Access control method and device and storage medium

By combining role access checksum policy access checksum in the access control method and handling conflicts based on priority, the problem of low access control verification efficiency and accuracy is solved, and more efficient and accurate access control verification is achieved.

CN120105451APending Publication Date: 2025-06-06ZTE CORP
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510156371.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-12
Publication Date
2025-06-06

AI Technical Summary

Technical Problem

With the surge in business visits, the policy configuration of access control verification through policy combination is large, and multiple policy combinations are prone to conflicts, resulting in inaccuracy and inefficiency of access control verification.

Method used

An access control method is provided, by receiving access requests for target resources, performing role access checksum policy access checksum, performing conflict detection processing, and determining the access control verification result based on the priority of role verification results and the priority of policy verification results.

Benefits of technology

Coarse-grained filtering is performed through role access verification, quickly determine whether the user has basic access rights, and fine-grained filtering is performed through policy access verification, improving the accuracy of access control verification. At the same time, the priority-based conflict resolution mechanism improves the efficiency of access control verification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120105451A_ABST
    Figure CN120105451A_ABST
Patent Text Reader

Abstract

The invention discloses an access control method and device and a storage medium, and belongs to the field of communication. The access control method provided by the embodiment of the invention comprises the following steps: receiving an access request for a target resource; responding to the access request, executing role access verification, determining a role verification result, executing strategy access verification, and determining a strategy verification result; performing conflict detection processing on the role verification result and the strategy verification result; determining an access control verification result according to the priority of the role verification result and the priority of the strategy verification result under the condition that the role verification result conflicts with the strategy verification result; and determining a response result of the access request according to the access control verification result.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the field of communications, and in particular to an access control method, device, and storage medium. Background Art

[0002] With the rapid development of computer technology, in order to ensure data security and business logic compliance, access control mechanisms such as role access verification and policy access verification can be added to the information system. To make up for the shortcomings of a single mechanism, role access verification can be added on the basis of policy access verification, such as allowing roles to participate in policy access verification as attributes.

[0003] However, with the surge in business access volume, the policy configuration workload for access control verification through the above-mentioned policy combination method is large, and multiple policy combinations are prone to conflicts, which will lead to low accuracy and efficiency of access control verification. Therefore, a solution to improve the efficiency and accuracy of access control verification is needed. Summary of the invention

[0004] The embodiments of the present application provide a solution for improving the efficiency and accuracy of access control verification.

[0005] In a first aspect, an access control method is provided, the method comprising: receiving an access request for a target resource; in response to the access request, performing a role access check to determine a role check result, and performing a policy access check to determine a policy check result; performing conflict detection processing on the role check result and the policy check result; in the event of a conflict between the role check result and the policy check result, determining an access control check result based on the priority of the role check result and the priority of the policy check result; and determining a response result of the access request based on the access control check result.

[0006] In a second aspect, an access control device is provided, the device comprising: a request receiving module for receiving an access request for a target resource; a verification module for performing a role access verification in response to the access request to determine a role verification result, and performing a policy access verification to determine a policy verification result; a conflict detection module for performing conflict detection processing on the role verification result and the policy verification result; a first determination module for determining an access control verification result according to a priority of the role verification result and a priority of the policy verification result when a conflict exists between the role verification result and the policy verification result; and a second determination module for determining a response result of the access request according to the access control verification result.

[0007] In a third aspect, an access control device is provided, the device comprising a processor and a memory, the memory storing a program or instruction executable on the processor, the program or instruction implementing the access control steps as described in the first aspect when executed by the processor.

[0008] In a fourth aspect, a readable storage medium is provided, on which a program or instruction is stored, and when the program or instruction is executed by a processor, the access control steps described in the first aspect are implemented.

[0009] The present application embodiment adopts the following technical solutions: Receive an access request for a target resource, and in response to the access request, perform role access verification to determine the role verification result, and perform policy access verification to determine the policy verification result. Then, perform conflict detection processing on the role verification result and the policy verification result. In the event of a conflict between the role verification result and the policy verification result, determine the access control verification result based on the priority of the role verification result and the priority of the policy verification result. Finally, determine the response result of the access request based on the access control verification result.

[0010] At least one of the above technical solutions adopted in the embodiments of the present application can achieve the following beneficial effects: On the one hand, coarse-grained filtering can be performed through role access verification, that is, role access verification can be used to quickly determine whether the user has basic access rights. At the same time, fine-grained filtering can be performed through policy access verification, that is, detailed verification can be performed through policy access verification to improve the accuracy of access control verification. On the other hand, in the case of a conflict between the role verification result and the policy verification result, the response result of the access request can be determined based on the priority of the role verification result and the priority of the policy verification result, that is, the conflict between the role access verification and the policy access verification can be resolved based on the priority-based conflict resolution mechanism, thereby improving the efficiency of access control verification. BRIEF DESCRIPTION OF THE DRAWINGS

[0011] Figure 1 is a schematic flow chart of an access control method according to an embodiment of the present application; Figure 2 is a schematic diagram of an access control process according to an embodiment of the present application; Figure 3 is a schematic flow chart of an access control method according to an embodiment of the present application; Figure 4 is a schematic diagram of another access control process according to an embodiment of the present application; Figure 5 is a schematic flow chart of an access control method according to an embodiment of the present application; Figure 6 is a schematic diagram of another access control process according to an embodiment of the present application; Figure 7 is a schematic diagram of another access control process according to an embodiment of the present application; Figure 8 is a schematic diagram of the structure of an access control device according to an embodiment of the present application; Fig. 9 It is a schematic diagram of the structure of an access control device according to an embodiment of the present application. DETAILED DESCRIPTION

[0012] The embodiments of this specification provide an access control method, device, and storage medium.

[0013] In order to enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below in conjunction with the drawings in the embodiments of this specification. Obviously, the described embodiments are only part of the embodiments of this specification, not all of the embodiments. Based on the embodiments in this specification, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of this specification.

[0014] The invention concept of the present application is as follows: With the rapid development of computer technology, in order to determine data security and business logic compliance, access control mechanisms such as role access verification and policy access verification can be added to the information system. In order to make up for the shortcomings of a single mechanism, role access verification can be added on the basis of policy access verification, such as allowing roles to participate in policy access verification as attributes. However, with the surge in business access volume, the policy configuration workload for access control verification through the above-mentioned policy combination method is large, and multiple policy combinations are prone to conflicts, which will lead to low accuracy and efficiency of access control verification. Therefore, a solution to improve the efficiency and accuracy of access control verification is needed. To this end, the embodiment of this specification provides a technical solution that can solve the above-mentioned problem. In this solution, an access request for a target resource can be received, and in response to the access request, a role access verification is performed to determine the role verification result, and a policy access verification is performed to determine the policy verification result. Then, conflict detection processing is performed on the role verification result and the policy verification result, and when there is a conflict between the role verification result and the policy verification result, the access control verification result is determined according to the priority of the role verification result and the priority of the policy verification result. Finally, according to the access control verification result, the response result of the access request is determined. In this way, on the one hand, coarse-grained filtering can be performed through role access verification, that is, role access verification can be used to quickly determine whether the user has basic access rights. At the same time, fine-grained filtering can be performed through policy access verification, that is, detailed verification can be performed through policy access verification to improve the accuracy of access control verification. On the other hand, in the case of a conflict between the role verification result and the policy verification result, the response result of the access request can be determined based on the priority of the role verification result and the priority of the policy verification result, that is, the conflict between the role access verification and the policy access verification can be resolved based on the priority-based conflict resolution mechanism, thereby improving the efficiency of access control verification. For details, please refer to the following content.

