Centralized authorization method and system based on authorization granularity matching
By adopting a centralized authorization method and system based on authorization granularity matching in the information sharing service system, the problems of complex system management, low security and slow response speed are solved, and the system architecture is simplified, security enhancement and compliance guarantee are achieved.
Patent Information
- Application Number
- CN202311614283.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-29
- Publication Date
- 2025-05-30
AI Technical Summary
The existing information sharing service system has problems such as high management complexity, low security and slow response speed in centralized authorization processing, especially under high load conditions.
A centralized authorization method and system based on authorization granularity matching is adopted. The method includes configuring resource directories, identifying the verification priority of resource items and adding identification tags, obtaining authorization requests and performing corresponding authorization operations. In this way, the system architecture is simplified, node interactions and dependencies are reduced, security is enhanced, and auditing and monitoring is facilitated.
This approach simplifies the system architecture, reduces complexity and maintenance costs, enhances system security, and facilitates auditing and monitoring by recording authorized operations, ensuring system compliance and proper operation.
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of document authorization management data processing and data security protection, and particularly relates to a centralized authorization method and system based on authorization granularity matching. Background Art
[0002] Centralized authorization of an information sharing service system refers to the central platform uniformly managing and authorizing the co - built nodes of each department and other platforms to achieve resource sharing and utilization.
[0003] In an information sharing service system, directory management is the key to realizing centralized authorization. Directory management includes not only full - process services such as directory creation, editing, auditing, and publishing, but also management of directory classification, attributes, permissions, and subscriptions. Through directory management, the central platform can provide a unified directory view and resource access interface to each department node and other platforms, and at the same time centrally manage and control the access permissions of the directory.
[0004] In the centralized authorization mode, the central platform, as the platform center management system, is responsible for managing and maintaining the directory structure and resource information of the entire system, and authorizing and publishing resource and directory information to each department node and other platforms. Each department node edits resource directories and resource data according to its authority scope and requirements, and submits them to the central platform for auditing and publishing. The shared service system stores the audited and published resource data in the data management system, and publishes the resource information and files to the unified portal and resource library. When a user needs to access shared resources, the user first needs to enter the unified portal or resource library of the central platform and select the directory where the desired shared directory or resource is located. According to the attributes and classification of the directory, the user can choose to build resources by themselves or entrust resources, and can also filter according to the organization or resource theme. After selecting the directory, the user can view the basic information of the directory and the authorization list to understand the authorized persons who have permissions for this directory and their authorization scopes. In the centralized authorization mode, the central platform can uniformly manage and authorize the directories and resources in the entire system, thus avoiding duplicate work and information island phenomena among department nodes, and improving the sharing and utilization efficiency of resources. At the same time, the central platform can also authorize and supervise each department node according to needs to ensure the reasonable utilization and security guarantee of resources.
[0005] However, there are still deficiencies in the processing process of implementing centralized authorization in the existing information sharing service system: Centralized authorization means that all permission management is concentrated at one point, which can lead to a significant increase in management complexity. For example, when a large number of users need to have their permissions managed, the operations become very complex; all permission information is stored in a central location, which may pose security problems. If this central location is attacked, then the attacker may obtain all the permission information, thus posing a major threat to the system; all permission requests need to be processed through the central node, which may lead to a slowdown in the response speed. Especially in high-load situations, this problem may be more obvious. Summary of the Invention
[0006] To solve the deficiencies of the prior art, the present invention proposes a centralized authorization method and system based on authorization granularity matching, which can simplify the system architecture, reduce the interaction and dependence between nodes, thereby reducing the complexity and maintenance cost of the system; all authorization requests need to be verified and processed by the central system, reducing potential security vulnerabilities, helping to enhance the security of the system. At the same time, the central system can record all authorization operations, facilitating auditing and monitoring to ensure the compliance and normal operation of the system.
[0007] To achieve the above objectives, the technical solutions adopted by the present invention include:
[0008] A centralized authorization method based on authorization granularity matching, characterized by comprising:
[0009] S1. Configure a resource directory, where the resource directory includes several subdirectories, and the subdirectories include several resource items;
[0010] S2. Identify the verification priority of the resource items, and add a first identification tag and / or a second identification tag to the resource items according to the identified verification priority;
[0011] S3. Obtain an authorization request, extract the involved resource items according to the authorization request, and determine whether the resource items have a first identification tag and / or a second identification tag;
[0012] S4. When it is determined that the resource item has a first identification tag and does not have a second identification tag, perform an authorization operation on the resource item and feedback the authorization result;
[0013] S5. When it is determined that the resource item has a second identification tag and does not have a first identification tag, perform an authorization operation on the subdirectory to which the resource item belongs and feedback the authorization result;
[0014] S6. When it is determined that the resource item has a first identification tag and also has a second identification tag, perform an authorization operation on the resource item and the subdirectory to which the resource item belongs and feedback the authorization result;
[0015] S7. Feedback the authorization request according to the authorization result.
