Permission configuration method and device, storage medium and electronic equipment
By introducing a two-factor verification permission configuration method in the airport environment, responding to permission configuration requests and configuring permissions based on the verification results, the problems of low efficiency and poor flexibility of permission configuration in the prior art are solved, and the accuracy and security of permission configuration are improved.
Patent Information
- Application Number
- CN202411856689.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-17
- Publication Date
- 2025-05-23
AI Technical Summary
The permission configuration method in the existing airport environment is difficult to efficiently allocate and manage the authority of personnel in different positions, and lacks a flexible authority adjustment mechanism, so it cannot adapt to various changes in the airport operation process.
A permission configuration method is proposed. By responding to the permission configuration request of the target object, the first information of the permission leading object is obtained and verified, the second information of the target object is obtained and verified, and finally the target permissions are configured for the target object based on the verification information.
It realizes instant response to permission configuration requests and introduces a two-factor verification mechanism to ensure that only those who have been strictly screened can obtain access rights, improves the accuracy and security of permission configuration, and reduces the cumbersomeness of manual audits.
Smart Images

Figure CN120030517A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of computer technology, and in particular to a permission configuration method, device, storage medium and electronic device. Background Art
[0002] As a transportation hub, the security of an airport is of vital importance. The permission configuration method in the airport environment needs to ensure that only authorized personnel can access key areas or systems to prevent illegal intrusion, terrorist attacks or other security threats.
[0003] As airports expand in size and passenger traffic increases, operational efficiency becomes an important challenge for airport management. This requires that the authority configuration method in the airport environment can efficiently allocate and manage the authority of personnel in different positions to ensure that they can complete their work tasks quickly and accurately. At the same time, the system also needs to support flexible authority adjustment to adapt to various changes in the airport operation process. Summary of the invention
[0004] The main purpose of the present disclosure is to provide a permission configuration method, device, storage medium and electronic device, aiming to solve the technical problems in the prior art.
[0005] To achieve the above objectives, the present disclosure proposes a permission configuration method, including:
[0006] In response to a permission configuration request of a target object, obtaining first information of a permission leading object corresponding to the target object;
[0007] Based on the first information, verifying the permission guidance object;
[0008] When the permission-guided object is verified, obtaining second information of the target object;
[0009] Based on the second information, verifying the target object;
[0010] When the target object passes the verification, target permissions are configured for the target object according to the first information and / or the second information.
[0011] Optionally, the verifying the permission guidance object based on the first information includes:
[0012] Determine the first certificate information and the first real-time biometric information of the authority-leading object according to the first information;
[0013] Verifying the certificate information of the authority-guiding object according to the first certificate information;
[0014] When the certificate information of the authority leading object is verified, the first real-time biometric information is compared with the biometric information pre-stored in the database to perform biometric verification on the authority leading object;
[0015] Among them, the first certificate information includes the identity information, certificate status information, authority information and one or more associated target object information of the authority-leading object, and the first real-time biometric information includes one or more of fingerprint information, iris information and face information.
[0016] Optionally, verifying the certificate information of the authority leading object according to the first certificate information includes:
[0017] Determining whether the first certificate information is valid;
[0018] If the first certificate information is valid, determining whether the authorized leading object has the leading authority to lead the target object according to the first certificate information;
[0019] In the case that the authority leading object has the leading authority, it is determined that the certificate information verification of the authority leading object has passed.
[0020] Optionally, when the permission-guiding object passes the verification, obtaining the second information of the target object includes:
[0021] Acquire the two-dimensional code data of the target object, wherein the two-dimensional code data is encrypted data;
[0022] Determining a target encryption algorithm for the two-dimensional code data;
[0023] Decrypt the QR code data according to the target encryption algorithm to obtain the ID number of the target object;
[0024] According to the ID number, query in the database to obtain the second certificate information of the target object;
[0025] Acquiring second real-time biological information of the target object;
[0026] The second certificate information includes the identity information, certificate status information, authority information and one or more associated authority-leading object information of the target object, and the second real-time biometric information includes one or more of fingerprint information, iris information and face information.
[0027] Optionally, after configuring target permissions for the target object according to the first information and / or the second information, the method further includes:
[0028] According to the first information, the second information and the permission configuration result of the target object, the permission configuration record of the target object and the permission configuration record of the permission leading object are updated.
