Method and apparatus for dynamic access control

By building an access control knowledge graph and using the inference engine module for dynamic access control, the problems of low access control efficiency and poor accuracy in the existing technology are solved, and efficient and accurate access permission management is achieved.

CN119939612APending Publication Date: 2025-05-06ROBERT BOSCH GMBH
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202311460868.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-06
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

When implementing access control in an organization, the prior art requires heavy manual operations, resulting in low efficiency and inaccurate query results, making it difficult to efficiently and accurately manage the access rights of a large number of members.

Method used

By building an access control knowledge graph, dynamically maintaining information related to access control, using the inference engine module to perform inference based on query requests, and returning query results to control access permissions.

Benefits of technology

It realizes efficient and accurate dynamic access control, reduces manual operations, and improves the flexibility and efficiency of access rights management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939612A_ABST
    Figure CN119939612A_ABST
Patent Text Reader

Abstract

The invention provides a method for dynamic access control, which comprises the following steps: receiving a query request which is associated with a specific person in an organization and a target access object to be subjected to access control; reasoning by using an access control knowledge graph based on the query request; and a query result is returned according to the reasoning, and the query result indicates the access authority of the specific personnel to the target access object.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates generally to the field of computers, and more particularly to a method and apparatus for dynamic access control. Background Art

[0002] At present, how to ensure the data security of digital assets owned by organizations (e.g., enterprises, social groups, project teams, etc.) has become a key issue. Access control is a technology commonly used to ensure data security. It can prevent any person from accessing the digital assets of an organization at will, but by assigning corresponding access rights to users, only users with access rights can access the digital assets. Information about access rights allocation can be statically stored in data structures such as tables and lists, and by querying such data structures, it can be determined whether a user is authorized to access a specific digital asset.

[0003] However, with the development of computer technology and the popularization of informatization, organizations usually have a large number of digital assets. In this case, especially for organizations with a large number of members, the way of implementing access control by statically storing access permission allocation information in a data structure such as a table usually involves heavy manual operations and may result in the inability to efficiently and accurately return access permission query results. Therefore, an improved dynamic access control method is needed to improve the efficiency and accuracy of access control for organizations. Summary of the invention

[0004] It is desirable to provide an improved method for dynamic access control. A knowledge graph can be constructed to dynamically maintain information associated with access control within an organization. An application for providing access objects can query the access rights that a specific person within the organization has for a target access object through the knowledge graph, and control the access of the specific person to the target access object based on the query result. In this way, efficient and accurate dynamic access control can be achieved.

[0005] According to one aspect of the present disclosure, a method for dynamic access control is provided, comprising: receiving a query request, the query request being associated with a specific person within an organization and a target access object to which access control is to be performed; performing reasoning using an access control knowledge graph based on the query request; and returning a query result based on the reasoning, wherein the query result indicates the access rights of the specific person to the target access object.

[0006] According to another aspect of the present disclosure, a method for dynamic access control is provided, comprising: sending a query request, the query request being associated with a specific person within an organization and a target access object to which access control is to be performed; receiving a query result, wherein the query result is obtained by reasoning using an access control knowledge graph based on the query request, and the query result indicates the access rights of the specific person to the target access object; and based on the query result, controlling the access of the specific person to the target access object.

[0007] According to another aspect of the present disclosure, a device for dynamic access control is provided, comprising: a memory; and a processor. The processor is coupled to the memory and configured to execute any one of the methods in the various embodiments of the present disclosure.

[0008] According to still another aspect of the present disclosure, a computer-readable medium is provided, which stores a computer program including instructions, and when the instructions are executed by a processor, the processor is configured to perform a method according to any one of the various embodiments of the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0009] Various embodiments of the claimed subject matter will now be described by way of example with reference to the accompanying drawings. In the different drawings, the same reference numerals are used to denote the same or similar components.

[0010] Figure 1 A schematic diagram showing the structure of a system for dynamic access control according to an example embodiment of the present disclosure.

[0011] Figure 2 A schematic diagram showing the structure of an access control knowledge graph according to an example embodiment of the present disclosure is shown.

[0012] Figure 3A-3D A schematic diagram showing four inheritance modes according to an example embodiment of the present disclosure.

[0013] Figure 4A A flowchart of a method for dynamic access control according to an example embodiment of the present disclosure is shown.

[0014] Figure 4B A flowchart of a method for dynamic access control according to an example embodiment of the present disclosure is shown.

[0015] Figure 5 A block diagram of a computing device according to an example embodiment of the present disclosure is shown, and the computing device can implement the above-mentioned method for dynamic access control. DETAILED DESCRIPTION

[0016] In the following description, many specific details are set forth to provide a thorough understanding of the embodiments of the present disclosure. However, those skilled in the relevant art will recognize that the present disclosure can be practiced without one or more of the specific details, or alternative methods, components, etc. can be used to practice the present disclosure. In some instances, well-known structures and operations are not shown or described in detail to avoid unnecessarily obscuring the present disclosure.

