Access authority management method and device, equipment and storage medium
By splitting super user permissions in the operating system, building a separation of rights model, and combining multi-factor authentication, blockchain technology and zero-trust security model, the problem of excessive concentration of super user permissions is solved, achieving higher system security and flexibility.
Patent Information
- Application Number
- CN202510222912.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-27
- Publication Date
- 2025-06-13
AI Technical Summary
The over-concentration of permissions of super user root in existing operating systems leads to the risk of system data leakage and damage, and the traditional single authentication method is difficult to meet current security needs.
Through the principle of least permission, split the permissions of the original super user of the operating system, build a three-rights separation model, and combine multi-factor authentication, blockchain technology and zero-trust security model to dynamically adjust access permissions to ensure the reasonable allocation and use of permissions.
Effectively prevent unauthorized access and potential security threats, improve system flexibility and adaptability, and reduce the risk of abuse of super user permissions.
Smart Images

Figure CN120145358A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and particularly relates to an access permission management method, device, equipment and storage medium. Background Art
[0002] With the rapid development of information technology, the operating system has become an indispensable part of the modern computing environment, and its security issues have attracted more and more attention. In the Linux operating system, there is a superuser, namely the root user, which has all the permissions to manage the system, such as arbitrarily adding, deleting users, terminating processes, deleting important files, and even changing the password of the root user. Therefore, once the root permission is exploited by malicious users, it may lead to the leakage and destruction of system data. The security risks brought by the misoperation of the superuser or the impersonation of its identity pose a great threat to the security of the operating system. At the same time, the traditional single authentication method (such as username and password) has been difficult to meet the current security requirements.
[0003] As can be seen from the above, how to avoid the excessive concentration of the permissions of the existing operating system superuser root is an urgent problem to be solved at present. Summary of the Invention
[0004] In view of this, the purpose of the present invention is to provide an access permission management method, device, equipment and storage medium, which can avoid the excessive concentration of the permissions of the existing operating system superuser root. The specific solutions are as follows:
[0005] In the first aspect, the present application provides an access permission management method, including:
[0006] Splitting the permissions of the original superuser of the operating system according to the principle of least privilege, constructing a separation-of-powers model based on the split permission users, and determining a security policy rule including a source type set by using a preset allow rule of a policy model in the TE security model;
[0007] Performing multi-factor authentication processing on the input user information, and determining a target permission user corresponding to the user information based on the multi-factor authentication result, so as to determine and record an initial access permission corresponding to the target permission user by using the separation-of-powers model and blockchain technology; the multi-factor authentication processing includes username login authentication, role switching authentication, user identifier permission authentication, and biometric identification authentication;
[0008] When it is monitored that the target permission user uses the initial access permission, authenticating the identity and checking the permissions of the target permission user by using the zero-trust security model;
[0009] If the inspection result indicates that the authentication or the permission check fails, the initial access permission is adjusted by using a machine learning model and the system environment corresponding to the target permission user to obtain the target access permission.
[0010] Optionally, splitting the permissions of the original superuser of the operating system according to the principle of least privilege, and constructing a separation-of-powers model based on the permission users obtained by splitting, including:
[0011] Using the TE security model and the role-based access control model, and splitting the permissions of the original superuser of the operating system according to the principle of least privilege to obtain each subset of permissions including different management permissions;
[0012] Establishing corresponding permission users based on each of the subsets of permissions, and creating corresponding permission roles by using each of the permission users, so as to construct a separation-of-powers model based on the permission roles and deleting the original superuser.
[0013] Optionally, determining the security policy rules including the source type set by using the preset allow rules of the policy model in the TE security model, including:
[0014] Creating a corresponding source type set based on the subset of permissions and each of the permission roles, and establishing an association relationship between the permission role and the permission user through a preset association policy;
[0015] Using the association relationship and the preset allow rules of the policy model in the TE security model to determine each source type, each target access type and the corresponding operation types in the source type set;
[0016] Determining the initial access permissions of the permission role based on each source type, each target access type and the corresponding operation types in the source type set;
[0017] Wherein, the initial access permission is a subset of the subset of permissions of the permission user corresponding to the initial access permission.
[0018] Optionally, performing multi-factor authentication processing on the input user information, and determining the target permission user corresponding to the user information based on the multi-factor authentication result, including:
[0019] Obtaining the user identifier corresponding to the user information to determine whether there is a user identifier corresponding to the user information in the preset user database;
[0020] If there is a user identifier corresponding to the user information in the preset user database, it indicates that the username authentication corresponding to the user information passes, and the password of the user information is verified by using the shadow password file;
[0021] If the password verification of the user information passes, the user corresponding to the user information is determined as an authorized user, and an authorization acquisition command and the user identifier of the authorized user are used to perform an authorization determination on the user information;
[0022] If the user identifier corresponding to the user information is a preset value, use biometrics to determine whether the authorized user meets the preset biometric conditions;
[0023] If the authorized user meets the preset biometric conditions, the authorized user is determined as the target authorized user.
[0024] Optionally, the determining and recording the initial access authority corresponding to the target authorized user by using the separation-of-powers model and blockchain technology includes:
[0025] Use the separation-of-powers model to determine the initial access authority corresponding to the target authorized user;
[0026] Use a smart contract to allocate the initial access authority, and when allocating the initial access authority, record the user number corresponding to the target authorized user, the authority type corresponding to the initial access authority, and the authority allocation time to obtain an authority allocation record, and store the authority allocation record in the first blockchain node;
[0027] Obtain the user operations of the target authorized user related to the initial access authority, generate corresponding user operation records based on the user operations, and save the user operation records to the second blockchain node.
[0028] Optionally, the access authority management method further includes:
[0029] If the target authorized user is vacant or the initial access authority meets the preset expiration conditions, perform an authority recovery operation on the initial access authority, create a corresponding authority recovery record, and store the authority recovery record in the third blockchain node;
[0030] Wherein, the authority recovery record includes the user number corresponding to the target authorized user, the authority type corresponding to the initial access authority, and the recovery time.