[0015] In one embodiment, if Figure 1 As shown, the embodiment of this specification provides an access control method, and the execution subject of the method can be a server, wherein the server can be an independent server or a server cluster composed of multiple servers. The method can specifically include the following steps: In S102, an access request for a target resource is received.

[0016] The target resource may be any accessible resource, for example, the target resource may be any accessible resource such as a database, a device, a system, a file, etc.

[0017] In an implementation, the server may receive access requests from one or more users for a target resource.

[0018] In S104, in response to the access request, a role access check is performed to determine a role check result, and a policy access check is performed to determine a policy check result.

[0019] In implementation, Figure 2 As shown, the server can perform access control verification through a multi-level access control architecture. The multi-level access control architecture can return information through multi-level assembly, improve the transparency of the access control system, and facilitate debugging and improvement. Among them, the access control architecture can include three levels, each level can be responsible for processing specific permission verification logic to form a hierarchical access control architecture. The multi-level access control architecture can specifically include: The first layer: the role-based access control (RBAC) verification layer used for coarse-grained filtering.

[0020] like Figure 2 As shown, the server can obtain the preset mapping relationship between the role and resource permissions corresponding to the target resource from the role permission library according to the resource identifier of the target resource carried in the access request, and then determine the target role that has access to the target resource based on the preset mapping relationship.

[0021] Then, the server may obtain the first role to which the user belongs according to the user identifier carried in the access request, and perform matching processing on the target role and the first role to determine a role verification result.

[0022] For example, the access request received by the server may be: User A requests to access resource Resource_001 on Saturday and perform an "approval" operation.

[0023] The server may determine the target role that has access to the target resource according to the preset mapping relationship between the role corresponding to the resource Resource_001 and the resource authority. For example, the target role that has access to the target resource may include “department head” and “project leader”.

[0024] The server can obtain the first role belonging to user A, and match the first role with the target role to determine the role verification result. That is, if the first role includes "department head" and / or "project leader", the role verification result can be determined as passed; otherwise, the role verification result can be determined as failed.

[0025] In the first-level RBAC verification, the preset mapping relationship between predefined roles and resource permissions can be used to check whether the role to which the user belongs has the permission to access the target resource. That is, the preset mapping relationship between roles and resource permissions can be used to quickly determine whether the user has basic access rights. In this way, this level can reduce the calculation pressure of subsequent complex strategies through fast and coarse-grained screening, improve overall performance, and is suitable for fast determination of static permissions and processing scenarios of a large number of low-complexity access requests.

[0026] The second layer: the policy access verification layer for fine-grained verification (Attribute Based Access Control, ABAC).

[0027] like Figure 2 As shown, the server can determine the target access policy corresponding to the target resource from the preset rule base according to the resource identifier of the target resource carried in the access request. At the same time, the server can also obtain the target data from the cache through the information acquisition module, and then through the rule execution engine, based on the target data, determine whether the target access policy is satisfied and determine the policy verification result.

[0028] The cache may store data within a preset data acquisition period (such as the past day, the past week, the past three months, etc.).

[0029] For example, it is assumed that the access request received by the server may be: User A requests to access resource Resource_001 on Saturday and perform an "approval" operation.

[0030] The target access policy corresponding to the resource Resource_001 obtained by the server may include Rule 1 (the resource must belong to the department to which the user belongs), Rule 2 (the request time must be between 09:00 and 18:00 on weekdays), and Rule 3 (approval from a superior is required when the approval amount is greater than 10,000).

[0031] The server can obtain the target data corresponding to the above three rules through the information acquisition module, and judge whether the above three rules are satisfied based on the obtained target data through the rule execution engine. Then, the server can determine the policy verification result according to the judgment results corresponding to the above three rules.

[0032] Through the second-layer ABAC verification, the target access policy corresponding to the target resource can be dynamically configured to achieve refined permission control in complex scenarios with high flexibility.

[0033] In S106, conflict detection processing is performed on the role verification result and the policy verification result.

[0034] In implementation, the role verification results may include verification passed and verification failed, and the policy verification results may also include verification passed and verification failed. Then, the server can determine that there is no conflict between the role verification results and the policy verification results when the role verification results and the policy verification results are the same, and determine that there is a conflict between the role verification results and the policy verification results when they are different.

[0035] In S108, when there is a conflict between the role verification result and the policy verification result, the access control verification result is determined according to the priority of the role verification result and the priority of the policy verification result.

[0036] In implementation, Figure 2 As shown, the multi-level access control architecture hiatus may include a third layer: a comprehensive strategy and conflict resolution layer.

[0037] The third layer can integrate the evaluation results of RBAC and ABAC and resolve the permission conflicts between the verification results based on the priority. For example, the server can define conflict resolution rules and handle conflicts according to the set conflict resolution rules. Specifically, the conflict resolution rules can be as follows: { "RBAC":{ "enabled": true, "priority": 1 }, "ABAC":{ "enabled": false, "priority": 2 } } That is, when the role verification result is "true" and the priority is 1, and the policy verification result is "false" and the priority is 2, since the role verification result conflicts with the policy verification result, the server can determine the access control verification result based on the role verification result with a higher priority.

[0038] In S110, a response result of the access request is determined according to the access control verification result.

[0039] In implementation, taking the access control verification results including "verification passed" and "verification failed" as an example, when the access control verification result is verification passed, the server can determine that the response result of the access request is access allowed; when the access control verification result is verification failed, the server can determine that the response result of the access request is access denied.

[0040] In addition, if Figure 2As shown, before performing role access verification and policy access verification, the server can also determine the verification method based on the resource identifier of the target resource through the permission policy library, where the verification method can include role access verification, policy access verification and combined verification (i.e., role access verification combined with policy access verification).

[0041] In this way, the adaptability and migration problems of multi-model integration can be effectively solved through the independent use and flexible integration of RBAC and ABAC: when used independently, the permission can be determined based on the role information through role access verification, which is suitable for simple scenarios. Dynamic policy evaluation can be performed through policy access verification, which is suitable for complex scenarios.

[0042] The flexible and integrated combined verification method provided in the embodiments of this specification can take into account the advantages of high access control verification efficiency of role access verification and high access control verification accuracy of policy access verification, and can meet the requirements of high efficiency and accuracy of access control verification in complex scenarios.

[0043] The embodiment of the present specification provides an access control method, which can receive an access request for a target resource, respond to the access request, perform a role access check, determine the role check result, and perform a policy access check to determine the policy check result, then perform conflict detection processing on the role check result and the policy check result, and in the case where there is a conflict between the role check result and the policy check result, determine the access control check result according to the priority of the role check result and the priority of the policy check result, and finally, determine the response result of the access request according to the access control check result. In this way, on the one hand, coarse-grained filtering can be performed through the role access check, that is, the role access check can be used to quickly determine whether the user has basic access rights, and at the same time, fine-grained filtering can also be performed through the policy access check, that is, the policy access check can be used to perform detailed verification to improve the accuracy of the access control check. On the other hand, in the case where there is a conflict between the role check result and the policy check result, the response result of the access request can be determined according to the priority of the role check result and the priority of the policy check result, that is, the conflict between the role access check and the policy access check can be resolved according to the priority-based conflict resolution mechanism, thereby improving the efficiency of the access control check.

