Identity authentication method and device based on identity center

By introducing an identity authentication method based on the identity center in the identity authentication system, and using policy components and functional components for continuous authentication and dynamic permission adjustment, the problems of insufficient flexibility of identity authentication and static security policies in the existing technology are solved, and higher security and flexibility are achieved.

CN119961903APending Publication Date: 2025-05-09BEIJING YUANJIAN INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510053156.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-14
Publication Date
2025-05-09

Smart Images

  • Figure CN119961903A_ABST
    Figure CN119961903A_ABST
Patent Text Reader

Abstract

The invention provides an identity authentication method and device based on an identity center, and the method and device are applied to an identity authentication system which comprises an access object, a strategy component and a function component. The identity authentication method comprises the following steps: in response to an access request initiated by an access subject to an access object, calling a function component based on a policy component to perform continuous authentication on the access subject based on identity information of the access subject, and adjusting an access permission corresponding to the access subject according to an authentication result, and in response to sending a resource request to the policy component by the access object, judging whether the resource request is legal based on the resource request, and if so, controlling the access subject to access the target resource of the corresponding access object based on the access request.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of data processing technology, and in particular, to an identity authentication method and device based on an identity center. Background Art

[0002] With the rapid development of modern information technology, it is often necessary to manage user permissions when users access system resources to ensure access security.

[0003] Currently, static permission management of users is mainly performed through two widely used access control models: role-based access control (RBAC) and attribute-based access control (ABAC).

[0004] However, for the two current access control models, the flexibility of the identity authentication process is average, and the security policies are mostly static settings, which are difficult to adapt to rapidly changing security needs and security threats. In addition, the lack of a continuous authentication mechanism makes it difficult to adjust user access rights in real time, making the system security average. Summary of the invention

[0005] In view of this, the purpose of the present application is to provide an identity authentication method and device based on an identity center, which can continuously authenticate the identity information of the access subject by calling the functional component based on the policy component, and adjust the access rights corresponding to the access subject according to the authentication result, thereby realizing a more dynamic and adaptive identity authentication mechanism, improving the flexibility of the identity authentication process, adapting to rapidly changing security requirements and security threats, and continuously authenticating the user's identity, further improving flexibility and system security.

[0006] In a first aspect, an embodiment of the present application provides an identity authentication method based on an identity hub, which is applied to an identity authentication system, wherein the identity authentication system includes an access object, a policy component, and a functional component; the method includes:

[0007] In response to the access subject initiating an access request to the access object, the function component is called based on the policy component to continuously authenticate the access subject based on the identity information of the access subject, and adjust the access rights corresponding to the access subject according to the authentication result; wherein the identity information includes at least user identity, device identity, application identity and service identity;

[0008] In response to the access object sending a resource request to the policy component, determining whether the resource request is legal based on the resource request;

[0009] If so, the access subject is controlled to access the corresponding target resource of the access object based on the access request; wherein the different data sources of the target resource of the access object include at least data, equipment, information system, application software, service and functional interface.

[0010] In a possible implementation, the policy component includes a policy execution point and a policy decision point; the policy decision point includes a policy engine and a policy manager; the continuous authentication of the access subject based on the identity information of the access subject to obtain a corresponding authentication result includes:

[0011] In response to the access subject sending the access request to the policy enforcement point, the policy enforcement point forwards the access request to the policy decision point for verification;

[0012] The policy decision point makes a decision on the access request according to the policy information in the policy manager and the identity information to assign a corresponding decision result;

[0013] The policy enforcement point performs corresponding access control operations based on the decision result of the policy decision point.

[0014] In a possible implementation, the method further includes:

[0015] Determining whether the access object meets the preset target re-authentication conditions;

[0016] If so, the access object is re-authenticated based on the policy decision point and the policy execution point to ensure that the subject identity continues to be credible.

[0017] In a possible implementation, the method further includes:

[0018] Associating and analyzing target resources of different data sources of the access object, continuously evaluating the trustworthiness of the access subject, and obtaining the credit score of the access subject;

[0019] The access rights of the access subject are dynamically adjusted based on the credit score.

[0020] In a possible implementation manner, the continuously evaluating the trustworthiness of the access subject to obtain the credit score of the access subject includes:

[0021] Acquire multi-dimensional behavior data of the access object in real time, and construct a behavior feature library of the access object based on the behavior data; wherein the multi-dimensional behavior data at least includes login frequency, usage habits, and operation mode;

[0022] Based on the behavior feature library and a preset machine learning algorithm, the abnormal behavior of the access object is identified, and the trust score of the access subject is determined in real time based on the abnormal behavior; wherein the abnormal behavior is abnormal behavior that deviates significantly from a preset normal behavior pattern.

