A service authentication management system

By implementing identity authentication, key pair generation and token verification, service analysis report generation, and permission adjustment, this system addresses the data security deficiencies in existing service authentication systems, enabling precise access control and data protection for authorized users.

CN118568782BActive Publication Date: 2026-03-27HENAN CLEAN ENERGY BRANCH OF HUANENG INT POWER CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-05-06
Publication Date
2026-03-27

AI Technical Summary

Technical Problem

Existing service authentication systems are ill-equipped to handle complex network environments and cannot ensure that only authorized users can access specific services, resulting in insufficient data security.

Method used

The identity authentication module obtains access requests and generates access permissions, the verification module generates key pairs and performs token verification, the request analysis module analyzes access logs and historical log databases to generate service analysis reports, and the adjustment module adjusts the fixed parameters of access permissions based on the reports to ensure that only authorized users can access specific services.

Benefits of technology

It improves the security and efficiency of service authentication management, ensuring that only authorized users can access specific services and protecting data security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118568782B_ABST
    Figure CN118568782B_ABST
Patent Text Reader

Abstract

The application provides a service authentication management system, and relates to the field of service authentication management, and comprises the following steps: obtaining an access request, performing identity authentication, and generating corresponding access permissions for the access request that passes the identity authentication; generating a corresponding key pair based on all access permissions corresponding to the access request and performing Token verification; obtaining a corresponding service analysis report based on the access log of the access request after the Token verification and a historical log database; and obtaining corresponding adjustment parameters based on the service analysis report and adjusting the fixed parameters in the access permission process. Only authorized users can access specific services, and the data of the services to be accessed is ensured to be safe.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of service authentication management, and more particularly to a service authentication management system. Background Technology

[0002] Currently, with an increasing amount of sensitive information and data being transmitted over the network, protecting the security of this information has become particularly important. Service authentication systems ensure that only authorized users can access specific services or resources, thereby preventing unauthorized access and potential security threats. Service authentication systems typically use a variety of technologies for authentication and authorization, including cryptographic algorithms, digital certificates, and two-factor authentication, but these are insufficient to cope with the increasingly complex network environment.

[0003] Therefore, the present invention provides a service authentication management system. Summary of the Invention

[0004] This invention provides a service authentication management system that performs identity authentication upon receiving access requests, generates corresponding access permissions for successfully authenticated access requests, analyzes all access permissions corresponding to the access requests, generates corresponding key pairs, and performs token verification. Furthermore, by analyzing access logs and historical log databases of access requests that have passed token verification, a corresponding service analysis report is obtained. Based on the service analysis report, corresponding adjustment parameters are derived, and fixed parameters are adjusted to ensure that only authorized users can access specific services, thereby guaranteeing the security of the data in the services to be accessed.

[0005] This invention provides a service authentication management system, comprising:

[0006] Identity authentication module: Receives access requests, performs identity authentication, and generates corresponding access permissions for access requests that pass authentication;

[0007] Verification module: Based on the full access permissions corresponding to the access request, generate a corresponding key pair and perform token verification;

[0008] Request Analysis Module: Based on access logs of access requests verified by Token and the historical log database, it generates corresponding service analysis reports;

[0009] Adjustment module: Based on the service analysis report, obtain the corresponding adjustment parameters and adjust the fixed parameters in the process of granting access permissions.

[0010] Preferably, the present invention provides a service authentication management system, including an identity authentication module, comprising:

[0011] Identity Parameter Acquisition Unit: Acquires the access request and obtains the corresponding identity parameters;

[0012] Identity analysis unit: Based on the identity parameters, obtain the corresponding service ID and identity source;

[0013] Identity Permission Acquisition Unit: If the identity source is within the allowed source database, then acquire the ID permission database;

[0014] Identity authentication unit: If the service ID is in the ID permission database, then the identity authentication is successful.