[0044] In practical applications, in the above step S108, when there is a conflict between the role verification result and the policy verification result, there are various specific processing methods for determining the access control verification result according to the priority of the role verification result and the priority of the policy verification result. The following is an optional processing method, such as Figure 3 As shown, the processing may specifically include the following steps S1082 to S1084.

[0045] In S1082, when the access policy corresponding to the role verification result is different from the access policy corresponding to the policy verification result, it is determined that there is a conflict between the role verification result and the policy verification result.

[0046] The access policy may include allowing access and denying access.

[0047] In S1084, the access control verification result is determined according to the verification result with a higher priority among the role verification result and the policy verification result.

[0048] In implementation, for example, Figure 4 As shown, when the server receives an access request from the user, it can obtain the verification method corresponding to the target resource (that is, it can load the policy configuration). If the verification method corresponding to the target resource does not include role access verification, that is, RBAC is not enabled, the RBAC verification can be skipped. If the verification method corresponding to the target resource includes role access verification, the server can check the first role to which the user belongs and perform an RBAC rule matching verification, that is, match the first role to which the user belongs with the target role that has access to the target resource. If there is a match, it can be determined that the RBAC verification has passed. If there is no match, it can be determined that the RBAC verification has failed.

[0049] If the verification method corresponding to the target resource does not include policy access verification, that is, ABAC is not enabled, the ABAC verification can be skipped. If the verification method corresponding to the target resource includes policy access verification, the server can check the user's dynamic attributes, obtain the target data, and then determine whether the ABAC rules match based on the target attribute data and the target access policy. That is, when it is determined according to the target attribute data that the target access policy is satisfied, it can be determined that the ABAC rules match, and at this time it can be determined that the ABAC verification has passed. When it is determined according to the target attribute data that the target access policy is not satisfied, it can be determined that the ABAC rules do not match, and at this time it can be determined that the ABAC verification has failed.

[0050] When the verification method includes role access verification and policy access verification, priority determination can be performed based on the priority of the role verification result and the priority of the policy verification result to determine the access control verification result.

[0051] Specifically, if the priority of the role verification result is higher than the priority of the policy verification result, then the server can determine the access control verification result based on the role verification result. For example, when the priority of the role verification result is higher than the priority of the policy verification result, and the role verification result is a passed verification, the server can determine that the access control verification result is an access authorization based on the role verification result; when the priority of the role verification result is higher than the priority of the policy verification result, and the role verification result is a failed verification, the server can determine that the access control verification result is an access denial based on the role verification result.

[0052] If the priority of the policy verification result is higher than the priority of the role verification result, the server can determine the access control verification result based on the policy verification result. For example, if the priority of the policy verification result is higher than the priority of the role verification result, and the policy verification result is a verification pass, the server can determine the access control verification result as access authorization based on the policy verification result; if the priority of the policy verification result is higher than the priority of the role verification result, and the policy verification result is a verification failure, the server can determine the access control verification result as access denial based on the policy verification result.

[0053] In addition, when the priority of the role verification result and the priority of the policy verification result are the same, the server may send the role verification result and the policy verification result to a preset processor, and receive the access control verification result determined by the preset processor.

[0054] Alternatively, when the priority of the role verification result is the same as the priority of the policy verification result, the server may also determine the access control verification result according to the conflict resolution policy corresponding to the target resource.

[0055] For example, when the conflict resolution policy corresponding to the target resource is role verification priority, if the priority of the role verification result is the same as the priority of the policy verification result, then the server can determine the access control verification result based on the role verification result.

[0056] When the conflict resolution policy corresponding to the target resource is policy verification priority, if the priority of the role verification result is the same as the priority of the policy verification result, the server can determine the access control verification result based on the policy verification result.

[0057] In practical applications, in the above S104, the role access verification is performed, and the specific processing methods for determining the role verification result can be various. The following is an optional processing method, such as Figure 3 As shown, the process may specifically include the following steps S1042 to S1044.

[0058] In S1042, a first role to which the user belongs is obtained, and a first permission corresponding to the first role is determined according to a preset mapping relationship between roles and resource permissions.

[0059] The relationship between users and roles may be many-to-many, and the server may obtain each first role to which the user belongs, and determine the first permission corresponding to each first role according to a preset mapping relationship between roles and resource permissions.

[0060] In S1044, the operation permission corresponding to the target resource is obtained, and the first permission and the operation permission are matched to determine the role verification result.

[0061] In implementation, assuming that the first role of the user is "department manager", according to the preset mapping relationship between roles and resource permissions, the first permission corresponding to the first role may be: being able to perform an "approval" operation.

[0062] If the operation permissions corresponding to the target resource include permissions that match the first permission (ie, the "approval" operation), then it can be determined that the role verification result is access allowed (or verification passed, etc.).

[0063] In practical applications, in the above step S104, the policy access check is performed, and the specific processing methods for determining the policy check result can be various. The following is an optional processing method, such as Figure 3 As shown, the processing may specifically include the following steps S1046 to S1048.

[0064] In S1046, target attribute data for policy access verification is determined according to the target access policy corresponding to the target resource.

[0065] Among them, the target attribute data may include one or more of user attribute data, resource attribute data and environmental attribute data. The user attribute data may include attribute data such as the department to which the user belongs, the user's position, the user's role status, etc. The resource attribute data may include attribute data such as the resource status, the group to which the resource belongs, the sensitivity level of the resource, etc. The environmental attribute data may include attribute data such as time, location information, and device type.

[0066] In practical applications, in the above S1046, according to the target access policy, there are many ways to determine the specific processing of the target attribute data used for policy access verification. An optional processing method is provided below, which may specifically include the processing of the following step A1.

[0067] In A1, according to the data source information corresponding to each policy rule, the policy device corresponding to each policy rule is determined, and the target attribute data corresponding to each policy rule is obtained through the policy device.

[0068] In implementation, the server can obtain and process data through a modularly designed policy controller, where each policy controller can be composed of "logical expression + executor". The logical expression can be used to define trigger conditions and constraints, and the executor can be used to perform specific operations or decisions. The executor can be expanded independently.

[0069] The standardized interface enables the executor to dynamically bind different logical expressions to achieve flexible adaptation. For example, the server can use the Aviator logical expression engine for processing.

[0070] In addition, the server can also define interface standards, that is, it can provide a common API to allow external modules to quickly integrate new actuators. It can also introduce "configurable actuators", that is, the policy can be quickly deployed through configuration files or rule engines.

[0071] In this way, different policymakers may be configured for different data sources, so as to determine the policymaker corresponding to each policy rule based on the data source information corresponding to each policy rule, and obtain the target attribute data corresponding to each policy rule.

[0072] The policy controller can transform data formats from different data sources into preset logical expressions, which can improve the scalability of the system.

[0073] In S1048, according to the verification logic corresponding to the target access policy, a policy access verification is performed on the target attribute data to determine the policy verification result.