[0023] In a possible implementation, the functional component includes an environment perception component; and the method further includes:

[0024] Based on the environment perception component, the operating environment of the access subject is continuously monitored in real time;

[0025] The access rights of the access subject are continuously adjusted based on the operating environment and the behavior data.

[0026] In a possible implementation, the method further includes:

[0027] Acquire the user attributes of the access subject; wherein the user attributes at least include user role and department;

[0028] The access authority of the access subject is adjusted based on the user attributes and the operating environment.

[0029] In a second aspect, an embodiment of the present application further provides an identity authentication device based on an identity center, which is applied to an identity authentication system, wherein the identity authentication system includes an access object, a policy component, and a functional component; the identity authentication device includes:

[0030] A first authentication module, configured to respond to an access request initiated by an access subject to the access object, call the function component based on the policy component to continuously authenticate the access subject based on the identity information of the access subject, and adjust the access rights corresponding to the access subject according to the authentication result; wherein the identity information includes at least a user identity, a device identity, an application identity, and a service identity;

[0031] A first judgment module, configured to respond to the access object sending a resource request to the policy component and judge whether the resource request is legal based on the resource request;

[0032] An access module is used to control the access subject to access the target resource of the corresponding access object based on the access request; wherein the different data sources of the target resource of the access object include at least data, equipment, information system, application software, service and functional interface.

[0033] In a possible implementation manner, the policy component includes a policy execution point and a policy decision point; the policy decision point includes a policy engine and a policy manager; the first authentication module is specifically used to:

[0034] In response to the access subject sending the access request to the policy enforcement point, the policy enforcement point forwards the access request to the policy decision point for verification;

[0035] The policy decision point makes a decision on the access request according to the policy information in the policy manager and the identity information to assign a corresponding decision result;

[0036] The policy enforcement point performs corresponding access control operations based on the decision result of the policy decision point.

[0037] In a possible implementation manner, the identity authentication device based on the identity center further includes:

[0038] A second judgment module is used to judge whether the access object meets the preset target re-authentication condition;

[0039] The second authentication module is used to re-authenticate the access object based on the policy decision point and the policy execution point to ensure that the subject identity continues to be credible.

[0040] In a possible implementation manner, the identity authentication device based on the identity center further includes:

[0041] An evaluation module, used to associate and analyze target resources of different data sources of the access object, continuously evaluate the trustworthiness of the access subject, and obtain the credit score of the access subject;

[0042] The first adjustment module is used to dynamically adjust the access rights of the access subject based on the credit score.

[0043] In a possible implementation manner, the evaluation module is specifically used to:

[0044] Acquire multi-dimensional behavior data of the access object in real time, and construct a behavior feature library of the access object based on the behavior data; wherein the multi-dimensional behavior data at least includes login frequency, usage habits, and operation mode;

[0045] Based on the behavior feature library and a preset machine learning algorithm, the abnormal behavior of the access object is identified, and the trust score of the access subject is determined in real time based on the abnormal behavior; wherein the abnormal behavior is abnormal behavior that deviates significantly from a preset normal behavior pattern.

[0046] In a possible implementation, the functional component includes an environment perception component; and the identity authentication device based on the identity center further includes:

[0047] A monitoring module, used for continuously monitoring the operating environment of the access subject in real time based on the environment perception component;

[0048] The second adjustment module is used to continuously adjust the access rights of the access subject based on the operating environment and the behavior data.

[0049] In a possible implementation manner, the identity authentication device based on the identity center further includes:

[0050] An acquisition module, used to acquire user attributes of the access subject; wherein the user attributes at least include user role and department;

[0051] The third adjustment module is used to adjust the access rights of the access subject based on the user attributes and the operating environment.

[0052] In the third aspect, an embodiment of the present application provides an electronic device, comprising: a processor, a storage medium and a bus, wherein the storage medium stores machine-readable instructions executable by the processor, and when the electronic device is running, the processor communicates with the storage medium through the bus, and the processor executes the machine-readable instructions to perform the steps of the identity authentication method based on the identity center as described in any one of the first aspects.

[0053] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the identity authentication method based on the identity center as described in any one of the first aspects are executed.