[0031] Optionally, the if the inspection result indicates that the identity verification or the authority inspection fails, use a machine learning model and the system environment corresponding to the target authorized user to adjust the initial access authority to obtain a target access authority, includes:
[0032] If the inspection result indicates that the identity verification or the authority inspection fails, use machine learning to determine whether there is an abnormality in the system environment corresponding to the target authorized user;
[0033] If there is an abnormality in the system environment corresponding to the target privileged user, the context awareness technology is used to obtain the geographical location and device type corresponding to the target privileged user, so as to judge whether there is a risk operation by the target privileged user based on the geographical location and device type;
[0034] If there is a risk operation by the target privileged user, the risk operation is isolated based on container technology, and the initial access privilege corresponding to the target privileged user is reduced to obtain the target access privilege.
[0035] In a second aspect, the present application provides an access privilege management device, including:
[0036] A privilege splitting module, configured to split the privileges of the original superuser of the operating system according to the principle of least privilege, construct a separation-of-powers model based on the split privilege users, and determine a security policy rule including a source type set by using a preset allow rule of a policy model in the TE security model;
[0037] An initial access privilege determination module, configured to perform multi-factor authentication processing on the input user information, and determine a target privileged user corresponding to the user information based on the multi-factor authentication result, so as to determine and record the initial access privilege corresponding to the target privileged user by using the separation-of-powers model and blockchain technology; the multi-factor authentication processing includes username login authentication, role switching authentication, user identifier privilege authentication, and biometric identification authentication;
[0038] A privilege check module, configured to, when it is monitored that the target privileged user uses the initial access privilege, perform identity authentication and privilege check on the target privileged user by using a zero-trust security model;
[0039] An access privilege adjustment module, configured to, if the check result indicates that the identity authentication or the privilege check fails, adjust the initial access privilege by using a machine learning model and the system environment corresponding to the target privileged user to obtain the target access privilege.
[0040] In a third aspect, the present application provides an electronic device, including:
[0041] A memory, configured to store a computer program;
[0042] A processor, configured to execute the computer program to implement the foregoing access privilege management method.
[0043] In a fourth aspect, the present application provides a computer-readable storage medium, configured to store a computer program, wherein the computer program, when executed by a processor, implements the foregoing access privilege management method.
[0044] This application first
[0045] A privilege splitting module, which is used to split the privileges of the original superuser of the operating system according to the principle of least privilege, construct a separation-of-powers model based on the privilege users obtained by splitting, and determine a security policy rule including a source type set by using a preset allow rule of a policy model in the TE security model; An initial access privilege determination module, which is used to perform multi-factor authentication processing on the input user information, and determine a target privilege user corresponding to the user information based on the multi-factor authentication result, so as to determine and record an initial access privilege corresponding to the target privilege user by using the separation-of-powers model and blockchain technology; The multi-factor authentication processing includes username login authentication, role switching authentication, user identifier privilege authentication, and biometric identification authentication; A privilege check module, which is used to authenticate the identity and check the privileges of the target privilege user by using the zero-trust security model when it is detected that the target privilege user uses the initial access privilege; An access privilege adjustment module, which is used to adjust the initial access privilege by using a machine learning model and the system environment corresponding to the target privilege user if the check result indicates that the identity authentication or the privilege check fails, so as to obtain a target access privilege.
[0046] As can be seen from the above, this application splits the privileges of the original superuser into multiple sub-privilege sets, assigns them to different privilege users to form a separation-of-powers model, and formulates a security policy rule including a source type set by using the sub-privilege set privilege role and the preset allow rule of the policy model in the TE security model. Then, the initial access privilege corresponding to the target privilege user is determined through multi-factor authentication methods such as username login authentication, role switching authentication, and user identifier privilege authentication, and the initial access privilege is recorded by using blockchain technology. When the target privilege user uses the initial access privilege, identity authentication and privilege check are performed through the zero-trust security model, and the initial access privilege is adjusted according to the check result and the system environment by using a machine learning model. In this way, through privilege splitting, multi-factor authentication, blockchain recording, and the zero-trust security model, unauthorized access and potential security threats are effectively prevented, and the initial access privilege is adjusted according to the system environment, thereby improving the flexibility and adaptability of the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.
[0048] Figure 1Flowchart of an access permission management method disclosed in this application;
[0049] Figure 2 Schematic diagram of a smart contract and a blockchain provided by this application;
[0050] Figure 3 Schematic diagram of dynamic permission adjustment provided by this application;
[0051] Figure 4 Schematic diagram of identity authentication and permission check provided by this application;
[0052] Figure 5 Flowchart of a specific access permission management method disclosed in this application;
[0053] Figure 6 Schematic diagram of the structure of an access permission management device disclosed in this application;
[0054] Figure 7 Schematic diagram of the structure of an electronic device disclosed in this application. Detailed implementation manners
[0055] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0056] Currently, there is a superuser in the Linux operating system, which has all the permissions to manage the system, such as arbitrarily adding or deleting users, terminating processes, deleting important files, or even changing the password of the superuser. Once the permissions of the superuser are exploited by malicious users, it may lead to the leakage and destruction of system data. The security risks brought by the misoperation of the superuser or the impersonation of its identity pose a great threat to the security of the operating system. Therefore, this application provides an access permission management method, which effectively prevents unauthorized access and potential security threats through permission splitting, multi-factor authentication, blockchain recording, and a zero-trust security model, and adjusts the initial access permissions through the system environment, thereby improving the flexibility and adaptability of the system.
[0057] See Figure 1 As shown, the embodiments of the present invention disclose an access permission management method, including:
[0058] Step S11: Split the permissions of the original superuser of the operating system according to the principle of least privilege, construct a separation-of-powers model based on the resulting permission users, and use the preset allow rules of the policy model in the TE security model to determine the security policy rules including the source type set.
