Cross-platform Permission Unified Management Method and System Based on Multiple WEB Systems
By building a multi-level tree topological network and a dual-channel transmission decision-maker, combining real-time network state and distributed verification, the problem of inconsistent permissions in multiple WEB systems is solved, and efficient, accurate and consistent management of cross-system permissions is achieved.
Patent Information
- Application Number
- CN202510595167.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-09
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2045-05-09
AI Technical Summary
In a multi-WEB system environment, the existing technology cannot realize real-time dynamic adjustment and synchronization of permission control, resulting in inconsistent permissions and affecting the normal progress of business operations.
By building a multi-level tree topological network, generating post permission baseline parameters, combining API gateways and real-time network status data, a dual-channel transmission decision-maker is built to realize dynamic path selection, and ensure consistency of permission synchronization through a distributed verification mechanism.
It realizes efficient, accurate and consistent cross-system permission configuration, significantly improves permission synchronization efficiency, provides traceable audit basis and proactive monitoring capabilities, and ensures compliance and security of permission management.
Smart Images

Figure CN120181813B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of WEB systems, and particularly to a cross-platform permission unified management method and system based on multiple WEB systems. Background Art
[0002] In the process of enterprise informatization construction, with the diversified development of business, it is often necessary to deploy multiple independent WEB systems to meet the needs of different business scenarios. The permission control of WEB systems means that users can only access resources with permissions. In the case of multiple WEB systems existing in a company, permission control and management become particularly important and complex. Due to their respective unique business function requirements and user groups, each business system needs to independently maintain its own permission model. When personnel permissions change, the operation and maintenance personnel of each system need to be notified to configure permission data.
[0003] Multiple independent WEB systems are mainly applied to medium and large enterprises or group organizations with complex organizational structures and diversified business systems. Often, there are multi-level department divisions within these enterprises, frequent cross-departmental collaborations, and each business system is developed by different technical teams or purchased from different suppliers, with significant differences in technical architectures, permission models, and data formats. In the use of multiple WEB systems by such enterprises, there is often an urgent need to solve the problem of unified management of permissions for multiple WEB systems.
[0004] In the existing permission management technologies for multiple WEB systems, static configuration methods or direct data synchronization are often adopted. When using static configuration, it is often impossible to dynamically adjust according to the real-time network status and interaction characteristics between systems. When directly performing data synchronization, the synchronization results are usually not verified, resulting in the situation that in both of these methods, it is easy to have the situation that the permissions of some systems are not updated in a timely manner or updated incorrectly, resulting in inconsistent permissions of users in different systems and affecting the normal progress of business operations. Summary of the Invention
[0005] In view of the deficiencies of the prior art, the present invention provides a cross-platform permission unified management method and system based on multiple WEB systems, which solves the above problems.
[0006] The above technical objectives of the present invention are achieved through the following technical solutions:
[0007] A cross-platform permission unified management method based on multiple WEB systems, the method comprising:
[0008] S1: Obtain the organizational structure data of the enterprise system, parse the organizational structure data, construct a multi-level tree-shaped topological network, and form organizational entity topological parameters;
[0009] S2: Parse the organizational entity topological parameters to generate position permission baseline parameters;
[0010] S3: Extract the API gateways of each WEB system to generate permission interface policies, calculate the baseline parameters of post permissions, and generate cross-system adaptation rule parameters;
[0011] S4: Construct a dual-channel transmission decision maker based on the organizational structure data, the interaction characteristics between WEB systems, and the cross-system adaptation rule parameters, and generate channel selection decision parameters in combination with real-time network status data;
[0012] S5: Trigger the synchronization engine to execute cross-system permission configuration based on the channel selection decision parameters, and at the same time generate timestamped permission propagation path parameters by associating the organizational entity topology parameters through the permission tracker;
[0013] S6: Deploy a policy executor at the permission management terminals of each WEB system, and collect the permission effective status based on the timestamped permission propagation path parameters to generate distributed verification parameters;
[0014] S7: Perform multi-modal verification on the distributed verification parameters to generate global permission synchronization achievement identification parameters;
[0015] S8: If the global permission synchronization achievement identification parameter is false, generate a compensation instruction queue, and generate permission panoramic situation parameters based on the compensation instruction queue.
[0016] Preferably, the obtaining of the organizational structure data of the enterprise system, the parsing of the organizational structure data, the construction of a multi-level tree topology network, and the formation of organizational entity topology parameters include:
[0017] Perform standardization processing on the organizational structure data, where the organizational structure data includes: department identifier, name, parent department identifier, hierarchical code, and cross-system identifier;
[0018] Extract the core fields from the organizational structure data, establish the department subordination relationship, and generate cross-system mapping rules taking the department subordination relationship as the link;
[0019] Starting from the root node of the organizational structure, recursively generate a multi-level tree network;
[0020] Analyze the multi-level tree network to form organizational entity topology parameters describing the full-dimensional characteristics of the organization.
[0021] Preferably, the parsing of the organizational entity topology parameters to generate baseline parameters of post permissions includes:
[0022] Parse the organizational entity topology parameters to establish initial post-permission association data;
[0023] Fuse the department subordination relationship and the cross-system mapping rules to generate a post relationship network diagram with permission weights;
[0024] Traverse the job relationship network diagram, calculate the job authority inheritance relationship layer by layer, and form a complete authority set;
[0025] Eliminate permissions from the complete permission set and transform it into a matrix to generate position permission baseline parameters.
[0026] Preferably, the extraction of the API gateway of each WEB system, the generation of the permission interface strategy, the calculation of the position permission baseline parameters, and the generation of the cross-system adaptation rule parameters include:
[0027] Extract the routing rules, authentication information and permission control strategies of each WEB system API gateway, and generate preliminary permission interface strategies;
[0028] Use cross-system mapping rules to map and convert the preliminary permission interface strategy to generate a permission interface strategy that is suitable for multiple systems;
[0029] Match the position authority baseline parameters with the authority interface policy set to generate the authority mapping relationship;
[0030] Analyze the differences in permission granularity and usage frequency between WEB systems, and generate a permission adaptation priority rule table;
[0031] Integrate the permission mapping relationship, permission adaptation priority rule table and constraint condition table to generate cross-system adaptation rule parameters.
[0032] Preferably, the dual-channel transmission decision maker is constructed according to the organizational structure data, the interaction characteristics between each WEB system and the cross-system adaptation rule parameters, and the channel selection decision parameters are generated in combination with the real-time network status data, including:
[0033] Disassemble the organizational structure data and generate a table of inter-departmental communication demand intensity;
[0034] Score the interaction characteristics between each WEB system to form a transmission performance and security score table between systems;
[0035] Generate channel constraint weight factors based on cross-system adaptation rule parameters and inter-system transmission performance and security score tables;
[0036] The inter-departmental communication demand intensity table, the inter-system transmission performance and security score table, and the channel constraint weight factor are integrated in multiple dimensions, and a dual-channel transmission decision maker with dynamic decision-making capabilities is constructed through preset policy priorities.
[0037] The dual-channel transmission decision maker and real-time network status data are calculated to generate channel selection decision parameters.
[0038] Preferably, the cross-system permission configuration is triggered by the channel selection decision parameter, and at the same time, the permission propagation path parameter with a timestamp is generated by associating the organization entity topology parameter through the permission tracker, including:
[0039] Eliminate the policy conflicts of the cross-system adaptation rule parameters to generate an enhanced permission descriptor;
[0040] Decompose the enhanced permission descriptor, and generate an atomic permission operation queue according to the dependencies between WEB systems;
[0041] Encapsulate the atomic permission operation queue into a distributed configuration instruction set with a unique ID. When the WEB system API gateway feeds back a ready confirmation signal, trigger the synchronization engine to perform the final submission operation;
[0042] Map the submitted distributed configuration instruction set to the organization entity topology parameter to generate an initial propagation path framework;
[0043] Analyze the initial propagation path framework to generate a propagation path node sequence with a version mark;
[0044] Associate the propagation path node sequence with the channel selection decision parameter and the organization entity topology parameter to generate a permission propagation path parameter with a timestamp.
