Multi-level authority management method and system based on unified login authentication, and medium

By adopting a multi-level permission management method based on unified login authentication in the field of information security technology, and combining dynamic attributes to adjust permissions, the problem of lack of flexibility in permission management and single system login in the existing technology has been solved, and the flexibility and security of user experience improvement and permission management have been achieved.

CN120050084APending Publication Date: 2025-05-27AVIC STAR BEIDOU CHONGQING TECHNOLOGY CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510189124.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-20
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

In the prior art, permission management lacks flexibility and makes it difficult to dynamically adjust user permissions, and the authentication mechanism of single system login increases user operation complexity and system security risks.

Method used

A multi-level permission management method based on unified login authentication is adopted to realize unified login through tokens with user identity, permission sets and dynamic attributes, and dynamic permission adjustments are performed in combination with dynamic attributes such as time, device credibility and geographical location.

Benefits of technology

It enables users to access multi-level systems with only one login, improves user experience and operation efficiency, and enhances the flexibility and security of permission management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120050084A_ABST
    Figure CN120050084A_ABST
Patent Text Reader

Abstract

The invention provides a multi-level authority management method and system based on unified login authentication and a medium. According to the invention, identity verification of the user in a plurality of systems is realized through unified login authentication, the token containing user identity information, a permission set and dynamic attributes is generated, and the subsystem is supported to analyze and verify the token. According to the method, dynamic attributes such as time, equipment credibility and geographic position are combined, the permission set of the user is dynamically adjusted, and the permission of the user is evaluated in real time through the preset authorization decision rule. The method supports dynamic inheritance and fine control of multi-level permissions, is suitable for a permission management scene of a complex system, and has high safety, flexibility and expandability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and particularly relates to a multi-level permission management method, system and medium based on unified login authentication. Background Art

[0002] With the rapid development of informatization, the application scenarios of multi-level systems are becoming increasingly widespread, such as enterprise-level management systems, distributed resource sharing platforms, and multi-tenant cloud computing environments. In these scenarios, permission management is an important part of ensuring the security and flexibility of the system. Traditional permission management methods usually focus on static permission allocation and are difficult to adapt to the changes in dynamic attributes (such as time, device, geographical location) during user access. In the existing technology, there is less comprehensive consideration of dynamic attributes, resulting in inflexible permission management and difficulty in dynamically adjusting user permissions. In addition, the authentication mechanism of single-system login often requires users to log in multiple times, which not only increases the complexity of user operations but also raises the security risks of the system. Summary of the Invention

[0003] The present invention aims to at least solve the technical problems existing in the prior art, and particularly innovatively proposes a multi-level permission management method based on unified login authentication, including:

[0004] Unified login authentication: Through the tokens of user identity, permission set and dynamic attributes, ensure that users only need to log in once to access resources in the multi-level system;

[0005] Combined decision of permissions and context: Provide a dynamic authorization decision method based on permission and context attributes, and dynamically adjust the final permissions of users by comprehensively evaluating the user's permission set and dynamic attributes.

[0006] In a preferred embodiment of the present invention, the unified login authentication includes:

[0007] Define the user token T user as the result of the following function:

[0008] T user = Encode(U, P user , A user , K);

[0009] wherein, T user is the generated user token, which contains user identity, permission set and dynamic attributes, and is a credential generated by encryption for verifying the user's identity and its access permissions;

[0010] U is the user ID, which uniquely represents the user's identity;

[0011] Encode(*) is the user token generation function;

[0012] P user is the permission matrix owned by the user, representing the permissions granted to the user, and its components are P user =(p 1 p 2 …p n ) T , where T represents the transpose of the matrix, p n represents the nth permission, and n represents the number of permissions;

[0013] A user is the dynamic attribute matrix, which grants different dynamic permissions according to the user's dynamic attributes;

[0014] K is the private key of the user, used to sign the token;

[0015] After receiving the user token, each subsystem performs identity authentication according to the parsing formula:

[0016] V(T user )=Decode(T user ,K pub );

[0017] Among them, V(*) is the token parsing function, Encode(*) is the parsing function, which verifies the validity of the token through the public key and extracts the user's identity information and permission information. K pub is the public key of the server, used to verify the token signature, and realizes asymmetric encryption through the pairing of the private key and the public key.

