A cross-domain dynamic authority authentication management method and system based on case granularity

Through the dynamic permission authentication management method based on case granularity, the problem of lack of permission management in cross-domain data interaction is solved, and refined management and dynamic process configuration with case granularity are realized, which improves the security and efficiency of judicial data exchange.

CN120238377BActive Publication Date: 2025-08-08SHANDONG UNIV +1
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202510724535.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-03
Publication Date
2025-08-08
Estimated Expiration
2045-06-03

AI Technical Summary

Technical Problem

The existing technology has poor permission management and lacks effective permission allocation and interception methods in cross-domain data interaction in the judicial field, and it is impossible to achieve refined management and dynamic process configuration with case-based granularity, resulting in difficulty in sharing information and insufficient security.

Method used

A dynamic permission authentication management method based on case granularity is adopted. By generating XML configuration files, combining non-HTTP methods to transmit data packets across optical gates, and permission authentication and verification are carried out during the flow process, a permission management system with case and process nodes as granularity is established, and the permission module and process module are used to coordinate the safe forwarding of cross-domain data packets.

Benefits of technology

It realizes refined permission management, improves the security and flexibility of cross-domain data exchange, reduces configuration error rate, enhances data security and confidentiality, supports dynamic process configuration, and improves the efficiency and adaptability of judicial work.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120238377B_ABST
    Figure CN120238377B_ABST
Patent Text Reader

Abstract

The present invention proposes a cross-domain dynamic authority authentication management method and system based on case granularity, which belongs to the field of identity authentication management technology, including: configuring dynamic case information based on case granularity, including: generating data item information of cases and case document resources, generating process node information; assembling data in an XML configuration file based on the generated data item information of cases and case document resources and the generated process node information; transferring data packets across optical gates for the XML configuration file through a non-HTTP method; performing authority authentication on case resources during the transfer process, and placing the cross-domain data packets in a proxy directory area for data packet forwarding after the authority verification is passed; then performing authority authentication on the process nodes, and placing the cross-domain data packets in a proxy directory area for data packet forwarding after the authority verification is passed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of identity authentication management, and in particular relates to a cross-domain dynamic authority authentication management method and system based on case granularity. Background Art

[0002] The statements in this section merely provide background information related to the present invention and do not necessarily constitute prior art.

[0003] In the judicial sector, each department of the Judicial and Procuratorial Department utilizes a dedicated network, physically isolated from the internet. Cross-departmental information exchange is facilitated by FTP file transfers via dual one-way isolation optical switches. Currently, each business system maintains its own business management system, which is incompatible with each other, making information sharing difficult and requiring manual management of permissions. This approach presents the following drawbacks:

[0004] 1. Insufficient connection with the business system's authority system. The current transmission method is not effectively connected with the business system's authority system and cannot meet the strict requirements of judicial work for authority management.

[0005] 2. The existing mechanism lacks an effective permission allocation system and permission interception method. Traditionally, when assigning and intercepting permissions based on HTTP, filters can be used, but there is currently no similar effective permission interception method across the optical gate.

[0006] With the development of technology, there are existing technologies that use data sharing or digital authentication to achieve cross-domain data interaction, such as: CN112434998B_Remote policing system and method based on public security network and public security digital certificate authentication, D1CN117879785B_Judicial data sharing system, method and computer equipment based on cross-chain. However, the following problems still exist:

[0007] 1. Batch file transfer lacks flexibility and does not support case-based transfers. Case granularity refers to placing all documents for a case in the same directory. Case-related information, such as the case number and a list of documents included in the case, is managed using a configuration file. For cross-domain transfers, the file directory for the same case is packaged and transferred as a whole. Traditional methods only transfer files in batches and fail to provide granular management for specific cases.

[0008] 2. Dynamic process configuration is not supported: Cross-domain business processes can only be pre-set and cannot be dynamically updated or adapted to new business scenarios. Summary of the Invention

[0009] In order to overcome the deficiencies of the above-mentioned prior art, the present invention provides a cross-domain dynamic authority authentication management method based on case granularity, which realizes authority management based on case granularity and realizes refined authority management.

[0010] To achieve the above objectives, one or more embodiments of the present invention provide the following technical solutions:

[0011] In the first aspect, a cross-domain dynamic permission authentication management method based on case granularity is disclosed, comprising:

[0012] Configure dynamic case information based on case granularity, including: generating data item information of cases and case document resources, and generating process node information;

[0013] Assemble and generate data in the XML configuration file based on the generated case and case document resource data item information and the generated process node information;

[0014] For XML configuration files, data packets are transferred across optical switches through non-HTTP methods;

[0015] During the transfer process, the case resources are authenticated. Once the authentication is passed, the cross-domain data packet is placed in the proxy directory area for data packet forwarding.