[0029] Optionally, the target authority includes one or more of area access authority, information access authority, equipment operation authority and resource use authority in the airport environment.
[0030] In addition, to achieve the above objectives, the present disclosure also provides a rights management system, including:
[0031] An information input device, used to collect and input user information of the target object and the authority leading object, wherein the user information includes certificate information and biometric information;
[0032] An information encryption device, used to encrypt the user information to obtain encrypted information;
[0033] A certificate generating device, used to generate an electronic certificate and / or a physical certificate according to the user information and / or the encrypted information;
[0034] The permission configuration device is used to configure permissions for the target object and / or the permission leading object.
[0035] Optionally, the authority configuration device includes:
[0036] A first acquisition module, configured to obtain first information of a permission leading object corresponding to the target object in response to a permission configuration request of the target object;
[0037] A first verification module, used for verifying the permission-guiding object based on the first information;
[0038] A second acquisition module, used for acquiring second information of the target object when the permission-led object is verified;
[0039] A second verification module, used to verify the target object based on the second information;
[0040] The permission configuration module is used to configure target permissions for the target object according to the first information and / or the second information when the target object is verified.
[0041] In addition, to achieve the above objectives, the present disclosure also provides a computer-readable storage medium, on which a computer program is stored, and a processor executes the computer program to implement the above method.
[0042] In addition, to achieve the above object, the present disclosure further provides an electronic device, which includes a memory and a processor. A computer program is stored in the memory, and the processor executes the computer program to implement the above method.
[0043] In addition, to achieve the above object, the present disclosure further provides a computer program product, which implements the above method when being run by a processor.
[0044] Through the above technical solution, in response to a permission configuration request of a target object, first obtain first information of a permission leading object corresponding to the target object, and based on the first information, verify the permission leading object. When the permission leading object is verified to be passed, obtain second information of the target object, and based on the second information, verify the target object. When the target object is verified to be passed, configure target permissions for the target object according to the first information and / or the second information. In this way, by immediately responding to the permission configuration request and introducing a dual verification mechanism, that is, first verifying the permission leading object and then verifying the target object, it is ensured that only strictly screened personnel can obtain access permissions. This process not only reduces the cumbersome manual review but also improves the accuracy of permission configuration. Dynamically configuring target permissions according to the verification result and the actual needs of the target object can adjust the permission settings according to different situations, further enhancing the security. This automated verification and permission configuration method reduces the workload of manual review and registration, simplifies the permission configuration process, and helps improve the efficiency and accuracy of airport management. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] To more clearly illustrate the technical solutions in the embodiments of the present disclosure or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present disclosure. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on the structures shown in these drawings.
[0046] Figure 1 It is a schematic diagram of the device structure of the hardware operating environment related to the solution of the embodiment of the present disclosure;
[0047] Figure 2 It is a schematic flowchart of a permission configuration method related to the solution of the embodiment of the present disclosure;
[0048] Figure 3 It is a block diagram of the structure of a permission configuration device related to the solution of the embodiment of the present disclosure.
[0049] The implementation, functional features, and advantages of the object of the present disclosure will be further described in conjunction with the embodiments with reference to the drawings. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0050] The following will be combined with the drawings in the embodiments of the present disclosure to clearly and completely describe the technical solutions in the embodiments of the present disclosure. Obviously, the described embodiments are only part of the embodiments of the present disclosure, rather than all the embodiments. Based on the embodiments in the present disclosure, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present disclosure.
[0051] Reference Figure 1 , Figure 1 The figure is a schematic diagram of the device structure of the hardware operating environment involved in the embodiment of the present disclosure.
[0052] Typically, the device includes: at least one processor 301, a memory 302, and a permission configuration program stored in the memory 302 and executable on the processor 301, wherein the permission configuration program is configured to implement the steps of the permission configuration method described above.
[0053] The processor 301 may include one or more processing cores, such as a 4-core processor, an 8-core processor, etc. The processor 301 may be implemented in at least one hardware form of DSP (Digital Signal Processing), FPGA (Field-Programmable Gate Array), and PLA (Programmable Logic Array). The processor 301 may also include a main processor and a coprocessor. The main processor is a processor for processing data in the awake state, also known as a CPU (Central Processing Unit); the coprocessor is a low-power processor for processing data in the standby state. In some embodiments, the processor 301 may be integrated with a GPU (Graphics Processing Unit), which is responsible for rendering and drawing the content to be displayed on the display screen. The processor 301 may also include an AI (Artificial Intelligence) processor, which is used to process operations related to the permission configuration method, so that the permission configuration method model can be trained and learned autonomously to improve efficiency and accuracy.
