URL authority control method and system based on black list and white list
By introducing a priority mechanism in the black and white list control solution, the shortcomings of traditional solutions in dealing with complex permission configuration are solved, and flexible processing of complex authorization requirements and fine management of permission configuration are realized.
Patent Information
- Application Number
- CN202510373891.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-27
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2045-03-27
AI Technical Summary
The traditional black and white list control scheme seems unscrupulous when dealing with complex permission configurations and cannot effectively deal with complex scenarios that allow and deny access to specific URLs at the same time.
The priority mechanism is introduced, and by setting the priority field in the black and white list, administrators are allowed to set priority for different black and white list items, thereby achieving flexible configuration and fine management of access control policies.
It realizes flexible handling of complex authorization requirements, avoids possible permission misjudgment or omissions in traditional solutions, and significantly improves the flexibility and accuracy of permission configuration.
Smart Images

Figure CN120017410A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a URL authority control method and system based on a blacklist and a whitelist. Background Art
[0002] With the rapid development of Internet technology, the diversification and complexity of network applications have made the management of URL access rights an important issue that needs to be solved urgently. Traditional blacklist and whitelist control solutions have occupied a place in the field of network security, limiting user access rights by explicitly listing allowed or denied URL lists. However, in the face of complex and changing authorization requirements in modern network environments, traditional solutions seem to be unable to cope with them.
[0003] Specifically, the traditional blacklist and whitelist control scheme has significant deficiencies in handling complex permission configurations. It can usually only simply determine access rights based on whether the URL exists in the blacklist or whitelist, and lacks the flexibility to handle complex scenarios where access to specific URLs is allowed and denied at the same time.
[0004] For example, user A is allowed to access all URLs (represented by whitelist / **), but at the same time, user A is not allowed to access all content under / users / (represented by blacklist / users / **). However, for special needs, user A needs to be allowed to access specific URLs such as / users / {id}. In traditional blacklist and whitelist solutions, such needs are often impossible to achieve because the blacklist will unconditionally override the whitelist's permission rules. Summary of the invention
[0005] The purpose of the present invention is to provide a URL permission control method and system based on blacklist and whitelist, which realizes flexible configuration and fine management of access control policies by introducing a priority mechanism, thereby meeting the urgent requirements of modern network environments for complex authorization needs and solving the problems raised in the above background technology.
[0006] To achieve the above object, the present invention provides the following technical solution: a URL permission control method based on blacklist and whitelist, including blacklist and whitelist creation and maintenance steps, specifically:
[0007] Administrators create blacklists and whitelists through the UI or API interface, and dynamically update and maintain them;
[0008] The blacklist and whitelist information is stored in a relational database data table. The fields of the data table include id, user_id, type, method, url_template, and priority. id is the primary key, user_id is the user ID, type is an enumeration type, the value black indicates the blacklist, the value white indicates the whitelist, method is the request method, including POST / GET / DELETE / PUT / PATCH / ALL, ALL can match all types of request methods, url_template is a URL template that supports wildcards, ? matches a single character, * matches a string of any length except the path identifier " / ", ** matches a string of any length, priority is a numeric type, the smaller the value, the higher the priority, and the larger the value, the lower the priority;
[0009] Provides interfaces for creating, deleting, modifying, and querying blacklists and whitelists of specified users. The request method for creating a blacklist and whitelist is POST, the request URI is / admin / url-permissions, and the request Body contains the type, userId, method, url_template, and priority fields; the request method for deleting a blacklist and whitelist is DELETE, and the request URI is / admin / url-permissions / {id}; the request method for modifying a blacklist and whitelist is PUT, and the request URI is / admin / url-permissions / {id}, and the request Body contains the type, method, url_template, and priority fields; the request method for querying a blacklist and whitelist of a specified user is GET, and the request URI is / admin / url-permissions?userId={userId}.
[0010] Preferably, the method further includes a request interception step:
[0011] The request interception module is located before all requests enter the backend service. It intercepts all requests by configuring the interception rules of the HTTP server or using the interceptor function of the framework.