[0016] Then the process node is authenticated. After the authentication is passed, the cross-domain data packet is placed in the proxy directory area for data packet forwarding.

[0017] As a further technical solution, the data item information of the case and case document resources includes: basic case information and criminal suspect information;

[0018] The basic case information includes the following data items:

[0019] Case identification, case name, case type code, case type name, cause of action code, cause of action name, names of parties or main persons involved in the case;

[0020] Criminal suspect information includes the following data items:

[0021] Case identifier, case title, name, former name, gender, date of birth, marital status;

[0022] Case document information includes the following data items:

[0023] Case identification, document number, document name, document type, and remarks.

[0024] As a further technical solution, the process node information includes the following data items: node number, sending unit, receiving unit, sending unit number, receiving unit number, process name, and corresponding case document resources.

[0025] As a further technical solution, the XML configuration file includes node information of a specified case and a specified process node, and a case number of a specified case. These two types of information are used in case resource authority verification and process node authority verification.

[0026] As a further technical solution, the XML configuration file is transferred across the optical gate in a non-HTTP manner, including:

[0027] Put the XML configuration file and related case documents into the same folder;

[0028] Then, compress and package the above folders. During the packaging process, encryption can be selected to compress and form a complete cross-domain data package.

[0029] During the service startup phase, the prepared cross-domain data packets are stored in the front-end's send directory. Next, the data packets are transmitted across optical gates, passing data between physically isolated networks, and are transferred to the set back-end's receive directory.

[0030] In the further forwarding stage of data, the process node information in the XML configuration file is read and parsed to determine the specific receiving department to which the data packet should be delivered. Then, the data packet is placed in the sending directory of the front-end machine of the corresponding business department, and transmitted to the receiving directory of the back-end machine of the target business domain via FTP through the cross-gate mechanism, completing the cross-domain data flow under non-HTTP mode.

[0031] As a further technical solution, case resources are authenticated, specifically including:

[0032] Configure case resource permissions based on case granularity;

[0033] Monitor case resources and configuration file information of the Judicial and Procuratorial Department;

[0034] Authenticate case authority based on case number and authority allocation information;

[0035] The permission verification results are stored in the local database, and a query interface is provided for business system users to query.

[0036] As a further technical solution, the case resources are authenticated. If the authentication fails, a feedback data file is generated and placed in the front-end machine of the feedback directory area. The feedback data file is transmitted to the receiving directory of the back-end machine of the original sending business domain through the cross-optical gate mechanism FTP transmission mechanism.

[0037] As a further technical solution, authorization authentication is performed on process nodes, including:

[0038] Configure case resource permissions based on process nodes;

[0039] Monitor case resources and configuration file information of the Judicial and Procuratorial Department;

[0040] Authenticate case authority based on process node information and authority allocation information;

[0041] The permission verification results are stored in the local database, and a query interface is provided for business system users to query.

[0042] As a further technical solution, the process nodes are authenticated. If the authentication fails, a feedback data file is generated and placed in the front-end machine of the feedback directory area. The feedback data file is transmitted to the receiving directory of the back-end machine of the original sending business domain through the cross-optical gate mechanism FTP transmission mechanism.

[0043] One or more of the above technical solutions have the following beneficial effects:

[0044] The technical solution of the present invention has the ability to configure permissions for cross-domain resources through the above-mentioned solution, thereby improving the security of cross-domain data exchange between public security, procuratorial and judicial organs; it improves the process based on the current on-site environment, and can achieve seamless upgrades under the condition of existing public security, procuratorial and judicial data flow; it realizes dynamic configurability of process nodes, reduces the workload of public security, procuratorial and judicial personnel in configuration, improves work efficiency, and reduces the error rate caused by complex configuration; it realizes permission management with case granularity, and realizes refined permission management.

[0045] The technical solution of this invention strengthens the correlation between rights management and business systems: By closely linking cross-domain data transmission with the rights system of business systems, this invention strictly meets the high requirements of judicial work for rights management. This ensures that only users with appropriate permissions can access and process specific data in a cross-domain environment, effectively improving data security and confidentiality, and providing a strong guarantee for the rigor of judicial work.

[0046] The technical solution of this invention establishes an effective permission allocation and interception system: To address the lack of an effective permission allocation system and permission interception method in existing mechanisms, this invention provides a permission allocation and interception method suitable for cross-gate environments. Unlike traditional HTTP-based methods that use filters, this invention builds a dedicated permission interception mechanism for cross-domain data transmission, ensuring data security during cross-domain transmission and preventing unauthorized access and manipulation.