[0017] As discussed in the background technology section above, organizations often need to perform access control on digital assets they own in order to achieve data protection for these digital assets. As discussed herein, organizations may refer to enterprises, social groups, project teams, and any other type of organization consisting of a group of members. In addition, the above digital assets may be referred to herein as access objects, which may include, for example, files, programs, services, applications, licenses, and any other tangible or intangible data information that requires access control.

[0018] Access control can be performed by assigning corresponding access rights to members of an organization. By assigning rights, only members who are assigned access rights can access corresponding digital assets. It has been noted that the current commonly used method of implementing access control by assigning corresponding access rights to each member of an organization and statically maintaining access rights assignment information in a data structure such as a table is very inefficient and may result in the inability to provide accurate access rights query results. In response to this, this paper proposes an improved mechanism for dynamic access control to solve at least the above problems.

[0019] Figure 1 FIG. 1 is a schematic diagram showing the structure of a system 100 for dynamic access control according to an example embodiment of the present disclosure. In one example, the system 100 can be used as a personnel access control or management platform of an organization (eg, an enterprise). Figure 1 As shown, the system 100 may include an access control subsystem 102 and an external support subsystem 104. The access control subsystem 102 may be used to implement the core function of the dynamic access control discussed herein, while the external support subsystem 104 may be used to provide the access control subsystem 102 with various external data, service support, and the like.

[0020] The access control subsystem 102 includes an inference engine module 110, which can receive a query request, which can be associated with a specific person in the organization and a target access object to be access controlled. The inference engine module 110 can generate one or more graph query statements applicable to the access control knowledge graph based on the received query request, so as to use the access control knowledge graph to infer whether the specific person has access rights to the target access object and what type of access rights he has. The graph query statement can be based on SPARQL, Cypher, and any other graph query language known in the art or known in the future. For example, the graph query statement may include MATCH, RETURN statements based on the Cypher language, etc. Depending on different user needs (in other words, different query targets), the inference engine module 110 can obtain the required query results by modifying the graph query statement (for example, adjusting the parameter values ​​in the graph query statement).

[0021] The above query request may be generated by the application module 120 in the access control subsystem 102. The application module 120 may be used to provide an access object to be access-controlled within an organization. In other words, members of an organization may perform access operations on access objects through the application module 120. For example, members may view browser pages, edit or view files, access storage space, and the like through the application module 120. In an application scenario, when a specific person attempts to perform an access operation on a target access object through the application module 120, the application module 120 may generate a query request for the specific person and the target access object. In one example, the query request may be generated based on the identification information of the specific person and the target access object. The identification information of the target access object may include, for example, the name, identification number, address, or any other information that may be used to uniquely identify the target access object within an organization. The identification information for a specific person may be any information such as his name, user name, nickname, user ID, etc. that is used to uniquely identify the specific person within an organization. In one example, the identification information of the specific person may be authenticated to ensure the legitimacy and authenticity of the identity of the specific person. Such authentication can be completed by the authentication module 122 in the external support subsystem 104. In this case, through the information interaction between the application module 120 and the authentication module 122, the application module 120 can provide the identification information of the specific person to the authentication module 122, and receive the authenticated identity information of the specific person from the authentication module 122. The application module 120 can further generate a query request for the specific person based on the identity information.

[0022] The application module 120 may send the generated query request to the inference engine module 110. The inference engine module 110 may obtain the query result by inference based on the query request using the access control knowledge graph, and may further return the query result to the application module 120. The returned query result may indicate the access rights of a specific person to the target access object. The application module 120 may further control the access operation of the specific person to the target access object based on the query result. For example, if the query result indicates that the specific person has read permission for the target access object, the application module 120 may allow the specific person to perform a read operation on the target access object; if the query result indicates that the specific person has write permission for the target access object, the application module 120 may allow the specific person to perform a write operation on the target access object; and so on.

[0023] The access control knowledge graph can be stored in the database 112 and can be called by the reasoning engine module 110 to perform reasoning about access rights. As can be understood by those skilled in the art, the knowledge graph can be constructed based on entities and relationships, and the entity can be represented as a node in the knowledge graph, and the relationship can be represented as an edge connected between two nodes in the knowledge graph. The access control knowledge graph discussed herein can be constructed by a graph construction module 114. The graph construction module 114 can construct the access control knowledge graph to include multiple access object nodes and multiple organization nodes. Each access object node can correspond to an access object entity, and each organization node can correspond to an organization entity. Two organization nodes and an organization node and an access object node can be connected by edges to respectively represent the organizational affiliation between the two organization entities and the access rights relationship of an organization entity to an access object entity. In an example aspect, two access object nodes can also be connected by edges to represent the object affiliation between the two access object entities. In the present disclosure, although the relationship between two entities is schematically described, such as the organizational affiliation between two organizational entities, the access permission relationship of an organizational entity to an access object entity, and the object affiliation between two access object entities, it should be understood that the two entities only represent a pair of mutually related entities in the constructed access control knowledge graph. In fact, the access control knowledge graph can be constructed based on the relationship between multiple pairs of entities. In another example aspect, a rule node can be set between the organization node and the access object node, rather than being directly connected by an edge as discussed above. The rule node is used to describe the access permission relationship of the organizational entity to the access object entity. In another example aspect, the access control knowledge graph may also include role nodes corresponding to role entities. The content of the example structure of the access control knowledge graph will be further referenced below. Figure 2 Describe in detail.