[0054] The memory 302 may include one or more storage media, which may be non-transitory. The memory 302 may also include a high-speed random access memory, and a non-volatile memory, such as one or more disk storage devices, flash memory storage devices. In some embodiments, the non-transitory storage medium in the memory 302 is used to store at least one instruction, which is used to be executed by the processor 301 to implement the permission configuration method provided in the method embodiment of the present disclosure.
[0055] In some embodiments, the terminal may further optionally include: a communication interface 303 and at least one peripheral device. The processor 301, the memory 302 and the communication interface 303 may be connected via a bus or a signal line. Each peripheral device may be connected to the communication interface 303 via a bus, a signal line or a circuit board. Specifically, the peripheral device includes: at least one of a radio frequency circuit 304, a display screen 305 and a power supply 306.
[0056] The communication interface 303 may be used to connect at least one peripheral device related to I / O (Input / Output) to the processor 301 and the memory 302. In some embodiments, the processor 301, the memory 302, and the communication interface 303 are integrated on the same chip or circuit board; in some other embodiments, any one or two of the processor 301, the memory 302, and the communication interface 303 may be implemented on a separate chip or circuit board, which is not limited in this embodiment.
[0057] The radio frequency circuit 304 is used to receive and transmit RF (Radio Frequency) signals, also known as electromagnetic signals. The radio frequency circuit 304 communicates with the communication network and other communication devices through electromagnetic signals. The radio frequency circuit 304 converts electrical signals into electromagnetic signals for transmission, or converts received electromagnetic signals into electrical signals. Optionally, the radio frequency circuit 304 includes: an antenna system, an RF transceiver, one or more amplifiers, a tuner, an oscillator, a digital signal processor, a codec chipset, a user identity module card, and the like. The radio frequency circuit 304 can communicate with other terminals through at least one wireless communication protocol. The wireless communication protocol includes, but is not limited to: a metropolitan area network, various generations of mobile communication networks (2G, 3G, 4G and 5G), a wireless local area network and / or a WiFi (Wireless Fidelity) network. In some embodiments, the radio frequency circuit 304 may also include circuits related to NFC (Near Field Communication), which is not limited in the present disclosure.
[0058] The display screen 305 is used to display the UI (User Interface). The UI may include graphics, text, icons, videos, and any combination thereof. When the display screen 305 is a touch display screen, the display screen 305 also has the ability to collect touch signals on the surface or above the surface of the display screen 305. The touch signal can be input to the processor 301 as a control signal for processing. At this time, the display screen 305 can also be used to provide virtual buttons and / or virtual keyboards, also known as soft buttons and / or soft keyboards. In some embodiments, the display screen 305 can be one, the front panel of the electronic device; in other embodiments, the display screen 305 can be at least two, respectively arranged on different surfaces of the electronic device or in a folding design; in some embodiments, the display screen 305 can be a flexible display screen, arranged on a curved surface or a folding surface of the electronic device. Even, the display screen 305 can also be set to a non-rectangular irregular shape, that is, a special-shaped screen. The display screen 305 can be made of materials such as LCD (Liquid Crystal Display), OLED (Organic Light-Emitting Diode, organic light-emitting diode).
[0059] The power supply 306 is used to power various components in the electronic device. The power supply 306 can be AC power, DC power, a disposable battery, or a rechargeable battery. When the power supply 306 includes a rechargeable battery, the rechargeable battery can support wired charging or wireless charging. The rechargeable battery can also be used to support fast charging technology. Those skilled in the art will understand that Figure 1 The structure shown in the figure does not constitute a limitation of the device, and may include more or less components than shown in the figure, or combine certain components, or arrange the components differently.
[0060] In addition, the embodiment of the present disclosure further proposes a storage medium, on which a permission configuration program is stored, and when the permission configuration program is executed by a processor, the steps of the permission configuration method described above are implemented. Therefore, it will not be repeated here. In addition, the description of the beneficial effects of adopting the same method will not be repeated. For technical details not disclosed in the storage medium embodiment involved in the present disclosure, please refer to the description of the method embodiment of the present disclosure. As an example, the program instructions can be deployed to be executed on one device, or on multiple devices located at one location, or on multiple devices distributed at multiple locations and interconnected by a communication network.