[0054] An embodiment of the present application provides an identity authentication method and device based on an identity center. In response to an access subject initiating an access request to an access object, a function component is called based on a policy component to continuously authenticate the access subject based on the identity information of the access subject, and the corresponding access rights of the access subject are adjusted according to the authentication result. In response to the access object sending a resource request to the policy component, whether the resource request is legal is determined based on the resource request. If so, the access subject is controlled to access the target resource of the corresponding access object based on the access request. In the present application, a more dynamic and adaptive identity authentication mechanism is implemented by continuously authenticating the identity information of the access subject through calling a function component based on a policy component, and the corresponding access rights of the access subject are adjusted according to the authentication result, thereby improving the flexibility of the identity authentication process, being able to adapt to rapidly changing security requirements and security threats, and being able to continuously authenticate the identity of the user, further improving flexibility and system security.

[0055] In order to make the above-mentioned objects, features and advantages of the present application more obvious and easy to understand, preferred embodiments are specifically cited below and described in detail with reference to the attached drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0056] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments will be briefly introduced below. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.

[0057] Figure 1 is a flow chart of an identity authentication method based on an identity hub according to an embodiment of the present application;

[0058] Figure 2 This is a schematic diagram of the identity authentication process based on the identity hub;

[0059] Figure 3 is a flow chart of an identity authentication method based on an identity hub according to another embodiment of the present application;

[0060] Figure 4 is a structural diagram of an identity authentication device based on an identity center according to an embodiment of the present application;

[0061] Figure 5 It is a schematic diagram of the structure of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION

[0062] To make the purpose, technical scheme and advantages of the embodiments of the present application clearer, the technical scheme in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. It should be understood that the drawings in the present application only serve the purpose of explanation and description and are not used to limit the scope of protection of the present application. In addition, it should be understood that the schematic drawings are not drawn in real proportion. The flowchart used in this application shows the operations implemented according to some embodiments of the present application. It should be understood that the operations of the flowchart can be implemented out of sequence, and the steps without logical context can be reversed in order or implemented simultaneously. In addition, those skilled in the art can add one or more other operations to the flowchart under the guidance of the content of the present application, or remove one or more operations from the flowchart.

[0063] In addition, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. The components of the embodiments of the present application described and shown in the drawings here can be arranged and designed in various configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the application claimed for protection, but merely represents the selected embodiments of the present application. Based on the embodiments of the present application, all other embodiments obtained by those skilled in the art without making creative work belong to the scope of protection of the present application.

[0064] It should be noted that the term "comprising" will be used in the embodiments of the present application to indicate the existence of the features declared thereafter, but does not exclude the addition of other features.

[0065] Taking into account the rapid development of modern information technology, when users access system resources, it is often necessary to manage user permissions to ensure access security.

[0066] Currently, static user permissions are managed mainly through two widely used access control models: role-based access control (RBAC) and attribute-based access control (ABAC). However, for these two current access control models, the flexibility of the identity authentication process is average, and security policies are mostly static settings, which are difficult to adapt to rapidly changing security needs and security threats. In addition, the lack of a continuous authentication mechanism makes it difficult to adjust user access rights in real time, making the system security average.

[0067] To address this problem, the present application provides an identity authentication method and device based on an identity center, which continuously authenticates the identity information of the access subject by calling the functional component based on the policy component, and adjusts the access rights corresponding to the access subject according to the authentication result, thereby realizing a more dynamic and adaptive identity authentication mechanism, improving the flexibility of the identity authentication process, and being able to adapt to rapidly changing security requirements and security threats. It can also continuously authenticate the user's identity, further improving flexibility and system security.

[0068] Figure 1 The flowchart of the identity authentication method based on the identity center according to one embodiment of the present application is applied to the identity authentication system, which includes an access object, a policy component and a functional component. Figure 1 As shown, the identity authentication method based on the identity center in the embodiment of the present application may specifically include:

[0069] S101. In response to an access subject initiating an access request to an access object, a policy component calls a functional component to continuously authenticate the access subject based on the identity information of the access subject, and adjusts the access rights corresponding to the access subject according to the authentication result.

[0070] S102: In response to the access object sending a resource request to the policy component, determine whether the resource request is legal based on the resource request.

[0071] S103: If yes, control the access subject to access the target resource of the corresponding access object based on the access request.

[0072] In the above-mentioned identity authentication method based on the identity center, the identity information of the access subject is continuously authenticated by calling the functional component based on the policy component, and the access rights corresponding to the access subject are adjusted according to the authentication results, thereby realizing a more dynamic and adaptive identity authentication mechanism, improving the flexibility of the identity authentication process, and being able to adapt to rapidly changing security requirements and security threats. In addition, the user's identity can be continuously authenticated, further improving flexibility and system security.