[0024] The above entities (including access object entities, organization entities and optional role entities) and relationships (including organizational affiliations and access permission relationships, as well as optional object affiliations) can be defined by the entity and relationship definition module 116 .

[0025] The access object definition submodule 116-1 in the entity and relationship definition module 116 can be used to define access object entities, which correspond to multiple access objects that need to be access controlled (for example, any files, programs, services, applications, licenses, etc.). At the same time, the access object definition submodule 116-1 can also define object subordination. For example, a section of program code can be part of a software, and therefore, the access object entity corresponding to the section of program code can be defined as subordinate to the access object entity corresponding to the software. Accordingly, in the access control knowledge graph constructed by the graph construction module 114, the access object node corresponding to the section of program code can be used as a child node of the access object node corresponding to the software. The hierarchical arrangement of access object nodes can implicitly define the following criteria: the access permission relationship applied to a specific access object node is also applied to the first-level or multi-level child nodes of the specific access object node, as shown below with reference Figure 2 described in further detail.

[0026] The organization definition submodule 116-2 in the entity and relationship definition module 116 can be used to define an organizational entity. An organizational entity can be defined based on the hierarchical structure of the organization. According to the hierarchical structure of the organization, all members of the organization can be divided into various sub-organizations belonging to different levels. In one example, the hierarchical structure of the organization can be divided according to personnel management. For example, the general manager can constitute a sub-organization of the first level, the hardware development manager and the software development manager under the jurisdiction of the general manager can respectively constitute the sub-organization of the second level, and the hardware development engineer under the jurisdiction of the hardware development manager and the software development engineer 1 and the software development engineer 2 under the jurisdiction of the software development manager respectively constitute the sub-organization of the third level. Based on the above hierarchical structure, the organization definition submodule 116-2 can define organizational entities corresponding to sub-organizations of different levels. For example, the general manager can be defined as an organizational entity of the first level, the hardware development manager and the software development manager can be defined as organizational entities of the second level, and the hardware development engineer and the software development engineer 1 and the software engineer 2 can be defined as organizational entities of the third level. Such a hierarchical relationship can be reflected in the access control knowledge graph constructed by the graph construction module 114 as organizational nodes arranged in a hierarchical manner accordingly. At the same time, the organizational affiliation between two organizational entities can be defined by the organization definition submodule 116-2 based on the above-mentioned jurisdictional relationship. In another example, the hierarchical structure of the organization can be divided according to project management. Based on such a division, the process of defining organizational entities and organizational affiliations can be consistent with the above description for personnel management, and will not be described in detail for the sake of brevity and clarity.

[0027] The rule definition submodule 116-3 in the entity and relationship definition module 116 can be used to define the access permission relationship of the organizational entity to the access object entity. It can be defined that the corresponding organizational entity has or does not have access permission to the corresponding access object entity. In one example aspect, the type of access permission relationship can be further defined, such as read permission, write permission, management permission, etc. It can be defined that the corresponding organizational entity has at least one of the above-mentioned multiple types of access permissions to the corresponding access object entity, such as at least one of read permission, write permission, management permission, etc. Among them, the read permission can specify that the organizational entity is authorized to view the content of the access object entity, the write permission can specify that the organizational entity is authorized to edit the access object entity, and the management permission can specify that the organizational entity is authorized to modify the type of access permission relationship applied to the access object entity, for example, modifying the read permission to the write permission.

[0028] In the case of using the Resource Description Framework (RDF) data model to describe various knowledge in the access control knowledge graph, the attribute field can be used to describe the type of the access permission relationship. As discussed above, based on the access permission relationship defined by the rule definition submodule 116-3, the graph construction module 114 can correspondingly establish an edge or rule node connecting the organization node and the access object node in the access control knowledge graph.

[0029] The entity and relationship definition module 116 also includes an optional role definition submodule 116-4, which can be used to define a role entity. The role entity can describe such information: what type of role permissions a member of the organization has for the above-mentioned access permission relationship. The type of role permission can include an administrator role that can modify the access permission relationship of the organizational entity to the access object entity. In one example aspect, the modification of the access permission relationship needs to be approved by the administrator. To this end, the external support subsystem 104 can further include an approval module 126 to implement the above-mentioned approval process. Role types can also include viewing roles, editing roles, etc., wherein the viewing role can only view the access permission relationship, and the editing role can edit the access permission relationship (such editing operations may require the approval of the administrator to take effect). In the access control knowledge graph, the role node corresponding to the role entity can be connected to the rule node, and the edge between the role node and the rule node can describe whether the role entity has the corresponding role permission for the access permission relationship specified by the rule node.

