A method and system for offline identity authentication and rights management
Through the dual verification of digital certificates and USB keys, combined with access control lists, the problem of user identity authentication and permission management in offline state is solved, reliable identity authentication and dynamic permission management in offline environment are realized, and the security and flexibility of the system are improved.
Patent Information
- Application Number
- CN202411484808.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-23
- Publication Date
- 2025-10-03
- Estimated Expiration
- 2044-10-23
AI Technical Summary
In offline state, existing technologies find it difficult to reliably verify user identity and manage permissions, resulting in limited service availability and flexibility. Especially in network isolation or high-security environments, traditional identity authentication methods are highly dependent on network connections and cannot meet real-time requirements.
Through dual verification of digital certificates and USB keys, identity authentication and permission management are performed using the access control list in the USB key to ensure the authenticity and legitimacy of user identity and operation permissions in offline state. Administrators can generate and update access control lists and dynamically adjust permissions.
It realizes reliable authentication of user identities and authority management in an offline environment, reduces dependence on the network, improves system security and flexibility, ensures that legitimate users perform necessary operations, prevents unauthorized access, and enhances user satisfaction and trust.
Smart Images

Figure CN119397511B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of identity authentication and authority management, and in particular to a method and system for off-line identity authentication and authority management. Background Art
[0002] With the rapid development of internet technology, network applications are becoming increasingly popular, and users are increasingly using online services more frequently and intensively. Against this backdrop, identity authentication and permission management technologies have emerged and are continuously evolving to ensure the security of network applications and user information. Currently, mainstream identity authentication and permission management technologies include identity authentication, digital certificates, role-based access control, and access control lists.
[0003] With the prevalence of mobile devices, users increasingly rely on online services to meet their various needs. However, verifying the identity and permissions of service users is equally crucial in offline scenarios. For example, certain network nodes may be isolated for various reasons. Or, in vehicles like cars, ships, and airplanes, mobile or embedded information systems may need to be accessed and used even without an internet connection. Another important application scenario for offline identity authentication and permissions management is in environments with high network security requirements. In these environments, network connectivity may be limited and affected by objective factors, making offline identity authentication and permissions management a crucial means of ensuring security. Offline identity authentication and permissions management can also reduce reliance on the network. In applications with high real-time requirements, such as online gaming and live video streaming, offline identity authentication and permissions management can provide faster and more stable services. Therefore, there is an urgent need to provide a method for authenticating user identities offline. Summary of the Invention
[0004] In view of this, the present invention provides a method and system for offline identity authentication and rights management, which can realize reliable authentication of user identities and dynamic management of user rights in an offline environment.
[0005] In a first aspect, the present invention provides a method for offline identity authentication and authority management, which is applied to an identity authentication client, comprising: receiving an operation request from a target user to a target terminal, the operation request including a digital certificate of the target user and an operation instruction of the target user to the target terminal; if the identity authentication client is in an offline state, verifying the digital certificate of the target user by a first authentication center of the identity authentication client to obtain a legitimacy verification result of the target user; if the target user is determined to be a legitimate user based on the legitimacy verification result of the target user, determining the target user's operation authority to the target terminal by using an access control list of the target user in a USB key, the USB key of the target user being obtained by the identity authentication server authorizing the target user to generate an access control list for the target user, and the access control list being written to the USB by the second authentication center of the identity authentication server; determining the target operation authority required for the operation instruction; if the target user's operation authority to the target terminal includes the target operation authority, determining that the target user has the authority to execute the operation request to the target terminal.
[0006] The method for offline identity authentication and authority management provided by an embodiment of the present invention is that after the identity authentication server authorizes the target user and generates an access control list for the target user, the second authentication center of the identity authentication server writes the access control list into the USB to obtain the USB key of the target user. Therefore, after the identity authentication client receives the operation request of the target user to the target terminal, even if the current identity authentication client is in an offline state, it can first authenticate the target user through the first authentication center of the identity authentication client, and then determine the target user's operation authority for the target terminal based on the target user's access control list in the USB key, thereby judging whether the target user has the operation authority to execute the operation instruction, and the identity authentication client can directly query the USB key. The relevant information in the system does not need to be queried through the identity authentication server. Therefore, the embodiment of the present invention realizes the identity authentication and permission authentication of the target user in an offline state, reducing the dependence on the network. Moreover, the embodiment of the present invention realizes fine-grained permission management through the access control list, and can assign different operation permissions according to the user's role, responsibility or demand, which helps to prevent unauthorized access and operation, while ensuring that legitimate users can perform the operations required for their duties. The administrator can generate and update the access control list through the identity authentication server and write it into the USB key. Through the dual verification of the digital certificate and the USB key, the authenticity and legitimacy of the user identity and operation permission can be ensured even in the offline state, which greatly improves the security of the system.
[0007] In an optional embodiment, if the target user does not have the authority to execute the operation request on the target terminal, the method further includes: determining the operation authority of each user on the target terminal based on the access control list in the USB key of each user; determining an administrative user with authorized authority on the target terminal based on the operation authority of each user on the target terminal; and using the administrative user to modify the access control list in the USB key of the target user so that the access control list in the USB key of the target user includes the authority corresponding to the operation instruction.
