A method for optimizing permissions in cross-domain access of industrial Internet

By obtaining user cross-domain access information and dynamic permission adjustments in the industrial Internet, the problem of long cross-domain access time is solved, access efficiency is improved and security is ensured.

CN118555090BActive Publication Date: 2025-08-19BEIJING TONGTECH CO LTD +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410473371.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-04-19
Publication Date
2025-08-19
Estimated Expiration
2044-04-19

AI Technical Summary

Technical Problem

In the industrial Internet, there is a complex permission management during cross-domain access, which leads to long access time and inability to achieve cross-domain access in time, which is inefficient.

Method used

By obtaining user cross-domain access information, performing user behavior analysis, and dynamic permission adjustment of the permission policy model in combination with industrial Internet status information to optimize cross-domain access control.

Benefits of technology

It realizes cross-domain access in a short time, improves cross-domain access efficiency, and ensures the security of data exchange and resource sharing between different domains.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118555090B_ABST
    Figure CN118555090B_ABST
Patent Text Reader

Abstract

The present invention provides a method for optimizing permissions during cross-domain access on the industrial internet, comprising: obtaining user cross-domain access information; performing user behavior analysis on the cross-domain access information to obtain user behavior information; dynamically adjusting permissions on a permission policy model based on the user behavior information and industrial internet status information to obtain a dynamically adjusted permission policy model; and implementing cross-domain access to an access target based on the user cross-domain access information based on the dynamically adjusted permission policy model. The method for optimizing permissions during cross-domain access on the industrial internet proposed by the present invention optimizes cross-domain access control through dynamic permission adjustment, enabling cross-domain access to be achieved in a shorter time and improving cross-domain access efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of industrial Internet, and in particular to a method for optimizing permissions during cross-domain access of the industrial Internet. Background Art

[0002] The Industrial Internet (IIoT) is a new type of infrastructure, application model, and industrial ecology that deeply integrates the new generation of information and communication technology with the industrial economy. By comprehensively connecting people, machines, objects, and systems, it builds a new manufacturing and service system covering the entire industrial chain and the entire value chain, providing a way to achieve the digitalization, networking, and intelligent development of industry and even the industry. In the IIoT, each management domain can achieve the security of data resources within a single domain. For the interaction between information in different domains, the security of cross-domain information interaction and data sharing is usually improved through permissions. However, the permission management of data exchange and resource sharing between different domains is complex. When performing cross-domain access, cross-domain access usually takes a long time, and access and access results cannot be obtained in time, resulting in low cross-domain access efficiency. Therefore, the present invention proposes a method for optimizing permissions in cross-domain access of the Industrial Internet. By dynamically adjusting permissions, cross-domain access control is optimized, so that cross-domain access can be achieved in a shorter time and cross-domain access efficiency is improved. Summary of the Invention

[0003] The purpose of the present invention is to provide a method for optimizing permissions in cross-domain access of the industrial Internet to solve the problems raised in the above background technology.

[0004] To achieve the above objectives, the present invention provides the following technical solution: a method for optimizing permissions in cross-domain access on the industrial Internet, comprising:

[0005] Obtain user cross-domain access information;

[0006] Conduct user behavior analysis on user cross-domain access information to obtain user behavior information;

[0007] The user behavior information is combined with the industrial Internet status information to dynamically adjust the permission policy model to obtain a dynamically adjusted permission policy model;

[0008] Based on the dynamic adjustment of the permission policy model, cross-domain access is achieved according to the user's cross-domain access information and the access target.

[0009] Furthermore, the permission policy model is pre-analyzed and constructed for the Industrial Internet, including:

[0010] Analyze the domain structure of the Industrial Internet and determine the domains that make up the Industrial Internet;

[0011] Analyze the permission requirements and access targets of the domains that make up the Industrial Internet, determine the relationships between the domains that make up the Industrial Internet, and the requirements for data interaction and resource sharing, and obtain the results of the Industrial Internet permission requirement analysis;

[0012] According to the results of the industrial Internet permission demand analysis, a permission policy model is established for the industrial Internet to obtain the permission policy model of the industrial Internet.

