Multi-tenant rights management method and system based on APaaS platform
By using two-factor authentication and dynamic key management methods in the tenant permission management system of the APaaS platform, the problem of large permission management burden in the existing technology is solved, and a safe and efficient tenant permission management is achieved.
Patent Information
- Application Number
- CN202411226830.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-03
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2044-09-03
AI Technical Summary
The existing tenant permission management method based on APaaS platform has problems such as high application burden or high user burden, which makes it difficult to achieve an effective balance between security and user experience, resulting in poor overall effectiveness of permission management.
By responding to user login requests, the first encryption key tag is matched according to the user identity tag, login timestamp tag and service type tag, and a SMS reference verification code is generated for two-factor authentication, a second decryption key tag and a second encryption key tag are built for key verification, allowing login.
While ensuring the security of permission management, it reduces the performance, maintenance burden and user operation burden brought by traditional complex protection measures, and improves the efficiency, security and user experience of tenant permission management.
Smart Images

Figure CN119363361B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of cloud computing technology, and in particular to a multi-tenant rights management method and system based on an APaaS platform. Background Art
[0002] In the APaaS platform, multi-tenant architecture is widely used to improve resource utilization and management efficiency. However, in this multi-tenant environment, to ensure the data security and permission isolation of each tenant, existing technologies usually adopt complex protection measures, such as code obfuscation, shell protection and multi-level verification processes. Although these measures can improve the security of the system, they also bring significant application and user burdens.
[0003] At present, the existing tenant permission management methods based on APaaS platforms have the problem of heavy application burden or heavy user burden, and it is difficult to achieve an effective balance between security and user experience, resulting in technical problems such as poor overall permission management effect. Summary of the invention
[0004] The purpose of this application is to provide a multi-tenant permission management method and system based on the APaaS platform, so as to solve the technical problems that the existing tenant permission management method based on the APaaS platform has a heavy application burden or a heavy user burden, and it is difficult to achieve an effective balance between security and user experience, resulting in poor overall permission management effect.
[0005] In view of the above problems, the present application provides a multi-tenant rights management method and system based on the APaaS platform.
[0006] In the first aspect, the present application provides a multi-tenant permission management method based on an APaaS platform, which is implemented through a multi-tenant permission management system based on an APaaS platform, including: responding to a login request input into the APaaS platform user interface, wherein the login request includes a user identity tag, a login timestamp tag, a first decryption key tag and a service type tag, and the user identity tag is the legal person identity information; matching a first encryption key tag according to the user identity tag, the login timestamp tag and the service type tag, wherein the first encryption key tag has a time domain update characteristic; generating an SMS benchmark verification code, which is sent to the bound mobile phone number of the user identity tag by the operator, and receiving an SMS comparison verification code; constructing a second decryption key tag according to the SMS comparison verification code and the first decryption key tag; at the same time, constructing a second encryption key tag according to the SMS benchmark verification code and the first encryption key tag; verifying according to the second decryption key tag and the second encryption key tag to obtain a key verification result; when the key verification result is passed, allowing login.
[0007] In a second aspect, the present application further provides a multi-tenant rights management system based on an APaaS platform, which is used to execute a multi-tenant rights management method based on an APaaS platform as described in the first aspect, including: a login request response module, which is used to respond to a login request input into the APaaS platform user interface, wherein the login request includes a user identity tag, a login timestamp tag, a first decryption key tag, and a service type tag, and the user identity tag is the legal person identity information; a first encryption key tag matching module, which is used to match the first encryption key tag according to the user identity tag, the login timestamp tag, and the service type tag, wherein the first encryption key tag has a time Domain update feature; a comparison verification code receiving module, used to generate a text message benchmark verification code, and receive the text message comparison verification code sent by the operator to the bound mobile phone number of the user identity tag; a second decryption key label construction module, used to construct a second decryption key label according to the text message comparison verification code and the first decryption key label; a second encryption key label construction module, used to simultaneously construct a second encryption key label according to the text message benchmark verification code and the first encryption key label; a key verification module, used to verify according to the second decryption key label and the second encryption key label to obtain a key verification result; a login permission module, used to allow login when the key verification result is passed.