[0074] In practical applications, in the above step S1048, according to the verification logic corresponding to the target access policy, the target attribute data is subjected to policy access verification. There are many ways to determine the specific processing results of the policy verification. An optional processing method is provided below, which may specifically include the processing of the following steps B1~B2.

[0075] In B1, multiple policy rules corresponding to the target access policy are obtained from the preset rule library, and according to the verification logic corresponding to each policy rule, it is determined whether the target attribute data satisfies the policy rule, and the verification result corresponding to each policy rule is obtained.

[0076] In implementation, the server can determine whether the target attribute data satisfies the policy rule through the policy device corresponding to each policy rule, and obtain the verification result corresponding to each policy rule. For example, the server can bring the target attribute data into the verification logic expression corresponding to the policy rule to obtain the verification result corresponding to each policy rule.

[0077] In B2, the policy verification result is determined according to the combined rule verification logic corresponding to the target access policy and the verification result corresponding to each policy rule.

[0078] The combined verification logic may include multiple logics, such as "and", "or", "not", etc. For example, the multiple policy rules corresponding to the target access policy may include rule 1 and rule 2, where rule 1: condition 1 AND condition 2 AND (condition 3 OR condition 4), rule 2: condition 2 OR condition 5 OR condition 7. The combined rule verification logic corresponding to the target access policy may be: rule 1 AND rule 2.

[0079] In practice, in a multi-policy system, policy rules may conflict with each other (e.g. overlapping conditions, unclear priorities, mutually exclusive results, etc.). If conflicts between policy rules are resolved through static priority settings or manual troubleshooting, there will be a lack of dynamic adaptability and it will be difficult to cope with complex scenarios.

[0080] For example, suppose a company configures the following policy rules for policy access control for a resource: Policy Rule R1: Regular employees can access non-confidential documents, but only during working hours.

[0081] Policy rule R2: Management can access all documents, but access to confidential documents requires being inside the company network.

[0082] Policy rule R3: Outsourced personnel can only access public resources.

[0083] Policy rule R4: Access restrictions may be relaxed if certain special conditions are met (such as emergency situations).

[0084] The following conflicts may exist between the above four policy rules: 1. Conflict of time conditions: Ordinary employees can only access during working hours, but management has no time restrictions. Then, when the restrictions are relaxed in an emergency, the time rules may become invalid.

[0085] For example: When a regular employee attempts to access during non-business hours, should that be allowed because of an emergency situation? 2. Conflict between roles and resource types: Outsourced personnel can only access public resources, while in an emergency, all users are allowed to access non-deletable resources, which may lead to conflicts between rules.

[0086] For example: When outsourced personnel access non-public resources in an emergency, do emergency rules take precedence? 3. Conflict between resource type and access environment: Management can access confidential documents, but only within the company network. If management attempts to access through an external network and an emergency situation is also met, the rules may conflict.

[0087] For example: In an emergency, can management access confidential documents on an external network? The conflicts between the above policy rules can be resolved by combining policies. For example, the combined rule verification logic corresponding to the access policy can be configured as: R4 || (R1&&R2&&R3).

[0088] In this way, by combining multiple policy rules, we can not only solve the conflict between policy rules, but also meet the permission determination in complex scenarios. In addition, to improve the simplicity and scalability of policy rule definitions, the definition and combination of policy rules can use the syntax supported by the Aviator expression engine.

[0089] In actual applications, different query feedback results can be generated according to different query level requirements. There are many specific processing methods for generating query feedback results. The following is an optional processing method, such as Figure 5 As shown, the processing may specifically include the following steps S502 to S504.

[0090] In S502, when the response result is access denial, the reason for the access control verification failure is determined according to the access control verification result.

[0091] In implementation, when the response result is access denied, the server can determine the cause of access control verification failure by disassembling the combined rule verification logic and recursively failing key nodes.

[0092] For example, assuming that the combined rule verification logic is (Rule1&&Rule2) || Rule3, the server can decompose it into two sub-expressions, Rule1&&Rule2 and Rule3, at the same layer according to the execution order of the expression, and solve each sub-expression separately. Then, the server can calculate each sub-expression layer by layer, and continue to recurse if it fails, find the final impact node, and determine the reason for the access control verification failure.

[0093] In this way, the server can accurately locate the specific strategy or condition that caused the failure by disassembling the combination rule verification logic and recursively checking the key nodes of failure, and provide detailed reasons for the failure.

[0094] In addition, the server can determine the cause of access control verification failure based on the access control verification results through a multi-level result expression mechanism, where the multi-level result expression mechanism can include single policy results and combined policy results. The single policy result can be the verification result corresponding to each policy rule, and diagnosis and tracking can be performed based on the single policy result. The combined policy result can be a summary result of the single policy results, and the combined policy result can be generated through a logical expression.

[0095] In S504, the query feedback result is determined according to the query level requirement of the user and the reason for the access control verification failure, and the query feedback result is fed back.

[0096] Among them, query level requirements may include basic level requirements, intermediate level requirements and high-level requirements. Basic level requirements may be simple execution status, such as execution success or execution failure, etc., intermediate level requirements may be access control verification results, such as whether the target access control policy is met, etc., and high-level requirements may be detailed descriptions and analyses of the access control verification results.

[0097] During implementation, the server can adjust the level and detail of the returned results according to the user's query level requirements. When the user's query level requirements are basic level requirements or intermediate level requirements, the server can determine the query feedback results through a simplified mode according to the reason for the failure of the access control verification, that is, the query feedback results can include summary information, such as execution status, etc.; when the user's query level requirements are high-level requirements, the server can determine the query feedback results through a detailed mode according to the reason for the failure of the access control verification, that is, the query feedback results can include the execution details and combined logical paths of each policy rule.

[0098] In addition, the server can return structured information (i.e., query feedback results) in a preset format such as JSON or XML, which can support automated parsing and visualization.

[0099] For example, the query feedback result of feedback can be: { "strategyResults": [ {"strategyName": "Strategy1", "status": "success", "details": {...}}, {"strategyName": "Strategy2", "status": "failed", "error": {...}} ], "combinedResult": { "status": "success", "summary": "Strategy1 executed successfully while Strategy2 failed due to threshold breach." } } In this way, on the one hand, when the access control verification fails, the specific policy or condition causing the failure can be accurately located according to the access control verification result, and the cause of the access control verification failure can be determined.

[0100] On the other hand, the query feedback results can also be improved according to the user's query level requirements, such as failed attribute conditions (such as time, geographic location, user status, etc.), so that administrators can quickly optimize the verification strategy.

[0101] like Figure 6 As shown, the access control verification process can be as follows: 1. Access and analysis of user requests (1) Receiving requests: The access controller receives the user's access request for the target resource (such as accessing or operating the target resource, etc.).

[0102] (2) Parsing request: a. Extract the user ID (userID), operation type (operationType), and resource ID (resourceID) of the target resource.

[0103] B. Based on the system configuration, determine whether RBAC and ABAC are enabled and their respective priorities.

[0104] (3) Request forwarding: The access controller determines the verification order based on the switch configuration and priority and forwards the request to the role permission verification module and / or policy verification module.

