Permission system and access method of industrial software

By designing the permission control platform and three-member module in industrial software, the problems of poor security, inconvenient management and low processing efficiency in the existing technology are solved, and permission management with high security, flexibility and audit traceability are achieved, which significantly improves the overall security and compliance of the system.

CN120105378APending Publication Date: 2025-06-06SUPCON TECH CO LTD +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411693317.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-11-25
Publication Date
2025-06-06

AI Technical Summary

Technical Problem

The prior art has problems such as poor security, inconvenient management and low processing efficiency in the permission management of industrial software, making it difficult to ensure data security and effectively identify and process user access.

Method used

A permission system for industrial software is designed, including a permission management platform and three-member modules (system processing unit, security and confidentiality unit and security audit unit). Through identity verification, automatic permission control, audit mechanism and data desensitization processing, it realizes permission management with high security, flexibility and audit traceability.

Benefits of technology

Significantly improves the overall security and compliance of the system, ensures that only strictly authorized personnel can access sensitive data and critical functions, reduces the risk of data leakage, and improves the efficiency and operability of permission management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120105378A_ABST
    Figure CN120105378A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of electric digital data processing, in particular to data protection. According to the technical scheme, hardware comprises a permission management and control platform and a three-member module, the three-member module comprises a system processing unit, a security secrecy unit and a security auditing unit, the three-member module is connected with the permission management and control platform, the permission management and control platform is connected with an application module, and the application module is connected with the system processing unit. The authority management and control platform comprises a user module and an audit log module, the security audit unit is unidirectionally connected with the system processing unit and the security secrecy unit through the audit log module, and the system processing unit is connected with the application module through the user module. The invention solves the problems of poor security, inconvenient management and low processing efficiency in the prior art, provides the authority system and the access method of the industrial software, and achieves the purposes of high security, flexibility, high efficiency, traceability of audit, data desensitization and dynamic management.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of electronic digital data processing, and in particular to protecting data. Background Art

[0002] In the development and application of industrial software, the permission system plays an important role. An effective permission system can not only ensure data security and the standardization of operations, but also improve the maintainability and user experience of the system. The permission system usually integrates an audit function to record the user's operation log. By analyzing the operation log, potential security threats can be discovered and the source of security incidents can be traced. In addition, many industrial software need to comply with certain industry standards and regulations (such as ISO, GDPR, etc.), and the audit function helps to ensure the compliance of system operations. In order to enhance the refinement and flexibility of permission management, modern industrial software generally adopts a multi-level permission architecture. Typical levels include user-level role permissions, function-level operation permissions, and data-level access permissions. The design of a multi-level architecture can better meet the permission requirements of users at different levels. For example, the Chinese patent with publication number CN113392423B discloses a user rights management method, system and storage medium, and provides the following technical solutions. The present invention discloses a multi-level and multi-organization user rights management method, system and storage medium, the method comprising: obtaining a pre-configured resource list of permissions to be controlled; marking the resources to be accessed in the resource list according to the preset application access hierarchy structure; registering the marked resources to be accessed according to the application access hierarchy structure; configuring corresponding application accounts and roles for each organizational level based on the preset organizational structure; assigning corresponding application role permissions to roles according to the organizational level and / or application access level; and performing user rights management based on the assigned application role permissions. The scheme of the present invention can achieve all-round data security from structure to data, so that all employees in the enterprise can safely access data according to their own role permissions, reduce the risk of data leakage, realize the effective control of enterprise data permissions, improve enterprise information security and the market competitiveness of enterprises; and reduce repeated development costs. However, the above-mentioned user rights management method, system and storage medium are difficult to ensure the security of each data, and there is no corresponding identification and processing of the user's access situation. Summary of the invention

[0003] The present invention solves the problems of poor security, inconvenient management and low processing efficiency in the prior art, and proposes an industrial software permission system and access method, achieving the goals of high security, flexibility and efficiency, audit traceability, data desensitization and dynamic management.

[0004] To achieve the above object, the present invention adopts the following technical solution: A permission system for industrial software includes a permission management and control platform and three-member modules. The three-member modules include a system processing unit, a security and confidentiality unit, and a security audit unit. The three-member modules are connected to the permission management and control platform, and the permission management and control platform is connected to an application module. The permission management and control platform includes a user module and an audit log module. The security audit unit is unidirectionally connected to the system processing unit and the security and confidentiality unit through the audit log module, and the system processing unit is connected to the application module through the user module.