[0061] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiments can be implemented by instructing related hardware through a computer program, and the above-mentioned program can be stored in a storage medium, and when the program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, the above-mentioned storage medium can be a disk, an optical disk, a read-only memory (ROM) or a random access memory (RAM), etc.
[0062] In the related technologies, for example, in the management of temporary personnel entering the control area, the traditional management method mainly relies on PVC material certificates without chips or paper certificates. Although these certificates are low-cost, they lack modern identification and verification methods. This has led to airports having to rely heavily on manual verification and registration when performing security checks. This is not only inefficient and increases the burden on staff, but is also prone to security omissions due to human factors, such as certificate forgery and fraudulent use, which are difficult to effectively prevent.
[0063] Therefore, it is particularly important to develop a permission configuration method that can reduce costs and achieve efficient and intelligent verification.
[0064] In view of this, the present disclosure provides a permission configuration method, system, storage medium and electronic device to solve the above technical problems.
[0065] Reference Figure 2 , Figure 2 The following is a flowchart of a permission configuration method according to an embodiment of the present disclosure, including the following steps:
[0066] Step S11: in response to the permission configuration request of the target object, obtaining first information of the permission leading object corresponding to the target object.
[0067] Step S12: Based on the first information, verify the authority-guiding object.
[0068] Step S13: When the authority-guided object is verified, the second information of the target object is obtained.
[0069] Step S14: verifying the target object based on the second information.
[0070] Step S15: When the target object passes the verification, target permissions are configured for the target object according to the first information and / or the second information.
[0071] It is worth noting that the target object can be one or more temporary personnel, and the authority leading object is the role of a guide and leader for temporary personnel to enter a specific area or obtain specific permissions. The authority leading object provides temporary personnel with legality and legitimacy endorsement of entry or operation through its own official documents and permissions, ensuring that temporary personnel can obtain corresponding permissions in accordance with prescribed procedures and requirements. The authority leading object not only refers to a certain staff member, but also an auxiliary element that plays a key role in the authority allocation system. They swipe their official documents for identity authentication and authority verification, provide the system with necessary input information, and thus trigger the system's allocation and verification process of temporary personnel permissions.
[0072] Through the above technical solution, in response to the permission configuration request of the target object, the first information of the permission leading object corresponding to the target object is first obtained, and the permission leading object is verified based on the first information. In the case where the permission leading object is verified, the second information of the target object is obtained, and the target object is verified based on the second information. In the case where the target object is verified, the target permission is configured for the target object according to the first information and / or the second information. In this way, by responding to the permission configuration request immediately and introducing a double verification mechanism, that is, first verifying the permission leading object and then verifying the target object, it is ensured that only strictly screened personnel can obtain access rights. This process not only reduces the tediousness of manual review, but also improves the accuracy of permission configuration. According to the verification results and the actual needs of the target object, the target permission is dynamically configured, and the permission setting can be adjusted according to different situations, further enhancing security. This automated verification and permission configuration method reduces the workload of manual review and registration, simplifies the permission configuration process, and helps to improve the efficiency and accuracy of airport management.
[0073] In a possible manner, after configuring the target permission for the target object according to the first information and / or the second information, the method further includes:
[0074] According to the first information, the second information and the permission configuration result of the target object, the permission configuration record of the target object and the permission configuration record of the permission leading object are updated.
[0075] It should be understood that in order to ensure the accuracy and traceability of the permission configuration, the permission configuration records of the target object and the permission-leading object can be updated after the permission configuration is completed. Not only can the detailed information of the permission configuration be recorded, including the time, content and information based on the configuration (first information and second information), but also the integrity and consistency of the permission configuration history can be ensured. By updating the permission configuration records in real time, it can provide strong support for subsequent auditing, tracing and permission adjustment.
[0076] In a possible manner, the target authority includes one or more of area access authority, information access authority, equipment operation authority, and resource use authority in the airport environment.
[0077] For example, in an airport environment, in addition to regional access rights, information access rights, equipment operation rights, and resource use rights, there are many similar rights that are intended to ensure the safety, order, and efficiency of airport operations. The present disclosure does not limit the specific scope of the target rights.
