Access control method based on attribute constraint

By introducing a task role access control model (A-TRBAC) based on attribute constraints, combining role manager, task manager and permission manager to dynamically manage permissions, the flexibility and fine-grained permission management problems in cloud computing environments are solved, and secure and effective access control is achieved.

CN120234792APending Publication Date: 2025-07-01XIAN TECH UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510305979.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-14
Publication Date
2025-07-01

AI Technical Summary

Technical Problem

The existing access control model has problems in the cloud computing environment, such as insufficient flexibility, insufficient permission management, insufficient multi-tenant isolation and insufficient permission audit, especially in dynamic permission management and cross-regional access control.

Method used

The task role access control model (A-TRBAC) based on attribute constraints is introduced. By introducing role manager, task manager and permission manager, combining the attribute constraints of users and tasks, we can dynamically manage permissions, ensuring that only users with relevant qualifications and abilities can execute tasks and obtain permissions, and permissions will be automatically recycled after the task is completed.

Benefits of technology

It realizes flexible permission management, avoids abuse of permissions, ensures that each user can only access resources related to their tasks, provides dynamic and fine-grained access control, and improves the security and management efficiency of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120234792A_ABST
    Figure CN120234792A_ABST
Patent Text Reader

Abstract

The invention provides an attribute constraint-based access control method, which comprises the following steps of: in response to a task request which is initiated by a user and carries a user role attribute through a task manager, verifying the authority of the user according to the user role attribute of the user and the task attribute of a target task requested to be executed by the user on the basis of a preset constraint rule; the user role attribute is preset through a role manager, and the task attribute is preset through a task manager; if the verification is passed, the task manager allocates the target task to the user; the permission manager grants the permission of executing the target task to the user, the task, the role and the user are associated, flexible permission management is achieved, the permission is dynamically allocated according to the role attribute and the task requirement of the user, it can be ensured that each user can only access resources related to the task of the user, the permission abuse problem is avoided, and the user experience is improved. And dynamic and flexible authority management and fine-grained access control are realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and particularly relates to an access control method based on attribute constraints. Background Art

[0002] As an important part of modern information technology, cloud computing has been widely applied in various enterprises and organizations. Through cloud computing, users can achieve on-demand allocation and use of computing resources, greatly improving resource utilization and system flexibility. However, with the popularization of cloud computing, the security issues of data and resources have become prominent. Due to the highly shared and dynamic nature of the cloud computing environment, users can access resources anytime and anywhere through the Internet. Therefore, ensuring data security, resource isolation, permission management, etc. have become core challenges in cloud computing. Among these issues, the access control model plays a crucial role, which is responsible for determining who can access which resources in the cloud and in what way.

[0003] The access control model is an extremely important part of the information security system, which determines whether a user can access a specific resource and what operations can be performed. The early access control models mainly consisted of mandatory access control (MAC) and discretionary access control (DAC). However, the limitation of the MAC model is the lack of flexibility. Users cannot flexibly adjust permissions according to their needs and cannot adapt to changes in the business environment or dynamic tasks. The DAC model was widely used in early operating systems and file systems, but its security is relatively low, which is prone to misuse and abuse of permissions. With the expansion of the scale of computing systems and the improvement of security requirements, the limitations of MAC and DAC have gradually emerged, and new models have emerged.

[0004] To address the deficiencies of early models, the Role-Based Access Control (RBAC) model became one of the most widely used models in the 1990s. In the RBAC model, users obtain corresponding permissions by being assigned to one or more roles. Permissions are associated with roles rather than directly bound to users. This design greatly simplifies the complexity of permission management. Especially in large organizations, it enables administrators to efficiently allocate and adjust permissions. When a user's responsibilities change, only their role needs to be adjusted to achieve dynamic permission management, without the need to change user permissions one by one. The advantages of RBAC lie in its simplicity in management and strong scalability, especially suitable for static or relatively stable environments in enterprises and institutions. However, RBAC has certain limitations in fine-grained permission management and dynamic permission adjustment. The mapping between its roles and permissions is usually pre-set, so it appears less flexible when dealing with the rapid changes in permission requirements in complex environments. In addition, the "role explosion" phenomenon is prone to occur in the RBAC model. That is, to meet the permission requirements of different users, the system has to create a large number of roles, increasing the management burden.