[0015] Preferably, the present invention provides a service authentication management system, a verification module, comprising:

[0016] Service sequence construction unit: Based on all access permissions corresponding to the access request, construct the corresponding service sequence;

[0017] Key selection unit: randomly selects a service key based on the key database corresponding to each service type in the service sequence;

[0018] First key sequence building block: Based on all service keys randomly selected under the service sequence, arrange them in order to construct the first key sequence;

[0019] Second key sequence construction block: Randomly arrange the service keys in the first key sequence to construct a second key sequence;

[0020] Key pair acquisition unit: Constructs a key pair based on the first key sequence and the second key sequence.

[0021] Preferably, the present invention provides a service authentication management system, including a request analysis module, comprising:

[0022] Log analysis unit: Based on the access logs of access requests verified by the token, obtain all accessed first services and the access time corresponding to each first service;

[0023] Second service acquisition unit: Extract access times that exceed a preset time and obtain the corresponding second service;

[0024] The first data acquisition unit: Based on the number of times each second service is accessed in the historical log database, the first data is obtained;

[0025] First filtering unit: Remove the second service corresponding to the first number that is less than the preset number of accesses;

[0026] Access parameter acquisition unit: Based on the retained second service and the historical log database, obtain the access parameters of each second service in each access log;

[0027] Access table construction unit: Based on the access parameters of each second service, construct the service access table according to the order of the access log;

[0028] First parameter acquisition unit: Based on the service access table corresponding to each pair of second services, obtain the first parameter corresponding to each pair of second services in the access logs in the same order;

[0029] The first number acquisition unit: Based on the number of times the first parameter is 1 among all the first parameters, the second number is obtained;

[0030] First probability acquisition unit: Based on the second number and the total number of access logs in the historical log database, the first probability is obtained;

[0031] Service combination acquisition unit: If the first probability is greater than the preset probability, then the two corresponding second services are obtained as a service combination;

[0032] Occurrence count acquisition unit: Based on all service combinations, obtain the occurrence count of each second service;

[0033] First combination acquisition unit: Extract the third service that appears more than once, merge all service combinations corresponding to the third service to obtain the first combination;

[0034] Confidence Calculation Unit: Based on all first combinations, service combinations that do not contain third services, and the historical log database, calculate the first confidence level corresponding to every two services in each combination;

[0035] Index Calculation Unit: Based on all first services of access requests after token verification, the corresponding access time, the first confidence level, and the corresponding associated services, calculate the corresponding request association index;

[0036] Report building unit: If the request correlation index is greater than the preset correlation index, a service analysis report is built based on the first confidence level in the access request and the corresponding first service.

[0037] Preferably, the present invention provides a service authentication management system and an index calculation unit.

[0038] ;in, This represents the request correlation index of access requests that have passed token verification. Indicates the total number of all primary services in the access request; This indicates the total number of all associated services in the access request; This indicates the first of all related services in the access request. The first change factor corresponding to the function of each associated service; This indicates the first of all related services in the access request. The first preset factor for the function corresponding to each associated service; This indicates that among all related services of the access request, the one related to the first... Each associated service has a second variable factor in the functionality of the associated services; This indicates that among all related services of the access request, the one related to the first... Each associated service has a second preset factor for the functions of the associated services; This indicates the first of all related services in the access request. The first confidence level of each associated service and the associated related services; This indicates the first of all related services in the access request. Access time of each associated service; This indicates that among all related services of the access request, the one related to the first... The access time of each associated service; Indicates the first in the access request The third factor in the change of the first service's functionality; Indicates the first in the access request The third preset factor for the first service function; Indicates the first in the access request The first service access time.

[0039] Preferably, the present invention provides a service authentication management system, an identity authentication module, which further includes:

[0040] Service database acquisition unit: Based on the service ID of the authenticated access request, obtain the corresponding identity-service database;

[0041] Service type acquisition unit: acquires the service name of the access request and obtains the corresponding service type;

[0042] Service Analysis Unit: Based on all service types and the identity-service database, it obtains a first set of services of the same type and a second set of services of different types;

[0043] First association analysis unit: Based on each service type in the second service set, obtain the corresponding first association type;

[0044] Third service set acquisition unit: Based on the first association type and the identity-service database, obtain a third service set with the same service type;

[0045] Permission matching unit: Based on the first service set, the third service set, and the service permission database, it matches the corresponding service permissions.