[0013] Furthermore, when obtaining user cross-domain access information, synchronous monitoring is performed on the user end in the Industrial Internet, including:

[0014] Conduct real-time monitoring on the user side and obtain user side monitoring information;

[0015] Analyze and determine whether there is user cross-domain access information in the user-side monitoring information, and obtain a first analysis and determination result;

[0016] When user cross-domain access information exists in the user-side monitoring information according to the first analysis and judgment result, the user cross-domain access information is extracted, and integrity analysis and judgment is performed on the user cross-domain access information to obtain a second analysis and judgment result;

[0017] When the second analysis determines that the user cross-domain access information is incomplete, the user cross-domain access information is continued to be extracted based on the user-side monitoring information, and the extracted user cross-domain access information is merged, and then the integrity analysis is performed on the merged user cross-domain access information until the user cross-domain access information is complete. The merged user cross-domain access information is used as the final user cross-domain access information obtained.

[0018] Furthermore, user behavior analysis is performed on user cross-domain access information, including:

[0019] Identify the source of user cross-domain access information and obtain user feature information;

[0020] Judging based on user feature information, determining whether the user is a valid user in the industrial Internet, and obtaining a user judgment result;

[0021] When the user determines that the user is a valid user in the industrial Internet, the user cross-domain access information is standardized to obtain the standardized user cross-domain access information;

[0022] In the standardized user cross-domain access information, access target identification and access requirement identification are performed respectively to obtain the access target and access requirement;

[0023] Analyze access requirements and obtain target access resources.

[0024] Furthermore, when dynamically adjusting the permission policy model by combining user behavior information with industrial Internet status information, the current status information of the industrial Internet is obtained, the current application scenario of the industrial Internet is determined, and the current status change information of the industrial Internet is analyzed. Then, the first dynamic permission adjustment is performed on the permission policy model based on the current status change information of the industrial Internet to obtain a first dynamic permission adjustment permission policy model. Then, based on the first dynamic permission adjustment permission policy model, a second dynamic permission adjustment is performed according to the user behavior information to obtain a second dynamic permission adjustment permission policy model.

[0025] Furthermore, when analyzing the current state change information of the industrial Internet, the current application scenario of the industrial Internet is compared with the initial state of the industrial Internet, the part of the industrial Internet where information changes occur is analyzed, and the part of the industrial Internet where information changes occur is filtered out to obtain the change information in the industrial Internet. Then, the industrial Internet component domain association combination is performed for the change information in the industrial Internet to obtain the current state change information of the industrial Internet.

[0026] Furthermore, when performing a first dynamic permission adjustment on the permission policy model according to the current state change information of the industrial Internet, it includes:

[0027] Match the industrial Internet component domains in the authority policy model based on the current state change information of the industrial Internet, and determine the valid industrial Internet component domains in the authority policy model;

[0028] Perform preliminary screening and adjustment on the permission policy model according to the effective industrial Internet component domain in the permission policy model to obtain a first screening and adjustment permission policy model;

[0029] Combined with the current status change information of the industrial Internet, a correlation analysis is performed on the first screening and adjustment permission policy model to determine whether there is an independent industrial Internet component domain in the first screening and adjustment permission policy model, and the first screening and adjustment permission policy model is adjusted again based on the analysis and judgment results to obtain the first dynamic permission adjustment permission policy model.

[0030] Furthermore, performing a second dynamic permission adjustment based on the first dynamic permission adjustment permission policy model according to user behavior information includes:

[0031] Performing target location matching in the first dynamic permission adjustment permission policy model according to the access target to determine the target location;

[0032] Determine the associated industrial Internet component domain based on the target location, and obtain the target area of the first dynamic permission adjustment permission policy model;

[0033] In the first dynamic permission adjustment permission policy model target area, permission granting, permission revocation and permission level adjustment are performed in combination with user feature information and target access resources to obtain the first dynamic permission adjustment permission policy model target area after permission adjustment;

[0034] A second dynamic permission adjustment permission policy model is obtained according to the target area of the first dynamic permission adjustment permission policy model.

[0035] Furthermore, based on the dynamically adjusted permission policy model, cross-domain access is achieved for the access target according to the user's cross-domain access information, including:

[0036] Perform user authentication for user cross-domain access information and obtain authentication results;

[0037] When the user authentication is passed, access behavior monitoring is started according to the authentication result;

[0038] Based on the dynamic adjustment permission policy model, access permission verification is performed on the user's cross-domain access information, and cross-domain access control is performed on the user's cross-domain access information after the access permission verification is passed.