[0005] Another one is the Task-Based Role Access Control (T-RBAC) model, which combines the traditional Role-Based Access Control (RBAC) model and a task-based dynamic permission management mechanism. T-RBAC is developed on the basis of the RBAC model. By associating permissions with specific tasks instead of directly assigning them to users or roles, it enhances the dynamicity and flexibility of permission management. Although the T-RBAC (Task-Based Role Access Control) model has significant advantages in dynamic permission management and task-driven permission allocation, it still has obvious limitations in dealing with complex cloud computing environments, fine-grained permission management, and multi-tenant isolation. Summary of the Invention

[0006] To solve the above problems existing in the prior art, the present invention provides an access control method based on attribute constraints, specifically including:

[0007] In a first aspect, the present invention provides an access control method based on attribute constraints, which is applied to a task role access control model based on attribute constraints. This model includes:

[0008] A role manager, a task manager, and a permission manager;

[0009] This method includes:

[0010] The task manager, in response to a task request carried with user role attributes initiated by a user, verifies the user's permissions based on preset constraint rules according to the user's user role attributes and the task attributes of the target task that the user requests to execute, where the user role attributes are pre-set by the role manager and the task attributes are pre-set by the task manager;

[0011] If the verification passes, the task manager assigns the target task to the user;

[0012] The permission manager grants the user the permission to execute the target task.

[0013] In a second aspect, the present invention further provides an electronic device, including a processor, a communication interface, a memory, and a communication bus. Among them, the processor, the communication interface, and the memory complete communication with each other through the communication bus;

[0014] The memory is used to store a computer program;

[0015] The processor, when executing the program stored on the memory, implements any method provided in the first aspect.

[0016] In a third aspect, the present invention provides a computer-readable storage medium, in which a computer program is stored, and when the computer program is executed by a processor, it implements any method provided in the first aspect.

[0017] In a fourth aspect, the present invention provides a program product, where the program product includes computer program instructions, and when the computer program instructions are executed, they can implement any method provided in the first aspect.

[0018] Advantages of the present invention:

[0019] The access control method based on attribute constraints provided by the present invention, through the task manager responding to a task request carried with user role attributes initiated by a user, based on preset constraint rules, according to the user's user role attributes and the task attributes of the target task that the user requests to execute, verifies the user's permissions, where the user role attributes are pre-set by the role manager and the task attributes are pre-set by the task manager; if the verification passes, the task manager assigns the target task to the user; the permission manager grants the user the permission to execute the target task, associates tasks, roles, and users, realizes flexible permission management, and by dynamically allocating permissions according to the user's role attributes and task requirements, can ensure that each user can only access resources related to their tasks, avoid the problem of permission abuse, and realize dynamic, flexible permission management and fine-grained access control.

[0020] The present invention will be further described in detail below in conjunction with the accompanying drawings and embodiments. Description of the Drawings

[0021] Figure 1 It is a schematic diagram of an A-TRBAC architecture provided by the present invention;

[0022] Figure 2 It is a schematic flowchart of an access control method based on attribute constraints provided by the present invention. Detailed Embodiments

[0023] The present invention will be further described in detail below in conjunction with specific embodiments, but the embodiments of the present invention are not limited thereto.