[0045] Preferably, a policy executor is deployed at the permission management terminal of each WEB system, and the permission effective status is collected based on the permission propagation path parameter with a timestamp to generate a distributed verification parameter, including:
[0046] Analyze the permission propagation path parameter with a timestamp to generate a propagation path tuple with a timestamp;
[0047] Parse the propagation path tuple to form a node hash chain;
[0048] Poll the permission status of the WEB system to generate a verification snapshot;
[0049] Combine the node hash chain with the verification snapshot to generate a distributed verification parameter with a Merkle root signature.
[0050] Preferably, perform multimodal verification on the distributed verification parameter to generate a global permission synchronization achievement identification parameter, including:
[0051] Perform verification analysis on the distributed verification parameter to establish two modes, namely:
[0052] Real-time mode: Use the policy executor to collect the Merkle root value of the current permission data at the permission management terminal of each WEB system to obtain the Merkle root value of the core input parameter in the real-time mode;
[0053] By traversing the hash tree nodes layer by layer, compare the Merkle root values of all WEB systems to obtain the number of different nodes with inconsistent hash values among systems;
[0054] Judge whether the number of different nodes is 0. If it is 0, mark this permission as the real-time mode true synchronization status identifier; otherwise, mark it as the real-time mode false synchronization status identifier;
[0055] Batch mode: Use the policy executor to collect the version snapshot WAL logs generated during the permission synchronization process of each WEB system to obtain the core input parameter WAL logs in batch mode. Concatenate the WAL logs of each WEB system in chronological order, identify the missing time segments in the log sequence, and obtain the log fault rate;
[0056] Judge whether the log fault rate is ≤0.1%. If it is ≤0.1%, mark this permission as the batch mode true synchronization status identifier; otherwise, mark it as the batch mode false synchronization status identifier;
[0057] Associate and compare the real-time mode synchronization status identifier with the batch mode synchronization status identifier. When both modes are true, generate the global permission true synchronization achievement identifier parameter;
[0058] If any one of the synchronization achievement identifier parameters of the two modes is false, generate the global permission false synchronization achievement identifier parameter.
[0059] Preferably, when the global permission synchronization achievement identifier parameter is false, generate a compensation instruction queue. Based on the compensation instruction queue, generate the permission panoramic situation parameter, including:
[0060] Extract the permission propagation path parameter with timestamp and the distributed verification parameter to generate the root cause feature vector of the fault conduction path;
[0061] Perform rule mapping on the root cause feature vector and the cross-system adaptation rule parameter, and generate a compensation instruction queue containing the repair action sequence based on the permission interface policy;
[0062] Generate the permission panoramic situation parameter based on the compensation instruction queue;
[0063] Based on the permission panoramic situation parameter, encapsulate the post permission baseline parameter and the cross-system adaptation rule parameter into the policy library of the self-service application interface;
[0064] When the user initiates a permission application, call the global permission synchronization achievement identifier parameter through the real-time status query algorithm;
[0065] If the global permission synchronization completion flag parameter is true, indicating that the permission statuses of all WEB systems are consistent, the permission lifecycle generator is triggered to match the user request with the job permission baseline, generate permission lifecycle parameters, and mark the "synchronization validity" in the permission lifecycle parameters as passed;
[0066] If the flag is false, indicating that there are inconsistent permission statuses in all WEB systems, the process is terminated through the exception interception algorithm, permission lifecycle parameters are generated, and the "synchronization validity" in the permission lifecycle parameters is marked as rejected.
[0067] The cross-platform permission unified management system based on multiple WEB systems includes:
[0068] Parsing module: Obtain the organizational structure data of the enterprise system, parse the organizational structure data, construct a multi-level tree-shaped topology network, and form organizational entity topology parameters;
[0069] Job permission module: Parse the organizational entity topology parameters to generate job permission baseline parameters;
[0070] Permission interface module: Extract the API gateways of each WEB system to generate permission interface policies, calculate the job permission baseline parameters, and generate cross-system adaptation rule parameters;
[0071] Channel selection module: Construct a dual-channel transmission decision maker based on the organizational structure data, the interaction characteristics between WEB systems, and the cross-system adaptation rule parameters, and generate channel selection decision parameters in combination with real-time network status data;
[0072] Permission propagation module: Trigger the synchronization engine to execute cross-system permission configuration based on the channel selection decision parameters, and at the same time generate timestamped permission propagation path parameters by associating the organizational entity topology parameters through the permission tracker;
[0073] Permission effectiveness module: Deploy a policy executor at the permission management terminals of each WEB system, and collect the permission effectiveness status based on the timestamped permission propagation path parameters to generate distributed verification parameters;
[0074] Permission synchronization module: Perform multi-modal verification on the distributed verification parameters to generate global permission synchronization completion flag parameters;
[0075] Panorama module: If the global permission synchronization completion flag parameter is false, generate a compensation instruction queue, and generate permission panorama situation parameters based on the compensation instruction queue.
[0076] In summary, the present invention mainly has the following beneficial effects:
[0077] By constructing a dual-channel transmission decision maker and combining real-time network status data with an interaction characteristic scoring table between systems, dynamic optimization of channel selection is achieved. Compared with the traditional static configuration method, this mechanism can automatically select the optimal transmission path according to parameters such as department communication intensity, system transmission performance, and security scores, avoiding network congestion or high-latency nodes, and significantly improving the efficiency of cross-system permission configuration. At the same time, through the mapping calculation of permission interface policies and job permission baseline parameters, cross-system adaptation rules are generated to solve the problem of permission granularity differences between different systems, ensuring the accuracy and consistency of permission allocation.
[0078] By introducing distributed verification parameters and global permission synchronization to achieve identification parameters, a dual-verification mechanism is constructed. In the real-time mode, through Merkle tree hash comparison, the consistency of the permission status of each system is quickly detected. In the batch mode, the WAL log fault rate is analyzed to identify the synchronization integrity within a long time span. The two modes complement each other, being able to capture instantaneous state differences and track historical synchronization trajectories, forming a "time-space" dual-verification coverage to achieve the effect of verifying the synchronization result.
[0079] When the synchronization fails, the system automatically generates a compensation instruction queue based on the permission propagation path parameters and the fault root cause feature vector, and constructs an interactive permission panoramic situation parameter. This parameter not only intuitively displays the permission distribution status, but also encapsulates the job permission baseline and cross-system rules into a self-service application interface policy library, forming a closed-loop management of "monitoring-diagnosis-repair-prevention". When a user initiates a permission application, abnormal processes are intercepted through a real-time status query algorithm to avoid the spread of errors. Brief Description of the Drawings
[0080] Figure 1 is the flowchart of the steps of the cross-platform permission unified management method based on multiple WEB systems of the present invention;
[0081] Figure 2 is the block diagram of the cross-platform permission unified management system based on multiple WEB systems of the present invention. Detailed Embodiments
[0082] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0083] Refer to Figure 1 , the cross-platform permission unified management method based on multiple WEB systems includes:
[0084] S1: Obtain the organizational structure data of the enterprise system, parse the organizational structure data, construct a multi-level tree-shaped topology network, and form organizational entity topology parameters;
[0085] S2: Parse the organizational entity topology parameters to generate job permission baseline parameters;
[0086] S3: Extract the API gateways of each WEB system to generate permission interface policies, calculate the job permission baseline parameters, and generate cross-system adaptation rule parameters;
[0087] S4: Construct a dual-channel transmission decision maker based on the organizational structure data, the interaction characteristics between WEB systems, and the cross-system adaptation rule parameters, and generate channel selection decision parameters in combination with real-time network status data;
[0088] S5: Trigger the synchronization engine to execute cross-system permission configuration based on the channel selection decision parameters, and at the same time associate the organizational entity topology parameters through the permission tracker to generate timestamped permission propagation path parameters;
[0089] S6: Deploy a policy executor at the permission management terminal of each WEB system, and collect the permission effective status based on the timestamped permission propagation path parameters to generate distributed verification parameters;
[0090] S7: Perform multi-modal verification on the distributed verification parameters to generate a global permission synchronization achievement identification parameter;
[0091] S8: If the global permission synchronization achievement identification parameter is false, generate a compensation instruction queue, and generate a permission panoramic situation parameter based on the compensation instruction queue.