[0039] Furthermore, when cross-domain access control is performed on the user's cross-domain access information after the access permission verification is passed, the permission level is determined for the user's cross-domain access information in the dynamically adjusted permission policy model to obtain the permission level of the user's cross-domain access information. Then, it is analyzed whether the user's cross-domain access information has priority permission. When the user's cross-domain access information has priority permission, the target information is accessed in the access target in priority within the permission level of the user's cross-domain access information, and the response information of the user's cross-domain access information is obtained. When the user's cross-domain access information does not have priority permission, the user's cross-domain access information is imported into the waiting response queue of the permission level of the user's cross-domain access information, and the target information is accessed in the access target in accordance with the waiting response queue of the permission level.

[0040] The present invention optimizes cross-domain access control through dynamic permission adjustment, so that when users perform cross-domain access, the time of cross-domain access is reduced, the access results are obtained in a shorter time, and the efficiency of cross-domain access is improved. Moreover, when performing dynamic permission adjustment, user behavior information is combined with industrial Internet status information, so that the dynamic adjustment permission policy model is more adapted to the current status of the industrial Internet. This not only ensures that the industrial Internet can perform cross-domain information interaction and data sharing in a timely manner, but also ensures the security of data exchange and resource sharing between different domains.

[0041] Other features and advantages of the present invention will be described in the following description, and in part will become apparent from the description, or will be understood by practicing the present invention. The purposes and other advantages of the present invention can be realized and obtained by the structures particularly pointed out in the written description, claims, and drawings.

[0042] The technical solution of the present invention is further described in detail below through the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] The accompanying drawings are used to provide a further understanding of the present invention and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation of the present invention. In the accompanying drawings:

[0044] Figure 1 A schematic diagram of the steps of a method for optimizing permissions in cross-domain access to the industrial Internet according to the present invention;

[0045] Figure 2 A schematic diagram of the steps for constructing a permission policy model in a method for optimizing permissions in cross-domain access to the industrial Internet according to the present invention;

[0046] Figure 3 This is a flow chart of step 1 in a method for optimizing permissions in cross-domain access on the industrial Internet according to the present invention;

[0047] Figure 4 This is a schematic diagram of step 2 in the method for optimizing permissions in cross-domain access on the industrial Internet according to the present invention;

[0048] Figure 5 This is a schematic diagram of the first dynamic permission adjustment step in step three of the method for optimizing permissions in cross-domain access on the industrial Internet according to the present invention;

[0049] Figure 6 This is a schematic diagram of the second dynamic permission adjustment step in step three of the method for optimizing permissions in cross-domain access to the industrial Internet described in the present invention. DETAILED DESCRIPTION

[0050] The preferred embodiments of the present invention are described below with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present invention, and are not used to limit the present invention.

[0051] like Figure 1 As shown, an embodiment of the present invention provides a method for optimizing permissions in cross-domain access on the industrial Internet, including:

[0052] Step 1: Obtain user cross-domain access information;

[0053] Step 2: Perform user behavior analysis on user cross-domain access information to obtain user behavior information;

[0054] Step 3: Dynamically adjust the permission policy model by combining user behavior information with industrial Internet status information to obtain a dynamically adjusted permission policy model;

[0055] Step 4: Implement cross-domain access for access targets based on the user's cross-domain access information based on the dynamically adjusted permission policy model.

[0056] In the above technical solution, the permission policy model is a permission policy model pre-built for the industrial Internet.

[0057] In the above technical solution, industrial Internet status information refers to the current status change information of the industrial Internet.

[0058] In the above technical solution, when cross-domain access is achieved for the access target based on the user cross-domain access information based on the dynamically adjusted authority policy model, cross-domain access control is executed for the user cross-domain access information according to the dynamically adjusted authority policy model.

[0059] The above technical solution optimizes cross-domain access control through dynamic permission adjustment, which reduces the time of cross-domain access when users conduct cross-domain access, obtains access results in a shorter time, and improves the efficiency of cross-domain access. Moreover, when performing dynamic permission adjustment, user behavior information is combined with industrial Internet status information, so that the dynamic adjustment permission policy model is more adapted to the current status of the industrial Internet. It can not only ensure that the industrial Internet can conduct cross-domain information interaction and data sharing in a timely manner, but also ensure the security of data exchange and resource sharing between different domains.

[0060] like Figure 2 As shown, in one embodiment provided by the present invention, the permission policy model is pre-analyzed and constructed for the Industrial Internet, including:

[0061] S1. Analyze the domain structure of the Industrial Internet and determine the domains that make up the Industrial Internet;

[0062] S2. Analyze the permission requirements and access targets for the domains that make up the Industrial Internet, determine the relationships between the domains that make up the Industrial Internet, and the requirements for data interaction and resource sharing, and obtain the results of the Industrial Internet permission requirement analysis;

[0063] S3. Establish a permission policy model for the industrial Internet based on the results of the industrial Internet permission demand analysis to obtain the permission policy model of the industrial Internet.