[0012] Extract URL information from HTTP requests and perform necessary preprocessing, such as URL decoding and removing query parameters;
[0013] According to the system's authentication mechanism, extract the current user's identity information from the request, including parsing the user ID and user name information from the HTTP header, Cookie, Session or Token.
[0014] Preferably, the method further includes priority comparison and decision making steps:
[0015] The priority comparison and decision module receives URL information and current user information from the request interception module;
[0016] Query all blacklist and whitelist lists of the current user from the database and sort them in ascending order from high to low priority;
[0017] Traverse the sorted blacklist and whitelist entries. If a whitelist entry is encountered first and its priority is higher than all possible conflicting blacklist entries, access is allowed; if a blacklist entry is encountered and its priority is higher than all possible whitelist entries that may cover it, access is denied; if multiple entries with the same priority are encountered at the same time, a decision is made according to the preset rules;
[0018] Based on the decision result, access to the current URL request is allowed or denied.
[0019] Preferably, the log audit step is also included:
[0020] The log audit module records relevant information at key nodes in the request processing process. The log information includes request time, user ID, request URL, request method, authentication result, blacklist and whitelist comparison result, and access control decision.
[0021] Use the log framework to output log information to the specified storage medium, using a unified log format, including timestamp, log level, and log content fields;
[0022] It provides audit interfaces in the form of RESTful API or Web interface, allowing administrators to query log records based on time range, user ID, and request URL conditions, supports paging and sorting functions, and desensitizes sensitive information.
[0023] A control system for a URL permission control method based on black and white lists, including a black and white list management module, which is used to realize the creation, deletion, modification and query functions of the black and white lists;
[0024] In the black and white list management module, the black and white list information is stored in a data table of a relational database. The fields of the data table include id, user_id, type, method, url_template, and priority, where id is the primary key, user_id is the user ID, type is an enumeration type, the value black indicates a blacklist, the value white indicates a whitelist, method is a request method, including POST / GET / DELETE / PUT / PATCH / ALL, ALL can match all types of request methods, url_template is a URL template that supports wildcards, ? matches a single character, * matches a string of any length except the path identifier " / ", ** matches a string of any length, and priority is a numerical type. The smaller the value, the higher the priority, and the larger the value, the lower the priority;
[0025] Provides interfaces for creating, deleting, modifying, and querying blacklists and whitelists of specified users. The request method for creating a blacklist and whitelist is POST, the request URI is / admin / url-permissions, and the request Body contains the type, userId, method, url_template, and priority fields; the request method for deleting a blacklist and whitelist is DELETE, and the request URI is / admin / url-permissions / {id}; the request method for modifying a blacklist and whitelist is PUT, and the request URI is / admin / url-permissions / {id}, and the request Body contains the type, method, url_template, and priority fields; the request method for querying a blacklist and whitelist of a specified user is GET, and the request URI is / admin / url-permissions?userId={userId}.
[0026] Preferably, it also includes a request interception module, which is located before all requests enter the backend service;
[0027] The request interception module intercepts all requests by configuring the interception rules of the HTTP server or using the interceptor function of the framework;
[0028] Extract URL information from HTTP requests and perform necessary preprocessing, such as URL decoding and removing query parameters;
[0029] According to the system's authentication mechanism, the current user's identity information is extracted from the request, including parsing the user ID and user name information from the HTTP header, Cookie, Session or Token, and forwarding the extracted URL information and user information to the priority comparison and decision module.
[0030] Preferably, it also includes a priority comparison and decision module;
[0031] The priority comparison and decision module receives the URL information and current user information forwarded by the request interception module;
[0032] Query all blacklist and whitelist lists of the current user from the database and sort them in ascending order from high to low priority;
[0033] Traverse the sorted blacklist and whitelist entries. If a whitelist entry is encountered first and its priority is higher than all possible conflicting blacklist entries, access is allowed; if a blacklist entry is encountered and its priority is higher than all possible whitelist entries that may cover it, access is denied; if multiple entries with the same priority are encountered at the same time, a decision is made according to the preset rules;
[0034] Based on the decision result, access to the current URL request is allowed or denied.