[0105] 2. RBAC and ABAC switch control and priority judgment (1) Switch inspection: a. RBAC enable switch: determines whether to enable role permission verification.

[0106] b. ABAC enable switch: determines whether to enable dynamic policy verification.

[0107] c. Priority determination: c1. Determine the priority of RBAC and ABAC based on system configuration (for example: RBAC priority > ABAC, ABAC priority > RBAC, etc.).

[0108] c2. If only one of RBAC and ABAC is enabled, the corresponding verification module is directly executed. If neither RBAC nor ABAC is enabled, the access request is rejected.

[0109] c3. If both are enabled, they are executed step by step according to the priority configuration and the conflict is resolved.

[0110] 3. Role-Based Access Control (RBAC) 1. Role authority loading: a. Load the preset mapping relationship between roles and resource permissions from the role permission library.

[0111] b. Role authority judgment: Determine whether the first role to which the user belongs has the authority to operate the target resource.

[0112] c. Result output: Output the role verification result (pass / reject).

[0113] 4. Policy loading and dynamic verification (ABAC) a. Policy loading: The policy calculation module loads the basic policy and combined policy, namely the target access policy, from the rule base.

[0114] b. Information acquisition and dynamic attribute loading: Dynamically load target attribute data from external systems or caches: user attribute data (such as department, position, role status, etc.), resource attribute data (such as resource status, group, sensitivity level, etc.), and environmental attribute data (such as time, geographic location, device type, etc.).

[0115] c. Policy execution and evaluation: Call the rule execution engine to gradually parse the combined policy logic (such as "and", "or", "not"). Combined with dynamic attributes, verify whether the permission requirements are met.

[0116] d. Result output: Output the policy verification result (pass / reject).

[0117] 5. RBAC and ABAC conflict resolution mechanism a. Conflict judgment: If the RBAC and ABAC verification results are consistent, they are returned directly. If the RBAC and ABAC verification results are inconsistent (for example: RBAC passes but ABAC rejects), the conflict resolution mechanism is triggered.

[0118] b. Conflict resolution: Conflicts are handled according to the priority configuration: If RBAC takes precedence, the access control verification result is based on the role verification result. If ABAC takes precedence, the access control result is based on the policy verification result.

[0119] d. Policy combination: Generate access control verification results based on the preset combination rules corresponding to the target access policy (such as RBAC must pass and ABAC must pass).

[0120] 6. Summary and return of permission verification results a. Result summary: The access controller combines the RBAC and ABAC verification results to generate the final permission decision (i.e., response result): allow access (i.e., the user passes the permission verification and performs the operation) or deny access (i.e., the user fails the permission verification) b. Return the response result to the requester.

[0121] c. Record detailed verification logs, including RBAC verification results, ABAC verification results, conflict resolution process, and priority judgment process.

[0122] d. Feedback query feedback results based on the user's query level requirements, that is, provide the user with specific rejection reasons and verification logs, etc.

[0123] like Figure 7 As shown, the embodiment of this specification also provides a specific scenario instantiation description: 1. User role: User A has the role of "department manager".

[0124] 2. Request operation: User A requests to access resource Resource_001 on Saturday and perform the "Approve" operation.

[0125] 3. Verification requirements: role access verification and policy access verification, where role access verification is: Only the "department manager" and "project leader" roles can perform the "approval" operation. The target access policy corresponding to the policy access check is a combination of the following three policy rules: Rule 1: The resource must belong to the user's department.

[0126] Rule 2: Request time must be between 09:00 - 18:00 on weekdays.

[0127] Rule 3: When the approval amount is greater than 10,000, approval from superiors is required.

[0128] 4. Priority configuration: ABAC priority, that is, the verification result of the ABAC strategy is used first.

[0129] 5. Conflict resolution mechanism: If the RBAC and ABAC results conflict, the final access control verification result is determined by the policy verification result.

[0130] The overall instantiation configuration and workflow can be as follows: The configuration list can be shown in Table 1 below.

[0131] Table 1

[0132] The instantiation access control process can be as follows: 1. User submits access request User A submits a permission verification request to the access controller (`AccessController`), which contains the following information: `userID`: user A, `operationType`: approval, `resourceID`: Resource_001.

[0133] 2. Parsing Request The access controller parses the access request, reads the permission configuration, including role-based access control (RBAC) and attribute-based access control (ABAC), and determines that ABAC has priority.

[0134] 3. Calling the strategy calculation module The access controller calls the policy calculation module (`PolicyModule`) to perform ABAC permission verification. The policy calculation module loads predefined policy rules (i.e., rule 1, rule 2, and rule 3).

[0135] 4. Loading dynamic properties The policy calculation module calls the information acquisition module (`InfoModule`) (i.e., the policy controller) to load the target attribute data related to the request. For example, the acquired target attribute data may include user attributes (the department to which user A belongs) and resource attributes (the department to which Resource_001 belongs). The information acquisition module may return the acquired target attribute data to the policy calculation module.

[0136] 5. Verify policy rules The policy calculation module calls the rule execution engine (`RuleEngine`) to check the policy rules one by one: a. Rule 1: Department matches, verification passes.

[0137] b. Rule 2: The current time is 10:00 on Saturday, and verification fails.

[0138] The rule execution engine returns the policy calculation result: access denied.

[0139] 6. Record ABAC results The access controller records the ABAC check result as access denied.

[0140] 7. Role permission verification (conditional branch) a. If the ABAC check result is that access is allowed, then the access controller can call the role permission check module (`RoleModule`) to perform RBAC check.

[0141] Verify whether user A has the "department manager" role. Since user A has the "department manager" role, the RBAC verification result can be access allowed, and the role verification result can be returned to the access controller.

[0142] b. If the ABAC check result is access denied, skip the RBAC check directly.

[0143] 8. Final result determination Based on the ABAC priority, the access controller determines the final result. In this case: Since the ABAC verification result is access denied, and the RBAC verification result is access allowed, and since ABAC has a higher priority, the final permission verification result (that is, the access control verification result) is access denied.

[0144] 9. Return access results The access controller may determine the access result according to the access control verification result (ie, access denied), and return the access result to user A.

[0145] In this way, the combined verification mechanism of role access verification and policy access verification solves the limitations of single permission verification. And by building a conflict resolution mechanism with priority, the seamless integration of role access verification and policy access verification can be achieved, which can meet the flexibility and accuracy of permission management in complex scenarios.

[0146] In addition, through the combination verification of policy rules, it can support flexible combination and precise positioning of policies, and can cope with multi-dimensional scenarios. Among them, through logical operators (such as AND / OR / NOT), it supports flexible combination of multiple policy rules, can process permission rules of multiple dimensions at the same time, and can help accurately locate policy rules that fail verification.

[0147] In addition, through modular architecture and flexible policy configuration, it can support seamless migration of RBAC and ABAC verification logic in different business environments. That is, it can adapt to new scenarios without large-scale reconstruction, and can meet the rapid deployment and expansion needs of enterprises for permission verification.

[0148] In summary, modular policy design, dynamic attribute loading, policy conflict handling and priority control are the core to improve the flexibility, performance and security of access control. Its policy reusability, dynamic adaptability, fine-grained control and high scalability are suitable for enterprise permission management, cloud service platform permission distribution, and access control in complex scenarios such as cross-system.

