User identity authentication method, rights management system, medium and program product
Through multi-dimensional identity authentication and blockchain recording of access history, the problem of insufficient security of user identity authentication is solved, efficient prevention of unauthorized access and data leakage is achieved, and the access experience and system stability are improved.
Patent Information
- Application Number
- CN202510209089.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-25
- Publication Date
- 2025-09-09
- Estimated Expiration
- 2045-02-25
AI Technical Summary
Existing user identity authentication methods are not secure enough in the face of complex network attacks, resulting in high risks of unauthorized access and data leakage, and traditional authentication methods affect the access experience.
A multi-dimensional identity authentication method is adopted to determine the effective access rights by identifying the access identity credential characteristics and content characteristics, and the access history is recorded on the blockchain to achieve decentralized design to improve system stability.
Effectively prevent unauthorized access and data leakage, improve access experience, ensure data integrity and consistency, and enhance system stability and reliability.
Smart Images

Figure CN120124027B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of access rights management, and in particular to a user identity authentication method, an access rights management system, a medium, and a program product. Background Art
[0002] In the current internet environment, unauthorized access and data leaks are frequent, causing significant losses to businesses and individual users. Unauthorized access not only leads to the leakage of sensitive information but can also trigger a series of chain reactions, such as system crashes and data tampering, seriously impacting the normal operations of businesses and the security of users' personal information. Therefore, improving the security of user identity authentication and effectively preventing the risks of unauthorized access and data leaks has become a pressing issue.
[0003] Traditional user authentication methods often rely on a single factor, such as a username and password. While this simple authentication method can identify users to a certain extent, it is no longer secure enough in the face of increasingly sophisticated cyberattacks. To improve security, complex password policies and multiple authentication steps are often employed. While this enhances security to a certain extent, it also brings inconvenience to visitors and reduces the access experience. Summary of the Invention
[0004] In order to improve the access experience of relevant visitors while effectively preventing unauthorized access and data leakage risks, this application provides a user identity authentication method, permission management system, medium and program product.
[0005] In the first aspect, the present application provides a user identity authentication method, which adopts the following technical solution:
[0006] A user identity authentication method, comprising:
[0007] When a user access request instruction is detected, identifying an access identity credential feature corresponding to the user access request instruction;
[0008] Determining whether the visitor's access identity is valid based on the identity credential characteristics;
[0009] If the visitor's access identity is valid, determining the access rights corresponding to the visitor based on the identity credential features;
[0010] The access content feature corresponding to the user access demand instruction is identified, and target feedback content is determined based on the access content feature, the identity credential feature, and the access permission.
[0011] By adopting the above technical solution and setting an identity validity judgment link, invalid identities can be eliminated, thereby effectively preventing illegal visitors or unauthorized visitors from accessing system resources. Only when the visitor's identity is valid can the relevant data be accessed or viewed, which helps prevent the relevant data from being illegally tampered with or deleted, thereby facilitating the maintenance of the integrity and consistency of the relevant data. After determining that the visitor's identity is valid and analyzing the visitor's accessible rights, not all accessible rights are fed back. Instead, after multi-dimensional authentication based on access content features and identity credential features, the target feedback content corresponding to the user's access requirement instructions is located from the accessible rights. Through basic identity authority verification and multi-dimensional identity authentication, it is convenient to improve the access experience of relevant visitors while effectively preventing unauthorized access and data leakage risks.
[0012] In one possible implementation, after determining the target feedback content, the method further includes:
[0013] Determining feedback data coverage based on the access content characteristics and the target feedback content;
[0014] When the feedback data coverage is lower than a preset coverage threshold, determining unfeedback data based on the access content feature and the target feedback content;
[0015] The authentication feature to be supplemented is determined based on the unfeedback data, and an additional permission verification prompt is generated based on the authentication feature to be supplemented, so as to remind the visitor to provide the authentication feature to be supplemented.
[0016] By adopting the above technical solution, by determining the feedback data coverage, it is convenient to quantitatively evaluate the degree of match between the target feedback content and the access needs of relevant visitors. When the feedback data coverage is lower than the preset coverage threshold, the non-feedback data can be automatically identified, and additional permission verification prompts can be generated based on the non-feedback data, ensuring that all key information is fully processed and fed back, while ensuring that all access operations are subject to strict identity authentication and permission review.
[0017] In one possible implementation, after determining the authentication feature to be supplemented based on the non-feedback data, the method further includes:
[0018] Based on the authentication feature to be supplemented and the identity credential feature, determining whether there is an associated authorized person associated with the visitor's credential;
[0019] If so, generating a permission application instruction based on the non-feedback data and the identity credential characteristics, wherein the permission application instruction is used to submit a permission application to the associated authorized person with one click;
[0020] If the submission operation is not detected within the preset response time period, and the unfeedback data contains preset data features, an abnormal access warning is generated based on the identity credential features, and the abnormal access warning is fed back to the associated authorized personnel.