[0064] In the above technical solution, when analyzing the permission requirements and access targets of the industrial Internet component domains, the industrial Internet component domains are analyzed in turn to obtain the access targets and data interaction and resource sharing requirements of each industrial Internet component domain.

[0065] In the above technical solution, when analyzing the domain composition of the industrial Internet, the structure of the industrial Internet is clarified and the domains that make up the industrial Internet are determined.

[0066] In the above technical solution, when establishing a permission policy model for the Industrial Internet based on the results of the Industrial Internet permission demand analysis, it includes:

[0067] Establish a domain architecture for the Industrial Internet and obtain the Industrial Internet domain framework;

[0068] In the industrial Internet domain framework, permissions are set for the industrial Internet component domains to obtain a first processing industrial Internet domain framework;

[0069] Based on the first processing industrial Internet domain framework, the permission inheritance relationship is limited to obtain the permission policy model of the industrial Internet.

[0070] The above technical solution constructs a permission policy model by analyzing the industrial Internet, so that users can directly perform cross-domain access based on the permission policy model when performing cross-domain access, providing convenience for users' cross-domain access. Moreover, the permission policy model is obtained by analyzing the domain composition, permission requirements and access targets of the industrial Internet, making the permission policy model highly consistent with the industrial Internet, avoiding the mismatch between the permission policy model and the industrial Internet, resulting in inaccessibility of the industrial Internet component domains.

[0071] like Figure 3 As shown, in one embodiment provided by the present invention, when obtaining user cross-domain access information, synchronous monitoring is performed on the user terminal in the industrial Internet, including:

[0072] Conduct real-time monitoring on the user side and obtain user side monitoring information;

[0073] Analyze and determine whether there is user cross-domain access information in the user-side monitoring information, and obtain a first analysis and determination result;

[0074] When user cross-domain access information exists in the user-side monitoring information according to the first analysis and judgment result, the user cross-domain access information is extracted, and integrity analysis and judgment is performed on the user cross-domain access information to obtain a second analysis and judgment result;

[0075] When the second analysis determines that the user cross-domain access information is incomplete, the user cross-domain access information is continued to be extracted based on the user-side monitoring information, and the extracted user cross-domain access information is merged, and then the integrity analysis is performed on the merged user cross-domain access information until the user cross-domain access information is complete. The merged user cross-domain access information is used as the final user cross-domain access information obtained.

[0076] In the above technical solution, the number of user terminals is not unique.

[0077] In the above technical solution, when the second analysis and judgment result is that the user cross-domain access information is complete, the user cross-domain access information at this time is the user cross-domain access information finally obtained.

[0078] The above technical solution monitors the user end so that it can respond in a timely manner when the user end sends user cross-domain access information, reducing the time waste caused by the untimely discovery of user cross-domain access information. Moreover, by performing integrity analysis and judgment on user cross-domain access information, user behavior analysis based on incomplete user cross-domain access information is avoided, thereby improving the effectiveness of user cross-domain access information for user behavior analysis and providing a guarantee for user behavior analysis.

[0079] like Figure 4 As shown, in one embodiment provided by the present invention, user behavior analysis is performed on user cross-domain access information, including:

[0080] B1. Identify the source of user cross-domain access information and obtain user feature information;

[0081] B2. Determine whether the user is a valid user in the Industrial Internet based on the user feature information and obtain a user determination result;

[0082] B3. When the user determines that the user is a valid user in the Industrial Internet, standardize the user's cross-domain access information to obtain standardized user cross-domain access information;

[0083] B4. Perform access target identification and access requirement identification on the standardized user cross-domain access information to obtain the access target and access requirement.

[0084] B5. Analyze access requirements and obtain target access resources.

[0085] In the above technical solution, the user characteristic information includes: user identification information, user role information, etc.

[0086] In the above technical solution, user feature information, access target, access requirements, and target access resources together constitute user behavior information.

[0087] In the above technical solution, when the user determines that the user is not a valid user in the industrial Internet, there is no need to perform any processing on the user's cross-domain access information.

[0088] In the above technical solution, when access target identification and access requirement identification are performed separately in the standardized user cross-domain access information, access requirement identification can be performed on the standardized user cross-domain access information while access target identification is performed on the standardized user cross-domain access information.