[0149] The following is a detailed description of specific application areas: 1. Enterprise information system authority management Various management systems within the enterprise need to control the permissions of employees in different positions, departments, and roles: For example, specific application scenarios may include: (1) Human Resources Management System: Control employees’ access rights to personal information, performance reports, and recruitment data.

[0150] (2) Financial system: Permission determination is performed based on user roles (such as financial manager, ordinary employee) and dynamic attributes (such as review status, time period).

[0151] (3) Customer Relationship Management (CRM): Assign permissions based on sales department groups and customer regions.

[0152] The above access control method can provide enterprises with fine-grained permission management based on organizational structure, department, and role. It can also provide enterprises with dynamic adjustment of permissions to adapt to changes in business scenarios (such as department reorganization and employee transfer).

[0153] 2. Cloud service platform and multi-tenant system In cloud computing and multi-tenant scenarios, the management of users and resources needs to take into account dynamic attributes and complex tenant isolation.

[0154] For example, specific application scenarios may include: (1) Public cloud platform: provides independent resource access rights to different tenants while supporting cross-tenant collaboration.

[0155] (2) Private cloud / hybrid cloud: Dynamically adjust permissions based on the user's access source (such as IP, device), tenant identity, and role.

[0156] The above access control method can achieve strong isolation in a multi-tenant environment while supporting flexible cross-tenant access policies. And by dynamically allocating resource access rights, resource utilization can be optimized.

[0157] The above access control method has the advantages of high flexibility, dynamic adaptability and high efficiency, and is applicable to a variety of fields from enterprise information management to industrial Internet of Things. This method can not only solve the shortcomings of the existing access control mechanism, but also meet the needs of complex application scenarios through dynamic loading and flexible combination strategies, and has broad market prospects and application value.

[0158] The embodiment of the present specification provides an access control method, which can receive an access request for a target resource, respond to the access request, perform a role access check, determine the role check result, and perform a policy access check to determine the policy check result, then perform conflict detection processing on the role check result and the policy check result, and in the case where there is a conflict between the role check result and the policy check result, determine the access control check result according to the priority of the role check result and the priority of the policy check result, and finally, determine the response result of the access request according to the access control check result. In this way, on the one hand, coarse-grained filtering can be performed through the role access check, that is, the role access check can be used to quickly determine whether the user has basic access rights, and at the same time, fine-grained filtering can also be performed through the policy access check, that is, the policy access check can be used to perform detailed verification to improve the accuracy of the access control check. On the other hand, in the case where there is a conflict between the role check result and the policy check result, the response result of the access request can be determined according to the priority of the role check result and the priority of the policy check result, that is, the conflict between the role access check and the policy access check can be resolved according to the priority-based conflict resolution mechanism, thereby improving the efficiency of the access control check.

[0159] In another embodiment, the above is an access control method provided in the embodiment of this specification. Based on the same idea, the embodiment of this specification also provides an access control device, such as Figure 8 shown.

[0160] The access control device comprises: a request receiving module 801, a verification module 802, a conflict detection module 803, a first determination module 804 and a second determination module 805, wherein: The request receiving module 801 is used to receive an access request for a target resource; A verification module 802 is used to perform role access verification in response to the access request, determine the role verification result, and perform policy access verification to determine the policy verification result; A conflict detection module 803 is used to perform conflict detection processing on the role verification result and the strategy verification result; A first determination module 804 is used to determine the access control verification result according to the priority of the role verification result and the priority of the policy verification result when there is a conflict between the role verification result and the policy verification result; The second determination module 805 is used to determine the response result of the access request according to the access control verification result.

[0161] In the embodiment of this specification, the first determining module 804 is used to: In the case where the access policy corresponding to the role verification result is different from the access policy corresponding to the policy verification result, determining that there is a conflict between the role verification result and the policy verification result, the access policy including allowing access and denying access; The access control verification result is determined according to the verification result with a higher priority among the role verification result and the policy verification result.

[0162] In the embodiment of this specification, the verification module 802 is used to: Obtaining a first role to which the user belongs, and determining a first permission corresponding to the first role according to a preset mapping relationship between roles and resource permissions; The operation permission corresponding to the target resource is obtained, and the first permission and the operation permission are matched to determine the role verification result.

[0163] In the embodiment of this specification, the verification module 802 is used to: Determining target attribute data for policy access verification according to a target access policy corresponding to the target resource, wherein the target attribute data includes one or more of user attribute data, resource attribute data, and environment attribute data; According to the verification logic corresponding to the target access policy, a policy access verification is performed on the target attribute data to determine the policy verification result.

[0164] In the embodiment of this specification, the verification module 802 is used to: Acquire multiple policy rules corresponding to the target access policy from a preset rule library, and determine whether the target attribute data satisfies the policy rule according to the verification logic corresponding to each policy rule, and obtain the verification result corresponding to each policy rule; The policy verification result is determined according to the combined rule verification logic corresponding to the target access policy and the verification result corresponding to each of the policy rules.

[0165] In the embodiment of this specification, the verification module 802 is used to: According to the data source information corresponding to each of the policy rules, a policy device corresponding to each of the policy rules is determined, and through the policy device, target attribute data corresponding to each of the policy rules is acquired.

[0166] In the embodiment of this specification, the verification module 802 is used to: The target attribute data is brought into the verification logic expression corresponding to the policy rule to obtain the verification result corresponding to each policy rule.

[0167] In the embodiment of this specification, the device further includes: A cause determination module, used to determine the cause of access control check failure according to the access control check result when the response result is access denied; The result feedback module is used to determine the query feedback result according to the query level requirements of the user and the reason for the failure of the access control verification, and to feed back the query feedback result.

[0168] The embodiment of the present specification provides an access control device, which can receive an access request for a target resource, and in response to the access request, perform a role access check to determine the role check result, and perform a policy access check to determine the policy check result, and then perform conflict detection processing on the role check result and the policy check result, and in the case where there is a conflict between the role check result and the policy check result, determine the access control check result according to the priority of the role check result and the priority of the policy check result, and finally, determine the response result of the access request according to the access control check result. In this way, on the one hand, coarse-grained filtering can be performed through the role access check, that is, the role access check can be used to quickly determine whether the user has basic access rights, and at the same time, fine-grained filtering can also be performed through the policy access check, that is, the policy access check can be used to perform detailed verification to improve the accuracy of the access control check. On the other hand, in the case where there is a conflict between the role check result and the policy check result, the response result of the access request can be determined according to the priority of the role check result and the priority of the policy check result, that is, the conflict between the role access check and the policy access check can be resolved according to the priority-based conflict resolution mechanism, and the efficiency of the access control check can be improved.

[0169] In another embodiment, based on the same idea, the embodiment of this specification also provides an access control device, such as Fig. 9 shown.

[0170] The access control device may have relatively large differences due to different configurations or performances, and may include one or more processors 901 and memory 902, and the memory 902 may store one or more storage applications or data. Among them, the memory 902 may be a short-term storage or a persistent storage. The application stored in the memory 902 may include one or more modules (not shown in the figure), and each module may include a series of computer executable instructions in the access control device. Furthermore, the processor 901 may be configured to communicate with the memory 902 to execute a series of computer executable instructions in the memory 902 on the access control device. The access control device may also include one or more power supplies 903, one or more wired or wireless network interfaces 904, one or more input and output interfaces 906, and one or more keyboards 906.