[0059] In this embodiment, all the permissions currently held by the original superuser (such as root) of the operating system are obtained through a permission management tool or by referring to system-related documents. Then, the TE (Type Enforcement) security model and the role-based access control model are used to split the permissions of the original superuser of the operating system according to the principle of least privilege, so as to obtain different types of sub-permission sets related to the operating system resource management, and corresponding permission users are created based on the sub-permission sets, and a separation-of-powers model is constructed using the permission roles created by the permission users; among them, each sub-permission set may include a set of permissions required to complete specific management tasks; after splitting the permissions of the original superuser, the original superuser is deleted. Specifically, splitting the permissions of the original superuser of the operating system according to the principle of least privilege and constructing a separation-of-powers model based on the resulting permission users includes: using the TE security model and the role-based access control model, and splitting the permissions of the original superuser of the operating system according to the principle of least privilege to obtain each sub-permission set including different management permissions; establishing corresponding permission users based on each sub-permission set, and using each permission user to create corresponding permission roles, so as to construct a separation-of-powers model based on the permission roles, and deleting the original superuser.
[0060] In a specific implementation, the permissions of the original superuser can be split into three sub-permission sets, including a system management sub-permission set, a security management sub-permission set, and an audit management sub-permission set. Among them, the system management sub-permission set is responsible for managing system-related resources, including user identity management, system resource configuration, system loading and startup, and exception handling during system operation; the security management sub-permission set is responsible for formulating system security policies, uniformly marking the subjects and objects in the system, authorizing the subjects, configuring consistent security policies, and ensuring the data integrity of the marking, authorization, and security policies; the audit management sub-permission set is responsible for setting audit options, auditing and monitoring security-related events, including monitoring system activities and log processing, providing audit and monitoring functions, and creating and maintaining access audit trail records of protected objects. It is worth mentioning that the sub-permission sets restrict each other, that is, the set of capabilities that each administrator can access is unique and restrictive.
[0061] In this embodiment, each authorized user in the separation-of-powers model is obtained to create corresponding authorization roles based on the authorized users, and then a corresponding source type set is created by using the subset of permissions and each of the authorization roles. And security policy rules corresponding to the source type set are formulated through the association relationship between the authorization roles and the authorized users and the preset allow rules of the policy model in the TE security model. Specifically, determining the security policy rules including the source type set by using the preset allow rules of the policy model in the TE security model includes: creating a corresponding source type set based on the subset of permissions and each of the authorization roles, and establishing an association relationship between the authorization roles and the authorized users through a preset association policy; using the association relationship and the preset allow rules of the policy model in the TE security model to determine each source type, each target access type and the corresponding operation types in the source type set; determining each initial access permission of the authorization role based on each source type, each target access type and the corresponding operation types in the source type set; where the initial access permission is a subset of the subset of permissions of the authorized user corresponding to the initial access permission.
[0062] It can be understood that corresponding authorization roles are created based on the authorized users in the separation-of-powers model, and the subset of permissions is assigned to the corresponding authorization roles; where an authorized user can create one or more authorization roles according to their responsibilities and actual needs, and then refine the subset of permissions by using the policy model in the TE security model to obtain a source type set corresponding to the authorization role, and establish an association relationship between the authorization role and the authorized user, and determine each source type, each target access type and the corresponding operation types in the source type set based on the association relationship and the allow syntax rules of the policy model in the TE security model, so as to determine each initial access permission of the authorization role by using each source type, each target access type and the corresponding operation types in the source type set.
[0063] In a specific embodiment, the policy model in the TE security model can be defined as: P = ST × OPT × TT, that is, the initial access permission (P) = the operation type (OPT) of the resource class (class) of the source type (ST) for the target access type (TT); where the source type is the type of the subject or domain; the target access type is the type of the object; the resource class is a certain category of resources for the access request, such as file, socket, etc.; the operation type is the operation type when the subject can access, such as search, read, write, etc.; the initial access permission indicates the permission that the subject is allowed to operate when it can access. The allow syntax rule formulated based on the policy model in the TE security model is as follows: allow ST TT:class{opt1, opt2,...}. If the security policy rule exists: allow auditadm_t auditd_log_t:dir list_dir_perms; it indicates that the source type (ST) is auditadm_t and the target access type (TT) is auditd_log_t. The identifier dir refers to a directory, which means that a process with the domain type of auditadm_t is allowed to perform the operation of listing the directory content on a directory with the type of auditd_log_t.
[0064] In another specific embodiment, for example, when installing software, its source type is rpm_t. Assuming that only the system administrator user has the permission to install software, that is, only the system administrator user can execute the rpm command, the corresponding initial access permission is defined for the rpm_t source type using the policy model of the TE security model. The corresponding security policy rule is as follows: allow rpm_t rpm_exec_t:file {execute}; which defines that the source type rpm_t grants the permission of execution (execute) to the file resource of the target access type rpm_exec_t (indicating the rpm command).
[0065] Step S12, perform multi-factor authentication processing on the input user information, and determine the target permission user corresponding to the user information based on the multi-factor authentication result, so as to determine and record the initial access permission corresponding to the target permission user by using the separation of powers model and blockchain technology; the multi-factor authentication processing includes username login authentication, role switching authentication, user identifier permission authentication, and biometric identification authentication.
[0066] In this embodiment, after formulating the security policy rules, the input user information is obtained, and a global judgment is made on the user identifier corresponding to the user information, that is, it is judged whether there is a user identifier corresponding to the user information in the preset user database; if there is a user identifier corresponding to the user information in the preset user database, it indicates that the user identifier corresponding to the user information is a valid identifier, that is, the user name corresponding to the user information passes the authentication, and role switching authentication is performed on the user information; if the role switching authentication result is authentication passed, the user corresponding to the user information is determined as a privileged user, and the user information is subjected to privilege judgment by using a privilege acquisition command and the user identifier of the privileged user; if the user identifier corresponding to the user information is a preset value, biometric features (such as fingerprint, face recognition, iris scan, etc.) are used to judge whether the privileged user meets the preset biometric conditions, and if the privileged user meets the preset biometric conditions, the privileged user is determined as the target privileged user.
[0067] Specifically, the multi-factor authentication process is performed on the input user information, and the target privileged user corresponding to the user information is determined based on the multi-factor authentication result, including: obtaining the user identifier corresponding to the user information to judge whether there is a user identifier corresponding to the user information in the preset user database; if there is a user identifier corresponding to the user information in the preset user database, it indicates that the user name corresponding to the user information passes the authentication, and the user information is verified by using a shadow password file; if the password verification of the user information passes, the user corresponding to the user information is determined as a privileged user, and the user information is subjected to privilege judgment by using a privilege acquisition command and the user identifier of the privileged user; if the user identifier corresponding to the user information is a preset value, biometric features are used to judge whether the privileged user meets the preset biometric conditions; if the privileged user meets the preset biometric conditions, the privileged user is determined as the target privileged user.