[0008] One or more technical solutions provided in this application have at least the following technical effects or advantages:
[0009] By responding to the user login request, the first encryption key tag is matched according to the user identity tag, login timestamp tag and service type tag; then a text message benchmark verification code is generated and sent to the bound mobile phone number of the user identity tag, and the text message comparison verification code is received; then according to the text message comparison verification code and the first decryption key tag, a second decryption key tag is constructed, and on the other hand, a second encryption key tag is constructed according to the text message benchmark verification code and the first encryption key tag; further verification is performed according to the second decryption key tag and the second encryption key tag to obtain a key verification result; when the key verification result is passed, the user is allowed to log in; the above method can ensure the security of permission management while reducing the performance, maintenance burden and user operation burden brought by traditional complex protection measures, and effectively improve the efficiency, security and user experience of tenant permission management.
[0010] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented according to the contents of the specification, and in order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are specifically cited below. It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present application, nor is it intended to limit the scope of the present application. Other features of the present application will become easy to understand through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] In order to more clearly illustrate the technical solutions in the present application or the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings in the following description are only exemplary, and for ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying any creative work.
[0012] Figure 1 A flowchart of a multi-tenant rights management method based on an APaaS platform is provided for this application;
[0013] Figure 2 A schematic diagram of a process for matching a first encryption key tag in a multi-tenant rights management method based on an APaaS platform in this application;
[0014] Figure 3 This is a structural diagram of a multi-tenant rights management system based on the APaaS platform for this application.
[0015] Description of reference numerals:
[0016] Login request response module 11, first encryption key label matching module 12, verification code comparison receiving module 13, second decryption key label construction module 14, second encryption key label construction module 15, key verification module 16, login permission module 17. DETAILED DESCRIPTION
[0017] This application provides a multi-tenant rights management method and system based on the APaaS platform, which solves the technical problem that the existing tenant rights management methods based on the APaaS platform have heavy application burden or heavy user burden, and it is difficult to achieve an effective balance between security and user experience, resulting in poor overall rights management effect. While ensuring the security of rights management, it can reduce the performance, maintenance burden and user operation burden brought by traditional complex protection measures, and effectively improve the efficiency, security and user experience of tenant rights management.
[0018] Below, the technical solutions in the present application will be clearly and completely described with reference to the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all of the embodiments of the present application. It should be understood that the present application is not limited to the example embodiments described herein. Based on the embodiments of the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present application. It should also be noted that, for the convenience of description, only the parts related to the present application are shown in the accompanying drawings, rather than all of them.
[0019] For example, please refer to the attached Figure 1 The present application provides a multi-tenant rights management method based on an APaaS platform, which is applied to a multi-tenant rights management system based on an APaaS platform, and specifically includes the following steps:
[0020] Step 1: Respond to a login request inputted from the APaaS platform user interface, wherein the login request includes a user identity tag, a login timestamp tag, a first decryption key tag, and a service type tag, and the user identity tag is legal person identity information.
[0021] Specifically, the APaaS platform is a cloud computing service model that provides an integrated development and deployment environment, including a series of tools, frameworks, and services for users to build, manage, and run applications on the cloud. When a user issues a login request through the user-side interface of the APaaS platform, the system responds to and processes the request, wherein the login request includes a user identity tag, a login timestamp tag, a first decryption key tag, and a service type tag; wherein the user identity tag is used to identify the user's identity, and the user identity tag is the legal person's identity information, which is represented by a unified social credit code; the login timestamp tag is used to record the specific time when the user issues the login request; the first decryption key tag is a key tag provided by the user for decrypting specific information; the service type tag is used to indicate the type of platform service that the user requests to access. Since the APaaS platform provides a variety of service functions, this tag helps the system identify and assign the specific service type requested by the user.
[0022] Step 2: Match a first encryption key tag according to the user identity tag, the login timestamp tag and the service type tag, wherein the first encryption key tag has a time domain update characteristic.
[0023] Specifically, according to the user identity tag, the login timestamp tag and the service type tag, a matching analysis is performed within the APaaS platform to determine the first encryption key tag corresponding to this information. The first encryption key tag has a time domain update feature. The time domain update feature means that the first encryption key tag will be dynamically updated according to a specific time period to ensure the security of the data and prevent the key from being used for a long time or being cracked by attackers. This dynamic update mechanism effectively improves the security and flexibility of the system by combining timestamp and key management.
[0024] Step 3: Generate a SMS reference verification code, send it to the mobile phone number bound to the user identity tag through the operator, and receive the SMS comparison verification code.