[0046] Preferably, the present invention provides a service authentication management system, a verification module, which further includes:

[0047] Token information matching unit: If each key of the key pair is in the key pair database, then a key in the key pair is randomly selected and matched with the corresponding token information.

[0048] Token verification unit: Inputs the token information into the token verification model to obtain the corresponding verification report.

[0049] Preferably, the present invention provides a service authentication management system, which, after the verification module, further includes:

[0050] Signal sending unit: If the verification report is passed, the corresponding Token information is matched with the corresponding service to be called, and an authentication signal is sent to the service to be called;

[0051] Authorization list acquisition unit: After receiving the authentication signal, the service to be invoked obtains the corresponding list of authorized services;

[0052] Authentication report acquisition unit: Based on the Token information and the list of authorized services, an authentication report is obtained;

[0053] Authentication Failure Handling Unit: If there is a service that failed authentication in the authentication report, the corresponding authentication report and Token information will be sent to the Qingzhou Authentication Center.

[0054] Compared with existing technologies, the beneficial effects of this application are as follows: by obtaining access requests, performing identity authentication, and generating corresponding access permissions for access requests that have passed identity authentication, analyzing all access permissions corresponding to the access requests, generating corresponding key pairs and performing token verification; furthermore, by analyzing the access logs of access requests that have passed token verification and the historical log database, a corresponding service analysis report is obtained, and according to the service analysis report, corresponding adjustment parameters are obtained, and fixed parameters are adjusted to ensure that only authorized users can access specific services, thus guaranteeing the security of the data of the services to be accessed.

[0055] Other features and advantages of the invention will be set forth in the following description, and will be apparent in part from the description, or may be learned by practicing the invention. The objects and other advantages of the invention may be realized and obtained by means of the structures particularly pointed out in the written description and the accompanying drawings.

[0056] The technical solution of the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. Attached Figure Description

[0057] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0058] Figure 1 This is a schematic diagram of the structure of a service authentication management system provided in an embodiment of the present invention. Detailed Implementation

[0059] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.

[0060] Example 1:

[0061] This invention provides a service authentication management system, such as... Figure 1 As shown, it includes:

[0062] Identity authentication module: Receives access requests, performs identity authentication, and generates corresponding access permissions for access requests that pass authentication;

[0063] Verification module: Based on the full access permissions corresponding to the access request, generate a corresponding key pair and perform token verification;

[0064] Request Analysis Module: Based on access logs of access requests verified by Token and the historical log database, it generates corresponding service analysis reports;

[0065] Adjustment module: Based on the service analysis report, obtain the corresponding adjustment parameters and adjust the fixed parameters in the process of granting access permissions.

[0066] In this embodiment, the access request refers to the received request to access the service and implement the service function, which includes the accessed service and the user's information.

[0067] In this embodiment, access permissions refer to the permissions granted to access the service obtained by analyzing access requests that have passed authentication.

[0068] In this embodiment, the key pair refers to the data security obtained by analyzing the access permissions corresponding to the access request.

[0069] In this embodiment, token verification refers to first verifying the correctness of the key pair; after verification, token information is obtained from the database to check the security of the access request.

[0070] In this embodiment, the access log refers to the services accessed and invoked by the user after the access request has been verified, as well as the time of access.

[0071] In this embodiment, the historical log database refers to the access logs of historical access requests.

[0072] In this embodiment, the service analysis report refers to the report obtained by analyzing the access logs and historical log database of the access request after token verification, which includes the relationship between services.

[0073] In this embodiment, adjusting parameters refers to analyzing the service analysis report to determine the degree of correlation between services that allow for adjustments to the granting of access permissions, and adjusting the permissions of two related services to make their permissions interdependent.

[0074] In this embodiment, the fixed parameters refer to the database used in the process of granting access permissions for each service.