[0024] In the cloud computing environment, traditional access control technologies face many new challenges. First, cloud computing usually adopts a multi-tenant architecture, which means that while multiple tenants share the same cloud computing infrastructure, their respective data and resources need to be strictly isolated to prevent unauthorized access. This multi-tenant environment poses higher requirements on access control technologies, not only to ensure the data security of each tenant, but also to ensure that there are no conflicts in resource access between different tenants. Second, the dynamic nature of cloud computing makes the allocation and usage methods of resources more complex, and the permission requirements of users also change continuously with the tasks and environment. Therefore, access control policies must have the ability to be dynamically updated to adjust users' permissions in real time to cope with the addition, reduction, or transfer of resources. For example, when a user starts a new virtual machine or increases storage capacity, the system needs to be able to immediately allocate corresponding permissions and reclaim the permissions in a timely manner after the task is completed to avoid permission abuse. In addition, the global nature of cloud computing makes cross-regional access and data sharing common requirements. Many cloud service providers have multiple data centers globally, and users can access the same cloud resources from different geographical locations. This requires access control technologies to not only handle local permission management, but also support cross-regional authentication and permission control. In this case, access control policies need to consider the laws, regulations, and compliance requirements of different regions to ensure that when cross-border data sharing occurs, the user's permission settings comply with local security policies. In the cloud computing environment, the complexity of access control is not only reflected in the number of users and resources, but also in how to achieve fine-grained permission management. There are various types of resources in cloud computing, including virtual machines, storage, databases, network resources, etc., and each type of resource may correspond to different operation permissions. For example, a user may need read permissions for storage resources, while for virtual machines, they need start and stop permissions. To meet these complex requirements, access control technologies must be able to finely manage each user's access permissions to specific resources to ensure that users can only perform authorized operations, thereby preventing unnecessary permission spread or abuse.

[0025] As the most advantageous existing access control model, T-RBAC combines the traditional Role-Based Access Control model (RBAC) and the task-based dynamic permission management mechanism. T-RBAC enhances the dynamicity and flexibility of permission management by associating permissions with specific tasks instead of directly assigning them to users or roles. In the traditional RBAC model, permissions are assigned through the mapping of roles to users. The advantage of RBAC lies in simplifying permission management in complex systems. Especially in enterprise organizations, administrators can reduce the management burden by assigning roles to users instead of assigning permissions one by one. However, a key limitation of the RBAC model is its static nature. The binding relationship between roles and permissions is fixed in the system. Once a role is assigned, users will have the corresponding permissions for a long time. This is not flexible enough in scenarios that require dynamic permission management such as cloud computing and workflow management. Especially when it comes to adjusting permissions according to the progress of tasks or the real-time status of users, RBAC seems inadequate. The T-RBAC model introduces a task hierarchy on the basis of RBAC, associating permissions with tasks rather than directly with roles or users. When a user undertakes a certain role, they will only obtain the permissions required to execute the task under the assigned task. Once the task is completed, the user's permissions will be automatically revoked. This task-driven mechanism greatly enhances the system's control ability over permissions. For example, in enterprise project management, developers have code modification permissions when executing development tasks, but after the task ends, the permissions are automatically revoked to prevent users from continuing to operate system resources after the task is completed. This approach not only solves the problems of permission retention and over-authorization in RBAC but also can dynamically assign permissions when tasks change, ensuring that each role can only access relevant resources during task execution. In T-RBAC, the core feature of the system is task-based permission assignment and revocation, which is in sharp contrast to the static permission assignment mechanism of RBAC. In the T-RBAC model, users' permissions are closely associated with the task life cycle, and the system will adjust users' permissions in real time according to the task status (such as start, pause, complete). This makes T-RBAC very suitable for systems that require strict management of the permission life cycle, such as workflow management systems, cloud computing platforms, and multi-tenant environments.

[0026] Although T-RBAC has significant advantages in dynamic permission management and task-driven permission assignment, it still has obvious limitations in dealing with complex cloud computing environments, fine-grained permission management, and multi-tenant isolation. Its deficiencies in flexibility, refined control, and security are mainly manifested in the following aspects:

[0027] First, the T-RBAC model has the problem of static binding in the relationship between tasks and roles. Although T-RBAC realizes relatively flexible permission allocation by associating tasks with roles, this binding relationship is still relatively rigid and difficult to cope with the real-time dynamic changes of tasks, roles, or permissions. In a complex cloud computing environment, the tasks and roles of users may need to be adjusted at any time, but T-RBAC lacks a real-time response mechanism in this process. For example, when a task changes urgently or a new role is introduced, the static role-task binding method of T-RBAC cannot quickly adjust the permission configuration, resulting in untimely system response and reducing work efficiency and security.