[0008] The offline identity authentication and authority management method provided by the embodiment of the present invention can dynamically adjust authorities according to user needs instead of relying solely on static preset rules. This improves the flexibility and adaptability of the system, enabling it to better meet ever-changing security and business needs. When a target user is unable to perform an operation due to insufficient authority, the system provides a clear path, namely, solving the problem by adjusting authorities through management users, which helps to improve user satisfaction and trust. By directly modifying the access control list of the target user through management users, the problem of insufficient authorities can be quickly resolved without the need for complex system configuration or re-authorization processes, thereby improving the response speed and efficiency of the system. Modifications to the access control list can be accurate to specific operation instructions or resources, thereby ensuring that the target user only obtains the minimum authority set to perform the required operation, reducing potential security risks.
[0009] In an optional embodiment, if the identity authentication client is online, the method further includes: sending the access control list in the target user's USB key to the identity authentication server, so that the identity authentication server compares the access control list in the target user's USB key with the access control list of the target user stored in the identity authentication server, and updates the access control list of the target user stored in the identity authentication server through the identity authentication server, or the access control list in the target user's USB key, so that the access control list of the target user stored in the identity authentication server is consistent with the access control list in the target user's USB key.
[0010] The offline identity authentication and rights management method provided by an embodiment of the present invention compares and synchronizes the access control list in the target user's USB key with the access control list stored in the identity authentication server when the identity authentication client is online. This comparison and synchronization ensures consistency between the target user's access control list stored in the identity authentication server and the USB key, avoiding confusion in rights management and potential security risks caused by inconsistent data. When a user needs to access resources on multiple devices or systems, ensuring consistency in rights data simplifies the user's identity authentication and rights checking process, thereby improving the user experience. The online synchronization mechanism enables the system to support dynamic rights management, namely, updating the user's access control list in real time based on changes in business needs or security policies. This improves the system's flexibility and responsiveness.
[0011] In an optional embodiment, after the step of receiving the operation request of the target user to the target terminal, if it is determined that the identity authentication client is online, the method further includes: sending the operation request to the identity authentication server so that the identity authentication server determines the authority of the operation request.
[0012] In a second aspect, the present invention provides an offline identity authentication and authority management system, comprising: an identity authentication server and an identity authentication client, the identity authentication server comprising a second authentication center, the identity authentication client comprising a first authentication center, wherein the identity authentication server is used to determine the operation authority of each user on different terminals, and generate an access control list based on the operation authority of each user on different terminals, and write the operation authority of each user on different terminals into the USB on a user basis through the second authentication center to generate a USB key for each user, the identity authentication client is used to receive an operation request from a target user on a target terminal, the operation request including the digital certificate of the target user and the operation instruction of the target user on the target terminal; if the identity authentication client is in an offline state, the digital certificate of the target user is verified by the first authentication center of the identity authentication client to obtain a legitimacy verification result of the target user; if the target user is determined to be a legitimate user based on the legitimacy verification result of the target user, the access control list of the target user in the USB key is used to determine the operation authority of the target user on the target terminal; the target operation authority required for the operation instruction is determined; if the target user's operation authority on the target terminal includes the target operation authority, it is determined that the target user has the authority to execute the operation request on the target terminal.
[0013] The offline identity authentication and authority management system provided by the embodiment of the present invention has the following characteristics: after the identity authentication server authorizes the target user and generates an access control list for the target user, the second authentication center of the identity authentication server writes the access control list into the USB to obtain the USB key of the target user; therefore, after the identity authentication client receives the operation request of the target user to the target terminal, even if the current identity authentication client is in an offline state, the identity of the target user can be authenticated by the first authentication center of the identity authentication client first, and then the operation authority of the target user to the target terminal is determined according to the access control list of the target user in the USB key, thereby judging whether the target user has the operation authority to execute the operation instruction; the identity authentication client can directly query the USB key The relevant information in the system does not need to be queried through the identity authentication server. Therefore, the embodiment of the present invention realizes the identity authentication and permission authentication of the target user in an offline state, reducing the dependence on the network. Moreover, the embodiment of the present invention realizes fine-grained permission management through the access control list, and can assign different operation permissions according to the user's role, responsibility or demand, which helps to prevent unauthorized access and operation, while ensuring that legitimate users can perform the operations required for their duties. The administrator can generate and update the access control list through the identity authentication server and write it into the USB key. Through the dual verification of the digital certificate and the USB key, the authenticity and legitimacy of the user identity and operation permission can be ensured even in the offline state, which greatly improves the security of the system.
[0014] In an optional embodiment, if the identity authentication client determines that the target user does not have the authority to execute the operation request on the target terminal, the method also includes: the identity authentication client is also used to determine the operation authority of each user on the target terminal based on the access control list in the USB key of each user; based on the operation authority of each user on the target terminal, determine the management user with authorization authority for the target terminal; and use the management user to modify the access control list in the USB key of the target user so that the access control list in the USB key of the target user includes the authority corresponding to the operation instruction.
[0015] In an optional embodiment, if the identity authentication client is online, the method also includes: the identity authentication client sends the access control list in the target user's USB key to the identity authentication server; the identity authentication server compares the access control list in the target user's USB key with the access control list of the target user stored in the identity authentication server; if the version of the access control list in the target user's USB key is higher than the access control list of the target user stored in the identity authentication server, the access control list of the target user stored in the identity authentication server is updated; if the version of the access control list in the target user's USB key is lower than the access control list of the target user stored in the identity authentication server, using the second authentication center to write the access control list of the target user stored in the identity authentication server into the USB key of the target user.