[0035] Preferably, a log audit module is also included;
[0036] The log audit module records relevant information at key nodes of the request processing flow, including request time, user ID, request URL, request method, authentication result, blacklist and whitelist comparison result, and access control decision;
[0037] Use the log framework to output log information to the specified storage medium, using a unified log format, including timestamp, log level, and log content fields;
[0038] It provides audit interfaces in the form of RESTful API or Web interface, allowing administrators to query log records based on time range, user ID, and request URL conditions, supports paging and sorting functions, and desensitizes sensitive information.
[0039] Compared with the prior art, the present invention has the following beneficial effects:
[0040] The blacklist-based URL permission control method and system proposed in the present invention achieves unprecedented permission configuration flexibility by allowing administrators to set priorities for different blacklist and whitelist items. This feature enables the system to easily cope with various complex and changeable authorization requirements, including but not limited to scenarios of simultaneously allowing and denying access to specific URLs, thereby greatly expanding the application scope of blacklist and whitelist control strategies.
[0041] The introduction of the priority mechanism ensures that the system can make decisions based on clear priority rules when dealing with permission conflicts, thus avoiding the misjudgment or omission of permissions that may occur in traditional solutions. This improvement in accuracy is crucial to ensuring the security and compliance of network access. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] Figure 1 The figure is a flow chart of the method of the present invention. DETAILED DESCRIPTION
[0043] In order to make the purpose and technical solution of the present invention clearly and completely described, and the advantages more clearly understood, the embodiments of the present invention are further described in detail with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are part of the embodiments of the present invention, rather than all of the embodiments, and are only used to explain the embodiments of the present invention, and are not used to limit the embodiments of the present invention. All other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0044] Embodiment 1, the present invention provides a technical solution: a URL permission control method based on blacklist and whitelist, including blacklist and whitelist creation and maintenance steps, specifically:
[0045] Administrators create blacklists and whitelists through the UI or API interface, and dynamically update and maintain them;
[0046] The blacklist and whitelist information is stored in a relational database data table. The fields of the data table include id, user_id, type, method, url_template, and priority. id is the primary key, user_id is the user ID, type is an enumeration type, the value black indicates the blacklist, the value white indicates the whitelist, method is the request method, including POST / GET / DELETE / PUT / PATCH / ALL, ALL can match all types of request methods, url_template is a URL template that supports wildcards, ? matches a single character, * matches a string of any length except the path identifier " / ", ** matches a string of any length, priority is a numeric type, the smaller the value, the higher the priority, and the larger the value, the lower the priority;
[0047] Provides interfaces for creating, deleting, modifying, and querying blacklists and whitelists of specified users. The request method for creating a blacklist and whitelist is POST, the request URI is / admin / url-permissions, and the request Body contains the type, userId, method, url_template, and priority fields; the request method for deleting a blacklist and whitelist is DELETE, and the request URI is / admin / url-permissions / {id}; the request method for modifying a blacklist and whitelist is PUT, and the request URI is / admin / url-permissions / {id}, and the request Body contains the type, method, url_template, and priority fields; the request method for querying a blacklist and whitelist of a specified user is GET, and the request URI is / admin / url-permissions?userId={userId}.
[0048] It also includes the request interception step:
[0049] The request interception module is located before all requests enter the backend service. It intercepts all requests by configuring the interception rules of the HTTP server or using the interceptor function of the framework.
[0050] Extract URL information from HTTP requests and perform necessary preprocessing, such as URL decoding and removing query parameters;
[0051] According to the system's authentication mechanism, extract the current user's identity information from the request, including parsing the user ID and user name information from the HTTP header, Cookie, Session or Token.