[0025] Specifically, the system generates a SMS benchmark verification code and sends it to the mobile phone number bound to the user's identity tag through the operator. After receiving the SMS benchmark verification code, the user sends the SMS comparison verification code to the system. The system receives the SMS comparison verification code entered by the user and compares it with the benchmark verification code to verify the authenticity of the user's identity. If the verification is successful, the user can continue with the subsequent operations; if the verification fails, the system will prompt the user that the input is wrong. Through the process of generating, sending, receiving and comparing SMS verification codes, a two-factor authentication mechanism is implemented, which effectively improves the security of user authority management. At the same time, through a simple SMS reception and input process, users can quickly complete identity authentication without significantly increasing the user's operating burden.
[0026] Step 4: Construct a second decryption key tag based on the SMS verification code and the first decryption key tag.
[0027] Specifically, a first position serial number is configured, and the first position serial number is used to specify the specific position where the SMS comparison verification code will be inserted into the first decryption key label, which can be set according to the actual application scenario; then based on the first position serial number, the SMS comparison verification code is inserted into a specific position in the first decryption key label to generate a second decryption key label. Since the second decryption key label combines the dynamically generated SMS comparison verification code, it has higher security and uniqueness. Therefore, by constructing the second decryption key label, the security of user authority verification can be further improved.
[0028] Step 5: At the same time, construct a second encryption key tag based on the SMS benchmark verification code and the first encryption key tag.
[0029] Specifically, on the other hand, a second position number is configured, and the second position number is used to specify the specific position where the SMS benchmark verification code will be inserted into the first encryption key tag, which can be set according to the actual application scenario; then based on the second position number, the SMS benchmark verification code is inserted into a specific position in the first encryption key tag to generate a second encryption key tag. Among them, the second encryption key tag is combined with the dynamic SMS benchmark verification code to ensure the uniqueness and security of the key during use. By combining the dynamically generated SMS verification code with the existing key tag, a new key tag is constructed, which greatly enhances the security of the system while maintaining the flexibility and adaptability of the system.
[0030] Step six: perform verification according to the second decryption key label and the second encryption key label to obtain a key verification result.
[0031] Step 7: When the key verification result is passed, login is allowed.
[0032] Specifically, the second decryption key tag and the second encryption key tag are key-verified, and a preset encryption algorithm or verification logic is used to perform matching verification. For example, hash value matching can be performed. If the hash values are consistent, it means that the two tags are corresponding in content and no tampering or error has occurred. If the second decryption key tag and the second encryption key tag match successfully, and the verification logic verification passes, the system will generate a passed key verification result, which means that all verification information provided by the user is accurate and the key generation and verification process meet the security requirements of the system; if the key tag fails to match, or an abnormality is found during the verification process, the system will generate a failed key verification result to indicate possible errors.
[0033] Finally, when the key verification result is passed, the system allows the user to log in successfully, which means that the user's identity has been verified by the system and all relevant security checks have passed. The user can continue to access resources and services within the system.
[0034] The multi-tenant rights management method based on the APaaS platform is applied to a multi-tenant rights management system based on the APaaS platform, which can solve the problem that the existing tenant rights management method based on the APaaS platform has a large application burden or a large user burden, and it is difficult to achieve an effective balance between security and user experience, resulting in a poor overall effect of rights management. By responding to the user login request, the first encryption key tag is matched according to the user identity tag, the login timestamp tag and the service type tag; then the SMS benchmark verification code is generated and sent to the bound mobile phone number of the user identity tag, and the SMS comparison verification code is received; then according to the SMS comparison verification code and the first decryption key tag, a second decryption key tag is constructed, and on the other hand, according to the SMS benchmark verification code and the first encryption key tag, a second encryption key tag is constructed; further verification is performed according to the second decryption key tag and the second encryption key tag to obtain a key verification result; when the key verification result is passed, the user is allowed to log in; through the above method, while ensuring the security of rights management, the performance, maintenance burden and user operation burden brought by traditional complex protection measures can be reduced, and the efficiency, security and user experience of tenant rights management can be effectively improved.