[0016] Further, the verification priority for identifying resource items includes determining whether the resource item supports coarse-grained authorization and determining whether the resource item mandatorily requires fine-grained authorization;
[0017] The coarse-grained authorization includes unified authorization for the subdirectories to which the resource item belongs;
[0018] The fine-grained authorization includes independent authorization for the resource item.
[0019] Further, performing the authorization operation on the resource item includes:
[0020] Performing an independent authorization operation on the resource item to generate an authorization result for the corresponding resource item.
[0021] Further, performing the authorization operation on the subdirectory to which the resource item belongs includes:
[0022] Performing a unified authorization operation on the entire subdirectory to which the resource item belongs to generate an authorization result for all resource items in the corresponding subdirectory.
[0023] Further, performing the authorization operation on the resource item and the subdirectory to which the resource item belongs includes:
[0024] Performing an independent authorization operation on the resource item to generate a first authorization result for the corresponding resource item;
[0025] Determining whether the first authorization results corresponding to each resource item in the subdirectory are all passed;
[0026] When it is determined that the first authorization results corresponding to each resource item in the subdirectory are all passed, performing a unified authorization operation on the subdirectory to generate a second authorization result;
[0027] Combining the first authorization result and the second authorization result to generate an authorization result.
[0028] The present invention also relates to a centralized authorization system based on authorization granularity matching, which is characterized by including:
[0029] A directory management module for configuring a resource directory;
[0030] A label management module for identifying the verification priority of a resource item and adding a first identification label and / or a second identification label to the resource item according to the identified verification priority;
[0031] A label judgment module for judging whether the resource item has a first identification label and / or a second identification label;
[0032] An authorization operation module for performing an authorization operation on a resource item, or on a sub-directory to which the resource item belongs, or on the resource item and the sub-directory to which the resource item belongs, and feeding back an authorization result.
[0033] The present invention also relates to a computer-readable storage medium, characterized in that a computer program is stored on the storage medium, and when the computer program is executed by a processor, the above-mentioned method is implemented.
[0034] The present invention also relates to an electronic device, characterized by comprising a processor and a memory;
[0035] The memory is used for storing a resource directory and an authorization request;
[0036] The processor is used for executing the above-mentioned method by calling the resource directory and the authorization request.
[0037] The present invention also relates to a computer program product, including a computer program and / or instructions, characterized in that when the computer program and / or instructions are executed by a processor, the steps of the above-mentioned method are implemented.
[0038] The beneficial effects of the present invention are:
[0039] By adopting the centralized authorization method and system based on authorization granularity matching of the present invention, the architecture of the system can be simplified, the interaction and dependence between nodes can be reduced, thereby reducing the complexity and maintenance cost of the system; all authorization requests need to be verified and processed by the central system, reducing possible security vulnerabilities, helping to enhance the security of the system, and at the same time the central system can record all authorization operations, facilitating auditing and monitoring to ensure the compliance and normal operation of the system. Specific embodiments
[0040] To understand the content of the present invention more clearly, it will be described in detail in conjunction with embodiments.
[0041] The first aspect of the present invention relates to a centralized authorization method based on authorization granularity matching, including:
[0042] S1. Configure a resource directory, where the resource directory includes several sub-directories, and the sub-directories include several resource items.
[0043] S2. Identify the verification priority of the resource item, and add a first identification tag and / or a second identification tag to the resource item according to the identified verification priority.
[0044] Preferably, identifying the verification priority of the resource item includes determining whether the resource item supports coarse-grained authorization, and determining whether the resource item requires fine-grained authorization compulsorily; the coarse-grained authorization includes unified authorization of the sub-directory to which the resource item belongs; the fine-grained authorization includes independent authorization of the resource item.
[0045] S3. Obtain an authorization request, extract the involved resource items according to the authorization request, and determine whether the resource items have the first identification label and / or the second identification label.