[0078] Among them, regional access rights may include the access rights of various types of personnel and vehicles in different areas within the airport. Information access rights may include information viewing rights of corresponding information systems such as flight information, passenger information, and freight information. Equipment operation rights may include operation rights of professional equipment such as baggage conveyor belts, security inspection equipment, and boarding bridges. Resource use rights may include the use rights of relevant resources such as conference rooms, lounges, and office equipment.
[0079] In a possible manner, based on the first information, verifying the authority leading object includes:
[0080] Determine the first certificate information and the first real-time biometric information of the authority-guiding object according to the first information;
[0081] Verify the certificate information of the authority-leading object according to the first certificate information;
[0082] When the certificate information of the authority-leading object is verified, the first real-time biometric information is compared with the biometric information pre-stored in the database to perform biometric verification on the authority-leading object;
[0083] Among them, the first certificate information includes the identity information, certificate status information, authority information and one or more associated target object information of the authority-leading object, and the first real-time biometric information includes one or more of fingerprint information, iris information and face information.
[0084] It should be understood that the first certificate information is the information contained on the certificate presented by the authority leading object, including but not limited to the identity information of the object (such as name, certificate number, affiliated unit, certificate start date, certificate end date, leader name, leader unit, certificate QR code, etc.), certificate status information (whether the certificate is valid, whether it is expired, etc.), authority information (areas, information, equipment, etc. that the authority leading object is authorized to access) and one or more target object information associated with the authority leading object (for example, if the target object is a team member, it can also include the team name, team leader, etc.).
[0085] The first real-time biometric information is the biometric information provided by the authority leading object in real time during the verification process, including one or more of fingerprint information, iris information and face information. These biometric information are used to compare with the pre-stored information in the database to confirm the identity of the authority leading object.
[0086] For example, the first certificate information is verified first to check the authenticity and validity of the certificate and whether the permission information on the certificate is consistent with the permission configuration request. For example, you can check whether the certificate number is valid, whether the certificate is expired, and whether the permissions on the certificate allow access to the requested resources. Checking the authenticity and validity of the certificate can include checking the anti-counterfeiting features of the certificate, the validity period, whether it has been reported lost or cancelled, etc. If the first certificate information verification fails, the permission-leading object's request for leadership should be rejected, and a corresponding error prompt should be given.
[0087] After the first certificate information is verified, the biometric feature comparison verification is performed. The first real-time biometric information can be compared with the biometric information pre-stored in the database. Since biometric information is highly unique and stable, this verification step can further improve the accuracy and security of identity confirmation.
[0088] If the first real-time biometric information matches the biometric information pre-stored in the database, the permission-leading object will be confirmed as a legitimate user and allowed to continue the subsequent permission-leading process, such as entering a specific area, accessing specific information, or operating a specific device.
[0089] This technical solution, by combining the methods of document information and biometric verification, ensures that only legitimate and authenticated users can obtain the corresponding permissions, thereby improving the security and management efficiency of places such as airports.
[0090] In a possible manner, verifying the certificate information of the authority-leading object according to the first certificate information includes:
[0091] Determining whether the first certificate information is valid;
[0092] If the first certificate information is valid, determining whether the authority leading object has the leading authority to lead the target object according to the first certificate information;
[0093] In the case where the authority leading object has leading authority, it is determined that the certificate information verification of the authority leading object has passed.
[0094] For example, a detailed check of the first certificate information provided by the authority guidance object may include verifying whether the format of the certificate is correct, whether the certificate number exists, whether the certificate has expired or been cancelled, etc. Through this step, those authority guidance objects holding invalid certificates can be screened out to prevent them from further authority guidance, thereby improving the accuracy of authority configuration.
[0095] After confirming that the first certificate information is valid, the authority information of the authority leading object is further analyzed. This information usually includes but is not limited to the target object that the authority leading object can lead, the scope of the leading (such as a specific area in the airport), the time period of the leading, etc. By comparing the certificate information of the authority leading object with the information in the authority configuration request, it is determined whether the authority leading object has the authority to lead the target object.
[0096] If the above two-step verification confirms that the certificate information of the authority leading object is both valid and contains the authority of the leading target object, it can be determined that the certificate information of the authority leading object has passed the verification. At this time, the authority leading object can be allowed to continue the subsequent authority leading process.
