Case granularity-based cross-domain dynamic authority authentication management method and system

Through the dynamic authority authentication management method based on case granularity, the problems of lack of strict authority management, inflexible file transfer and inability to dynamic updates in cross-domain data interaction of judicial departments are solved, and refined management and safe and efficient cross-domain data transmission are achieved, which improves the collaborative efficiency of judicial work.

CN120238377AActive Publication Date: 2025-07-01SHANDONG UNIV +1
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510724535.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-03
Publication Date
2025-07-01
Estimated Expiration
2045-06-03

AI Technical Summary

Technical Problem

In the prior art, the cross-domain data interaction of judicial departments has problems such as lack of permission management, lack of permission allocation and interception methods, inflexible file transfer, inability to fine-grained management of cases as granularity, and the inability to dynamically update cross-domain business processes.

Method used

The dynamic permission authentication management method based on case granularity is adopted. By generating data item information and process node information of case and case document resources, assembling XML configuration files, cross-optical data packets are flowed using non-HTTP methods, and after the permission verification is passed, the data packets are placed in the proxy directory area for forwarding, realizing permission management of case resources and process nodes.

Benefits of technology

It realizes refined permission management, improves the security and flexibility of cross-domain data exchange, reduces configuration error rate, improves work efficiency, meets the strict permission management requirements of judicial work, supports dynamic process configuration, and adapts to changing business needs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120238377A_ABST
    Figure CN120238377A_ABST
Patent Text Reader

Abstract

The invention provides a cross-domain dynamic authority authentication management method and system based on case granularity, and belongs to the technical field of identity authentication management, and the method comprises the steps: configuring dynamic case information based on the case granularity: generating data item information of a case and a case document resource, and generating process node information; assembling and generating data in an XML (Extensible Markup Language) configuration file based on the generated case, the data item information of the case document resource and the generated process node information; carrying out cross-optical-shutter data packet circulation on the XML configuration file in a non-HTTP (Hyper Text Transport Protocol) mode; authority authentication is carried out on the case resources in the circulation process, and after the authority authentication is passed, a cross-domain data packet is placed in an agent directory area for data packet forwarding; and then authority authentication is carried out on the process node, and after the authority authentication is passed, a cross-domain data packet is placed in a proxy directory area to carry out data packet forwarding.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of identity authentication management, and particularly relates to a cross-domain dynamic permission authentication management method and system based on case granularity. Background Art

[0002] The statements in this part only provide background technical information related to the present invention and do not necessarily constitute prior art.

[0003] In the judicial field, each department of the court, procuratorate, and judicial department uses a dedicated network, which is physically isolated from the Internet. Cross-border information interaction between departments is realized by means of a double unidirectional isolation optical switch through FTP file ferry. Currently, each business system has its own business management system, which cannot be interconnected, and information sharing is difficult. The previous permission management relied on manual operations. This method has the following disadvantages: 1. Insufficient association with the permission system of the business system. The current transmission method is not effectively associated with the permission system of the business system and cannot meet the strict requirements of judicial work for permission management.

[0004] 2. Lack of an effective permission allocation system and permission interception method under the existing mechanism. When traditional permission allocation and interception are carried out based on the HTTP method, a filter can be used, but there is currently no similar effective permission interception method for crossing the optical switch.

[0005] With the development of technology, there are ways in the prior art to achieve cross-domain data interaction by using data sharing or digital authentication. For example: CN112434998B_Remote policing system and method based on public security network and public security digital certificate authentication, D1CN117879785B_Judicial data sharing system, method and computer device based on cross-chain, but the existing problems are as follows: 1. Insufficient flexibility in file batch transmission, does not support transmission based on case granularity. Case granularity means taking a case as a unit, all documents of the same case are placed in the same file directory, and a configuration file is used to manage case-related information, which includes case numbers, document list information included in the case, etc. When transmitting across domains, the file directory of the same case is packaged and transmitted as a whole. The traditional method only transmits files in batches and cannot perform refined management for specific cases.

[0006] 2. Does not support dynamic process configuration: The cross-domain business process can only be preset in advance and cannot be dynamically updated, and cannot dynamically adapt to new business scenarios. Summary of the Invention

[0007] To overcome the deficiencies of the above-mentioned existing technologies, the present invention provides a cross-domain dynamic permission authentication management method based on case granularity, which realizes permission management at the case granularity and achieves refined permission management.

[0008] To achieve the above object, one or more embodiments of the present invention provide the following technical solutions: In the first aspect, a cross-domain dynamic permission authentication management method based on case granularity is disclosed, including: Configuring dynamic case information based on case granularity, including: generating data item information of cases and case document resources, and generating process node information; Assembling and generating the data in the XML configuration file based on the generated data item information of cases and case document resources and the generated process node information; For the XML configuration file, perform data packet transfer across the air gap through a non-HTTP method; During the transfer process, perform permission authentication on case resources. After the permission verification passes, place the cross-domain data packet in the proxy directory area and perform data packet forwarding; Then perform permission authentication on the process node. After the permission verification passes, place the cross-domain data packet in the proxy directory area and perform data packet forwarding.