[0016] In an optional embodiment, after the identity authentication client receives the target user's operation request for the target terminal, if it is determined that the identity authentication client is online, the method also includes: the identity authentication client sends the operation request to the identity authentication server; the identity authentication server receives the operation request; the digital certificate of the target user is verified by the second authentication center to obtain the legitimacy verification result of the target user; if the target user is determined to be a legitimate user based on the legitimacy verification result of the target user, the target user's operation authority for the target terminal is determined using the access control list of the target user stored in the identity authentication service; the target operation authority required for the operation instruction is determined; if the target user's operation authority for the target terminal includes the target operation authority, it is determined that the target user has the authority to execute the operation request on the target terminal.
[0017] In a third aspect, the present invention provides a computer device comprising: a memory and a processor, the memory and the processor being communicatively connected to each other, the memory storing computer instructions, and the processor executing the upgrade method of the first aspect or any corresponding embodiment thereof by executing the computer instructions.
[0018] In a fourth aspect, the present invention provides a computer-readable storage medium having computer instructions stored thereon, the computer instructions being used to enable a computer to execute the log data query method of the first aspect or any corresponding embodiment thereof. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the specific embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0020] Figure 1 1 is a flow chart of an offline identity authentication and rights management method according to an embodiment of the present invention;
[0021] Figure 2 is a flowchart of another offline identity authentication and rights management method according to an embodiment of the present invention;
[0022] Figure 3 This is a schematic diagram of an application scenario provided by an embodiment of the present invention;
[0023] Figure 4 is a schematic diagram of another application scenario provided by an embodiment of the present invention;
[0024] Figure 5 1 is a flow chart of another offline identity authentication and rights management method according to an embodiment of the present invention;
[0025] Figure 6 Schematic diagram of an offline identity authentication and rights management system provided by an embodiment of the present invention;
[0026] Figure 7 is a signaling flow chart between an identity authentication server and an identity authentication client according to an embodiment of the present invention;
[0027] Figure 8 Schematic diagram of the structure of a computer device according to an embodiment of the present invention. DETAILED DESCRIPTION
[0028] To make the purpose, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without making creative efforts shall fall within the scope of protection of the present invention.
[0029] The offline identity authentication and authority management method provided by the embodiment of the present invention can be applied to network isolation or restricted environments, high security requirement environments and application scenarios with high real-time requirements as the development of Internet technology and the popularization of network applications. Different environments or scenarios require identity authentication and authority management. By receiving the target user's operation request for the target terminal; if the identity authentication client is in an offline state, the digital certificate of the target user is verified by the first authentication center of the identity authentication client to obtain the legitimacy verification result of the target user; if the target user is determined to be a legitimate user according to the legitimacy verification result of the target user, the target user's access control list in the USB key is used to determine the target user's operation authority for the target terminal; determine the target operation authority required for the operation instruction; if the target user's operation authority for the target terminal includes the target operation authority, it is determined that the target user has the authority to execute the operation request on the target terminal. By executing the present invention, user identity authentication and authority management in an offline environment can be achieved.
[0030] At present, traditional identity authentication and permission management methods rely on network connections. Traditional identity authentication technologies, such as Internet-based verification codes and SMS verification, are highly dependent on network connections. Once the network fails or is offline, these authentication methods will become unusable, thereby limiting the availability and flexibility of the service. Therefore, in an offline environment, how to reliably verify the user's identity is a difficult problem. In an offline environment, permission management also faces challenges. How to ensure that users can only access authorized resources while taking into account the flexibility and scalability of the system is a problem that needs to be solved.
[0031] The present invention provides a method for offline identity authentication and rights management. Through dual verification of a digital certificate and a USB key, and modification of the access control list in the target user's USB key, the method can authenticate the user identity and manage operation rights even in an offline state, thereby realizing reliable authentication of user identity and dynamic management of user rights in an offline environment.
[0032] According to an embodiment of the present invention, a method for offline identity authentication and authority management is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0033] In this embodiment, a method for offline identity authentication and rights management is provided, which can be used for the above-mentioned identity authentication client. Figure 1 : is a flow chart of an offline identity authentication and rights management method according to an embodiment of the present invention. Figure 1As shown, the process includes the following steps:
[0034] Step S101: receiving an operation request from a target user for a target terminal, where the operation request includes a digital certificate of the target user and an operation instruction from the target user for the target terminal.
[0035] In an optional embodiment, the identity authentication client needs to receive an operation request from the target user, where the operation request contains all necessary information required to perform the operation, exemplarily, the user identity identifier and the requested operation type. The operation request is an instruction sent by the target user to the identity authentication client in a specific manner, exemplarily, through a network, a local interface, etc.
[0036] In an optional embodiment, the operation request includes multiple key information, the most important of which is the digital certificate of the target user and the target user's operation instructions for the target terminal based on the digital certificate. The digital certificate of the target user is a digital file used to verify the user's identity in a network environment and is issued by the second authentication center of the identity authentication service.
[0037] Step S102: determine whether the identity authentication client is offline.
[0038] If the identity authentication client is in an offline state, step S103 is executed: the digital certificate of the target user is verified by the first authentication center of the identity authentication client to obtain a legitimacy verification result of the target user.
[0039] If the identity authentication client is online, step S104 is executed: the operation request is sent to the identity authentication server, so that the identity authentication server determines the authority of the operation request.
[0040] In one embodiment, the identity authentication client uses a heartbeat mechanism to determine whether it is connected to the identity authentication server. The identity authentication client periodically sends a signal to the identity authentication server to confirm whether it can communicate normally with the identity authentication server. If the identity authentication client sends a signal to the identity authentication server and the identity authentication server does not respond, the identity authentication client determines that it is offline.