[0047] The technical solution of this invention enhances the flexibility of batch file transfer: it supports case-by-case file transfer, breaking the limitations of traditional batch file transfers. This enables judicial personnel to conduct refined case management, improves the pertinence and accuracy of data transmission, and facilitates the advancement of case handling.

[0048] The technical solution of this invention supports dynamic process configuration: This invention enables dynamic updates of cross-domain business processes, allowing for flexible adjustments based on new business scenarios. Compared to traditional pre-defined cross-domain business processes that cannot be dynamically updated, this invention can better adapt to the ever-changing needs of judicial work, improving the system's adaptability and practicality.

[0049] Advantages of additional aspects of the present invention will be given in part in the following description and in part will be obvious from the following description, or will be learned through practice of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] The accompanying drawings, which constitute a part of the present invention, are used to provide a further understanding of the present invention. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute improper limitations on the present invention.

[0051] Figure 1 This is a schematic diagram of the entire system deployment according to an embodiment of the present invention;

[0052] Figure 2 This is a schematic diagram of the entire method flow of an embodiment of the present invention;

[0053] Figure 3 This is a flowchart of authority determination according to an embodiment of the present invention. DETAILED DESCRIPTION

[0054] It should be noted that the following detailed descriptions are exemplary and intended to provide further explanation of the present invention. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art to which the present invention belongs.

[0055] It should be noted that the terms used herein are for describing particular embodiments only and are not intended to limit the exemplary embodiments according to the present invention.

[0056] In the absence of conflict, the embodiments of the present invention and the features thereof may be combined with each other.

[0057] Cross-domain dynamic permission authentication scheme is very important.

[0058] "Cross-domain": In the judicial field, when the various departments of the court use dedicated networks and are physically isolated from the Internet, cross-border information interaction is achieved through dual one-way isolation optical switches, rather than based on the common TCP / IP protocol.

[0059] Business System (Law and Procuratorial Department): Each business system is responsible for the creation and management of cases, ensuring that each department (court, procuratorate, and judiciary) functions independently while working together.

[0060] Permission verification module:

[0061] The permission platform provides identity authentication, process node permissions, and case permissions functions;

[0062] The authority verification module is deployed on each back-end machine corresponding to the Law and Procuratorate Department. It monitors the data packets transmitted from the back-end machine of the Law and Procuratorate Department, calls the authority platform to perform authentication checks, and then places the data in the proxy directory after passing the authentication checks.

[0063] Process module:

[0064] Supports dynamic configuration of process nodes, and can add or delete nodes in the original process;

[0065] Connect to the business system of the Law and Procuratorate (simulation) to obtain case information, assemble the XML and document packages according to the data packet specifications of Topic 5, put them into the front-end machine and ferry them to the Political and Legal Affairs Commission.

[0066] Forwarding module:

[0067] Read the collaborative data package from the agent directory;

[0068] The information is forwarded to the front-end machine of the corresponding department.

[0069] Directory definition:

[0070] Receiving directory: The receiving directory of the optical gate ferry, which receives files sent from the other end.

[0071] Sending directory: The sending directory of the optical gate ferry. The files in the directory are to be sent to the other end.

[0072] Proxy directory: The directory of data packets scanned by the forwarding module. The permission verification module receives the file packets from the receiving directory and transfers them to the proxy directory after authentication.

[0073] Response directory: A directory used to respond to messages from the business system.

[0074] Example 1

[0075] See attached Figure 1As shown, the purpose of this embodiment is to provide a cross-domain dynamic authority authentication management system based on case granularity, including: a first server, a second server, a third server, and a fourth server;

[0076] The first server includes a first business system and a first process module; the second server includes a second business system and a second process module; the third server includes an authority verification module and a forwarding module; the fourth server includes a third business system and a third process module;

[0077] The first business system sends the case data to the first process module, and the first process module packages the files, wherein the files include an XML configuration file and a case document file;

[0078] The first process module transmits the data packet to the front-end sending directory, and the data packet enters the receiving directory area by crossing the optical gate;

[0079] The authority verification module verifies the authority of case information and process node information;

[0080] The forwarding module determines whether the data packet is sent to the second business system or the third business system according to the process node receiving unit;

[0081] If the data is transmitted to the second business system: the forwarding module puts the data packet into the sending directory of the front-end processor corresponding to the second business system, and the data packet enters the receiving directory area of the back-end processor by crossing the optical gate;

[0082] If the data is transmitted to a third business system: the forwarding module puts the data packet into the sending directory of the front-end processor corresponding to the third business system;

[0083] The second process module of the second server monitors the data packets received in the receiving directory area, parses the data packets and forwards the data packets to the second business system;

[0084] The third process module of the fourth server monitors the data packets received in the receiving directory area, parses the data packets and forwards the data packets to the third business system.

