User permission processing method and device, computer equipment and storage medium
Through real-time monitoring and dynamic response mechanisms, user permission change requests are handled, which solves the problem of permission update delay in the existing technology, and significantly improves user experience and system performance.
Patent Information
- Application Number
- CN202510532561.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-25
- Publication Date
- 2025-06-06
AI Technical Summary
The existing technology has insufficient timeliness in user permission changes, resulting in poor user experience. Especially in the fields of medical health and financial technology, delays in permission updates may affect the timeliness and accuracy of medical decision-making and transaction processing.
By monitoring the target user's access request to the target component in real time, receiving and processing requests using message queues, obtaining user identity information and comparing permission requirements, and verifying access permissions. When there is no access permission, record the reason for insufficient permissions and generate permission change notifications, receive user's permission change requests, process and send processing results based on historical permission data and predefined policies.
It realizes timely and efficient handling of user permission changes, greatly improves user experience, reduces user waiting time and operation burden, and improves the overall performance and security of the system.
Smart Images

Figure CN120105401A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of security protection technology, and in particular to a user authority processing method, device, computer equipment and computer-readable storage medium. Background Art
[0002] At present, in the account operation system of some enterprises, store users are important participants, and their permission management is crucial to the smooth development of the business. With the continuous expansion of store business, users often need to increase or decrease permissions according to business needs. At present, in the existing enterprise account operation system, changes in user permissions and store switching often face the problem of untimely message delivery. The traditional permission update method usually requires users to actively log out and re-login to the system to obtain the latest permission information. This practice not only increases the user's operation burden, but may also cause users to perform illegal operations without knowing it, thereby affecting the normal operation of the business. For example, an employee may try to access a new business module without obtaining new permissions, but cannot operate due to insufficient permissions. This not only reduces work efficiency, but may also bring an unfriendly experience to users.
[0003] Currently, in the fields of healthcare and financial technology, user authority management in account operation systems is also crucial, but existing technologies also have many shortcomings in these areas.
[0004] In the healthcare sector, medical staff need real-time access to the latest patient data for accurate diagnosis and treatment. Delays in updating permissions may prevent medical staff from obtaining necessary information in a timely manner, thus affecting the timeliness and accuracy of medical decisions. For example, when a patient's condition changes and requires emergency treatment, medical staff may not be able to access the latest test results due to insufficient permissions, thus delaying treatment.
[0005] In the field of financial technology, risk managers need to process a large amount of transaction data in real time. Delays in updating permissions may result in the employee being unable to access necessary information in a timely manner, thus affecting the speed and accuracy of transaction processing. For example, when a customer makes a large transaction, risk managers need to access the customer's transaction history and credit record in real time to assess transaction risk. Delays in updating permissions may result in untimely risk assessments, thereby increasing the risk of financial institutions.
[0006] That is, the current user rights management method is insufficient in the timeliness of user rights changes, which affects the user experience.
[0007] Therefore, the existing technology still needs to be improved and developed. Summary of the invention
[0008] In view of the above-mentioned deficiencies in the prior art, the purpose of the present invention is to provide a user authority processing method, apparatus, computer device and computer-readable storage medium, aiming to solve the problem that the current user authority management method is insufficient in the timeliness of user authority changes, affecting the user experience.
[0009] In order to achieve the above object, the present invention adopts the following technical solutions:
[0010] In a first aspect, the present invention provides a method for processing user rights, which includes:
[0011] Real-time monitoring of the target client's access request to the target component, wherein the access request is received and processed through the established message queue;
[0012] When the target user terminal's access request to the target component is monitored, user identity information of the target user in the target user terminal is obtained, and the user identity information is compared with the permission requirement of the target component to verify whether the target user terminal has permission to access the target component;
[0013] When the target user terminal does not have access rights to the target component, a permission-inadequate reason for not having access rights is recorded, and a permission change notification is generated based on the permission-inadequate reason and sent to the target user terminal;
[0014] Receive the permission change request returned by the target user terminal based on the permission change notification, process the permission change request according to the historical permission data of the target user and a predefined permission change policy, generate a permission processing result, and send the permission processing result to the target user terminal.
[0015] In a second aspect, the present invention provides a user rights processing device, comprising:
[0016] A request monitoring module, used to monitor in real time the access request of the target user end to the target component, wherein the access request is received and processed through the established message queue;
[0017] The permission verification module is used to obtain the user identity information of the target user in the target user when the access request of the target user to the target component is monitored, and compare the user identity information with the permission requirement of the target component to verify whether the target user has the permission to access the target component;
[0018] A notification sending module, used for recording the reason of insufficient authority for not having access rights when the target user terminal has no access rights to the target component, and generating a permission change notification based on the reason of insufficient authority and sending it to the target user terminal;
[0019] The permission processing module is used to receive the permission change request returned by the target user terminal based on the permission change notification, process the permission change request according to the historical permission data of the target user and the predefined permission change policy, generate a permission processing result, and send the permission processing result to the target user terminal.
[0020] In a third aspect, the present invention provides a computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the user authority processing method as described above when executing the computer program.
[0021] In a fourth aspect, the present invention provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, wherein the computer program, when executed by a processor, implements the user authority processing method as described above.