[0005] A method for accessing permissions of industrial software comprises the following steps: S1: The user applies for access, and the system authenticates the user through the platform to confirm the user's identity and permission level; S2: According to the access rights rules, the system automatically controls the user's access rights; S3: When a user needs to access beyond the scope of his / her basic permissions, he / she can apply for access permissions on his / her own initiative, and the system will review the application. S4: Users have access based on their permission level and authorization status.

[0006] The advantage of this design is that, through the orderly connection between the permission management platform and the three-member module, the centralization and modularization of permission management are realized, the security and manageability of the system are improved, and a complete permission access process is established, from identity authentication to permission control, and then to permission application and access, ensuring the security and controllability of the access process.

[0007] Preferably, the system processing unit creates a business personnel account through the user module and assigns permission points to different application roles; the security and confidentiality unit assigns corresponding permission roles to business personnel in the user module, performs authorization management on the roles, and authorizes the roles to ordinary user accounts.

[0008] The advantage of this design is that by systematically creating and assigning permission roles, it ensures that different business personnel have appropriate permissions, thereby enhancing the flexibility and security of permission management.

[0009] Preferably, the system processing unit controls the application module through the user module, configures corresponding authority points and roles, adds or deletes applications, and changes application-related information.

[0010] The advantage of this design is that it makes permission configuration and application management more convenient, can quickly respond to changes in business needs, and improves the adaptability and maintainability of the system.

[0011] Preferably, the permission management and control platform also includes a permission maintenance module, and the system processing unit performs permission point maintenance through the permission maintenance module, adds or edits relevant permission identifiers, and the permission management and control platform feeds back user account information to the application module, and the application module feeds back user logs to the permission management and control platform.

[0012] The advantage of this design is that the permission maintenance and log feedback mechanism enhance the real-time and transparency of permission management, and help to promptly discover and handle permission-related issues.

[0013] Preferably, the security and confidentiality unit checks the operation logs of the security audit unit and the business personnel through the audit log module, and the security audit unit checks the operation logs of the system processing unit and the security and confidentiality unit through the audit log module.

[0014] The advantage of this design is that by checking each other's operation logs and restricting each other, the internal monitoring and auditing capabilities of the system are enhanced, and the overall security and compliance are improved.

[0015] Preferably, the authority levels include internal and general confidentiality and important confidentiality, and the access permission rules include subject and object access permission rules, specifically, the platform defines custom access rules according to the dimensions that affect the user's viewing of directories and data, specifically including access control dimensions composed of organizational structure, model, and business subject; wherein for the security system, it is required to adopt subject and object access permission rules for important subjects and objects; the system will check whether the user has the basic authority to access a certain type of directory or data, if so, it will enter step S3, if not, it will deny access, record the log and return to step S1.

[0016] The advantage of this design is that by refining permission levels and customizing access rules, users' access rights to different data and directories can be more accurately controlled, enhancing the security and flexibility of the system.

[0017] Preferably, the step S3 includes the following steps: S3.1: When a user needs to access a specific directory or data beyond the scope of his / her basic authority, he / she shall submit an access application; S3.2: The system or personnel with corresponding authority shall review the user's access application; S3.3: Review whether the application complies with security policies and business requirements. If so, grant the corresponding access rights and record the authorization log. If not, reject the application and provide feedback to the user on the application result.

[0018] The benefit of this design is that it establishes a strict permission application and review mechanism, ensuring that only access requests that comply with security policies and business requirements can be authorized, thereby improving the security and compliance of the system.

[0019] Preferably, the access permission rules also include controlling data permissions by rows and columns, specifically: users can only view data rows that match their permission levels; users can only view columns that are not marked as higher than their permission levels, and important columns are desensitized.

[0020] The advantage of this design is that, through fine-grained data permission control, it ensures that users can only access data content within their permission scope, effectively protecting sensitive information and reducing the risk of data leakage.

[0021] Preferably, in step S4, the system limits the user's operating scope on the data according to the permission control rules, specifically: when developers preview data, they can only view data rows that meet the permission level and desensitize important columns; when business personnel view data, the corresponding data content is displayed according to the permission level and data row level.