[0018] In a preferred embodiment of the present invention, the combined decision of the permission and the context includes:

[0019] R=(R 1 R 2 …R n ) T ;

[0020] Among them, R represents the result matrix of the authorization decision, and R n represents the authorization result of the nth permission, and n represents the number of permissions;

[0021] Combined with the dynamic attribute matrix A user and the permission matrix P owned by the user user , it is used to calculate the permission adjustment result:

[0022]

[0023] P user is the permission matrix owned by the user, representing the permissions granted to the user, and p n represents the nth permission, and n represents the number of permissions;

[0024] A user is a dynamic attribute matrix that grants different dynamic permissions according to the user's dynamic attributes;

[0025] Among them, a im represents the restriction factor of the dynamic attribute on the i-th permission, where the value range of i is 1, 2,...., n, and the value range of m is 1, 2, 3;

[0026] Among them, a i1 is the time restriction factor, a i2 is the device credibility restriction factor, a i3 is the geographical location restriction factor;

[0027] Among them, the calculation method of the device credibility restriction factor a i2 is as follows:

[0028] a i2 = ω 1 S reg + ω 2 S history + ω 3 S security ;

[0029] Among them, S reg is the device registration status. When S reg = 1, it means registered. When S reg = 0, it means unregistered;

[0030] S history is the device usage history, indicating the number of times the device has been used in the most recent N visits;

[0031] S security is the device security score. When two-factor authentication is enabled, S security = 1. When it is not enabled, S security = 0.5;

[0032] ω 1 , ω 2 , ω 3 are adjustable weight coefficients that satisfy ω 1 + ω 2 + ω 3 = 1;

[0033] Among them, the geographical location restriction factor a i3 is determined by the consistency of the IP address access, and its calculation method is:

[0034]

[0035] Among them, S ipIt is the matching degree score of IP and geographical location.

[0036] In a preferred embodiment of the present invention, the combined decision of the permission and the context further includes:

[0037] Q is the permission weight matrix, Q = (q 1 q 2 q 3 ) T , q 1 is the weight of the time limit factor, q 2 is the weight of the device credibility limit factor, q 3 is the weight of the geographical location limit factor;

[0038] Through the linear transformation of the dynamic attribute matrix A user and the permission weight matrix Q, the permission adjustment matrix F user is obtained:

[0039]

[0040] where, f n is the influence factor of the nth permission;

[0041] Using element-wise multiplication to ensure that the permission value is controlled by the influence factor, the permission adjustment result P final is obtained:

[0042]

[0043] where, ⊙ represents element-wise multiplication, p′ n represents the final value of the nth permission;

[0044] where, p i ′ = p i ·f i , p i ′ is the final value of the ith permission, p i is the ith permission, f i is the influence factor of the ith permission;

[0045] In a preferred embodiment of the present invention, the combined decision of the permission and the context further includes:

[0046] Dynamic permission adjustment logic:

[0047]

[0048] Set a threshold τ i for each permission. When p i ′ ≥ τ i , the authorization passes; otherwise, it is rejected.

[0049] R i represents the authorization result of the i-th permission;

[0050] Through multi-level permission inheritance, the accumulation or restriction of permissions across departments and systems is achieved:

[0051] P fi ′ nal =max(P final ,P layer );

[0052] where P fi ′ nal is the inherited permission;

[0053] P final is the permission adjustment result, which is used to represent the basic permissions granted to the user in the system;

[0054] P layer is the additional permission matrix, that is, the permissions that the user inherits additionally due to different levels;

[0055] max(*) represents taking the maximum value element by element, that is, in each permission dimension, the highest-level permission is selected as the final permission.

[0056] The present invention also discloses a computer system, including:

[0057] a processor;

[0058] a memory for storing instructions executable by the processor;

[0059] wherein the processor is configured to implement the multi-level permission management method based on unified login authentication when executing the executable instructions.

[0060] The present invention also discloses a computer-readable storage medium, including:

[0061] a memory having a computer program stored thereon;

[0062] a processor for executing the program in the memory to implement the multi-level permission management method based on unified login authentication.

[0063] In summary, due to the adoption of the above technical solutions, the beneficial effects of the present invention are:

[0064] Unified identity authentication: Users can access multiple systems through a single login, eliminating the cumbersome process of repeated logins and improving the user experience and operation efficiency.

[0065] Dynamic Attribute-driven Permission Adjustment: The present invention combines dynamic attributes such as time, device credibility, and geographical location, and realizes real-time adjustment of permissions through the operation of a dynamic attribute matrix, effectively enhancing the flexibility of permission management.

[0066] Multi-level Fine-grained Permission Control: The present invention supports dynamic inheritance and superposition according to permission levels, and at the same time combines context attributes for authorization decisions, ensuring that permission management meets both global requirements and supports fine-grained control.