[0068] It can be understood that the user password corresponding to the privileged user is obtained by using a privilege acquisition command, and it is judged whether the user password is consistent with the privilege password corresponding to the privileged user; if the user password is consistent with the privilege password corresponding to the privileged user, it is further judged whether the user identifier corresponding to the privileged user is a preset value; if the user identifier corresponding to the user information is a preset value, the target privileged user corresponding to the user information is determined based on the preset value. In a specific embodiment, a user with UID (i.e., user identifier) of 0 is regarded as a privileged user, that is, if the user identifier corresponding to the user information is 0, the target privileged user corresponding to the user information is determined based on the preset value.
[0069] In this embodiment, since the login procedures for privileged users and ordinary users are consistent, a global judgment is made on the input user information. When the UID corresponding to the user information is consistent with the user identifier in the preset user database, it is determined whether the user corresponding to the user information is an ordinary user or a privileged user; then, role-switching authentication is performed on the user information. For example, the user information is verified using a shadow password file. The user password corresponding to the user information input by the user is obtained through the operating system, and it is determined whether the user password is consistent with the password in the shadow password file. If the user password is consistent with the password in the shadow password file, it indicates that the password verification of the user information has passed, and the user corresponding to the user information is determined as the privileged user; if the password verification of the user information fails, it indicates that the user corresponding to the user information is an ordinary user, and the ordinary user interface corresponding to the ordinary user is entered, and the permissions corresponding to the ordinary user are obtained.
[0070] In this embodiment, after determining the target privileged user, the initial access permissions are determined for the target privileged user using the separation-of-powers model, and the permissions are allocated through a smart contract. At the same time, the relevant information on the permission allocation is recorded and stored in the first blockchain node. In addition, the user operations performed by the target privileged user based on the initial access permissions are monitored and recorded, and these operation records are saved to the second blockchain node. Specifically, determining and recording the initial access permissions corresponding to the target privileged user using the separation-of-powers model and blockchain technology includes: determining the initial access permissions corresponding to the target privileged user using the separation-of-powers model; allocating the initial access permissions using a smart contract, and when allocating the initial access permissions, recording the user number corresponding to the target privileged user, the permission type corresponding to the initial access permissions, and the permission allocation time to obtain a permission allocation record, and storing the permission allocation record in the first blockchain node; obtaining the user operations performed by the target privileged user related to the initial access permissions, and generating corresponding user operation records based on the user operations, and saving the user operation records to the second blockchain node.
[0071] It can be understood that due to reasons such as personnel changes and position adjustments, the situation where the target permission user is vacant may occur. At this time, it is necessary to recycle the initial access permission corresponding to the target permission user. Moreover, corresponding validity periods are set for each of the initial access permissions, and the validity period is determined according to the permission type of the initial access permission and business requirements. If the initial access permission exceeds the corresponding validity period, a permission recycling operation is performed. Specifically, the access permission management method further includes: if the target permission user is vacant or the initial access permission meets the preset expiration condition, the permission recycling operation of the initial access permission is performed, and a corresponding permission recycling record is created, and the permission recycling record is stored in the third blockchain node; wherein, the permission recycling record includes the user number corresponding to the target permission user, the permission type corresponding to the initial access permission, and the recycling time.
[0072] Figure 2 A schematic diagram of an intelligent contract and a blockchain provided in this embodiment is mainly divided into three stages: permission allocation, permission operation, and permission recycling. First, an intelligent contract is used to allocate corresponding initial access permissions to the target permission user, and when allocating the initial access permission, the user number corresponding to the target permission user, the permission type corresponding to the initial access permission, and the permission allocation time are recorded. The above records will be stored in the first blockchain node; after the target permission user obtains the corresponding initial access permission, all operations related to the initial access permission performed by the target permission user will be recorded, including the user number, the permission operation type, the corresponding operation time, and the operation result. The above operation records will be stored in the second blockchain node; when the initial access permission corresponding to the target permission user needs to be recycled, for example, when the target permission user leaves the company or the initial access permission expires, the intelligent contract will automatically execute the permission recycling operation. When performing the permission recycling, a corresponding permission recycling record will be created, including the user number corresponding to the target permission user, the permission type corresponding to the initial access permission, and the recycling time. These recycling records will be stored in the third blockchain node for subsequent data analysis and auditing.
[0073] Step S13: When it is monitored that the target permission user uses the initial access permission, the zero-trust security model is used to perform identity authentication and permission check on the target permission user.
[0074] In this embodiment, when it is detected that the target privileged user uses the initial access privilege, the identity verification of the target privileged user is first performed; the identity verification includes two-factor authentication, such as mobile phone verification code, fingerprint recognition, etc., to ensure again that the target privileged user is the holder of the initial access privilege. After passing the identity verification, check whether there are problems such as privilege overstepping or privilege insufficiency in the initial access privilege corresponding to the target privileged user.
[0075] Step S14: If the inspection result indicates that the identity verification or the privilege inspection fails, use the machine learning model and the system environment corresponding to the target privileged user to adjust the initial access privilege to obtain the target access privilege.
[0076] In this embodiment, when the inspection result indicates that the identity verification or the privilege inspection fails, use the machine learning model to analyze the system environment where the target privileged user is located to determine whether there is an abnormality in the system environment corresponding to the target privileged user based on the analysis result; if there is an abnormality in the system environment, use the context awareness technology to obtain the geographical location and device type corresponding to the target privileged user to determine whether the target privileged user has risky operations based on the geographical location and device type; if the target privileged user has risky operations, isolate the risky operations based on the container technology and reduce the initial access privilege corresponding to the target privileged user to obtain the target access privilege. It is worth mentioning that the machine learning model can consider factors such as the user's historical behavior pattern and the matching degree between the current behavior and the system state to predict whether the user has potential security risks or improper behaviors, so as to obtain the corresponding analysis result, and adjust the initial access privilege based on the analysis result to obtain a more appropriate target access privilege. This privilege adjustment may include raising or lowering the privilege level, restricting the access scope or time, etc.