[0022] The advantage of this design is that it provides customized data access permissions for users in different roles, which not only meets business needs but also ensures data security and privacy.

[0023] Compared with the prior art, the invention has the following beneficial effects.

[0024] 1. The present invention builds a multi-level authority control system by introducing a three-member management model of system administrator, security and confidentiality administrator, and security audit administrator. The effective combination of system processing unit, data authority, and audit log module ensures that only strictly authorized personnel can access sensitive data and key functions. At the same time, the design of the audit log module realizes the full monitoring and recording of operation behavior, provides a strong guarantee for security auditing and tracking of potential threats, and significantly improves the overall security of the system.

[0025] 2. The present invention covers the comprehensive management and control of user permissions, data permissions (including row and column controls) and entity permissions. Through the division of permissions (internal, general confidentiality, important confidentiality) and multi-dimensional access control (such as organization, model, business subject, etc.), the system can accurately limit the user's access rights to specific data and functions. In addition, the data desensitization processing mechanism ensures that data will not flow from high-level to low-level, further strengthening the security and privacy protection of data.

[0026] 3. The present invention simplifies the creation, allocation and maintenance process of permissions through the modular design of the permission management and control platform (user management, role management, permission maintenance, etc.), and improves the efficiency and operability of permission management. At the same time, the permission inheritance and combination functions allow for flexible configuration of roles and permissions, meet the personalized needs in different business scenarios, and improve the overall maintainability and user experience of the system. BRIEF DESCRIPTION OF THE DRAWINGS

[0027] Figure 1 The present invention is a method flow chart of an industrial software authority system and access method.

[0028] Figure 2 The present invention is a hardware block diagram of an industrial software authority system and access method.

[0029] Figure 3 A schematic diagram of access control dimensions of an industrial software authority system and access method of the present invention. DETAILED DESCRIPTION

[0030] In order to make the purpose, technical scheme and advantages of the present disclosure clearer, the following will further describe the embodiments of the present disclosure in detail with reference to the accompanying drawings. The proportions of the components are not drawn according to the actual proportions, and the proportions and sizes shown in the accompanying drawings should not limit the substantial technical scheme of the present invention. These embodiments do not describe all the details in detail, nor do they limit the invention to the specific embodiments described.

[0031] See also Figure 1-3 As shown, an industrial software permission system includes a permission management platform and three-member modules, the three-member modules include a system processing unit, a security and confidentiality unit, and a security audit unit, the three-member modules are connected to the permission management platform, the permission management platform is connected to the application module, the permission management platform includes a user module and an audit log module, the security audit unit is unidirectionally connected to the system processing unit and the security and confidentiality unit through the audit log module, and the system processing unit is connected to the application module through the user module.

[0032] A method for accessing permissions of industrial software comprises the following steps: S1: The user applies for access, and the system authenticates the user through the platform to confirm the user's identity and permission level; S2: According to the access rights rules, the system automatically controls the user's access rights; S3: When a user needs to access beyond the scope of his / her basic permissions, he / she can apply for access permissions on his / her own initiative, and the system will review the application. S4: Users have access based on their permission level and authorization status.

[0033] like Figure 1 and Figure 3 In one embodiment shown, Figure 1 This is a method flow chart of an industrial software authority system and access method of the present invention. Figure 3 The schematic diagram of access control dimensions of an industrial software permission system and access method of the present invention is shown in FIG. The permission access method designed by the present invention mainly includes the following steps: S1: User applies for access; S2: The system automatically controls access rights; S3: The user voluntarily applies for access beyond the basic permissions; S3.1: Submit a request for access; S3.2: Review access requests; S3.3: Decide whether to grant permission; S4: The user actually accesses the site.

[0034] In addition, this method also involves the classification of permission levels, the formulation of access permission rules, and the row and column level control of data. The following will explain each step and its related mechanisms in detail step by step: S1: User applies for access: When a user needs to access a functional module or data of industrial software, he or she must first submit an access application through the system platform. During this process, the system will perform identity verification to confirm the user's identity and the level of authority to which he or she belongs. The specific process is as follows: Identity verification: The system confirms the user's true identity through multi-factor authentication (such as user name and password, fingerprint recognition, SMS verification code, etc.) to prevent unauthorized access; Permission level confirmation: The system determines the initial permission level of the user based on factors such as the user's role, department, and work requirements. Permission levels are usually divided into three levels: internal, general confidential, and important confidential.