[0092] In the embodiment of the present invention, through constructing a multi-level tree-shaped topology network and cross-system adaptation rules, the automatic modeling and dynamic configuration of the enterprise permission system are realized. On the one hand, based on the job permission baseline parameters generated by organizational structure parsing, combined with the interface policies extracted from the API gateway, the error risk of manual permission configuration is effectively eliminated, ensuring the strong consistency between permission allocation and business architecture; on the other hand, the dual-channel transmission decision maker dynamically selects the optimal channel in combination with the real-time network status, significantly improving the permission synchronization efficiency. Especially in complex heterogeneous systems, the configuration cycle can be shortened, and the timestamped permission propagation path parameters provide a traceable audit basis for the full life cycle management of permissions, strengthening the compliance control ability.
[0093] By deploying a distributed verification mechanism and a multi-modal verification algorithm, the system forms a closed-loop management chain of "configuration-verification-repair", which can perform verification in a timely manner during permission synchronization. When the identification parameters are abnormal during global permission synchronization, the automatically triggered compensation instruction queue can quickly locate the failed nodes. Combined with the spatio-temporal dimension aggregation analysis of the visualization console, it enables the administrator to quickly complete fault location. This proactive monitoring not only shortens the permission exception response time, but also realizes real-time early warning of potential permission risks through continuous status collection of the policy executor, constructs an intelligent permission governance system with self-optimization ability for the enterprise, and ensures unified management of permissions in multiple WEB systems.
[0094] In one case of this embodiment, the method for obtaining the organizational structure data of the enterprise system, parsing the organizational structure data, constructing a multi-level tree-shaped topology network, and forming organizational entity topology parameters includes:
[0095] Performing standardization processing on the organizational structure data, where the organizational structure data includes: department identifier, name, parent department identifier, level code, and cross-system identifier;
[0096] Extracting the core fields from the organizational structure data, establishing the department subordination relationship, and generating cross-system mapping rules with the department subordination relationship as the link. Specifically, it includes: extracting core fields such as department identifier, name, and parent department identifier, and cleaning the data to ensure the validity of the parent department identifier. Using the parent department identifier as the association key, constructing a tree structure, recursively traversing from the root node to the associated sub-departments, and then determining the subordination relationship through recursive query to form the department subordination relationship. Using the department identifier and the parent department identifier as the link, establishing the corresponding relationship between departments in different systems, forming cross-system data conversion and synchronization mapping rules, and then generating cross-system mapping rules;
[0097] Starting from the root node of the organizational structure, recursively generating a multi-level tree-shaped network, specifically including: starting from the root node of the organizational structure, recursively querying its sub-departments, adding the sub-departments to the tree structure, and repeating this process for each sub-department, traversing layer by layer downward until all department levels are covered, forming a complete multi-level tree-shaped network;
[0098] Analyzing the multi-level tree-shaped network to form organizational entity topology parameters describing the full-dimensional characteristics of the organization, specifically including: performing a depth-first traversal on the multi-level tree-shaped network, calculating topological characteristics such as network depth, number of nodes, and sub-department distribution, analyzing the department subordination relationship path and hierarchical structure, generating topological parameters such as the number of organizational levels, department concentration, and subordination chain length, and combining multiple topological parameters into organizational entity topology parameters describing the full-dimensional characteristics of the organization;
[0099] By standardizing and cleaning organizational structure data, we ensure data quality and consistency, and provide a reliable basis for subsequent analysis; clarifying the hierarchy and reporting relationships between departments and establishing departmental affiliations will help understand the overall picture of the organizational structure and provide support for decision-making; using departmental affiliations as a link, we generate cross-system mapping rules to achieve the correspondence and conversion of departmental information between different systems, promote data sharing and system integration, and improve work efficiency; starting from the root node of the organizational structure, we recursively generate a multi-level tree network to intuitively display the hierarchical structure of the organizational structure, facilitate analysis and decision-making, and help discover potential problems; we analyze the multi-level tree network to form organizational entity topology parameters that describe the full-dimensional characteristics of the organization, comprehensively describe the characteristics of the organizational structure, provide a basis for organizational optimization and change, and help organizational development.
[0100] In one case of this embodiment, parsing the organizational entity topology parameters to generate the position authority baseline parameters includes:
[0101] Analyze the topological parameters of the organizational entity and establish the initial correlation data between the position and the authority, including: analyze the organizational entity topological parameters including the organizational structure characteristics such as departmental level and affiliation, and establish the initial correlation between the position and the authority based on the position and function of the position in the organizational structure. At the same time, allocate the corresponding authority according to the departmental function, refine the matching degree between the authority and the position responsibility, and then form the initial correlation data between the position and the authority;
[0102] Integrate department affiliation and cross-system mapping rules to generate a position relationship network diagram with authority weights; specifically, extract the position information in the department affiliation and cross-system mapping rules as nodes of the network diagram, use the affiliation between departments and the mapping relationship between systems as the edges connecting the nodes, build an initial position relationship network diagram, and then calculate the authority weight of each position according to the level and function of the position in the organizational structure, and add the weight to the corresponding edge, finally forming a position relationship network diagram with authority weights;
[0103] Traverse the position relationship network diagram, calculate the position authority inheritance relationship layer by layer, and form a complete authority set, specifically including: traverse the position relationship network diagram, starting from the root node position, visit all its direct child node positions, calculate the authority inheritance relationship of the child node positions according to the authority weights in the position relationship network diagram, form the authority set of the child node positions, and repeat the above process for each child node position, traverse downward layer by layer until all position levels are covered, and finally form a complete authority set of all positions;
[0104] Eliminate permissions from the complete permission set and perform matrix conversion on it to generate job permission baseline parameters, specifically including: setting a preset rule based on job responsibilities, security policies, and compliance requirements, eliminating redundant permissions according to the preset rule, retaining core permissions, then constructing a matrix with jobs as rows and permissions as columns, filling matrix elements according to the association strength between jobs and permissions, and finally generating job permission baseline parameters;
[0105] By parsing the organizational entity topology parameters to generate job permission baseline parameters, the refinement and systematization of permission management are realized. First, establish the initial association between jobs and permissions based on the organizational structure characteristics to ensure that the permission allocation highly matches the job responsibilities, improving the accuracy and efficiency of permission allocation. Second, integrate the department affiliation relationship and cross-system mapping rules to construct a job relationship network diagram with permission weights, intuitively showing the permission flow and inheritance relationship between jobs, enhancing the system integration and data sharing capabilities. Finally, calculate the permission inheritance relationship by traversing the network diagram to form a complete permission set, eliminate redundant permissions, and generate matrix-based job permission baseline parameters, providing a standardized and quantifiable basis for permission management, enhancing the depth of organizational structure analysis and decision support. Overall, it promotes the standardization and compliance of permission management in multiple WEB systems, achieving efficient and secure permission control.
