Permission Filtering Method, Device, Equipment and Medium Based on Zero Trust Gateway
A zero-trust gateway integrated with RBAC models addresses permission inconsistencies and security risks in complex business environments by enforcing uniform access control, enhancing system efficiency and security.
Patent Information
- Application Number
- CN202211670527.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-23
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2042-12-23
Smart Images

Figure CN116208364B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of computer technology, and in particular to a permission filtering method, apparatus, device and medium based on a zero-trust gateway. Background Art
[0002] In the current development of the Internet, a single system can no longer meet the business needs of users. In the same business environment, multiple business systems are interconnected to form a network system, making the relationship between systems increasingly complex.
[0003] Due to various reasons, many systems under the same business system have their own permission control system, which leads to four major problems. First, when the permissions of a user or role change, the permission control of each system needs to be modified, which greatly increases the workload and causes configuration errors and inconsistent system configurations. Second, in special cases, due to inconsistent permission controls between multiple systems, users may exceed their rights, leak information, or have poor user experience between multiple systems. Third, when calling data interfaces between systems, if the control rules between the two systems are inconsistent, additional logic is required to convert the permission control logic. At the same time, developers are required to be familiar with the permission control rules of the two systems, which increases the difficulty of system maintenance and development and is not convenient for future maintenance of the system. Fourth, the traditional permission control system will process internal requests or trust requests without verification. When attackers break into the internal system, the role of the permission control system is reduced or even invalid. Summary of the invention
[0004] In view of the above problems, the present disclosure provides a permission filtering method based on a zero-trust gateway to solve the above technical problems.
[0005] One aspect of the present disclosure provides a permission filtering method based on a zero-trust gateway, including: receiving an access request from a user, forwarding the access request to a preset permission management system, the permission management system being constructed based on a zero-trust gateway and an RBAC permission control model; identifying the user role information of the user and the permission control result of the access request based on the permission management system; forwarding the user role information and the permission control result to a target business system of the access request, so that the target business system verifies the user's access rights based on the role information and the permission control result; and when the user's access rights are verified, causing the target business system to respond to the access request.
[0006] Optionally, it includes: constructing a permission management system based on a zero-trust gateway and an RBAC permission control model, and pre-storing the operation association relationship between the user role information and the function modules of the target business system in the permission management system.
[0007] Optionally, the identifying the user role information of the user and the permission control result of the access request based on the permission management system includes: querying the user role information in the permission management system according to the user information in the access request; matching the operation association relationship with the function modules of the target business system based on the user role information to obtain the permission control result of the user.
[0008] Optionally, before querying the user role information, the method further includes: parsing the user environment, the target module of the target business system, the hardware, and the network environment according to the access request; verifying whether the user environment, the target module, the hardware, and the network environment are abnormal; and rejecting the access request when the user environment, the target module, the hardware, and the network environment are abnormal.
[0009] Optionally, it further includes: judging whether to forward the access request to the target business system according to the permission control result; when the permission control result is that the user has permission, forwarding the user role information and the permission control result to the target business system; and when the permission control result is that the user has no permission, rejecting the access request.
[0010] Optionally, forwarding the user role information and the permission control result to the target business system of the access request, so that the target business system verifies the user's access permission based on the role information and the permission control result includes: encapsulating the user role information and the permission control result into the access request; forwarding the access request to the target business system, so that the target business system parses the access request, and when the permission control result is that the user has permission, checking whether the user corresponding to the user role information has data permission; when the user corresponding to the user role information has data permission, the verification of the user's access permission passes.
[0011] Optionally, when the verification of the user's access permission passes, making the target business system respond to the access request includes: obtaining data according to the access request and transmitting it to the user to generate a rendered page.
[0012] On the other hand, the present disclosure provides a permission filtering device based on a zero-trust gateway, including: a request forwarding module, configured to receive an access request from a user and forward the access request to a preset permission management system, where the permission management system is constructed based on a zero-trust gateway and an RBAC permission control model; a permission control module, configured to identify user role information of the user and a permission control result of the access request based on the permission management system; a role verification module, configured to forward the user role information and the permission control result to a target business system of the access request, so that the target business system verifies the access permission of the user based on the role information and the permission control result; and a request response module, configured to cause the target business system to respond to the access request when the access permission of the user is verified.
[0013] Another aspect of the present disclosure provides an electronic device, including: a memory, a processor, and a computer program stored on the memory and executable on the processor, where when the processor executes the computer program, each step in the permission filtering method based on a zero-trust gateway is implemented.