[0035] Through strict identity authentication, we ensure that only legitimate users can access system resources, reducing the risk of unauthorized access. By clarifying the user's permission level, it helps to effectively manage user permissions and avoid abuse of permissions. At the same time, the process of user application for access is transparent, which helps users understand their own permissions and improves their user experience.

[0036] S2: The system automatically controls access rights: After confirming the user's identity and permission level, the system automatically controls the user's access rights according to predefined access rights rules. Access rights rules include subject and object access rights rules, as follows: Subject and object access rights rules: The system defines custom access rules based on the user's organization, model, business subject, and other dimensions to determine which directories and data the user can access; Permission check: The system checks whether the user has basic permissions to access a certain type of directory or data. If so, further access application is allowed (enter S3). Otherwise, access is denied and logs are recorded.

[0037] The use of automated systems can reduce manual intervention, improve the efficiency and accuracy of permission control, reduce the possibility of human error, and achieve precise control of resource access through multi-dimensional access rules to meet the needs of complex industrial environments. At the same time, the system records all access attempts and results to facilitate subsequent audits and security monitoring.

[0038] S3: Users voluntarily apply for access beyond basic permissions: When a user needs to access a specific directory or data that is beyond the scope of their basic permissions, they need to apply for access permissions on their own. This step includes the following three sub-steps: S3.1: Submit a request for access: When users need to access specific resources, they need to submit a specific access application on the system platform. The application content usually includes: The type of resource you are requesting access to (such as a specific directory or data), the reason and purpose of the access, the applicant's department and position, and the time and urgency of the request.

[0039] S3.2: Review access requests: The system or personnel with corresponding authority will review the user's access application. The review process includes: Qualification review: confirm the rationality and necessity of the applicant's access request; Compliance check: Ensure that the application complies with the enterprise's security policies and relevant regulatory requirements; Business needs assessment: Evaluate whether the application meets current business needs and project progress.

[0040] S3.3: Decide whether to grant permission: Based on the review results, the system will take the following actions: Grant access rights: If the application meets the security policy and business requirements, the system will grant the corresponding access rights and record the authorization log; Reject application: If the application does not meet the relevant requirements, the system will reject the application and provide the user with the specific reasons for rejection; The advantage of this design is that it allows users to dynamically apply for higher permissions when needed to meet the needs of business development, and through a strict review process, it ensures that only necessary and compliant access requests are approved, reducing the risk of abuse of permissions. At the same time, all application and approval records are logged to facilitate subsequent audits and traceability, and improve responsibility transparency.

[0041] S4: User actually accesses: After permission confirmation and authorization, users can access data according to their permission level and authorization status. The system will limit the user's scope of operation on data according to permission control rules, as follows: Permission control rules: Row-level control: Users can only view data rows that match their permission level. That is, users can only access specific data rows within their permission range to prevent sensitive data leakage; Column-level control: Users can only view columns that are not marked as higher than their permission level, and important columns are desensitized. For example, when developers preview data, important columns (such as customer information, financial data, etc.) will be desensitized to protect sensitive information.

[0042] Data access restrictions: Developers: When previewing data, they can only view data rows that meet the permission level and desensitize important columns; Business personnel: When viewing data, the corresponding data content is displayed according to the permission level and data row level, ensuring business needs while protecting data security.

[0043] The present invention ensures that users can only access their authorized data through fine-grained row and column level control, prevents data leakage and abuse, meets the business needs of different positions and improves work efficiency while ensuring data security, and provides sufficient flexibility to support users in completing work tasks while ensuring high security.

[0044] The system divides the permission levels into the following three levels: Internal permissions: Applicable to internal employees of the company, limited to accessing general internal data and functions; General confidentiality authority: Applicable to employees who need to handle sensitive information, allowing access to confidential data within a certain range; Significant Confidential Clearance: Applicable to senior management and specific positions, allowing access to highly sensitive and confidential data.

[0045] Access rights rules are based on subject and object access rights rules and include the following dimensions: Organization: Define the scope of resources that users can access based on the department or team they belong to; Model: restrict users’ access to specific types of data based on the device or system model they are operating; Business subject: Refine the user's access rights based on their business responsibilities to ensure that they can only access data related to their responsibilities.