[0030] Based on the above entities and relationships defined by the entity and relationship definition module 116, for example, access object entities and object affiliations, organization entities and organization affiliations, access permission relationships of organization entities to access object entities, and role entities and role permissions, the constructed access control knowledge graph can dynamically maintain information associated with permission allocations of members within the organization. For example, by updating the above relationships, dynamic adjustment of permission allocation information maintained by the access control knowledge graph can be achieved, thereby achieving dynamic access control for specific personnel. Therefore, compared to statically maintaining access permissions for each member in the prior art, for example, manually adjusting the access permissions assigned to each member to achieve adjustment of access permissions, the dynamic access control mechanism disclosed in the present invention has higher flexibility and efficiency.

[0031] The user can directly implement the above-mentioned process of defining entities and relationships using the entity and relationship definition module 116. In addition, the entity and relationship definition module 116 can also extract such entities and relationships from existing external source data. In one example, the extraction of entities and relationships from existing external source data can be completed through an extraction, transformation, and loading (ETL) operation. Figure 1As shown, the entity and relationship definition module 116 can extract such entities and relationships from the external source data provided by the source data providing module 124 in the external support submodule 104. The source data providing module 124 can further include a personnel management submodule 124-1, a project management submodule 124-2, and a role management submodule 124-3, to interact with the corresponding external source database to provide organizational hierarchical architecture information associated with personnel management, organizational hierarchical architecture information associated with project management, and personnel role information. Among them, the personnel role information can be maintained in an access control list (ACL) as known in the art. In the ACL, corresponding roles can be defined for members of the organization. The entities and relationships defined or extracted by the entity and relationship definition module 116 through the above operations can be represented as nodes and edges in the constructed access control knowledge graph. In this case, when the inference engine module 110 receives a query request, a graph query statement can be generated to execute a query using the constructed access control knowledge graph to obtain, for example, a query result about the access rights of a specific person to a target access object.

[0032] In one example aspect, the above-mentioned external source data may be stored in a non-graph data structure such as a table or a list. In this case, the graph construction module 114 may construct the access control knowledge graph to include virtual nodes and edges. In other words, the virtual nodes and edges do not directly describe the entities and relationships themselves, but describe the mapping relationship between the entities and relationships and the external source data provided by the source data providing module 124. In this case, when the inference engine module 110 receives a query request, the constructed access control knowledge graph can be used, and based on the mapping relationship between the entities and relationships maintained by the access control knowledge graph and the external source data, a query is performed to obtain, for example, a query result about the access rights of a specific person to the target access object. After the inference engine module 110 generates a graph query statement based on the query request, the graph construction module 114 may further convert the graph query statement into a query statement that is compatible with the data structure of the external source data, for example, a table query statement such as SQL. Thus, based on the above-mentioned mapping relationship maintained in the access control knowledge graph and the converted table query statement, the corresponding table data can be further retrieved in the external source database. Then, the graph construction module 114 can convert the retrieved table data into graph data, and generate query results based on the converted graph data through the inference engine module 110. Compared with directly extracting entities and relationships from an external source database, maintaining the above mapping relationships in the access control knowledge graph can avoid potential adverse effects caused by the lag in graph data updates. For example, the information in the external source database has been updated (for example, the organizational affiliation of a specific person has changed), but the relevant knowledge in the access control knowledge graph has not been updated in time, resulting in inaccurate query results obtained using the access control knowledge graph.

[0033] Figure 1 The various components (e.g., subsystems, modules, submodules, etc.) in the example structure shown can be embodied as independently operated applications, services, etc., and information interaction between each other can be achieved through an application programming interface (API). Alternatively, these components can also be embodied as various functional modules in a complete application, service, etc., and information interaction between each other can be achieved through underlying data calls, etc. In such a case, the application or service, etc. can be used as a whole to implement the complete process of using the access control knowledge graph discussed above to query the access rights of a specific person to the target access object, and to control the access of the specific person to the target access object based on the query process. In addition, it should be noted that the structure of the system 100 discussed above is only exemplary. As can be imagined by those skilled in the art, the system 100 can adopt different arrangements, for example, including more or fewer modules and submodules than shown, without departing from the scope of the present disclosure.

[0034] Figure 2A schematic diagram showing the structure of an access control knowledge graph according to an example embodiment.

[0035] exist Figure 2 In order to more clearly illustrate the example structure of the access control knowledge graph, the access control knowledge graph is divided into different parts. Among them, the graph structure associated with access objects and rules is shown in box 202, the graph structure associated with organizational information based on personnel management is shown in box 204, the graph structure associated with organizational information based on project management is shown in box 206, and the graph structure associated with role information is shown in box 208.