[0067] Balancing Security and Scalability: The present invention adopts a token encryption and verification mechanism to ensure the security of user tokens during transmission and storage. At the same time, the method of combining permissions with dynamic attributes supports flexible expansion to adapt to the diverse needs of complex systems.

[0068] The additional aspects and advantages of the present invention will be partly given in the following description, partly will become obvious from the following description, or will be learned through the practice of the present invention. Brief Description of the Drawings

[0069] The above and / or additional aspects and advantages of the present invention will become obvious and easy to understand from the description of the embodiments in conjunction with the following drawings, where:

[0070] Figure 1 is the flowchart of the method of the present invention. Detailed Description of the Embodiments

[0071] The embodiments of the present invention will be described in detail below. The examples of the embodiments are shown in the drawings, where the same or similar reference numerals denote the same or similar elements or elements with the same or similar functions throughout. The embodiments described below by referring to the drawings are exemplary and are only used to explain the present invention and should not be construed as a limitation of the present invention.

[0072] As Figure 1 shown, the present invention discloses a multi-level permission management method, system and medium based on unified login authentication:

[0073] 1. Unified Login Authentication

[0074] Dynamic Token Generation and Permission Embedding

[0075] Dynamically embed the real-time attributes of the user (including role, device information, and geographical location) in the token to avoid the limitations of static tokens.

[0076] Adopt a single sign-on (SSO) mechanism. Users can access multiple systems through a single authentication, reducing the overhead caused by repeated authentication. Transmit user identity information and permissions through the token mechanism to ensure the security and efficiency of access.

[0077] Define user token Tuser is the result of the following function:

[0078] T user = Encode(U, P user , A user , K);

[0079] where T user is the generated user token, which contains the user identity, permission set, and dynamic attributes, and is a credential generated through encryption for verifying the user identity and their access permissions;

[0080] U is the user ID, uniquely representing the user's identity;

[0081] Encode(*) is the user token generation function;

[0082] P user is the permission matrix owned by the user, representing the permissions granted to the user, and its components are P user = (p 1 p 2 … p n ), T T represents the transpose of the matrix, p n represents the nth permission, and n represents the number of permissions;

[0083] A user is the dynamic attribute matrix, which grants different dynamic permissions according to the user's dynamic attributes;

[0084] K is the user's private key, used for signing the token;

[0085] After receiving the user token, each subsystem performs identity authentication according to the parsing formula:

[0086] V(T user ) = Decode(T user , K pub );

[0087] where V(*) is the token parsing function, Encode(*) is the parsing function, which verifies the validity of the token through the public key and extracts the user's identity information and permission information, and K pub is the public key of the server, used for verifying the token signature, and realizes asymmetric encryption through the pairing of the private key and the public key.

[0088] Each business subsystem usually receives and parses the token to ensure that the user has access permissions. For example, the finance system checks whether the user has the permission to view financial data, and the HR system checks whether the user can access employee information.

[0089] After parsing, the system extracts the user identity, permission matrix, and dynamic attributes, and calculates the final authorization result based on the dynamic attributes.

[0090] 2. Combined Decision of Permissions and Context

[0091] R = (R 1 R 2 …R n ) T ;

[0092] where R represents the result matrix of the authorization decision, and R n represents the authorization result of the nth permission, and n represents the number of permissions;

[0093] Combined with the dynamic attribute matrix A user and the permission matrix P user owned by the user, it is used to calculate the permission adjustment result:

[0094]

[0095] P user is the permission matrix owned by the user, representing the permissions granted to the user, and p n represents the nth permission, and n represents the number of permissions;

[0096] A user is the dynamic attribute matrix, which grants different dynamic permissions according to the user's dynamic attributes;

[0097] where a im represents the restriction factor of the dynamic attribute on the i-th permission, the value range of i is 1, 2,...., n, and the value range of m is 1, 2, 3;

[0098] where a i1 is the time restriction factor, a i2 is the device credibility restriction factor, and a i3 is the geographical location restriction factor;

[0099] where the calculation method of the device credibility restriction factor a i2 is:

[0100] a i2 = ω 1 S reg + ω 2 S history + ω 3 S security ;

[0101] where S reg is the device registration status. When S reg = 1, it means registered. When S regWhen it is 0, it indicates unregistered;

[0102] S history is the device usage history, which represents the number of times the device has been used in the most recent N visits;

[0103] S security is the device security score. When two-factor authentication is enabled (the user needs to provide two credentials that are independent of each other in nature to prove their identity), S security = 1. When it is not enabled, S security = 0.5;

[0104] ω 1 ,ω 2 ,ω 3 is an adjustable weight coefficient, satisfying ω 1 +ω 2 +ω 3 = 1;

[0105] Among them, the geographical location restriction factor a i3 is determined by the consistency of access from the IP address, and its calculation method is:

[0106]

[0107] Among them, S ip is the IP and geographical location matching degree score.