[0035] Further, according to the user identity tag, the login timestamp tag and the service type tag, the first encryption key tag is matched, as shown in the attached Figure 2 As shown, step 2 of this application includes:
[0036] When the encryption key of the preset user and the preset service type is configured, a first encryption key valid time zone is constructed based on the encryption key configuration timestamp and the preset encryption key update duration; when the first encryption key valid time zone ends, optimization is performed based on the asymmetric key library to obtain a key pair optimization result, wherein the key pair optimization result has an encryption key update result and a decryption key update result, and the key pair optimization result has a second encryption key valid time zone; the decryption key update result is sent to the user end of the preset service type of the preset user for decryption key update; the encryption key update result is set as the valid key of the second encryption key valid time zone; according to the login timestamp label, the valid encryption key of the user identity label and the service type label is matched and set as the first encryption key label.
[0037] Specifically, when the encryption key of the preset user and the preset service type is configured, the system generates a configuration timestamp, which records the initial configuration time of the key; configures the encryption key preset update duration, which determines the validity period of the encryption key and can be set according to the actual scenario; then, based on the encryption key configuration timestamp and the encryption key preset update duration, constructs the first encryption key valid time zone. Within this time zone, the encryption key is valid and can be used for data encryption operations.
[0038] When the effective time zone of the first encryption key ends, the system needs to update the encryption key to ensure security. Then, based on the key selection frequency and the key selection duration, the asymmetric key library is used to optimize the key pair. The optimization process will select the best key pair and obtain the key pair optimization result, wherein the optimization result includes a new encryption key update result and a corresponding decryption key update result, and the key pair optimization result has a second encryption key effective time zone. Then the system sends the generated decryption key update result to the user terminal of the preset service type of the preset user, and the user terminal will receive the new decryption key and update it to ensure that the subsequent data decryption operation can match the latest encryption key. The encryption key update result is further set as the effective key of the second encryption key effective time zone. Finally, according to the login timestamp label, the effective encryption key matching the user identity label and the service type label is set as the first encryption key label. For example, if the current timestamp is within the effective time zone of the first encryption key, the first encryption key label is used; if not, the second encryption key label is used. By dynamically updating and effectively managing encryption keys, the security and flexibility of the system under multiple users and multiple service types are ensured.
[0039] Further, when the effective time zone of the first encryption key ends, optimization is performed based on the asymmetric key library to obtain a key pair optimization result. The present application also includes the following steps:
[0040] Configure an adaptability index, wherein the adaptability index includes a selection frequency and a selection duration, wherein the selection frequency refers to the frequency with which the key pair is configured for the preset user and the preset service type, and the selection duration refers to the average of the time intervals between the key selection historical timestamp and the current timestamp; construct a fitness evaluator based on the selection frequency and the selection duration; optimize the asymmetric key library based on the fitness evaluator to obtain the key pair optimization result.
[0041] Specifically, first, configure the adaptability index, wherein the adaptability index includes the selection frequency and the selection duration, wherein the selection frequency refers to the frequency of the key pair being configured for the preset user and the preset service type, and this index measures the frequency of a certain key pair in historical use, wherein the key pair with a lower selection frequency has better security performance; the selection duration refers to the average of the time interval between the key selection historical timestamp and the current timestamp, wherein the longer the selection duration, the better the security performance of the key pair. Further, based on the selection frequency and the selection duration, construct a fitness evaluator, which is a comprehensive evaluation tool used to evaluate the adaptability of each key pair in the asymmetric key library based on the two indicators of selection frequency and selection duration.
[0042] Then, the fitness evaluator is used to evaluate the fitness of multiple preset key pairs in the asymmetric key library, and multiple fitness of multiple preset key pairs is obtained, and the preset key pair corresponding to the minimum fitness is selected as the key pair optimization result. By introducing the fitness index and the fitness evaluator, the key pair selection process is made more scientific and accurate, thereby improving the intelligence and efficiency of key management while ensuring system security.
[0043] Further, according to the selection frequency and the selection duration, a fitness evaluator is constructed, and the present application further includes the following steps:
[0044] A first coordinate axis is constructed with a normalized index of the selection frequency, and a second coordinate axis is constructed with a normalized index of the inverse of the selection duration; a two-dimensional virtual coordinate system is constructed based on the first coordinate axis and the second coordinate axis; a fitness evaluation function is constructed, wherein the fitness evaluation function is used to calculate the product of the horizontal and vertical coordinates; and the fitness evaluator is constructed based on the fitness evaluation function and the two-dimensional virtual coordinate system.