[0036] In the boxes 204 and 206, multiple organization nodes (represented by circles) arranged in a hierarchy are shown respectively. In the box 204, six organization nodes 204-1 to 204-6 at three levels are shown. Figure 1 In the example of detailed description, the first level includes the organization node 204-1 corresponding to the general manager. The second level includes the organization node 204-2 corresponding to the manager of the hardware development department and the organization node 204-3 corresponding to the manager of the software development department. The third level includes the organization node 204-4 corresponding to the hardware development engineer and the organization node 204-5 corresponding to the software development engineer 1 and the organization node 204-6 corresponding to the software development engineer 2. At the same time, the edge between two organization nodes ( Figure 2 The arrowed connecting line in box 204) indicates that the corresponding two sub-organizations have a subordinate relationship. In such a hierarchical arrangement, for a current organization node (e.g., 204-3), the organization node at the upper level (e.g., 204-1) having a connection relationship with it can be called the parent node of the current organization node, and the organization node at the lower level (e.g., 204-5) having a connection relationship with it can be called the child node of the current organization node. In box 206, in a manner similar to that in box 204, an example of the hierarchically arranged organization nodes constructed and the edges connecting two organization nodes when representing the organizational hierarchy by project management is shown, and is omitted here for the sake of brevity of description. It should be noted that although in Figure 2 , a box 204 associated with personnel management and a box 206 associated with project management are shown at the same time, but it should be understood that the access control knowledge graph may also only include information associated with personnel management, or only include information associated with project management.

[0037] In box 202, a plurality of access object nodes (represented by rectangles and labeled 202-1 to 202-5) and a plurality of rule nodes (represented by squares and labeled "R1" and "R2") corresponding to the access rights relationship that the organization entity has for the access object entity are shown. The rule node may specify the type of access rights, for example, R1 may correspond to management rights, R2 may correspond to read rights, and so on. Each rule node may be connected between an organization node and an access object node. Figure 2 As shown, rule node R1 can be connected between organization node 204-3 and access object node 202-1, indicating that the organization entity corresponding to organization node 204-3 has management authority for the access object entity corresponding to access object node 202-1. In addition, multiple organization nodes can be connected to same rule node simultaneously. For example, rule node R1 is also connected between another organization node 206-1 and access object node 202-1, which similarly indicates that the organization entity corresponding to organization node 206-1 has management authority for the access object entity corresponding to access object node 202-1.

[0038] In addition, if Figure 2 As shown in box 202 in the figure, multiple access object nodes can be arranged in a dispersed manner so that two access object nodes are not connected by an edge, that is, there is no relationship between the corresponding two access object entities, as shown in access object nodes 202-1, 202-4 and 202-5. Alternatively, the access object nodes can also be arranged in a hierarchical manner. For example, access object node 202-2 and access object node 202-3 are connected to access object node 202-1 by an edge, indicating that access object node 202-2 and access object node 202-3 are subordinate to access object node 202-1. This hierarchical arrangement can implicitly define the access permission relationship applied to access object node 202-1 (represented as management permission by rule node R1) as also applied to one or more levels (if there are more levels) of child nodes of access object node 202-1, for example, access object node 202-2 and access object node 202-3. In other words, based on Figure 2 The example structure of the access control knowledge graph shown can infer that the organization entity corresponding to the organization node 204-3 also has management authority over the access object entity corresponding to the access object node 202-2 / access object node 202-3.

[0039] exist Figure 2 The role node 208-1 is shown in the box 208 of FIG. 2 , which may correspond to the role entity (e.g., the administrator role) described above. The role node 208-1 may be connected to the rule node R1 via an edge. Figure 2In the case where the organization node 204-3 and the role node 208-1 are connected to the rule node R1 at the same time, the connection between the organization node 204-3 and the rule node R1 and the connection between the role node 208-1 and the rule node R1 conform to the logical relationship of AND. More specifically, based on the structure shown, it can be inferred that only personnel who belong to the sub-organization corresponding to the organization node 204-3 and who also have the administrator role can modify the access permission relationship specified by the rule node R1.

[0040] In one example, the connection relationship between the organization node and the rule node (embodied as an edge between the two nodes) can be further defined to have different inheritance modes. The inheritance mode can be embodied in the access control knowledge graph as an attribute of the edge.

[0041] Figure 3A-3D Schematic diagram showing four example inheritance modes according to an example embodiment of the present disclosure. Figure 3A-3D In FIG. 1 , an organizational node is represented by a circle, and a regular node is represented by a square. It should be understood that for convenience, Figure 3A-3D Only a portion of a complete access control knowledge graph is shown, and the complete access control knowledge graph may include multiple rule nodes and multiple organization nodes.