[0014] Another aspect of the present disclosure provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, each step in the permission filtering method based on a zero-trust gateway is implemented.
[0015] At least one of the above technical solutions adopted in the embodiments of the present disclosure can achieve the following beneficial effects:
[0016] The present disclosure provides a permission filtering method based on a zero-trust gateway, which verifies all requests of downstream business systems in the same business system through a zero-trust gateway, and controls, processes, and filters these requests through a permission control method of an RBAC model. While ensuring the accuracy of the permission control system of downstream business systems, it also provides a set of unified standard permission control data for downstream business systems. This method increases the unity and consistency of permission data within the business system and greatly enhances the security of the business system. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] To more fully understand the present disclosure and its advantages, reference is now made to the following description taken in conjunction with the accompanying drawings, in which:
[0018] Figure 1 Schematically shows an application scenario diagram of a permission filtering method based on a zero-trust gateway provided by an embodiment of the present disclosure;
[0019] Figure 2 Schematically shows a diagram of a permission filtering method based on a zero-trust gateway provided by an embodiment of the present disclosure;
[0020] Figure 3 Schematically shows a structural block diagram of a permission filtering device based on a zero-trust gateway provided by an embodiment of the present disclosure;
[0021] Figure 4 Schematically shows a structural block diagram of an electronic device provided by an embodiment of the present disclosure. Detailed implementation manners
[0022] Hereinafter, embodiments of the present disclosure will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are merely exemplary and are not intended to limit the scope of the present disclosure. In the following detailed description, for the sake of explanation, many specific details are set forth to provide a thorough understanding of the embodiments of the present disclosure. However, obviously, one or more embodiments can also be implemented without these specific details. In addition, in the following description, descriptions of well-known structures and technologies are omitted to avoid unnecessarily confusing the concepts of the present disclosure.
[0023] The terms used herein are merely for describing specific embodiments and are not intended to limit the present disclosure. The terms "including", "comprising", etc. used herein indicate the presence of the described features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.
[0024] All terms (including technical and scientific terms) used herein have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification and should not be interpreted in an idealized or overly rigid manner.
[0025] Some block diagrams and / or flowcharts are shown in the accompanying drawings. It should be understood that some blocks or combinations of blocks in the block diagrams and / or flowcharts can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing devices, so that when executed by the processor, these instructions can create a device for implementing the functions / operations illustrated in these block diagrams and / or flowcharts.
[0026] Accordingly, the technology of the present disclosure can be implemented in the form of hardware and / or software (including firmware, microcode, etc.). Additionally, the technology of the present disclosure can take the form of a computer program product on a computer-readable medium storing instructions, which can be used by or in conjunction with an instruction execution system. In the context of the present disclosure, a computer-readable medium can be any medium that can contain, store, transmit, propagate, or transport instructions. For example, a computer-readable medium can include, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, components, or propagation media. Specific examples of computer-readable media include: magnetic storage devices, such as magnetic tapes or hard disk drives (HDDs); optical storage devices, such as compact discs (CD-ROMs); memories, such as random access memories (RAMs) or flash memories; and / or wired / wireless communication links.
[0027] Figure 1 FIG. schematically shows an application scenario diagram of a permission filtering method based on a zero-trust gateway provided by an embodiment of the present disclosure.
[0028] As Figure 1 shown, when there are multiple systems under a unified business system and the permissions of users and roles change, it is necessary to modify the permission control of each system, resulting in a large amount of repetitive work, high maintenance costs, inconsistent permission controls among multiple systems, differences in users' permissions in each system, the need to perform a permission control system conversion during system information interaction, leading to system redundancy, and the risk problem from the "inside" in the traditional permission system.
[0029] An embodiment of the present disclosure provides a permission filtering method based on a zero-trust gateway. This method optimizes the permission control, the logical relationship and process sequence between users and multiple application systems through the zero-trust gateway, and provides a unified permission control standard system for downstream systems, enabling the permission control to be separated as a common part from multiple application systems as an independent functional module, making each application system more focused on processing business operations, improving the processing efficiency of the application system, simplifying the processing logic of the application system, and performing unified control over permissions, facilitating the management of permissions.
[0030] Figure 2 FIG. schematically shows a diagram of a permission filtering method based on a zero-trust gateway provided by an embodiment of the present disclosure.
[0031] As Figure 2 shown, an embodiment of the present disclosure provides a permission filtering method based on a zero-trust gateway, including S210 to S240.