[0021] By adopting the above technical solution, by identifying the authentication features to be supplemented and the identity credential features, it is easy to automatically determine whether there is an associated authorized person associated with the visitor's credentials, and by submitting the permission application to the associated authorized person with one click, it is easy to simplify the permission application process, thereby improving the convenience of permission management. In addition, if the visitor's submission operation is not detected within the preset response time period, and the feedback data does not contain the preset data features, by timely generating an abnormal access warning based on the visitor's identity credential features and feeding back to the associated authorized person, it is easy to timely discover and deal with potential illegal access or abnormal behavior, thereby enhancing the security of the access process.
[0022] In a possible implementation, after determining the unfeedback data based on the access content feature and the target feedback content, the method further includes:
[0023] Identifying a first data feature corresponding to the target feedback content and a second data feature corresponding to the non-feedback data;
[0024] determining, based on the first data feature and the second data feature, a data correlation degree between the target feedback content and the non-feedback data;
[0025] When the data relevance is higher than a preset relevance threshold, determining a display position of the non-feedback data in the target feedback content based on the first data feature and the second data feature, and determining a description feature based on the non-feedback data;
[0026] The description feature is superimposed on the display position to obtain updated target feedback content.
[0027] By adopting the above technical solution, by analyzing the data correlation between the target feedback content and the non-feedback data, it is convenient to judge whether the missing non-feedback data will affect the normal browsing of visitors. If the missing non-feedback data may affect the visitor's browsing experience, the descriptive features of the non-feedback data can be summarized and the summarized descriptive features can be superimposed on the display position, so as to protect the security of the non-feedback data while reducing the impact on the access experience caused by insufficient visitor permissions.
[0028] In one possible implementation, it also includes:
[0029] Acquire access data to be integrated within a preset integration time period, wherein the access data to be integrated includes visitor identity information, access content, and access time;
[0030] Determining a data block to be written from a preset access blockchain based on the access time, and obtaining a block hash value of a previous data block corresponding to the data block to be written, wherein the block hash value is composed of visitor identity information, access content, and access time corresponding to the previous data block;
[0031] The block hash value of the access data to be integrated and the previous data block corresponding to the data block to be written is written into the data block to be written to update the preset access blockchain.
[0032] By adopting the above technical solution, by recording the access data to be integrated by all visitors within the preset integration time period on the blockchain, it is easy to ensure the integrity and authenticity of the access history. By storing different access histories in different data blocks, it is easy to eliminate the risk of single point failure. Even if a data block fails or is attacked, other blocks can still continue to record work. This decentralized design facilitates improving the stability and reliability of the system.
[0033] In one possible implementation, it also includes:
[0034] Identifying at least one block feature corresponding to each data block in the preset access blockchain, and determining at least one associated blockchain corresponding to each data block based on all block features corresponding to each data block;
[0035] Based on at least one block feature corresponding to each data block, generating a screening identifier corresponding to each data block, and superimposing each screening identifier onto the corresponding data block;
[0036] When it is detected that the relevant manager triggers the filtering mark corresponding to the data block, the associated blockchain corresponding to the triggered filtering mark will be displayed.
[0037] By adopting the above technical solution, by identifying the block features corresponding to each data block in the preset access blockchain, it is convenient to have a more comprehensive understanding of the attributes and content of the data block, thereby facilitating the understanding of the potential associations between different data blocks. By establishing connections between data blocks and other related data blocks, it is convenient to quickly find other data blocks related to a specific data block when needed, thereby facilitating the enhancement of data traceability.
[0038] In a second aspect, the present application provides a rights management system that adopts the following technical solutions:
[0039] A rights management system, comprising:
[0040] at least one processor;
[0041] Memory;
[0042] At least one application, wherein the at least one application is stored in a memory and configured to be executed by at least one processor, and the at least one application is configured to: execute the above-mentioned user identity authentication method.
[0043] In a third aspect, the present application provides a computer-readable storage medium, which adopts the following technical solution:
[0044] A computer-readable storage medium includes: a computer program that can be loaded by a processor and execute the user identity authentication method.
[0045] In a fourth aspect, the present application provides a computer program product that adopts the following technical solution:
[0046] A computer program product includes a computer program, which implements the above-mentioned user identity authentication method when executed by a processor.
[0047] In summary, this application includes at least one of the following beneficial technical effects:
[0048] By setting up an identity validity judgment link, invalid identities can be eliminated, thereby effectively preventing illegal visitors or unauthorized visitors from accessing system resources. Only when the visitor's identity is valid can the relevant data be accessed or viewed, which helps prevent the relevant data from being illegally tampered with or deleted, thereby maintaining the integrity and consistency of the relevant data. After determining that the visitor's identity is valid and analyzing the visitor's accessible rights, not all accessible rights are fed back. Instead, after multi-dimensional authentication based on access content features and identity credential features, the target feedback content corresponding to the user's access requirement instructions is located from the accessible rights. Through basic identity authority verification and multi-dimensional identity authentication, it is convenient to improve the access experience of relevant visitors while effectively preventing unauthorized access and data leakage risks.
