority, the authority grantor can also be allowed to revoke the granted authority by pre-setting the authority granting time. For example, the authority granting time is pre-set in the business system. In this way, after the second system account is granted the authority to use the first system account, when the time the second system account uses the authority of the first system account reaches the pre-set authority granting time, the authority of the second system account to use the first system account is automatically canceled, that is, the authority grantor automatically revokes the granted authority. Among them, this authority granting time can be pre-set based on actual needs, such as 1 hour or 2 hours, etc., and this embodiment does not limit this.

[0083] In the embodiment of the present application, in addition to granting permissions based on a permission granting trigger request, the permission that has been granted can also be cancelled based on a permission cancelling trigger request. Optionally, the permission management method may further include:

[0084] The business system receives a first identifier, a second identifier, and a permission cancellation identifier from the network device; wherein the first identifier, the second identifier, and the permission cancellation identifier are sent by the network device after receiving a permission cancellation trigger request from the terminal of the permission grantor;

[0085] The business system determines a first system account of the authority grantor based on the first identifier, and determines a second system account of the authority granted based on the second identifier;

[0086] The business system cancels the permission of the second system account to use the first system account according to the permission cancellation flag.

[0087] In this way, the authority granter can revoke the granted authority, preventing the authority temporarily granted by the authority granter to the authority grantee from being used continuously, thereby protecting the rights and interests of the authority granter.

[0088] It should be pointed out that the process of revoking permission in this embodiment is similar to the process of granting permission mentioned above. For example, the first identifier, the second identifier and the permission revocation identifier are carried in the permission revocation trigger request, or the second identifier and the permission revocation identifier are carried in the permission revocation trigger request, etc. In order to avoid repeated limitations, they will not be repeated here.

[0089] The following combination Figure 2 The permission management process in the specific example of this application is explained.

[0090] In the specific examples of this application, Figure 2 As shown, the rights management system includes a base station 21 and a business system 22. The base station 21 includes an identification module 211, and the business system 22 includes a conversion module 221 and a rights granting module 222. In other words, the rights management system in this example integrates the communication system and the business system. The newly designed module can utilize the communication functions of the mobile communication system to remotely and securely implement rights management of the business system.

[0091] For example, if the trigger request is a text message and user A's business permissions are granted to user B, Figure 2 As shown, the corresponding permission management process includes the following steps:

[0092] S1: User A uses his mobile phone to send a short message to the SMS service receiving port address of the base station 21 to trigger the permission granting operation of the service system; wherein the short message includes user B's mobile phone number, user A's system login password, and permission granting identifier.

[0093] The receiving SMS service port address is the receiving short message number. The base station 21 can determine the service system to which the number in the received SMS service port address belongs, that is, determine which service system is triggered to perform the permission granting operation.

[0094] Optionally, the identification module 211 is located in the base station 21, and the processing operation includes: identifying the mobile phone number of user A according to the uniqueness of the physical characteristics of the wireless channel.

[0095] S2: The base station 21 sends the mobile phone number of user A, the mobile phone number of user B, the system login password of user A, and the permission granting identifier to the corresponding business system 22.

[0096] Among them, the business system 22 can communicate with the base station 21 through a VPN line or a public line with TLS encryption enabled, and receive user A's mobile phone number, user B's mobile phone number, user A's system login password, and permission granting identifier sent by the base station 21.

[0097] S3: The conversion module 221 in the business system 22 performs the following operations: 1) searches for the business system account of the authorized user A based on the mobile phone number of user A; 2) searches for the business system account of the authorized user B based on the mobile phone number of user B; 3) sends the business system account and login password of user A, the business system account of user B, and the permission granting identifier to the permission granting module 222.

[0098] The authority granting module 222 may receive the business system account and login password of user A, the business system account of user B, and the authority granting identifier sent by the conversion module 221 through the internal interface.

[0099] S4: The authority granting module 222 performs the following operations: 1) determines the legitimacy of the business system identity based on the business system account and login password of user A found; 2) after successful identity authentication, temporarily grants user B authority to user A based on the authority granting identifier.

[0100] In addition, through the similar process of S1-S4 above and with the permission cancellation mark included in the short message, the permission of user B to use user A can also be cancelled, so that user A takes back the granted permission.