[0032] S210, receive a user's access request, and forward the access request to a preset permission management system, where the permission management system is constructed based on a zero-trust gateway and an RBAC permission control model.
[0033] S220. Identify the user role information of the user and the permission control result of the access request based on the permission management system.
[0034] S230. Forward the user role information and the permission control result to the target business system of the access request, so that the target business system verifies the access permission of the user based on the role information and the permission control result.
[0035] S240. When the access permission of the user is verified, cause the target business system to respond to the access request.
[0036] According to the method provided by the embodiments of the present disclosure, the information received by the zero-trust security gateway is parsed to obtain the request path and user information therein. Parse according to the request path and user information. According to the path of the request information, determine the target business system and its target module that the request needs to request. According to the permissions corresponding to each role, determine whether the request has menu-level permissions for the corresponding module, and perform a preliminary filter on the request. Attach the corresponding permission information to the request and forward it to the downstream target business system. After receiving the forwarded request, the downstream target business system parses the unified permission information attached to the request and judges whether it has the corresponding data permission information through its own business logic. Finally, each business system loads data to render the page and displays the corresponding page.
[0037] This method verifies all requests of downstream business systems in the same business system through a zero-trust gateway, controls, processes, and filters these requests through the permission control method of the RBAC model, while ensuring the accuracy of the permission control system of the downstream business system, and also provides a set of unified standard permission control data for the downstream business system.
[0038] Specifically, in the embodiments of the present disclosure, a permission management system based on a zero-trust gateway and an RBAC permission control model is pre-constructed, and the operation association relationship between the user role information and the function modules of the target business system is pre-stored in the permission management system. The zero-trust gateway technology refers to the most core part of the zero-trust architecture, which is usually deployed at the network entrance or the front end of the application service, separating users and resources, enforcing access control policies on all traffic, adopting a distrust policy for any request, and performing security checks on each request, greatly reducing the probability of system security risks. The RBAC model refers to role-based access control. Permissions are indirectly granted to users by associating users with roles and roles with permissions. The permission design of the current mainstream permission management systems is the RBAC model or a variant of the RBAC model.
[0039] When the gateway receives the user's access request, it forwards the access request to the permission management system. Before querying the user role information, the user environment, the target module of the target business system, the hardware, and the network environment can be parsed according to the access request to verify whether the user environment, the target module, the hardware, and the network environment are abnormal. When the user environment, the target module, the hardware, and the network environment are abnormal, the access request is rejected.
[0040] After confirming that the access environment is normal, according to S220, the user role information of the user and the permission control result of the access request are identified based on the permission management system. S220 includes S221 to S222.
[0041] S221, according to the user information in the access request, query the user role information in the permission management system.
[0042] In this embodiment, use the role of role to match whether the role role has the operation permission of the module moudle of the system system in the zero-trust gateway permission management system. Wait for the corresponding result Result. If there is no corresponding permission, reject this request.
[0043] S222, based on the user role information, match the operation association relationship with the function module of the target business system to obtain the user's permission control result.
[0044] According to S230, forward the user role information and the permission control result to the target business system of the access request, including S231 to S233.
[0045] S231, encapsulate the user role information and the permission control result into the access request. Before encapsulating the access request, it can be determined whether to forward the access request to the target business system according to the permission control result. When the permission control result is that there is permission, forward the user role information and the permission control result to the target business system; when the permission control result is that there is no permission, reject the access request.
[0046] S232, forward the access request to the target business system so that the target business system parses the access request. When the permission control result is that there is permission, check whether the user corresponding to the user role information has data permission.
[0047] S233, when the user corresponding to the user role information has data permission, the user's access permission verification passes. When the permission control result is that there is no permission, reject the access request.
[0048] According to S240, when the access permission of the user is verified and passed, the target business system is made to respond to the access request. Specifically, data is obtained according to the access request and transmitted to the user, and a rendered page is generated.
[0049] The method provided by the embodiments of the present disclosure isolates the user network from the system network where the application system is located through a zero-trust gateway. Using zero-trust gateway technology, access control is enforced for all requests to downstream business systems. For requests, no distinction is made between internal requests and external requests of the system, and all requests are uniformly processed. Any request adopts a distrust policy, and each request is subject to security inspection, greatly reducing the probability of system security risks occurring.