[0049] By recording the access data of all visitors to be integrated within the preset integration time period on the blockchain, it is easy to ensure the integrity and authenticity of the access history. By storing different access histories in different data blocks, it is easy to eliminate the risk of single point failure. Even if a data block fails or is attacked, other blocks can still continue to record work. This decentralized design can improve the stability and reliability of the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0050] Figure 1 This is a flowchart of a user identity authentication method in an embodiment of the present application;
[0051] Figure 2 This is a schematic diagram of a blockchain update process in an embodiment of the present application;
[0052] Figure 3 It is a structural diagram of a rights management system in an embodiment of the present application. DETAILED DESCRIPTION
[0053] The following is combined with Figures 1 to 3 This application is described in further detail.
[0054] After reading this specification, those skilled in the art may make non-creative modifications to this embodiment as needed, but such modifications are protected by patent law as long as they fall within the scope of the claims of this application.
[0055] To make the purpose, technical solutions, and advantages of the embodiments of this application more clear, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the drawings in the embodiments of this application. Obviously, the described embodiments are part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0056] It should be noted that in the optional embodiments of the present application, the object information and other related data involved, when the embodiments in the present application are applied to specific products or technologies, need to obtain the permission or consent of the object, and the collection, use and processing of the relevant data need to comply with the relevant laws, regulations and standards of the relevant countries and regions. In other words, if the embodiments of the present application involve data related to the object, it needs to be obtained through the authorization and consent of the object, the authorization and consent of the relevant departments, and in compliance with the relevant laws, regulations and standards of the country and region. If personal information is involved in the embodiments, the acquisition of all personal information requires the consent of the individual. If sensitive information is involved, the separate consent of the information subject needs to be obtained. The embodiments also need to be implemented with the authorization and consent of the object.
[0057] Specifically, embodiments of the present application provide a user identity authentication method, which is executed by a rights management system. The rights management system can be a server or a terminal device, wherein the server can be an independent physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing cloud computing services. The terminal device can be a smartphone, tablet computer, laptop computer, desktop computer, etc., but is not limited to these. The terminal device and the server can be directly or indirectly connected via wired or wireless communication, which is not limited in the embodiments of the present application.
[0058] refer to Figure 1 , Figure 1: is a flow chart of a user identity authentication method in an embodiment of the present application, the method comprising steps S110 to S140, wherein:
[0059] Step S110: When a user access request instruction is detected, the access identity credential feature corresponding to the user access request instruction is identified.
[0060] Specifically, the front-end framework can be used to customize instructions for monitoring visitor clicks, scrolling, input and other behaviors, so that the user access demand instructions issued or triggered by the visitor can be detected in time. For example, when a visitor clicks a link or button, the front-end JavaScript code can capture this trigger event and send it to the permission management system as a user access demand instruction. The specific method of detecting the user access demand instruction is not specifically limited in the embodiment of this application. The access identity credential features of the corresponding visitor can be identified from the user access demand instruction based on a preset feature recognition algorithm. The access identity credential features include at least a login account and a login password. The specific content is not specifically limited in the embodiment of this application and can be set by relevant staff according to actual needs. The preset feature recognition algorithm can be a regular expression algorithm, a hash algorithm, etc. The specific feature recognition algorithm is not specifically limited in the embodiment of this application, as long as the identity credential features can be identified from the user access demand instruction.
[0061] Step S120: determining whether the visitor's access identity is valid based on the identity credential characteristics.
[0062] Specifically, when judging the validity of the identity based on the characteristics of the identity credentials, the login account provided by the visitor can be queried in the database of the rights management system to confirm whether the login account exists. When it is determined that the login account exists, the login password submitted by the visitor can be hashed using a hash algorithm and compared with the password hash value stored in the database. If the hash difference between the hash processing result and the password hash value is less than the preset hash threshold, it is determined that the login password verification has passed, and at this time it can be determined that the visitor's access identity is valid.
[0063] Step S130: If the visitor's access identity is valid, the corresponding access rights of the visitor are determined based on the identity credential characteristics.
[0064] Specifically, access permissions are only analyzed if the visitor's access identity is valid. If the access identity is invalid, the rights management system will deny the visitor's access request and may trigger appropriate security response mechanisms, such as logging failed attempts and locking the account, to ensure the security of the rights management system. Identity validity assessment allows for preliminary screening, reducing operational pressure on the rights management system when faced with frequent or large-scale access.