[0101] It should be noted that to address the issue of SMS content leakage over wireless air interfaces, the wireless portion of this example no longer carries identity information such as the International Mobile Subscriber Identity (TMSI) / S-TMSI that can be used to identify the sender user when sending short messages, as in traditional mobile communication systems. Instead, it utilizes wireless channel physical characteristics to identify User A. This technology ensures that the base station uniquely identifies User A and prevents impersonation. Thus, the information transmitted in the SMS content lacks the four elements required for permission granting: the authorized user identity, password, authorized user identity, and the authorized user identity in the permission granting identifier. This prevents the leakage of the authorized user identity and the subsequent manipulation of the authorized user by impersonating the user.

[0102] In addition, the content transmitted in the SMS in this example includes the authorized user's login password, the authorized user's indirect identity information (mobile phone number), and the permission granting identifier, but does not include the authorized user's account information in the business system. In this way, even if the content of the SMS sent by User A is obtained, it is impossible to directly operate in the business system. At the same time, the authorized user's password is transmitted in the SMS, but this password is not the authorized user's login password in the SMS content. Even if the content of the SMS sent by User A is obtained, it will cause confusion to the attacker. If the attacker uses the authorized user's indirect identity information and the authorized user's login password to test the business system attack, after several tests, the password attempt protection mechanism of the business system will be triggered, and the authorized user's account login permission will be frozen with a high probability.

[0103] See Figure 3 , Figure 3 This is a schematic diagram of the structure of a rights management system provided by an embodiment of the present application. Figure 3 As shown, the rights management system 30 includes: a network device 31 and a business system 32 .

[0104] The network device 31 is used to receive a permission granting trigger request from the permission granting terminal, and send the first identifier of the permission granting terminal, the second identifier of the permission granted terminal, and the permission granting identifier to the business system 32 .

[0105] The business system 32 is used to: receive the first identifier, the second identifier and the permission granting identifier from the network device 31, and determine the first system account of the permission granter based on the first identifier, and determine the second system account of the permission grantee based on the second identifier, and grant the second system account permission to use the first system account based on the permission granting identifier.

[0106] In the rights management system of the embodiment of the present application, after receiving a rights granting trigger request from the rights granting terminal, the network device 31 can send the first identifier of the rights granting terminal, the second identifier of the rights granting terminal, and the rights granting identifier to the business system 32, so that the business system 32 can determine the first system account of the rights granting terminal based on the first identifier, determine the second system account of the rights granting terminal based on the second identifier, and grant the second system account the right to use the first system account based on the rights granting identifier. In this way, the communication function of the mobile communication system can be utilized to remotely control the business system with the help of the network device to grant rights, thereby eliminating the need to log in to the business system for rights management, thereby flexibly granting rights to the business system.

[0107] Optionally, the permission grant trigger request includes: the second identifier and the permission grant identifier; the network device 31 is further used to: determine the first identifier according to the wireless channel corresponding to the permission grant trigger request.

[0108] Optionally, the network device 31 is further configured to determine the business system according to the receiving port address of the permission grant trigger request.

[0109] Optionally, the permission granting trigger request includes: the system login password of the permission granter;

[0110] The business system 32 is also used to: receive the system login password from the network device 31; authenticate the identity of the authority granter based on the first system account and the system login password; when the identity authentication of the authority granter is successful, grant the second system account the authority to use the first system account based on the authority granting identifier.

[0111] Optionally, the permission grant trigger request includes: permission grant time;

[0112] The business system 32 is further configured to: receive the permission granting time from the network device 31; and cancel the permission of the second system account to use the first system account when the time during which the second system account uses the permission of the first system account reaches the permission granting time.

[0113] Optionally, the network device 31 is configured to: receive a permission cancellation trigger request from a terminal of a permission grantor, and send a first identifier, a second identifier, and a permission cancellation identifier to the business system;

[0114] The business system 32 is used to: receive the first identifier, the second identifier and the permission cancellation identifier from the network device 31; determine the first system account of the permission grantor based on the first identifier, and determine the second system account of the permission grantee based on the second identifier; and cancel the permission of the second system account to use the first system account based on the permission granting identifier.

[0115] It is understandable that the rights management system 30 of the embodiment of the present application can achieve the above Figure 1 The various processes of the method embodiment shown can achieve the same technical effect, and to avoid repetition, they will not be described again here.