[0022] Compared with the prior art, the present invention provides a user authority processing method, apparatus, computer equipment and computer-readable storage medium, wherein, by real-time monitoring of the access request of the target user terminal to the target component, the access request is received and processed through an established message queue; when the access request of the target user terminal to the target component is monitored, the user identity information of the target user in the target user terminal is obtained, and the user identity information is compared with the authority requirement of the target component to verify whether the target user terminal has the authority to access the target component; when the target user terminal has no access authority to the target component, the reason for insufficient authority for not having access authority is recorded, and a permission change notification is generated and sent to the target user terminal based on the reason for insufficient authority; the permission change request returned by the target user terminal based on the permission change notification is received, the permission change request is processed according to the historical authority data of the target user and the predefined permission change policy, a permission processing result is generated, and the permission processing result is sent to the target user terminal; thus, the present invention can process the user's authority changes in a timely and efficient manner, greatly improving the user experience. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0024] Figure 1 A schematic diagram of an application environment of a user authority processing method provided by an embodiment of the present invention.
[0025] Figure 2 A flowchart of a method for processing user rights provided by an embodiment of the present invention.
[0026] Figure 3 A schematic diagram of a program module of a user rights processing device provided by an embodiment of the present invention.
[0027] Figure 4 A schematic diagram of the structure of a computer device provided by an embodiment of the present invention.
[0028] Figure 5 Another structural schematic diagram of a computer device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0029] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0030] It should be understood that when used in the present specification and the appended claims, the term "comprising" indicates the presence of described features, integers, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components and / or combinations thereof.
[0031] It should also be understood that the term "and / or" used in the present description and the appended claims refers to and includes any and all possible combinations of one or more of the associated listed items.
[0032] As used in the present specification and the appended claims, the term "if" can be interpreted as "when" or "uponce" or "in response to determining" or "in response to detecting", depending on the context. Similarly, the phrase "if it is determined" or "if [described condition or event] is detected" can be interpreted as meaning "uponce it is determined" or "in response to determining" or "uponce [described condition or event] is detected" or "in response to detecting [described condition or event]", depending on the context.
[0033] In addition, in the description of the present specification and the appended claims, the terms "first", "second", "third", etc. are only used to distinguish the descriptions and cannot be understood as indicating or implying relative importance.
[0034] References to "one embodiment" or "some embodiments" etc. described in the present specification mean that one or more embodiments of the present invention include specific features, structures or characteristics described in conjunction with the embodiment. Therefore, the statements "in one embodiment", "in some embodiments", "in some other embodiments", "in some other embodiments", etc. that appear in different places in this specification do not necessarily refer to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized in other ways. The terms "including", "comprising", "having" and their variations all mean "including but not limited to", unless otherwise specifically emphasized in other ways.
[0035] It should be understood that the order of execution of the steps in the following embodiments does not imply a precedence of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0036] In order to illustrate the technical solution of the present invention, specific embodiments are provided below for illustration.
[0037] A user rights processing method provided by an embodiment of the present invention can be applied in Figure 1 In the application environment shown, the client and the server communicate through the network. The client includes but is not limited to PDAs, desktop computers, laptops, ultra-mobile personal computers (UMPCs), netbooks, cloud computing devices, personal digital assistants (PDAs) and other computer devices. The server can be an independent server or a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content delivery networks (CDNs), and big data and artificial intelligence platforms.
[0038] See also Figure 2 An embodiment of the present invention provides a method for processing user rights, wherein the method comprises the following steps:
[0039] S100, monitoring in real time the access request of the target user end to the target component, wherein the access request is received and processed through the established message queue;
[0040] S200, when the target user terminal's access request to the target component is monitored, obtaining the user identity information of the target user in the target user terminal, and comparing the user identity information with the permission requirement of the target component to verify whether the target user terminal has the permission to access the target component;
[0041] S300: When the target user terminal has no access rights to the target component, a permission-inadequate reason for not having access rights is recorded, and a permission change notification is generated according to the permission-inadequate reason and sent to the target user terminal;
[0042] S400, receiving a permission change request returned by the target user terminal based on the permission change notification, processing the permission change request according to the historical permission data of the target user and a predefined permission change policy, generating a permission processing result, and sending the permission processing result to the target user terminal.
[0043] During specific implementation, the user rights processing method of this embodiment can process user rights changes in a timely and efficient manner through real-time monitoring and dynamic response mechanisms, thereby significantly improving user experience.
[0044] Specifically:
[0045] 1. Real-time monitoring of access requests: By real-time monitoring of the target user terminal (referring to the electronic terminal where the target user is currently logged in)'s access requests to the target component, the access requests are received and processed through the established message queue, which is implemented based on the WebSocket protocol to support low-latency two-way communication; in this way, the system can capture the operation intention of the target user logged in in the target user terminal at the first time. This real-time monitoring mechanism ensures that the system will not miss any user's access request, and provides a basis for subsequent permission detection and processing.
[0046] 2. Instant permission verification: When the target user terminal's access request to the target component is monitored, the system immediately obtains the user identity information of the target user in the target user terminal, and compares the user identity information with the permission requirements of the target component to verify whether the target user terminal has the permission to access the target component; this instant verification mechanism can quickly determine whether the target user terminal has the permission to access the target component, avoiding the user waiting for a long time for the permission verification result, and improving the system's response speed.