[0075] The working principle and beneficial effects of the above technical solution are as follows: by acquiring access requests, performing identity authentication, and generating corresponding access permissions for access requests that have passed identity authentication, analyzing all access permissions corresponding to the access requests, generating corresponding key pairs and performing token verification; furthermore, by analyzing the access logs of access requests that have passed token verification and the historical log database, a corresponding service analysis report is obtained, and according to the service analysis report, corresponding adjustment parameters are obtained, and fixed parameters are adjusted to ensure that only authorized users can access specific services, thus guaranteeing the security of the data of the services to be accessed.

[0076] Example 2:

[0077] According to the system provided in Embodiment 1 of the invention, the identity authentication module includes:

[0078] Identity Parameter Acquisition Unit: Acquires the access request and obtains the corresponding identity parameters;

[0079] Identity analysis unit: Based on the identity parameters, obtain the corresponding service ID and identity source;

[0080] Identity Permission Acquisition Unit: If the identity source is within the allowed source database, then acquire the ID permission database;

[0081] Identity authentication unit: If the service ID is in the ID permission database, then the identity authentication is successful.

[0082] In this embodiment, the identity parameter refers to the user's identity information in the access request, including: the user's identity name and the user's source IP address.

[0083] In this embodiment, the service ID refers to the code of the identity name in the identity parameters.

[0084] In this embodiment, the source of identity refers to the IP address from which the user originated.

[0085] In this embodiment, the allowed source database refers to the database of source IP addresses that are allowed to be accessed.

[0086] In this embodiment, the ID permission database refers to the code in the name of the user who is allowed access.

[0087] The working principle and beneficial effects of the above technical solution are as follows: by analyzing the identity parameters in the access request, identity authentication is performed, thereby ensuring the security of the environment in which users call services and preventing data leakage from the source.

[0088] Example 3:

[0089] According to the system provided in Embodiment 1 of the invention, the verification module includes:

[0090] Service sequence construction unit: Based on all access permissions corresponding to the access request, construct the corresponding service sequence;

[0091] Key selection unit: randomly selects a service key based on the key database corresponding to each service type in the service sequence;

[0092] First key sequence building block: Based on all service keys randomly selected under the service sequence, arrange them in order to construct the first key sequence;

[0093] Second key sequence construction block: Randomly arrange the service keys in the first key sequence to construct a second key sequence;

[0094] Key pair acquisition unit: Constructs a key pair based on the first key sequence and the second key sequence.

[0095] In this embodiment, the service sequence refers to the sequence obtained by randomly arranging all access permissions corresponding to the access request.

[0096] In this embodiment, the service type refers to the type of service that needs to be invoked for each access permission in the service sequence, and the service type is determined by the content of the webpage being accessed.

[0097] In this embodiment, the key database refers to a database that contains service types and their corresponding keys.

[0098] In this embodiment, the service key refers to the key that matches the service type in the key database.

[0099] In this embodiment, the first key sequence refers to the sequence constructed by arranging the service keys corresponding to the service sequence in order.

[0100] In this embodiment, the second key sequence refers to the sequence constructed by randomly arranging the service keys in the key sequence.

[0101] The working principle and beneficial effects of the above technical solution are as follows: by analyzing all access permissions corresponding to the access request, a corresponding key pair is generated, thereby enhancing the security of the key and ensuring the security of service data.

[0102] Example 4:

[0103] According to the system provided in Embodiment 1 of the invention, the request analysis module includes:

[0104] Log analysis unit: Based on the access logs of access requests verified by the token, obtain all accessed first services and the access time corresponding to each first service;

[0105] Second service acquisition unit: Extract access times that exceed a preset time and obtain the corresponding second service;

[0106] The first data acquisition unit: Based on the number of times each second service is accessed in the historical log database, the first data is obtained;

[0107] First filtering unit: Remove the second service corresponding to the first number that is less than the preset number of accesses;

[0108] Access parameter acquisition unit: Based on the retained second service and the historical log database, obtain the access parameters of each second service in each access log;