[0052] It also includes priority comparison and decision-making steps:
[0053] The priority comparison and decision module receives URL information and current user information from the request interception module;
[0054] Query all blacklist and whitelist lists of the current user from the database and sort them in ascending order from high to low priority;
[0055] Traverse the sorted blacklist and whitelist entries. If a whitelist entry is encountered first and its priority is higher than all possible conflicting blacklist entries, access is allowed; if a blacklist entry is encountered and its priority is higher than all possible whitelist entries that may cover it, access is denied; if multiple entries with the same priority are encountered at the same time, a decision is made according to the preset rules;
[0056] Based on the decision result, access to the current URL request is allowed or denied.
[0057] Also includes the log audit steps:
[0058] The log audit module records relevant information at key nodes in the request processing process. The log information includes request time, user ID, request URL, request method, authentication result, blacklist and whitelist comparison result, and access control decision.
[0059] Use the log framework to output log information to the specified storage medium, using a unified log format, including timestamp, log level, and log content fields;
[0060] It provides audit interfaces in the form of RESTful API or Web interface, allowing administrators to query log records based on time range, user ID, and request URL conditions, supports paging and sorting functions, and desensitizes sensitive information.
[0061] Embodiment 2, based on embodiment 1, proposes a control system of a URL permission control method based on a blacklist and whitelist, including:
[0062] Blacklist and whitelist management module: Administrators create blacklist and whitelist through the interface or API interface, and dynamically update and maintain them.
[0063] Blacklist and whitelist storage: Blacklist and whitelist information is stored in a relational database table. The table structure is as follows:
[0064]
[0065] Main interfaces
[0066] Create a blacklist and whitelist
[0067] Request method POST
[0068] Request URI / admin / url-permissions Request Body:
[0069]
[0070]
[0071] Delete blacklist and whitelist
[0072] Request method DELETE
[0073] Request URI / admin / url-permissions / {id}
[0074] Modify the blacklist and whitelist
[0075] Request method PUT
[0076] Request URI / admin / url-permissions / {id}
[0077] Request Body:
[0078]
[0079] Query the blacklist and whitelist of a specified user
[0080] Request method GET
[0081] Request URI / admin / url-permissions?userId={userId}Return result:
[0082]
[0083]
[0084] Request interception module: The request interception module is located before all requests enter the backend service. It is responsible for intercepting all requests, extracting the requested URL information and current user information, and forwarding the request to the subsequent priority comparison and decision module for further processing based on this information.
[0085] Request interception: By configuring the interception rules of the HTTP server (such as Nginx, Apache or Tomcat, etc.), or using the interceptor function of the framework (such as Spring MVC, ASP.NET MVC, etc.), all HTTP requests entering the system can be intercepted.
[0086] URL extraction: Extract URL information from HTTP requests and perform necessary preprocessing (such as URL decoding, removing query parameters, etc.).
[0087] User extraction: Extract the current user's identity information from the request based on the system's authentication mechanism. This may include parsing user ID, user name, and other information from HTTP headers (such as Authorization, X-User-ID, etc.), cookies, sessions, or tokens.
[0088] Priority comparison and decision-making module:
[0089] The priority comparison and decision module is responsible for comparing the URL information extracted from the request with the entries in the blacklist and whitelist database, and making access control decisions based on the priority rules.
[0090] Information extraction: Receive URL information (including request method and URL path) and current user information from the request interception module.
[0091] Get all blacklist and whitelist information of the current user: query all blacklist and whitelist information of the current user from the database, and sort them from high to low according to priority. Since the smaller the priority value is, the higher the priority is, the matched entries need to be sorted in ascending order.
[0092] Decision logic: traverse the sorted blacklist and whitelist entries:
[0093] If a whitelist entry is encountered first and takes precedence over all potentially conflicting blacklist entries, access is allowed.
[0094] If a blacklist entry is encountered and it takes precedence over all whitelist entries that might override it, access is denied.
[0095] If multiple entries with the same priority are encountered at the same time (although this should be avoided as much as possible by design), a decision is made based on preset rules (such as "blacklist first").
[0096] Result output:
[0097] If the decision result is allowed, the current URL request is allowed to access.