[0106] In one case of this embodiment, extract the API gateways of each WEB system to generate permission interface policies, and calculate the job permission baseline parameters to generate cross-system adaptation rule parameters, including:
[0107] Extract the routing rules, authentication information, and permission control policies of the API gateways of each WEB system to generate preliminary permission interface policies, specifically including: collect the gateway configuration information, parse the routing rules such as API endpoints, request methods, path parameters, etc., obtain the authentication mechanisms of the permission interfaces such as API keys and OAuth tokens, and based on the role-based access control rules, associate and match the three to clarify the access permission requirements of each interface and generate preliminary permission interface policies to provide a basis for permission management;
[0108] Use cross-system mapping rules to map and transform the preliminary permission interface policies to generate permission interface policies adapted to multiple systems, specifically including: through cross-system mapping rules, convert the department identifiers of each system into the corresponding identifiers of the target system and establish the corresponding relationship between departments. At the same time, traverse the permission interface policies, replace the original department roles with the mapped identifiers, adjust the routing rules, authentication methods, and access control parameters, and automatically adjust according to the priority of the mapping rules for policy conflicts. By batch-converting the preliminary permission interface policies, generate permission interface policies adapted to multiple systems and ensure the effectiveness of cross-system permission control through consistency verification;
[0109] Match the job permission baseline parameters with the permission interface policy set to generate a permission mapping relationship, specifically including: first, parse the job permission baseline parameters to extract the core permissions and associated strength values of each job; then traverse the permission interface policy set, parse the permission requirements of each API endpoint, and precisely match the interface permissions with the permission items. If the permission exists and the associated strength meets the requirements, establish a mapping relationship between the job and the interface. Finally, generate a structured mapping table containing metadata such as job identifiers, interface identifiers, permission items, and validity periods. Expand the inherited permissions of sub-jobs based on the structured mapping table to form an executable permission mapping relationship across the system;
[0110] Analyze the permission granularity differences and usage frequencies among WEB systems to generate a permission adaptation priority rule table, specifically including: collect the permission levels and usage data among each WEB system, evaluate the granularity of permissions based on the permission levels, and count the number of times the permissions are called. Divide the permission levels into n levels, set the initial permission level as n1 and evaluate it as 1 point. When the permission level is n2, evaluate it as 2 points, and so on. The higher the permission level score, the finer the granularity. Each time a permission is called, it is evaluated as 1 point. The higher the permission call frequency, the higher the usage frequency. Assign high priorities to permissions with high usage frequencies and fine granularities, and lower the priorities for low-frequency or coarse-grained permissions to generate a permission adaptation priority rule table;
[0111] Integrate the permission mapping relationship and the permission adaptation priority rule table to generate cross-system adaptation rule parameters, specifically including: match each record in the permission mapping relationship with the permission adaptation priority rule table, sort the permission mapping relationship according to the priority scores of the permission items in the rule table. For each permission mapping relationship, combine the associated job identifier, interface identifier, validity period, and other data to generate cross-system adaptation rules, and form a score for the adaptation rules according to the sum of the scores of each permission mapping relationship and the permission adaptation priority rule table. Sort the adaptation rules from high to low according to the scores, and integrate all the adaptation rules into a structured parameter table in the order of the scores to form cross-system adaptation rule parameters;
[0112] By systematically integrating multi-system permission management elements, the intelligence and collaboration of permission control are significantly improved. Routes, authentication, and permission policies are extracted from the API gateways of each WEB system to generate preliminary policies, unifying the permission description standards for multi-source heterogeneous interfaces and establishing a basic data framework for cross-system permission governance. The policies are subject to identity conversion and parameter optimization using cross-system mapping rules, not only solving the problem of incompatible department identities between systems but also automatically resolving policy conflicts through a priority mechanism to ensure the consistency of permission control. Moreover, by matching the baseline parameter of position permissions with interface policies, a two-way mapping relationship between positions and interfaces is established, and the inherited permissions of sub-positions are extended to achieve refined and dynamically extensible permission allocation. Further analyzing the permission granularity and usage frequency to generate priority rules, promoting high-frequency and fine-grained permissions to the front of the adaptation queue to optimize system resource allocation. Finally, structured adaptation rule parameters are integrated to provide a quantitative basis for automated permission decision-making, cross-system risk control, and compliance auditing, driving the leap of multi-WEB systems from isolated permission management to global collaborative control and providing technical support for building a secure and efficient digital organization.
[0113] In one case of this embodiment, a dual-channel transmission decision-maker is constructed according to the organizational structure data, the interaction characteristics between WEB systems, and the cross-system adaptation rule parameters, and combined with real-time network status data to generate channel selection decision parameters, including:
[0114] Disassemble the organizational structure data to generate a table of communication demand intensity between departments, specifically including: cleaning the core fields such as department identifiers, names, parent department identifiers, and hierarchical codes in the organizational structure data, then analyzing department functions, hierarchies, and cross-system collaboration requirements based on department subordination relationships and cross-system mapping rules, evaluating the communication demand intensity between departments using a 1-5 scoring system, where 1 point represents extremely low demand and 5 points represent extremely high demand. Set a communication frequency threshold. If the communication frequency of this department is less than the communication frequency threshold, it proves that this department has independent functions and a relatively high level, and is rated 1 to 2 points; if the communication frequency of this department is equal to the communication frequency threshold, it proves that this department mainly focuses on internal communication and is rated 3 to 4 points; if the communication frequency of this department is greater than the communication frequency threshold, it proves that this department has frequent cross-departmental collaboration and is rated 5 points. Sort according to the scores from high to low to construct a table of communication demand intensity between departments, providing a quantitative basis for subsequent decision-making and analysis;
[0115] Score the interaction characteristics between WEB systems to form a transmission performance and security score table between systems, specifically including: collect the transmission delay and encryption method of each WEB system. Set the total transmission delay to be scored from 1 to 5 points. If the transmission delay is less than 100ms, it is scored 5 points; if it is between 100ms - 200ms, it is scored 4 points, and so on. For the encryption method, if AES - 256 is used, it is scored 5 points; if other methods are used, it is scored 3 points; if there is no encryption, it is scored 1 point. Finally, rank the scores according to the sum of the transmission delay and encryption method scores from high to low, and construct a transmission performance and security score table between systems to provide a quantitative basis for subsequent decision - making and analysis;
[0116] Based on the cross - system adaptation rule parameters and the transmission performance and security score table between systems, generate the channel constraint weight factor, specifically including: use the priority scores in the permission adaptation priority rule table as the basis for weight calculation. Obtain the transmission performance score and encryption method score of each system from the transmission performance and security score table between systems. Use these two scores as the weight factors for the two dimensions of transmission performance and security respectively. Then, combine the communication demand score in the inter - department communication demand intensity table and use it as the weight factor for the communication demand dimension. Finally, fuse these three - dimension weight factors through the weighted average method to generate the channel constraint weight factor. The calculation method of the weight factor is: channel constraint weight factor=(priority score of permission adaptation×0.5)+(transmission performance score×0.2)+(encryption method score×0.1)+(communication demand score×0.2);
[0117] Perform multi - dimensional fusion on the inter - department communication demand intensity table, the transmission performance and security score table between systems, and the channel constraint weight factor. Through the preset policy priorities, construct a dual - channel transmission decision - maker with dynamic decision - making ability, specifically including: take the inter - department communication demand intensity table, the transmission performance and security score table between systems, and the channel constraint weight factor as inputs. According to each priority, use the decision - tree algorithm for multi - dimensional fusion calculation to construct a dual - channel transmission decision - maker. The dual - channel transmission decision - maker will dynamically select the optimal transmission channel according to the current channel constraint weight factor and policy priorities. Among them, when the performance priority is the highest, the decision - maker will give priority to selecting the channel with the highest transmission performance score; when the security priority is the highest, the decision - maker will give priority to selecting the channel with the highest encryption method score; when the communication demand priority is the highest, the decision - maker will give priority to selecting the channel with the highest communication demand score;
[0118] Calculate the dual-channel transmission decision maker and real-time network status data to generate channel selection decision parameters, specifically including: The dual-channel transmission decision maker will obtain network status data in real time, such as network bandwidth, latency, packet loss rate, etc., combine these data with the channel constraint weight factor, and use the dynamic programming algorithm for calculation to generate channel selection decision parameters. The decision parameters include channel selection, transmission priority, encryption method, etc. Among them, when the network bandwidth is sufficient and the latency is low, the decision maker selects the channel with a higher transmission performance score and sets a higher transmission priority; when the network bandwidth is tight or the latency is high, the decision maker will select the channel with a higher communication demand score and set a lower transmission priority to ensure the smoothness of critical communications;
[0119] Through multi-dimensional quantitative analysis and dynamic decision-making algorithms, the intelligent level of data transmission between systems is significantly improved. By constructing a triple quantitative evaluation system (department communication intensity, system transmission performance, security encryption level), the organizational structure characteristics are transformed into computable decision factors, enabling channel allocation to shift from empirical judgment to data-driven; and innovating the channel constraint weight model, integrating four dimensions of permission priority, transmission performance, security level, and business requirements, and achieving multi-objective decision balance through the weighted average algorithm, which not only ensures the smoothness of high-frequency cross-departmental collaboration but also takes into account data encryption requirements; finally, introducing a real-time network status feedback mechanism to dynamically adjust the transmission priority and channel selection strategy, automatically opening a priority channel for critical services during network congestion and preferentially selecting high-performance links when the bandwidth is sufficient, forming a "business demand-driven + network adaptive" dual-wheel optimization mechanism. This decision maker not only improves the cross-system transmission efficiency but also achieves an accurate match between security policies and business requirements through quantitative scoring, providing quantifiable decision support for multi-system collaboration under complex organizational structures.