[0077] If the inspection result indicates that the identity verification or the privilege inspection fails, use the machine learning model and the system environment corresponding to the target privileged user to adjust the initial access privilege to obtain the target access privilege, including: if the inspection result indicates that the identity verification or the privilege inspection fails, use machine learning to determine whether there is an abnormality in the system environment corresponding to the target privileged user; if there is an abnormality in the system environment corresponding to the target privileged user, use the context awareness technology to obtain the geographical location and device type corresponding to the target privileged user to determine whether the target privileged user has risky operations based on the geographical location and device type; if the target privileged user has risky operations, isolate the risky operations based on the container technology and reduce the initial access privilege corresponding to the target privileged user to obtain the target access privilege.
[0078] Figure 3 A schematic diagram of dynamic permission adjustment provided for this embodiment. By analyzing the operation behavior of the target permission user through a machine learning model, when abnormal operations are detected, such as frequent failed login attempts, unconventional file access patterns, etc., the initial access permission of the target permission user is automatically reduced or restricted. Container technology can be used to isolate high-risk operations. For example, file deletion operations are only executed in independent containers, and temporary permissions are automatically cleared after the containers are destroyed. The geographical location and device type of the target permission user are obtained through context awareness technology to dynamically adjust the corresponding initial access permission. In a specific implementation, when the target permission user logs in from an unusual device, access to sensitive resources is restricted. If the target permission user attempts to log in to the system multiple times but fails within a short period, the machine learning model analyzes these operation behaviors, identifies them as abnormal operations, reduces the initial access permission, restricts access to sensitive resources, and records the event in the corresponding operation log. If the system is monitored to be in a high-risk state, the initial access permission is increased. The high-risk state includes network attacks and system vulnerabilities, and additional authentication steps are added, such as integrating a hardware key, etc. If the target permission user logs in to the system from an unusual device, the system obtains its geographical location and device information, identifies it as an unusual device, reduces the initial access permission of the target permission user, restricts access to sensitive resources, and requires additional authentication.
[0079] Figure 4 A schematic diagram of authentication and permission check provided for this embodiment. When it is monitored that the target permission user uses the initial access permission, the target permission user is authenticated using biometrics. In addition to authenticating the target permission user using biometrics, other authentication factors can be introduced, such as SMS verification codes, hardware tokens, etc., to further enhance the security of the system. If the target permission user meets the preset biometric conditions, permission checks are performed using the user environment corresponding to the target permission user. The user environment includes but is not limited to the geographical location where the target permission user is located and the corresponding device type. In addition, the initial access permission can also be adjusted based on the operation behavior of the target permission user, the system state, and changes in business requirements.
[0080] As can be seen from the above, the present application splits the permissions of the original superuser into multiple sub - permission sets and assigns them to different permission users, forming a separation - of - powers model. And it formulates security policy rules including a source type set by using the preset allow rules of the sub - permission set permission roles and the policy model in the TE security model. Then, through multi - factor authentication methods such as username login authentication, role - switching authentication, and user - identifier permission authentication, it determines the initial access permissions corresponding to the target permission user and uses blockchain technology to record the initial access permissions. When the target permission user uses the initial access permissions, it performs identity verification and permission checks through a zero - trust security model and adjusts the initial access permissions according to the check results and the system environment by using a machine - learning model. In this way, through permission splitting, multi - factor authentication, blockchain recording, and the zero - trust security model, unauthorized access and potential security threats are effectively prevented, and the initial access permissions are adjusted according to the system environment, thereby improving the flexibility and adaptability of the system.
[0081] As can be known from the above - mentioned embodiments, the present application obtains the initial access permissions corresponding to the target permission role based on multi - factor authentication processing and security policy rules. Therefore, the process of obtaining the initial access permissions corresponding to the target permission role based on multi - factor authentication processing and security policy rules is described.
[0082] Figure 5A flowchart of a specific access permission management method disclosed in this embodiment. To improve security and ensure the implementation of the principle of least privilege, a role-based access control model and the principle of least privilege are used to assign the permission roles to the permission users to obtain the corresponding permissions (i.e., source types). It should be noted that one permission role can correspond to multiple source types, and one permission user can correspond to multiple permission roles. Then, the allow syntax rule is used to specify the authorization for the source type ST, and then the source type ST is assigned to the permission role. Finally, the set of permission roles is assigned to the specified permission user (i.e., privileged user). The specific steps are as follows: First, declare the permission user and its associated permission roles. In a specific implementation, the declaration statement is as follows: user sysadm roles {sysadm_r, staff_r}; This statement declares a permission user sysadm and the effectively associated permission roles sysadm_r and staff_r. Then, declare the association between the permission role and its source type. The statement is as follows: role sysadm_r types sysadm_t; This statement effectively associates the permission role sysadm_r with the source type sysadm_t. When the user-side executes the program and needs to execute in other domains, it also supports the transfer of permission domains. The statement is as follows: role_transition sysadm_r tsysadm_initrc_exec_t system_r; This statement transfers the sysadm_r domain to the sysadm_initrc_exec_t domain.
[0083] It is worth mentioning that each privilege user is associated with a corresponding privilege role, and the privilege role is associated with a corresponding set of source types. The original super-privilege user root becomes an ordinary user and no longer has any privileges related to privilege users. In a specific implementation, three sub-privilege sets are obtained by splitting the privileges of the original superuser of the operating system, and the privilege users are divided into system administrator users sysadm, security administrator users secdam, and audit administrator users auditadm, and 3 privilege roles role are defined: sysadm_r (system administrator role), secadm_r (security administrator role), and auditadm_r (audit administrator role). Then, 3 groups of source type ST sets, STsy, STse, and Stau, are defined, and the source type sets satisfy the following conditions: STsys = {Stsys_a, Stsys_b,...}; STse = {Stse_a, Stse_b,...}; STau = {Stau_a, Stau_b,...}; Based on the policy model in the TE security model, 3 groups of policy models corresponding to the privilege users can be obtained: (1) Psy = STsy × OPT × TT, and the initial access privileges of each source type corresponding to the system administrator user are a subset of the sub-privilege set corresponding to the system administrator user; (2) Pse = STse × OPT × TT, and the initial access privileges of each source type corresponding to the security administrator user are a subset of the sub-privilege set corresponding to the security administrator user; (3) Pau = STau × OPT × TT, and the initial access privileges of each source type corresponding to the audit administrator user are a subset of the sub-privilege set corresponding to the audit administrator user; where Psy, Pse, and Pau are the initial access privileges of each source type corresponding to the system administrator user, security administrator user, and audit administrator user, respectively. And at the same time, it satisfies ; ; .