[0046] Among them, for the graded protection system (level protection system), it is required to adopt subject and object access permission rules for important subjects and objects to meet the compliance requirements of relevant laws and regulations.

[0047] In one embodiment, the following scheme is adopted to implement: 1. User login and identity authentication: The user enters credentials (user name, password, two-factor authentication, etc.) in the data middle-end application system or data portal, and the system verifies the user's identity through the IAM platform to confirm his or her role and permission level.

[0048] 2. Confirmation of permission level and access control dimension: The system determines the user's basic access rights based on the user's authority level (internal, general confidentiality, important confidentiality) and access control dimensions (such as organization, model, business subject, etc.); The system determines the basic access rights based on the user's authority level (internal, general confidentiality, important confidentiality) and access control dimensions (such as organization, model, business subject, etc.). Based on the user's organization and business subject, the system automatically filters the directory and data range that the user can access; Check whether the user has basic permissions to access a certain directory or data. If yes, proceed to the next step. If no, deny access and record a log.

[0049] 3. Subject and object access rights control: The system automatically controls user access to specific directories and data based on predefined subject and object permission rules; For example, user A (important confidential) can access data of all levels, while user B (general confidential) can only access data of public, internal, and secret levels, and the confidential columns are desensitized; Check whether the user has the basic permission to access a certain type of directory or data, and whether the user's permission level and access control dimension allow him to access the target directory or data. If so, allow access and continue with the subsequent process. If not, deny the access request, record the denial log, and prompt the user that he does not have permission to access. Data permissions are controlled by row and column, for example: Row-level permissions: Users can only view data rows that match their permission level; Column-level permissions: Users can only view columns that are not marked as higher than their permission level, and important columns are anonymized.

[0050] 4. Apply for access rights on your own: When a user needs to access a specific directory or data beyond the scope of his / her basic authority, he / she shall submit an access application; The application process includes application submission, administrator review and permission granting.

[0051] 5. Approval and authorization: The system administrator or administrator with corresponding authority shall review the user's access application; Review whether the application complies with security policies and business requirements. If so, grant the corresponding access rights and record the authorization log. If not, reject the application and provide feedback to the user on the application result.

[0052] 6. Data access and manipulation: Users can view, preview or download data according to their permission level and authorization status; The system limits the scope of user operations on data based on permission control rules, for example: When developers preview data, they can only view data rows that meet their permission levels and desensitize important columns; When business personnel view data, the corresponding data content is displayed according to the permission level and data row level.

[0053] 7. Permission inheritance and combination: High-level roles automatically inherit the permissions of low-level roles to ensure the hierarchy and inheritance of permissions; The system supports flexible combinations of permissions to meet complex business needs.

[0054] 8. Audit and monitoring: The system automatically records all user operation logs, including login, data access, permission application and approval, etc.; Security and confidentiality administrators and security audit administrators regularly review and analyze operation logs to ensure the legality and security of system operations.

[0055] In another embodiment, the permission access system is divided into subject-object permission access control and autonomous application access control. The principle of mandatory access control is: the platform defines custom access rules based on the dimensions that affect users' viewing of directories and data. For example: the user's organization, permission level, model, business subject, etc., these dimensions can affect the directories and data that users can see. The principle of autonomous access control is: the user initiates an application for specific directories and data, and after approval, the specific directory and data access rights are granted. Among them, for the security protection system, it is required to adopt a mandatory access control mechanism for important subjects and objects. In the system, the user's permissions and the security attributes of the object are manually set by the system administrator, and business personnel are not allowed to modify the security attributes of the subject; similarly, some security policies are known to the user, but the system cannot perceive them, such as tenant isolation and organizational isolation of tables. At this time, it is necessary to combine autonomous application access control to allow users to autonomously apply for data that they do not have permission to.

[0056] When a data development role is developing a data warehouse, the data viewing permission is affected by the data permission level. During the development process, only rows that meet the permission level requirements can be previewed. The number of preview rows is limited, and important columns are desensitized.

[0057] There are corresponding access control dimensions for personnel and data, among which the permission level is the basic dimension. The personnel permission level identification is divided into [internal, general confidentiality, important confidentiality], and the data permission level identification is divided into [public, internal, secret, confidential]. It supports the on-demand definition of access control dimensions for personnel, directories, and entities, such as organizational structure, model, business subject, etc., and data permission control is controlled to rows and columns.