[0097] In a possible manner, when the authority-guided object is verified, obtaining the second information of the target object includes:
[0098] Get the QR code data of the target object, which is encrypted data;
[0099] Determine the target encryption algorithm for the QR code data;
[0100] According to the target encryption algorithm, the QR code data is decrypted to obtain the ID number of the target object;
[0101] According to the ID number, query in the database to obtain the second certificate information of the target object;
[0102] Acquiring second real-time biological information of the target object;
[0103] The second certificate information includes identity information, certificate status information, authority information and one or more associated authority-leading object information of the target object, and the second real-time biometric information includes one or more of fingerprint information, iris information and face information.
[0104] For example, a scanning device (such as a smart phone, barcode scanner, etc.) can be used to scan the QR code of the target object's ID card. The QR code data can be encoded using QR Code, combined with the AES-128 encryption algorithm to ensure data security. By encrypting the ID number representing the uniqueness of the document information with AES-128, only the encrypted ID number is stored in the QR code, rather than the direct document information, and must be decrypted using the same AES-128 key as when it was encrypted. This ensures that even if the QR code is scanned, its actual content cannot be obtained without the correct decryption key, greatly improving the security level of the QR code and preventing unauthorized access and tampering.
[0105] In a possible manner, verifying the target object based on the second information includes:
[0106] Verifying the certificate information of the target object according to the first certificate information and the second information;
[0107] When the certificate information of the target object is verified, the second real-time biometric information is compared with the biometric information pre-stored in the database to verify the target object.
[0108] For example, the method of verifying the certificate information of the target object is the same as the method of verifying the certificate information of the authority-leading object, and the present disclosure will not elaborate on it here.
[0109] The present disclosure also provides a rights management system, comprising:
[0110] An information input device, used to collect and input user information of the target object and the authority-leading object, the user information including certificate information and biometric information;
[0111] An information encryption device, used to encrypt user information to obtain encrypted information;
[0112] A certificate generating device, used to generate an electronic certificate and / or a physical certificate based on user information and / or encrypted information;
[0113] The permission configuration device is used to configure permissions for the target object and / or the permission leading object.
[0114] For example, the information entry device collects user information of the target object and the authority leading object through various input devices (such as cameras, fingerprint identifiers, iris scanners, document readers, etc.), and enters the collected user information (including document information and biometric information) into the system database for subsequent processing.
[0115] The information encryption device uses encryption algorithms (such as AES, RSA, etc.) to encrypt user information to protect the confidentiality and integrity of user information. The encrypted information (encrypted message) will be more difficult for unauthorized parties to obtain or tamper with, thereby ensuring the security of user information during storage and transmission.
[0116] The certificate generation device generates electronic certificates and / or physical certificates based on user information and / or encrypted information. Among them, the electronic certificate can be stored in digital devices (such as mobile phones, computers), which is convenient for carrying and verification. The physical certificate exists in paper or other physical forms and is applicable to occasions that require physical vouchers. The certificate can contain anti-counterfeiting elements such as QR codes, barcodes, encrypted watermarks, etc. to increase the authenticity and security of the certificate. The certificate information can be associated with the user information database for verification when needed.
[0117] The permission configuration device configures permissions for the target object and / or the permission leading object, and defines the access permissions and operation permissions on specific resources of the system. Among them, the permission configuration can be flexibly set according to factors such as user roles, departments, positions, etc. In this way, refined permission management can be achieved, ensuring that each user can only access the resources they are authorized to. Improve the security and manageability of the system, and reduce security risks caused by improper permissions.
[0118] Through the above permission management system, by integrating functions such as information collection, encryption, certificate generation, and permission configuration, an efficient and secure permission management system is constructed to ensure the security of user information and the accuracy of permission management.
[0119] Refer to Figure 3 , Figure 3 FIG. is a structural block diagram of a permission configuration device involved in the solution of an embodiment of the present disclosure. Based on the same inventive concept as the foregoing embodiment, the device includes:
[0120] The first acquisition module 10 is configured to acquire first information of the permission leading object corresponding to the target object in response to a permission configuration request of the target object;
[0121] The first verification module 20 is configured to verify the permission leading object based on the first information;
[0122] The second acquisition module 30 is configured to acquire second information of the target object when the permission leading object passes the verification;
[0123] The second verification module 40 is configured to verify the target object based on the second information;
[0124] The permission configuration module 50 is used to configure target permissions for the target object according to the first information and / or the second information when the target object is verified.