[0109] Access table construction unit: Based on the access parameters of each second service, construct the service access table according to the order of the access log;

[0110] First parameter acquisition unit: Based on the service access table corresponding to each pair of second services, obtain the first parameter corresponding to each pair of second services in the access logs in the same order;

[0111] The first number acquisition unit: Based on the number of times the first parameter is 1 among all the first parameters, the second number is obtained;

[0112] First probability acquisition unit: Based on the second number and the total number of access logs in the historical log database, the first probability is obtained;

[0113] Service combination acquisition unit: If the first probability is greater than the preset probability, then the two corresponding second services are obtained as a service combination;

[0114] Occurrence count acquisition unit: Based on all service combinations, obtain the occurrence count of each second service;

[0115] First combination acquisition unit: Extract the third service that appears more than once, merge all service combinations corresponding to the third service to obtain the first combination;

[0116] Confidence Calculation Unit: Based on all first combinations, service combinations that do not contain third services, and the historical log database, calculate the first confidence level corresponding to every two services in each combination;

[0117] Index Calculation Unit: Based on all first services of access requests after token verification, the corresponding access time, the first confidence level, and the corresponding associated services, calculate the corresponding request association index;

[0118] Report building unit: If the request correlation index is greater than the preset correlation index, a service analysis report is built based on the first confidence level in the access request and the corresponding first service.

[0119] In this embodiment, the first service refers to the service invoked in the access log of the access request after token verification.

[0120] In this embodiment, the access time refers to the time when the service is invoked in the access log of the access request after token verification.

[0121] In this embodiment, the preset time refers to the time when a service with analytical value is accessed or invoked in advance.

[0122] In this embodiment, the second service refers to the first service corresponding to an access time that is longer than a preset time.

[0123] In this embodiment, the first number refers to the number of times each second service is accessed in the historical log database.

[0124] In this embodiment, the preset access count refers to the number of times a second service with analytical value is called in the historical log database.

[0125] In this embodiment, the access parameter refers to the parameter assigned to whether a service is accessed, wherein the parameter for an accessed service is 1, and the parameter for an unaccessed service is 0.

[0126] In this embodiment, the service access table refers to a table constructed by taking all the access parameters of the second service and following the order of the access logs, which indicates whether the second service has been accessed in each access log.

[0127] In this embodiment, the first parameter refers to the access parameter in the access log of the same order in the service access table corresponding to each of the two second services.

[0128] In this embodiment, the second number refers to the number of times the first parameter is 1 out of all the first parameters.

[0129] In this embodiment, the first probability refers to the ratio of the second number to the total number of access logs in the historical log database.

[0130] In this embodiment, the preset probability refers to the probability that is pre-set to indicate a relationship between two second services.

[0131] In this embodiment, the service combination refers to two second services corresponding to a first probability greater than a preset probability.

[0132] In this embodiment, the occurrence count refers to the number of times each second service appears in the entire service combination.

[0133] In this embodiment, the third service refers to the second service that appears more than once.

[0134] In this embodiment, the first combination refers to the combination of services obtained by merging all service combinations corresponding to the third service and removing duplicate third services.

[0135] In this embodiment, the first confidence level refers to the degree of association between related services, which is obtained by calculating the number of times each pair of services in the entire first combination and service combination that does not contain a third service are accessed simultaneously in the historical log database.

[0136] In this embodiment, the associated service refers to the associated service that exists among all the first services and corresponds to the first confidence level.

[0137] In this embodiment, the request association index refers to the index of the importance of the associated service in this access request among all services.

[0138] In this embodiment, the preset association index refers to a pre-set index of the importance of associated services in access requests among all services.

[0139] The working principle and beneficial effects of the above technical solution are as follows: By analyzing the access logs and historical log database of access requests after token verification, the associated services in this access request are analyzed to obtain corresponding service analysis reports. This is beneficial for adjusting and updating the permission database in the subsequent process of granting access permissions, improving the efficiency of service authentication management, and ensuring the security of service authentication.