[0058] During the data warehouse construction process, access control identifiers such as personnel authority levels are maintained as needed. For example, the construction specifications for maintaining personnel authority level identifiers can be referenced as follows: The ODS layer table is consistent with the business system, and no row-level permission level identification is performed; All tables at all levels above ODS must contain a permission level column [secretLevel] to identify the permission level of the row. The row-level permission level is determined by specific business.

[0059] Tables at all levels above ODS can identify permission levels. When creating tables in a standardized manner, the source layer sets whether a column is confidential on the platform. The upper-level table determines whether a column is confidential based on the field lineage relationship.

[0060] The construction specifications for reference for maintaining access control identifications such as organizations, models, and business subjects are as follows: Models, business subjects, etc. are processed as needed in tables above the ODS; The values ​​of columns such as model and business subject in the table are determined based on business data.

[0061] Data maps, data assets, data services, data indicators, and data tags in the data portal are obtained from the big data platform through REST API, and data permissions are uniformly controlled by the big data platform. The application entry for directories and entities is retained on the data portal.

[0062] The data portal is unified with the big data platform user system. The big data platform user center is connected to the IAM platform. The data portal access roles are defined on demand on the IAM platform. The data portal access roles also include access roles for each subsystem of the big data platform.

[0063] Developers are subject to mandatory access control based on data permission levels. They can set permission levels for projects and tables, restrict data preview, and only support previewing data that is not higher than the developer's permission level.

[0064] Business personnel are subject to mandatory access control based on organization, permission level, and custom access control dimensions: mandatory access control to directories and entities; page preview data is subject to mandatory control of permission level, and data viewing (such as indicator query results) is subject to mandatory control of data row-level permissions.

[0065] Platform-level personnel obtain big data platform data through data services (APIs) and are subject to mandatory access control by custom row-level permissions. Custom row-level permissions can control any field in the table.

[0066] From the perspective of personnel, if a software is delivered to a client in a certain industrial industry, there are two personnel among them. The first person A has the permission level of important confidential, and the other person B has the permission level of general confidential. The first threshold is the project level. Important confidential user A can join any level of project, but internal user B can only join general confidential or internal projects. When they are both in a general confidential project at the same time, access the same user table to view data. A can see all data (public, internal, secret, confidential) and all columns, and B can only see the data with the permission level of public, internal, and secret. At the same time, if the personnel address column is confidential, then even if B views the information of a general confidential person C, the data seen in the personnel address column are all desensitized data and cannot be viewed.

[0067] From the perspective of the project, high-level projects cannot pull low-level personnel into them, nor can they access higher-level data. If a field in a piece of data has a higher level than the current project, it will be desensitized during preview and download to ensure that data will not flow from high-level to low-level.

[0068] like Figure 2 In one embodiment shown, Figure 2 The hardware block diagram of the permission system and access method of industrial software of the present invention. The permission management and control platform is the core of the system, including a user module, an audit log module and a permission maintenance module. The user module is responsible for the creation, modification and deletion of the overall user account, and assigns corresponding permission points to different application roles according to business needs. The audit log module is responsible for recording and managing all user operation logs to ensure that every operation in the system is traceable and enhance the transparency and security of the system. The permission maintenance module provides dynamic maintenance capabilities for permission points, allowing the system processing unit to add or edit relevant permission identifiers to adapt to changing business needs and security requirements.

[0069] Working closely with the authority management and control platform are three-member modules, including the system processing unit, the security and confidentiality unit, and the security audit unit. The system processing unit creates business personnel accounts through the user module and assigns corresponding authority points to different application roles. It is also responsible for controlling application modules, configuring authority points and roles, adding or deleting applications, and changing application-related information. The security and confidentiality unit assigns business personnel corresponding authority roles in the user module and performs authorization management on these roles to ensure that the allocation of authority is reasonable and secure, and authorizes roles to ordinary user accounts, thereby simplifying the authority management process. The security audit unit connects the system processing unit and the security and confidentiality unit unidirectionally through the audit log module, and is responsible for viewing and analyzing the operation logs of the system processing unit and the security and confidentiality unit to ensure the standardization and compliance of internal system operations.