[0073] The above exemplary steps of the embodiment of the present application are described below with reference to specific examples:

[0074] S101, in response to an access subject initiating an access request to an access object, a policy component calls a function component to continuously authenticate the access subject based on the identity information of the access subject, and adjusts the access rights corresponding to the access subject according to the authentication result.

[0075] It should be noted that the access object refers to the object where the resource accessed by the access subject is located, the policy component is the component that performs policy management on the access request of the access subject, and the functional component is the component with various functions. Figure 2 As shown, the core component is the strategy component, and the supporting component is the functional component.

[0076] In the embodiment of the present application, the access subject is the subject that initiates the access request, and the identity information of the access subject includes at least the user identity, device identity, application identity and service identity, for example, Figure 2 As shown; the identity information includes at least user identity, device identity, application identity and service identity; when the access subject initiates an access request to the access object, the policy component calls the functional component to continuously authenticate the access subject based on the access subject's identity information, and adjusts the access rights corresponding to the access subject according to the authentication result.

[0077] It should be noted that all access requests are encrypted to protect the security of data transmission. Specifically, the policy component calls the functional component to encrypt all access requests to obtain encrypted access requests, and decrypts the encrypted access requests to obtain decrypted access requests. Optionally, the cryptographic service component in the functional component is called to encrypt and decrypt all access requests.

[0078] Therefore, the identity information of the access subject is taken as the core of access control to ensure that all network participants have a verified subject identity. By continuously authenticating the identity of the access subject, it is ensured that only authorized users can access the corresponding resources. At the same time, by encrypting the access request, the security of the data transmission process is protected and secure access is achieved.

[0079] Among them, the policy components include policy execution points and policy decision points; the policy decision points include policy engines and policy managers; the functional components include at least task management components, environment perception components, identity management components, resource management components and cryptographic service components. Figure 2 shown.

[0080] Optionally, when the access subject is continuously authenticated based on the identity information of the access subject and the corresponding authentication result is obtained, in response to the access subject sending an access request to the policy execution point, the policy execution point forwards the access request to the policy decision point for verification; the policy decision point makes a decision on the access request based on the policy information and identity information in the policy manager to assign the corresponding decision result; the policy execution point performs corresponding access control operations based on the decision result of the policy decision point. Among them, the access control operation is, for example, allowing access, denying access, etc. For example, Figure 2 As shown, the access subject can be continuously authenticated according to the policy component. Specifically, the identity management component in the functional component is called to continuously authenticate the access subject.

[0081] Therefore, the policy component calls the functional component to continuously authenticate the access subject, and control the access of the access object based on the decision result. Specifically, the corresponding access control operation or access control policy is enforced based on the user's identity information, which reflects the authorization enforcement of this application.

[0082] S102, in response to the access object sending a resource request to the policy component, judging whether the resource request is legal based on the resource request.

[0083] In the embodiment of the present application, when the access object sends a resource request to the policy component, it is determined whether the resource request is legal based on the resource request, and corresponding processing is performed according to the determination result.

[0084] S103: If yes, the access subject is controlled to access the target resource of the corresponding access object based on the access request.

[0085] In the embodiment of the present application, different data sources of the target resource of the access object include at least data, equipment, information system, application software, service and functional interface, for example, Figure 2As shown; if the resource request is legitimate, the access subject is controlled to access the target resource of the corresponding access object based on the access request, thereby completing the access subject's resource access to the access object.

[0086] It should be noted that global identity management can establish a flexible and reliable trust relationship between the access subject and the access object, thereby improving the security and efficiency of the entire network environment.

[0087] Therefore, this application proposes a centralized identity authentication system, which is the core of implementing identity authentication and access control operations. By centrally storing and managing all identity information, it provides a unified and efficient operating environment for identity authentication and access control. It can not only realize the unified management of identity information and ensure the consistency and accuracy of information, but also greatly improve the efficiency of identity authentication through rapid retrieval functions.

[0088] Specifically, first, through centralized management, the security risks and data inconsistency problems caused by decentralized information storage are reduced; second, the quick retrieval function makes the identity authentication process faster, reduces waiting time, and improves user experience; third, the simplified identity authentication process reduces the complexity of operations and reduces security issues caused by operational errors; finally, through continuous trust evaluation and dynamic permission adjustment, the platform can respond to security threats in real time and adjust access policies in a timely manner, thereby effectively improving the security of the entire system. These significant effects not only improve the operating efficiency of the system, but also provide users with a safer and more reliable service environment.