[0009] As a further technical solution, the data item information of the case and case document resources includes: basic case information and criminal suspect information; The basic case information includes the following data items: Case identifier, case name, case type code, case type name, case cause code, case cause name, name of the party or the main person involved in the case; The criminal suspect information includes the following data items: Case identifier, case name, name, former name, gender, date of birth, marital status; The case document information includes the following data items: Case identifier, document number, document name, document type, remarks.

[0010] As a further technical solution, the process node information includes the following data items: node number, sending unit, receiving unit, sending unit number, receiving unit number, process name, corresponding case document resources.

[0011] As a further technical solution, the XML configuration file includes node information of specified process nodes of a specified case and the case number of the specified case, and these two types of information are used in case resource permission verification and process node permission verification.

[0012] As a further technical solution, for the XML configuration file, the data packet transfer across the air gap is carried out in a non-HTTP manner, including: Put the XML configuration file and the relevant case documents into the same folder; Then, compress and package the above folder. During the packaging process, an encryption method can be selected for compression to form a complete cross-domain data packet; At the business startup stage, store the prepared cross-domain data packet in the sending directory of the front-end machine. Then, the data packet is transmitted through the air gap mechanism, and the data is transferred between physically isolated networks. The data packet is transmitted to the set receiving directory of the back-end machine; In the further data forwarding stage, read and parse the process node information in the XML configuration file to determine the specific receiving department to which the data packet should be delivered. Then, place the data packet in the sending directory of the front-end machine of the corresponding business department and transmit it to the receiving directory of the back-end machine of the target business domain in an FTP manner through the air gap mechanism to complete the cross-domain data transfer in a non-HTTP manner.

[0013] As a further technical solution, perform permission authentication on case resources, specifically including: Configure the case resource permissions at the case granularity; Monitor the case resources and configuration file information of the procuratorial, judicial and public security departments; Authenticate the case permissions based on the case number and permission allocation information; Store the permission verification result in the local database and provide a query interface for business system users to query.

[0014] As a further technical solution, perform permission authentication on case resources. After the permission verification fails, generate a feedback data file and place it in the front-end machine of the feedback directory area. Through the FTP transmission mechanism of the air gap mechanism, the feedback data file is transmitted to the receiving directory of the back-end machine of the original sending business domain.

[0015] As a further technical solution, perform permission authentication on process nodes, including: Configure the case resource permissions at the process node granularity; Monitor the case resources and configuration file information of the procuratorial, judicial and public security departments; Authenticate the case permissions based on the process node information and permission allocation information; Store the permission verification result in the local database and provide a query interface for business system users to query.

[0016] As a further technical solution, permission authentication is performed on process nodes. After the permission verification fails, a feedback data file is generated and placed in the front-end machine of the feedback directory area. Through the cross-air-gap mechanism FTP transmission mechanism, the feedback data file is transmitted to the receiving directory of the back-end machine in the original sending business domain.

[0017] The above one or more technical solutions have the following beneficial effects: The technical solution of the present invention has the ability to configure permissions for cross-domain resources through the above solution, improving the security of cross-domain data exchange between the public security, procuratorial, and judicial organs; based on the current on-site environment, the process has been improved, enabling seamless upgrade under the existing data flow of the public security, procuratorial, and judicial organs; realizing dynamic configurability of process nodes, reducing the workload of configuration by public security, procuratorial, and judicial personnel, improving work efficiency, and reducing the error rate caused by complex configuration; realizing permission management at the case level, achieving refined permission management.

[0018] The technical solution of the present invention enhances the relevance between permission management and the business system: by closely associating cross-domain data transmission with the permission system of the business system, the present invention strictly meets the high requirements of judicial work for permission management. It ensures that only users with corresponding permissions can access and process specific data in a cross-domain environment, effectively improving the security and confidentiality of data, and providing a strong guarantee for the rigor of judicial work.

[0019] The technical solution of the present invention establishes an effective permission allocation and interception system: aiming at the problem that the existing mechanism lacks an effective permission allocation system and permission interception method, the present invention provides a permission allocation and interception method suitable for the cross-air-gap environment. Different from the traditional use of filter filters based on the HTTP method, the present invention constructs a special permission interception mechanism for cross-domain data transmission to ensure the security of data during cross-domain transmission and prevent unauthorized access and operations.

[0020] The technical solution of the present invention improves the flexibility of file batch transmission: the present invention supports file transmission at the case level, breaking the limitation of the traditional method of only batch transmitting files. This enables judicial workers to conduct refined management for specific cases, improving the pertinence and accuracy of data transmission, and helping to better promote the progress of case handling.