[0125] Optionally, the first verification module 20 is used to:
[0126] Determine the first certificate information and the first real-time biometric information of the authority-leading object according to the first information;
[0127] Verifying the certificate information of the authority-guiding object according to the first certificate information;
[0128] When the certificate information of the authority leading object is verified, the first real-time biometric information is compared with the biometric information pre-stored in the database to perform biometric verification on the authority leading object;
[0129] Among them, the first certificate information includes the identity information, certificate status information, authority information and one or more associated target object information of the authority-leading object, and the first real-time biometric information includes one or more of fingerprint information, iris information and face information.
[0130] Optionally, the first verification module 20 is used to:
[0131] Determining whether the first certificate information is valid;
[0132] If the first certificate information is valid, determining whether the authorized leading object has the leading authority to lead the target object according to the first certificate information;
[0133] In the case that the authority leading object has the leading authority, it is determined that the certificate information verification of the authority leading object has passed.
[0134] Optionally, the second acquisition module 30 is used to:
[0135] Acquire the two-dimensional code data of the target object, wherein the two-dimensional code data is encrypted data;
[0136] Determining a target encryption algorithm for the two-dimensional code data;
[0137] Decrypt the QR code data according to the target encryption algorithm to obtain the ID number of the target object;
[0138] According to the ID number, query in the database to obtain the second certificate information of the target object;
[0139] Acquiring second real-time biological information of the target object;
[0140] The second certificate information includes the identity information, certificate status information, authority information and one or more associated authority-leading object information of the target object, and the second real-time biometric information includes one or more of fingerprint information, iris information and face information.
[0141] Optionally, the permission configuration device further includes an updating module, and the updating module is used to:
[0142] After configuring the target permission for the target object according to the first information and / or the second information, the permission configuration record of the target object and the permission configuration record of the permission-leading object are updated according to the first information, the second information and the permission configuration result of the target object.
[0143] Optionally, the target authority includes one or more of area access authority, information access authority, equipment operation authority and resource use authority in the airport environment.
[0144] It should be noted that, since the steps executed by the device of this embodiment are the same as the steps of the aforementioned method embodiment, its specific implementation method and the technical effects that can be achieved can refer to the aforementioned embodiment and will not be repeated here.
[0145] In addition, in one embodiment, an embodiment of the present disclosure further provides an electronic device, which includes a processor, a memory, and a computer program stored in the memory, and the computer program implements the steps of the method in the aforementioned embodiment when executed by the processor.
[0146] In addition, in one embodiment, an embodiment of the present disclosure further provides a computer storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the method in the aforementioned embodiment are implemented.
[0147] In some embodiments, the computer readable storage medium may be a memory such as FRAM, ROM, PROM, EPROM, EEPROM, flash memory, magnetic surface memory, optical disk, or CD-ROM; or various devices including one or any combination of the above memories. The computer may be various computing devices including intelligent terminals and servers.
[0148] In some embodiments, executable instructions may be in the form of a program, software, software module, script or code, written in any form of programming language (including compiled or interpreted languages, or declarative or procedural languages), and may be deployed in any form, including as a stand-alone program or as a module, component, subroutine or other unit suitable for use in a computing environment.
[0149] As an example, executable instructions may, but need not, correspond to a file in a file system, may be stored as part of a file that stores other programs or data, such as in one or more scripts in a HyperText Markup Language (HTML) document, in a single file dedicated to the program in question, or in multiple coordinated files (e.g., files storing one or more modules, subroutines, or code portions).
[0150] By way of example, executable instructions may be deployed to be executed on one computing device, or on multiple computing devices located at one site, or on multiple computing devices distributed across multiple sites and interconnected by a communication network.
[0151] It should be noted that, in this article, the terms "include", "may include" or any other variations thereof are intended to cover non-exclusive inclusions, so that a process, method, article or system including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or system. In the absence of further restrictions, an element defined by the sentence "includes a ..." does not exclude the existence of other identical elements in the process, method, article or system including the element.