[0028] Second, there are certain security risks in the permission isolation of the T-RBAC model in a multi-tenant system. In a multi-tenant environment, strict permission isolation is required between different tenants to prevent cross-tenant permission abuse or data leakage. However, the T-RBAC model does not fully consider the attribute differences between tenants and relies only on the static relationship between tasks and roles, making it difficult to achieve fine-grained permission isolation between tenants. This may cause users of a certain tenant to accidentally obtain unauthorized permissions through the mapping of roles and tasks, thus endangering system security.

[0029] Finally, the T-RBAC model is insufficient in terms of permission auditing and security analysis. Although the T-RBAC model has advantages in task-driven permission allocation, it lacks fine-grained permission auditing and security analysis functions and cannot monitor and analyze the usage of permissions in real time. This results in the difficulty of timely discovery of security issues such as permission abuse or unauthorized access in a complex cloud computing environment.

[0030] To solve the problems existing in the prior art, the present invention provides an Attribute-Constrained Task-Role Based Access Control model (A-TRBAC), as Figure 1 shown. By extending the traditional RBAC, A-TRBAC expands its three-layer structure (user-role-permission) to a four-layer structure (user-role-task-permission), introduces "task" as an intermediate layer, and adopts an attribute constraint mechanism to enhance the flexibility and security of the system. In this model, users obtain tasks through roles and then obtain corresponding permissions by completing the tasks. Each task is associated with specific permissions, and users can only execute the task and obtain the corresponding permissions after meeting the attribute constraint conditions of the task.

[0031] Specifically, A-TRBAC proposes three managers: (1) Role Manager (RM), which is used for the dynamic management and monitoring of roles. It can supervise roles after activation, records the behaviors and permission statuses of all roles for completing the entire task, and can impose constraints on roles. (2) Task Manager (TM), which is used to manage and monitor task status, dynamically adjust and allocate tasks, combine tasks with context, and can determine whether to assign a certain task to a certain user according to attributes, task constraints, etc. (3) Permission Manager, which is used to assign and revoke permissions to prevent the "once-activated-and-permanently-used" permissions of roles.

[0032] In addition, A-TRBAC also introduces the concept of the Attribute-Based Access Control Model (ABAC). When a user obtains a task through a role, not only does the role need to match the task, but the user also needs to meet the attribute requirements of the task for the user. The attributes of the user describe the qualifications and capabilities of the user to complete the task, while the attributes of the task describe the requirements for the qualifications and capabilities of the user to complete the task. This method ensures that only users who meet the attribute constraints can be assigned specific tasks. By introducing attribute constraints, the security and accuracy of task assignment and permission granting can be effectively improved, ensuring that only users with the necessary qualifications and capabilities can execute specific tasks and obtain relevant permissions accordingly.

[0033] Specifically, an access control method based on attribute constraints provided by the present invention is applied to a Figure 1 task-role access control model based on attribute constraints as shown. The task-role access control model based on attribute constraints can be applied to actual scenarios, such as financial systems, attendance systems, etc. The model includes: a role manager, a task manager, and a permission manager.

[0034] As Figure 2 shown, the method includes:

[0035] S201. In response to a task request carrying the user role attributes initiated by a user, the task manager verifies the user's permissions based on preset constraint rules according to the user role attributes of the user and the task attributes of the target task requested by the user to be executed. The user role attributes are preset through the role manager, and the task attributes are preset through the task manager.

[0036] Introducing the concept of attributes can strengthen the constraints on users and prevent users without qualifications from being wrongly assigned relevant tasks. Among them, the user role attributes of the user represent the qualifications of the user, and the task attributes of the task represent the qualification requirements for completing the task.