[0089] The identity authentication method based on the identity center provided in the embodiment of the present application responds to the access subject initiating an access request to the access object, calls the functional component based on the policy component to continuously authenticate the access subject based on the identity information of the access subject, and adjusts the corresponding access rights of the access subject according to the authentication result, responds to the access object sending a resource request to the policy component, and determines whether the resource request is legal based on the resource request. If so, the access subject is controlled to access the target resource of the corresponding access object based on the access request. The identity authentication method based on the identity center of the present application implements a more dynamic and adaptive identity authentication mechanism by calling the functional component based on the policy component to continuously authenticate the identity information of the access subject, and adjusts the corresponding access rights of the access subject according to the authentication result, thereby improving the flexibility of the identity authentication process, being able to adapt to rapidly changing security requirements and security threats, and being able to continuously authenticate the identity of the user, further improving flexibility and system security.

[0090] Further, such as Figure 3 As shown, the identity authentication method based on the identity center in the embodiment of the present application may also include the following steps:

[0091] S301, determining whether the access object meets the preset target re-authentication condition.

[0092] In the embodiment of the present application, the target re-authentication condition is a preset condition that needs to be met for re-authentication, for example, access failure; a judgment is made as to whether the access object meets the target re-authentication condition, and corresponding processing is performed based on the judgment result.

[0093] S302: If yes, re-authenticate the access object based on the policy decision point and the policy execution point to ensure that the subject identity continues to be credible.

[0094] In an embodiment of the present application, if the access object meets the target re-authentication conditions, re-authentication is required. At this time, based on the policy decision point and policy execution point in the policy component, the access object is re-authenticated to ensure that the subject identity continues to be credible.

[0095] Furthermore, the target resources of different data sources of the access object are associated and analyzed, and the trust of the access subject is continuously evaluated to obtain the credit score of the access subject; the access rights of the access subject are dynamically adjusted based on the credit score. Figure 2 As shown, by associating and analyzing the information of target resources from different data sources, the trust of the access subject is continuously evaluated to obtain a trust evaluation result, namely a credit score. The access rights of the access subject can be dynamically adjusted based on the trust evaluation result to adapt to changing security needs.

[0096] Optionally, when the trust of the access subject is continuously evaluated and the credit score of the access subject is obtained, the multi-dimensional behavior data of the access object can be obtained in real time, and the behavior feature library of the access object can be constructed based on the behavior data; the abnormal behavior of the access object can be identified based on the behavior feature library and the preset machine learning algorithm, and the trust score of the access subject can be determined in real time based on the abnormal behavior. Among them, abnormal behavior is abnormal behavior that deviates significantly from the preset normal behavior pattern; the multi-dimensional behavior data at least includes login frequency, usage habits, operation mode, etc.

[0097] In short, this application collects and analyzes the behavioral data of users, i.e., access subjects, builds a personal behavioral feature library, identifies the pattern differences between normal and abnormal behaviors through machine learning algorithms, and determines or adjusts the user's trust score in real time. Therefore, based on the fusion processing of user behavior analysis and multi-source behavior data, it is possible to achieve real-time and accurate evaluation of user trust scores. At the same time, real-time monitoring and intelligent analysis of user behavior are carried out to detect abnormal behaviors that deviate significantly from normal behavior patterns, and potential malicious behaviors or system anomalies can be quickly identified and responded to, thereby significantly enhancing the system's intrusion detection capabilities, which not only improves the speed and accuracy of identifying internal and external security threats, but also can timely discover and take measures to prevent threats before they cause damage, effectively reducing security risks and potential losses.

[0098] It should be noted that this behavior-based authentication method can more accurately identify potential security threats by real-time monitoring and analysis of user behavior, thereby achieving dynamic management of access rights. It not only enhances security, but also provides a personalized service experience, because it can adapt to changes in user behavior and continuously optimize the authentication process. Compared with traditional static authentication methods, behavioral analysis technology can provide more accurate and dynamic security protection, thereby better protecting the user's identity information and privacy security. At the same time, it significantly enhances the adaptability and flexibility of the system, enabling it to more effectively cope with complex and changing security environments, ensuring the security and efficiency of the system, while reducing the risks caused by static trust assessment.

[0099] Optionally, the trust level of the access subject is adjusted in real time based on the credit score; the access rights of the access subject are dynamically adjusted based on the trust level of the access subject. It should be noted that the access subject can set the trust level, determine the trust level of the access subject based on the credit score, and dynamically adjust the access rights of the access subject based on the trust level.

[0100] Furthermore, the operating environment of the access subject is continuously monitored in real time based on the environment perception component; the access rights of the access subject are continuously adjusted based on the operating environment and behavior data. The operating environment includes whether the computer system is genuine, whether the software is genuine, the operation time, the operation location, etc.