[0045] Specifically, first, the selection frequency is normalized. The purpose of normalization is to convert the selection frequency value into a standardized range (usually between 0 and 1) for comparison with other indicators; then the normalized selection frequency is used as the horizontal axis (the first coordinate axis), which represents the frequency of key pairs used in history. On the other hand, the reciprocal of the selection duration is calculated. The longer the duration, the smaller the reciprocal, reflecting the higher security of the key pair; then the reciprocal of the selection duration is normalized and converted into a standardized range between 0 and 1; then the normalized reciprocal of the selection duration is used as the vertical axis (the second coordinate axis), which represents the security indicator of the key pair's historical usage duration.
[0046] Then, the first coordinate axis and the second coordinate axis are combined to form a two-dimensional virtual coordinate system, which is used to visualize the adaptability of the key pair; then, a fitness evaluation function is constructed, which is used to calculate the product of the horizontal and vertical coordinates, that is, the fitness is obtained by calculating the product of the normalized value of the selection frequency and the reciprocal normalized value of the selection duration, wherein the smaller the fitness, the better the key pair performs in terms of security and adaptability, and thus is more suitable for priority selection. Finally, according to the fitness evaluation function and the two-dimensional virtual coordinate system, the fitness evaluator is constructed, which can visualize the position of each key pair in the two-dimensional coordinate system, and sort and filter the key pairs according to the fitness score. By visualizing the key selection process and using the fitness evaluation function to optimize the key pair selection, the accuracy and convenience of key pair optimization can be improved.
[0047] Further, before constructing the second decryption key tag based on the SMS verification code and the first decryption key tag, step 4 of the present application includes:
[0048] The login request also includes a login address tag; the SMS comparison verification code has a sending address tag; an address verification is performed based on the sending address tag and the login address tag to obtain an address verification result; when the address verification result is passed, the second decryption key tag is constructed based on the SMS comparison verification code and the first decryption key tag; when the address verification result is failed, the login request is rejected, and an address exception error is generated and displayed on the APaaS platform user interface.
[0049] Specifically, the login request also includes a login address tag, which refers to the network address information (such as IP address, geographic location, etc.) when the user initiates the login request. This tag is used to identify the source location of the login request. The system uses the login address tag to record the specific address from which the user initiated the request for subsequent security verification. The SMS verification code has a sending address tag, which refers to the network address information (such as IP address or geographic location) recorded when the system sends the SMS verification code to the user. The sending address tag is used to ensure that the operation of sending the verification code is consistent with the source of the user's actual login request.
[0050] Then, an address verification is performed based on the sending address tag and the login address tag, that is, the sending address tag and the login address tag are compared for address consistency. If the two address tags are the same, the address verification passes; if the two address tags are not the same, the address verification fails, and the address verification result is obtained. When the address verification result is passed, a second decryption key tag is constructed based on the SMS comparison verification code and the first decryption key tag; when the address verification result is not passed, the login request is rejected, and an address exception error is generated and displayed on the APaaS platform user interface. By introducing an address verification mechanism in the login process, the security of the APaaS platform is effectively improved, ensuring that login verification can only be continued when the address matches, preventing potential network attacks and deception.
[0051] Further, address verification is performed according to the sending address tag and the login address tag to obtain an address verification result. The present application further includes the following steps:
[0052] According to the user identity tag, a search is performed based on the APaaS platform database to match the registration address tag; when the registration address tag is different from the login address tag, or / and the sending address tag is different from the login address tag, the address verification result is failed; when the registration address tag is the same as the login address tag, and the sending address tag is the same as the login address tag, the address verification result is passed.
[0053] Specifically, according to the user identity tag, a search is performed based on the database of the APaaS platform to find the registration address tag corresponding to the user identity. The registration address tag usually refers to the official address information provided by the legal person user when registering. Then the obtained registration address tag is compared with the login address tag in the current login request to check whether they are consistent. When the registration address tag is different from the login address tag, or / and the sending address tag is different from the login address tag, the address verification result is failed. When the registration address tag is the same as the login address tag and the sending address tag is the same as the login address tag, the address verification result is passed.
[0054] Further, according to the SMS verification code and the first decryption key tag, a second decryption key tag is constructed. Step 4 of this application includes:
[0055] According to the SMS comparison verification code, the SMS comparison verification code is inserted into the first decryption key tag according to the first preset position sequence number to construct the second decryption key tag.