[0041] In an optional embodiment, the second authentication center of the identity authentication server is responsible for the issuance and management of digital certificates. The second authentication center verifies the user's identity, generates a public key and private key pair for the user, and associates the public key with the user's identity information to generate a digital certificate. The digital certificate contains the user's identity information, public key, and the validity period of the certificate. After the second authentication center of the identity authentication server issues the digital certificate, it will also synchronize the relevant information to the first authentication center of the identity authentication client. When the identity authentication client is offline and cannot authenticate the target user through the second authentication center, it can also authenticate the target user through the information in the first authentication center.
[0042] In an optional embodiment, the process of verifying a digital certificate includes multiple aspects, for example, checking whether the format of the certificate is correct, whether the certificate has expired, whether the issuing authority of the certificate is trustworthy, whether the public key in the certificate matches the expected public key, etc.
[0043] In an optional embodiment, a verification result is obtained through verification, indicating whether the digital certificate of the target user is valid, thereby inferring whether the target user is legal. If the digital certificate passes all verification steps, the target user is regarded as a legal user, otherwise, it is regarded as an illegal user.
[0044] After executing step S102, if it is determined that the identity authentication client is offline and the legitimacy verification result obtained by executing step S103 determines that the target user is an illegal user, feedback information is sent to the target user, and the feedback information is used to prompt that the target user is an illegal user.
[0045] After executing step S102, if it is determined that the identity authentication client is offline, and the legitimacy verification result obtained by executing step S103 determines that the target user is a legitimate user, the method provided by the embodiment of the present invention further executes the following steps:
[0046] Step S105: Use the access control list of the target user in the USB key to determine the target user's operating authority on the target terminal. The USB key of the target user is generated by the identity authentication server to authorize the target user, and the access control list is written into the USB by the second authentication center of the identity authentication server.
[0047] In an optional embodiment, the USB key is used to store the access control list of the target user. The access control list is written to the USB. When the target user needs to use the USB key for identity authentication, the identity authentication client can read the access control list from the USB key and determine the target user's operating authority according to regulations.
[0048] Step S106: determining the target operation authority required by the operation instruction.
[0049] In an optional embodiment, the target user requires different operation permissions when executing different operation instructions on the target terminal. For example, if the target user needs to log in to the target terminal, the target terminal login permission needs to be obtained; if the target user needs to use an application in the target terminal, the target user needs to obtain permission to use the application. Therefore, after receiving the operation request of the target user on the target terminal, the identity authentication client needs to determine the target operation permission required for the operation instruction, and then verify the target user's permission to determine whether the target user can execute the operation instruction.
[0050] Step S107 : if the target user's operation authority on the target terminal includes the target operation authority, it is determined that the target user has the authority to execute the operation request on the target terminal, and a control instruction is sent to the target terminal to enable the target terminal to execute the operation instruction.
[0051] The operation authority of the target user is determined according to the access control list of the target user stored in the USB key, and whether the target user has the authority to execute the operation request on the target terminal is judged according to the operation authority of the target user.
[0052] In the embodiment of the present invention, strict permission matching is used to ensure that only users with corresponding permissions can perform specific operations, thereby preventing unauthorized access and operations and improving the security of the target terminal.
[0053] In one embodiment, after first determining whether the identity authentication client is in an offline state, the state of the identity authentication client may change due to various reasons, for example, network fluctuations, environmental changes, etc. Therefore, when determining that the target user has the authority to execute the operation request on the target terminal, it is possible to determine again whether the identity authentication client is in an offline state. When it is again determined that the identity authentication client is in an offline state, a control instruction is sent to the target terminal to enable the target terminal to execute the operation instruction. Conversely, if it is determined that the identity authentication client is in an online state at this time, the operation request of the target user is sent to the identity authentication server, and the identity authentication server verifies the identity and authority of the target user again to improve the security of the operation.
[0054] The method for offline identity authentication and authority management provided by an embodiment of the present invention is that after the identity authentication server authorizes the target user and generates an access control list for the target user, the second authentication center of the identity authentication server writes the access control list into the USB to obtain the USB key of the target user. Therefore, after the identity authentication client receives the operation request of the target user to the target terminal, even if the current identity authentication client is in an offline state, it can first authenticate the target user through the first authentication center of the identity authentication client, and then determine the target user's operation authority for the target terminal based on the target user's access control list in the USB key, thereby judging whether the target user has the operation authority to execute the operation instruction, and the identity authentication client can directly query the USB key. The relevant information in the system does not need to be queried through the identity authentication server. Therefore, the embodiment of the present invention realizes the identity authentication and permission authentication of the target user in an offline state, reducing the dependence on the network. Moreover, the embodiment of the present invention realizes fine-grained permission management through the access control list, and can assign different operation permissions according to the user's role, responsibility or demand, which helps to prevent unauthorized access and operation, while ensuring that legitimate users can perform the operations required for their duties. The administrator can generate and update the access control list through the identity authentication server and write it into the USB key. Through the dual verification of the digital certificate and the USB key, the authenticity and legitimacy of the user identity and operation permission can be ensured even in the offline state, which greatly improves the security of the system.
[0055] In this embodiment, an offline identity authentication and rights management method is provided, which can be used for the above-mentioned identity authentication client. Figure 2 is a flow chart of another offline identity authentication and rights management method according to an embodiment of the present invention. Figure 2 As shown, the process includes the following steps:
[0056] Step S201: Receive an operation request from a target user for a target terminal. The operation request includes the target user's digital certificate and the target user's operation instruction for the target terminal. Figure 1 Step S101 of the illustrated embodiment will not be described in detail here.
[0057] Step S202: Determine whether the identity authentication client is offline. Figure 1 Step S102 of the illustrated embodiment will not be described in detail here.
