Universal user white list integration system

By designing a general user whitelist integration system and adopting a combination of push and pull modes, whitelist integration and synchronization between companies and systems is achieved, solving the problems of low whitelist management efficiency and difficulty in data synchronization in the existing technology, and improving data management efficiency and data consistency.

CN120045620APending Publication Date: 2025-05-27NANJING WANDE INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510070135.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-16
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

The existing technology is difficult to achieve user whitelist integration between companies and systems, resulting in low efficiency in whitelist management, difficult data synchronization, and requires a lot of manual intervention.

Method used

A general user whitelist integration system is designed, using a combination of push mode and pull mode. Through whitelist synchronization, update module, whitelist verification module, whitelist cache, speedup module and whitelist storage module, the integration and unified management of user whitelists among multiple systems and multiple platforms of different companies are realized.

Benefits of technology

It realizes the automated integration and synchronization of user whitelists, reduces manual intervention, improves data management efficiency, ensures the accuracy and consistency of whitelist data, and meets the needs of whitelist data sharing and unified integration in cross-platform and multi-system environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120045620A_ABST
    Figure CN120045620A_ABST
Patent Text Reader

Abstract

The invention provides a universal user white list integration system, which is used for realizing the integration and unification of user white lists among multiple systems and multiple platforms of different companies, and is characterized by comprising a white list synchronization and updating module; a white list verification module; a white list caching and acceleration module; and a white list storage module. The method not only can be applied to data protection, but also can guarantee the security of personal privacy. Specifically, the invention provides an efficient and reliable method to ensure the accuracy and consistency of the user white list, thereby realizing seamless security integration between different companies and systems. Therefore, in the current digital era, the method is crucial to enterprises and individuals.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of computer network data security, and focuses on the integration of user white lists across companies and systems. Background Art

[0002] Currently, most enterprises and institutions manage user white lists by building or purchasing CRM systems (Customer Relationship Management systems) themselves. However, most of these traditional management methods rely on manual operations on the interface to maintain the white list, and this method is only applicable to the management of white lists within a single enterprise. In the face of cross-enterprise cooperation and the need to share white lists, traditional methods are inadequate. Usually, many companies have to use emails, file transfers, or invest additional manpower and resources to develop new systems to achieve the synchronization and integration of white lists. This is not only time-consuming and laborious but also highly customized.

[0003] To solve these problems, there is an urgent need in the market for a general white list integration solution. This solution should be able to automatically integrate the white lists of multiple systems, thereby releasing human resources and improving work efficiency. Through such an integrated system, enterprises can efficiently manage the white list requirements in cross-enterprise cooperation, achieve seamless synchronization and integration of data, and then optimize business processes and improve overall operational efficiency. Summary of the Invention

[0004] The object of the present invention is to propose an innovative general white list integration system, aiming to replace the traditional method of manually reviewing and maintaining user white lists.

[0005] To achieve the above object, the technical solution of the present invention discloses a general user white list integration system for realizing the integration and unification of user white lists among multiple systems and platforms of different companies. It is characterized by including:

[0006] A white list synchronization and update module for obtaining and integrating user white list data among multiple systems and platforms of different companies, adopting a push mode - real-time push mode, a pull mode - batch pull - full amount pull mode, a pull mode - batch pull - incremental pull mode, a pull mode - single item verification - preloading mode, and a pull mode - single item verification - real-time loading / asynchronous loading, where:

[0007] In the push mode - real-time push mode, different platforms and / or different systems of cooperating companies synchronize and update user white list data by pushing messages to the white list synchronization and update module;

[0008] In the pull mode - batch pull - full - volume pull mode, different platforms and / or different systems of the partner company provide a whitelist synchronization interface. The whitelist synchronization and update module pulls the full - volume user whitelist data page by page at a fixed time every day for matching and updating;

[0009] In the pull mode - batch pull - incremental pull mode, different platforms and / or different systems of the partner company provide a whitelist synchronization interface. The whitelist synchronization and update module pulls the changed user whitelist data multiple times at a fixed time every day for matching and updating;