[0021] The technical solution of the present invention supports dynamic process configuration: the present invention realizes dynamic update of cross-domain business processes and can be flexibly adjusted according to new business scenarios. Compared with the traditional cross-domain business processes that are preset and cannot be dynamically updated, the present invention can better adapt to the changing needs of judicial work, improving the adaptability and practicality of the system.

[0022] Advantages of additional aspects of the present invention will be given in part in the following description, become apparent in part from the following description, or be learned through the practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] The accompanying drawings forming a part of this specification are used to provide a further understanding of the present invention. The schematic embodiments and descriptions thereof of the present invention are used to explain the present invention and do not unduly limit the present invention.

[0024] Figure 1 It is a schematic diagram of the entire system deployment of the embodiment of the present invention; Figure 2 It is a schematic diagram of the entire method flow of the embodiment of the present invention; Figure 3 It is a flowchart of permission judgment of the embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0025] It should be noted that the following detailed description is exemplary and is intended to provide further explanation of the present invention. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which the present invention belongs.

[0026] It should be noted that the terms used herein are only for describing specific embodiments and are not intended to limit the exemplary embodiments according to the present invention.

[0027] In the case of no conflict, the embodiments in the present invention and the features in the embodiments can be combined with each other.

[0028] The cross-domain dynamic permission authentication scheme is very important. "Cross-domain": In the judicial field, when each department of the judiciary, procuratorate, and public security uses a dedicated network physically isolated from the Internet, cross-border information interaction is achieved through a double-unidirectional isolation optical switch, rather than based on the common TCP / IP protocol.

[0029] Business system (judiciary, procuratorate, public security): Each business system is responsible for the creation and management of cases, ensuring the independent functions of each department (court, procuratorate, public security) while enabling them to work together.

[0030] Permission verification module: The permission platform provides functions of identity authentication, process node permissions, and case permissions; The permission verification module is deployed on the corresponding back-end machines of the judiciary, procuratorate, and public security, listens to the data packets transmitted from the back-end machines of the judiciary, procuratorate, and public security, and places them in the proxy directory after passing the authentication check by calling the permission platform.

[0031] Process module: Supports dynamic configuration of process nodes, and nodes can be added or deleted in the original process; Connect to the judicial and procuratorial business system (simulation) to obtain case information. Assemble xml and documents for packaging according to the data packet specification of Project Five, and place them on the front-end machine for ferry to the Political and Legal Affairs Committee.

[0032] Forwarding module: Read the collaborative data packet from the proxy directory; Forward the information to the front-end machine of the corresponding department according to the information.

[0033] Directory definition: Receiving directory: The receiving directory for ferry through the air gap, which receives files sent from the other end.

[0034] Sending directory: The sending directory for ferry through the air gap. The files in the directory are to be sent to the other end.

[0035] Proxy directory: The data packet directory scanned by the forwarding module. The permission verification module retrieves the file package from the receiving directory and transfers it to the proxy directory after authentication.

[0036] Response directory: The directory used to respond to messages from the business system.

[0037] Embodiment 1 See the appendix Figure 1 As shown, the purpose of this embodiment is to provide a cross-domain dynamic permission authentication management system based on case granularity, including: the first server, the second server, the third server, and the fourth server; The first server includes the first business system and the first process module; the second server includes the second business system and the second process module; the third server includes the permission verification module and the forwarding module; the fourth server includes the third business system and the third process module; The first business system sends case data to the first process module, and the first process module packs the files, where the files include XML configuration files and case document files; The first process module transfers the data packet to the sending directory of the front-end machine, and the data packet enters the receiving directory area in a cross-air-gap manner; The permission verification module performs permission verification on the case information and process node information; The forwarding module determines whether to send the data packet to the second business system or the third business system according to the receiving unit of the process node; If the data is transmitted to the second business system: the forwarding module places the data packet in the sending directory of the front-end machine corresponding to the second business system, and the data packet enters the receiving directory area of the back-end machine in a cross-air-gap manner; If the data is transmitted to the third business system: the forwarding module places the data packet in the sending directory of the front-end machine corresponding to the third business system; The second process module of the second server monitors the data packets received in the receiving directory area, parses the data packets and forwards the data packets to the second business system; The third process module of the fourth server monitors the data packets received in the receiving directory area, parses the data packets and forwards the data packets to the third business system.

[0038] In this embodiment, the above-mentioned first server is a judicial server, the third server is a political and legal committee server, the second server is a court server, and the fourth server is a procuratorate server.

[0039] The court business system is the second business system, the procuratorate business system is the third business system, and the judicial business system is the first business system.