[0047] 3. Actively push permission change notifications: When the target user does not have access rights to the target component, the reason for insufficient permission is recorded, and based on the reason for insufficient permission, a permission change notification is generated and sent to the target user; the permission change notification is pushed to the target user in real time via the WebSocket protocol. This active notification mechanism not only informs users of their current insufficient permissions in a timely manner, but also provides users with a way to solve the problem, avoiding users from repeatedly trying to access due to ignorance, thereby reducing user confusion and dissatisfaction.
[0048] 4. Efficiently process permission change requests: Receive permission change requests returned by the target user based on permission change notifications, process permission change requests based on the target user's historical permission data and predefined permission change policies, generate permission processing results, and send permission processing results to the target user; this processing method based on historical data can quickly evaluate the rationality and feasibility of permission changes, and ensure the accuracy and security of permission changes. At the same time, the system will promptly feedback the processing results to the user, so that the user can immediately understand the status of the permission change without waiting or re-logging into the system.
[0049] Through the above steps, the method of this embodiment realizes real-time monitoring, instant feedback and efficient processing of permission changes, greatly reducing the waiting time and operation burden of users in the permission change process, and improving the overall performance and user experience of the system. This dynamic and active permission processing mechanism not only improves user satisfaction, but also enhances the security and reliability of the system.
[0050] It can be understood that the user authority processing method provided in the embodiment of the present invention can be applied to user authority processing scenarios related to the medical and health field. The following is a specific example:
[0051] Example: User permission handling in the healthcare field
[0052] Scenario Description
[0053] In the healthcare field, a typical scenario is the hospital information management system (HIS). In this system, medical staff with different roles (such as doctors, nurses, laboratory technicians, etc.) need to access and operate different medical data and functional modules. As the patient's condition changes and the business process is adjusted, the permissions of medical staff need to be updated in real time to ensure that they can access the latest patient data and perform necessary operations.
[0054] Specific Examples
[0055] It is assumed that the HIS system of a certain hospital adopts the user authority processing method provided by the embodiment of the present invention.
[0056] The following are the specific implementation steps and scenario descriptions:
[0057] 1. Real-time monitoring of access requests: The hospital's information management system monitors in real time the access requests of medical staff to modules such as patient medical records, examination results, and treatment plans. For example, doctor Zhang San tries to access the latest examination results of patient Li Si.
[0058] 2. Instant permission verification: After the system detects the access request from doctor Zhang San, it immediately checks whether his identity information has the permission to access the examination results of patient Li Si. Assuming that Zhang San does not currently have this permission, the system will proceed to the next step.
[0059] 3. Actively push permission change notifications: The system pushes permission change notifications of insufficient permissions to Doctor Zhang San, informing him that he currently does not have permission to access the examination results of patient Li Si and whether he needs to apply for and change permissions.
[0060] 4. Efficiently handle permission change requests: Doctor Zhang San submits a permission change request through the system. The system can evaluate it based on Zhang San’s historical permission data (such as whether he previously had permission to access other patients’ test results) and predefined permission change policies (such as whether doctors in this department have permission to access patients in this department).
[0061] After evaluation, the system considers the application reasonable, approves the permission change request, and immediately updates the system with the new permission information. The system notifies Doctor Zhang San of the permission change result, informing him that he can now access the examination results of Patient Li Si.
[0062] Through the above steps, the user authority processing method provided by the embodiment of the present invention can promptly and efficiently process the authority change request of medical staff. The specific technical effects are as follows:
[0063] 1. Real-time: When medical staff try to access data, the system can immediately detect insufficient permissions and push notifications in a timely manner, preventing medical staff from performing invalid operations without knowing it.
[0064] 2. Efficiency: Permission change requests can be quickly evaluated and processed, reducing the time medical staff spend waiting for permission updates and improving work efficiency.
[0065] 3. User experience: Medical staff can obtain the latest permission information without frequently logging out and re-logging into the system, which greatly improves the system's usability and user experience.
[0066] 4. Security: The system can evaluate permission changes based on historical permission data and predefined rules, ensuring the rationality and security of permission changes and avoiding the risk of permission abuse.
[0067] Through this dynamic and real-time authority management mechanism, the hospital's information management system can better support the work of medical staff and improve the quality and efficiency of medical services.
[0068] It can be understood that the user rights processing method provided in the embodiment of the present invention can also be applied to user rights processing scenarios related to the financial technology field. The following is a specific example:
[0069] Example: User rights handling in the fintech sector
[0070] Scenario Description
[0071] In the field of FinTech, a typical scenario is an online financial service platform, such as a bank's online banking system or a FinTech company's trading system. These systems involve a large amount of financial transaction data and user personal information, and users with different roles (such as customers, account managers, risk managers, compliance officers, etc.) need to access and operate different functional modules. As the business changes and user needs adjust, user permissions need to be updated in real time to ensure that they can access the latest data and perform necessary operations.
[0072] Specific Examples
[0073] Assume that a financial technology company's trading system adopts the user rights processing method provided by the embodiment of the present invention. The following are specific implementation steps and scenario descriptions:
[0074] 1. Real-time monitoring of access requests: The trading system monitors user access requests to different functional modules in real time. For example, account manager Li Ming tries to access the account transaction records of customer Zhang Wei.