[0070] The entire system achieves two-way feedback of user account information and user logs through the close connection between the permission control platform and the application module. The permission control platform will promptly feed back user account information to the application module to ensure that the application system can make corresponding adjustments and controls based on the latest account and permission configuration. At the same time, the application module will feed back user operation logs to the permission control platform, centrally store and manage these log information, and further enhance the audit capability of the system. The security and confidentiality unit and the security audit unit view and analyze the operation logs of their respective units and business personnel through the audit log module, forming a closed-loop management system that not only improves the security of the system, but also improves the efficiency and transparency of management.

[0071] The present invention brings many significant advantages through its highly integrated and intelligent design. First, the system realizes the centralization and automation of rights management. The seamless integration of user module, audit log module and rights maintenance module makes the allocation, adjustment and monitoring of rights more efficient, significantly reducing the complexity and error rate of manual management. Centralized management not only simplifies the operation process, but also improves the overall efficiency of rights management and ensures the consistency and standardization of rights configuration.

[0072] Secondly, the system performs well in terms of security. The design of the security and confidentiality unit and the security audit unit makes the internal operations of the system highly standardized and controllable. Through the one-way connection of the audit log module, all key operations can be fully monitored and recorded, potential security threats can be discovered and responded to in a timely manner, and the security of the system and data can be guaranteed. At the same time, the transparent operation audit mechanism enhances the traceability of operations, helps enterprises to discover and prevent internal violations in a timely manner, and further improves the overall security protection capabilities.

[0073] Flexibility is another major advantage of the system. The permission maintenance module provides the ability to dynamically maintain permission points, so that permission management can be updated in a timely manner as business needs change, ensuring that the permission system always meets the current business environment and security requirements. The system processing unit's dynamic control capability over application modules allows users to add, delete or change application-related information as needed, allowing the system to quickly adapt to changes in business needs and improving the system's scalability and maintainability.

[0074] In addition, the introduction of role-based authorization management simplifies the complex permission allocation process into role allocation, greatly improving the efficiency and accuracy of permission management. Role definition and management not only makes the permission system clearer and easier to maintain, but also facilitates the rapid onboarding of new users and permission adjustment for old users, ensuring the rationality and consistency of permission allocation. This role-based management method reduces the tedious operations in permission configuration and reduces security risks caused by human negligence.

[0075] The system processing unit automatically creates and manages business personnel accounts through the user module, reducing the tediousness and error rate of manual operations and ensuring the standardization and consistency of user accounts and authority allocation. The dynamic management capability of application information enables the system to flexibly respond to changes in business needs and quickly adjust authority configuration, improving the adaptability and flexibility of the system.

[0076] Finally, the closed-loop feedback mechanism ensures the timely transmission and processing of user account information and user logs, enhancing the interactivity and synergy of the system. The information feedback between the permission management platform and the application module enables permission management and log auditing to form an efficient cycle, avoiding the problems of information islands and data lags, and ensuring the real-time and accuracy of system management.

[0077] In one embodiment, the three-member management is divided into three types of accounts: system administrator, security and confidentiality administrator, and security audit administrator. Among them, the three-member management can only log in to the permission management platform, and cannot log in to the application system. The overall implementation method is as follows: (1) User management: The system administrator creates business personnel accounts, and the security administrator assigns role permissions and user permission levels to business personnel accounts for them to log in to the data center application system; (2) Application management: manage all module applications used by the current platform, which are used to match business personnel accounts when logging into corresponding application systems, thereby playing a role in authority management; (3) Role management & permission management: Manage all permission points of all current applications, select permission points for a role, and assign the role to an application user so that the user has all permission points of the current role. (4) Audit logs: collect and display the operation logs generated by all applications, as well as the logs of the three personnel when operating the permission management platform. Only the security and confidentiality officers and security auditors can view the audit logs. The security and confidentiality officers can view the logs of ordinary users and security auditors to conduct security audits on the behavior of ordinary users. The security auditors can view the operation logs of the system administrator and the security and confidentiality officers.