[0040] A more detailed solution is expressed as follows: The cross-domain data flow between the court, procuratorate, and judiciary includes 3 data routes (including from the judiciary to the court or procuratorate, from the court to the judiciary or procuratorate, and from the procuratorate to the judiciary or court), Figure 2 which shows the data flow from the judiciary to the court or procuratorate. Data transmission Figure 2 process is as follows: (1) The judicial business system in the judicial domain starts the process. The judicial business system in the judicial domain sends the case data to the first process module. The first process module packs the files, where the files include an XML configuration file and a case document file. The packing method is a compressed package. The compression package packing process can use an encrypted packing method to enhance the security of the data packet.

[0041] (2) The first process module places the data packet in the sending directory of the judicial front-end machine. The data packet enters the receiving directory area of the political and legal committee domain through the cross-air-gap method.

[0042] (3) The permission verification module monitors the data packets received in the receiving directory area, decompresses the data packets and parses the XML configuration file therein, performs permission verification on the case information and process node information, and the permission verification module records the verification result. If the verification is successful, the data packet is forwarded to the proxy directory area. If the verification fails, the failure record information is placed in the response directory area.

[0043] (4) The forwarding module monitors the data packets received in the proxy directory area, decompresses the data packets and parses the XML configuration file therein, and determines whether the data packet is sent to the court or the procuratorate according to the receiving unit of the process node.

[0044] If the data is transmitted to the court: The forwarding module places the data packet in the sending directory of the court front-end machine. The data packet enters the receiving directory area of the post-machine in the court domain through the cross-air-gap method.

[0045] If the data is transmitted to the procuratorate: The forwarding module places the data packet in the sending directory of the procuratorate front-end machine, and the data packet enters the receiving directory area of the procuratorate domain back-end machine in a cross-air-gap manner.

[0046] (5) The process module in the court domain monitors the data packets received in the receiving directory area, parses the data packets and forwards them to the court business system.

[0047] The process module in the procuratorate domain monitors the data packets received in the receiving directory area, parses the data packets and forwards them to the procuratorate business system.

[0048] Specifically, this process first generates a compressed package containing case-related information and required transfer files by the source business system, and protects the compressed package by encryption means, and then places it in a preset sending directory. The compressed package is transmitted to the receiving directory on the target side through the air-gap mechanism, ensuring the integrity and confidentiality of the data during this process. The permission verification module on the receiving side decompresses and parses the received data packet, and performs permission verification on the case information and process node information according to the XML configuration file carried therein. After passing the verification, the data packet is transferred to the proxy directory and waits for further processing. Finally, the forwarding module forwards the data packet to the correct business department according to the instructions in the configuration file, completing the entire business process.

[0049] See Appendix Figure 2 As shown, the judicial business system contains two business processes. The first business process is that the judicial business system first obtains the case information of the current process node from the process module, and then gives the information of the new node to the process module. The process module packs the case information of the new node into a file and sends it out through the judicial front-end machine via the air-gap. Another business process is the case information sent from the Political and Legal Affairs Commission via the air-gap. After passing through the judicial back-end machine, the process module receives the data and pushes it to the judicial business system.

[0050] The technical solution of the present invention realizes a new cross-domain data transmission process for the court, procuratorate and judicial department, adds a permission module, and realizes the permission management of cross-domain data through the cooperation of the permission module with the process module and the forwarding module.

[0051] The present invention establishes a cross-domain configuration file, defines case resources and process nodes through the XML configuration file, packs and sends the configuration file together with the files to be transmitted across domains, and realizes the case-level management of cross-domain data through the parsing of the configuration file, thereby realizing cross-domain data synchronization and permission control. Currently, the method of directly sending the file directory by ftp is adopted.

[0052] The present invention establishes a permission management system at the case granularity, adds a permission module, and the permission module realizes more refined permission allocation and control by combining with case configuration. Currently, cross-domain files can only be managed manually.

[0053] The present invention establishes a system for dynamically configuring process nodes and managing permissions for process nodes.

[0054] Through the present invention, fine-grained management and secure transmission of cross-domain data are realized, information collaboration and efficient circulation among various departments of the judiciary, procuratorate, and public security are promoted, and the security of data processing and the overall efficiency of cross-domain collaborative work are improved.

[0055] Embodiment 2 This embodiment discloses a cross-domain dynamic permission authentication management method based on case granularity. In each link of the case, the basic case information, suspect information, and case document information can be modified. For example, new documents can be added, and only the corresponding information in the configuration file needs to be synchronously modified after the above information is modified. The permissions for case resources can be verified in units of the entire case and automatically corresponding to the above modified information.

[0056] The method specifically includes: Step 1: Dynamic case information configuration based on case granularity: Step 2: Dynamic process configuration and service flow across the air gap in a non-HTTP manner; Step 3: Perform permission authentication on case resources; Step 4: Perform permission authentication on process nodes.