[0037] Specifically, the user role attributes are pre-set. They can be pre-assigned by an administrator or pre-set by the task role access control model based on attribute constraints according to the corresponding characteristic information of the user.

[0038] Optionally, the user role attributes are pre-set by a role manager.

[0039] The process of setting user role attributes includes: the role manager, in response to the received role request message, sets the user role attributes for the corresponding user according to the characteristic information of the user carried in the role request message.

[0040] The characteristic information of the user can be the user's work number, name, age, years of service, position, hobbies, etc. It can be determined according to the actual situation and is not specifically limited here.

[0041] According to different classification methods, the user role attributes can correspond to different contents. For example, they can be administrators, members, etc., or data analysts, verification personnel, developers, etc., without specific limitations.

[0042] Task attributes can include the importance of the task, the priority of the task, the sensitivity of the data, the user roles suitable for the task, etc.

[0043] The task attributes corresponding to any task can be pre-set manually by an administrator or pre-set by the task role access control model based on the characteristic information corresponding to the task.

[0044] Optionally, the task attributes are pre-set by a task manager.

[0045] The process of setting task attributes includes: the task manager, in response to the received task attribute definition request message, determines the permissions of the task according to the characteristic information of the task to be defined, and defines the task attributes of the task according to the permissions of the task.

[0046] Optionally, the preset constraint rules include: conflicting roles are not assigned to the same user; conflicting users are not assigned conflicting roles; conflicting roles are not assigned the same task; conflicting permissions are not assigned to the same task; the maximum number of users owned by a role does not exceed the user base of the role; the same user is not allowed to execute conflicting tasks.

[0047] Exemplarily, r1∈CR∧r2∈CR => u(r1) = u(r2) means that if r1 and r2 belong to conflicting roles, then the users assigned to r1 and r2 are not the same.

[0048] For example, in a financial system, the declarer and the approver are conflicting roles.

[0049] It means that the intersection of conflicting users and conflicting role users is empty, that is, conflicting users cannot be assigned conflicting roles.

[0050] For example, the person who needs to submit an expense account and the person who audits the accounts are conflicting users.

[0051] r1∈CR∧r2∈CR∧t∈T => r1(t) = r2(t) means that the same task cannot be assigned to conflicting roles.

[0052] p1∈CP∧p2∈CP∧t∈T => p1(t) = p2(t) means that the same task cannot be assigned conflicting permissions.

[0053] The maximum number of users owned by a role cannot exceed the user base of the role. |u(r)| < max_u(r) means that the maximum number of users owned by a role cannot exceed the user base of the role.

[0054] In the above rules, p represents permissions, r represents roles, and u represents users.

[0055] CR = {cri|i = 1,2,...n} is defined as the set of conflicting roles, which contains the roles with conflicting relationships in the system.

[0056] CT = {cti|i = 1,2,...n} is defined as the set of conflicting tasks, which identifies the tasks that conflict with each other in the system.

[0057] CP = {cpi|i = 1,2,...n} is defined as the set of conflicting permissions, which lists all the conflicting permissions in the system.

[0058] CU = {cui|i = 1,2,...n} is defined as the set of conflicting users, which contains the users who may have conflicts in the system.

[0059] max_u(r) refers to the maximum number of users allowed to be assigned to role r, also known as the user base of r.

[0060] This method introduces an attribute constraint mechanism in the task assignment process. Both users and tasks have attributes. User attributes represent the qualifications, skills, etc. of users, and task attributes represent the conditions required to complete the task. When the system assigns tasks, it will verify the user attributes according to the task attributes. Only when the user attributes meet the requirements of the task can the task be executed. This mechanism ensures that only users with relevant qualifications can obtain corresponding permissions, preventing misuse or abuse of permissions. At the same time, it can effectively improve the fineness of access control.

[0061] S202. If the verification passes, the task manager assigns the target task to the user.

[0062] If the verification fails, the task manager will not assign the target task to the user.