[0084] It can be understood that the separation-of-powers model is constructed based on the permission users, and corresponding permission roles are created by using the permission users in the separation-of-powers model. In a specific implementation, the system administrator user sysadm is associated with the corresponding permission role sysadm_r, and the default source type of sysadm_r is sysadm_t. This source type ST allows conversion to other source types associated with the permission role sysadm_r. Then, corresponding initial access permissions are assigned to each source type based on the policy model of the TE security model. Among them, the system administrator user sysadm is used to complete the daily management and maintenance of the operating system, including system user account password management, network-related management, kernel module loading, service switching, archival backup and recovery of files, installation or uninstallation of software systems, etc. The system administrator user sysadm is used to complete the daily management and maintenance of the operating system, including system user account password management, network-related management, kernel module loading, service switching, archival backup and recovery of files, installation or uninstallation of software systems, etc. The security administrator user secadm is associated with the permission role secadm_r, and the default source type of secadm_r is secadm_t, which allows conversion to other source types associated with the permission role secadm_r. The security administrator user secadm is responsible for the management of the operating system security policy, including modifying the SELinux running mode, loading binary security policies, setting file security contexts, etc.
[0085] Taking the loading of security policies as an example, its source type is load_policy_t, and secadm has the permission to load policy rules, that is, only security administrators can execute the load_policy command. Therefore, corresponding initial access permissions are defined for the load_policy_t source type in the security policy rules. The definition statement is as follows: allow load_policy_t load_policy_exec_t:file{open read execute}; This defines that the source type load_policy_t grants the permissions of open, read, and execute to the target access type load_policy_exec_t (indicating the load_policy command). The audit administrator user auditadm is associated with the permission role auditadm_r. The default source type of auditadm_r is auditadm_t, and it is allowed to be converted to other source types associated with the role auditadm_r. The audit administrator is responsible for audit log-related permissions. Taking the auditadm_t source type as an example, only the audit administrator can have the permission to view audit logs. Corresponding initial access permissions are defined for the auditadm_t source type in the security policy rules. The statement is as follows: allow auditadm_t auditd_log_t:file map; This defines that the source type auditadm_t grants the file mapping (map) permission to the target access type auditd_log_t (indicating the audit log file), eliminating the super permission function.
[0086] Further, when the user information input by the client is obtained, multi-factor authentication processing is performed on the input user information, and a global judgment is made on the user information based on the user identifier corresponding to the user account in the user information; it is judged whether there is a user identifier corresponding to the user information in the preset user database; if there is a user identifier corresponding to the user information in the preset user database, it indicates that the user identifier corresponding to the user information is a valid identifier, that is, the user name authentication corresponding to the user information passes, and role switching authentication is performed on the user information; if the role switching authentication result is passed, the user corresponding to the user information is determined as a privileged user, and a privilege acquisition command and the user identifier of the privileged user are used to perform privilege judgment on the user information; if the user identifier corresponding to the user information is a preset value, the target privileged user corresponding to the user information is determined based on the preset value. In a specific implementation manner, the privilege role role(secadm_r) switching authentication can be performed through the instruction newrole -r secadm_r, and password authentication is performed with the predefined role role in the trusted environment as the judgment source. If the password verification passes, the privileged user secadm is allowed to log in. Then, the user identifier can be judged through the su command. If the user identifier is 0, the initial access privilege corresponding to the target privileged user is obtained.
[0087] As can be seen from the above, the present application splits the permissions of the original superuser to obtain sub-permission sets with different management permissions, and each sub-permission set is independent of each other, greatly reducing the risk that the attacked user completely controls the system. The clear mapping between permissions and target access types is realized through the policy model of the TE security model, effectively preventing permission abuse and reducing management complexity. Then, user authentication is performed through multi-factor authentication, improving the security of the operating system.
[0088] Correspondingly, as shown in Figure 6 the present application also provides an access privilege management device, including:
[0089] A privilege splitting module 11, configured to split the permissions of the original superuser of the operating system according to the principle of least privilege, construct a separation-of-powers model based on the split privileged users, and determine a security policy rule including a source type set by using a preset allow rule of the policy model in the TE security model;
[0090] The initial access right determination module 12 is configured to perform multi-factor authentication processing on the input user information, and determine the target privilege user corresponding to the user information based on the multi-factor authentication result, so as to determine and record the initial access right corresponding to the target privilege user by using the separation of powers model and blockchain technology; the multi-factor authentication processing includes user name login authentication, role switching authentication, user identifier privilege authentication, and biometric identification authentication;
[0091] The privilege check module 13 is configured to, when it is detected that the target privilege user uses the initial access right, perform identity authentication and privilege check on the target privilege user by using the zero-trust security model;
[0092] The access right adjustment module 14 is configured to, if the check result indicates that the identity authentication or the privilege check fails, adjust the initial access right by using a machine learning model and the system environment corresponding to the target privilege user to obtain the target access right.
[0093] As can be seen from the above, the present application splits the privileges of the original super user into multiple sub-privilege sets, and assigns them to different privilege users to form a separation of powers model, and formulates a security policy rule including a source type set by using the preset allow rules of the sub-privilege set privilege role and the policy model in the TE security model. Then, the initial access right corresponding to the target privilege user is determined through multi-factor authentication methods such as user name login authentication, role switching authentication, and user identifier privilege authentication, and the blockchain technology is used to record the initial access right. When the target privilege user uses the initial access right, identity authentication and privilege check are performed through the zero-trust security model, and the initial access right is adjusted by using the machine learning model according to the check result and the system environment. In this way, through privilege splitting, multi-factor authentication, blockchain recording, and the zero-trust security model, unauthorized access and potential security threats are effectively prevented, and the initial access right is adjusted by the system environment, thereby improving the flexibility and adaptability of the system.