[0010] In the pull mode - single - item verification - pre - loading mode, different platforms and / or different systems of the partner company provide a whitelist synchronization interface. The whitelist synchronization and update module uses the built - in user identity information to call the interface at a fixed time every day to determine whether the user belongs to the corresponding whitelist;

[0011] In the pull mode - single - item verification - real - time loading / asynchronous loading mode, different platforms and / or different systems of the partner company provide a whitelist synchronization interface. The whitelist synchronization and update module triggers the whitelist interface call when receiving the whitelist request for the corresponding user to determine whether the user belongs to the whitelist. The pull mode - single - item verification - real - time loading / asynchronous loading mode is combined with the asynchronous mode, that is, real - time loading is performed when exceeding the set cache time range, and asynchronous loading is performed within the cache time range to update the whitelist. Among them, the asynchronous loading mode can also set the cache time, that is, asynchronous loading and updating are performed when exceeding the cache time, and no execution is performed within the cache time;

[0012] The whitelist verification module is used to receive and process the user whitelist verification requirements from different request sources. By using the integrated user whitelist data, it determines and confirms whether there is a legal association between the user mentioned in the request and a specific whitelist;

[0013] The whitelist caching and speed - up module is used to effectively manage the user whitelist data by using shared cache and local memory cache; The whitelist caching and speed - up module establishes an inverted index structure from whitelist ID to user ID and stores it in the cache;

[0014] The whitelist storage module uses database technology to persistently store the final integrated result of the user whitelist.

[0015] Preferably, for the whitelist synchronization and update module, in the push mode - real - time push mode, 2 types of general message receiving methods are provided, namely Kafka message queue and HTTPS interface. The push message content adopted includes:

[0016] The whitelist ID field is used to identify which whitelist this operation is for;

[0017] The user unique identification field is the encrypted user mobile phone number or email address;

[0018] The whitelist status field is used to identify whether it is "delete whitelist" or "activate whitelist";

[0019] The operation time field is the time of this operation.

[0020] Preferably, for the whitelist synchronization and update module, in the pull mode - batch pull - full amount pull mode, 1 type of data pull method is provided, which is the HTTP / HTTPS interface. The pull content table used includes:

[0021] The user unique identification field is the encrypted user mobile phone number or email address;

[0022] The whitelist status field is used to identify whether it is "delete whitelist" or "activate whitelist";

[0023] The operation time field is the last operation time.

[0024] Preferably, for the whitelist synchronization and update module, in the pull mode - batch pull - incremental pull mode, 1 type of data pull method is supported, which is the HTTP / HTTPS interface. The pull content includes:

[0025] The user unique identification field is the encrypted user mobile phone number or email address;

[0026] The whitelist status field is used to identify whether it is "delete whitelist" or "activate whitelist";

[0027] The operation time field is the last operation time.

[0028] Preferably, for the whitelist synchronization and update module, in the pull mode - single - item verification - pre - loading mode, 1 type of verification method is supported, which is the HTTP / HTTPS interface. The user information that can be provided includes:

[0029] The user unique identification field is the encrypted user mobile phone number or email address.

[0030] Preferably, for the whitelist synchronization and update module, the single - item pre - loading process adopted in the pull mode - single - item verification - pre - loading mode includes the following steps:

[0031] After the timing task starts to execute, obtain the built - in full - amount user IDs and identity information;

[0032] After generating the whitelist verification task by user, start to execute the task with multi - threads;

[0033] After execution is completed, analyze the verification result and perform user identity matching. If they match, update the corresponding whitelist.

[0034] Preferably, for the whitelist synchronization and update module, in the pull mode - single verification - real-time loading / asynchronous loading mode, 1 type of verification method is supported, which is the HTTP / HTTPS interface. The user information that can be provided includes:

[0035] The user unique identification field is the encrypted user mobile phone number or email.