[0108] Time, device credibility, and geographical location are used as key dynamic attribute factors, which affect the final permission allocation through matrix operations. Among them, the calculation of device credibility comprehensively considers the registration status, historical usage, and security score of the device, and introduces a weight factor for adjustment to balance the influence of different factors, ensuring that the access permissions of trusted devices are greater, while the permissions of unregistered or insecurely authenticated devices are restricted. The influence of geographical location is based on the IP matching degree, calculating the matching degree between the user's historical access IP and the current access IP, so as to adjust the final permissions and avoid security risks caused by abnormal location logins.

[0109] Q is the permission weight matrix, Q = (q 1 q 2 q 3 ) T , q 1 is the weight of the time restriction factor, q 2 is the weight of the device credibility restriction factor, q 3 is the weight of the geographical location restriction factor;

[0110] Through the linear transformation of the dynamic attribute matrix A user and the permission weight matrix Q, the permission adjustment matrix F user is obtained:

[0111]

[0112] Among them, f n is the influence factor of the nth permission;

[0113] Use element-wise multiplication to ensure that the permission value is controlled by the influence factor, and obtain the permission adjustment result P final :

[0114]

[0115] Among them, ⊙ represents element-wise multiplication, and p′ n represents the final value of the nth permission;

[0116] Among them, p i ′ = p i ·f i , p i ′ is the final value of the i-th permission, p i is the i-th permission, and f i is the influence factor of the i-th permission;

[0117] Dynamic permission adjustment logic:

[0118]

[0119] Set a threshold τ i for each permission. When p i ′ ≥ τ i , authorization passes; otherwise, it is rejected;

[0120] R i represents the authorization result of the i-th permission;

[0121] Through multi-level permission inheritance, achieve permission accumulation or constraint across departments and systems:

[0122] P fi ′ nal = max(P final , P layer );

[0123] Among them, P fi ′ nal is the inherited permission;

[0124] P final is the permission adjustment result, used to represent the basic permissions granted to the user in the system;

[0125] P layer is the additional permission matrix, that is, the permissions inherited by the user due to different levels;

[0126] max(*) represents taking the maximum value element by element. That is, on each permission dimension, the highest-level permission is selected as the final permission.

[0127] Adopt a priority strategy to solve permission conflicts and prevent access exceptions caused by permission mutual exclusion.

[0128] Combine the short-term token + refresh token (Access Token + Refresh Token) mechanism to ensure that user permission changes can be synchronized to each subsystem in a timely manner, and avoid permission abuse caused by using old tokens.

[0129] The server maintains a token blacklist. Once the user's permission changes, the old token becomes invalid automatically, ensuring the security of access control.

[0130] Through key technologies such as dynamic token mechanism, context-aware permission adjustment, permission inheritance and conflict resolution, and secure storage and update of tokens, a flexible, secure, and efficient access control system is realized. It can be widely applied to complex permission management environments such as enterprise information systems, government agencies, cloud computing platforms, and intelligent Internet of Things, and has good security, scalability, and adaptability.

[0131] Although the embodiments of the present invention have been shown and described, those of ordinary skill in the art can understand that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the claims and their equivalents.

Claims

1. A multi-level rights management method based on unified login authentication, characterized in that: include: Unified login authentication: through the token of user identity, permission set and dynamic attributes, it ensures that users can access resources in multi-level systems with only one login; Combined decision of permissions and context: It provides a dynamic authorization decision method based on permissions and context attributes. It dynamically adjusts the user's final permissions by comprehensively evaluating the user's permission set and dynamic attributes.