[0050] The method provided by the embodiments of the present disclosure combines the traditional RBAC model with zero-trust gateway technology, refines the traditional RBAC model, associates the permissions of roles with operations. At the same time, since the vast majority of systems on the market use the RBAC model, and zero-trust gateway technology is mainly based on PBAC. By refining the relationship between corresponding roles and modules, the problem that the traditional RBAC model has too much authority for the zero-trust gateway is solved, and the RBAC model and zero-trust gateway technology are more adapted.
[0051] Figure 3 The structural block diagram of a permission filtering device based on a zero-trust gateway provided by the embodiments of the present disclosure is schematically shown.
[0052] As Figure 3 shown, the embodiments of the present disclosure provide a permission filtering device 300 based on a zero-trust gateway, including a request forwarding module 310, a permission control module 320, a role verification module 330, and a request response module 340.
[0053] The request forwarding module 310 is configured to receive an access request of a user and forward the access request to a preset permission management system, and the permission management system is constructed based on a zero-trust gateway and an RBAC permission control model.
[0054] The permission control module 320 is configured to identify user role information of the user and a permission control result of the access request based on the permission management system.
[0055] The role verification module 330 is configured to forward the user role information and the permission control result to a target business system of the access request, so that the target business system verifies the access permission of the user based on the role information and the permission control result.
[0056] The request response module 340 is configured to make the target business system respond to the access request when the access permission of the user is verified and passed.
[0057] It is understandable that the request forwarding module 310, the permission control module 320, the role verification module 330, and the request response module 340 can be implemented in one module, or any one of them can be split into multiple modules. Or, at least part of the functions of one or more of these modules can be combined with at least part of the functions of other modules and implemented in one module. According to an embodiment of the present invention, at least one of the request forwarding module 310, the permission control module 320, the role verification module 330, and the request response module 340 can be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on chip, a system on a substrate, a system on a package, an application specific integrated circuit (ASIC), or can be implemented in any other reasonable way of integrating or packaging circuits, etc., in hardware or firmware, or in an appropriate combination of software, hardware, and firmware. Or, at least one of the request forwarding module 310, the permission control module 320, the role verification module 330, and the request response module 340 can be at least partially implemented as a computer program module, which can execute the functions of the corresponding module when the program is run on a computer.
[0058] Figure 4 Schematically shows a block diagram of an electronic device provided by an embodiment of the present disclosure.
[0059] As Figure 4 shown, the electronic device described in this embodiment includes: The electronic device 400 includes a processor 410 and a computer-readable storage medium 420. The electronic device 400 can execute the method described above with reference to Figure 1 to implement the detection of specific operations.
[0060] Specifically, the processor 410 can include, for example, a general microprocessor, an instruction set processor, and / or a related chipset, and / or a dedicated microprocessor (e.g., an application specific integrated circuit (ASIC)), etc. The processor 410 can also include on-board memory for caching purposes. The processor 410 can be a single processing unit or multiple processing units for executing different actions of the method flow according to the embodiment of the present disclosure described with reference to Figure 1 above.
[0061] A computer-readable storage medium 420 can be, for example, any medium capable of containing, storing, transmitting, propagating, or transporting instructions. For example, the readable storage medium may include, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, components, or propagation media. Specific examples of the readable storage medium include: magnetic storage devices such as magnetic tapes or hard disk drives (HDDs); optical storage devices such as compact discs (CD-ROMs); memories such as random access memories (RAMs) or flash memories; and / or wired / wireless communication links.
[0062] The computer-readable storage medium 420 may include a computer program 421, which may include code / computer-executable instructions that, when executed by the processor 410, cause the processor 410 to perform, for example, the method flows and any variations thereof described above in connection with Figure 1 those described.
[0063] The computer program 421 may be configured to have computer program code that includes, for example, computer program modules. For example, in an exemplary embodiment, the code in the computer program 421 may include one or more program modules, such as module 42lA, module 42lB,.... It should be noted that the way of dividing the modules and the number of modules are not fixed, and those skilled in the art can use appropriate program modules or combinations of program modules according to the actual situation. When these combinations of program modules are executed by the processor 410, the processor 410 can perform, for example, the method flows and any variations thereof described above in connection with Figures 1 - 2 those described.
[0064] According to an embodiment of the present invention, at least one of the request forwarding module 410, the permission control module 420, the role verification module 430, and the request response module 440 may be implemented as a computer program module as referred to in Figure 4 the description, which, when executed by the processor 410, can implement the corresponding operations described above.