[0152] The serial numbers of the above-mentioned embodiments of the present disclosure are only for description and do not represent the advantages or disadvantages of the embodiments.
[0153] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus a necessary general hardware platform, and of course by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present disclosure, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as a read-only memory / random access memory, a magnetic disk, or an optical disk), and includes a number of instructions for enabling a multimedia terminal device (which can be a mobile phone, a computer, a television receiver, or a network device, etc.) to execute the methods described in each embodiment of the present disclosure.
[0154] The above descriptions are only optional embodiments of the present disclosure, and are not intended to limit the patent scope of the present disclosure. All equivalent structural transformations made using the contents of the present disclosure and the drawings under the inventive concept of the present disclosure, or direct / indirect applications in other related technical fields are included in the patent protection scope of the present disclosure.
Claims
1. A permission configuration method, characterized in that: include: In response to a permission configuration request of a target object, obtaining first information of a permission leading object corresponding to the target object; Based on the first information, verifying the permission guidance object; When the permission-guided object is verified, obtaining second information of the target object; Based on the second information, verifying the target object; When the target object passes the verification, target permissions are configured for the target object according to the first information and / or the second information.
2. The method according to claim 1, characterized in that The verifying the permission guidance object based on the first information includes: Determine the first certificate information and the first real-time biometric information of the authority-leading object according to the first information; Verifying the certificate information of the authority-guiding object according to the first certificate information; When the certificate information of the authority leading object is verified, the first real-time biometric information is compared with the biometric information pre-stored in the database to perform biometric verification on the authority leading object; Among them, the first certificate information includes the identity information, certificate status information, authority information and one or more associated target object information of the authority-leading object, and the first real-time biometric information includes one or more of fingerprint information, iris information and face information.
3. The method according to claim 2, characterized in that The verifying the certificate information of the authority leading object according to the first certificate information includes: Determining whether the first certificate information is valid; If the first certificate information is valid, determining whether the authorized leading object has the leading authority to lead the target object according to the first certificate information; In the case that the authority leading object has the leading authority, it is determined that the certificate information verification of the authority leading object has passed.
4. The method according to claim 1, characterized in that: When the authority-guided object is verified, obtaining the second information of the target object includes: Acquire the two-dimensional code data of the target object, wherein the two-dimensional code data is encrypted data; Determining a target encryption algorithm for the two-dimensional code data; Decrypt the QR code data according to the target encryption algorithm to obtain the ID number of the target object; According to the ID number, query in the database to obtain the second certificate information of the target object; Acquiring second real-time biological information of the target object; The second certificate information includes the identity information, certificate status information, authority information and one or more associated authority-leading object information of the target object, and the second real-time biometric information includes one or more of fingerprint information, iris information and face information.
5. The method according to claim 1, characterized in that After configuring the target permission for the target object according to the first information and / or the second information, the method further includes: According to the first information, the second information and the permission configuration result of the target object, the permission configuration record of the target object and the permission configuration record of the permission leading object are updated.
6. The method according to any one of claims 1 to 5, characterized in that: The target authority includes one or more of area access authority, information access authority, equipment operation authority, and resource use authority in the airport environment.
7. A rights management system, characterized in that: include: An information input device, used to collect and input user information of the target object and the authority leading object, wherein the user information includes certificate information and biometric information; An information encryption device, used to encrypt the user information to obtain encrypted information; A certificate generating device, used to generate an electronic certificate and / or a physical certificate according to the user information and / or the encrypted information; The permission configuration device is used to configure permissions for the target object and / or the permission leading object.
8. The system according to claim 7, characterized in that The authority configuration device comprises: A first acquisition module, configured to obtain first information of a permission leading object corresponding to the target object in response to a permission configuration request of the target object; A first verification module, used for verifying the permission-guiding object based on the first information; A second acquisition module, used for acquiring second information of the target object when the permission-led object is verified; A second verification module, used to verify the target object based on the second information; The permission configuration module is used to configure target permissions for the target object according to the first information and / or the second information when the target object is verified.
9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and the processor executes the computer program to implement the method according to any one of claims 1 to 7.
10. An electronic device, characterized in that: The electronic device comprises a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Guide method and device applied to unmanned vehicle
CN110619760A
System and method for checking entry of people, vehicles and objects in chemical industrial park
CN112927405A
Linkage type non-contact man-vehicle verification system
CN118711362A