[0058] If the identity authentication client is in an offline state, step S203 is executed: the digital certificate of the target user is verified by the first authentication center of the identity authentication client to obtain a legitimacy verification result of the target user.
[0059] If the identity authentication client is online, step S204 is executed: the operation request is sent to the identity authentication server, so that the identity authentication server determines the authority of the operation request.
[0060] After executing step S202, if it is determined that the identity authentication client is offline and the legitimacy verification result obtained by executing step S203 determines that the target user is an illegal user, feedback information is sent to the target user, and the feedback information is used to prompt that the target user is an illegal user.
[0061] After executing step S202, if it is determined that the identity authentication client is offline, and the legitimacy verification result obtained by executing step S203 determines that the target user is a legitimate user, the method provided by the embodiment of the present invention further executes the following steps:
[0062] Step S205: Use the target user's access control list in the USB key to determine the target user's operating authority on the target terminal. The target user's USB key is generated by the identity authentication server authorizing the target user to generate the target user's access control list, and the second authentication center of the identity authentication server writes the access control list into the USB. Figure 1 Step S105 of the illustrated embodiment will not be described in detail here.
[0063] Step S206: Determine the target operation authority required for the operation instruction. Figure 1 Step S106 of the illustrated embodiment will not be described in detail here.
[0064] Step S207 , if the target user's operation authority on the target terminal includes the target operation authority, it is determined that the target user has the authority to execute the operation request on the target terminal, and a control instruction is sent to the target terminal to enable the target terminal to execute the operation instruction.
[0065] After executing the above step S206, if it is determined that the target user's operation permissions for the target terminal do not include the target operation permission, the following steps are executed:
[0066] Step S208: determining each user's operation authority for the target terminal according to the access control list in each user's USB key.
[0067] In an optional embodiment, the identity authentication server uses a role-based access control model to manage access rights for the application system. Ultimately, the access control list is derived through role calculations and used as the final storage format for the permission results. When performing permission abstraction, a method for representing terminal authorization permissions must be specifically designed to clarify who has the right to modify the ACL in an offline state. The access control list is shown in Table 1 below:
[0068] Table 1
[0069]
[0070]
[0071] When the second authentication center of the identity authentication server creates a USB key, it writes data to the USB in units of a single user. At this time, the access control list only contains the information of the user. For example, the access control list of user 1 (User-1) is:
[0072] {
[0073] "Terminal 1": ["Usage Permission", "Authorized Permission"],
[0074] "Terminal 2": ["Usage Permission", "Usage Permission for APP-2"]
[0075] }
[0076] This indicates that user 1 has the right to use and authorize terminal 1, and has the right to use terminal 2 and the right to use APP-2 in terminal 2.
[0077] Step S209: determining a management user who has authorization authority for the target terminal according to the operation authority of each user for the target terminal.
[0078] Step S210: Using the management user to modify the access control list in the target user's USB key, so that the access control list in the target user's USB key includes the authority corresponding to the operation instruction.
[0079] For example, Figure 3 As shown, User 2 is a legitimate user of Terminal 2, and User 3 is a legitimate user of Terminal 3. When both Terminals 2 and 3 are offline, if User 3 needs to log in to Terminal 2, the offline permission change is designed to solve the problem of how to make User 3 a legitimate user of Terminal 2. After User 3 sends an operation request to Terminal 2, Terminal 2 loads User 3's USB key and verifies it as a legitimate digital certificate using the public key. However, because User 3 does not have permission on Terminal 2, he cannot perform the business operation.
[0080] At this time, terminal 2 determines that user 2 is an administrative user with authorization authority for terminal 2 based on the operation authority of each user. Then, user 2 can grant user 3 authority on terminal 2, that is, modify the access control list in user 3's USB key.
[0081] For example, if user 3's original access control list is:
[0082] {
[0083] "Terminal 3": ["Usage Permission", "Authorized Permission"],
[0084] }
[0085] After modification by user 2, the access control list in user 3's USB key is changed to:
[0086] {
[0087] "Terminal 3": ["Usage Permission", "Authorized Permission"],
[0088] "Terminal 2": ["Usage Permission", "Authorized Permission"]
[0089] }
[0090] At this time, if Figure 4 As shown, user 3 becomes a legitimate user of terminal 2. When user 3 sends an operation request to terminal 2 again, terminal 3 queries the USB key of user 3 and can determine whether user 3 has certain operation permissions on terminal 2 based on the access control list.
[0091] The offline identity authentication and authority management method provided by the embodiment of the present invention can dynamically adjust authorities according to user needs instead of relying solely on static preset rules. This improves the flexibility and adaptability of the system, enabling it to better meet ever-changing security and business needs. When a target user is unable to perform an operation due to insufficient authority, the system provides a clear path, namely, solving the problem by adjusting authorities through management users, which helps to improve user satisfaction and trust. By directly modifying the access control list of the target user through management users, the problem of insufficient authorities can be quickly resolved without the need for complex system configuration or re-authorization processes, thereby improving the response speed and efficiency of the system. Modifications to the access control list can be accurate to specific operation instructions or resources, thereby ensuring that the target user only obtains the minimum authority set to perform the required operation, reducing potential security risks.
[0092] In this embodiment, an offline identity authentication and rights management method is provided, which can be used for the above-mentioned identity authentication client. Figure 5 is a flow chart of another offline identity authentication and rights management method according to an embodiment of the present invention. Figure 5 As shown, the process includes the following steps:
[0093] Step S501: Receive an operation request from a target user for a target terminal. The operation request includes the target user's digital certificate and the target user's operation instruction for the target terminal. Figure 1 Step S101 of the illustrated embodiment will not be described in detail here.