[0057] In Step 1, the dynamic case information configuration based on case granularity specifically includes: Step 1.1 Generate data items for cases and case document resources; The configuration file of a case contains case information and case document information; Case information includes basic case information and suspect information.

[0058] The basic case information includes the following data items: Case identifier, case name, case type code, case type name, case cause code, case cause name, name of the party or main suspect; The suspect information includes the following data items: Case identifier, case name, name, former name, gender, date of birth, marital status.

[0059] The case document information includes the information of the documents corresponding to the case. The data item is the smallest information unit in the configuration file, and both case information and case document information are composed of multiple data items.

[0060] The case document information includes the following data items: Case identifier, document number, document name, document type, remarks.

[0061] Both the case information and the case document information include multiple data items.

[0062] Step 1.2 Generate process node information A business scenario can be divided into multiple process nodes, and the process nodes include the following data items: Node number, sending unit, receiving unit, sending unit number, receiving unit number, process name, corresponding case document resources.

[0063] The process system designs a set of process nodes in the business scenario according to the cross-domain business scenario requirements, and formulates the node number, sending unit, receiving unit, and corresponding case document resources of each process node. Users can customize the business scenario and the process nodes included in the business scenario.

[0064] Step 1.3 Define the data format of the XML configuration file The XML configuration file describes the basic case information included in the specified case in the current process node, the document information corresponding to this process, and the current process node information.

[0065] Based on the data items that can be changed to case and case document resources generated in Step 1.1 and the process node information generated in Step 1.2, assemble and generate the data in the XML configuration file. The XML configuration file contains the node information of the specified process node of the specified case and the case number of the specified case. These two types of information are used in Step 3 for case resource permission verification and Step 4 for process node permission verification.

[0066] In Step 2, for the dynamic process configuration and business flow across the optical switch in a non-HTTP manner, this step describes how to use the XML configuration file and achieve the data packet flow across the optical switch in a non-HTTP manner. During the transmission process, the folder is compressed and packaged to improve the transmission stability, and the compressed package is encrypted and compressed to improve the transmission security. The specific approach is as follows: Step 2.1 Generate a data packet containing the XML configuration file and case documents First, put the XML configuration file and the relevant case documents into the same folder. Then, the process module performs compression and packaging on this folder. To improve data security, an encryption method can be selected during the packaging process to form a complete cross-domain data packet.

[0067] This step organizes the information of the determined document list into the case document resource part of the XML configuration file for management.

[0068] Step 2.2 The data packet is transmitted across the air gap in a non-HTTP manner In the service startup phase, the process module stores the prepared cross-domain data packets in the sending directory of the front-end machine. Then, the data packets are transmitted through the air gap mechanism. The data is transferred between physically isolated networks, rather than through the ordinary HTTP network protocol. The data packets are transmitted to the receiving directory of the back-end machine in the Political and Legal Affairs domain.

[0069] In the further forwarding phase of the data, the forwarding module reads and parses the process node information in the XML configuration file to determine the specific receiving department to which the data packet should be delivered. After that, the forwarding module places the data packet in the sending directory of the front-end machine of the corresponding business department and transmits it to the receiving directory of the back-end machine of the target business domain via the air gap mechanism in FTP mode, thus completing the cross-domain data flow in a non-HTTP manner.

[0070] Step 3: The permission module performs permission authentication on case resources The permission module allocates permissions and generates permission relationship information between users and case resources; the permission verification module verifies the permissions of the case resources that need to have their permissions determined according to the permission relationship information and gives the result of whether the permissions are available.

[0071] In the present invention, a new permission verification module is added. Business personnel allocate permissions to case resources through the permission module, and during the collaborative process, the permission verification module verifies the permissions of resources and users to perform permission judgment, realizing the permission management of the collaborative process and enhancing the security of the collaborative process.

[0072] Step 3.1 Configure the permissions of case resources at the case granularity.

[0073] In the system deployment phase, the business personnel of the public security, procuratorial, and judicial organs need to import the organizational structure of this system into the permission module to generate organizational structure information, which is stored in the permission module database. The organizational structure information includes business departments and user information in the departments.

[0074] Specifically, in the way of importing the existing excel table of the organizational structure of this unit into the permission module, after the permission module parses out the department and user information, it creates a department table, a user table, and a department-user relationship table in the permission module database to store the organizational structure information.

[0075] In the business initiation phase, when the business system generates a configuration file for the first time through the process module, it will generate a unique case number for this case in the business scenario. The case number is the primary key for the permission module to configure the case permissions.

[0076] Based on the case number and organizational structure information, the public security, procuratorial, and judicial business personnel can allocate permissions for cases and documents within their business domains through the permission module. Permissions can be allocated to specific departments or users, generating permission allocation information.

[0077] The permission allocation information is stored in the internal storage of the permission module, using the local database method for storage.

[0078] Step 3.2 The permission module listens for case resources and configuration file information of the procuratorial, judicial, and legal affairs departments.