[0085] In this embodiment, the first server is a judicial server, the third server is a Political and Legal Affairs Commission server, the second server is a court server, and the fourth server is a procuratorate server.

[0086] The court business system is the second business system, the procuratorate business system is the third business system, and the judicial business system is the first business system.

[0087] A more detailed solution is as follows: The cross-domain data flow of the judicial and procuratorial departments includes three data routes (including judicial to court or procuratorate, court to judicial or procuratorate, and procuratorate to judicial or court). Figure 2It shows the data flow from the judiciary to the court or procuratorate. Figure 2 The process is as follows:

[0088] (1) The judicial business system in the judicial domain starts the process. The judicial business system in the judicial domain sends the case data to the first process module. The first process module packages the files, which include XML configuration files and case document files. The packaging method is a compressed package. The compressed package packaging process can use encryption packaging to enhance the security of the data package.

[0089] (2) The first process module puts the data packet into the sending directory of the judicial front-end machine, and the data packet enters the receiving directory area of the Political and Legal Affairs Commission domain by crossing the optical gate.

[0090] (3) The permission verification module listens to the data packets received in the receiving directory area, decompresses the data packets and parses the XML configuration files contained therein, performs permission verification on the case information and process node information, and records the verification results. If the verification is successful, the data packet is forwarded to the proxy directory area. If the verification fails, the failure record information is placed in the response directory area.

[0091] (4) The forwarding module monitors the data packets received in the proxy directory area, decompresses the data packets and parses the XML configuration files therein, and determines whether the data packets are sent to the court or the procuratorate according to the receiving unit of the process node.

[0092] If the data is transmitted to the court: the forwarding module puts the data packet into the sending directory of the court front-end machine, and the data packet enters the receiving directory area of the court domain back-end machine by crossing the optical gate.

[0093] If the data is transmitted to the procuratorate: the forwarding module puts the data packet into the sending directory of the procuratorate front-end machine, and the data packet enters the receiving directory area of the procuratorate domain back-end machine by crossing the optical gate.

[0094] (5) The process module in the court domain monitors the data packets received in the receiving directory area, parses the data packets and forwards them to the court business system.

[0095] The process module in the procuratorate domain listens to the data packets received in the receiving directory area, parses the data packets and forwards the data packets to the procuratorate business system.

[0096] Specifically, the process begins with the source business system generating a compressed package containing case-related information and the files required for transmission, and using encryption to protect the compressed package, which is then placed in a preset sending directory. The compressed package is transmitted to the receiving directory on the target side through a light gate mechanism, ensuring the integrity and confidentiality of the data during this process. The permission verification module on the receiving side decompresses and parses the received data packet, and performs permission verification on the case information and process node information based on the XML configuration file carried therein. After the verification is passed, the data packet is transferred to the proxy directory for further processing. Finally, the forwarding module forwards the data packet to the correct business department according to the instructions in the configuration file, completing the entire business flow process.

[0097] See attached Figure 2 As shown in the figure, the judicial business system contains two business processes. The first business process is that the judicial business system first obtains case information for the current process node from the process module, then passes the information of the new node to the process module. The process module packages the case information of the new node into a file and sends it through the judicial front-end machine through the optical gate. The other business process is that case information is sent from the Political and Legal Affairs Commission through the optical gate. After passing through the judicial back-end machine, the process module receives the data and pushes it to the judicial business system.

[0098] The technical solution of the present invention realizes a new cross-domain data transmission process of the Law and Procuratorate, adds a permission module, and realizes the permission management of cross-domain data through the collaboration of the permission module with the process module and the forwarding module.

[0099] This invention establishes a cross-domain configuration file, defines case resources and process nodes through an XML configuration file, packages the configuration file with the files to be transmitted across domains, and manages the case granularity of cross-domain data by parsing the configuration file, thereby achieving cross-domain data synchronization and permission control. Currently, the method of directly sending file directories via FTP is used.

[0100] The present invention establishes a case-based permission management system, adds a permission module, and combines the permission module with the case configuration to achieve more refined permission allocation and management. Currently, cross-domain files can only be managed manually.

[0101] The present invention establishes a system for dynamically configuring process nodes and performing authority management on the process nodes.

[0102] Through the present invention, fine-grained management and secure transmission of cross-domain data are achieved, information collaboration and efficient flow among various departments of the Law and Procuratorate are promoted, and the security of data processing and the overall efficiency of cross-domain collaborative work are improved.

[0103] Example 2

[0104] This embodiment discloses a cross-domain dynamic permission authentication management method based on case granularity. This method allows modification of basic case information, suspect information, and case documents at every stage of a case. For example, if a new document is added, modifying this information only requires modifying the corresponding information in the configuration file. Permissions to case resources can be verified on a case-by-case basis, automatically aligning with the modified information.