[0075] 2. Instant permission verification: After the system detects the access request from account manager Li Ming, it immediately checks whether his identity information has the permission to access the transaction records of customer Zhang Wei's account. Assuming that Li Ming currently does not have this permission, the system will proceed to the next step.
[0076] 3. Actively push permission change notifications: The system pushes permission change notifications of insufficient permissions to account manager Li Ming, informing him that he currently does not have permission to access customer Zhang Wei's account transaction records and whether he needs to apply for and change permissions.
[0077] 4. Efficiently handle permission change requests: Account manager Li Ming submits a permission change request through the system. The system can evaluate Li Ming's historical permission data (such as whether he previously had permission to access other customers' transaction records) and predefined permission change policies (such as whether the account manager of this department has the permission to visit customers of this department).
[0078] After evaluation, the system found the application reasonable, approved the permission change request, and immediately updated the new permission information to the system. The system notified the account manager Li Ming of the permission change result, informing him that he can now access the account transaction records of customer Zhang Wei.
[0079] Through the above steps, the user rights processing method provided by the embodiment of the present invention can timely and efficiently process the user's rights change request. The specific technical effects are as follows:
[0080] 1. Real-time: When a user tries to access data, the system can immediately detect insufficient permissions and push notifications in a timely manner, preventing users from performing invalid operations without knowing it.
[0081] 2. Efficiency: Permission change requests can be quickly evaluated and processed, reducing the time users have to wait for permission updates and improving work efficiency.
[0082] 3. User experience: Users can obtain the latest permission information without frequently logging out and back in, which greatly improves the system's usability and user experience.
[0083] 4. Security: The system can evaluate permission changes based on historical permission data and predefined rules, ensuring the rationality and security of permission changes and avoiding the risk of permission abuse.
[0084] Through this dynamic, real-time permission management mechanism, the transaction systems of financial technology companies can better support users' work and improve the quality and efficiency of financial services.
[0085] Further, in one embodiment, the user rights processing method, wherein the step S100, real-time monitoring of the target user's access request to the target component, wherein the access request is received and processed through an established message queue, specifically includes:
[0086] Establishing the message queue for processing the target user-side message;
[0087] Receiving and processing the access request of the target client to the target component through the message queue;
[0088] The access request is processed according to the priority of the urgency level of the access request and the authority level of the target user.
[0089] In specific implementation, in the user authority processing method of this embodiment, by establishing a message queue and processing access requests according to the urgency level of the access request and the priority of the user authority level, efficient and orderly authority management can be achieved. The establishment of a message queue provides a stable and efficient channel for receiving and processing access requests, ensuring that the requests can be captured and processed in a timely manner, avoiding delays caused by a backlog of requests. At the same time, priority processing is performed according to the urgency level of the access request and the user's authority level, so that high-priority access requests can be given priority processing. For example, urgent high-authority user requests can be responded to quickly, while low-priority requests are processed in sequence, thereby optimizing resource allocation and improving the overall processing efficiency of the system. This mechanism not only ensures the timely response to key access requests, but also improves the flexibility and adaptability of the system, further enhancing the user experience and system reliability.
[0090] Further, in one embodiment, the user authority processing method, wherein the step S200, when monitoring the access request of the target user terminal to the target component, obtains the user identity information of the target user in the target user terminal, and compares the user identity information with the authority requirement of the target component to verify whether the target user terminal has the authority to access the target component, specifically includes:
[0091] When the access request of the target user terminal to the target component is monitored, the user identity information of the target user logged in in the target user terminal is obtained through a multi-factor identity authentication mechanism;
[0092] Comparing the user identity information with the permission requirement of the target component, dynamically adjusting the permission requirement according to the context information of the access request of the target user terminal during the comparison, so that the user identity information is compared with the adjusted permission requirement;
[0093] According to the comparison result of the user identity information and the adjusted permission requirement, it is verified whether the target user terminal has the permission to access the target component, and a verification result is generated and sent to the target user terminal.
[0094] In specific implementation, in the user rights processing method of this embodiment, the user identity information is obtained through a multi-factor authentication mechanism, and the permission requirements are dynamically adjusted in combination with the context information of the access request, so that accurate and flexible permission verification can be achieved. The multi-factor authentication mechanism improves the accuracy and security of user identity authentication, ensuring that only legitimate users can initiate access requests. Among them, the multi-factor authentication mechanism includes but is not limited to at least one of the following: biometric-based authentication, such as fingerprint, facial recognition or iris recognition; hardware token-based authentication, such as smart card or USBKey; one-time password (OTP)-based authentication, such as SMS verification code or dynamic password; behavior analysis-based authentication, such as user operation habits, device fingerprints, etc. At the same time, the permission requirements are dynamically adjusted according to the context information of the access request, so that the permission verification is more in line with the actual scenario, and can flexibly respond to different access requirements and environmental changes. This dynamic adjustment method not only improves the flexibility of permission verification, but also effectively avoids the problem of excessive or insufficient permissions caused by static permission settings. That is, in the comparison process, a context-aware mechanism is introduced to dynamically adjust permission requirements based on the context information of the target user's access request (such as access time, access location, access device type, network environment, etc.) to achieve more fine-grained access control. Ultimately, accurate comparison results are used to verify whether the target user has the permission to access the target component, and the verification results are quickly fed back to the user, ensuring that the user can understand the status of their access permissions in a timely manner, further improving the efficiency of permission management and user experience.