[0140] Example 5:

[0141] According to the system provided in Embodiment 4 of the invention, the index calculation unit includes:

[0142] ;in, This represents the request correlation index of access requests that have passed token verification. Indicates the total number of all primary services in the access request; This indicates the total number of all associated services in the access request; This indicates the first of all related services in the access request. The first change factor corresponding to the function of each associated service; This indicates the first of all related services in the access request. The first preset factor for the function corresponding to each associated service; This indicates that among all related services of the access request, the one related to the first... Each associated service has a second variable factor in the functionality of the associated services; This indicates that among all related services of the access request, the one related to the first... Each associated service has a second preset factor for the functions of the associated services; This indicates the first of all related services in the access request. The first confidence level of each associated service and the associated related services; This indicates the first of all related services in the access request. Access time of each associated service; This indicates that among all related services of the access request, the one related to the first... The access time of each associated service; Indicates the first in the access request The third factor in the change of the first service's functionality; Indicates the first in the access request The third preset factor for the first service function; Indicates the first in the access request The first service access time.

[0143] In this embodiment, the first change factor refers to the first of all related services in the access request. The numerical changes in parameters of a related service before and after access.

[0144] In this embodiment, the first preset factor refers to the first of all associated services in a pre-set access request. The numerical changes in parameters of a related service before and after access.

[0145] In this embodiment, the second change factor refers to the service associated with the access request that is related to the first one. The changes in parameters of related services before and after access.

[0146] In this embodiment, the second preset factor refers to the pre-set factor among all associated services of the access request that is related to the first one. The changes in parameters of related services before and after access.

[0147] In this embodiment, the third change factor refers to the first change factor in the access request. The numerical changes in parameters of the first service function before and after access.

[0148] In this embodiment, the third preset factor refers to the first preset factor in the access request. The numerical changes in parameters of the first service function before and after access.

[0149] The working principle and beneficial effects of the above technical solution are as follows: by analyzing and calculating all first services, corresponding access times, first confidence levels, and corresponding associated services of access requests after token verification, the corresponding request association index is obtained, which accurately represents the importance of associated services in access requests. This helps to accurately determine whether the permission database needs to be adjusted and updated during the process of granting access permissions, thereby improving the efficiency of service authentication management.

[0150] Example 6:

[0151] According to the system provided in Embodiment 1 of the invention, the identity authentication module further includes:

[0152] Service database acquisition unit: Based on the service ID of the authenticated access request, obtain the corresponding identity-service database;

[0153] Service type acquisition unit: acquires the service name of the access request and obtains the corresponding service type;

[0154] Service Analysis Unit: Based on all service types and the identity-service database, it obtains a first set of services of the same type and a second set of services of different types;

[0155] First association analysis unit: Based on each service type in the second service set, obtain the corresponding first association type;

[0156] Third service set acquisition unit: Based on the first association type and the identity-service database, obtain a third service set with the same service type;

[0157] Permission matching unit: Based on the first service set, the third service set, and the service permission database, it matches the corresponding service permissions.

[0158] In this embodiment, the identity-service database refers to the database of services corresponding to each service ID.

[0159] In this embodiment, the first service set refers to the set of service types that have the same service type in the identity-service database, obtained by analyzing the service types corresponding to the same service ID and the identity-service database.

[0160] In this embodiment, the second service set refers to the set of service types that cannot have the same service type in the identity-service database, obtained by analyzing the service types corresponding to the same service ID and the identity-service database.

[0161] In this embodiment, the first association type refers to the associated service type corresponding to each service type in the second service set.

[0162] In this embodiment, the third service set refers to the set of service types that have the same service type in the identity-service database, obtained by analyzing the first association type and the identity-service database.

[0163] In this embodiment, the service permission database refers to a database containing the service permissions corresponding to each service type.

[0164] The working principle and beneficial effects of the above technical solution are as follows: by generating corresponding access permissions for access requests that have not passed identity authentication, it ensures that as many services as possible are matched with reasonable service permissions, thereby improving the efficiency of service authentication management.