[0079] The permission module implements a permission service data packet listening mechanism, configuring the service listening directory, proxy directory, and feedback directory. The service listening directory is the path where the data packet is stored after crossing the political and legal affairs information gateway. The permission service listens to this directory to obtain the data packet, parses the configuration file in the data packet, obtains the case and document information therein, and verifies the permissions for the above information according to the configured permissions. The proxy directory is the storage directory of the data packet after the permission service authentication is successful. The forwarding module listens to the proxy directory and forwards the data packet to the next node according to the process node information in the configuration file.

[0080] The permission verification module listens for cross-domain data packets in the receiving directory, decompresses the cross-domain data packets. If the data packet is encrypted and compressed, it is decrypted and decompressed with the corresponding secret key to obtain the XML configuration file and the case document list.

[0081] The permission verification module parses the data in the XML configuration file to obtain the case number and actor information.

[0082] Step 3.3 Authenticate the case permissions based on the case number and permission allocation information.

[0083] Permission judgment process: After the authentication plugin intercepts the data packet, it judges whether the permissions have been configured. If the permissions have not been configured, it needs to return to Step 3.1 and wait for the permissions to be configured before performing subsequent operations. Obtain the unified case number from the xml, obtain the permission configuration of the case through the unified case number, perform permission verification, and take the intersection of the participating units, autonomous access, role access, and mandatory access. Those not configured are not judged.

[0084] Step 3.4 Feedback of the permission verification result The permission module stores the permission verification result in the local database and provides a query interface for business system users to query.

[0085] After the permission verification passes, the permission module places the cross-domain data packet in the proxy directory area for the forwarding module to forward the data packet. After the permission verification fails, the permission module generates a feedback data file and places it in the front-end machine of the feedback directory area. Through the cross-gateway mechanism FTP transmission mechanism, the feedback data file is transmitted to the receiving directory of the back-end machine of the original sending business domain.

[0086] See the appendix Figure 3 As shown, Step 4: The permission module performs permission authentication on the process nodes In the present invention, a new permission verification module is added. Business personnel allocate process node permissions for cases through the permission module, and the permission module verifies the process node permissions during the collaborative process to perform permission judgment, realizing the permission management of the collaborative process and enhancing the security of the collaborative process.

[0087] Step 4.1 Configure the case resource permissions at the granularity of process nodes.

[0088] During the system deployment phase, the business personnel of the public security, procuratorial, and judicial organs need to import the organizational structure of this system into the permission module to generate organizational structure information, which is stored in the permission module database. The organizational structure information includes business departments and user information in the departments.

[0089] The permission module provides a function for entering process node information. During the system deployment phase, when the process node information included in the business scenario is determined, the business personnel need to enter the process node information into the permission module. The process node information is stored in the local database of the permission module.

[0090] Based on the process nodes and organizational structure information, the business personnel of the public security, procuratorial, and judicial organs can allocate permissions for the process nodes through the permission module, which can be allocated to specific departments or users to generate permission allocation information.

[0091] The permission allocation information is stored in the internal storage of the permission module and is stored in the form of a local database.

[0092] Step 4.2 The permission module listens to the case resources and configuration file information of the procuratorial, judicial, and judicial administrative organs

[0093] The permission module implements a permission service data packet listening mechanism, configuring a service listening directory, a proxy directory, and a feedback directory. The service listening directory is the path where the data packet is stored after crossing the political and legal affairs information gateway. The permission service listens to this directory to obtain the data packet, parses the configuration file in the data packet, obtains the case and document information therein, and verifies the permissions of the above information according to the configured permissions. The proxy directory is the storage directory of the data packet after the permission service authentication is successful. The forwarding module listens to the proxy directory and forwards the data packet to the next node according to the process node information in the configuration file.

[0094] The permission module listens to the cross-domain data packets in the receiving directory, decompresses the cross-domain data packets. If the data packets are encrypted and compressed, they are decrypted and decompressed with the corresponding secret key to obtain the XML configuration file and the case document list.

[0095] The permission verification module parses the data in the XML configuration file to obtain the current process node information.

[0096] Step 4.3 Authenticate the case permissions based on the process node information and the permission assignment information.

[0097] Permission judgment process: After the authentication plugin intercepts the data packet, it determines whether the permissions are configured. If the permissions are not configured, it is necessary to return to Step 4.1 and wait for the permissions to be configured before performing subsequent operations. Obtain the process node number from the xml, and obtain the process node permission configuration of the case through the process node number for permission verification.

[0098] Step 4.4 Feedback of the permission verification result The permission module stores the permission verification result in the local database and provides a query interface for business system users to query.