[0095] Further, in one embodiment, the user rights processing method, wherein the step S300, when the target user terminal has no access rights to the target component, records the insufficient rights reason for not having access rights, and generates a rights change notification based on the insufficient rights reason and sends it to the target user terminal, specifically includes:
[0096] When the target client has no access rights to the target component, the reason for insufficient access rights is recorded;
[0097] The permission change notification is generated according to the reason for insufficient permission and the current business demand of the target user terminal, and the permission change notification is sent to the target user terminal.
[0098] During specific implementation, in the user permission processing method of this embodiment, when the target user terminal has no access rights to the target component, accurate and targeted permission change guidance can be achieved by recording the reasons for insufficient permissions and generating permission change notifications in combination with the current business needs of the target user terminal. Specifically, recording the reasons for insufficient permissions clearly points out to users the specific reasons for not being able to access the target component, allowing users to understand the key points of missing permissions. Generating permission change notifications in combination with current business needs further considers the specific needs of users in actual operation scenarios, making the notification content more targeted and practical. This approach not only helps users quickly understand how to apply for appropriate permission changes, but also reduces the trouble of users being unable to complete business operations due to insufficient permissions, improves the efficiency of users solving problems, and thus significantly improves the user experience and the friendliness of the system.
[0099] Further, in one embodiment, the user rights processing method, wherein the step S400, receiving the rights change request returned by the target user terminal based on the rights change notification, processing the rights change request according to the historical rights data of the target user and a predefined rights change policy, generating a rights processing result, and sending the rights processing result to the target user terminal, specifically includes:
[0100] Receiving the permission change request returned by the target user terminal based on the permission change notification; the permission change request includes change content and a timestamp;
[0101] According to the historical permission data of the target user and the predefined permission change policy, risk assessment and compliance check are performed on the change content to generate assessment and check results;
[0102] The target user terminal's access rights to the target component are adjusted according to the evaluation and inspection results, the permission processing result is generated, and the permission processing result is sent to the target user terminal.
[0103] During specific implementation, in the user permission processing method of this embodiment, by receiving permission change requests with change content and timestamps, and combining the user's historical permission data and predefined permission change policies for risk assessment and compliance checks, safe, efficient and accurate permission change processing can be achieved. The introduction of timestamps ensures the timeliness and sequentiality of requests, and avoids erroneous processing caused by request conflicts or outdated requests. At the same time, based on the evaluation and inspection of historical permission data and permission change policies, the rationality and potential risks of permission changes can be comprehensively analyzed to ensure that the change operations meet both business needs and security compliance requirements. Finally, adjusting permissions based on the evaluation and inspection results and promptly feeding back permission processing results not only improves the accuracy and security of permission changes, but also allows users to quickly understand the results of permission changes, further improving user experience and system reliability.
[0104] Furthermore, in one embodiment, the user rights processing method, wherein the step of performing risk assessment and compliance check on the change content according to the historical rights data of the target user and the predefined rights change policy, and generating assessment and check results, specifically includes:
[0105] Acquire the historical authority data of the target user from a database; the historical authority data includes the authority currently owned by the target user, the authority previously owned, the history of authority changes, and the user behavior log;
[0106] Obtain the predefined permission change policy from the configuration file;
[0107] Based on the historical permission data and the permission change policy, risk assessment and compliance check are performed on the change content to generate the assessment and check results.
[0108] During specific implementation, in the user authority processing method of this embodiment, by comprehensively considering the historical authority data of the target user and the predefined authority change policy, risk assessment and compliance check are performed on the authority change request, so as to achieve accurate, safe and efficient authority change management. Specifically, the historical authority data of the user is obtained from the database, including the current authority, the authority previously possessed, the authority change record and the user behavior log, which provides comprehensive background information for the evaluation. At the same time, combined with the predefined authority change policy obtained from the configuration file, it can ensure that the authority change operation complies with the established rules and standards. Based on this information, risk assessment and compliance check can effectively identify potential security risks and non-compliant change requests, thereby avoiding security issues caused by abuse of authority or improper changes. The evaluation and inspection results finally generated provide a clear basis for authority adjustment, ensure the transparency and traceability of the authority change process, and further improve the security and reliability of the system.
[0109] Furthermore, in one embodiment, the user rights processing method, wherein adjusting the access rights of the target user terminal to the target component according to the evaluation and inspection results, generating the rights processing result, and sending the rights processing result to the target user terminal, specifically includes:
[0110] When the evaluation and inspection result is passed, a dynamic permission configuration plan is generated according to the change content and the permission change strategy;
[0111] Executing a permission configuration engine to adjust the target user's access rights to the target component according to the dynamic permission configuration scheme, and generating the permission processing result;
[0112] The permission processing result is formatted and sent to the target user end, and permission change report information is sent to the administrator end at the same time.