[0165] Example 7:

[0166] According to the system provided in Embodiment 1 of the invention, the verification module further includes:

[0167] Token information matching unit: If each key of the key pair is in the key pair database, then a key in the key pair is randomly selected and matched with the corresponding token information.

[0168] Token verification unit: Inputs the token information into the token verification model to obtain the corresponding verification report.

[0169] In this embodiment, the key pair database refers to a database containing all secure key pairs.

[0170] In this embodiment, Token information refers to code information in a format that can be input into the Token verification model by matching a key in a randomly obtained key pair.

[0171] In this embodiment, the Token verification model refers to a model trained using Token information and the corresponding verification report.

[0172] In this embodiment, the inspection report refers to a report that includes whether the security inspection results corresponding to each part of the Token information have passed.

[0173] The working principle and beneficial effects of the above technical solution are as follows: by analyzing the key pair, performing token verification, checking the security of service permissions, and ensuring the security of the data of the service to be accessed.

[0174] Example 8:

[0175] According to the system provided in Embodiment 7 of the invention, after the verification module, it further includes:

[0176] Signal sending unit: If the verification report is passed, the corresponding Token information is matched with the corresponding service to be called, and an authentication signal is sent to the service to be called;

[0177] Authorization list acquisition unit: After receiving the authentication signal, the service to be invoked obtains the corresponding list of authorized services;

[0178] Authentication report acquisition unit: Based on the Token information and the list of authorized services, an authentication report is obtained;

[0179] Authentication Failure Handling Unit: If there is a service that failed authentication in the authentication report, the corresponding authentication report and Token information will be sent to the Qingzhou Authentication Center.

[0180] In this embodiment, the service to be invoked refers to the service that is to be invoked and accessed, which is matched with the Token information corresponding to the passed verification report.

[0181] In this embodiment, the authentication signal refers to a signal sent to the service to be invoked to obtain a list of authorized services for the service to be invoked.

[0182] In this embodiment, the authorized service list refers to the list of authorized services to be invoked.

[0183] In this embodiment, the authentication report refers to a report on whether the authentication permissions are the same by comparing the token information with the list of authorized services.

[0184] In this embodiment, the Lightboat Authentication Center refers to the data center used for service authentication management.

[0185] The working principle and beneficial effects of the above technical solution are as follows: by re-authenticating the service permissions of the Token information, the security of the data of the service to be accessed is guaranteed, and the efficiency of service authentication management is improved.

[0186] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A service authentication management system characterized by comprising: Comprise: Identity authentication module: obtain access request, identity authentication, and generate corresponding access rights for identity authentication access request; Verification module: based on the access request corresponding to all access rights, generate the corresponding key pair and Token verification; Request analysis module: based on the access log and historical log database of the access request after Token verification, get the corresponding service analysis report; The request analysis module comprises: log analysis unit: based on the access log of the access request after Token verification, get all the first services and the access time corresponding to each first service; second service acquisition unit: extract the access time greater than the preset time to get the corresponding second service; first number acquisition unit: based on the number of times each second service is accessed in the historical log database, get the first number; first screening unit: remove the second service corresponding to the first number less than the preset access number; access parameter acquisition unit: based on the retained second service and the historical log database, get the access parameter of each second service in each access log; access table construction unit: based on the access parameter of each second service, construct a service access table according to the order of the access log; first parameter acquisition unit: based on the service access table corresponding to each two second services, get the first parameter corresponding to each two second services in the same order of access log; first number acquisition unit: based on the number of first parameters with value 1 in all first parameters, get the second number; First probability acquisition unit: based on the second number and the number of all access logs in the historical log database, get the first probability; service combination acquisition unit: if the first probability is greater than the preset probability, the corresponding two second services are obtained as the service combination; occurrence frequency acquisition unit: based on all service combinations, get the occurrence frequency of each second service; first combination acquisition unit: extract the third service with occurrence frequency greater than one, merge all service combinations corresponding to the third service to get the first combination; Confidence calculation unit: based on all first combinations, service combinations without third services, and historical log database, calculate the first confidence corresponding to each two services in each combination; index calculation unit: based on all first services of the access request after Token verification and corresponding access time, the first confidence and corresponding associated services, calculate the corresponding request association index; report construction unit: if the request association index is greater than the preset association index, construct a service analysis report based on the first confidence and corresponding first service in the access request; Adjustment module: based on the service analysis report, get the corresponding adjustment parameter, and adjust the fixed parameter in the access right granting process.