[0065] The present disclosure also provides a computer-readable medium, which may be included in the device / apparatus / system described in the above embodiments; or may exist separately without being assembled into the device / apparatus / system. The above computer-readable medium carries one or more programs that, when the one or more programs are executed, implement the method according to the embodiments of the present disclosure.
[0066] Those skilled in the art will understand that the features recited in the various embodiments and / or claims of the present disclosure can be combined or / and combined in various ways, even if such combinations or combinations are not explicitly recited in the present disclosure. In particular, without departing from the spirit and teachings of the present disclosure, the features recited in the various embodiments and / or claims of the present disclosure can be combined and / or combined in various ways. All such combinations and / or combinations fall within the scope of the present disclosure.
[0067] Although the present disclosure has been shown and described with reference to specific exemplary embodiments thereof, those skilled in the art should understand that various changes in form and detail may be made therein without departing from the spirit and scope of the present disclosure as defined by the appended claims and their equivalents. Therefore, the scope of the present disclosure should not be limited to the above embodiments, but should be determined not only by the appended claims, but also by the equivalents of the appended claims.
Claims
1. A permission filtering method based on a zero-trust gateway, characterized in that, Including: Receiving the access request of the user and forwarding the access request to a preset permission management system, which is constructed based on a zero-trust gateway and an RBAC permission control model; Identifying the user role information of the user and the permission control result of the access request based on the permission management system; Forwarding the user role information and the permission control result to the target business system of the access request, so that the target business system verifies the access permission of the user based on the role information and the permission control result, including: Encapsulating the user role information and the permission control result into the access request; Forwarding the access request to the target business system, so that the target business system parses the access request. When the permission control result is "authorized", checking whether the user corresponding to the user role information has data permissions; When the user corresponding to the user role information has data permissions, the access permission verification of the user passes; When the access permission verification of the user passes, causing the target business system to respond to the access request; Judging whether to forward the access request to the target business system according to the permission control result; When the permission control result is "authorized", forwarding the user role information and the permission control result to the target business system; When the permission control result is "not authorized", rejecting the access request.
2. The method according to claim 1, characterized in that Including: Constructing a permission management system based on a zero-trust gateway and an RBAC permission control model, and pre-storing the operation association relationship between the user role information and the function modules of the target business system in the permission management system.
3. The method according to claim 2, wherein The identifying the user role information of the user and the permission control result of the access request based on the permission management system includes: Querying the user role information in the permission management system according to the user information in the access request; Based on the user role information, matching the operation association relationship with the function modules of the target business system to obtain the permission control result of the user.
4. The method according to claim 3, wherein Before querying the user role information, the method further includes: According to the access request, parsing the user environment, the target module of the target business system, the hardware and the network environment; Verifying whether the user environment, the target module, the hardware and the network environment are abnormal; When the user environment, the target module, the hardware and the network environment are abnormal, rejecting the access request.
5. The method according to claim 1, characterized in that, The causing the target business system to respond to the access request when the access permission verification of the user passes includes: Obtaining data according to the access request and transmitting it to the user, and generating a rendered page.
6. A permission filtering device based on a zero-trust gateway, characterized in that, Including: A request forwarding module, configured to receive the access request of the user and forward the access request to a preset permission management system, which is constructed based on a zero-trust gateway and an RBAC permission control model; A permission control module, configured to identify the user role information of the user and the permission control result of the access request based on the permission management system; A role verification module, configured to forward the user role information and the permission control result to the target business system of the access request, so that the target business system verifies the user's access permission based on the role information and the permission control result, including: Encapsulating the user role information and the permission control result into the access request; Forwarding the access request to the target business system, so that the target business system parses the access request. When the permission control result is "authorized", check whether the user corresponding to the user role information has data permissions; When the user corresponding to the user role information has data permissions, the verification of the user's access permission passes; A request response module, configured to cause the target business system to respond to the access request when the verification of the user's access permission passes; Judge whether to forward the access request to the target business system according to the permission control result; When the permission control result is "authorized", forward the user role information and the permission control result to the target business system; When the permission control result is "not authorized", reject the access request.
7. An electronic device, comprising: A memory, a processor, and a computer program stored on the memory and executable on the processor, wherein when the processor executes the computer program, each step in the permission filtering method based on a zero-trust gateway according to any one of claims 1 to 5 is implemented.
8. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, each step in the permission filtering method based on a zero-trust gateway according to any one of claims 1 to 5 is implemented.
Citation Information
Patent Citations
Authority management method, management server, service server and readable storage medium
CN112926068A
Access control method and device
CN115017484A