[0036] Preferably, for the whitelist synchronization and update module, the single real-time / asynchronous loading process of the pull mode - single verification - real-time loading / asynchronous loading mode includes the following steps:

[0037] After receiving the user verification request, determine whether it exceeds the maximum cache time for real-time loading:

[0038] If it exceeds the maximum cache time for real-time loading, then:

[0039] Perform real-time loading and update. After passing the verification, put it into the corresponding whitelist.

[0040] If it does not exceed the maximum cache time for real-time loading, then:

[0041] Determine whether it exceeds the maximum cache time for asynchronous loading: if it exceeds, trigger asynchronous loading and update, and then return the last cached verification result of this user; if it does not exceed, directly return the last cached verification result of this user.

[0042] The present invention can not only be applied to data protection, but also ensure the security of personal privacy. Specifically, the present invention provides an efficient and reliable method to ensure the accuracy and consistency of the user whitelist, so as to achieve seamless security integration between different companies and systems. Therefore, in today's digital age, the present invention is crucial for both enterprises and individuals.

[0043] Compared with the prior art solutions, the present invention has the following characteristics:

[0044] 1. Improve efficiency and optimize the user experience:

[0045] Traditional access control methods may require a large amount of manual review and maintenance, such as through emails, work orders, file transfers, etc., with low efficiency and poor user experience. While an automated user whitelist integration system can reduce this workload and reduce security incidents or customer complaints caused by misoperations or untimely processing.

[0046] 2. Meet compliance requirements:

[0047] With the development of information technology, security issues such as data leakage, identity theft, and cyberattacks have become increasingly prominent. Enterprises and organizations need to ensure the security of sensitive data and user privacy, and the user whitelist integration system disclosed in the present invention provides a mechanism to protect data from unauthorized access by strictly controlling and verifying which users and devices can access sensitive information. Especially in the financial, healthcare, and public sectors, they are faced with more stringent data protection regulations

[0048] 3. Meet cross-platform and multi-system integration requirements:

[0049] The modern enterprise operation environment has become increasingly complex, involving multiple platforms and systems. The user whitelist integration system allows the sharing and synchronization of whitelist data between different systems, ensuring the consistency and security of the entire user whitelist system

[0050] The system disclosed in the present invention significantly improves efficiency through automated processing and greatly reduces the dependence on human resources. The present invention is particularly applicable to modern multi-enterprise cooperation models, effectively solving the problem of realizing whitelist data sharing and unified integration in a cross-platform and multi-system environment. The system disclosed in the present invention not only optimizes the data management process but also enhances the transparency and reliability of operations, ensuring that all parties can efficiently and securely access and manage the verified user list. The integrated solution disclosed in the present invention provides enterprises with a more flexible and easily expandable framework to support their ever-changing and increasingly complex business needs BRIEF DESCRIPTION OF THE DRAWINGS

[0051] Figure 1 is the overall system structure diagram;

[0052] Figure 2 is the data synchronization mode classification diagram;

[0053] Figure 3 is the push processing flow chart;

[0054] Figure 4 is the full-volume pull processing flow chart;

[0055] Figure 5 is the incremental pull processing flow chart;

[0056] Figure 6 is the single-item preloading flow chart;

[0057] Figure 7 is the single-item real-time / asynchronous loading flow chart;

[0058] Figure 8 is the whitelist verification flow chart;

[0059] Figure 9 is the whitelist cache structure diagram. Detailed Implementation Modes

[0060] The present invention will be further described below in conjunction with specific embodiments. It should be understood that these embodiments are only used to illustrate the present invention and not to limit the scope of the present invention. In addition, it should be understood that after reading the content taught by the present invention, those skilled in the art can make various changes or modifications to the present invention, and these equivalent forms also fall within the scope defined by the appended claims of this application.

[0061] The technical terms adopted in the technical solution disclosed by the present invention include:

[0062] 1. Kafka: A distributed stream processing component, mainly used to build real-time data pipelines and applications, and can efficiently process large-scale data streams.