[0094] In some specific embodiments, the privilege splitting module 11 may specifically include:
[0095] The privilege splitting completion unit is configured to use the TE security model and the role-based access control model, and split the privileges of the original super user of the operating system through the principle of least privilege to obtain each sub-privilege set including different management privileges;
[0096] The model construction unit is configured to establish corresponding privilege users based on each of the sub-privilege sets, create corresponding privilege roles by using each of the privilege users, construct a separation of powers model based on the privilege roles, and delete the original super user.
[0097] In some specific embodiments, the permission splitting module 11 may specifically include:
[0098] An association relationship establishing unit, which creates a corresponding source type set based on the sub - permission set and each of the permission roles, and establishes an association relationship between the permission role and the permission user through a preset association policy;
[0099] A source type determining unit, which determines each source type, each target access type, and corresponding operation types in the source type set by using the association relationship and the preset allow rules of the policy model in the TE security model;
[0100] A permission determining unit, which is used to determine each initial access permission of the permission role based on each source type, each target access type, and corresponding operation types in the source type set.
[0101] In some specific embodiments, the initial access permission determining module 12 may specifically include:
[0102] A user identifier judging unit, which is used to obtain the user identifier corresponding to the user information to judge whether there is a user identifier corresponding to the user information in a preset user database;
[0103] A role switching authentication unit, which, if there is a user identifier corresponding to the user information in the preset user database, indicates that the username authentication corresponding to the user information passes, and uses the shadow password file to verify the password of the user information;
[0104] A permission judging unit, which, if the password verification of the user information passes, determines the user corresponding to the user information as a permission user, and uses a permission acquisition command and the user identifier of the permission user to judge the permission of the user information;
[0105] A biometric judging unit, which, if the user identifier corresponding to the user information is a preset value, uses biometrics to judge whether the permission user meets a preset biometric condition;
[0106] A target permission user determining unit, which, if the permission user meets the preset biometric condition, determines the permission user as the target permission user.
[0107] In some specific embodiments, the initial access permission determining module 12 may specifically include:
[0108] An initial permission determining unit, which is used to determine the initial access permission corresponding to the target permission user by using the separation of powers model;
[0109] A permission allocation unit, configured to allocate the initial access permission by using a smart contract, and record the user number corresponding to the target permission user, the permission type corresponding to the initial access permission, and the permission allocation time when allocating the initial access permission, so as to obtain a permission allocation record, and store the permission allocation record in a first blockchain node;
[0110] A user operation record generation unit, configured to obtain user operations related to the initial access permission performed by the target permission user, generate corresponding user operation records based on the user operations, and save the user operation records to a second blockchain node.
[0111] In some specific embodiments, the access permission management device may specifically further include:
[0112] A permission recovery unit, configured to perform a permission recovery operation on the initial access permission if the target permission user is vacant or the initial access permission meets a preset expiration condition, create a corresponding permission recovery record, and store the permission recovery record in a third blockchain node.
[0113] In some specific embodiments, the access permission adjustment module 14 may specifically include:
[0114] A system environment judgment unit, configured to use machine learning to judge whether there is an abnormality in the system environment corresponding to the target permission user if the inspection result indicates that the identity authentication or the permission inspection fails;
[0115] A risk operation judgment unit, configured to obtain the geographical location and device type corresponding to the target permission user by using context awareness technology if there is an abnormality in the system environment corresponding to the target permission user, so as to judge whether there is a risk operation for the target permission user based on the geographical location and the device type;
[0116] A risk operation isolation unit, configured to isolate the risk operation based on container technology and reduce the initial access permission corresponding to the target permission user to obtain a target access permission if there is a risk operation for the target permission user.
[0117] Furthermore, an embodiment of the present application also discloses an electronic device, Figure 7The structure diagram of the electronic device 20 shown according to an exemplary embodiment. The content in the figure should not be considered as any limitation on the scope of use of this application. The electronic device 20 may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. Among them, the memory 22 is used to store a computer program, and the computer program is loaded and executed by the processor 21 to implement the relevant steps in the access right management method disclosed in any of the foregoing embodiments. Additionally, the electronic device 20 in this embodiment may specifically be an electronic computer.
[0118] In this embodiment, the power supply 23 is used to provide working voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows is any communication protocol applicable to the technical solution of this application, and specific limitations are not imposed here; the input / output interface 25 is used to obtain external input data or output data to the outside, and its specific interface type can be selected according to specific application needs, and no specific limitations are made here.
[0119] In addition, as a carrier for resource storage, the memory 22 can be a read-only memory, a random access memory, a disk, or an optical disc, etc. The resources stored thereon may include an operating system 221, a computer program 222, etc., and the storage method can be temporary storage or permanent storage.
[0120] Among them, the operating system 221 is used to manage and control each hardware device and the computer program 222 on the electronic device 20, and it can be Windows Server, Netware, Unix, Linux, etc. The computer program 222, in addition to including the computer program capable of completing the access right management method executed by the electronic device 20 disclosed in any of the foregoing embodiments, may further include computer programs capable of completing other specific tasks.
[0121] Furthermore, this application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, it implements the access right management method disclosed above. For the specific steps of this method, reference can be made to the corresponding content disclosed in the foregoing embodiments, and details will not be repeated here.
[0122] In this specification, the various embodiments are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. The same or similar parts among the various embodiments can be referred to each other. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple, and the relevant parts can be referred to the description of the method part.
[0123] Those skilled in the art may further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.
[0124] The steps of the methods or algorithms described in combination with the embodiments disclosed herein can be directly implemented by hardware, software modules executed by a processor, or a combination of the two. The software modules can be placed in a random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium well-known in the technical field.
[0125] Finally, it should also be noted that in this document, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variation thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising a..." does not exclude the existence of additional identical elements in the process, method, article or device comprising the element.
[0126] The technical solutions provided in this application have been introduced in detail above. Specific examples have been used in this article to elaborate on the principles and implementation manners of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application; at the same time, for those of ordinary skill in the art, according to the idea of this application, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to this application.