[0116] See Figure 4 , Figure 4 This is a schematic diagram of the structure of a rights management device provided by an embodiment of the present application. The method is applied to a business system, such as Figure 4 As shown, the rights management device 40 includes:

[0117] A receiving module 41 is configured to receive a first identifier of an authority grantor, a second identifier of an authority grantee, and an authority granting identifier from a network device; wherein the first identifier, the second identifier, and the authority granting identifier are sent by the network device after receiving an authority granting trigger request from the terminal of the authority grantor;

[0118] a parsing module 42, configured to determine a first system account of the authority granter based on the first identifier, and to determine a second system account of the authority granted based on the second identifier;

[0119] The authority management module 43 is configured to grant the second system account the authority to use the first system account according to the authority granting identifier.

[0120] Optionally, the permission grant trigger request includes: the second identifier and the permission grant identifier; the first identifier is determined by the network device according to the wireless channel corresponding to the permission grant trigger request.

[0121] Optionally, the receiving port address of the permission grant trigger request corresponds to the business system.

[0122] Optionally, the permission granting trigger request includes: the system login password of the permission granter;

[0123] The receiving module 41 is further configured to: receive the system login password from the network device;

[0124] The authority management module 43 is further configured to authenticate the authority grantor based on the first system account and system login password; and when the authority grantor's identity authentication is successful, grant the second system account the authority to use the first system account based on the authority granting identifier.

[0125] Optionally, the permission grant trigger request includes: permission grant time;

[0126] The receiving module 41 is further configured to: receive the permission granting time from the network device;

[0127] The authority management module 43 is further configured to cancel the authority of the second system account to use the first system account when the time for the second system account to use the authority of the first system account reaches the authority granting time.

[0128] Optionally, the receiving module 41 is further configured to: receive the first identifier, the second identifier, and the permission cancellation identifier from the network device; wherein the first identifier, the second identifier, and the permission cancellation identifier are sent by the network device after receiving the permission cancellation trigger request from the terminal of the permission grantor;

[0129] The parsing module 42 is configured to: determine a first system account of the authority granter based on the first identifier, and determine a second system account of the authority granted based on the second identifier;

[0130] The authority management module 43 is further configured to cancel the authority of the second system account to use the first system account according to the authority cancellation identifier.

[0131] It is understandable that the rights management device 40 of the embodiment of the present application can achieve the above Figure 1 The various processes of the method embodiment shown can achieve the same technical effect, and to avoid repetition, they will not be described again here.

[0132] In addition, if Figure 5 As shown, an embodiment of the present application also provides a business system, including a processor 51, a memory 52, and a program or instruction stored in the memory 52 and executable on the processor 51. When the program or instruction is executed by the processor 51, each process of the above-mentioned permission management method embodiment is implemented, and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.

[0133] An embodiment of the present application also provides a computer-readable storage medium on which a program or instruction is stored. When the program or instruction is executed by a processor, the various processes of the above-mentioned permission management method embodiment can be implemented and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.

[0134] Computer-readable media includes both permanent and non-permanent, removable and non-removable media, and can be implemented using any method or technology for information storage. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change RAM (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media, such as modulated data signals and carrier waves.

[0135] It should be noted that, in this document, the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or apparatus comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or apparatus comprising the element.

[0136] The serial numbers of the above embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.

[0137] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus the necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes a number of instructions for enabling a service classification device (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in each embodiment of the present application.

[0138] The above is only a preferred embodiment of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present application. These improvements and modifications should also be regarded as the scope of protection of the present application.

Claims

1. A rights management method, applied to a business system, characterized in that: include: Receiving from a base station a first identifier of an authority granter, a second identifier of an authority grantee, and an authority granting identifier; wherein the first identifier, the second identifier, and the authority granting identifier are sent by the base station after receiving an authority granting trigger request from a terminal of the authority granter; the authority granting identifier is used to instruct the service system to grant the authority granted to the authority granter to use the authority granter; Determine a first system account of the authority granter according to the first identifier, and determine a second system account of the authority granted according to the second identifier; According to the permission granting identifier, the second system account is granted permission to use the first system account.

2. The method according to claim 1, characterized in that The permission grant trigger request includes: the second identifier and the permission grant identifier; The first identifier is determined by the base station according to the wireless channel corresponding to the authority grant trigger request.

3. The method according to claim 1, characterized in that The receiving port address of the permission grant trigger request corresponds to the business system.