[0065] Based on the identity credential features, the role identity corresponding to the visitor can be determined. For example, the role identity can be an administrator, ordinary user, collaborator, etc. Different identity credential features correspond to different access rights. A mapping relationship between access rights and role identities can be established in advance, that is, the access rights corresponding to the identity credential features can be determined based on a preset permission mapping relationship. The preset permission mapping relationship contains access rights corresponding to different combinations of identity credential features, which can be determined by relevant staff based on historical experimental data and uploaded to the permission management system. The specific content is not specifically limited in the embodiments of this application. Determining the visitor's access rights based on identity credential features is basic identity authentication.
[0066] Step S140: Identify access content features corresponding to the user access demand instruction, and determine target feedback content based on the access content features, identity credential features, and access rights.
[0067] Specifically, the corresponding access content features can be determined from the user's access request instruction based on a preset feature recognition algorithm. The specific preset feature recognition algorithm is not specifically limited in the embodiments of this application. The access content features can be used to summarize or characterize the meaning of the corresponding access content. The access permissions are further filtered based on the access content features and the identity credential features, and the target feedback content obtained is more compatible with the visitor's access needs. For example, after the access permissions of the relevant visitor are determined to be data a, data b, data c, data d, and data e based on the identity credential features, the corresponding data a, data b, data c, data d, and data e are not directly fed back to the corresponding visitor, nor is the corresponding visitor allowed to access or view any one of data a, data b, data c, data d, and data e. Instead, the access permissions are further filtered based on the access content features and the identity credential features, and the target feedback content finally determined as data a, data d, and data e is fed back. When the identity credential features also include features such as department and personnel position, the target feedback content is determined by combining the identity credential features and the access content features to filter the access permissions, thereby facilitating multi-dimensional authentication.
[0068] For the embodiment of the present application, by setting an identity validity judgment link, it is convenient to eliminate invalid identities, thereby effectively preventing illegal visitors or unauthorized visitors from accessing system resources. Only when the visitor's identity is valid can the relevant data be accessed or viewed, which helps to prevent the relevant data from being illegally tampered with or deleted, thereby facilitating the maintenance of the integrity and consistency of the relevant data. After determining that the visitor's identity is valid and analyzing the visitor's accessible access rights, not all accessible access rights are fed back. Instead, after multi-dimensional authentication is performed through access content features and identity credential features, the target feedback content corresponding to the user's access demand instructions is located from the accessible access rights. Through basic identity authority verification and multi-dimensional identity authentication, it is convenient to improve the access experience of relevant visitors while effectively preventing unauthorized access and data leakage risks.
[0069] Furthermore, to ensure that all key information is fully processed and fed back, the method provided in the embodiment of the present application may further include, after determining the target feedback content:
[0070] Based on the access content characteristics and the target feedback content, the feedback data coverage rate is determined; when the feedback data coverage rate is lower than the preset coverage threshold, the non-feedback data is determined based on the access content characteristics and the target feedback content; based on the non-feedback data, the authentication features to be supplemented are determined, and additional permission verification prompts are generated based on the authentication features to be supplemented to remind the visitor to provide the authentication features to be supplemented.
[0071] Specifically, the target feedback features contained in the target feedback content can be identified through a preset feature recognition algorithm, and the feedback data coverage can be obtained by matching the access content features with the target feedback features. The higher the feedback data coverage, the higher the overlap between the target feedback features and the access content features, and also indicates that the target feedback content can meet the visitor's access needs. For example, the access content features include features 1, 2, 3, and 4, and the target feedback features include features 1, 2, 3, and 5; the lower the feedback data coverage, the lower the overlap between the target feedback features and the access content features, and also indicates that the target feedback content may not meet the visitor's access needs. For example, the access content features include features 1, 2, 3, and 4, and the target feedback features include features 4, 5, 6, and 7.
[0072] The feedback data coverage rate can be compared with the preset coverage threshold to determine whether it is necessary to send additional permission verification prompts to the visitor based on the non-feedback data. For example, when the feedback data coverage rate is lower than the preset coverage threshold, the access content features including features 1, 2, 3, and 4 can be compared with the target feedback features including features 4, 5, 6, and 7 to determine the access content features not involved in the target feedback features. After determining features 1, 2, and 3, the data content corresponding to the non-involved access content features is determined as non-feedback data. Since the access content features are determined based on the user's access demand instructions and belong to the content that the visitor needs to access, and the target feedback features are determined based on the identity credential features identified in the user's access demand instructions through multi-dimensional authentication, and belong to the content that the visitor can access, the access content features not involved in the target feedback features are data content that the visitor does not have the right to access.
[0073] After identifying unreturned data, an additional permission verification prompt can be generated based on the unreturned data to remind the visitor to provide additional authentication features, such as fingerprint, iris, device information, geographic location, etc., to expand access rights and enable access or viewing of the unreturned data. After the additional permission verification prompt is generated, the corresponding visitor can be reminded to provide the additional authentication features via SMS reminder or pop-up reminder.