[0056] Specifically, first, configure the first preset position serial number, which is used to specify the specific position where the SMS comparison verification code will be inserted into the first decryption key label, and can be set according to the actual application scenario; then based on the first preset position serial number, insert the SMS comparison verification code into a specific position in the first decryption key label to generate a second decryption key label. By constructing the second decryption key label, the security of user authority verification can be further improved.
[0057] Further, according to the SMS benchmark verification code and the first encryption key tag, a second encryption key tag is constructed. Step five of this application includes:
[0058] According to the SMS reference verification code, the SMS reference verification code is inserted into the first encryption key tag according to a second preset position sequence number to construct the second encryption key tag.
[0059] Specifically, a second preset position number is configured, and the second preset position number is used to specify the specific position where the SMS benchmark verification code will be inserted into the first encryption key tag, which can be set according to the actual application scenario; then based on the second preset position number, the SMS benchmark verification code is inserted into a specific position in the first encryption key tag to generate a second encryption key tag. The second encryption key tag is combined with the dynamic SMS benchmark verification code to ensure the uniqueness and security of the key during use. By combining the dynamically generated SMS verification code with the existing key tag, a new key tag is constructed, which greatly enhances the security of the system while maintaining the flexibility and adaptability of the system.
[0060] In summary, the multi-tenant rights management method based on the APaaS platform provided by this application has the following technical effects:
[0061] By responding to the user login request, the first encryption key tag is matched according to the user identity tag, login timestamp tag and service type tag; then a text message benchmark verification code is generated and sent to the bound mobile phone number of the user identity tag, and the text message comparison verification code is received; then according to the text message comparison verification code and the first decryption key tag, a second decryption key tag is constructed, and on the other hand, a second encryption key tag is constructed according to the text message benchmark verification code and the first encryption key tag; further verification is performed according to the second decryption key tag and the second encryption key tag to obtain a key verification result; when the key verification result is passed, the user is allowed to log in; the above method can ensure the security of permission management while reducing the performance, maintenance burden and user operation burden brought by traditional complex protection measures, and effectively improve the efficiency, security and user experience of tenant permission management.
[0062] Embodiment 2, based on the multi-tenant rights management method based on the APaaS platform in the previous embodiment, the same inventive concept, this application also provides a multi-tenant rights management system based on the APaaS platform, please refer to the attached Figure 3 ,include:
[0063] A login request response module 11 is used to respond to a login request inputted into the user interface of the APaaS platform, wherein the login request includes a user identity tag, a login timestamp tag, a first decryption key tag and a service type tag, wherein the user identity tag is the legal person identity information; a first encryption key tag matching module 12 is used to match the first encryption key tag according to the user identity tag, the login timestamp tag and the service type tag, wherein the first encryption key tag has a time domain update characteristic; a comparison verification code receiving module 13 is used to generate an SMS benchmark verification code, and receive the SMS comparison verification code sent to the bound mobile phone number of the user identity tag by the operator; a second decryption key tag construction module 14 is used to construct a second decryption key tag according to the SMS comparison verification code and the first decryption key tag; a second encryption key tag construction module 15 is used to simultaneously construct a second encryption key tag according to the SMS benchmark verification code and the first encryption key tag; a key verification module 16 is used to verify according to the second decryption key tag and the second encryption key tag to obtain a key verification result; a login permission module 17 is used to allow login when the key verification result is passed.
[0064] Furthermore, the multi-tenant rights management system based on the APaaS platform is also used for:
[0065] The login request also includes a login address tag; the SMS comparison verification code has a sending address tag; an address verification is performed based on the sending address tag and the login address tag to obtain an address verification result; when the address verification result is passed, the second decryption key tag is constructed based on the SMS comparison verification code and the first decryption key tag; when the address verification result is failed, the login request is rejected, and an address exception error is generated and displayed on the APaaS platform user interface.
[0066] Furthermore, the multi-tenant rights management system based on the APaaS platform is also used for:
[0067] According to the user identity tag, a search is performed based on the APaaS platform database to match the registration address tag; when the registration address tag is different from the login address tag, or / and the sending address tag is different from the login address tag, the address verification result is failed; when the registration address tag is the same as the login address tag, and the sending address tag is the same as the login address tag, the address verification result is passed.