[0089] The above technical solution can clarify who sent the user's cross-domain access information by identifying the source of the user's cross-domain access information, and then ensure the security of the user's cross-domain access information by determining whether the user is a valid user in the industrial Internet, avoiding abnormal user terminals from sending user cross-domain access information for cross-domain access, and ensuring the security of industrial Internet information. Moreover, by standardizing the user's cross-domain access information, the identified user's cross-domain access information is made into a specific and unified standardized form, ensuring the access target identification and access requirement identification. At the same time, it can also reduce the errors in access target identification and access requirement identification, and improve the accuracy of access targets and access requirements.

[0090] In one embodiment provided by the present invention, when dynamically adjusting the permission policy model by combining user behavior information with industrial Internet status information, current status information of the industrial Internet is obtained, the current application scenario of the industrial Internet is determined, and the current status change information of the industrial Internet is analyzed. Then, a first dynamic permission adjustment is performed on the permission policy model based on the current status change information of the industrial Internet to obtain a first dynamic permission adjustment permission policy model. Then, a second dynamic permission adjustment is performed based on the user behavior information based on the first dynamic permission adjustment permission policy model to obtain a second dynamic permission adjustment permission policy model.

[0091] In the above technical solution, the second dynamic permission adjustment permission policy model is the final dynamic adjustment permission policy model.

[0092] In the above technical solution, the industrial Internet status information refers to the usage and environment of the industrial Internet component domains of the industrial Internet.

[0093] The above technical solution dynamically adjusts the permission policy model by combining user behavior information with industrial Internet status information, making the dynamically adjusted permission policy model more adapted to the current status of the industrial Internet, improving the flexibility of the permission policy model, and adapting to different scenarios, so as to better respond to user cross-domain access information, avoid consuming more time when responding to user cross-domain access information, and improve the cross-domain access efficiency of user cross-domain access information.

[0094] In one embodiment provided by the present invention, when analyzing the current state change information of the industrial Internet, the current application scenario of the industrial Internet is compared with the initial state of the industrial Internet, the part where information changes in the industrial Internet are analyzed, and the part where information changes in the industrial Internet are filtered out to obtain the change information in the industrial Internet, and then the industrial Internet component domain association combination is performed for the change information in the industrial Internet to obtain the current state change information of the industrial Internet.

[0095] In the above technical solution, the initial state of the industrial Internet is the complete composition structure and environmental information of the industrial Internet.

[0096] In the above technical solution, when the industrial Internet component domains are associated and combined with the change information in the industrial Internet, the change information in the industrial Internet is integrated into the industrial Internet component domains, and the industrial Internet component domains are associated to obtain a complete set of process application scenarios.

[0097] The above technical solution analyzes the current status change information of the industrial Internet so that the dynamic permission adjustment permission policy model only involves valid information in the current application scenario of the industrial Internet, reduces the redundancy of irrelevant information, and improves the adaptability of the dynamic permission adjustment permission policy model to the current status of the industrial Internet, thereby making it more efficient to implement cross-domain access to the access target based on the user's cross-domain access information based on the dynamic adjustment permission policy model.

[0098] like Figure 5 As shown, in one embodiment provided by the present invention, when performing a first dynamic permission adjustment on the permission policy model according to the current state change information of the industrial Internet, it includes:

[0099] C1. Match the Industrial Internet component domains in the permission policy model based on the current state change information of the Industrial Internet, and determine the valid Industrial Internet component domains in the permission policy model;

[0100] C2. Perform preliminary screening and adjustment on the permission policy model based on the valid industrial Internet component domains in the permission policy model to obtain a first screening and adjustment permission policy model;

[0101] C3. Combined with the current status change information of the industrial Internet, a correlation analysis is performed on the first screening and adjustment permission policy model to determine whether there is an independent industrial Internet component domain in the first screening and adjustment permission policy model, and the first screening and adjustment permission policy model is adjusted again according to the analysis and judgment results to obtain the first dynamic permission adjustment permission policy model.

[0102] In the above technical solution, an independent industrial Internet component domain refers to an industrial Internet component domain that does not have cross-domain information interaction or data sharing with other industrial Internet component domains.

[0103] In the above technical solution, when the first screening adjustment authority policy model is readjusted according to the analysis and judgment results, if there is no independent industrial Internet component domain in the authority policy model, there is no need to make further adjustments; if there is an independent industrial Internet component domain in the authority policy model, the independent industrial Internet component domain in the first screening adjustment authority policy model will be eliminated.