[0099] After the permission verification passes, the permission module places the cross-domain data packet in the proxy directory area for the forwarding module to forward the data packet. After the permission verification fails, the permission module generates a feedback data file and places it in the front-end machine of the feedback directory area. Through the cross-gateway mechanism FTP transmission mechanism, the feedback data file is transmitted to the receiving directory of the back-end machine in the original sending business domain.

[0100] Step 1 organizes the configuration file in the way of the information of a case and the process node where the case is located. The main purpose of this configuration file is to be transmitted to Steps 3 and 4 for use. Steps 3 and 4 parse the configuration file to obtain the case information and verify the permissions for this information. Step 2 mainly plays the role of data transmission and transfer.

[0101] Through the technical solution of this embodiment, an XML configuration file is created to manage the cross-domain resources of the case. By inserting the permission authentication link, it is possible to achieve permission management at the case granularity. By dynamically configuring the process node information through the configuration file, it is possible to achieve permission management for the process node, and then achieve the trusted transmission of the case resource data across the optical gateway.

[0102] A dynamic permission authentication method and system for cross-domain of public security, procuratorate and court proposed by the present invention manages cross-domain resources by designing a configuration file, realizes permission management at the case granularity, and realizes the trusted transmission of case resource data across the optical gateway by verifying the permissions of case resources.

[0103] Based on the dynamic case information configuration at the case granularity, the technical solution of this embodiment uses the XML configuration file as a bridge to realize the cross-domain transmission of case information. Different from the traditional file management method based on FTP transmission, the present invention defines case resources and process nodes through XML files, thereby realizing cross-domain data synchronization and permission control.

[0104] Define case, offender, and document information through an XML file, and encapsulate the document list information into XML format for easy reading and parsing by the permission module, process module, and forwarding module. Define the nodes where the business process is located through an XML file for easy reading and parsing by the permission module and process module.

[0105] Dynamic process configuration and business transfer across airgaps in non-HTTP mode. Without relying on the HTTP protocol, the present invention enables data to flow securely and reliably across airgaps in a physically isolated network environment by establishing a standardized data packet transmission process on both sides of the airgap.

[0106] The present invention allows business users to configure specific process node information in different business scenarios through the process system. Define the nodes where the business process is located through an XML file, and through the parsing of the process node information in the configuration file by the process system, realize the automatic operation of the entire business process scenario, enhancing the flexibility and efficiency of cross-domain business processing.

[0107] Permission interception system based on airgap directories: During data transmission, the present invention introduces a permission management mechanism at the directory level. By setting up specific directories on both sides of the airgap, including receiving directories, sending directories, proxy directories, and response directories, permission interception and verification of data packets are achieved, ensuring that only authenticated data can continue to flow.

[0108] The technical solution of this embodiment is an authentication method and system for dynamic configuration management of process nodes in cross-domain business scenarios and permission configuration management of case resources, realizing the secure and efficient transfer of case resources across domains and improving the collaborative efficiency of the judiciary, procuratorate, and public security department.

[0109] Embodiment III The purpose of this embodiment is to provide a computer device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the steps of the above method are implemented.

[0110] Embodiment IV The purpose of this embodiment is to provide a computer-readable storage medium.

[0111] A computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, the steps of the above method are executed.

[0112] Embodiment V The purpose of this embodiment is to provide a computer program product containing instructions. When it runs on a computer, it enables the computer to execute the methods and functions involved in any one of the above embodiments. The steps involved in the devices in the above Embodiments 3, 4, and 5 correspond to those in Method Embodiment 2. For the specific implementation manners, reference may be made to the relevant description part of Embodiment 2. The term "computer-readable storage medium" should be understood to include a single medium or multiple media containing one or more sets of instructions; it should also be understood to include any medium that can store, encode, or carry a set of instructions for execution by a processor and cause the processor to execute any method in the present invention.

[0113] Those skilled in the art should understand that the above-mentioned modules or steps of the present invention can be implemented by a general-purpose computer device. Optionally, they can be implemented by program codes executable by a computing device, so that they can be stored in a storage device and executed by the computing device, or they can be separately fabricated into individual integrated circuit modules, or multiple modules or steps among them can be fabricated into a single integrated circuit module for implementation. The present invention is not limited to any specific combination of hardware and software.

[0114] Although the specific implementation manners of the present invention have been described above in conjunction with the accompanying drawings, it is not a limitation on the protection scope of the present invention. Those skilled in the art should understand that, based on the technical solutions of the present invention, various modifications or deformations that can be made without creative efforts by those skilled in the art are still within the protection scope of the present invention.

Claims

1. A cross-domain dynamic permission authentication management method based on case granularity, characterized in that Including: Configuring dynamic case information based on case granularity, including: generating data item information of cases and case document resources, and generating process node information; Assembling and generating the data in the XML configuration file based on the generated data item information of cases and case document resources and the generated process node information; Performing cross-photon-gate data packet transfer for the XML configuration file in a non-HTTP manner; Performing permission authentication on case resources during the transfer process. After the permission verification passes, place the cross-domain data packet in the proxy directory area for data packet forwarding; Then perform permission authentication on the process node. After the permission verification passes, place the cross-domain data packet in the proxy directory area for data packet forwarding.