2. The multi-level rights management method based on unified login authentication according to claim 1 is characterized in that: The unified login authentication includes: Define user token T user is the result of the following function: T user =Encode(U,P user ,A user ,K); Among them, T user It is a generated user token, which contains the user identity, permission set and dynamic attributes. It is a credential generated by encryption and is used to verify the user identity and access rights. U is the user ID, which uniquely represents the user's identity; Encode(*) is the user token generation function; P user It is the permission matrix of the user, indicating the permissions granted to the user, and its components are P user =(p1 p2…p n ) T , T represents the transpose of the matrix, p n Indicates the nth permission, where n indicates the number of permissions; A user It is a dynamic attribute matrix that grants different dynamic permissions based on the user's dynamic attributes; K is the user's private key, used to sign the token; After receiving the user token, each subsystem performs identity authentication according to the parsing formula: V(T user )=Decode(T user ,K pub ); Among them, V(*) is the token parsing function, Encode(*) is the parsing function, which verifies the validity of the token through the public key and extracts the user's identity information and permission information, K pub It is the server's public key, which is used to verify the token signature and implement asymmetric encryption through the pairing of private key and public key.

3. The multi-level rights management method based on unified login authentication according to claim 1 is characterized in that: The combined decision of permissions and context includes: R=(R1 R2…R n ) T ; Among them, R represents the result matrix of authorization decision, R n Indicates the authorization result of the nth permission, where n represents the number of permissions; Combined with the dynamic attribute matrix A user And the user's permission matrix P user , used to calculate the permission adjustment result: P user is the permission matrix of the user, indicating the permissions granted to the user, p n Indicates the nth permission, where n indicates the number of permissions; A user It is a dynamic attribute matrix that grants different dynamic permissions based on the user's dynamic attributes; Among them, a im Indicates the restriction factor of the dynamic attribute on the i-th permission. The value range of i is 1, 2, ..., n, and the value range of m is 1, 2, 3; Among them, a i1 is the time limit factor, a i2 is the device credibility limiting factor, a i3 It is the geographical location limiting factor; Among them, the device credibility limiting factor a i2 The calculation method is: a i2 =ω1S reg +ω2S history +ω3S security ; Among them, S reg Is the device registration status. When S reg =1 indicates that it has been registered. reg =0 means not registered; S history It is the device usage history, indicating the number of times the device has been used in the last N visits; S security is the device security score, when two-factor authentication is enabled security =1, when not enabled S security =0.5; ω1, ω2, ω3 are adjustable weight coefficients, satisfying ω1+ω2+ω3=1; Among them, the geographical location restriction factor a i3 It is determined by the consistency of access by IP address and is calculated as follows: Among them, S ip It is the IP and geographic location matching score.

4. The multi-level rights management method based on unified login authentication according to any one of claims 1 to 3, characterized in that: The combined decision of permissions and context includes: Q is the authority weight matrix, Q = (q1 q2 q3) T , q1 is the weight of the time restriction factor, q2 is the weight of the device credibility restriction factor, and q3 is the weight of the geographical location restriction factor; Through the dynamic attribute matrix A user The linear transformation of the authority weight matrix Q gives the authority adjustment matrix F user : Among them, f n is the impact factor of the nth permission; Use element-by-element multiplication to ensure that the permission value is controlled by the affected factors and obtain the permission adjustment result P final : Among them, ⊙ represents element-by-element multiplication, p′ n Indicates the final value of the nth permission; Among them, p′ i =p i ·f i ; p′ i is the final value of the i-th permission, p i is the i-th permission, f i The impact factor of the i-th permission.

5. The multi-level rights management method based on unified login authentication according to any one of claims 1 to 4, characterized in that: The combined decision of permissions and context includes: Dynamic permission adjustment logic: Set a threshold τ for each permission i , when p′ i ≥τ i If yes, the authorization is passed, otherwise it is rejected; R i Indicates the authorization result of the i-th permission; Through multi-level permission inheritance, permission accumulation or restriction across departments and systems can be achieved: P′ final =max(P final ,P layer ); Among them, P′ final It is the inherited permission; P final It is the result of permission adjustment, which is used to indicate the basic permissions granted to the user in the system; P layer It is the additional permissions matrix, i.e. the permissions that users inherit due to their different levels; max(*) means taking the maximum value element by element, that is, in each permission dimension, the highest level of permission is selected as the final permission.

6. A computer system, characterized in that: include: processor; a memory for storing processor-executable instructions; Wherein, the processor is configured to implement the multi-level authority management method based on unified login authentication as described in any one of claims 1 to 5 when executing the executable instructions.

7. A computer-readable storage medium, characterized in that: include: a memory having a computer program stored thereon; A processor is used to execute the program in the memory to implement the multi-level authority management method based on unified login authentication as described in any one of claims 1 to 5.

Citation Information

Cited By

  • Cross-enterprise identity management and authorization management and control method, equipment and medium

    CN120639511A

  • Network equipment management method, platform and system based on RADIUS authentication

    CN121690869A