[0074] By determining the feedback data coverage, it is convenient to quantitatively evaluate the degree of match between the target feedback content and the access needs of relevant visitors. When the feedback data coverage is lower than the preset coverage threshold, the non-feedback data can be automatically identified, and additional permission verification prompts can be generated based on the non-feedback data to ensure that all key information is fully processed and fed back, while ensuring that all access operations are subject to strict identity authentication and permission review.
[0075] Furthermore, after determining the authentication features to be supplemented based on the non-feedback data, the method provided in the embodiment of the present application may further include:
[0076] Based on the authentication features to be supplemented and the identity credential features, determine whether there is an associated authorized person associated with the visitor's credentials; if so, generate a permission application instruction based on the unfeedback data and the identity credential features, and the permission application instruction is used to submit a permission application to the associated authorized person with one click; if the submission operation is not detected within the preset response time period, and the unfeedback data contains the preset data features, generate an abnormal access warning based on the identity credential features, and feedback the abnormal access warning to the associated authorized person.
[0077] Specifically, since the identity credentials corresponding to the visitor correspond to the visitor's role identity, when the visitor does not have the authority to access the unfeedback data, other personnel associated with the visitor's credentials may have the authority to access the unfeedback data. For example, based on the visitor's identity credential characteristics, it can be determined that the visitor is a member of the xx team and does not have the authority to access the unfeedback data h, while person W is the leader of the xx team and has the authority to access the unfeedback data h. In this case, person W can be determined as the visitor's associated authority person. The visitor and the associated authority person contain at least one associated identity credential characteristic. Based on the preset credential association relationship, the associated authority person associated with the visitor's credential can be determined. The associated authority person needs to be associated with the visitor's credential and must also have access rights to the unfeedback data. The preset credential association relationship includes the associated person corresponding to each identity credential characteristic and the access rights corresponding to each associated person. The preset credential association relationship can be determined by the relevant staff when assigning permissions to each person and uploaded to the permission association system.
[0078] After determining the associated authorized person, a permission application instruction can be generated based on the unfeedback data and the visitor's identity credential features, and a submission button or submission option for the permission application instruction can be generated at the same time. The visitor can submit the permission application to the associated authorized person with one click on the terminal device, which simplifies the permission application process and thus facilitates the convenience of permission management. In order to further discover and handle potential illegal access or abnormal behavior, after the permission application instruction is generated, a timing component can be started to count the duration. If no visitor clicks or triggers a related submission operation within the preset reaction time period, that is, if the visitor does not apply for permission to the associated authorized person within the preset reaction time period, it is necessary to identify and detect whether the unfeedback data contains the preset data features. When the unfeedback data contains the preset data features, an abnormal access warning is generated and the abnormal access warning is fed back to the associated authorized person so that the associated authorized person can understand the access behavior. The preset data features can be encryption features, privacy features, etc., and the specific content is not specifically limited in this embodiment of the application. The preset reaction time period is a period of time after the permission application instruction is generated. The length of the preset reaction time period can be 3 minutes or 5 minutes. The specific length is not specifically limited in this embodiment of the application.
[0079] Furthermore, to reduce the impact on access experience caused by insufficient visitor permissions, after determining the unfeedback data based on the access content characteristics and the target feedback content, the method provided in the embodiment of the present application may further include:
[0080] Identify a first data feature corresponding to target feedback content and a second data feature corresponding to non-feedback data; determine a data correlation between the target feedback content and the non-feedback data based on the first data feature and the second data feature; when the data correlation is higher than a preset correlation threshold, determine a display position of the non-feedback data in the target feedback content based on the first data feature and the second data feature, and determine a descriptive feature based on the non-feedback data; superimpose the descriptive feature on the display position to obtain updated target feedback content.
[0081] Specifically, a first data feature in the target feedback content is identified based on a preset feature recognition algorithm. The first data feature can be a data logic feature, a timestamp feature, a business scenario feature, etc. corresponding to the target feedback content. The specific preset feature recognition algorithm and the first data feature are not specifically limited in the embodiments of this application. Based on the above method, a second data feature corresponding to the non-feedback data can be determined, wherein the second data feature can be a data logic feature, a timestamp feature, a business scenario feature, etc. corresponding to the non-feedback data. The first data feature and the second data feature are matched for correlation to facilitate understanding the correlation between the non-feedback data and the target feedback content. If the data correlation is not higher than the preset correlation threshold, it can be determined that the correlation between the non-feedback data and the target feedback content is weak, that is, the visitor's access and reading experience will not be affected in the absence of the non-feedback data; if the data correlation is higher than the preset correlation threshold, it can be determined that the correlation between the non-feedback data and the target feedback content is strong, that is, the visitor's access and reading experience may be affected in the absence of the non-feedback data. Among them, the data correlation between the first data feature and the second data feature can be calculated based on feature matching algorithms such as cosine similarity, Jaccard similarity, and Euclidean distance. The data correlation can also be calculated using trained KNN, SVM, neural network and other machine learning models. The specific method is not limited in the embodiments of this application, as long as the data correlation between the first data feature and the second data feature can be calculated.