Claims
1. A method for managing access rights, characterized in that: include: The original super user's permissions of the operating system are split according to the principle of least privilege, and a three-power separation model is built based on the privileged users obtained by the split. The security policy rules including the source type set are determined by using the preset permission rules of the policy model in the TE security model. Perform multi-factor authentication on the input user information, and determine the target authorized user corresponding to the user information based on the multi-factor authentication result, so as to determine and record the initial access rights corresponding to the target authorized user by using the three-power separation model and blockchain technology; The multi-factor authentication process includes user name login authentication, role switching authentication, user identifier authority authentication, and biometric feature recognition authentication; When it is detected that the target authorized user uses the initial access right, the target authorized user is authenticated and authorized to check using the zero trust security model; If the check result indicates that the identity authentication or the permission check fails, the initial access permission is adjusted using a machine learning model and a system environment corresponding to the target permission user to obtain the target access permission.
2. The access rights management method according to claim 1, characterized in that: The original super user's rights of the operating system are split according to the principle of least privilege, and a three-power separation model is constructed based on the privileged users obtained by the split, including: Utilize the TE security model and the role-based access control model, and split the original super user's permissions of the operating system according to the principle of least privilege to obtain sub-permission sets including different management permissions; Corresponding permission users are established based on each of the sub-permission sets, and corresponding permission roles are created using each of the permission users, so as to construct a three-power separation model based on the permission roles, and delete the original super user.
3. The access rights management method according to claim 2, characterized in that: The method of using the preset permission rule of the policy model in the TE security model to determine the security policy rule including the source type set includes: Creating a corresponding source type set based on the sub-permission set and each of the permission roles, and establishing an association relationship between the permission role and the permission user through a preset association strategy; Determine each source type, each target access type, and each corresponding operation type in the source type set by using the association relationship and the preset permission rules of the policy model in the TE security model; Determine each initial access right of the permission role based on each source type, each target access type and each corresponding operation type in the source type set; The initial access permission is a subset of the sub-permission set of the permission user corresponding to the initial access permission.
4. The access rights management method according to claim 1, characterized in that: The performing multi-factor authentication processing on the input user information and determining the target authorized user corresponding to the user information based on the multi-factor authentication result includes: Obtaining a user identifier corresponding to the user information to determine whether a user identifier corresponding to the user information exists in a preset user database; If the user identifier corresponding to the user information exists in the preset user database, it indicates that the user name authentication corresponding to the user information is passed, and the password of the user information is verified by using the shadow password file; If the password verification of the user information passes, the user corresponding to the user information is determined as an authorized user, and the authority of the user information is determined by using the authority acquisition command and the user identifier of the authorized user; If the user identifier corresponding to the user information is a preset value, using biometrics to determine whether the authorized user meets the preset biometric conditions; If the authorized user meets the preset biometric condition, the authorized user is determined as a target authorized user.
5. The access rights management method according to claim 1, characterized in that: The method of using the three-power separation model and blockchain technology to determine and record the initial access rights corresponding to the target permission user includes: Determine the initial access rights corresponding to the target permission user by using the three-power separation model; The initial access rights are allocated by using a smart contract, and when allocating the initial access rights, a user number corresponding to the target permission user, a permission type corresponding to the initial access rights, and a permission allocation time are recorded to obtain a permission allocation record, and the permission allocation record is stored in the first blockchain node; Obtain user operations related to the initial access rights performed by the target authorized user, generate corresponding user operation records based on the user operations, and save the user operation records to the second blockchain node.
6. The access rights management method according to claim 5, characterized in that: Also includes: If the target permission user is vacant or the initial access permission meets the preset expiration condition, the permission recovery operation of the initial access permission is performed, and a corresponding permission recovery record is created, and the permission recovery record is stored in the third blockchain node; The permission recovery record includes the user number corresponding to the target permission user, the permission type corresponding to the initial access permission, and the recovery time.
7. The access rights management method according to any one of claims 1 to 6, characterized in that: If the check result indicates that the identity authentication or the permission check fails, the initial access permission is adjusted using a machine learning model and a system environment corresponding to the target permission user to obtain the target access permission, including: If the check result indicates that the identity authentication or the permission check fails, machine learning is used to determine whether there is an abnormality in the system environment corresponding to the target permission user; If there is any abnormality in the system environment corresponding to the target authorized user, the geographical location and device type corresponding to the target authorized user are obtained by using context-aware technology, so as to determine whether the target authorized user has performed risky operations based on the geographical location and device type; If the target permission user has any risky operation, the risky operation is isolated based on the container technology, and the initial access rights corresponding to the target permission user are reduced to obtain the target access rights.
8. An access rights management device, characterized in that: include: The permission splitting module is used to split the permissions of the original super user of the operating system according to the principle of least permission, build a three-power separation model based on the permission users obtained by the splitting, and determine the security policy rules including the source type set by using the preset permission rules of the policy model in the TE security model; An initial access right determination module is used to perform multi-factor authentication processing on the input user information, and determine the target permission user corresponding to the user information based on the multi-factor authentication result, so as to determine and record the initial access right corresponding to the target permission user by using the three-power separation model and blockchain technology; The multi-factor authentication process includes user name login authentication, role switching authentication, user identifier authority authentication, and biometric feature recognition authentication; A permission checking module is used to perform identity authentication and permission checking on the target permission user by using a zero-trust security model when the target permission user is detected to use the initial access permission; The access permission adjustment module is used to adjust the initial access permission by using a machine learning model and the system environment corresponding to the target permission user to obtain the target access permission if the check result indicates that the identity authentication or the permission check fails.
9. An electronic device, characterized in that: include: Memory, used to store computer programs; A processor, configured to execute the computer program to implement the access permission management method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: Used to store a computer program, wherein when the computer program is executed by a processor, the access permission management method according to any one of claims 1 to 7 is implemented.
Citation Information
Cited By
Operation command sending method and device, electronic equipment and storage medium
CN120567554A
Enterprise data security access control method and system
CN120582877A
Process permission configuration method and device based on multi-domain transfer, equipment and medium
CN121030732A