[0042] The first inheritance mode is the bidirectional inheritance mode, such as Figure 3A shown. Figure 3A It includes six organization nodes 301-1 to 301-6 and one rule node 302, and the organization node 301-2 is connected to the rule node 302. For the convenience of description, the rule node 302 can be called the first rule node, and the organization node 301-2 connected to the rule node 302 can be called the first organization node. It should be understood that the "first" rule node here is only used to distinguish one rule node from other rule nodes without any order limitation. Similarly, the "first" organization node is only used to distinguish one organization node from other organization nodes without any order limitation. In addition, Figure 3A The parent node 301-1 of the organization node 301-2 and the child nodes 301-4 and 301-5 of the organization node 301-2 are shown. The bidirectional inheritance mode indicates that the connection relationship between the first organization node and the first rule node is inherited by the parent node and the child node of the first organization node. In other words, based on the connection relationship between the organization node 301-2 and the rule node 302, and the connection relationship is in the bidirectional inheritance mode, it can be inferred that the parent node 301-1 and the child nodes 301-4 and 301-5 of the organization node 301-2 also implicitly have a connection relationship with the rule node 302 (such as Figure 3A , as shown by the dashed edge in FIG.

[0043] The second inheritance mode is an upward inheritance mode, which indicates that the connection relationship between the first organization node and the first rule node is inherited only by the parent node of the first organization node, such as Figure 3B In other words, based on the fact that the first organization node has a connection relationship with the first rule node, and the connection relationship is in an upward inheritance mode, it can be inferred that the parent node of the first organization node has an implicit connection relationship with the first rule node (such as Figure 3B , as shown by the dashed edge in FIG.

[0044] The third inheritance mode is the downward inheritance mode, which indicates that the connection relationship between the first organization node and the first rule node is inherited only by the child nodes of the first organization node. In other words, based on the connection relationship between the first organization node and the first rule node, and the connection relationship is in the downward inheritance mode, it can be inferred that the child nodes of the organization node and the rule node implicitly have a connection relationship (such as Figure 3C , as shown by the dashed edge in FIG.

[0045] The fourth inheritance mode is the no inheritance mode, which indicates that the connection relationship between the organization node and the rule node is not inherited by the parent node or child node of the organization node. Figure 3D As shown, based on the connection relationship between the organization node and the rule node, and the connection relationship is in a non-inheritance mode, it is not inferred that the parent node and / or child node of the organization node has an implicit connection relationship with the rule node.

[0046] Such an inheritance model can more efficiently describe the access rights that an organization entity has to an access object entity. For example, in the knowledge graph, the access rights that an organization entity has to an access object can be maintained only for higher-level organization entities or fewer organization entities, rather than for each organization member.

[0047] Figure 4A and Figure 4B Flowcharts of a method for dynamic access control according to an example embodiment of the present disclosure are respectively shown.

[0048] in, Figure 4A The process of using the access control knowledge graph to query the access rights of a specific person for a target access object is described, and can therefore be referred to as an operation performed on the query side. Figure 4B The operation of performing access control on the target access object according to the query result is described, and thus it can be referred to as an operation performed on the access control side.

[0049] Combine the following Figure 4A To describe the operations performed on the query side. In one example, Figure 4A The method steps shown can be combined as above Figure 1 The inference engine module 110 described above is executed.

[0050] In step S402, a query request may be received. The query request may be associated with a specific person in the organization and a target access object to be access controlled. Figure 1 As discussed, the above query request may be generated by the application module 120 and transmitted to the inference engine module 110 .

[0051] In step S404, reasoning may be performed using an access control knowledge graph based on the query request. An access control knowledge graph may be constructed based on multiple entities and the relationship between two entities among the multiple entities. The multiple entities may include multiple access object entities, multiple organization entities, and the multiple access object entities correspond to multiple access objects to be access controlled, and the multiple organization entities correspond to multiple sub-organizations of different levels into which the organization is divided. The relationship may include an organizational subordination relationship between two organization entities among the multiple organization entities, and an access permission relationship between a corresponding organization entity among the multiple organization entities and a corresponding access object entity among the multiple access object entities. The multiple entities may further include at least one role entity, so that the relationship may further include a corresponding role permission of the corresponding role entity for the access permission relationship. The relationship may also include an object subordination relationship between two access object entities among the multiple access object entities. As shown in reference Figure 1 As discussed, the above entities and relationships may be defined by the entity and relationship definition module 116 or extracted from external source data. Based on the above entities and relationships, the graph construction module 114 may construct an access control knowledge graph by representing such entities and relationships as nodes and edges in the access control knowledge graph.

[0052] In step S406, the query result may be returned based on the inference. The query result may indicate the access rights of the specific person to the target access object. Figure 1 As discussed, the reasoning engine module 110 may provide the query result to the application module 120, so that the application module 120 may control the access of a specific person to the target access object based on the query result.

[0053] Combine the following Figure 4B To describe the content of the operation performed on the access control side. In one example, Figure 4B The method steps shown can be combined as above Figure 1 The described application module 120 is executed.

[0054] In step S408, a query request may be sent. The query request may be associated with a specific person in the organization and a target access object to be access controlled. Figure 1 As discussed above, the query request may be generated by the application module 120 and transmitted to the inference engine module 110. In one example, the inference engine module 110 may perform the above combined Figure 4A The step S402 discussed is to receive the query request.