[0046] S4. When it is determined that the resource item has the first identification label but does not have the second identification label, perform an authorization operation on the resource item and feedback the authorization result. Preferably, it includes: performing an independent authorization operation on the resource item to generate an authorization result corresponding to the resource item.
[0047] S5. When it is determined that the resource item has the second identification label but does not have the first identification label, perform an authorization operation on the sub-directory to which the resource item belongs and feedback the authorization result. Preferably, it includes: performing a unified authorization operation on the entire sub-directory to which the resource item belongs to generate an authorization result for all resource items in the corresponding sub-directory.
[0048] S6. When it is determined that the resource item has both the first identification label and the second identification label, perform an authorization operation on the resource item and the sub-directory to which the resource item belongs and feedback the authorization result. Preferably, it includes: performing an independent authorization operation on the resource item to generate a first authorization result corresponding to the resource item; determining whether the first authorization results corresponding to each resource item in the sub-directory are all passed; when it is determined that the first authorization results corresponding to each resource item in the sub-directory are all passed, performing a unified authorization operation on the sub-directory to generate a second authorization result; combining the first authorization result and the second authorization result to generate an authorization result.
[0049] S7. Feedback the authorization request according to the authorization result.
[0050] By implementing centralized authorization management through the above method, effective management and control of the data resources of the information sharing service system can be achieved. By establishing measures such as a comprehensive resource directory, strict authorization application and approval processes, operation log records, data security guarantees, and user management, it can be ensured that the data resources are reasonably used and shared on the premise of meeting security and privacy requirements.
[0051] On the other hand, the present invention also relates to a centralized authorization system based on authorization granularity matching, including:
[0052] A directory management module for configuring a resource directory;
[0053] A label management module for identifying the verification priority of resource items and adding the first identification label and / or the second identification label to the resource items according to the identified verification priority;
[0054] A label judgment module for judging whether the resource items have the first identification label and / or the second identification label;
[0055] An authorization operation module is used to perform authorization operations on resource items, or on subdirectories to which resource items belong, or on resource items and subdirectories to which resource items belong, and feedback the authorization results.
[0056] By using this system, the above arithmetic processing method can be executed and the corresponding technical effects can be achieved.
[0057] An embodiment of the present invention also provides a computer-readable storage medium capable of implementing all steps in the method in the above embodiment. A computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, all steps in the method in the above embodiment are implemented.
[0058] An embodiment of the present invention also provides an electronic device for executing the above method. As an implementation device of this method, the electronic device at least includes a processor and a memory. In particular, data and related computer programs required for executing the method are stored on the memory, such as a resource directory and an authorization request, etc. And all steps of the method are implemented by the processor calling the data and programs in the memory, and the corresponding technical effects are obtained.
[0059] Preferably, the electronic device may include a bus architecture. The bus may include any number of interconnected buses and bridges, and the bus links various circuits including one or more processors and memories together. The bus may also link various other circuits such as peripheral devices, voltage regulators, and power management circuits, etc., which are well known in the art. Therefore, they will not be further described herein. The bus interface provides an interface between the bus and the receiver and the transmitter. The receiver and the transmitter may be the same element, that is, a transceiver, which provides a unit for communicating with various other systems on the transmission medium. The processor is responsible for managing the bus and general processing, and the memory may be used to store data used by the processor when executing operations.
[0060] Additionally, the electronic device may further include components such as a communication module, an input unit, an audio processor, a display, a power supply, etc. The processor (or controller, operation control) employed therein may include a microprocessor or other processor devices and / or logic devices, which receive inputs and control the operations of various components of the electronic device; the memory may be one or more of a buffer, a flash memory, a hard drive, a removable medium, a volatile memory, a non-volatile memory, or other suitable devices, capable of storing the above-mentioned relevant data information, and may also store programs for executing relevant information, and the processor may execute the programs stored in the memory to achieve information storage or processing, etc.; the input unit is used to provide inputs to the processor, for example, it may be a key or a touch input device; the power supply is used to supply power to the electronic device; the display is used to display display objects such as images and texts, for example, it may be an LCD display. The communication module is a transmitter / receiver that transmits and receives signals via an antenna. The communication module (transmitter / receiver) is coupled to the processor to provide input signals and receive output signals, which may be the same as in the case of a conventional mobile communication terminal. Based on different communication technologies, multiple communication modules may be provided in the same electronic device, such as a cellular network module, a Bluetooth module, and / or a wireless local area network module, etc. The communication module (transmitter / receiver) is also coupled to the speaker and the microphone via the audio processor to provide audio output via the speaker and receive audio input from the microphone, thereby realizing normal telecommunication functions. The audio processor may include any suitable buffer, decoder, amplifier, etc. Additionally, the audio processor is also coupled to the central processor, so that it is possible to record on the device through the microphone and play the sounds stored on the device through the speaker.