[0068] Furthermore, the multi-tenant rights management system based on the APaaS platform is also used for:
[0069] When the encryption key of the preset user and the preset service type is configured, a first encryption key valid time zone is constructed based on the encryption key configuration timestamp and the preset encryption key update duration; when the first encryption key valid time zone ends, optimization is performed based on the asymmetric key library to obtain a key pair optimization result, wherein the key pair optimization result has an encryption key update result and a decryption key update result, and the key pair optimization result has a second encryption key valid time zone; the decryption key update result is sent to the user end of the preset service type of the preset user for decryption key update; the encryption key update result is set as the valid key of the second encryption key valid time zone; according to the login timestamp label, the valid encryption key of the user identity label and the service type label is matched and set as the first encryption key label.
[0070] Furthermore, the multi-tenant rights management system based on the APaaS platform is also used for:
[0071] Configure an adaptability index, wherein the adaptability index includes a selection frequency and a selection duration, wherein the selection frequency refers to the frequency with which the key pair is configured for the preset user and the preset service type, and the selection duration refers to the average of the time intervals between the key selection historical timestamp and the current timestamp; construct a fitness evaluator based on the selection frequency and the selection duration; optimize the asymmetric key library based on the fitness evaluator to obtain the key pair optimization result.
[0072] Furthermore, the multi-tenant rights management system based on the APaaS platform is also used for:
[0073] A first coordinate axis is constructed with a normalized index of the selection frequency, and a second coordinate axis is constructed with a normalized index of the inverse of the selection duration; a two-dimensional virtual coordinate system is constructed based on the first coordinate axis and the second coordinate axis; a fitness evaluation function is constructed, wherein the fitness evaluation function is used to calculate the product of the horizontal and vertical coordinates; and the fitness evaluator is constructed based on the fitness evaluation function and the two-dimensional virtual coordinate system.
[0074] Furthermore, the multi-tenant rights management system based on the APaaS platform is also used for:
[0075] According to the SMS comparison verification code, the SMS comparison verification code is inserted into the first decryption key tag according to the first preset position sequence number to construct the second decryption key tag.
[0076] Furthermore, the multi-tenant rights management system based on the APaaS platform is also used for:
[0077] According to the SMS reference verification code, the SMS reference verification code is inserted into the first encryption key tag according to a second preset position sequence number to construct the second encryption key tag.
[0078] The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The multi-tenant permission management method based on the APaaS platform and the specific examples in the aforementioned embodiment one are also applicable to the multi-tenant permission management system based on the APaaS platform in this embodiment. Through the aforementioned detailed description of the multi-tenant permission management method based on the APaaS platform, those skilled in the art can clearly understand the multi-tenant permission management system based on the APaaS platform in this embodiment, so for the sake of brevity of the specification, it will not be described in detail here. For the system disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the method description.
[0079] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present application. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application will not be limited to the embodiments shown herein, but will conform to the widest scope consistent with the principles and novel features disclosed herein.
[0080] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application belong to the scope of the present application and its equivalent technology, the present application is also intended to include these modifications and variations.
Claims
1. A multi-tenant rights management method based on the APaaS platform, characterized in that: include: Responding to a login request inputted from the APaaS platform user interface, wherein the login request includes a user identity tag, a login timestamp tag, a first decryption key tag, and a service type tag, and the user identity tag is the legal person identity information; Matching a first encryption key tag according to the user identity tag, the login timestamp tag and the service type tag, wherein the first encryption key tag has a time domain update characteristic; Generate a SMS benchmark verification code, which is sent to the mobile phone number bound to the user's identity tag through the operator, and receive the SMS comparison verification code; Constructing a second decryption key tag according to the SMS verification code and the first decryption key tag; At the same time, constructing a second encryption key tag according to the SMS benchmark verification code and the first encryption key tag; Perform verification according to the second decryption key label and the second encryption key label to obtain a key verification result; When the key verification result is passed, login is allowed; Matching a first encryption key tag according to the user identity tag, the login timestamp tag, and the service type tag includes: When the encryption key of the preset user and the preset service type is configured, constructing a first encryption key effective time zone based on the encryption key configuration timestamp and the encryption key preset update duration; When the first encryption key validity period ends, performing optimization based on the asymmetric key library to obtain a key pair optimization result, wherein the key pair optimization result has an encryption key update result and a decryption key update result, and the key pair optimization result has a second encryption