[0171] Specifically in this embodiment, the access control device includes a memory and one or more programs, wherein the one or more programs are stored in the memory, and the one or more programs may include one or more modules, and each module may include a series of computer executable instructions in the access control device, and the one or more programs are configured to be executed by one or more processors, including computer executable instructions for performing the following: receiving an access request for a target resource; In response to the access request, performing a role access check and determining a role check result, and performing a policy access check and determining a policy check result; Performing conflict detection processing on the role verification result and the strategy verification result; In the event that there is a conflict between the role verification result and the policy verification result, determining the access control verification result according to the priority of the role verification result and the priority of the policy verification result; A response result of the access request is determined according to the access control verification result.

[0172] Optionally, when there is a conflict between the role verification result and the policy verification result, determining the access control verification result according to the priority of the role verification result and the priority of the policy verification result includes: In the case where the access policy corresponding to the role verification result is different from the access policy corresponding to the policy verification result, determining that there is a conflict between the role verification result and the policy verification result, the access policy including allowing access and denying access; The access control verification result is determined according to the verification result with a higher priority among the role verification result and the policy verification result.

[0173] Optionally, performing role access verification and determining a role verification result includes: Obtaining a first role to which the user belongs, and determining a first permission corresponding to the first role according to a preset mapping relationship between roles and resource permissions; The operation permission corresponding to the target resource is obtained, and the first permission and the operation permission are matched to determine the role verification result.

[0174] Optionally, the performing policy access verification and determining a policy verification result includes: Determining target attribute data for policy access verification according to a target access policy corresponding to the target resource, wherein the target attribute data includes one or more of user attribute data, resource attribute data, and environment attribute data; According to the verification logic corresponding to the target access policy, a policy access verification is performed on the target attribute data to determine the policy verification result.

[0175] Optionally, performing a policy access check on the target attribute data according to a check logic corresponding to the target access policy and determining the policy check result includes: Acquire multiple policy rules corresponding to the target access policy from a preset rule library, and determine whether the target attribute data satisfies the policy rule according to the verification logic corresponding to each policy rule, and obtain the verification result corresponding to each policy rule; The policy verification result is determined according to the combined rule verification logic corresponding to the target access policy and the verification result corresponding to each of the policy rules.

[0176] Optionally, determining target attribute data for policy access verification according to the target access policy includes: According to the data source information corresponding to each of the policy rules, a policy device corresponding to each of the policy rules is determined, and through the policy device, target attribute data corresponding to each of the policy rules is acquired.

[0177] Optionally, judging whether the target attribute data satisfies the policy rule according to the verification logic corresponding to each policy rule, and obtaining the verification result corresponding to each policy rule includes: The target attribute data is brought into the verification logic expression corresponding to the policy rule to obtain the verification result corresponding to each policy rule.

[0178] Optionally, the method further comprises: In the case where the response result is access denial, determining the reason for the access control verification failure according to the access control verification result; According to the user's query level requirements and the reasons for the access control verification failure, the query feedback result is determined and fed back.

[0179] The embodiment of the present specification provides an access control device, which can receive an access request for a target resource, and in response to the access request, perform a role access check to determine the role check result, and perform a policy access check to determine the policy check result, and then perform conflict detection processing on the role check result and the policy check result, and in the case where there is a conflict between the role check result and the policy check result, determine the access control check result according to the priority of the role check result and the priority of the policy check result, and finally, determine the response result of the access request according to the access control check result. In this way, on the one hand, coarse-grained filtering can be performed through the role access check, that is, the role access check can be used to quickly determine whether the user has basic access rights, and at the same time, fine-grained filtering can also be performed through the policy access check, that is, the policy access check can be used to perform detailed verification to improve the accuracy of the access control check. On the other hand, in the case where there is a conflict between the role check result and the policy check result, the response result of the access request can be determined according to the priority of the role check result and the priority of the policy check result, that is, the conflict between the role access check and the policy access check can be resolved according to the priority-based conflict resolution mechanism, and the efficiency of the access control check can be improved.

[0180] Furthermore, based on the above Figures 1 to 7 In one embodiment, the present specification further provides a storage medium for storing computer executable instruction information. In a specific embodiment, the storage medium may be a USB flash drive, an optical disk, a hard disk, etc. When the computer executable instruction information stored in the storage medium is executed by the processor, the following process can be implemented: receiving an access request for a target resource; In response to the access request, performing a role access check and determining a role check result, and performing a policy access check and determining a policy check result; Performing conflict detection processing on the role verification result and the strategy verification result; In the event that there is a conflict between the role verification result and the policy verification result, determining the access control verification result according to the priority of the role verification result and the priority of the policy verification result; A response result of the access request is determined according to the access control verification result.

[0181] Each embodiment in this specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the above-mentioned storage medium embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

[0182] The embodiment of the present specification provides a computer-readable storage medium, which can receive an access request for a target resource, and in response to the access request, perform a role access check to determine the role check result, and perform a policy access check to determine the policy check result, and then perform conflict detection processing on the role check result and the policy check result, and in the case where there is a conflict between the role check result and the policy check result, determine the access control check result according to the priority of the role check result and the priority of the policy check result, and finally, determine the response result of the access request according to the access control check result. In this way, on the one hand, coarse-grained filtering can be performed through the role access check, that is, the role access check can be used to quickly determine whether the user has basic access rights, and at the same time, fine-grained filtering can also be performed through the policy access check, that is, the policy access check can be used to perform detailed verification to improve the accuracy of the access control check. On the other hand, in the case where there is a conflict between the role check result and the policy check result, the response result of the access request can be determined according to the priority of the role check result and the priority of the policy check result, that is, the conflict between the role access check and the policy access check can be resolved according to the priority-based conflict resolution mechanism, and the efficiency of the access control check can be improved.

[0183] Furthermore, based on the above Figures 1 to 7 In one or more embodiments of the present specification, a computer program product is provided, including a computer program. When the computer program in the computer program product is executed by a processor, the following process can be implemented: receiving an access request for a target resource; In response to the access request, performing a role access check and determining a role check result, and performing a policy access check and determining a policy check result; Performing conflict detection processing on the role verification result and the strategy verification result; In the event that there is a conflict between the role verification result and the policy verification result, determining the access control verification result according to the priority of the role verification result and the priority of the policy verification result; A response result of the access request is determined according to the access control verification result.

[0184] Each embodiment in this specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the above-mentioned computer program product embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

[0185] The embodiment of the present specification provides a computer program product, which can receive an access request for a target resource, and in response to the access request, perform a role access check to determine the role check result, and perform a policy access check to determine the policy check result, and then perform conflict detection processing on the role check result and the policy check result, and in the case where there is a conflict between the role check result and the policy check result, determine the access control check result according to the priority of the role check result and the priority of the policy check result, and finally, determine the response result of the access request according to the access control check result. In this way, on the one hand, coarse-grained filtering can be performed through the role access check, that is, the role access check can be used to quickly determine whether the user has basic access rights, and at the same time, fine-grained filtering can also be performed through the policy access check, that is, the policy access check can be used to perform detailed verification to improve the accuracy of the access control check. On the other hand, in the case where there is a conflict between the role check result and the policy check result, the response result of the access request can be determined according to the priority of the role check result and the priority of the policy check result, that is, the conflict between the role access check and the policy access check can be resolved according to the priority-based conflict resolution mechanism, and the efficiency of the access control check can be improved.