[0104] The above technical solution makes a first dynamic permission adjustment for the permission policy model according to the current state change information of the industrial Internet, so that the first dynamic permission adjustment permission policy model is adapted to the current application scenario of the industrial Internet, so that the first dynamic permission adjustment permission policy model only contains the part related to the current application scenario of the industrial Internet, reducing the redundancy and interference of irrelevant information. It can not only reduce the error probability of cross-domain access based on the dynamic adjustment permission policy model, but also reduce the consumption of response time, improve the efficiency of cross-domain access based on the dynamic adjustment permission policy model, and by judging whether there is an independent industrial Internet component domain in the first screening adjustment permission policy model, optimize the first screening adjustment permission policy model, reduce the redundancy of invalid information, and simplify the first dynamic permission adjustment permission policy model.

[0105] like Figure 6 As shown, in one embodiment provided by the present invention, a second dynamic permission adjustment is performed based on the first dynamic permission adjustment permission policy model according to user behavior information, including:

[0106] D1. Match the target location in the first dynamic permission adjustment permission policy model according to the access target to determine the target location;

[0107] D2. Determine the associated industrial Internet component domain based on the target location and obtain the target area of the first dynamic permission adjustment permission policy model;

[0108] D3. In the first dynamic permission adjustment permission policy model target area, permission granting, permission revocation, and permission level adjustment are performed in combination with user feature information and target access resources to obtain the first dynamic permission adjustment permission policy model target area after permission adjustment;

[0109] D4. Obtain a second dynamic permission adjustment permission policy model according to the target area of the first dynamic permission adjustment permission policy model.

[0110] The above technical solution further optimizes the first dynamic permission adjustment permission policy model by performing a second dynamic permission adjustment based on user behavior information, so that the second dynamic permission adjustment permission policy model matches the user behavior, thereby enabling the second dynamic permission adjustment permission policy model to better perform cross-domain access control for the corresponding user behavior.

[0111] In one embodiment of the present invention, cross-domain access is implemented for an access target based on user cross-domain access information based on a dynamically adjusted permission policy model, including:

[0112] Perform user authentication for user cross-domain access information and obtain authentication results;

[0113] When the user authentication is passed, access behavior monitoring is started according to the authentication result;

[0114] Based on the dynamic adjustment permission policy model, access permission verification is performed on the user's cross-domain access information, and cross-domain access control is performed on the user's cross-domain access information after the access permission verification is passed.

[0115] In the above technical solution, when the user identity authentication is passed according to the identity authentication result, after the access behavior monitoring is started, the access behavior monitoring information obtained from the access behavior monitoring is stored according to the user's cross-domain access information.

[0116] In the above technical solution, when the identity authentication result is that the user identity authentication fails, an abnormal prompt is given for the user's cross-domain access information.

[0117] In the above technical solution, when performing access permission verification for user cross-domain access information based on the dynamically adjusted permission policy model, it is determined whether the user corresponding to the user cross-domain access information has permission in the access target, thereby obtaining the access permission verification result.

[0118] The above technical solution performs user identity authentication and access permission verification, so that when cross-domain access control is performed on user cross-domain access information, cross-domain access is only performed when the user cross-domain access information issued by the user who has passed the identity authentication has access permission in the access target, ensuring the security of cross-domain access, ensuring the security of interaction between information in different fields, avoiding abnormal access and leakage of information in different fields, and starting access behavior monitoring when the user identity authentication is passed according to the identity authentication result. Not only can access behavior monitoring be performed when the user identity authentication is passed, thereby improving the effectiveness of access behavior monitoring and reducing the monitoring of invalid information, but also records can be left for cross-domain access of user cross-domain access information, which is convenient for review and verification.

[0119] In one embodiment provided by the present invention, when cross-domain access control is performed on user cross-domain access information after access authority verification is passed, the permission level is determined for the user cross-domain access information in a dynamically adjusted permission policy model to obtain the permission level of the user cross-domain access information. Then, it is analyzed whether the user cross-domain access information has priority permission. When the user cross-domain access information has priority permission, the target information is accessed in the access target in priority to the user cross-domain access information in the permission level of the user cross-domain access information, and response information of the user cross-domain access information is obtained. When the user cross-domain access information does not have priority permission, the user cross-domain access information is imported into a waiting queue for response of the permission level of the user cross-domain access information, and the target information is accessed in the access target in accordance with the waiting queue for response of the permission level.