[0055] In step S410, a query result may be received. The query result may be obtained by reasoning based on the query request using the access control knowledge graph, and may indicate the access rights of a specific person to the target access object. Figure 1 As discussed above, the query result may be generated by the inference engine module 110 and returned to the application module 120. In one example, the query result may be generated by the inference engine module 110 and returned to the application module 120. Figure 4A Obtained from step S404 discussed above.

[0056] In step S412, based on the query result, the access of a specific person to the target access object can be controlled. Figure 1 As discussed above, the application module 120 may control the access operation of the specific person to the target access object based on the query result. For example, if the query result indicates that the specific person has read permission for the target access object, the application module 120 may allow the specific person to perform a read operation on the target access object; if the query result indicates that the specific person has write permission for the target access object, the application module 120 may allow the specific person to perform a write operation on the target access object; and so on.

[0057] Figure 5 A block diagram of a computing device according to an example embodiment of the present disclosure is shown, and the computing device can implement the above-mentioned method for dynamic access control.

[0058] The example computing device 500 includes an internal communication bus 502 and a processor (e.g., a central processing unit (CPU)) 504 connected to the internal communication bus 502, the processor 504 being used to execute instructions stored in a memory 506 to implement the method for dynamic access control described in detail above. The memory 506 is suitable for tangibly embodying computer program instructions and data, and can include various forms of memory, including, for example, semiconductor memory devices such as EPROM, EEPROM, and flash memory devices; magnetic disks such as internal hard disks and removable disks; magneto-optical disks; and CD-ROM disks, etc. The computing device 500 may also include an input / output (I / O) interface 508, so that various I / O devices (e.g., a cursor control device such as a mouse, a keyboard, etc.) can be coupled to the computing device 500 through the I / O interface 508 to allow a user to apply various commands and input data. The computing device 500 may also include a display unit 510 for displaying a graphical user interface.

[0059] The computer program may include instructions that can be executed by a computer, and the instructions are used to cause the processor 504 of the computing device 500 to perform the method for dynamic access control disclosed in the present invention. The program can be recorded on any data storage medium including a memory. For example, the program can be implemented in digital electronic circuits, or in computer hardware, firmware, software, or a combination thereof. The process / method steps described in the present disclosure can be performed by a programmable processor that executes program instructions to perform methods, steps, operations by operating on input data and generating output.

[0060] In addition to what is described herein, various modifications may be made to the disclosed embodiments and implementations of the present invention without departing from the scope of the disclosed embodiments and implementations of the present invention. Therefore, the descriptions and examples herein should be interpreted as illustrative rather than limiting. The scope of the present invention should be measured only by reference to the claims.

Claims

1. A method for dynamic access control, comprising: receiving a query request, wherein the query request is associated with a specific person in the organization and a target access object to be access controlled; Based on the query request, reasoning is performed using the access control knowledge graph; as well as A query result is returned according to the reasoning, wherein the query result indicates the access rights of the specific person to the target access object.

2. The method according to claim 1, wherein: The access control knowledge graph is constructed based on a plurality of entities and a relationship between two entities among the plurality of entities, and wherein: The multiple entities include multiple access object entities and multiple organization entities, the multiple access object entities correspond to multiple access objects to be access controlled, the multiple access objects include the target access object, and the multiple organization entities correspond to multiple sub-organizations of different levels into which the organization is divided; and The relationships include: an organizational affiliation between two organizational entities among the plurality of organizational entities; and The access authority relationship between a corresponding organizational entity among the plurality of organizational entities and a corresponding access object entity among the plurality of access object entities.

3. The method according to claim 2, wherein: The plurality of entities further includes at least one role entity; and The relationship further includes at least one of the following: corresponding role permissions of a corresponding role entity in the at least one role entity for the access permission relationship; and An object dependency relationship between two access object entities among the plurality of access object entities.

4. The method according to claim 3, wherein: The access control knowledge graph includes a plurality of access object nodes corresponding to the plurality of access object entities, a plurality of organization nodes corresponding to the plurality of organization entities, and at least one role node corresponding to the at least one role entity; and In the access control knowledge graph: The organizational affiliation is represented as an edge connecting two organizational nodes corresponding to the two organizational entities; The access right relationship is represented as a rule node connected between an organization node corresponding to the corresponding organization entity and an access object node corresponding to the corresponding access object entity; The object affiliation is represented as an edge connecting two access object nodes corresponding to the two access object entities; and The corresponding role permissions are represented as edges connecting between a role node corresponding to the corresponding role entity and a rule node corresponding to the access permission relationship.

5. The method according to claim 4, wherein: The rule node in the access control knowledge graph further specifies the type of the access permission relationship; and The type of the access permission relationship includes at least one of management permission, read permission and write permission.

6. The method according to claim 4, wherein: The query result is derived based on an inheritance pattern for a connection relationship between a first organization node among the plurality of organization nodes and a first rule node among the plurality of rule nodes; and The inheritance mode includes one of the following: a bidirectional inheritance mode, which indicates that the connection relationship between the first organization node and the first rule node is inherited by the parent node and the child node of the first organization node; An upward inheritance mode, which indicates that the connection relationship between the first organization node and the first rule node is inherited only by the parent node of the first organization node; A downward inheritance mode, which indicates that the connection relationship between the first organization node and the first rule node is inherited only by child nodes of the first organization node; as well as There is no inheritance mode, which indicates that the connection relationship between the first organization node and the first rule node is not inherited by the parent node or child node of the first organization node.