[0120] In one case of this embodiment, the synchronization engine is triggered based on the channel selection decision parameters to execute cross-system permission configuration, and at the same time, the permission tracker is used to associate the organizational entity topology parameters to generate timestamped permission propagation path parameters, including:
[0121] Eliminate the policy conflicts of the cross-system adaptation rule parameters to generate an enhanced permission descriptor, specifically including: By constructing a rule parameter conflict detection engine, automatically parse the conditional expressions, resource identifiers, and operation constraints in the permission policies of each system to generate a standardized policy fingerprint map, identify overlapping rules through fingerprint comparison, combine the conflict resolution principle of the main system priority, rank the priority of the conflict rules, and then inject the resolved rules into the permission descriptor to generate an enhanced permission descriptor;
[0122] Decompose the enhanced permission descriptor, generate an atomic permission operation queue according to the dependency relationships among WEB systems, specifically including: identifying the composite permission declarations in the enhanced permission descriptor through a semantic parsing engine, decomposing them into atomic operation sequences, establishing a dependency relationship graph of WEB systems, analyzing the service call chains, data flows, and permission inheritance relationships among systems, determining the priorities of permission operations, based on the dependency relationship graph, incorporating the decomposed atomic operations into the priority queue according to the topological sorting rules, and adding system identifiers, pre-dependency markers, and retry mechanisms to each operation. When generating the queue, automatically filter redundant operations and merge independent operations that can be executed in parallel, finally generating an efficient and deadlock-free atomic permission operation queue;
[0123] Encapsulate the atomic permission operation queue into a distributed configuration instruction set with a unique ID. When the WEB system API gateway sends a ready confirmation signal, trigger the synchronization engine to perform the final submission operation, specifically including: after generating the atomic permission operation queue, the system packages it into an instruction set with a unique identifier, clarifying the specific type, target system, and permission parameters of each operation. These instructions are shared in a distributed environment through a reliable transmission mechanism, and the API gateway of the WEB system is used as the permission configuration hub to monitor the status of each service in real time. After all associated systems complete initialization and send ready signals, immediately trigger the synchronization engine to start the submission process;
[0124] Among them, the synchronization engine adopts a two-step strategy of "verify first and then execute": first send pre-submission requests to each system to confirm the feasibility of the operations; after all systems confirm without errors, then uniformly execute the formal submission to update the permission configuration. The entire process is monitored by a permission tracker, which records the time and results of each permission change in real time. If an operation fails on a certain system, the system can quickly locate the problem instruction according to the unique identifier, automatically retry or prompt for manual processing to ensure the overall consistency of cross-system permission configuration;
[0125] Map the submitted distributed configuration instruction set to the organizational entity topology parameters to generate an initial propagation path framework, specifically including: after the distributed configuration instruction set is submitted, the system automatically associates each operation with the organizational structure data. First, parse the target system and permission parameters in the instruction, match the corresponding departments, roles, and resources in the organizational topology library to form an association relationship graph between operations and entities. Then, according to rules such as permission inheritance and exclusion, generate an initial propagation path framework that includes a starting point (original instruction), intermediate nodes (approval system, resource gateway), and an end point (target permission table), and add timestamps and dependency labels to each link. If the operation involves multi-system linkage, the path will clearly show the trigger order and data flow of each system in the form of a flowchart.
[0126] Analyze the initial propagation path framework to generate a sequence of propagation path nodes with version tags, specifically including: first, extract the timestamps, dependency relationships, and operation parameters of each node in the initial propagation path framework, construct a node dependency graph, then determine the execution order through a sorting algorithm to ensure that preconditions such as permission approval are executed first. Subsequently, generate version tags for the nodes. The major version number reflects major organizational structure adjustments, and the minor version number corresponds to permission rule changes. When the department structure is adjusted, the major version is upgraded, and when the permission validity period is modified, the revision number is updated. Finally, synthesize a sequence of propagation path nodes with version tags, which not only clarifies the execution path but also supports version comparison and fault rollback. This sequence makes the permission propagation process traceable and ensures the stability and reliability of the system;
[0127] Associate the sequence of propagation path nodes with the channel selection decision parameters and the organizational entity topology parameters to generate timestamped permission propagation path parameters, specifically including: first, match the version tags, execution order, and dependency relationships of the node sequence with the priorities and channel types in the channel selection parameters. For example, emergency nodes preferentially select message queues, and regular nodes use API interfaces. At the same time, refer to the department levels and role relationships in the organizational structure data to match specific propagation paths for the nodes, and automatically add approval nodes during cross-departmental operations. During the association, the system adds a millisecond-level timestamp to each node and compares it with the channel timeout threshold. Finally, generate timestamped permission propagation path parameters to form an auditable full-link record.
[0128] Achieve policy conflict resolution by constructing a standardized policy fingerprint map, significantly improve the efficiency of consistent management of permission rules, form an enhanced permission descriptor in combination with the principle of giving priority to the main system, effectively avoid permission redundancy or omission caused by policy overlap between multiple systems. Based on the atomic operation queue generation mechanism of the semantic parsing engine, optimize the execution sequence through topological sorting rules, and cooperate with the system dependency map to realize the coupling analysis of service call chains and data flows, making the priority allocation of permission operations more accurate. The redundant operation filtering and parallel execution merging mechanism can improve the configuration efficiency. The synchronization engine adopts a two-phase commit strategy of pre-verification - execution, combined with the API gateway status monitoring mechanism, to reduce the risk of execution failure while ensuring the integrity of distributed transactions. The full-link audit record formed by the permission tracker meets compliance requirements such as SOX, and the version tag system uses a three-segment identifier of major version number - minor version number - revision number to achieve accurate traceability of organizational structure adjustments, permission rule changes, and parameter modifications. Combined with the channel selection parameter matching algorithm, timestamps and dependency tags are automatically injected during the generation of cross-system propagation paths, forming time series data with millisecond-level accuracy, providing multi-dimensional decision-making basis for permission propagation performance analysis and root cause location of faults.