[0094] Step S502: Determine whether the identity authentication client is offline. Figure 1 Step S102 of the illustrated embodiment will not be described in detail here.
[0095] If the identity authentication client is in an offline state, execute step S503: verify the digital certificate of the target user through the first authentication center of the identity authentication client to obtain the legitimacy verification result of the target user.
[0096] If the identity authentication client is online, step S504 is executed: the operation request is sent to the identity authentication server, so that the identity authentication server determines the authority of the operation request.
[0097] After executing step S502, if it is determined that the identity authentication client is offline and the legitimacy verification result obtained by executing step S503 determines that the target user is an illegal user, feedback information is sent to the target user, and the feedback information is used to prompt that the target user is an illegal user.
[0098] After executing step S502, if it is determined that the identity authentication client is offline, and the legitimacy verification result obtained by executing step S503 determines that the target user is a legitimate user, the method provided by the embodiment of the present invention further executes the following steps:
[0099] Step S505: Use the target user's access control list in the USB key to determine the target user's operating authority on the target terminal. The target user's USB key is generated by the identity authentication server authorizing the target user to generate the target user's access control list, and the second authentication center of the identity authentication server writes the access control list into the USB. Figure 1 Step S105 of the illustrated embodiment will not be described in detail here.
[0100] Step S506: Determine the target operation authority required for the operation instruction. Figure 1 Step S106 of the illustrated embodiment will not be described in detail here.
[0101] Step S507 : if the target user's operation authority on the target terminal includes the target operation authority, it is determined that the target user has the authority to execute the operation request on the target terminal, and a control instruction is sent to the target terminal to enable the target terminal to execute the operation instruction.
[0102] After executing the above step S506, if it is determined that the target user's operation permissions for the target terminal do not include the target operation permission, the following steps are executed:
[0103] Step S508: Determine the operation authority of each user on the target terminal according to the access control list in each user's USB key. Figure 2 Step S208 of the illustrated embodiment will not be described in detail here.
[0104] Step S509: Determine the management user who has the authorization authority for the target terminal according to the operation authority of each user for the target terminal. Figure 2 Step S209 of the illustrated embodiment will not be described in detail here.
[0105] Step S510: Use the management user to modify the access control list in the target user's USB key so that the access control list in the target user's USB key contains the permissions corresponding to the operation instruction. Figure 2 Step S210 of the illustrated embodiment will not be described in detail here.
[0106] When the authentication client comes back online, it performs the following steps:
[0107] Step S511, sending the access control list in the target user's USB key to the identity authentication server, so that the identity authentication server compares the access control list in the target user's USB key with the access control list of the target user stored in the identity authentication server, and updates the access control list of the target user stored in the identity authentication server through the identity authentication server, or the access control list in the target user's USB key, so that the access control list of the target user stored in the identity authentication server is consistent with the access control list in the target user's USB key.
[0108] In an optional embodiment, the identity authentication server compares the timestamp and version number. If the access control list in the USB key is a historical version of the server, the latest access control list is written to the USB key. If the access control list on the server is a historical version of the access control list in the USB key, indicating that the access control list has been modified offline, the access control list on the server is automatically updated. If the access control list in the USB key and the access control list on the server diverge, the server administrator decides which access control list to use as the final result, and synchronizes the access control lists on the server and the USB key to maintain consistency.
[0109] The offline identity authentication and rights management method provided by an embodiment of the present invention compares and synchronizes the access control list in the target user's USB key with the access control list stored in the identity authentication server when the identity authentication client is online. This comparison and synchronization ensures consistency between the target user's access control list stored in the identity authentication server and the USB key, avoiding confusion in rights management and potential security risks caused by inconsistent data. When a user needs to access resources on multiple devices or systems, ensuring consistency in rights data simplifies the user's identity authentication and rights checking process, thereby improving the user experience. The online synchronization mechanism enables the system to support dynamic rights management, namely, updating the user's access control list in real time based on changes in business needs or security policies. This improves the system's flexibility and responsiveness.
[0110] In this embodiment, an offline identity authentication and authority management system is provided, such as Figure 6 As shown, it includes an identity authentication server and an identity authentication client. The identity authentication server contains a second authentication center, and the identity authentication client contains a first authentication center. The second authentication center of the identity authentication server is used to make a USB key. When the identity authentication client is offline, the target user is authenticated and authorized through the first authentication center and the USB key.
[0111] Figure 7 : is a signaling flow chart between the identity authentication server and the identity authentication client according to an embodiment of the present invention, such as Figure 7 As shown, the identity authentication server and identity authentication client are used to perform the following steps respectively:
[0112] Step S701: The identity authentication server determines each user's operating rights for different terminals and generates an access control list based on each user's operating rights for different terminals. The second authentication center writes each user's operating rights for different terminals into the USB on a user-by-user basis to generate a USB key for each user.
[0113] Step S702: The identity authentication client receives an operation request from a target user for a target terminal. The operation request includes a digital certificate of the target user and an operation instruction from the target user for the target terminal.
[0114] Step S703: The identity authentication client determines whether it is in an offline state.
[0115] If the identity authentication client is in an offline state, execute step S704: the identity authentication client verifies the digital certificate of the target user through the first authentication center to obtain the legitimacy verification result of the target user.
[0116] If the identity authentication client is online, step S705 is executed: the identity authentication client sends the operation request to the identity authentication server, so that the identity authentication server determines the authority of the operation request.