[0120] In the above technical solution, when the target information is accessed in the access target with priority for the user cross-domain access information in the permission level of the user cross-domain access information, the priority value is obtained for the user cross-domain access information that currently has priority permission, and the priority data of the current user cross-domain access information is obtained. At the same time, the pending response queue of the permission level of the user cross-domain access information is obtained, and data processing is performed on the pending response queue. The reception time of the user cross-domain access information in the pending response queue is combined with the priority permission to perform a comprehensive priority value calculation to obtain the priority data value queue of the pending response queue. Then, according to the priority data of the current user cross-domain access information, a numerical comparison is performed in the priority data value queue of the pending response queue to determine the target position of the current user cross-domain access information, and based on the target position, the user cross-domain access information with priority permission is queued in the pending response queue of the corresponding permission level.

[0121] In the above technical solution, the cross-domain access information of the user with the current priority permission is the most recently received cross-domain access information of the user.

[0122] In the above technical solution, when the comprehensive priority value is calculated by combining the reception time of the user cross-domain access information in the response queue with the priority authority, the waiting time of the user cross-domain access information is determined according to the reception time combined with the current time, and the priority level of the user cross-domain access information is determined according to the priority authority. Then, a comprehensive evaluation is performed on the waiting time of the user cross-domain access information and the priority level of the user cross-domain access information to obtain the priority data of the user cross-domain access information.

[0123] The above technical solution determines the permission level by dynamically adjusting the permission policy model for user cross-domain access information, performs access according to the permission level, and also analyzes whether the user cross-domain access information has priority permissions, so that the cross-domain access information of users with priority permissions is given priority cross-domain access, thereby improving the efficiency of cross-domain access, enabling cross-domain access to be achieved in a shorter time, and obtaining response information of the user cross-domain access information. In addition, through priority data calculation, when the user cross-domain access information is given priority in the permission level of the user cross-domain access information, when the target information is accessed in the access target, the priority permission is executed while reducing the impact on the cross-domain access information of other users in the same permission level. At the same time, it can also enable the cross-domain access information of users with multiple priority permissions in the same permission level to better access the target information.

[0124] Those skilled in the art should understand that the first and second in the present invention merely refer to different application stages.

[0125] Other embodiments of the present disclosure will readily occur to those skilled in the art after considering the specification and practicing the disclosure herein. This application is intended to cover any variations, uses, or adaptations of the present disclosure that follow from the general principles of the present disclosure and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered as exemplary only, with the true scope and spirit of the present disclosure being indicated by the following claims.

[0126] It should be understood that the present disclosure is not limited to the exact structures that have been described above and shown in the drawings, and that various modifications and changes can be made without departing from the scope thereof. The scope of the present disclosure is limited only by the appended claims.

Claims

1. A method for optimizing permissions in cross-domain access on the industrial Internet, characterized in that: include: Obtain user cross-domain access information; Conduct user behavior analysis on user cross-domain access information to obtain user behavior information; The user behavior information is combined with the industrial Internet status information to dynamically adjust the permission policy model to obtain a dynamically adjusted permission policy model; Based on the dynamic adjustment of the permission policy model, cross-domain access is achieved according to the user's cross-domain access information and the access target; Among them, when dynamically adjusting the permission policy model by combining user behavior information with industrial Internet status information, the current status information of the industrial Internet is obtained, the current application scenario of the industrial Internet is determined, and the current status change information of the industrial Internet is analyzed. Then, the first dynamic permission adjustment is made to the permission policy model based on the current status change information of the industrial Internet to obtain a first dynamic permission adjustment permission policy model. Then, based on the first dynamic permission adjustment permission policy model, a second dynamic permission adjustment is made according to the user behavior information to obtain a second dynamic permission adjustment permission policy model. Moreover, when analyzing the current status change information of the industrial Internet, the current application scenario of the industrial Internet is compared with the initial state of the industrial Internet, the part of the industrial Internet where information changes is analyzed, and the part of the industrial Internet where information changes is filtered out to obtain change information in the industrial Internet. Then, the industrial Internet component domain association combination is performed on the change information in the industrial Internet to obtain the current status change information of the industrial Internet.

2. The method according to claim 1, characterized in that The permission policy model is pre-analyzed and constructed for the Industrial Internet, and includes: Analyze the domain structure of the Industrial Internet and determine the domains that make up the Industrial Internet; Analyze the permission requirements and access targets of the domains that make up the Industrial Internet, determine the relationships between the domains that make up the Industrial Internet, and the requirements for data interaction and resource sharing, and obtain the results of the Industrial Internet permission requirement analysis; According to the results of the industrial Internet permission demand analysis, a permission policy model is established for the industrial Internet to obtain the permission policy model of the industrial Internet.