4. The method according to claim 1, wherein The permission granting trigger request includes: the system login password of the permission granter; The method further comprises: receiving the system login password from the base station; authenticating the permission grantor based on the first system account and the system login password; The step of granting the second system account permission to use the first system account according to the permission granting identifier includes: When the identity authentication of the authority granter is successful, the second system account is granted the authority to use the first system account according to the authority granting identifier.

5. The method according to claim 1, wherein The permission grant trigger request includes: permission grant time; The method further comprises: receiving the authority granting time from the base station; After granting the second system account permission to use the first system account according to the permission granting identifier, the method further includes: When the time for the second system account to use the permission of the first system account reaches the permission granting time, the permission of the second system account to use the first system account is revoked.

6. The method according to claim 1, characterized in that The method further comprises: Receiving the first identifier, the second identifier, and the permission cancellation identifier from the base station; wherein the first identifier, the second identifier, and the permission cancellation identifier are sent by the base station after receiving the permission cancellation trigger request from the terminal of the permission grantor; Determining a first system account of the authority grantor according to the first identifier, and determining a second system account of the authority granted according to the second identifier; The permission of the second system account to use the first system account is revoked according to the permission revocation identifier.

7. A rights management system, characterized in that: include: Base stations and service systems; The base station is configured to: receive a permission granting trigger request from a terminal of a permission grantor, and send a first identifier of the permission grantor, a second identifier of the permission grantee, and a permission granting identifier to the service system; the permission granting identifier is configured to instruct the service system to grant the permission grantee to use the permission of the permission grantor; The business system is used to: receive the first identifier, the second identifier and the authority granting identifier from the base station; determine the first system account of the authority granter based on the first identifier, and determine the second system account of the authority granted based on the second identifier; and grant the second system account authority to use the first system account based on the authority granting identifier.

8. The system according to claim 7, characterized in that The permission grant trigger request includes: the second identifier and the permission grant identifier; The base station is further configured to determine the first identifier according to a wireless channel corresponding to the authority grant trigger request.

9. The system according to claim 7, wherein: The base station is further configured to determine the service system according to the receiving port address of the authority grant trigger request.

10. The system according to claim 7, wherein: The permission granting trigger request includes: the system login password of the permission granter; The business system is also used to: receive the system login password from the base station; authenticate the identity of the authority granter based on the first system account and the system login password; when the identity authentication of the authority granter is successful, grant the second system account the authority to use the first system account based on the authority granting identifier.

11. The system according to claim 7, wherein: The permission grant trigger request includes: permission grant time; The service system is further configured to: receive the permission granting time from the base station; and cancel the permission of the second system account to use the first system account when the time during which the second system account uses the permission of the first system account reaches the permission granting time.

12. The system according to claim 7, wherein: The base station is configured to: receive a permission cancellation trigger request from the terminal of the permission grantor, and send the first identifier, the second identifier, and a permission cancellation identifier to the service system; The service system is configured to: receive the first identifier, the second identifier, and the permission cancellation identifier from the base station; Determining a first system account of the authority grantor according to the first identifier, and determining a second system account of the authority granted according to the second identifier; The permission of the second system account to use the first system account is revoked according to the permission granting identifier.

13. A rights management device, applied to a business system, characterized in that: include: A receiving module, configured to receive from a base station a first identifier of an authority grantor, a second identifier of an authority grantee, and an authority granting identifier; wherein the first identifier, the second identifier, and the authority granting identifier are sent by the base station after receiving an authority granting trigger request from the terminal of the authority grantor; and the authority granting identifier is used to instruct the service system to grant the authority granted to the authority grantor to use the authority grantor; a parsing module, configured to determine a first system account of the authority granter based on the first identifier, and to determine a second system account of the authority granted based on the second identifier; The authority management module is used to grant the second system account the authority to use the first system account according to the authority granting identifier.

14. A business system, characterized in that: The method comprises a processor, a memory, and a program or instruction stored in the memory and executable on the processor, wherein the program or instruction, when executed by the processor, implements the steps of the rights management method according to any one of claims 1 to 6.

15. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a program or instruction, and when the program or instruction is executed by the processor, the steps of the rights management method according to any one of claims 1 to 6 are implemented.

Citation Information

Patent Citations

  • Account management method, system and device and storage medium

    CN110992186A