[0063] 2. Redis: An open-source high-performance key-value in-memory database, which supports various data structures such as strings, hash tables, lists, sets, etc., and provides data persistence, automatic sharding, and built-in replication functions.

[0064] 3. Caffeine Cache: A high-performance Java cache library, designed for nearly optimal hit rates, and supports various expiration policies and automated memory management.

[0065] 4. HTTP / HTTPS: HTTP is a stateless application layer protocol for communication between clients and servers, while HTTPS is a secure version of HTTP, which encrypts data transmission through SSL / TLS to enhance security.

[0066] As Figure 1 shown, a general user whitelist integration system disclosed in an embodiment of the present invention is used to achieve the integration and unification of user whitelists among multiple systems and platforms of different companies. The present invention mainly includes:

[0067] Whitelist synchronization and update module: Used to obtain and update the user whitelist;

[0068] Whitelist cache acceleration module: Used to cache user whitelist data and speed up query;

[0069] Whitelist verification module: Used to provide an API externally for user whitelist verification;

[0070] Whitelist storage module: Used for the persistence of user whitelist data;

[0071] Among the above modules, the whitelist synchronization and update module is the core functional innovation point. Each module will be introduced separately below.

[0072] I) Whitelist synchronization and update module:

[0073] The core function of this module is to efficiently integrate user whitelist data across multiple platforms and systems of different companies. Facing the diverse platform and system environments of each company, this system has designed a variety of flexible data synchronization strategies. These general methods aim to achieve seamless docking and quickly adapt to the differences between different platforms, thus significantly reducing the development cost and time investment. By adopting these advanced data synchronization technologies, this module can easily interact with various platforms and systems, ensuring the real-time update and consistency of user whitelist data. This not only improves the efficiency of data processing but also enhances the scalability and compatibility of the system.

[0074] As Figure 2 shown, the whitelist data synchronization modes adopted by the whitelist synchronization and update module are mainly divided into 2 major categories and 6 sub-categories:

[0075] 1) Push mode - real-time push: That is, the platforms and systems of partner companies synchronize and update the whitelist data by pushing messages to this system.

[0076] a) This system currently provides 2 types of general message receiving methods:

[0077] (1) Kafka message queue

[0078] (2) HTTPS interface

[0079] b) Push message content:

[0080]

[0081] Table 1 Message content table

[0082] c) Internal processing flow, as Figure 3 shown.

[0083] 2) Pull mode - batch pull - full volume pull: That is, the platforms and systems of partner companies provide whitelist synchronization interfaces, and this system regularly pulls the full volume of user whitelist data in pages once a day for matching and updating.

[0084] a) This system currently supports 1 type of data pull method:

[0085] (1) HTTP / HTTPS interface

[0086] b) Pulled content (including but not limited to the following):

[0087]

[0088] Table 2 Pulled content table

[0089] c) Internal processing flow, asFigure 4 as shown

[0090] 3) Pull mode - batch pull - incremental pull: That is, the platform and system of the cooperating company provide a whitelist synchronization interface, and this system regularly pulls the changed user whitelist data multiple times a day for matching and updating.

[0091] a) This system currently supports 1 type of data pull method:

[0092] (1) HTTP / HTTPS interface

[0093] b) Pulled content (including but not limited to the following):

[0094]

[0095] Table 3 Pulled content table

[0096] c) Internal processing flow, as Figure 5 shown

[0097] 4) Pull mode - single - item verification - pre - loading: That is, the platform and system of the cooperating company provide a whitelist synchronization interface, and this system regularly uses the built - in user identity information to call the interface every day to determine whether the user belongs to the corresponding whitelist.