7. The method according to claim 1, wherein: Based on the query request, reasoning using the access control knowledge graph includes: Based on the query request, generating one or more graph query statements applicable to the access control knowledge graph; and The access rights of the specific person to the target access object are inferred based on the graph query statement.

8. The method according to claim 7, wherein: The plurality of entities and relationships used to construct the access control knowledge graph are extracted from external source data; and The access control knowledge graph includes virtual nodes and edges, and the virtual nodes and edges describe the mapping relationship between the multiple entities and the relationships and external source data.

9. The method according to claim 8, wherein: Based on the query request, reasoning using the access control knowledge graph further includes: Converting the one or more graph query statements into table query statements applicable to the data structure of the external source data; and Based on the converted table query statement, corresponding table data is retrieved from the external source data.

10. The method according to claim 1, wherein: Also includes: Based on the query result, the access of the specific person to the target access object is controlled.

11. A method for dynamic access control, comprising: Sending a query request, wherein the query request is associated with a specific person in the organization and a target access object to be access controlled; Receiving a query result, wherein the query result is obtained by reasoning using an access control knowledge graph based on the query request, and the query result indicates access rights of the specific person to the target access object; as well as Based on the query result, the access of the specific person to the target access object is controlled.

12. The method according to claim 11, wherein: The method is used on the access control side, and the query result is obtained on the query side by reasoning using the access control knowledge graph based on the query request.

13. The method according to claim 11, wherein: The access control knowledge graph is constructed based on a plurality of entities and a relationship between two entities among the plurality of entities, and wherein: The multiple entities include multiple access object entities and multiple organization entities, the multiple access object entities correspond to multiple access objects to be access controlled, the multiple access objects include the target access object, and the multiple organization entities correspond to multiple sub-organizations of different levels into which the organization is divided; and The relationships include: an organizational affiliation between two organizational entities among the plurality of organizational entities; and The access authority relationship between a corresponding organizational entity among the plurality of organizational entities and a corresponding access object entity among the plurality of access object entities.

14. The method according to claim 13, wherein: The plurality of entities further includes at least one role entity; and The relationship further includes at least one of the following: corresponding role permissions of a corresponding role entity in the at least one role entity for the access permission relationship; and An object dependency relationship between two access object entities among the plurality of access object entities.

15. The method according to claim 14, wherein: The access control knowledge graph includes a plurality of access object nodes corresponding to the plurality of access object entities, a plurality of organization nodes corresponding to the plurality of organization entities, and at least one role node corresponding to the at least one role entity; and In the access control knowledge graph: The organizational affiliation is represented as an edge connecting two organizational nodes corresponding to the two organizational entities; The access right relationship is represented as a rule node connected between an organization node corresponding to the corresponding organization entity and an access object node corresponding to the corresponding access object entity; The object affiliation is represented as an edge connecting two access object nodes corresponding to the two access object entities; and The corresponding role permissions are represented as edges connecting between a role node corresponding to the corresponding role entity and a rule node corresponding to the access permission relationship.

16. The method of claim 15, wherein: The rule node in the access control knowledge graph further specifies the type of the access permission relationship; and The type of the access permission relationship includes at least one of management permission, read permission and write permission.

17. The method of claim 16, wherein: The query result is derived based on an inheritance pattern for a connection relationship between a first organization node among the plurality of organization nodes and a first rule node among the plurality of rule nodes; and The inheritance mode includes one of the following: a bidirectional inheritance mode, which indicates that the connection relationship between the first organization node and the first rule node is inherited by the parent node and the child node of the first organization node; An upward inheritance mode, which indicates that the connection relationship between the first organization node and the first rule node is inherited only by the parent node of the first organization node; A downward inheritance mode, which indicates that the connection relationship between the first organization node and the first rule node is inherited only by child nodes of the first organization node; as well as There is no inheritance mode, which indicates that the connection relationship between the first organization node and the first rule node is not inherited by the parent node or child node of the first organization node.

18. The method of claim 11, wherein: The plurality of entities and relationships used to construct the access control knowledge graph are extracted from external source data; and The access control knowledge graph includes virtual nodes and edges, and the virtual nodes and edges describe the mapping relationship between the multiple entities and the relationships and external source data.

19. A device for dynamic access control, comprising: Memory; as well as A processor, coupled to the memory, configured to perform the method according to any one of claims 1-10 or any one of claims 11-18.

20. A computer readable medium storing a computer program comprising instructions which, when executed by a processor, cause the processor to be configured to perform a method according to any one of claims 1-10 or any one of claims 11-18.

Citation Information

Cited By

  • Quantum encryption transmission and knowledge graph fused data security system

    CN122001583A