[0117] After executing step S703, if it is determined that the identity authentication client is offline, and the legitimacy verification result obtained by executing step S704 determines that the target user is a legitimate user, the following steps are further executed:
[0118] Step S706: The identity authentication client uses the access control list of the target user in the USB key to determine the target user's operation authority on the target terminal.
[0119] Step S707: The identity authentication client determines the target operation authority required by the operation instruction.
[0120] In step S708, if the target user's operation rights on the target terminal include the target operation rights, the identity authentication client determines that the target user has the rights to execute the operation request on the target terminal and sends a control instruction to the target terminal to enable the target terminal to execute the operation instruction.
[0121] In an optional embodiment, the identity authentication client is further used to determine each user's operating authority over the target terminal based on the access control list in each user's USB key; determine the management user with authorized authority over the target terminal based on each user's operating authority over the target terminal; and use the management user to modify the access control list in the target user's USB key so that the access control list in the target user's USB key contains authority corresponding to the operating instructions.
[0122] In an optional embodiment, if the identity authentication client returns to an online state, the system provided by the embodiment of the present invention further includes:
[0123] The identity authentication client sends the access control list in the target user's USB key to the identity authentication server.
[0124] The identity authentication server compares the access control list in the target user's USB key with the access control list of the target user stored in the identity authentication server.
[0125] If the version of the access control list in the target user's USB key is higher than the access control list of the target user stored in the identity authentication server, the access control list of the target user stored in the identity authentication server is updated.
[0126] If the version of the access control list in the target user's USB key is lower than the access control list of the target user stored in the identity authentication server, the second authentication center is used to write the access control list of the target user stored in the identity authentication server into the USB key of the target user.
[0127] In an optional embodiment, after the identity authentication client receives the target user's operation request for the target terminal, if it is determined that the identity authentication client is in an online state, the system provided by the embodiment of the present invention further includes:
[0128] The identity authentication client sends the operation request to the identity authentication server;
[0129] The identity authentication service receives the operation request; the digital certificate of the target user is verified through the second authentication center to obtain the legitimacy verification result of the target user; if the target user is determined to be a legitimate user based on the legitimacy verification result of the target user, the access control list of the target user stored in the identity authentication service is used to determine the target user's operation authority for the target terminal; the target operation authority required for the operation instruction is determined; if the target user's operation authority for the target terminal includes the target operation authority, it is determined that the target user has the authority to execute the operation request on the target terminal.
[0130] Figure 8 is a structural diagram of a computer device provided by an optional embodiment of the present invention, such as Figure 8 As shown, the computer device includes: one or more processors 10, memory 20, and interfaces for connecting various components, including high-speed interfaces and low-speed interfaces. Various components utilize different buses to communicate with each other and can be installed on a common mainboard or installed in other ways as needed. The processor can process the instructions executed in the computer device, including instructions stored in the memory or on the memory to display the graphical information of the GUI on an external input / output device (such as, a display device coupled to the interface). In some optional embodiments, if necessary, multiple processors and / or multiple buses can be used together with multiple memories and multiple memories. Equally, multiple computer devices can be connected, and each device provides part of the necessary operations (for example, as a server array, a group of blade servers, or a multi-processor system). Figure 8 A processor 10 is taken as an example.
[0131] The processor 10 may be a central processing unit, a network processor, or a combination thereof. The processor 10 may further include a hardware chip. The hardware chip may be an application-specific integrated circuit, a programmable logic device, or a combination thereof. The programmable logic device may be a complex programmable logic device, a field programmable gate array, a general purpose array logic, or any combination thereof.
[0132] The memory 20 stores instructions that can be executed by at least one processor 10, so as to enable at least one processor 10 to execute the method shown in the above embodiment.
[0133] The memory 20 may include a program storage area and a data storage area, wherein the program storage area may store an operating system and application programs required for at least one function; the data storage area may store data created based on the use of the computer device, etc. In addition, the memory 20 may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some optional embodiments, the memory 20 may optionally include a memory remotely located relative to the processor 10, and these remote memories may be connected to the computer device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0134] The memory 20 may include a volatile memory, such as a random access memory; the memory may also include a non-volatile memory, such as a flash memory, a hard disk or a solid-state drive; the memory 20 may also include a combination of the above types of memory.
[0135] The computer device further includes an input device 30 and an output device 40. The processor 10, the memory 20, the input device 30 and the output device 40 may be connected via a bus or other means. Figure 8 The bus connection is taken as an example.
[0136] The input device 30 can receive input digital or character information and generate key signal input related to user settings and function control of the computer device, such as a touch screen, a keypad, a mouse, a trackpad, a touch pad, an indicator stick, one or more mouse buttons, a trackball, a joystick, etc. The output device 40 can include a display device, an auxiliary lighting device (e.g., an LED), and a tactile feedback device (e.g., a vibration motor). The above-mentioned display device includes but is not limited to a liquid crystal display, a light emitting diode, a display, and a plasma display. In some optional embodiments, the display device can be a touch screen.
[0137] The embodiment of the present invention also provides a computer-readable storage medium. The above-mentioned method according to the embodiment of the present invention can be implemented in hardware, firmware, or implemented as a computer code that can be recorded in a storage medium, or implemented as a computer code that is originally stored in a remote storage medium or a non-temporary machine-readable storage medium and downloaded through a network and will be stored in a local storage medium, so that the method described herein can be stored in such software processing on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only storage memory, a random access memory, a flash memory, a hard disk or a solid-state drive, etc.; further, the storage medium can also include a combination of the above-mentioned types of memory. It can be understood that a computer, a processor, a microprocessor controller or programmable hardware includes a storage component that can store or receive software or computer code. When the software or computer code is accessed and executed by a computer, a processor or hardware, the method shown in the above embodiment is implemented.