[0105] The method specifically includes:

[0106] Step 1: Dynamic case information configuration based on case granularity:

[0107] Step 2: Dynamic process configuration and business flow across optical gates in non-HTTP mode;

[0108] Step 3: Authenticate the permissions of case resources;

[0109] Step 4: Authenticate the permissions of the process nodes.

[0110] In step 1, the dynamic case information configuration based on case granularity specifically includes:

[0111] Step 1.1 Generate data items of cases and case document resources;

[0112] A case profile contains case information and case document information;

[0113] Case information includes basic case information and suspect information.

[0114] The basic case information includes the following data items:

[0115] Case identification, case name, case type code, case type name, cause of action code, cause of action name, names of parties or main persons involved in the case;

[0116] Criminal suspect information includes the following data items:

[0117] Case ID, case name, name, former name, gender, date of birth, marital status.

[0118] Case document information contains information about the documents corresponding to the case. A data item is the smallest unit of information in a configuration file. Case information and case document information are both composed of multiple data items.

[0119] Case document information includes the following data items:

[0120] Case identification, document number, document name, document type, and remarks.

[0121] Both case information and case document information contain multiple data items.

[0122] Step 1.2 Generate process node information

[0123] A business scenario can be divided into multiple process nodes, which contain the following data items:

[0124] Node number, sending unit, receiving unit, sending unit number, receiving unit number, process name, and corresponding case document resources.

[0125] The process system designs a set of process nodes based on cross-domain business scenarios. Each process node is assigned a node number, a sending unit, a receiving unit, and corresponding case document resources. Users can customize business scenarios and the process nodes they contain.

[0126] Step 1.3 Define the XML configuration file data format

[0127] The XML configuration file describes the basic case information of the specified case at the current process node, the document information corresponding to the process, and the current process node information.

[0128] Based on the data items generated in step 1.1 that can be converted to case and case document resources and the process node information generated in step 1.2, assemble and generate the data in the XML configuration file. The XML configuration file contains node information for a specific case and process node, as well as the case number for the specific case. These two types of information are used for case resource permission verification in step 3 and process node permission verification in step 4.

[0129] In step 2, the dynamic process configuration and business flow across the optical gate in non-HTTP mode, this step describes how to use XML configuration files and implement data packet flow across the optical gate in non-HTTP mode, compress and package the folders during the transmission process to improve the stability of the transmission, and encrypt and compress the compressed packages to improve the security of the transmission. The specific steps are as follows:

[0130] Step 2.1 Generate a data package containing the XML configuration file and case documents

[0131] First, place the XML configuration file and related case documents in the same folder. The process module then compresses and packages this folder. To improve data security, encryption can be used during the packaging process to compress the data, thus forming a complete cross-domain data package.

[0132] This step organizes the information of the confirmed document list into the case document resource section of the XML configuration file for management.

[0133] Step 2.2 Data packets are transmitted across the optical switch via non-HTTP methods

[0134] During service startup, the process module stores the prepared cross-domain data packets in the front-end's outgoing directory. The data packets are then transmitted across optical switches, transferring data between physically isolated networks rather than using standard HTTP protocols. The data packets are then transferred to the receiving directory of the back-end machine in the Political and Legal Affairs Commission domain.

[0135] During the data forwarding phase, the forwarding module reads and parses the process node information in the XML configuration file to determine the specific receiving department to which the data packet should be delivered. The forwarding module then places the data packet in the send directory of the corresponding business department's front-end processor. Through the cross-gate mechanism, it is transferred via FTP to the receive directory of the target business domain's back-end processor, thus completing cross-domain data transfer without HTTP.

[0136] Step 3: The permission module authenticates the case resources

[0137] The permission module allocates permissions and generates permission relationship information between users and case resources; the permission verification module verifies the permissions of case resources that need to be determined based on the permission relationship information and gives a result on whether the permissions are granted.

[0138] The present invention adds a permission verification module, and business personnel allocate permissions to case resources through the permission module. During the collaborative process, the permission verification module verifies the permissions of resources and users and makes permission judgments to realize the permission management of the collaborative process and enhance the security of the collaborative process.

[0139] Step 3.1 Configure case resource permissions at the case level.

[0140] During the system deployment phase, public security, procuratorial, and judicial personnel need to import the system's organizational structure into the permissions module to generate organizational structure information, which is stored in the permissions module database. This organizational structure information includes information about business departments and users within those departments.

[0141] Specifically, the existing Excel table of the unit's organizational structure is imported into the authority module. After the authority module parses the department and user information, it creates a department table, a user table, and a department-user relationship table in the authority module database to store the organizational structure information.