[0063] Specifically, the task manager verifies the user's permissions based on preset constraint rules according to the user's role attribute and the task attribute of the target task to be executed by the user, including: constructing a role attribute expression corresponding to the user according to the user's role attribute; constructing a task authorization attribute expression corresponding to the target task according to the task attribute of the target task; based on the preset constraint rules, comparing the role attribute expression corresponding to the user and the task authorization attribute expression corresponding to the target task, and if the role attribute expression corresponding to the user is superior to or meets the task authorization attribute expression corresponding to the target task, it is determined that the user verification is passed.

[0064] Specifically, property logic expressions are used to implement the verification. The property value represents the value of the entity attribute. Several attributes and property values of the entity can be connected into a property expression by various mathematical operators and the symbol "&", and the property expression of the entity reflects the objective characteristics of the entity at a certain moment.

[0065] For example, in the process of range test data management, a user has many attributes, which can be defined as: the user's role r, the user's department d, and the number of tasks completed s (reflecting the user's ability). Then r = 1 & d = 2 & s = 20 is a property expression. The value of a single attribute is also a property expression, such as r = 1. Through these property logic expressions, we can accurately describe and verify the user's qualifications and capabilities, thus ensuring the accuracy and security in the task assignment process. After defining the corresponding attributes for the role and the task, we perform property verification and comparison of the property expressions. Use to represent the precedence relationship or satisfaction relationship between two property expressions.

[0066] A = (r = 3 & d = 1 & s = 20),

[0067] B = (r = 1 & d = 1 & s = 15),

[0068] C = (r ≥ 1 & d = 1 & s ≥ 15),

[0069] The expression indicates that property expression A takes precedence over property expression B, and the expression indicates that property expression A meets property expression C.

[0070] AAE represents the task authorization property expression, which expresses the requirements of the task for the qualifications and capabilities of the role user. AAE consists of several property expressions. For example: C = (r ≥ 1 & d = 1 & s ≥ 15) is the task authorization property expression of a certain task.

[0071] In role-task assignment, the attribute expression of the role user is compared with the authorization attribute expression of the task. If the attribute expression of the user is superior to or meets the authorization attribute expression of the task, the task can be assigned to the user; otherwise, the task is not allowed to be assigned to the corresponding user.

[0072] This method can ensure that tasks are authorized to the correct roles and prevent the abuse and misuse of permissions.

[0073] S203. The permission manager grants the user the permission to execute the target task.

[0074] After the permission manager grants the user the permission to execute the target task, the user can execute the target task.

[0075] Optionally, the method further includes: when the user finishes executing the target task, the permission manager recovers the permission of the user to execute the target task.

[0076] Immediately recovering the permissions related to the task after the task is completed can prevent the abuse of permissions.

[0077] Optionally, the method further includes: during the process of the user executing the target task, the permission manager adjusts the user's permissions in real time according to the task execution progress and environmental changes.

[0078] Adjusting permissions in real time according to the task progress and environmental changes during the task execution can ensure that users can only access system resources at appropriate times and under appropriate conditions.

[0079] The access control method based on attribute constraints provided by the present invention responds to a task request carrying the user role attribute initiated by the user through the task manager. Based on preset constraint rules, according to the user role attribute of the user and the task attribute of the target task requested by the user, the user's permissions are verified. The user role attribute is pre-set by the role manager, and the task attribute is pre-set by the task manager. If the verification passes, the task manager assigns the target task to the user; the permission manager grants the user the permission to execute the target task, associating the task, role, and user, realizing flexible permission management. By dynamically allocating permissions according to the user's role attributes and task requirements, it can ensure that each user can only access resources related to their tasks, avoid the problem of permission abuse, and realize dynamic, flexible permission management and fine-grained access control.

[0080] For the sake of easy understanding, the following uses the range test data management scenario to illustrate the execution process of the attribute constraints of the A-TRBAC model.