[0113] In specific implementation, in the user rights processing method of this embodiment, when the evaluation and inspection results are that the evaluation and inspection are passed, a dynamic rights configuration scheme is generated according to the change content and the rights change strategy; the user rights are adjusted by the generated dynamic rights configuration scheme and the rights configuration engine is executed, and relevant notifications are sent to the user and the administrator at the same time, so that efficient, flexible and transparent rights change management can be achieved. When the evaluation and inspection results are passed, a dynamic rights configuration scheme is generated based on the change content and the rights change strategy to ensure the pertinence and adaptability of the rights adjustment. The execution of the rights configuration engine can quickly and accurately implement the rights change, improving the response speed and operating efficiency of the system. The rights processing results are formatted and sent to the user, so that the user can clearly understand the specific circumstances of the rights change, enhancing the user experience. At the same time, the rights change reporting information is sent to the administrator side to realize the supervision and recording of the rights change process, which is convenient for subsequent management and auditing, and further improves the security and reliability of the system.
[0114] It can be seen from the above method embodiments that the user authority processing method provided by the present invention includes: real-time monitoring of the target user terminal's access request to the target component, the access request is received and processed through the established message queue; when the target user terminal's access request to the target component is monitored, the user identity information of the target user in the target user terminal is obtained, and the user identity information is compared with the permission requirements of the target component to verify whether the target user terminal has the permission to access the target component; when the target user terminal has no access rights to the target component, the reason for insufficient authority for not having access rights is recorded, and according to the reason for insufficient authority, a permission change notification is generated and sent to the target user terminal; receiving the permission change request returned by the target user terminal based on the permission change notification, processing the permission change request according to the historical permission data of the target user and the predefined permission change policy, generating a permission processing result, and sending the permission processing result to the target user terminal. In this way, the method of the present invention can timely and efficiently process the user's permission changes, greatly improving the user experience.
[0115] It should be understood that, although the present application provides method operation steps as described in the embodiments or flowcharts, more or less operation steps may be included based on conventional or non-creative labor, and these operation steps are not necessarily performed in sequence according to the embodiment or flowchart. The order of steps listed in the embodiment or flowchart is only one way of executing the order of many steps, and does not represent the only execution order. It should be noted that there is not necessarily a certain order between the above steps. A person of ordinary skill in the art can understand from the description of the embodiment of the present invention that in different embodiments, the above steps may have different execution orders, that is, they may be executed in parallel, or they may be executed in exchange, etc. Moreover, at least a part of the steps in the embodiment or flowchart may include multiple sub-steps or multiple stages, and these sub-steps or stages are not necessarily executed at the same time, but may be executed at different times, and the execution order of these sub-steps or stages is not necessarily performed in sequence, but may be executed in turn, alternately or synchronously with other steps or at least a part of the sub-steps or stages of other steps.
[0116] Based on the above method embodiment, please refer to Figure 3 Another embodiment of the present invention further provides a user rights processing device, wherein the device comprises:
[0117] A request monitoring module 11 is used to monitor in real time the access request of the target user end to the target component, and the access request is received and processed through the established message queue;
[0118] The permission verification module 12 is used to obtain the user identity information of the target user in the target user when the access request of the target user to the target component is monitored, and compare the user identity information with the permission requirement of the target component to verify whether the target user has the permission to access the target component;
[0119] The notification sending module 13 is used to record the reason for insufficient permission for not having access rights when the target user terminal has no access rights to the target component, and generate a permission change notification based on the reason for insufficient permission and send it to the target user terminal;
[0120] The permission processing module 14 is used to receive the permission change request returned by the target user terminal based on the permission change notification, process the permission change request according to the historical permission data of the target user and the predefined permission change policy, generate a permission processing result, and send the permission processing result to the target user terminal.
[0121] Furthermore, in one embodiment, in the user rights processing device, the request monitoring module 11 is specifically used to:
[0122] Establishing the message queue for processing the target user-side message;
[0123] Receiving and processing the access request of the target client to the target component through the message queue;
[0124] The access request is processed according to the priority of the urgency level of the access request and the authority level of the target user.
[0125] Furthermore, in one embodiment, in the user authority processing device, the authority verification module 12 is specifically used to:
[0126] When the access request of the target user terminal to the target component is monitored, the user identity information of the target user logged in in the target user terminal is obtained through a multi-factor identity authentication mechanism;
[0127] Comparing the user identity information with the permission requirement of the target component, dynamically adjusting the permission requirement according to the context information of the access request of the target user terminal during the comparison, so that the user identity information is compared with the adjusted permission requirement;
[0128] According to the comparison result of the user identity information and the adjusted permission requirement, it is verified whether the target user terminal has the permission to access the target component, and a verification result is generated and sent to the target user terminal.
[0129] Furthermore, in one embodiment, in the user rights processing device, the notification sending module 13 is specifically used to:
[0130] When the target client has no access rights to the target component, the reason for insufficient access rights is recorded;
[0131] The permission change notification is generated according to the reason for insufficient permission and the current business demand of the target user terminal, and the permission change notification is sent to the target user terminal.
[0132] Furthermore, in one embodiment, the user authority processing device, wherein the authority processing module 14 is specifically used to:
[0133] Receiving the permission change request returned by the target user terminal based on the permission change notification; the permission change request includes change content and a timestamp;
[0134] According to the historical permission data of the target user and the predefined permission change policy, risk assessment and compliance check are performed on the change content to generate assessment and check results;
[0135] The target user terminal's access rights to the target component are adjusted according to the evaluation and inspection results, the permission processing result is generated, and the permission processing result is sent to the target user terminal.