[0142] During the business initiation phase, when the business system generates a configuration file for the first time through the process module, it will generate a unique case number for the case in the business scenario. The case number is the primary key for the permission module to configure case permissions.

[0143] Based on case numbers and organizational structure information, public security, procuratorial and judicial personnel can use the authority module to allocate permissions to cases and documents within their business domain. They can also allocate permissions to specific departments or users and generate permission allocation information.

[0144] The permission allocation information is stored in the internal storage of the permission module and is stored in the local database.

[0145] Step 3.2 The permission module monitors the case resources and configuration file information of the Law and Procuratorate.

[0146] The permission module implements the permission service data packet monitoring mechanism and configures the permission service monitoring directory, proxy directory, and feedback directory. The service monitoring directory is the path where data packets are stored after they pass through the Political and Legal Affairs Commission's optical gate. The permission service monitors this directory to obtain data packets, parses the configuration files in the data packets, obtains the case and document information contained therein, and verifies the permissions of this information according to the configured permissions. The proxy directory is the storage directory for data packets after successful authentication by the permission service. The forwarding module monitors the proxy directory and forwards the data packets to the next node according to the process node information in the configuration file.

[0147] The permission verification module listens to the cross-domain data packets in the receiving directory and decompresses the cross-domain data packets. If the data packets are encrypted and compressed, they are decrypted and decompressed using the corresponding secret key to obtain the XML configuration file and the case document list.

[0148] The authority verification module parses the XML configuration file to obtain the case number and perpetrator information.

[0149] Step 3.3: Authenticate the case authority based on the case number and authority allocation information.

[0150] Permission determination process: After the authentication plug-in intercepts the data packet, it determines whether permissions have been configured. If not, it returns to step 3.1 and waits for permissions to be configured before proceeding. The unified case number is obtained from the XML file. The case's permission configuration is then retrieved using the unified case number. Permissions are then verified, taking the intersection of participating units, autonomous access, role access, and mandatory access. Unconfigured permissions are not determined.

[0151] Step 3.4 Permission verification result feedback

[0152] The permission module stores the permission verification results in the local database and provides a query interface for business system users to query.

[0153] After the permission verification is passed, the permission module places the cross-domain data packet in the proxy directory area for the forwarding module to forward the data packet. If the permission verification fails, the permission module generates a feedback data file and places it in the feedback directory area of the front-end machine. Through the cross-gate mechanism FTP transmission mechanism, the feedback data file is transferred to the receiving directory of the back-end machine of the original sending business domain.

[0154] See attached Figure 3As shown, step 4: the authority module authenticates the process node

[0155] The present invention adds a permission verification module. Business personnel use the permission module to allocate process node permissions to cases. During the collaborative process, the permission module verifies the process node permissions and makes permission judgments to realize the permission management of the collaborative process and enhance the security of the collaborative process.

[0156] Step 4.1 Configure case resource permissions based on process nodes.

[0157] During the system deployment phase, public security, procuratorial, and judicial personnel need to import the system's organizational structure into the permissions module to generate organizational structure information, which is stored in the permissions module database. This organizational structure information includes information about business departments and users within those departments.

[0158] The permissions module provides a function for entering process node information. During the system deployment phase, once the process node information included in the business scenario is determined, business personnel need to enter this process node information into the permissions module. This process node information is stored in the permissions module's local database.

[0159] Based on process nodes and organizational structure information, public security, procuratorial and judicial personnel can use the permission module to assign permissions to process nodes, which can be assigned to specific departments or users to generate permission allocation information.

[0160] The permission allocation information is stored in the internal storage of the permission module and is stored in the local database.

[0161] Step 4.2 The permission module monitors the case resources and configuration file information of the Law and Procuratorate.

[0162] The permission module implements the permission service data packet monitoring mechanism and configures the permission service monitoring directory, proxy directory, and feedback directory. The service monitoring directory is the path where data packets are stored after they pass through the Political and Legal Affairs Commission's optical gate. The permission service monitors this directory to obtain data packets, parses the configuration files in the data packets, obtains the case and document information contained therein, and verifies the permissions of this information according to the configured permissions. The proxy directory is the storage directory for data packets after successful authentication by the permission service. The forwarding module monitors the proxy directory and forwards the data packets to the next node according to the process node information in the configuration file.

[0163] The permission module listens to the cross-domain data packets in the receiving directory and decompresses the cross-domain data packets. If the data packets are encrypted and compressed, they are decrypted and decompressed with the corresponding secret key to obtain the XML configuration file and the case document list.

[0164] The permission verification module parses the XML configuration file to obtain the current process node information.