key validity period; Sending the decryption key update result to the user terminal of the preset service type of the preset user to update the decryption key; Setting the encryption key update result as the valid key in the valid time zone of the second encryption key; According to the login timestamp tag, a valid encryption key matching the user identity tag and the service type tag is set as the first encryption key tag; When the effective time zone of the first encryption key ends, optimizing is performed based on the asymmetric key library to obtain a key pair optimization result, including: Configure adaptability indicators, wherein the adaptability indicators include selection frequency and selection duration, wherein the selection frequency refers to the frequency of key pair configuration for the preset user and the preset service type, and the selection duration refers to the average time interval between the key selection historical timestamp and the current timestamp; Constructing a fitness evaluator according to the selection frequency and the selection duration; According to the fitness evaluator, optimizing the asymmetric key library to obtain the key pair optimization result; According to the selection frequency and the selection duration, a fitness evaluator is constructed, including: A first coordinate axis is constructed using a normalized index of the selection frequency, and a second coordinate axis is constructed using a normalized index of the reciprocal of the selection duration; Constructing a two-dimensional virtual coordinate system according to the first coordinate axis and the second coordinate axis; Constructing a fitness evaluation function, wherein the fitness evaluation function is used to calculate the product of the horizontal and vertical coordinates; The fitness evaluator is constructed according to the fitness evaluation function and the two-dimensional virtual coordinate system.
2. The multi-tenant rights management method based on the APaaS platform according to claim 1, characterized in that: Constructing a second decryption key tag according to the SMS verification code and the first decryption key tag, which includes: The login request also includes a login address tag; The SMS comparison verification code has a sending address label; Performing address verification according to the sending address tag and the login address tag to obtain an address verification result; When the address verification result is passed, constructing the second decryption key label according to the SMS verification code and the first decryption key label; When the address verification result is failed, the login request is rejected, and an address exception error is generated and displayed on the APaaS platform user terminal interface.
3. The multi-tenant rights management method based on the APaaS platform according to claim 2, characterized in that: Performing address verification according to the sending address tag and the login address tag to obtain an address verification result includes: According to the user identity tag, searching is performed based on the APaaS platform database to match the registration address tag; When the registered address tag is different from the logged address tag, or / and the sent address tag is different from the logged address tag, the address verification result is failed; When the registered address tag is the same as the logged-in address tag, and the sent address tag is the same as the logged-in address tag, the address verification result is passed.
4. The multi-tenant rights management method based on the APaaS platform according to claim 1, characterized in that: Constructing a second decryption key tag according to the SMS verification code and the first decryption key tag, including: According to the SMS comparison verification code, the SMS comparison verification code is inserted into the first decryption key tag according to the first preset position sequence number to construct the second decryption key tag.
5. The multi-tenant rights management method based on the APaaS platform according to claim 1, characterized in that: Constructing a second encryption key tag according to the SMS reference verification code and the first encryption key tag, including: According to the SMS reference verification code, the SMS reference verification code is inserted into the first encryption key tag according to a second preset position sequence number to construct the second encryption key tag.
6. A multi-tenant rights management system based on the APaaS platform, characterized by: The steps for implementing the multi-tenant rights management method based on the APaaS platform according to any one of claims 1 to 5 include: A login request response module, used to respond to a login request inputted from the APaaS platform user interface, wherein the login request includes a user identity tag, a login timestamp tag, a first decryption key tag, and a service type tag, and the user identity tag is the legal person identity information; A first encryption key tag matching module, configured to match a first encryption key tag according to the user identity tag, the login timestamp tag and the service type tag, wherein the first encryption key tag has a time domain update characteristic; A verification code comparison receiving module is used to generate a SMS reference verification code, which is sent to the mobile phone number bound to the user identity tag by the operator, and receives the SMS verification code comparison; A second decryption key label construction module, used to construct a second decryption key label according to the SMS verification code and the first decryption key label; A second encryption key label construction module, used to simultaneously construct a second encryption key label according to the SMS benchmark verification code and the first encryption key label; A key verification module, used to perform verification according to the second decryption key label and the second encryption key label to obtain a key verification result; The login permission module is used to allow login when the key verification result is passed.
Citation Information
Patent Citations
Identity authentication method, device and system and electronic equipment
CN112887282A
Authentication method and system of SaaS platform, equipment and medium
CN116015636A
Cloud platform hybrid identity authentication method and system
CN116389095A