3. The method according to claim 1, characterized in that When obtaining user cross-domain access information, synchronous monitoring is performed on the user end in the Industrial Internet, including: Conduct real-time monitoring on the user side and obtain user side monitoring information; Analyze and determine whether there is user cross-domain access information in the user-side monitoring information, and obtain a first analysis and determination result; When user cross-domain access information exists in the user-side monitoring information according to the first analysis and judgment result, the user cross-domain access information is extracted, and integrity analysis and judgment is performed on the user cross-domain access information to obtain a second analysis and judgment result; When the second analysis determines that the user cross-domain access information is incomplete, the user cross-domain access information is continued to be extracted based on the user-side monitoring information, and the extracted user cross-domain access information is merged, and then the integrity analysis is performed on the merged user cross-domain access information until the user cross-domain access information is complete. The merged user cross-domain access information is used as the final user cross-domain access information obtained.

4. The method according to claim 1, wherein Conduct user behavior analysis on cross-domain access information, including: Identify the source of user cross-domain access information and obtain user feature information; Judging based on the user feature information, determining whether the user is a valid user in the industrial Internet, and obtaining a user judgment result; When the user determines that the user is a valid user in the industrial Internet, the user cross-domain access information is standardized to obtain the standardized user cross-domain access information; In the standardized user cross-domain access information, access target identification and access requirement identification are performed respectively to obtain the access target and access requirement; Analyze access requirements and obtain target access resources.

5. The method according to claim 4, characterized in that When performing the first dynamic permission adjustment for the permission policy model based on the current status change information of the Industrial Internet, it includes: Match the industrial Internet component domains in the authority policy model based on the current state change information of the industrial Internet, and determine the valid industrial Internet component domains in the authority policy model; Perform preliminary screening and adjustment on the permission policy model according to the effective industrial Internet component domain in the permission policy model to obtain a first screening and adjustment permission policy model; Combined with the current status change information of the industrial Internet, a correlation analysis is performed on the first screening and adjustment permission policy model to determine whether there is an independent industrial Internet component domain in the first screening and adjustment permission policy model, and the first screening and adjustment permission policy model is adjusted again based on the analysis and judgment results to obtain the first dynamic permission adjustment permission policy model.

6. The method according to claim 4, characterized in that Performing a second dynamic permission adjustment based on the first dynamic permission adjustment policy model and user behavior information includes: Performing target location matching in the first dynamic permission adjustment permission policy model according to the access target to determine the target location; Determine the associated industrial Internet component domain based on the target location, and obtain the target area of the first dynamic permission adjustment permission policy model; In the first dynamic permission adjustment permission policy model target area, permission granting, permission revocation and permission level adjustment are performed in combination with user feature information and target access resources to obtain the first dynamic permission adjustment permission policy model target area after permission adjustment; A second dynamic permission adjustment permission policy model is obtained according to the target area of the first dynamic permission adjustment permission policy model.

7. The method according to claim 1, characterized in that Based on the dynamically adjusted permission policy model, cross-domain access is achieved according to the user's cross-domain access information and the access target, including: Perform user authentication for user cross-domain access information and obtain authentication results; When the user authentication is passed, access behavior monitoring is started according to the authentication result; Based on the dynamic adjustment permission policy model, access rights are verified for user cross-domain access information, and cross-domain access control is performed on the user cross-domain access information after the access rights are verified.

8. The method according to claim 7, characterized in that When cross-domain access control is performed on the user's cross-domain access information after the access permission verification is passed, the permission level is determined for the user's cross-domain access information in the dynamically adjusted permission policy model to obtain the permission level of the user's cross-domain access information. Then, it is analyzed whether the user's cross-domain access information has priority permission. When the user's cross-domain access information has priority permission, the target information is accessed in the access target in priority within the permission level of the user's cross-domain access information, and the response information of the user's cross-domain access information is obtained. When the user's cross-domain access information does not have priority permission, the user's cross-domain access information is imported into the waiting response queue of the permission level of the user's cross-domain access information, and the target information is accessed in the access target in accordance with the waiting response queue of the permission level.

Citation Information

Patent Citations

  • Cross-domain collaboration method and system based on zero trust

    CN117544346A

  • Fine-grained dynamic authority control method based on operation behavior feedback

    CN117828578A