[0129] In a case of this embodiment, a policy executor is deployed at the permission management terminals of each WEB system, and the permission effective status is collected based on the timestamped permission propagation path parameters to generate distributed verification parameters, including:
[0130] Analyze the timestamped permission propagation path parameters to generate a timestamped propagation path tuple;
[0131] Parse the propagation path tuple to form a node hash chain, specifically including: extract the four elements of the propagation path tuple, the four elements include person, location, time, and relationship, convert the four elements into numerical nodes through a hash algorithm, and generate a time-series graph by sorting according to time. Each node hash value is calculated by the current tuple hash + the previous node hash to form a node hash chain;
[0132] Poll the permission status of the WEB system to generate a verification snapshot, specifically including: let the client obtain permission updates in real time through the long polling mechanism of the WEB system. The client sends a request to the server every 5 seconds and carries the timestamp of the last check. The server will detect whether the permission has changed. If a change is found, it will return a snapshot that only contains the changed part;
[0133] Combine the node hash chain with the verification snapshot to generate distributed verification parameters with a Merkle root signature, specifically including: slice the hash chain according to a time window, build a Merkle tree for each slice, take the root hash as the summary of this period, then perform an exclusive OR operation on each period summary and the corresponding verification snapshot to generate intermediate verification parameters, and then use the BLS aggregate signature algorithm to aggregate all intermediate parameters into a global root signature, so as to generate distributed verification parameters with a Merkle root signature. This signature supports batch verification, and the verifier only needs to save the latest root hash to complete the full-chain verification;
[0134] Intelligent upgrade of multi-system permission management is achieved by building a distributed permission verification system. First, an anti-tampering audit link is established. Based on the propagation path tuple, four elements of person, location, time, and relationship are extracted, and a time-series graph is generated through the hash algorithm. By combining the Merkle tree shard root hash with the exclusive OR operation of the verification snapshot, an immutable permission change record chain is formed. The BLS aggregation signature technology enables the verifier to complete the full-chain verification by only saving the latest root hash, improving the audit efficiency and reducing the compliance cost. Moreover, real-time status perception can be achieved. The long polling mechanism is used to trigger the permission status detection every 5 seconds, and the server only returns the incremental change snapshot, reducing a large amount of invalid data transmission compared with traditional polling. Combining with the timestamp propagation path parameter, the permission effective time point can be accurately located, and the abnormal response delay is compressed from the minute level to the second level. Finally, the cross-system collaboration efficiency is improved. The distributed verification parameters are automatically deployed at each terminal through the policy executor, and the network status is dynamically adapted in combination with the channel selection decision parameter, improving the success rate of permission configuration. Moreover, the Merkle tree root signature supports batch verification, and the verification time for millions of permission changes is shortened from the hour level to the millisecond level, providing quantifiable decision-making support for multi-system permission governance under complex organizational structures.
[0135] In one case of this embodiment, the multi-modal verification of the distributed verification parameters to generate a global permission synchronization achievement identification parameter includes:
[0136] The verification analysis of the distributed verification parameters is carried out to establish two modes, namely:
[0137] Real-time mode: The Merkle tree root value of the current permission data is collected at each WEB system permission management terminal by using the policy executor to obtain the core input parameter Merkle tree root value of the real-time mode;
[0138] By traversing the hash tree nodes layer by layer, the Merkle root values of all WEB systems are compared to obtain the number of different nodes with inconsistent hash values among systems. Specifically, it includes: First, obtain the Merkle root hash values of each WEB system. If there are different root values, mark the existence of global differences and trigger the next-layer comparison. The comparison process starts from the root node. The hash value of the current layer is split into a set of child node hashes by the binary method. For example, if the root node hash corresponds to the Kth layer, it is split into the sub-tree hashes of the (K - 1)th layer. The hash values of each split child node are compared across systems. When it is found that the hash value of a certain child node is inconsistent among at least two systems, record this node as a different node and enter its next-layer child nodes for continued splitting and comparison. For the completely consistent child node hash values, there is no need to continue splitting, and it is directly regarded as no difference in this branch. Eventually, the different paths will converge to the specific leaf node layer. At this time, the position of the inconsistent hash of the permission data block can be determined. Each leaf node corresponds to an original permission record. Furthermore, the number of different nodes with inconsistent hash values among systems can be obtained, and breadth-first traversal can be used to avoid repeated calculations. At the same time, when multiple systems share the same sub-tree hash, the deep comparison of this branch can be skipped to improve the comparison efficiency;
[0139] Judge whether the number of different nodes is 0. If it is 0, mark this permission as the real-time mode true synchronization status identifier; otherwise, mark it as the real-time mode false synchronization status identifier;
[0140] Batch mode: Use the policy executor to collect the version snapshot WAL logs generated during the permission synchronization process of each WEB system to obtain the core input parameter WAL logs of the batch mode. Concatenate the WAL logs of each WEB system in chronological order and identify the missing time segments in the log sequence to obtain the log fault rate. Specifically, when the core input parameter WAL logs of the batch mode are obtained, the awk tool can be used to sort and compare the concatenated logs to find discontinuous timestamps or sequence numbers, so as to identify the missing log segments. After identifying the missing segments, calculate the log fault rate through the following formula: Log fault rate = number of missing segments / total number of segments * 100%. Among them, the number of missing segments refers to the number of identified missing log segments, and the total number of segments refers to the concatenated logs;
[0141] Judge whether the log fault rate is ≤ 0.1%. If it is ≤ 0.1%, mark this permission as the batch mode true synchronization status identifier; otherwise, mark it as the batch mode false synchronization status identifier;
[0142] Associate and compare the real-time mode synchronization status identifier with the batch mode synchronization status identifier. When both modes are true, generate the global permission true synchronization achievement identifier parameter;
[0143] If the synchronization achievement identification parameter of any of the two modes is false, a global permission false synchronization achievement identification parameter is generated.
[0144] By integrating real-time and batch verification modes, the accuracy and reliability of the permission synchronization system are significantly improved. The real-time mode is based on the Merkle tree layer-by-layer hash comparison to quickly locate the nodes with different permissions across systems. The binary splitting strategy is combined to optimize the comparison efficiency and ensure that exceptions are responded to in seconds. The batch mode uses WAL log splicing analysis to accurately identify the log fault rate within 0.1% and form a historical synchronization audit chain. The dual-mode complementary mechanism not only ensures the consistency of the current state, but also realizes long-term data integrity verification. The BLS aggregate signature technology is used to build a tamper-proof audit link. This solution upgrades the traditional passive verification to an active defense system, supports intelligent decision-making in a dynamic network environment, and provides quantitative and traceable synchronization guarantees for the permission governance of complex organizational structures, effectively balancing security and operational efficiency.
[0145] In one case of this embodiment, if the global permission synchronization achievement identification parameter is false, a compensation instruction queue is generated, and based on the compensation instruction queue, a permission panoramic situation parameter is generated, including:
[0146] Extract the timestamped permission propagation path parameters and distributed verification parameters to generate the root cause feature vector of the fault conduction path, including: extracting the timestamp sequence, node hash value, and propagation path tuple from the permission propagation path parameters, combining the Merkle tree root hash, node hash chain, and verification snapshot in the distributed verification parameters to construct a multi-dimensional feature vector, and by analyzing the timestamp deviation, hash value conflict point, and abnormal fragments in the verification snapshot, generate a root cause feature vector containing error types, including configuration timeout, hash conflict, impact range, and time window;
[0147] The root cause feature vector and the cross-system adaptation rule parameters are mapped by rules, and a compensation instruction queue containing a repair action sequence is generated based on the permission interface strategy, specifically including: matching the error type in the root cause feature vector with the permission priority and transmission channel constraint weight in the cross-system adaptation rule; if the fault is caused by network delay and configuration timeout, the backup high-performance channel is automatically selected according to the transmission performance score in the channel constraint weight factor; if the permission is not effective due to hash conflict, the retry mechanism of the atomic permission operation queue is triggered, and the API endpoint, request method, and authentication information in the permission interface strategy are combined to generate an instruction queue containing specific repair actions to ensure that the instructions can be accurately mapped to the faulty node.