[0081] In common range experiment data management scenarios, there are usually the following types of tasks. Taking the drone category as an example, they include preparing drone flight test data, reviewing flight test data, analyzing and approving flight test data reports, maintaining flight data records, and canceling flight test data preparation. This process requires several roles such as data preparers, data reviewers, data analysis and approvers, and data maintainers. Four different roles of users are needed to complete the entire process, and the users are represented by u1, u2, u3, and u4 respectively. In the A-TRBAC model, it can be described as follows: The task flow instance T = t1, t2, t3, t4, t5, where t1 represents preparing drone flight test data, t2 represents reviewing flight test data, t3 is analyzing and approving flight test data reports, t4 is maintaining flight data records, and t5 is canceling flight test data preparation. The user set U = u1, u2, u3, u4. The role set R = r1, r2, r3, r4, where r1 is the data preparation role, r2 is the data review role, r3 is the data analysis and approval role, and r4 is the data maintenance role. The permission set P = p1, p2, p3, p4, p5, where p1 represents (prepare, flight test data), p2 represents (review, flight test data), p3 represents (analyze and approve, flight test data report), p4 represents (maintain, flight data record), and p5 represents (cancel, flight test data preparation). According to the system settings, the user attribute set A = a1, a2, a3, a4, where a1 represents the attribute description of user u1, a2 represents the attribute description of user u2, a3 represents the attribute description of user u3, and the attribute describes the relevant qualifications of the user. The user-role assignment relationship is UR = (u1, r1), (u2, r2), (u3, r3), (u4, r4). The role-task assignment relationship RT = (r1, t1), (r2, t2), (r3, t3), (r4, t4), (r1, t5). The task-permission assignment relationship TP = (t1, p1), (t2, p2), (t3, p3), (t4, p4), (t5, p5). The conflict task set CT = t1, t2, and the bound task set BT = t1, t5.

[0082] The execution process of the instance can be described as follows:

[0083] First, task t1 (preparing UAV flight test data) is assigned to u1. During the assignment process, static constraints are first checked. For example, it is checked whether user u1 has been assigned a conflicting role or whether the maximum number of users allowed by role r1 has been exceeded. After passing the static constraints, the system performs attribute constraint verification to check whether user u1 has the attribute a1 required to execute t1. After passing the attribute verification, the system performs dynamic constraint checking to ensure that u1 does not violate the dynamic constraint rules when executing t1. For example, it is ensured that in a workflow instance, all task instances in the bound task set BT must be completed by the same user. After all checks pass, u1 is authorized to execute task t1 and obtains the corresponding permission p1. Next, when u1 completes task t1, task t2 (reviewing flight test data) starts, generating task instance ti2. The system first checks the static constraints, confirms that u2 has not been assigned a conflicting role and is within the number of users allowed by role r2. Then it performs attribute constraint verification to ensure that u2 has the attribute a2 required to execute t2. After passing the verification, the system performs dynamic constraint checking to ensure that u2 does not violate the dynamic constraint rules when executing t2. For example, since t1 and t2 belong to the conflicting task set, authorization (u1, p2) is not generated. Because the attributes of u2 match task instance ti2, authorization (u2, p2) is generated. After user u2 finishes executing task instance ti2, authorization (u3, p3) follows, generating task instance ti3 to complete the operation of analyzing and approving the flight test data report. If any of tasks t2 and t3 is not completed, the cancellation process is automatically started, and the cancellation process tasks are completed by the person who applied for the process.

[0084] Through the above example, the whole process of static constraint checking, attribute verification, and dynamic constraint checking of the A-TRBAC model in task execution is demonstrated, effectively ensuring the security and accuracy of permission allocation, and at the same time demonstrating the practical application of static and dynamic constraint rules.

[0085] The present invention also provides a structure of an electronic device, including a processor, a communication interface, a memory, and a communication bus. Among them, the processor, the communication interface, and the memory communicate with each other through the communication bus.

[0086] The memory is used to store a computer program.

[0087] The processor is used to implement the steps provided in the above method embodiments when executing the program stored on the memory.