[0082] When it is determined that the visitor's access and reading experience may be affected in the absence of non-feedback data, the target feedback content can be divided into logically relatively independent paragraphs or modules according to the first data feature, and then the key information points, turning points or summary sentences are identified in each paragraph or module. After matching the second data feature with the key information points, turning points or summary sentences, the display position is determined. If there are multiple non-feedback data that need to determine the display position, a relevance sorting algorithm can be used to determine the processing priority of the non-feedback data. The descriptive features corresponding to the non-feedback data can be determined based on a preset text analysis algorithm, wherein the preset text analysis algorithm can be a TF-IDF algorithm, a TextRank algorithm or a bag-of-words model algorithm, wherein the TextRank algorithm is a graph-based sorting algorithm used for tasks such as keyword extraction and sentence summarization in text analysis. By calculating the similarity between words or sentences, a graph structure is constructed, and the importance is sorted using a graph sorting algorithm. The specific text analysis algorithm is not specifically limited in the embodiment of this application, as long as it can summarize the descriptive features of the non-feedback data. The display form of the descriptive features can be text, icons, labels or badges, etc. The specific display form is not specifically limited in the embodiments of this application. The summarized descriptive features are superimposed on the display position to protect the security of non-feedback data while reducing the impact on the access experience caused by insufficient visitor permissions.
[0083] Furthermore, in order to improve the stability and reliability of the system, the method provided in the embodiment of the present application further includes steps S210 to S230, such as Figure 2 As shown, where:
[0084] Step S210: obtaining access data to be integrated within a preset integration time period, where the access data to be integrated includes visitor identity information, access content, and access time.
[0085] Specifically, the preset integration time period is a period before the current time. The duration of the preset integration interval can be 24 hours or 48 hours. The specific duration is not specifically limited in the embodiments of this application. By organizing all access data within the historical time period, it is easier to understand the visitor's access needs and to promptly discover and summarize potential security threats. The access data to be integrated must at least include visitor identity information, access content, and access time. Among them, the visitor identity information can be replaced by the visitor's identity credential characteristics, and the access content can be the target feedback content ultimately received by the visitor.
[0086] Step S220: Determine the data block to be written from the preset access blockchain based on the access time, and obtain the block hash value of the previous data block corresponding to the data block to be written. The block hash value is composed of the visitor identity information corresponding to the previous data block, the access content, and the access time.
[0087] Specifically, the preset access blockchain can be established in advance by relevant staff. The preset access blockchain may contain access data corresponding to the previous integration time period. When integrating the access data corresponding to the current integration time period, the data block to be written can be determined from the preset access block based on the access time of each access data to be integrated. The block hash value is then extracted from the block header of the previous data block. At this time, it is necessary to ensure that the block hash value is calculated using the hash algorithm based on the visitor identity information, access content, and access time of the previous data block. At the same time, it is also necessary to calculate the block hash value corresponding to the access data to be integrated based on the hash algorithm to facilitate the acquisition of the next data block to be written after the data block to be written. For example, based on the access time, it is determined from the preset access blockchain that the data block to be written corresponding to the access data a to be integrated is data block b. It is known that data block a, data block b, and data block c are arranged in order in the preset access blockchain. After determining that the data block to be written corresponding to the access data a to be integrated is data block b, it is necessary to obtain the block hash value corresponding to data block a, and at the same time, calculate the hash value corresponding to the access data a to be integrated as the block hash value corresponding to data block b.
[0088] Step S230: Write the block hash value of the previous data block corresponding to the access data to be integrated and the data block to be written into the data block to be written, so as to update the preset access blockchain.
[0089] Specifically, the visitor identity information, access content, and access time corresponding to each access data to be integrated are collected, and these data information and the block hash value of the previous data block are input into the corresponding data block to be written to complete the update of the preset access blockchain.
[0090] For the embodiment of the present application, by recording the access data to be integrated of all visitors within a preset integration time period on the blockchain, it is convenient to ensure the integrity and authenticity of the access history. By storing different access histories in different data blocks, it is convenient to eliminate the risk of single point failure. Even if a data block fails or is attacked, other blocks can still continue to record work. This decentralized design facilitates improving the stability and reliability of the system.