[0148] Generate the panoramic situation parameters of permissions based on the compensation instruction queue, specifically including: associating the root cause features such as the repair action sequence, timestamp deviation, and hash conflict points in the compensation queue with the metadata of the permission propagation path, constructing a three-dimensional situation model including the distribution of faulty nodes, the heat map of the influence range, and the repair timeliness, and using the time series analysis algorithm to monitor the channel switching and retry mechanism trigger frequency in the instruction queue in real time to generate the panoramic situation parameters of permissions;
[0149] Based on the panoramic situation parameters of permissions, encapsulate the post permission baseline parameters and cross-system adaptation rule parameters into the policy library of the self-service application interface, specifically including: converting the fault features, repair actions, channel performance, etc. in the panoramic situation parameters of permissions into standardized data, establishing the mapping relationship between the permission status and the policy rules, adopting the policy-as-code mode, orthogonally combining the post permission baseline and the cross-system adaptation rules, dynamically generating a logic tree including conditional judgments, and then embedding the conflict resolution rules. When multiple rules are triggered, make a decision based on the three-level priorities of business criticality, system compatibility, and execution efficiency, where business criticality > system compatibility > execution efficiency to ensure the feasibility of the policy. Then encapsulate the policy library into a RESTful API service, provide policy query, pre-check, and execution endpoints. When the user applies, the interface dynamically calculates the available policy set and returns a policy package containing specific parameters and a compliance proof chain;
[0150] When the user initiates a permission application, call the global permission synchronization to achieve the identification parameters through the real-time status query algorithm;
[0151] If the global permission synchronization to achieve the identification parameter is true, representing that the permission statuses of all WEB systems are consistent, then trigger the permission life cycle generator, match the user request with the post permission baseline, generate the permission life cycle parameters, and mark the "synchronization validity" in the permission life cycle parameters as passed;
[0152] If the identification is false, representing that there are inconsistent permission statuses in all WEB systems, then terminate the process through the exception interception algorithm, generate the permission life cycle parameters, and mark the "synchronization validity" in the permission life cycle parameters as rejected.
[0153] The collaborative and self-healing capabilities of multi-WEB system permission management are significantly enhanced through an intelligent fault handling and policy encapsulation mechanism. When global permission synchronization is abnormal, the system can automatically extract key verification parameters such as timestamps and hash chains in the propagation path tuple, construct a multi-dimensional root cause feature vector to accurately identify fault types such as configuration timeouts and hash conflicts; dynamically generate a compensation instruction queue based on cross-system adaptation rules to ensure that repair instructions are accurately mapped to fault nodes. The system drives the generation of a three-dimensional situation model through the compensation queue, quantifies the fault distribution, impact scope, and repair progress in real time, and generates visual decision support such as heat maps; further fuses the situation parameters with permission baselines and adaptation rules and encapsulates them into a self-service API policy library, generates a logic tree with conditional judgments in a policy-as-code mode, and embeds a three-level priority conflict resolution mechanism, enabling the permission application interface to have context awareness capabilities. The returned policy package not only meets compliance requirements but also adapts to complex multi-system environments, significantly enhancing the resilience of permission control under complex organizational structures.
[0154] Reference Figure 2 , A cross-platform permission unified management system based on multi-WEB systems, including:
[0155] Parsing module: Obtain the organizational structure data of the enterprise system, parse the organizational structure data, construct a multi-level tree-shaped topology network, and form organizational entity topology parameters;
[0156] Position permission module: Parse the organizational entity topology parameters to generate position permission baseline parameters;
[0157] Permission interface module: Extract the API gateways of each WEB system to generate permission interface policies, calculate the position permission baseline parameters, and generate cross-system adaptation rule parameters;
[0158] Channel selection module: Construct a dual-channel transmission decision maker based on the organizational structure data, interaction characteristics between each WEB system, and cross-system adaptation rule parameters, and generate channel selection decision parameters in combination with real-time network status data;
[0159] Permission propagation module: Trigger the synchronization engine to execute cross-system permission configuration based on the channel selection decision parameters, and at the same time generate timestamped permission propagation path parameters by associating the organizational entity topology parameters through the permission tracker;
[0160] Permission effectiveness module: Deploy a policy executor at the permission management terminals of each WEB system, and collect the permission effectiveness status based on the timestamped permission propagation path parameters to generate distributed verification parameters;
[0161] Permission synchronization module: Perform multi-modal verification on the distributed verification parameters to generate global permission synchronization achievement identification parameters;
[0162] Panoramic module: When the global permission synchronization achievement flag parameter is false, generate a compensation instruction queue, and generate a permission panoramic situation parameter based on the compensation instruction queue.
[0163] Although the embodiments of the present invention have been shown and described, those of ordinary skill in the art can understand that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principle and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.
Claims
1. Cross-platform permission unified management method based on multiple WEB systems, characterized in that The method includes: S1: Obtain the organizational structure data of the enterprise system, parse the organizational structure data, construct a multi-level tree-shaped topology network, and form organizational entity topology parameters; S2: Parse the organizational entity topology parameters to generate job permission baseline parameters; S3: Extract the API gateways of each WEB system to generate permission interface policies, calculate the job permission baseline parameters, and generate cross-system adaptation rule parameters; S4: Construct a dual-channel transmission decision maker based on the organizational structure data, the interaction characteristics between WEB systems, and the cross-system adaptation rule parameters, and generate channel selection decision parameters in combination with real-time network status data; S5: Trigger the synchronization engine to execute cross-system permission configuration based on the channel selection decision parameters, and at the same time, associate the organizational entity topology parameters through the permission tracker to generate timestamped permission propagation path parameters; S6: Deploy a policy executor at the permission management terminal of each WEB system, and collect the permission effective status based on the timestamped permission propagation path parameters to generate distributed verification parameters; S7: Perform multi-modal verification on the distributed verification parameters to generate a global permission synchronization achievement identification parameter; S8: If the global permission synchronization achievement identification parameter is false, generate a compensation instruction queue, and generate a permission panoramic situation parameter based on the compensation instruction queue.
2. The cross-platform permission unified management method based on a multi-WEB system according to claim 1, characterized in that, The obtaining of the organizational structure data of the enterprise system, parsing the organizational structure data, constructing a multi-level tree-shaped topology network, and forming organizational entity topology parameters includes: Perform standardization processing on the organizational structure data, where the organizational structure data includes: department identifier, name, parent department identifier, hierarchical code, and cross-system identifier; Extract the core fields from the organizational structure data, establish the department subordination relationship, and generate cross-system mapping rules with the department subordination relationship as the link; Starting from the root node of the organizational structure, recursively generate a multi-level tree-shaped network; Analyze the multi-level tree-shaped network to form organizational entity topology parameters that describe the full-dimensional characteristics of the organization.
3. The cross-platform permission unified management method based on a multi-WEB system according to claim 2, characterized in that, The parsing of the organizational entity topology parameters to generate job permission baseline parameters includes: Parse the organizational entity topology parameters to establish initial job-permission association data; Integrate the department subordination relationship and cross-system mapping rules to generate a job relationship network diagram with permission weights; Traverse the job relationship network diagram, calculate the job permission inheritance relationship layer by layer, and form a complete permission set; Perform permission elimination on the complete permission set and perform matrix conversion on it to generate job permission baseline parameters.