2. The system of claim 1, wherein, Identity authentication module, comprising: Identity parameter acquisition unit: obtain access request, get corresponding identity parameter; Identity analysis unit: based on the identity parameter, get the corresponding service ID and identity source; Identity permission acquisition unit: if the identity source is in the allowed source database, acquire the ID permission database; Identity authentication unit: if the service ID is in the ID permission database, the identity authentication is qualified.

3. The system of claim 1, wherein, The verification module comprises: Service sequence construction unit: based on all access permissions corresponding to the access request, construct a corresponding service sequence; Key selection unit: based on the key database corresponding to each service category in the service sequence, randomly select a service key; First key sequence construction block: based on all randomly selected service keys under the service sequence, arrange them in order to construct a first key sequence; Second key sequence construction block: randomly arrange the service keys in the first key sequence to construct a second key sequence; Key pair acquisition unit: based on the first key sequence and the second key sequence, construct a key pair.

4. The system of claim 1, wherein, an index calculation unit, ; wherein, represents a request correlation index of the access request after token verification; represents a number of all first services in the access request; represents a number of all correlation services in the access request; represents a first change factor corresponding to the function of the th correlation service among all correlation services of the access request; represents a first preset factor corresponding to the function of the th correlation service among all correlation services of the access request; represents a second change factor of the function of the correlation service associated with the th correlation service among all correlation services of the access request; represents a second preset factor of the function of the correlation service associated with the th correlation service among all correlation services of the access request; represents a first confidence degree of the th correlation service and the associated correlation service among all correlation services of the access request; represents an access time of the th correlation service among all correlation services of the access request; represents an access time of the correlation service associated with the th correlation service among all correlation services of the access request; represents a third change factor of the function of the th first service in the access request; represents a third preset factor of the function of the th first service in the access request; represents an access time of the th first service in the access request.

5. The system of claim 1, wherein, The identity authentication module further comprises: Service database acquisition unit: based on the service ID of the access request that passes the identity verification, obtain the corresponding identity-service database; Service category acquisition unit: obtain the service name of the access request to obtain the corresponding service category; Service analysis unit: based on all service categories and the identity-service database, obtain a first service set with the same category and a second service set with different categories; First association analysis unit: based on each service category in the second service set, obtain the corresponding first association category; Third service set acquisition unit: based on the first association category and the identity-service database, obtain a third service set with the same service category; Permission matching unit: based on the first service set, the third service set, and the service permission database, match the corresponding service permission.

6. The system of claim 1, wherein, The verification module further comprises: Token information matching unit: if each key of the key pair is in the key pair database, randomly acquire one key in the key pair to match the corresponding Token information; Token inspection unit: input the Token information into the Token verification model to obtain the corresponding inspection report.

7. The system of claim 6, wherein, The verification module further comprises: Signal sending unit: if the inspection report is passed, match the corresponding Token information to the to-be-called service, and send an authentication signal to the to-be-called service; Authorized list acquisition unit: after the to-be-called service receives the authentication signal, obtain the corresponding authorized service list; Authentication report acquisition unit: based on the Token information and the authorized service list, obtain the authentication report; Authentication failure processing unit: if there is an authentication failure service in the authentication report, send the corresponding authentication report and Token information to the Light Boat Authentication Center.

Citation Information

Patent Citations

  • Network system and method for realizing click to dial service based on capability open platform

    CN102148828A

  • Access request response method and device and electronic equipment

    CN111478923A