[0098] If the decision result is denied, access to the current URL request is denied.
[0099] Log audit module:
[0100] The log audit module is responsible for recording information such as user access behavior, authentication results, blacklist and whitelist comparison results, and provides an audit interface for administrators to trace and review.
[0101] Logging: Record relevant information at key points in the request processing process (such as request interception, priority comparison and decision-making, access control execution, etc.). Log information includes but is not limited to: request time, user ID, request URL, request method, authentication result, blacklist and whitelist comparison result, access control decision, etc.
[0102] Use a logging framework (such as Log4j, Serilog, etc.) to output log information to a specified storage medium (such as a file, database, remote log server, etc.).
[0103] Log format: Use a unified log format to facilitate subsequent analysis and query.
[0104] It can include fields such as timestamp, log level (such as INFO, WARN, ERROR, etc.), log content, etc.
[0105] Audit interface: Provides an audit interface in the form of a RESTful API or web interface, allowing administrators to query log records based on conditions such as time range, user ID, request URL, etc.
[0106] Supports paging and sorting functions to help administrators browse and review log information efficiently.
[0107] Sensitive information is desensitized to protect user privacy and data security.
[0108] Although embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. A URL permission control method based on blacklist and whitelist, characterized by: Includes the steps of creating and maintaining blacklists and whitelists, specifically: Administrators create blacklists and whitelists through the UI or API interface, and dynamically update and maintain them; The blacklist and whitelist information is stored in a relational database data table. The fields of the data table include id, user_id, type, method, url_template, and priority. id is the primary key, user_id is the user ID, type is an enumeration type, the value black indicates the blacklist, the value white indicates the whitelist, method is the request method, including POST / GET / DELETE / PUT / PATCH / ALL, ALL can match all types of request methods, url_template is a URL template that supports wildcards, ? matches a single character, * matches a string of any length except the path identifier " / ", ** matches a string of any length, priority is a numeric type, the smaller the value, the higher the priority, and the larger the value, the lower the priority; Provides interfaces for creating, deleting, modifying, and querying blacklists and whitelists of specified users. The request method for creating a blacklist and whitelist is POST, the request URI is / admin / url-permissions, and the request Body contains the type, userId, method, url_template, and priority fields; the request method for deleting a blacklist and whitelist is DELETE, and the request URI is / admin / url-permissions / {id}; the request method for modifying a blacklist and whitelist is PUT, and the request URI is / admin / url-permissions / {id}, and the request Body contains the type, method, url_template, and priority fields; the request method for querying a blacklist and whitelist of a specified user is GET, and the request URI is / admin / url-permissions?userId={userId}.
2. According to claim 1, a URL permission control method based on blacklist and whitelist is characterized in that: It also includes the request interception step: The request interception module is located before all requests enter the backend service. It intercepts all requests by configuring the interception rules of the HTTP server or using the interceptor function of the framework. Extract URL information from HTTP requests and perform necessary preprocessing, such as URL decoding and removing query parameters; According to the system's authentication mechanism, extract the current user's identity information from the request, including parsing the user ID and user name information from the HTTP header, Cookie, Session or Token.
3. According to claim 2, a URL permission control method based on blacklist and whitelist is characterized in that: It also includes priority comparison and decision-making steps: The priority comparison and decision module receives URL information and current user information from the request interception module; Query all blacklist and whitelist lists of the current user from the database and sort them in ascending order from high to low priority; Traverse the sorted blacklist and whitelist entries. If a whitelist entry is encountered first and its priority is higher than all possible conflicting blacklist entries, access is allowed; if a blacklist entry is encountered and its priority is higher than all possible whitelist entries that may cover it, access is denied; if multiple entries with the same priority are encountered at the same time, a decision is made according to the preset rules; Based on the decision result, access to the current URL request is allowed or denied.