4. The cross-platform permission unified management method based on a multi-WEB system according to claim 3, wherein, The extraction of the API gateways of each WEB system to generate permission interface policies, calculation of the job permission baseline parameters, and generation of cross-system adaptation rule parameters includes: Extract the routing rules, authentication information, and permission control policies of the API gateways of each WEB system to generate preliminary permission interface policies; Use cross-system mapping rules to map and transform the preliminary permission interface policies to generate permission interface policies adapted to multiple systems; Match the job permission baseline parameters with the permission interface policy set to generate a permission mapping relationship; Analyze the permission granularity differences and usage frequencies between WEB systems to generate a permission adaptation priority rule table; Integrate the permission mapping relationship, the permission adaptation priority rule table, and the constraint condition table to generate cross-system adaptation rule parameters.
5. The cross-platform permission unified management method based on a multi-WEB system according to claim 4, characterized in that Construct a dual-channel transmission decision maker based on the organizational structure data, the interaction characteristics between WEB systems, and the cross-system adaptation rule parameters, and generate channel selection decision parameters in combination with real-time network status data, including: Decompose the organizational structure data to generate a table of communication demand intensities between departments; Score the interaction characteristics between WEB systems to form a table of transmission performance and security scores between systems; Generate channel constraint weight factors based on the cross-system adaptation rule parameters and the table of transmission performance and security scores between systems; Multidimensionally integrate the table of communication demand intensities between departments, the table of transmission performance and security scores between systems, and the channel constraint weight factors, and construct a dual-channel transmission decision maker with dynamic decision-making capabilities through preset policy priorities; Calculate the dual-channel transmission decision maker and the real-time network status data to generate channel selection decision parameters.
6. The cross-platform permission unified management method based on a multi-WEB system according to claim 5, characterized in that Trigger the synchronization engine to execute cross-system permission configuration based on the channel selection decision parameters, and at the same time generate timestamped permission propagation path parameters by associating the organization entity topology parameters through the permission tracker, including: Eliminate the policy conflicts of the cross-system adaptation rule parameters to generate enhanced permission descriptors; Decompose the enhanced permission descriptors and generate an atomic permission operation queue according to the dependencies between WEB systems; Encapsulate the atomic permission operation queue into a distributed configuration instruction set with a unique ID, and trigger the synchronization engine to execute the final submission operation when the WEB system API gateway feedbacks a ready confirmation signal; Map the submitted distributed configuration instruction set to the organization entity topology parameters to generate an initial propagation path framework; Analyze the initial propagation path framework to generate a sequence of propagation path nodes with version markers; Associate the sequence of propagation path nodes with the channel selection decision parameters and the organization entity topology parameters to generate timestamped permission propagation path parameters.
7. The cross-platform permission unified management method based on a multi-WEB system according to claim 6, characterized in that, Deploy a policy executor at the permission management terminals of each WEB system, and collect the permission effective status based on the timestamped permission propagation path parameters to generate distributed verification parameters, including: Analyze the timestamped permission propagation path parameters to generate timestamped propagation path tuples; Parse the propagation path tuples to form a node hash chain; Poll the permission status of the WEB system to generate a verification snapshot; Combine the node hash chain with the verification snapshot to generate distributed verification parameters with a Merkle root signature.
8. The cross-platform permission unified management method based on a multi-WEB system according to claim 7, characterized in that, Perform multimodal verification on the distributed verification parameters to generate a global permission synchronization achievement identification parameter, including: Perform verification analysis on the distributed verification parameters to establish two modes, namely: Real-time mode: Use the policy executor to collect the Merkle root value of the current permission data at the permission management terminals of each WEB system to obtain the core input parameter Merkle root value of the real-time mode; Compare the Merkle root values of all WEB systems by traversing the hash tree nodes layer by layer to obtain the number of different nodes with inconsistent hash values between systems; Determine whether the number of different nodes is 0. If it is 0, mark this permission as the real-time mode true synchronization status identifier; otherwise, mark it as the real-time mode false synchronization status identifier. Batch mode: Use the policy executor to collect the version snapshot WAL logs generated during the permission synchronization process of each WEB system, obtain the core input parameter WAL logs in batch mode, splice the WAL logs of each WEB system in chronological order, identify the missing time segments in the log sequence, and obtain the log fault rate. Determine whether the log fault rate is ≤ 0.1%. If it is ≤ 0.1%, mark this permission as the batch mode true synchronization status identifier; otherwise, mark it as the batch mode false synchronization status identifier. Associate and compare the real-time mode synchronization status identifier with the batch mode synchronization status identifier. When both modes are true, generate the global permission true synchronization achievement identifier parameter. If any one of the synchronization achievement identifier parameters of the two modes is false, generate the global permission false synchronization achievement identifier parameter.
9. The cross-platform permission unified management method based on a multi-WEB system according to claim 8, characterized in that, When the global permission synchronization achievement identifier parameter is false, generate a compensation instruction queue. Based on the compensation instruction queue, generate the permission panoramic situation parameter, including: Extract the timestamped permission propagation path parameter and the distributed verification parameter to generate the root cause feature vector of the fault conduction path. Perform rule mapping on the root cause feature vector and the cross-system adaptation rule parameter, and generate a compensation instruction queue containing the repair action sequence based on the permission interface policy. Generate the permission panoramic situation parameter based on the compensation instruction queue. Based on the permission panoramic situation parameter, encapsulate the position permission baseline parameter and the cross-system adaptation rule parameter into the policy library of the self-service application interface. When the user initiates a permission application, call the global permission synchronization achievement identifier parameter through the real-time status query algorithm. If the global permission synchronization achievement identifier parameter is true, indicating that the permission status of all WEB systems is consistent, trigger the permission life cycle generator, match the user request with the position permission baseline, generate the permission life cycle parameter, and mark the "synchronization validity" in the permission life cycle parameter as passed. If the identifier is false, indicating that there are inconsistent permission statuses in all WEB systems, terminate the process through the exception interception algorithm, generate the permission life cycle parameter, and mark the "synchronization validity" in the permission life cycle parameter as rejected.
10. A cross-platform permission unified management system based on a multi-WEB system, which is applied to the cross-platform permission unified management method based on a multi-WEB system according to any one of claims 1-9, and is characterized in that, Including: Parsing module: Obtain the organizational structure data of the enterprise system, parse the organizational structure data, construct a multi-level tree-shaped topology network, and form the organizational entity topology parameter. Position permission module: Parse the organizational entity topology parameter to generate the position permission baseline parameter. Permission interface module: Extract the API gateways of each WEB system to generate the permission interface policy, calculate the position permission baseline parameter to generate the cross-system adaptation rule parameter. Channel selection module: Construct a dual-channel transmission decision maker according to the organizational structure data, the interaction characteristics between each WEB system, and the cross-system adaptation rule parameter, and generate the channel selection decision parameter in combination with the real-time network status data. Permission Propagation Module: Trigger the synchronization engine to execute cross-system permission configuration based on the channel selection decision parameters, and at the same time generate timestamped permission propagation path parameters by associating the organizational entity topology parameters through the permission tracker; Permission Effectiveness Module: Deploy a policy executor at the permission management terminal of each WEB system, and collect the permission effectiveness status based on the timestamped permission propagation path parameters to generate distributed verification parameters; Permission Synchronization Module: Perform multimodal verification on the distributed verification parameters to generate a global permission synchronization achievement identification parameter; Panoramic Module: If the global permission synchronization achievement identification parameter is false, generate a compensation instruction queue, and generate permission panoramic situation parameters based on the compensation instruction queue.
Citation Information
Patent Citations
Integrated information security system supporting multi-platform environment
CN119835079A
Privilege management and revocation
US20160188847A1