[0101] Optionally, the access subject can be continuously adjusted based on the operating environment and behavioral data.

[0102] Therefore, by dynamically evaluating the user's behavior and operating environment, the user's trust level can be continuously monitored and adjusted. The significant effect is that the real-time response capability of the system is improved, and the access rights can be dynamically adjusted according to the real-time data analysis of environmental changes and user behavior, so as to achieve more accurate security management and risk control. This dynamic trust link technology based on real-time data and behavior analysis not only improves the adaptability and flexibility of the system, but also strengthens the ability to respond to complex and changing security environments, ensuring the security and efficiency of the system.

[0103] Further, the user attributes of the access subject are obtained; and the access rights of the access subject are adjusted based on the user attributes and the operating environment. The user attributes include at least the user role and the department. It is understandable that the access rights of the access subject can be adjusted according to the user attributes and the operating environment of the access subject.

[0104] It should be noted that the ability to grant or restrict access rights in a customized manner based on the specific attributes of the user and environmental conditions reflects a fine-grained access control strategy. This strategy achieves precise control over user access behavior by finely dividing access rights, thereby ensuring data and resource security while also meeting the specific needs of different users. Its significant effect is that it provides more personalized and precise access control, effectively reduces the risk of abuse of rights, and enhances the security of the system. In addition, it also supports dynamic adjustment, which can automatically adjust access rights based on real-time monitored user behavior and environmental changes to adapt to changing security needs. The flexibility and adaptability of this strategy enable the system to better respond to complex and changing security threats, and provide a solid foundation for building a secure, reliable, and efficient information environment.

[0105] Furthermore, the identity management component can be replaced based on a preset decentralized target identity authentication framework to manage the identity information of the access subject. The target identity authentication framework is the distributed storage solution IPFS (InterPlanetary File System). For example, IPFS is used to store identity information.

[0106] Optionally, the identity information of the access subject is stored to obtain multiple data files; a unique hash value corresponding to each data file is assigned according to the content of the data file, and an access link corresponding to the data file is determined to manage the identity information of the access subject based on the access link.

[0107] Therefore, through the decentralized identity authentication framework IPFS, another way of managing identity information can be achieved. Each data file stored on IPFS is assigned a unique hash value (CID) generated according to the content, which ensures the immutability and self-authentication of the data. Any modification to the data will generate a new hash value, ensuring the integrity and authenticity of the data. Using the distributed hash table (DHT) technology, IPFS implements decentralized object indexing, which reduces the risk of centralized storage. IPFS's Interstellar Naming System (IPNS) supports users to publish and update content through public key hashing, maintains the persistence of links, and maintains access continuity even after data is updated. These technical features together provide a secure, reliable and decentralized solution for identity authentication. Users can fully control their identity information and ensure privacy through encryption technology. IPFS's network partition tolerance ensures the stability of the network. Even if part of the network is unavailable, data can still be accessed and retrieved.

[0108] Furthermore, a trust chain based on blockchain technology can be constructed, and policy components can be replaced based on the trust chain.

[0109] It should be noted that blockchain technology is used to build trust links, and its immutability and decentralization characteristics are utilized to enhance the security and reliability of trust links.

[0110] Therefore, blockchain technology provides a solution to enhance security and reliability through its tamper-proof chain data structure and decentralized characteristics. It uses encryption technology to protect data security and privacy, and ensures the consistency of data among all nodes through a consensus mechanism. The distributed storage mechanism ensures the persistence and anti-attack capability of data, while the transparency and traceability of blockchain provide audit trails for identity information changes, improving the reliability and trust of the system.

[0111] Figure 4 is a flow chart of an identity authentication device based on an identity center according to an embodiment of the present application, which is applied to an identity authentication system, and the identity authentication system includes an access object, a policy component and a functional component; Figure 4 As shown, the identity authentication device 400 based on the identity center in the embodiment of the present application may specifically include:

[0112] The first authentication module 401 is used to respond to the access subject initiating an access request to the access object, call the functional component based on the policy component, so as to continuously authenticate the access subject based on the identity information of the access subject, and adjust the access rights corresponding to the access subject according to the authentication result; wherein the identity information includes at least user identity, device identity, application identity and service identity.

[0113] The first judgment module 402 is used to respond to the access object sending a resource request to the policy component, and judge whether the resource request is legal based on the resource request.

[0114] The access module 403 is used to control the access subject to access the target resource of the corresponding access object based on the access request; wherein the different data sources of the target resource of the access object include at least data, equipment, information system, application software, service and functional interface.