4. According to claim 3, a URL permission control method based on blacklist and whitelist is characterized in that: Also includes the log audit steps: The log audit module records relevant information at key nodes in the request processing process. The log information includes request time, user ID, request URL, request method, authentication result, blacklist and whitelist comparison result, and access control decision. Use the log framework to output log information to the specified storage medium, using a unified log format, including timestamp, log level, and log content fields; It provides audit interfaces in the form of RESTful API or Web interface, allowing administrators to query log records based on time range, user ID, and request URL conditions, supports paging and sorting functions, and desensitizes sensitive information.
5. A control system for the URL authority control method based on blacklist and whitelist according to claim 4, characterized in that: Includes a blacklist and whitelist management module, which is used to implement the creation, deletion, modification and query functions of blacklist and whitelist; In the black and white list management module, the black and white list information is stored in a data table of a relational database. The fields of the data table include id, user_id, type, method, url_template, and priority, where id is the primary key, user_id is the user ID, type is an enumeration type, the value black indicates a blacklist, the value white indicates a whitelist, method is a request method, including POST / GET / DELETE / PUT / PATCH / ALL, ALL can match all types of request methods, url_template is a URL template that supports wildcards, ? matches a single character, * matches a string of any length except the path identifier " / ", ** matches a string of any length, and priority is a numerical type. The smaller the value, the higher the priority, and the larger the value, the lower the priority; Provides interfaces for creating, deleting, modifying, and querying blacklists and whitelists of specified users. The request method for creating a blacklist and whitelist is POST, the request URI is / admin / url-permissions, and the request Body contains the type, userId, method, url_template, and priority fields; the request method for deleting a blacklist and whitelist is DELETE, and the request URI is / admin / url-permissions / {id}; the request method for modifying a blacklist and whitelist is PUT, and the request URI is / admin / url-permissions / {id}, and the request Body contains the type, method, url_template, and priority fields; the request method for querying a blacklist and whitelist of a specified user is GET, and the request URI is / admin / url-permissions?userId={userId}.
6. A blacklist and whitelist-based URL permission control system according to claim 5, characterized in that: It also includes a request interception module, which is located before all requests enter the backend service; The request interception module intercepts all requests by configuring the interception rules of the HTTP server or using the interceptor function of the framework; Extract URL information from HTTP requests and perform necessary preprocessing, such as URL decoding and removing query parameters; According to the system's authentication mechanism, the current user's identity information is extracted from the request, including parsing the user ID and user name information from the HTTP header, Cookie, Session or Token, and forwarding the extracted URL information and user information to the priority comparison and decision module.
7. A blacklist and whitelist-based URL permission control system according to claim 6, characterized in that: It also includes priority comparison and decision-making modules; The priority comparison and decision module receives the URL information and current user information forwarded by the request interception module; Query all blacklist and whitelist lists of the current user from the database and sort them in ascending order from high to low priority; Traverse the sorted blacklist and whitelist entries. If a whitelist entry is encountered first and its priority is higher than all possible conflicting blacklist entries, access is allowed; if a blacklist entry is encountered and its priority is higher than all possible whitelist entries that may cover it, access is denied; if multiple entries with the same priority are encountered at the same time, a decision is made according to the preset rules; Based on the decision result, access to the current URL request is allowed or denied.
8. A blacklist and whitelist-based URL permission control system according to claim 7, characterized in that: Also includes a log audit module; The log audit module records relevant information at key nodes of the request processing flow, including request time, user ID, request URL, request method, authentication result, blacklist and whitelist comparison result, and access control decision; Use the log framework to output log information to the specified storage medium, using a unified log format, including timestamp, log level, and log content fields; It provides audit interfaces in the form of RESTful API or Web interface, allowing administrators to query log records based on time range, user ID, and request URL conditions, supports paging and sorting functions, and desensitizes sensitive information.
Citation Information
Patent Citations
Black-and-white list extension method and black-and-white list information processing method and apparatus
CN107181665A
Java security protection method and device based on JVM sandbox and black and white lists and medium
CN113672907A
Mass storage distributed system black and white list control method and device
CN114615008A
Black and white list access control implementation method and device and medium
CN117081781A
Data request access control method
CN119135440A