[0186] The above is a description of a specific embodiment of the specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in an order different from that in the embodiments and still achieve the desired results. In addition, the processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0187] In the 1990s, it was very clear whether the improvement of a technology was hardware improvement (for example, improvement of the circuit structure of diodes, transistors, switches, etc.) or software improvement (improvement of the method flow). However, with the development of technology, many improvements of the method flow today can be regarded as direct improvements of the hardware circuit structure. Designers almost always obtain the corresponding hardware circuit structure by programming the improved method flow into the hardware circuit. Therefore, it cannot be said that the improvement of a method flow cannot be implemented with a hardware entity module. For example, a programmable logic device (PLD) (such as a field programmable gate array (FPGA)) is such an integrated circuit whose logical function is determined by the user's programming of the device. Designers can "integrate" a digital system on a PLD by programming themselves, without having to ask chip manufacturers to design and make dedicated integrated circuit chips. Moreover, nowadays, instead of manually making integrated circuit chips, this kind of programming is mostly implemented by "logic compiler" software, which is similar to the software compiler used when developing and writing programs, and the original code before compilation must also be written in a specific programming language, which is called hardware description language (HDL). There is not only one kind of HDL, but many kinds, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc. The most commonly used ones are VHDL (Very-High-Speed ​​Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should also know that it is only necessary to program the method flow slightly in the above-mentioned hardware description languages ​​and program it into the integrated circuit, and then it is easy to obtain the hardware circuit that implements the logic method flow.

[0188] The controller may be implemented in any suitable manner, for example, the controller may take the form of a microprocessor or processor and a computer-readable medium storing a computer-readable program code (e.g., software or firmware) executable by the (micro)processor, a logic gate, a switch, an application-specific integrated circuit (ASIC), a programmable logic controller, and an embedded microcontroller, examples of which include but are not limited to the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicone Labs C8051F320, and the memory controller may also be implemented as part of the control logic of the memory. It is also known to those skilled in the art that, in addition to implementing the controller in a purely computer-readable program code manner, the controller may be implemented in the form of a logic gate, a switch, an application-specific integrated circuit, a programmable logic controller, and an embedded microcontroller by logically programming the method steps. Therefore, such a controller may be considered as a hardware component, and the devices for implementing various functions included therein may also be considered as structures within the hardware component. Or even, the devices for implementing various functions may be considered as both software modules for implementing the method and structures within the hardware component.

[0189] For the convenience of description, the above devices are described in terms of functions and are divided into various units. Of course, when implementing one or more embodiments of this specification, the functions of each unit can be implemented in the same or multiple software and / or hardware.

[0190] Those skilled in the art will appreciate that the embodiments of this specification may be provided as methods, systems, or computer program products. Therefore, one or more embodiments of this specification may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, one or more embodiments of this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program codes.

[0191] The embodiments of this specification are described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of this specification. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable access control device to generate a machine, so that the instructions executed by the processor of the computer or other programmable access control device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0192] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.

[0193] Those skilled in the art will appreciate that the embodiments of this specification may be provided as methods, systems or computer program products. Therefore, one or more embodiments of this specification may be in the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware. Furthermore, one or more embodiments of this specification may be in the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0194] Each embodiment in this specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

[0195] The above description is only an embodiment of the present specification and is not intended to limit the present specification. For those skilled in the art, the present specification may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present specification shall be included in the scope of the claims of the present specification.

Claims

1. An access control method, the method comprising: receiving an access request for a target resource; In response to the access request, performing a role access check and determining a role check result, and performing a policy access check and determining a policy check result; Performing conflict detection processing on the role verification result and the strategy verification result; In the event that there is a conflict between the role verification result and the policy verification result, determining the access control verification result according to the priority of the role verification result and the priority of the policy verification result; A response result of the access request is determined according to the access control verification result.

2. The method according to claim 1, wherein when there is a conflict between the role verification result and the policy verification result, determining the access control verification result according to the priority of the role verification result and the priority of the policy verification result comprises: In the case where the access policy corresponding to the role verification result is different from the access policy corresponding to the policy verification result, determining that there is a conflict between the role verification result and the policy verification result, the access policy including allowing access and denying access; The access control verification result is determined according to the verification result with a higher priority among the role verification result and the policy verification result.

3. The method according to claim 1, wherein performing role access verification and determining a role verification result comprises: Obtaining a first role to which the user belongs, and determining a first permission corresponding to the first role according to a preset mapping relationship between roles and resource permissions; The operation permission corresponding to the target resource is obtained, and the first permission and the operation permission are matched to determine the role verification result.

4. The method according to claim 1, wherein the performing of the policy access verification and determining the policy verification result comprises: Determining target attribute data for policy access verification according to a target access policy corresponding to the target resource, wherein the target attribute data includes one or more of user attribute data, resource attribute data, and environment attribute data; According to the verification logic corresponding to the target access policy, a policy access verification is performed on the target attribute data to determine the policy verification result.

5. The method according to claim 4, wherein the step of performing a policy access check on the target attribute data according to the check logic corresponding to the target access policy and determining the policy check result comprises: Acquire multiple policy rules corresponding to the target access policy from a preset rule library, and determine whether the target attribute data satisfies the policy rule according to the verification logic corresponding to each policy rule, and obtain the verification result corresponding to each policy rule; The policy verification result is determined according to the combined rule verification logic corresponding to the target access policy and the verification result corresponding to each of the policy rules.

6. The method according to claim 5, wherein determining target attribute data for policy access verification according to the target access policy comprises: According to the data source information corresponding to each of the policy rules, a policy device corresponding to each of the policy rules is determined, and through the policy device, target attribute data corresponding to each of the policy rules is acquired.

7. The method according to claim 6, wherein judging whether the target attribute data satisfies the policy rule according to the verification logic corresponding to each policy rule and obtaining the verification result corresponding to each policy rule comprises: The target attribute data is brought into the verification logic expression corresponding to the policy rule to obtain the verification result corresponding to each policy rule.

8. The method according to claim 3, further comprising: In the case where the response result is access denial, determining the reason for the access control verification failure according to the access control verification result; According to the user's query level requirements and the reasons for the access control verification failure, the query feedback result is determined and fed back.

9. An access control device, characterized in that: The method comprises a processor and a memory, wherein the memory stores a program or instruction that can be run on the processor, and when the program or instruction is executed by the processor, the steps of the access control method according to any one of claims 1 to 8 are implemented.

10. A readable storage medium, characterized in that: The readable storage medium stores a program or an instruction, and when the program or the instruction is executed by the processor, the steps of the access control method according to any one of claims 1 to 8 are implemented.

11. A computer program product, characterized in that The invention comprises a computer program, which implements the steps of the access control method according to any one of claims 1 to 8 when executed by a processor.

Citation Information

Cited By

  • Data authority control strategy verification system and control method thereof

    CN120763977A

  • Data use control strategy determination method and device, medium, equipment and product

    CN121144566A