[0136] Furthermore, in one embodiment, the user rights processing device, wherein the step of performing risk assessment and compliance check on the change content according to the historical rights data of the target user and the predefined rights change policy, and generating assessment and check results, specifically includes:
[0137] Acquire the historical authority data of the target user from a database; the historical authority data includes the authority currently owned by the target user, the authority previously owned, the history of authority changes, and the user behavior log;
[0138] Obtain the predefined permission change policy from the configuration file;
[0139] Based on the historical permission data and the permission change policy, risk assessment and compliance check are performed on the change content to generate the assessment and check results.
[0140] Further, in one embodiment, the user rights processing device, wherein adjusting the access rights of the target user terminal to the target component according to the evaluation and inspection results, generating the rights processing result, and sending the rights processing result to the target user terminal, specifically includes:
[0141] When the evaluation and inspection result is passed, a dynamic permission configuration plan is generated according to the change content and the permission change strategy;
[0142] Executing a permission configuration engine to adjust the target user's access rights to the target component according to the dynamic permission configuration scheme, and generating the permission processing result;
[0143] The permission processing result is formatted and sent to the target user end, and permission change report information is sent to the administrator end at the same time.
[0144] It should be noted that in the embodiment of the device of the present invention, the information interaction, execution process and other contents between the above-mentioned modules are based on the same concept as the embodiment of the method of the present invention. Their specific functions and technical effects can be found in the aforementioned method embodiment part and will not be repeated here.
[0145] Based on the above method embodiment, another embodiment of the present invention further provides a computer device, which may be a server, and its internal structure diagram may be as follows: Figure 4 As shown. The computer device includes a processor, a memory, a network interface and a database connected via a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the computer device is used to communicate with an external terminal via a network connection. When the computer program is executed by the processor, the functions or steps on the service side of the user authority processing method in any of the above method embodiments are implemented.
[0146] Based on the above method embodiment, another embodiment of the present invention further provides a computer device, which may be a client, and its internal structure diagram may be as follows: Figure 5 As shown. The computer device includes a processor, a memory, a network interface, a display screen and an input device connected via a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the computer device is used to communicate with an external terminal via a network connection. When the computer program is executed by the processor, the functions or steps of the client side of the user authority processing method in any of the above method embodiments are implemented.
[0147] Those skilled in the art will understand that Figure 4 and Figure 5 The structural schematic diagram shown in the figure is only a schematic diagram of a partial structure related to the solution of the present invention, and does not constitute a limitation on the computer device to which the solution of the present invention is applied. The specific computer device may include more components than those shown in the figure, or combine certain components, or have a different arrangement of components.
[0148] The processor may be a CPU, or other general-purpose processors, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor, or the processor may be any conventional processor, etc.
[0149] Among them, the memory includes a readable storage medium, an internal memory, etc., wherein the internal memory can be the memory of a computer device, and the internal memory provides an environment for the operation of an operating system and computer-readable instructions in the readable storage medium. The readable storage medium can be a hard disk of a computer device, and in other embodiments, it can also be an external storage device of a computer device, for example, a plug-in hard disk, a smart memory card (Smart Media Card, SMC), a secure digital (Secure Digital, SD) card, a flash card (Flash Card), etc. equipped on a computer device. Further, the memory can also include both an internal storage unit of a computer device and an external storage device. The memory is used to store an operating system, an application program, a boot loader (BootLoader), data, and other programs, such as the program code of a computer program, etc. The memory can also be used to temporarily store data that has been output or is to be output.
[0150] Based on the above method embodiments, another embodiment of the present invention further provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, wherein when the computer program is executed by a processor, the user rights processing method in any of the above method embodiments is implemented. The computer-readable storage medium may be non-volatile or volatile.
[0151] It should be noted that the above-mentioned functions or steps that can be implemented by the computer-readable storage medium or computer device, and the technical effects brought about by the functions / steps, can be found in the relevant descriptions in the aforementioned method embodiments. To avoid repetition, they will not be described one by one here.
[0152] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. As an illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM). The disclosed memory components or memories of the operating environments described herein are intended to comprise one or more of these and / or any other suitable types of memory.
[0153] The technicians in the relevant field can clearly understand that for the convenience and simplicity of description, in the embodiment of the device of the present invention, only the division of the above-mentioned functional units and modules is used as an example. In practical applications, the above-mentioned function allocation can be completed by different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above. The functional units and modules in the embodiment can be integrated in a processing unit, or each unit can exist physically separately, or two or more units can be integrated in one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of software functional units. In addition, the specific names of the functional units and modules are only for the convenience of distinguishing each other, and are not used to limit the scope of protection of the present invention. The specific working process of the units and modules in the above-mentioned device can refer to the corresponding process in the above-mentioned method embodiment, which will not be repeated here. If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium.
[0154] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present invention.