[0098] a) This system currently supports 1 type of verification method:

[0099] (1) HTTP / HTTPS interface

[0100] b) User information that can be provided:

[0101]

[0102] Table 4 User information provided table

[0103] c) Internal processing flow, as Figure 6 shown

[0104] 5) Pull mode - single - item verification - real - time loading / asynchronous loading: That is, the platform and system of the cooperating company provide a whitelist synchronization interface, and this system triggers the call of the whitelist interface when receiving the whitelist request corresponding to the user to determine whether the user belongs to the whitelist. To reduce the coupling between systems, this mode is usually combined with the asynchronous mode. That is, real - time loading is performed when the set cache time range is exceeded, and asynchronous loading is performed within the cache time range to update the whitelist. The asynchronous loading mode can also set a cache time, that is, asynchronous loading and updating are performed when the cache time is exceeded, and no execution is performed within the cache time.

[0105] a) This system currently supports 1 type of verification method:

[0106] (1)HTTP / HTTPS Interface

[0107] b) User information that can be provided:

[0108]

[0109] User information table provided in Table 5

[0110] c) Internal processing flow, such as Figure 7 as shown

[0111] II) Whitelist verification module:

[0112] The core function of this module is to receive and process the user whitelist verification requirements from different request sources. It accurately judges and confirms whether the users mentioned in the request have a legal association with a specific whitelist by using the user whitelist data integrated in this system. This process includes a detailed analysis of the matching degree between user information and whitelist criteria, so as to ensure that only verified and eligible users can access restricted resources or perform sensitive operations.

[0113] The user whitelist verification process adopted by the whitelist verification module is as Figure 8 shown

[0114] III) Whitelist caching and speed-up module:

[0115] The main function of this module is to effectively manage user whitelist data by using a shared cache (Redis) and a local memory cache (CaffeineCache). Specifically, it establishes an inverted index structure from whitelist ID to user ID and stores it in the cache. This method can significantly improve the efficiency of the system when performing user whitelist verification, thus accelerating the data processing speed and optimizing the overall performance. In addition, using this index structure helps to quickly locate and retrieve relevant information, further enhancing the system's support and response capabilities for the whitelist verification process.

[0116] The whitelist cache structure adopted by the whitelist caching and speed-up module is as Figure 9 shown

[0117] IV) Whitelist storage module:

[0118] The main function of this module is to persistently store the final integrated result of the user whitelist by using database technology. This process ensures that even in the case of cache invalidation or data loss, user whitelist information can still be safely saved and restored. By writing key data into a stable database system, the module provides a reliable backup mechanism, thus enhancing the protection of the entire system for data integrity and accessibility.

[0119] The following table is the database field table:

[0120]

[0121] Table 6 White list database storage field table.

Claims

1. A universal user whitelist integration system, used to achieve the integration and unification of user whitelists across multiple systems and platforms of different companies, characterized by: include: The whitelist synchronization and update module is used to obtain and integrate user whitelist data between multiple systems and platforms of different companies. It adopts push mode-real-time push mode, pull mode-batch pull-full pull mode, pull mode-batch pull-incremental pull mode, pull mode-single verification-preload mode and pull mode-single verification-real-time loading / asynchronous loading, among which: In push mode - real-time push mode, different platforms and / or different systems of the partner company synchronize and update the user whitelist data by pushing messages to the whitelist synchronization and update module; In the pull mode, batch pull mode, and full pull mode, different platforms and / or different systems of the partner company provide whitelist synchronization interfaces. The whitelist synchronization and update module pulls the full amount of user whitelist data in a scheduled page every day for matching and updating. In the pull mode, batch pull mode, and incremental pull mode, different platforms and / or different systems of the partner company provide whitelist synchronization interfaces. The whitelist synchronization and update modules pull the changed user whitelist data for matching and updating multiple times a day. In the pull mode - single verification - preload mode, different platforms and / or different systems of the partner company provide whitelist synchronization interfaces. The whitelist synchronization and update module uses the built-in user identity information to call the interface at regular intervals every day to determine whether the user belongs to the corresponding whitelist; In the pull mode - single verification - real-time loading / asynchronous loading mode, different platforms and / or different systems of the partner company provide whitelist synchronization interfaces. When receiving the whitelist request corresponding to the user, the whitelist synchronization and update module triggers the whitelist interface call to determine whether the user belongs to the whitelist; the pull mode - single verification - real-time loading / asynchronous loading mode is combined with the asynchronous mode, that is, real-time loading is performed when the set cache time range is exceeded, and asynchronous loading is performed within the cache time range to update the whitelist. The asynchronous loading mode can also set the cache time, that is, asynchronous loading and updating are performed when the cache time is exceeded, and no execution is performed within the cache time; The whitelist verification module is used to receive and process user whitelist verification requests from different request sources. By using the integrated user whitelist data, it determines and confirms whether the user mentioned in the request has a legal association with a specific whitelist; The whitelist cache and speed-up module is used to effectively manage the user whitelist data by using the shared cache and the local memory cache. The whitelist cache and speed-up module establishes an inverted index structure from the whitelist ID to the user ID and stores it in the cache. The whitelist storage module uses database technology to persistently store the final integrated results of the user whitelist.