[0165] Step 4.3: Authenticate case permissions based on process node information and permission allocation information.

[0166] Permission Verification Process: After the authentication plug-in intercepts a data packet, it determines whether permissions have been configured. If not, it returns to step 4.1 and waits for permissions to be configured before continuing. The process node number is obtained from the XML file. The process node number is used to retrieve the case's process node permission configuration and perform permission verification.

[0167] Step 4.4 Permission verification result feedback

[0168] The permission module stores the permission verification results in the local database and provides a query interface for business system users to query.

[0169] After the permission verification is passed, the permission module places the cross-domain data packet in the proxy directory area for the forwarding module to forward the data packet. If the permission verification fails, the permission module generates a feedback data file and places it in the feedback directory area of the front-end machine. Through the cross-gate mechanism FTP transmission mechanism, the feedback data file is transferred to the receiving directory of the back-end machine of the original sending business domain.

[0170] Step 1 organizes a configuration file based on case information and the process node it falls into. This configuration file is primarily used for transmission to steps 3 and 4, which parse the configuration file to obtain case information and verify permissions for that information. Step 2 primarily serves as a data transfer hub.

[0171] Through the above-mentioned sub-technical solution of this embodiment, an XML configuration file is created to manage cross-domain resources of cases, and by inserting the permission authentication link, permission management with case granularity can be realized. By dynamically configuring process node information through the configuration file, permission management of process nodes can be realized, thereby realizing trusted transmission of case resource data across optical gates.

[0172] The present invention proposes a dynamic permission authentication method and system for cross-domain public security, procuratorial and judicial departments. By designing configuration files to manage cross-domain resources, it realizes permission management based on case granularity, and realizes trusted transmission of case resource data across optical gates by verifying the permissions of case resources.

[0173] Based on case-level dynamic case information configuration, this embodiment's sub-technical solution uses XML configuration files as a bridge to achieve cross-domain case information transmission. Unlike traditional FTP-based file management, this invention defines case resources and process nodes through XML files, thereby achieving cross-domain data synchronization and permission control.

[0174] Cases, criminals, and document information are defined through XML files, and document list information is encapsulated in XML format, making it easier for the authority module, process module, and forwarding module to read and parse. The nodes of the business process are defined through XML files, making it easier for the authority module and process module to read and parse.

[0175] Dynamic process configuration and business flow across optical gates in non-HTTP manner. Without relying on the HTTP protocol, the present invention establishes a standardized data packet transmission process on both sides of the optical gate, so that data can be safely and reliably circulated across optical gates in a physically isolated network environment.

[0176] The present invention allows business users to configure specific process node information in different business scenarios through the process system, define the nodes where the business process is located through XML files, and parse the process node information in the configuration file through the process system to realize the automatic operation of the entire process of the business scenario, thereby enhancing the flexibility and efficiency of cross-domain business processing.

[0177] A directory-based permission interception system based on the optical gate: During data transmission, this invention introduces a directory-level permission management mechanism. By establishing specific directories on both sides of the optical gate, including receiving directories, sending directories, proxy directories, and response directories, permission interception and verification of data packets are achieved, ensuring that only authenticated data can continue to flow.

[0178] The sub-technical solutions of this embodiment are the authentication method and system for dynamic configuration management of process nodes in cross-domain business scenarios and configuration management of case resource permissions, which can realize the safe and efficient cross-domain flow of case resources and improve the collaborative efficiency of law enforcement and prosecution departments.

[0179] Example 3

[0180] The purpose of this embodiment is to provide a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the above method when executing the program.

[0181] Example 4

[0182] The purpose of this embodiment is to provide a computer-readable storage medium.

[0183] A computer-readable storage medium stores a computer program, which, when executed by a processor, performs the steps of the above method.

[0184] Example 5

[0185] The purpose of this embodiment is to provide a computer program product containing instructions, which, when running on a computer, enables the computer to execute the methods and functions involved in any of the above embodiments.

[0186] The steps involved in the apparatuses in the above embodiments 3, 4, and 5 correspond to those in the method embodiment 2. For detailed implementation, please refer to the relevant description of embodiment 2. The term "computer-readable storage medium" should be understood to mean a single medium or multiple media that includes one or more instruction sets; it should also be understood to include any medium that can store, encode, or carry an instruction set for execution by a processor and cause the processor to perform any method of the present invention.

[0187] Those skilled in the art will appreciate that the modules or steps of the present invention described above can be implemented using a general-purpose computer device. Alternatively, they can be implemented using program code executable by a computing device, which can then be stored in a storage device and executed by the computing device. Alternatively, they can be fabricated into separate integrated circuit modules, or multiple modules or steps can be fabricated into a single integrated circuit module for implementation. The present invention is not limited to any specific combination of hardware and software.