[0155] In the embodiments provided by the present invention, it should be understood that the disclosed devices / computer equipment and methods can be implemented in other ways. For example, the device / computer equipment embodiments described above are only schematic, for example, the division of modules or units is only a logical function division, and there may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0156] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0157] It should be noted that if software tools or components other than those of the Company appear in the embodiments of the present application, they are only used for illustration and do not represent actual use. The above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the above embodiments, a person of ordinary skill in the art should understand that the technical solutions described in the above embodiments can still be modified, or some of the technical features thereof can be replaced by equivalents; and these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention, and should be included in the protection scope of the present invention.
Claims
1. A user rights processing method, characterized in that: include: Real-time monitoring of the target client's access request to the target component, wherein the access request is received and processed through the established message queue; When the target user terminal's access request to the target component is monitored, user identity information of the target user in the target user terminal is obtained, and the user identity information is compared with the permission requirement of the target component to verify whether the target user terminal has permission to access the target component; When the target user terminal does not have access rights to the target component, a permission-inadequate reason for not having access rights is recorded, and a permission change notification is generated based on the permission-inadequate reason and sent to the target user terminal; Receive the permission change request returned by the target user terminal based on the permission change notification, process the permission change request according to the historical permission data of the target user and a predefined permission change policy, generate a permission processing result, and send the permission processing result to the target user terminal.
2. The user rights processing method according to claim 1, characterized in that: The real-time monitoring of the target user's access request to the target component, wherein the access request is received and processed through the established message queue, includes: Establishing the message queue for processing the target user-side message; Receiving and processing the access request of the target client to the target component through the message queue; The access request is processed according to the priority of the urgency level of the access request and the authority level of the target user.
3. The user rights processing method according to claim 1, characterized in that: When the access request of the target user terminal to the target component is monitored, user identity information of the target user in the target user terminal is obtained, and the user identity information is compared with the permission requirement of the target component to verify whether the target user terminal has the permission to access the target component, including: When the access request of the target user terminal to the target component is monitored, the user identity information of the target user logged in in the target user terminal is obtained through a multi-factor identity authentication mechanism; Comparing the user identity information with the permission requirement of the target component, dynamically adjusting the permission requirement according to the context information of the access request of the target user terminal during the comparison, so that the user identity information is compared with the adjusted permission requirement; According to the comparison result of the user identity information and the adjusted permission requirement, it is verified whether the target user terminal has the permission to access the target component, and a verification result is generated and sent to the target user terminal.
4. The user rights processing method according to claim 1, characterized in that: When the target user terminal does not have access rights to the target component, recording the insufficient authority reason for not having access rights, and generating a permission change notification based on the insufficient authority reason and sending it to the target user terminal, including: When the target client has no access rights to the target component, the reason for insufficient access rights is recorded; The permission change notification is generated according to the reason for insufficient permission and the current business demand of the target user terminal, and the permission change notification is sent to the target user terminal.
5. The user rights processing method according to claim 1, characterized in that: The receiving the permission change request returned by the target user terminal based on the permission change notification, processing the permission change request according to the historical permission data of the target user and a predefined permission change policy, generating a permission processing result, and sending the permission processing result to the target user terminal, includes: Receiving the permission change request returned by the target user terminal based on the permission change notification; the permission change request includes change content and a timestamp; According to the historical permission data of the target user and the predefined permission change policy, risk assessment and compliance check are performed on the change content to generate assessment and check results; The target user terminal's access rights to the target component are adjusted according to the evaluation and inspection results, the permission processing result is generated, and the permission processing result is sent to the target user terminal.
6. The user rights processing method according to claim 5, characterized in that: The step of performing risk assessment and compliance check on the change content according to the historical permission data of the target user and the predefined permission change policy, and generating assessment and check results, includes: Acquire the historical authority data of the target user from a database; the historical authority data includes the authority currently owned by the target user, the authority previously owned, the history of authority changes, and the user behavior log; Obtain the predefined permission change policy from the configuration file; Based on the historical permission data and the permission change policy, risk assessment and compliance check are performed on the change content to generate the assessment and check results.
7. The user rights processing method according to claim 5, characterized in that: The step of adjusting the target user terminal's access rights to the target component according to the evaluation and inspection results, generating the permission processing result, and sending the permission processing result to the target user terminal includes: When the evaluation and inspection result is passed, a dynamic permission configuration plan is generated according to the change content and the permission change strategy; Executing a permission configuration engine to adjust the target user's access rights to the target component according to the dynamic permission configuration scheme, and generating the permission processing result; The permission processing result is formatted and sent to the target user end, and permission change report information is sent to the administrator end at the same time.
8. A user rights processing device, characterized in that: include: A request monitoring module, used to monitor in real time the access request of the target user end to the target component, wherein the access request is received and processed through the established message queue; The permission verification module is used to obtain the user identity information of the target user in the target user when the access request of the target user to the target component is monitored, and compare the user identity information with the permission requirement of the target component to verify whether the target user has the permission to access the target component; A notification sending module, used for recording the reason of insufficient authority for not having access rights when the target user terminal has no access rights to the target component, and generating a permission change notification based on the reason of insufficient authority and sending it to the target user terminal; The permission processing module is used to receive the permission change request returned by the target user terminal based on the permission change notification, process the permission change request according to the historical permission data of the target user and the predefined permission change policy, generate a permission processing result, and send the permission processing result to the target user terminal.
9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the user authority processing method according to any one of claims 1 to 7 is implemented.
10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the user rights processing method according to any one of claims 1 to 7 is implemented.