2. A universal user whitelist integration system as claimed in claim 1, characterized in that: For the whitelist synchronization and update module, in the push mode-real-time push mode, two types of general message receiving methods are provided, namely Kafka message queue and HTTPS interface. The push message content used includes: The whitelist ID field is used to identify which whitelist this operation is on; The user's unique identification field is the encrypted user's mobile phone number or email address; Whitelist status field, used to identify "delete whitelist" or "enable whitelist"; The operation time field is the time of this operation.

3. A universal user whitelist integration system as claimed in claim 1, characterized in that: For the whitelist synchronization and update module, in the pull mode-batch pull-full pull mode, a type 1 data pull method is provided, which is an HTTP / HTTPS interface, and the pull content table used includes: The user's unique identification field is the encrypted user's mobile phone number or email address; Whitelist status field, used to identify "delete whitelist" or "enable whitelist"; The operation time field is the last operation time.

4. A universal user whitelist integration system as claimed in claim 1, characterized in that: For the whitelist synchronization and update module, in the pull mode-batch pull-incremental pull mode, a type 1 data pull method is supported, which is an HTTP / HTTPS interface. The pull content includes: The user's unique identification field is the encrypted user's mobile phone number or email address; Whitelist status field, used to identify "delete whitelist" or "enable whitelist"; The operation time field is the last operation time.

5. A universal user whitelist integration system as claimed in claim 1, characterized in that: For the whitelist synchronization and update module, in the pull mode-single verification-preload mode, a type 1 verification method is supported, which is an HTTP / HTTPS interface. The user information that can be provided includes: The user's unique identification field is the encrypted user's mobile phone number or email address.

6. A universal user whitelist integration system as claimed in claim 1, characterized in that: For the whitelist synchronization and update module, the single preloading process adopted by the pull mode-single verification-preloading mode includes the following steps: After the scheduled task starts executing, obtain the built-in full user ID and identity information; After generating a whitelist verification task according to the user, start multi-threaded execution of the task; After the execution is completed, the verification results are parsed and the user identity is matched. If a match is found, the corresponding whitelist is updated.

7. A universal user whitelist integration system as claimed in claim 1, characterized in that: For the whitelist synchronization and update module, in the pull mode-single verification-real-time loading / asynchronous loading mode, a type 1 verification method is supported, which is an HTTP / HTTPS interface. The user information that can be provided includes: The user's unique identification field is the encrypted user's mobile phone number or email address.

8. A universal user whitelist integration system as claimed in claim 1, characterized in that: For the whitelist synchronization and update module, the pull mode-single verification-real-time loading / asynchronous loading mode single real-time / asynchronous loading process includes the following steps: After receiving the user verification request, determine whether the maximum cache time for real-time loading has been exceeded: If the maximum cache time for real-time loading is exceeded, then: Perform real-time loading and updating, and put it into the corresponding whitelist after passing verification; If the maximum cache time for real-time loading is not exceeded, then: Determine whether the maximum cache time of asynchronous loading is exceeded: if exceeded, the asynchronous loading update is triggered and the last cache verification result of the user is returned; if not exceeded, the last cache verification result of the user is directly returned.