2. The method for cross-domain dynamic permission authentication management based on case granularity according to claim 1, wherein The XML configuration file contains the node information of the specified process node of the specified case and the case number of the specified case. These two types of information are used in case resource permission verification and process node permission verification.

3. The cross-domain dynamic permission authentication management method based on case granularity according to claim 1, characterized in that, Performing cross-photon-gate data packet transfer for the XML configuration file in a non-HTTP manner, including: Putting the XML configuration file and related case documents into the same folder; Then, performing compression and packaging processing on the above folder. Encryption methods can be selected during the packaging process to form a complete cross-domain data packet; During the business startup phase, store the prepared cross-domain data packet in the sending directory of the front-end machine. Then, the data packet is transmitted through the cross-photon-gate mechanism, and the data is transferred between physically isolated networks. The data packet is transmitted to the set receiving directory of the back-end machine; In the further data forwarding phase, read and parse the process node information in the XML configuration file to determine the specific receiving department to which the data packet should be delivered. Then, place the data packet in the sending directory of the front-end machine of the corresponding business department and transmit it to the receiving directory of the back-end machine of the target business domain via the cross-photon-gate mechanism in an FTP manner to complete cross-domain data transfer in a non-HTTP manner.

4. The cross-domain dynamic permission authentication management method based on case granularity according to claim 1, characterized in that Performing permission authentication on case resources, specifically including: Configuring case resource permissions at the case granularity; Listening to the case resources and configuration file information of the judicial and procuratorial departments; Authenticating case permissions based on the case number and permission allocation information; Storing the permission verification results in the local database and providing a query interface for business system users to query; When performing permission authentication on case resources and the permission verification fails, generate a feedback data file and place it in the front-end machine of the feedback directory area. Through the cross-photon-gate mechanism FTP transmission mechanism, the feedback data file is transmitted to the receiving directory of the back-end machine of the original sending business domain.

5. The method for cross-domain dynamic permission authentication management based on case granularity according to claim 1, characterized in that Performing permission authentication on process nodes, including: Configuring case resource permissions at the process node granularity; Listening to the case resources and configuration file information of the judicial and procuratorial departments; Authenticating case permissions based on the process node information and permission allocation information; Storing the permission verification results in the local database and providing a query interface for business system users to query.

6. The cross-domain dynamic permission authentication management method based on case granularity according to claim 1, characterized in that When performing permission authentication on process nodes and the permission verification fails, generate a feedback data file and place it in the front-end machine of the feedback directory area. Through the cross-photon-gate mechanism FTP transmission mechanism, the feedback data file is transmitted to the receiving directory of the back-end machine of the original sending business domain.

7. A system for implementing a cross - domain dynamic permission authentication and management method based on case granularity according to any one of claims 1 - 6, characterized in that, Including: The first server, the second server, the third server, and the fourth server; The first server includes a first business system and a first process module; The second server includes a second business system and a second process module; the third server includes an authentication module and a forwarding module; the fourth server includes a third business system and a third process module; The first business system sends case data to the first process module, and the first process module packs the files, where the files include an XML configuration file and case document files; The first process module transfers the data packet to the sending directory of the front-end machine, and the data packet enters the receiving directory area in a cross-air-gap manner; The authentication module performs permission verification on the case information and process node information; The forwarding module determines whether to send the data packet to the second business system or the third business system according to the receiving unit of the process node; If the data is transmitted to the second business system: the forwarding module places the data packet in the sending directory of the front-end machine corresponding to the second business system, and the data packet enters the receiving directory area of the back-end machine in a cross-air-gap manner; If the data is transmitted to the third business system: the forwarding module places the data packet in the sending directory of the front-end machine corresponding to the third business system; The second process module of the second server monitors the data packets received in the receiving directory area, parses the data packets, and forwards the data packets to the second business system; The third process module of the fourth server monitors the data packets received in the receiving directory area, parses the data packets, and forwards the data packets to the third business system.

8. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the method described in any one of claims 1 to 6.

9. A computer device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the steps of the method described in any one of the above claims 1-6.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by a processor, it executes the steps of the method described in any one of the above claims 1-6.

Citation Information

Patent Citations

  • Case node management system based on two-dimensional code

    CN113222419A

  • Judicial data sharing system and method based on cross-chain and computer equipment

    CN117879785A

  • Intelligent network connection automobile fine-grained data evidence obtaining method based on conditional agent re-encryption

    CN118102289A

  • Intelligent judicial cross-domain-oriented credible interaction method and system

    CN119341726A

  • Distributed judicial data management platform architecture

    CN119848926A