[0115] In a possible implementation, the policy component includes a policy execution point and a policy decision point; the policy decision point includes a policy engine and a policy manager; the first authentication module is specifically used to:

[0116] In response to the access subject sending an access request to the policy enforcement point, the policy enforcement point forwards the access request to the policy decision point for verification;

[0117] The policy decision point makes a decision on the access request based on the policy information and identity information in the policy manager to assign the corresponding decision result;

[0118] The policy enforcement point performs corresponding access control operations based on the decision results of the policy decision point.

[0119] In a possible implementation, the identity authentication device based on the identity center further includes:

[0120] The second judgment module is used to judge whether the access object meets the preset target re-authentication conditions;

[0121] The second authentication module is used to re-authenticate the access object based on the policy decision point and the policy execution point to ensure that the subject identity continues to be credible.

[0122] In a possible implementation, the identity authentication device based on the identity center further includes:

[0123] The evaluation module is used to associate and analyze the target resources of different data sources of the access object, continuously evaluate the trustworthiness of the access subject, and obtain the credit score of the access subject;

[0124] The first adjustment module is used to dynamically adjust the access rights of the access subject based on the credit score.

[0125] In a possible implementation, the evaluation module is specifically configured to:

[0126] Acquire multi-dimensional behavior data of the access object in real time, and build a behavior feature library of the access object based on the behavior data; wherein the multi-dimensional behavior data at least includes login frequency, usage habits, and operation mode;

[0127] Based on the behavioral feature library and the preset machine learning algorithm, the abnormal behavior of the access object is identified, and the trust score of the access subject is determined in real time based on the abnormal behavior; among which, the abnormal behavior is abnormal behavior that deviates significantly from the preset normal behavior pattern.

[0128] In a possible implementation, the functional component includes an environment perception component; and the identity authentication device based on the identity center further includes:

[0129] A monitoring module, used for continuously monitoring the operating environment of the access subject in real time based on the environment perception component;

[0130] The second adjustment module is used to continuously adjust the access rights of the access subject based on the operating environment and behavior data.

[0131] In a possible implementation, the identity authentication device based on the identity center further includes:

[0132] The acquisition module is used to acquire the user attributes of the access subject; wherein the user attributes at least include the user role and department;

[0133] The third adjustment module is used to adjust the access rights of the access subject based on user attributes and operating environment.

[0134] The identity authentication device based on the identity center provided in the embodiment of the present application responds to the access subject initiating an access request to the access object, calls the functional component based on the policy component to continuously authenticate the access subject based on the identity information of the access subject, and adjusts the corresponding access rights of the access subject according to the authentication result, responds to the access object sending a resource request to the policy component, and determines whether the resource request is legal based on the resource request. If so, the access subject is controlled to access the target resource of the corresponding access object based on the access request. The identity authentication device based on the identity center of the present application realizes a more dynamic and adaptive identity authentication mechanism by calling the functional component based on the policy component to continuously authenticate the identity information of the access subject, and adjusts the corresponding access rights of the access subject according to the authentication result, thereby improving the flexibility of the identity authentication process, being able to adapt to rapidly changing security requirements and security threats, and being able to continuously authenticate the identity of the user, further improving flexibility and system security.

[0135] like Figure 5 As shown, an electronic device 500 provided in an embodiment of the present application includes: a processor 501, a memory 502 and a bus, wherein the memory 502 stores machine-readable instructions executable by the processor 501. When the electronic device is running, the processor 501 communicates with the memory 502 through the bus, and the processor 501 executes the machine-readable instructions to perform the steps of the identity authentication method based on the identity center as described above.

[0136] Specifically, the above-mentioned memory 502 and processor 501 can be general-purpose memory and processor, which are not specifically limited here. When the processor 501 runs the computer program stored in the memory 502, it can execute the above-mentioned identity authentication method based on the identity center.

[0137] Corresponding to the above-mentioned identity authentication method based on the identity center, an embodiment of the present application also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is run by a processor, the steps of the above-mentioned identity authentication method based on the identity center are executed.

[0138] Those skilled in the art can clearly understand that, for the convenience and simplicity of description, the specific working process of the system and device described above can refer to the corresponding process in the method embodiment, and will not be repeated in this application. In the several embodiments provided in this application, it should be understood that the disclosed system, device and method can be implemented in other ways. The device embodiments described above are merely schematic. For example, the division of the modules is only a logical function division. There may be other division methods in actual implementation. For example, multiple modules or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some communication interfaces, indirect coupling or communication connection of devices or modules, which can be electrical, mechanical or other forms.