[0061] Those skilled in the art should understand that the embodiments of the present invention may be provided as a method, a system, or a computer program product. Therefore, the present invention may take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program code.
[0062] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate a system for implementing the functions specified in one or more flows of the flowchart and / or one or more blocks of the block diagram.
[0063] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufacture including an instruction system that implements the functions specified in one or more flows of the flowchart and / or one or more blocks of the block diagram.
[0064] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more flows of the flowchart and / or one or more blocks of the block diagram. Although the preferred embodiments of the present invention have been described, those skilled in the art can make additional changes and modifications to these embodiments once they learn the basic creative concepts. Therefore, the appended claims are intended to be construed to include the preferred embodiments and all changes and modifications that fall within the scope of the present invention.
[0065] The above is only the preferred specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed by the present invention should be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.
Claims
1. A centralized authorization method based on authorization granularity matching, characterized in that, it includes: S1. Configure a resource directory, where the resource directory includes several subdirectories, and the subdirectories include several resource items; S2. Identify the verification priority of the resource items, and add a first identification label and / or a second identification label to the resource items according to the identified verification priority; S3. Obtain an authorization request, extract the involved resource items according to the authorization request, and determine whether the resource items have a first identification label and / or a second identification label; S4. When it is determined that the resource item has a first identification label and does not have a second identification label, perform an authorization operation on the resource item and feedback the authorization result; S5. When it is determined that the resource item has a second identification label and does not have a first identification label, perform an authorization operation on the subdirectory to which the resource item belongs and feedback the authorization result; S6. When it is determined that the resource item has a first identification label and also has a second identification label, perform an authorization operation on the resource item and the subdirectory to which the resource item belongs and feedback the authorization result; S7. Feedback the authorization request according to the authorization result.
2. The method according to claim 1, characterized in that, the verification priority for identifying the resource items includes determining whether the resource items support coarse-grained authorization and determining whether the resource items force fine-grained authorization; the coarse-grained authorization includes unified authorization of the subdirectories to which the resource items belong; the fine-grained authorization includes independent authorization of the resource items.
3. The method according to claim 1, characterized in that, performing the authorization operation on the resource item includes: Performing an independent authorization operation on the resource item to generate an authorization result corresponding to the resource item.
4. The method according to claim 1, characterized in that, performing the authorization operation on the subdirectory to which the resource item belongs includes: Performing a unified authorization operation on the whole of the subdirectory to which the resource item belongs to generate an authorization result for all resource items in the corresponding subdirectory.
5. The method according to claim 1, characterized in that, performing the authorization operation on the resource item and the subdirectory to which the resource item belongs includes: Performing an independent authorization operation on the resource item to generate a first authorization result corresponding to the resource item; Determining whether the first authorization results corresponding to each resource item in the subdirectory are all passed; When it is determined that the first authorization results corresponding to each resource item in the subdirectory are all passed, performing a unified authorization operation on the subdirectory to generate a second authorization result; Combining the first authorization result and the second authorization result to generate an authorization result.
6. A centralized authorization system based on authorization granularity matching, characterized in that, it includes: A directory management module for configuring a resource directory; A label management module for identifying the verification priority of resource items and adding a first identification label and / or a second identification label to the resource items according to the identified verification priority; A label judgment module for judging whether the resource items have a first identification label and / or a second identification label; An authorization operation module for performing an authorization operation on the resource item, or performing an authorization operation on the subdirectory to which the resource item belongs, or performing an authorization operation on the resource item and the subdirectory to which the resource item belongs, and feedbacking the authorization result.
7. A computer-readable storage medium, characterized in that, A computer program is stored on the storage medium, and when the computer program is executed by a processor, the method described in any one of claims 1 to 5 is implemented.
8. An electronic device, characterized in that it includes a processor and a memory; the memory is used to store a resource directory and an authorization request; the processor is used to execute the method described in any one of claims 1 to 5 by calling the resource directory and the authorization request.
9. A computer program product, including a computer program and / or instructions, characterized in that when the computer program and / or instructions are executed by a processor, the steps of the method described in any one of claims 1 to 5 are implemented.