[0138] Although the embodiments of the present invention have been described with reference to the accompanying drawings, those skilled in the art may make various modifications and variations without departing from the spirit and scope of the present invention. Such modifications and variations are all within the scope defined by the appended claims.
Claims
1. A method for offline identity authentication and rights management, characterized in that: The method is applied to an identity authentication client, and the method includes: receiving an operation request from a target user for a target terminal, wherein the operation request includes a digital certificate of the target user and an operation instruction of the target user for the target terminal; If the identity authentication client is offline, Verifying the digital certificate of the target user through the first authentication center of the identity authentication client to obtain a legitimacy verification result of the target user; If the target user is determined to be a legitimate user based on the legitimacy verification result of the target user, Determining the target user's operation authority over the target terminal by utilizing the target user's access control list in a USB key, wherein the target user's USB key is generated by an identity authentication server authorizing the target user and the access control list is written into the USB by a second authentication center of the identity authentication server; Determining the target operation authority required for the operation instruction; If the target user's operation authority on the target terminal includes the target operation authority, it is determined that the target user has the authority to execute the operation request on the target terminal.
2. The method according to claim 1, characterized in that If the target user does not have permission to execute the operation request on the target terminal, the method further includes: Determine each user's operating authority for the target terminal based on the access control list in each user's USB key; Determining a management user with authorization authority for the target terminal based on the operation authority of each user for the target terminal; The management user is used to modify the access control list in the target user's USB key so that the access control list in the target user's USB key includes the authority corresponding to the operation instruction.
3. The method according to claim 2, characterized in that If the identity authentication client is online, the method further includes: The access control list in the target user's USB key is sent to the identity authentication server, so that the identity authentication server compares the access control list in the target user's USB key with the access control list of the target user stored in the identity authentication server, and updates the access control list of the target user stored in the identity authentication server through the identity authentication server, or the access control list in the target user's USB key is used to make the access control list of the target user stored in the identity authentication server consistent with the access control list in the target user's USB key.
4. The method according to claim 1, wherein After the step of receiving the operation request of the target user to the target terminal, if it is determined that the identity authentication client is in an online state, the method further includes: The operation request is sent to the identity authentication server, so that the identity authentication server determines the authority of the operation request.
5. An offline identity authentication and rights management system, characterized in that: It includes an identity authentication server and an identity authentication client, wherein the identity authentication server includes a second authentication center and the identity authentication client includes a first authentication center; The identity authentication server is used to determine the operation rights of each user for different terminals, and generate an access control list based on the operation rights of each user for different terminals. The second authentication center writes the operation rights of each user for different terminals into the USB on a user-by-user basis to generate a USB key for each user; The identity authentication client is used to receive an operation request from a target user for a target terminal, the operation request including the digital certificate of the target user and the operation instruction of the target user for the target terminal; if the identity authentication client is offline, the digital certificate of the target user is verified by the first authentication center of the identity authentication client to obtain a legitimacy verification result of the target user; If the target user is determined to be a legitimate user according to the legitimacy verification result of the target user, determining the target user's operation authority on the target terminal using the target user's access control list in the USB key; and determining the target operation authority required for the operation instruction; If the target user's operation authority on the target terminal includes the target operation authority, it is determined that the target user has the authority to execute the operation request on the target terminal.
6. The system according to claim 5, characterized in that If the identity authentication client determines that the target user does not have the authority to execute the operation request on the target terminal, the system further includes: The identity authentication client is further configured to determine, based on an access control list within each user's USB key, each user's operating authority over the target terminal; determine, based on each user's operating authority over the target terminal, a management user with authorized authority over the target terminal; and utilize the management user to modify the access control list within the target user's USB key so that the access control list within the target user's USB key includes authority corresponding to the operating instruction.
7. The system according to claim 6, characterized in that If the identity authentication client is online, the system further includes: The identity authentication client sends the access control list in the target user's USB key to the identity authentication server; The identity authentication server compares the access control list in the target user's USB key with the access control list of the target user stored in the identity authentication server; If the version of the access control list in the target user's USB key is higher than the access control list of the target user stored in the authentication server, update the access control list of the target user stored in the identity authentication server; If the version of the access control list in the target user's USB key is lower than the access control list of the target user stored in the identity authentication server, the second authentication center is used to write the access control list of the target user stored in the identity authentication server into the USB key of the target user.
8. The system according to claim 5, wherein: After the identity authentication client receives the target user's operation request for the target terminal, if it is determined that the identity authentication client is in an online state, the system further includes: The identity authentication client sends the operation request to the identity authentication server; The identity authentication server receives the operation request; verifies the digital certificate of the target user through the second authentication center to obtain the legitimacy verification result of the target user; if the target user is determined to be a legal user based on the legitimacy verification result of the target user, the target user's operation authority on the target terminal is determined using the access control list of the target user stored in the identity authentication server; the target operation authority required for the operation instruction is determined; if the target user's operation authority on the target terminal includes the target operation authority, it is determined that the target user has the authority to execute the operation request on the target terminal.
9. A computer device, characterized in that: include: A memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the method according to any one of claims 1 to 4 by executing the computer instructions.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the method according to any one of claims 1 to 4.
Citation Information
Patent Citations
Information processing method and device
CN110719173A
Digital certificate offline authentication system and method
CN111600718A