[0139] The modules described as separate components may or may not be physically separated, and the components shown as modules may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0140] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0141] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a non-volatile computer-readable storage medium that is executable by a processor. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for a computer device (which can be a personal computer, server, or network device, etc.) to perform all or part of the steps of the deployment method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard drives, ROM, RAM, magnetic disks, or optical disks.

[0142] The above are only specific implementations of the present application, but the protection scope of the present application is not limited thereto. Any technician familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.

Claims

1. An identity authentication method based on an identity center, applied to an identity authentication system, wherein the identity authentication system includes an access object, a policy component and a functional component; characterized in that: The identity authentication method comprises: In response to the access subject initiating an access request to the access object, the function component is called based on the policy component to continuously authenticate the access subject based on the identity information of the access subject, and adjust the access rights corresponding to the access subject according to the authentication result; wherein the identity information includes at least user identity, device identity, application identity and service identity; In response to the access object sending a resource request to the policy component, determining whether the resource request is legal based on the resource request; If so, the access subject is controlled to access the corresponding target resource of the access object based on the access request; wherein the different data sources of the target resource of the access object include at least data, equipment, information system, application software, service and functional interface.

2. The method according to claim 1, characterized in that The policy component includes a policy execution point and a policy decision point; the policy decision point includes a policy engine and a policy manager; the continuous authentication of the access subject based on the identity information of the access subject to obtain the corresponding authentication result includes: In response to the access subject sending the access request to the policy enforcement point, the policy enforcement point forwards the access request to the policy decision point for verification; The policy decision point makes a decision on the access request according to the policy information in the policy manager and the identity information to assign a corresponding decision result; The policy enforcement point performs corresponding access control operations based on the decision result of the policy decision point.

3. The method according to claim 2, characterized in that The method further comprises: Determining whether the access object meets the preset target re-authentication conditions; If so, the access object is re-authenticated based on the policy decision point and the policy execution point to ensure that the subject identity continues to be credible.

4. The method according to claim 1, characterized in that: The method further comprises: Associating and analyzing target resources of different data sources of the access object, continuously evaluating the trustworthiness of the access subject, and obtaining the credit score of the access subject; The access rights of the access subject are dynamically adjusted based on the credit score.

5. The method according to claim 4, characterized in that The continuously evaluating the trustworthiness of the access subject to obtain the credit score of the access subject includes: Acquire multi-dimensional behavior data of the access object in real time, and construct a behavior feature library of the access object based on the behavior data; wherein the multi-dimensional behavior data at least includes login frequency, usage habits, and operation mode; Based on the behavior feature library and a preset machine learning algorithm, the abnormal behavior of the access object is identified, and the trust score of the access subject is determined in real time based on the abnormal behavior; wherein the abnormal behavior is abnormal behavior that deviates significantly from a preset normal behavior pattern.

6. The method according to claim 5, characterized in that The functional component includes an environment perception component; the method also includes: Based on the environment perception component, the operating environment of the access subject is continuously monitored in real time; The access rights of the access subject are continuously adjusted based on the operating environment and the behavior data.

7. The method according to claim 6, characterized in that The method further comprises: Acquire the user attributes of the access subject; wherein the user attributes at least include user role and department; The access authority of the access subject is adjusted based on the user attributes and the operating environment.

8. An identity authentication device based on an identity center, applied to an identity authentication system, wherein the identity authentication system includes an access object, a policy component and a functional component; characterized in that: The identity authentication device comprises: an authentication module, configured to respond to an access request initiated by an access subject to the access object, call the functional component based on the policy component, perform continuous authentication on the access subject based on the identity information of the access subject, and adjust the access rights corresponding to the access subject according to the authentication result; wherein the identity information includes at least user identity, device identity, application identity and service identity; A judgment module, configured to respond to the access object sending a resource request to the policy component and judge whether the resource request is legal based on the resource request; An access module is used to control the access subject to access the target resource of the corresponding access object based on the access request; wherein the different data sources of the target resource of the access object include at least data, equipment, information system, application software, service and functional interface.

9. An electronic device, characterized in that: include: A processor, a memory and a bus, wherein the memory stores machine-readable instructions executable by the processor. When the electronic device is running, the processor and the memory communicate via the bus. When the machine-readable instructions are executed by the processor, the steps of the identity authentication method based on the identity center as described in any one of claims 1 to 7 are performed.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, which, when executed by a processor, executes the steps of the identity authentication method based on the identity center as described in any one of claims 1 to 7.