[0088] The communication interface is used for communication between the above electronic device and other devices.

[0089] The method provided by the embodiments of the present invention can be applied to an electronic device. Specifically, the electronic device can be: a desktop computer, a portable computer, a smart mobile terminal, a server, etc. There is no limitation here. Any electronic device that can implement the present invention belongs to the protection scope of the present invention.

[0090] The present invention also provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a processor, the steps provided in the above method embodiments are implemented.

[0091] The present invention also provides a program product, which includes program instructions. When the program instructions are executed by a processor, the steps provided in the above method embodiments are implemented.

[0092] For the embodiments of the apparatus / electronic device / storage medium / program product, since they are basically similar to the method embodiments, the description is relatively simple. For the specific content, beneficial effects, etc., please refer to the partial description of the method embodiments.

[0093] The terms "first" and "second" are only used for descriptive purposes and cannot be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include one or more of such features. In the description of the present invention, "a plurality" means two or more, unless otherwise specifically defined.

[0094] The above content is a further detailed description of the present invention in combination with specific preferred embodiments. It cannot be determined that the specific implementation of the present invention is only limited to these descriptions. For those of ordinary skill in the technical field to which the present invention belongs, without departing from the concept of the present invention, several simple deductions or substitutions can be made, and all should be regarded as belonging to the protection scope of the present invention.

Claims

1. An access control method based on attribute constraints, characterized in that: Applied to a task role access control model based on attribute constraints, the model includes: Role Manager, Task Manager, and Permission Manager; The method comprises: The task manager, in response to a task request initiated by a user carrying a user role attribute, verifies the authority of the user based on a preset constraint rule, according to the user role attribute of the user and the task attribute of the target task requested to be executed by the user, wherein the user role attribute is preset by the role manager, and the task attribute is preset by the task manager; If the verification is successful, the task manager assigns the target task to the user; The permission manager grants the user permission to execute the target task.

2. The method according to claim 1, characterized in that The preset constraint rules include: Conflicting roles are not assigned to the same user; Conflicting users are not assigned conflicting roles; Conflicting roles are not assigned the same tasks; Conflicting permissions are not assigned to the same task; The maximum number of users a role has does not exceed the user base of the role; The same user is not allowed to perform conflicting tasks.

3. The method according to claim 2, characterized in that The task manager verifies the authority of the user based on preset constraint rules, according to the user role attribute of the user and the task attribute of the target task requested to be executed by the user, including: Constructing a role attribute expression corresponding to the user according to the user role attribute of the user; Constructing a task authorization attribute expression corresponding to the target task according to the task attribute of the target task; Based on the preset constraint rules, the role attribute expression corresponding to the user and the task authorization attribute expression corresponding to the target task are compared. If the role attribute expression corresponding to the user is better than or satisfies the task authorization attribute expression corresponding to the target task, it is determined that the user verification has passed.

4. The method according to claim 3, characterized in that The user role attributes are preset by the role manager, The user role attribute setting process includes: In response to the received role request message, the role manager sets user role attributes for the corresponding user according to the characteristic information of the user carried in the role request message.

5. The method according to claim 4, characterized in that The task attributes are preset by the task manager; The process of setting the task attributes includes: The task manager responds to the received task attribute definition request message, determines the authority of the task according to the characteristic information of the task to be defined, and defines the task attribute of the task according to the authority of the task.

6. The method according to claim 5, characterized in that The method further comprises: After the user completes the target task, the authority manager reclaims the user's authority to execute the target task.

7. The method according to claim 6, characterized in that The method further comprises: When the user is performing the target task, the authority manager adjusts the user's authority in real time according to the task execution progress and environmental changes.

8. An electronic device, characterized in that: It includes a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other through the communication bus; Memory, used to store computer programs; A processor, for implementing any of the methods described in claims 1-7 when executing a program stored in a memory.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.

10. A program product, characterized in that The program product comprises computer program instructions, and when the computer program instructions are executed, the method according to any one of claims 1 to 7 can be implemented.