[0078] The specific implementation is as follows: (1) First, the administrator of the permission control platform needs to log in to the system and create three accounts. In the three-member account management, add the system administrator, security officer, and security auditor accounts; (2) The system administrator creates a business personnel account in the user management module; (3) The security officer assigns the corresponding roles to the business personnel in the user management module (business personnel do not include the three-member accounts); (4) In the user management module, the system administrator adds application-related information and configures the corresponding permission points and roles. Applications can also be added or deleted. (5) In the authority management module, the system administrator maintains the authority points and adds or edits relevant authority identifiers; (6) The system administrator assigns permissions to different application roles in the role management module; (7) The security officer manages the authorization of roles and authorizes roles to ordinary user accounts; (8) Audit log module: security and confidentiality officers can view the operation logs of security auditors and business personnel, and the Security Audit Institute can view the operation logs of system administrators and security and confidentiality officers, thereby ensuring mutual control.

[0079] The present invention is not limited to the above-mentioned embodiments. No matter any changes are made in the shape or material composition, any structural design provided by the present invention is a variation of the present invention and should be considered to be within the protection scope of the present invention.

Claims

1. An industrial software authority system, characterized in that: It includes an authority management and control platform and three-member modules. The three-member modules include a system processing unit, a security and confidentiality unit, and a security audit unit. The three-member modules are connected to the authority management and control platform. The authority management and control platform is connected to the application module. The authority management and control platform includes a user module and an audit log module. The security audit unit is unidirectionally connected to the system processing unit and the security and confidentiality unit through the audit log module. The system processing unit is connected to the application module through the user module.

2. The industrial software authority system according to claim 1, characterized in that: The system processing unit creates business personnel accounts through the user module and grants permission points to different application roles; the security and confidentiality unit grants business personnel corresponding permission roles in the user module, performs authorization management on the roles, and authorizes the roles to ordinary user accounts.

3. An industrial software authority system according to claim 1 or 2, characterized in that: The system processing unit controls the application module through the user module, configures corresponding authority points and roles, adds or deletes applications, and changes application-related information.

4. The industrial software authority system according to claim 3, characterized in that: The permission management and control platform also includes a permission maintenance module, and the system processing unit performs permission point maintenance through the permission maintenance module, adds or edits relevant permission identifiers, and the permission management and control platform feeds back user account information to the application module, and the application module feeds back user logs to the permission management and control platform.

5. An industrial software authority system according to claim 1 or 2, characterized in that: The security and confidentiality unit checks the operation logs of the security audit unit and the business personnel through the audit log module, and the security audit unit checks the operation logs of the system processing unit and the security and confidentiality unit through the audit log module.

6. A method for accessing industrial software permissions, using an industrial software permissions system as described in any one of claims 1 to 5, characterized in that: The following steps are involved: S1: The user applies for access, and the system authenticates the user through the platform to confirm the user's identity and permission level; S2: According to the access rights rules, the system automatically controls the user's access rights; S3: When a user needs to access beyond the scope of his / her basic permissions, he / she can apply for access permissions on his / her own initiative, and the system will review the application. S4: Users have access based on their permission level and authorization status.

7. An industrial software authority system according to claim 6, characterized in that: The authority levels include internal and general confidentiality and important confidentiality. The access permission rules include subject and object access permission rules. Specifically, the platform defines custom access rules based on the dimensions that affect the user's viewing of directories and data, specifically including access control dimensions composed of organizational structure, model, and business subject. Among them, for the security system, subject and object access permission rules are required for important subjects and objects. The system checks whether the user has the basic authority to access a certain type of directory or data. If so, it goes to step S3. If not, it denies access, records the log and returns to step S1.

8. An industrial software authority system according to claim 6 or 7, characterized in that: The step S3 includes the following steps: S3.1: When a user needs to access a specific directory or data beyond the scope of his / her basic authority, he / she shall submit an access application; S3.2: The system or personnel with corresponding authority shall review the user's access application; S3.3: Review whether the application complies with security policies and business requirements. If so, grant the corresponding access rights and record the authorization log. If not, reject the application and provide feedback to the user on the application result.

9. The industrial software authority system according to claim 8, characterized in that: The access permission rules also include controlling data permissions by rows and columns, specifically: users can only view data rows that match their permission levels; users can only view columns that are not marked as higher than their permission levels, and important columns are desensitized.

10. An industrial software authority system according to claim 9, characterized in that: In step S4, the system limits the user's operating scope on the data according to the permission control rules. Specifically, when developers preview data, they can only view data rows that meet the permission level and desensitize important columns; when business personnel view data, the corresponding data content is displayed according to the permission level and data row level.

Citation Information

Patent Citations

  • User access control methods, systems, and storage media

    CN113392423B