[0091] Furthermore, in order to facilitate rapid locating of other data blocks related to a specific data block when needed, the method provided in the embodiment of the present application further includes:
[0092] Identify at least one block feature corresponding to each data block in the preset access blockchain, and based on all block features corresponding to each data block, determine at least one associated blockchain corresponding to each data block; based on at least one block feature corresponding to each data block, generate a filtering identifier corresponding to each data block, and superimpose each filtering identifier on the corresponding data block; when it is detected that the relevant management personnel triggers the filtering identifier corresponding to the data block, display the associated blockchain corresponding to the triggered filtering identifier.
[0093] Specifically, a block feature corresponding to each data block can be identified based on a preset feature recognition algorithm. Each data block includes at least one block feature. The specific preset feature recognition algorithm is not specifically limited in the embodiments of this application. The block feature can be a visitor feature, a data feature, a time feature, etc. For any data block, based on at least one block feature corresponding to the data block, a traversal is performed from the preset access blockchain to determine associated blocks that have at least one block feature in common with the data block. For example, the block features corresponding to data block X are block feature a, block feature b, and block feature c. Blocks 1 and 2 have block feature a, blocks 3, 4, and 5 have block feature b, and block 6 has block feature c. In this case, blocks 1, 2, 3, 4, 5, and 6 can all serve as associated blocks of data block X. Different associated blockchains correspond to different block characteristics. An associated blockchain includes a data block and all associated blocks that share the same block characteristics as the data block. For example, data block X and blocks 3, 4, and 5 all have block characteristic b. Therefore, the associated blockchain corresponding to data block X can be data block X-block 3-block 4-block 5. Based on the above method, at least one associated blockchain corresponding to each data block can be obtained.
[0094] In order to facilitate the retrieval or viewing of all data blocks with the same block feature, the corresponding block feature can be superimposed on each data block to generate a screening identifier. The display form of the screening identifier can be text, pattern, etc. The specific display form is not specifically limited in the embodiment of the present application and can be set by relevant staff according to actual needs. After the relevant management personnel trigger the screening identifier corresponding to any data block, it is convenient to display the associated blockchain corresponding to the triggered screening identifier. For example, after triggering the screening identifier corresponding to the block feature b corresponding to data block X, data block X-block 3-block 4-block 5 will be directly displayed. Similarly, after triggering the screening identifier corresponding to the block feature b corresponding to block 3, the associated blockchain of data block X-block 3-block 4-block 5 will also be directly displayed. By establishing a connection between a data block and other associated data blocks, it is convenient to quickly find other data blocks related to a specific data block when needed, thereby enhancing the traceability of data.
[0095] The present application provides a rights management system, such as Figure 3 As shown, Figure 3 The rights management system 300 shown includes: a processor 301 and a memory 303. The processor 301 and the memory 303 are connected, for example, via a bus 302. Optionally, the rights management system 300 may further include a transceiver 304. It should be noted that in actual applications, the number of transceivers 304 is not limited to one, and the structure of the rights management system 300 does not constitute a limitation on the embodiments of the present application.
[0096] Processor 301 can be a CPU (Central Processing Unit), a general-purpose processor, a DSP (Digital Signal Processor), an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or other programmable logic device, transistor logic device, hardware component, or any combination thereof. It can implement or execute the various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. Processor 301 can also be a combination that implements computing functions, such as a combination of one or more microprocessors, a combination of a DSP and a microprocessor, etc.
[0097] Bus 302 may include a path for transmitting information between the above components. Bus 302 may be a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus. Bus 302 may be divided into an address bus, a data bus, a control bus, etc. For ease of illustration, Figure 3 The fact that only one line is used does not mean that there is only one bus or one type of bus.
[0098] The memory 303 may be a ROM (Read Only Memory) or other type of static storage device that can store static information and instructions, a RAM (Random Access Memory) or other type of dynamic storage device that can store information and instructions, or an EEPROM (Electrically Erasable Programmable Read Only Memory), a CD-ROM (Compact Disc Read Only Memory) or other optical disk storage, optical disk storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto.
[0099] The memory 303 is used to store application code for executing the solution of the present application, and the execution is controlled by the processor 301. The processor 301 is used to execute the application code stored in the memory 303 to implement the content shown in the above method embodiment.
[0100] The rights management system includes, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), and in-vehicle terminals (e.g., in-vehicle navigation terminals), as well as fixed terminals such as digital TVs and desktop computers. Servers are also possible. Figure 3 The rights management system shown is merely an example and should not limit the functions and scope of use of the embodiments of the present application.
[0101] An embodiment of the present application provides a computer-readable storage medium having a computer program stored thereon. When the computer-readable storage medium is run on a computer, the computer can execute the corresponding contents of the aforementioned method embodiment.
[0102] The present application provides a computer program product, which includes a computer program that, when executed by a processor, implements the method described in any of the above embodiments. Compared with related technologies, the present application provides an identity validity judgment link to facilitate the elimination of invalid identities, thereby effectively preventing illegal or unauthorized visitors from accessing system resources. Only when the visitor's identity is valid can the visitor access or view the relevant data, which helps prevent the relevant data from being illegally tampered with or deleted, thereby facilitating the maintenance of the integrity and consistency of the relevant data. After determining that the visitor's identity is valid and analyzing the visitor's accessible rights, not all accessible rights are fed back. Instead, after performing multi-dimensional authentication based on access content features and identity credential features, target feedback content corresponding to the user's access requirement instruction is located from the accessible rights. Through basic identity authority verification and multi-dimensional identity authentication, it is convenient to improve the access experience of the relevant visitor while effectively preventing unauthorized access and data leakage risks.
[0103] It should be understood that although the steps in the flowcharts of the accompanying drawings are shown in sequence as indicated by the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some of the steps in the flowcharts of the accompanying drawings may include multiple sub-steps or multiple stages, and these sub-steps or stages are not necessarily executed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be executed in turn or alternately with other steps or at least a portion of the sub-steps or stages of other steps.
[0104] The above description is only part of the implementation methods of the present application. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present application. These improvements and modifications should also be regarded as the scope of protection of the present application.
Claims
1. A user identity authentication method, characterized in that: include: When a user access request instruction is detected, identifying an access identity credential feature corresponding to the user access request instruction; Determining whether the visitor's access identity is valid based on the identity credential characteristics; If the visitor's access identity is valid, determining the access rights corresponding to the visitor based on the identity credential features; Identifying access content features corresponding to the user access demand instruction, and determining target feedback content based on the access content features, the identity credential features, and the access rights; After determining the target feedback content, the method further includes: Determining feedback data coverage based on the access content characteristics and the target feedback content; When the feedback data coverage is lower than a preset coverage threshold, determining unfeedback data based on the access content feature and the target feedback content; Determining the authentication features to be supplemented based on the unfeedback data, and generating an additional permission verification prompt based on the authentication features to be supplemented, so as to remind the visitor to provide the authentication features to be supplemented; After determining the unfeedback data based on the access content feature and the target feedback content, the method further includes: Identifying a first data feature corresponding to the target feedback content and a second data feature corresponding to the non-feedback data; determining, based on the first data feature and the second data feature, a data correlation degree between the target feedback content and the non-feedback data; When the data relevance is higher than a preset relevance threshold, determining a display position of the non-feedback data in the target feedback content based on the first data feature and the second data feature, and determining a description feature based on the non-feedback data; The description feature is superimposed on the display position to obtain updated target feedback content.
2. A user identity authentication method according to claim 1, characterized in that: After determining the authentication feature to be supplemented based on the non-feedback data, the method further includes: Based on the authentication feature to be supplemented and the identity credential feature, determining whether there is an associated authorized person associated with the visitor's credential; If so, generating a permission application instruction based on the non-feedback data and the identity credential characteristics, wherein the permission application instruction is used to submit a permission application to the associated authorized person with one click; If the submission operation is not detected within the preset response time period, and the unfeedback data contains preset data features, an abnormal access warning is generated based on the identity credential features, and the abnormal access warning is fed back to the associated authorized personnel.
3. A user identity authentication method according to claim 1, characterized in that: Also includes: Acquire access data to be integrated within a preset integration time period, wherein the access data to be integrated includes visitor identity information, access content, and access time; Determining a data block to be written from a preset access blockchain based on the access time, and obtaining a block hash value of a previous data block corresponding to the data block to be written, wherein the block hash value is composed of visitor identity information, access content, and access time corresponding to the previous data block; The block hash value of the access data to be integrated and the previous data block corresponding to the data block to be written is written into the data block to be written to update the preset access blockchain.
4. A user identity authentication method according to claim 3, characterized in that: Also includes: Identifying at least one block feature corresponding to each data block in the preset access blockchain, and determining at least one associated blockchain corresponding to each data block based on all block features corresponding to each data block; Based on at least one block feature corresponding to each data block, generating a screening identifier corresponding to each data block, and superimposing each screening identifier onto the corresponding data block; When it is detected that the relevant manager triggers the filtering mark corresponding to the data block, the associated blockchain corresponding to the triggered filtering mark will be displayed.
5. A rights management system, characterized in that: The rights management system includes: at least one processor; Memory; At least one application, wherein the at least one application is stored in a memory and configured to be executed by at least one processor, and the at least one application is configured to: execute a user identity authentication method according to any one of claims 1-4.
6. A computer-readable storage medium, characterized in that include: A computer program is stored which can be loaded by a processor and executes a user identity authentication method according to any one of claims 1 to 4.
7. A computer program product, characterized in that The invention comprises a computer program, which implements the steps of a user identity authentication method according to any one of claims 1 to 4 when the computer program is executed by a processor.
Citation Information
Patent Citations
Access credential generation method for block chain network, data access method, storage medium, and computing device
CN109344647A
Electronic business card management method and system
CN119475303A