[0188] Although the above describes the specific embodiments of the present invention in conjunction with the accompanying drawings, it is not intended to limit the scope of protection of the present invention. Those skilled in the art should understand that various modifications or variations that can be made by those skilled in the art on the basis of the technical solution of the present invention without any creative work are still within the scope of protection of the present invention.

Claims

1. A cross-domain dynamic authority authentication management method based on case granularity, characterized by: include: Configure dynamic case information based on case granularity, including: generating data item information of cases and case document resources, and generating process node information; Assemble and generate data in the XML configuration file based on the generated case and case document resource data item information and the generated process node information; For XML configuration files, data packets are transferred across optical switches using non-HTTP methods, including: Put the XML configuration file and related case documents into the same folder; Then, compress and package the above folders. During the packaging process, encryption can be selected to compress and form a complete cross-domain data package. During the service startup phase, the prepared cross-domain data packets are stored in the front-end's send directory. Next, the data packets are transmitted across optical gates, passing data between physically isolated networks, and are transferred to the set back-end's receive directory. During the data forwarding phase, the process node information in the XML configuration file is read and parsed to determine the specific receiving department to which the data packet should be delivered. The data packet is then placed in the sending directory of the corresponding business department's front-end processor and transferred via FTP to the receiving directory of the target business domain's back-end processor via the cross-gate mechanism, completing cross-domain data transfer in a non-HTTP manner. During the transfer process, the case resources are authenticated. Once the authentication is passed, the cross-domain data packet is placed in the proxy directory area for data packet forwarding. Then, the process node is authenticated. After the authentication is passed, the cross-domain data packet is placed in the proxy directory area for data packet forwarding. The XML configuration file includes node information of a specified case and a specified process node, and the case number of the specified case. These two types of information are used in case resource authority verification and process node authority verification.

2. A cross-domain dynamic authority authentication management method based on case granularity as claimed in claim 1, characterized in that: Authenticate case resources, including: Configure case resource permissions based on case granularity; Monitor case resources and configuration file information of the Judicial and Procuratorial Department; Authenticate case authority based on case number and authority allocation information; The permission verification results are stored in the local database, and a query interface is provided for business system users to query; Perform permission authentication on case resources. If permission authentication fails, generate a feedback data file and place it in the front-end machine of the feedback directory area. Through the cross-gate mechanism FTP transmission mechanism, the feedback data file is transferred to the receiving directory of the back-end machine of the original sending business domain.

3. The cross-domain dynamic authority authentication management method based on case granularity as claimed in claim 1 is characterized in that: Perform permission authentication on process nodes, including: Configure case resource permissions based on process nodes; Monitor case resources and configuration file information of the Judicial and Procuratorial Department; Authenticate case authority based on process node information and authority allocation information; The permission verification results are stored in the local database, and a query interface is provided for business system users to query.

4. The cross-domain dynamic permission authentication management method based on case granularity as claimed in claim 1 is characterized in that: Perform authority authentication on the process node. If the authority verification fails, generate a feedback data file and place it in the front-end machine of the feedback directory area. Through the cross-gate mechanism FTP transmission mechanism, the feedback data file is transmitted to the receiving directory of the back-end machine of the original sending business domain.

5. A system for implementing a case-based cross-domain dynamic authority authentication management method according to any one of claims 1 to 4, characterized in that: include: a first server, a second server, a third server, and a fourth server; The first server includes a first business system and a first process module; The second server includes a second business system and a second process module; the third server includes an authority verification module and a forwarding module; the fourth server includes a third business system and a third process module; The first business system sends the case data to the first process module, and the first process module packages the files, wherein the files include an XML configuration file and a case document file; The first process module transmits the data packet to the front-end sending directory, and the data packet enters the receiving directory area by crossing the optical gate; The authority verification module verifies the authority of case information and process node information; The forwarding module determines whether the data packet is sent to the second business system or the third business system according to the process node receiving unit; If the data is transmitted to the second business system: the forwarding module puts the data packet into the sending directory of the front-end processor corresponding to the second business system, and the data packet enters the receiving directory area of the back-end processor by crossing the optical gate; If the data is transmitted to a third business system: the forwarding module puts the data packet into the sending directory of the front-end processor corresponding to the third business system; The second process module of the second server monitors the data packets received in the receiving directory area, parses the data packets and forwards the data packets to the second business system; The third process module of the fourth server monitors the data packets received in the receiving directory area, parses the data packets and forwards the data packets to the third business system.

6. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the method according to any one of claims 1 to 4 is implemented.

7. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, the steps of the method according to any one of claims 1 to 4 are implemented.

8. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the steps of the method according to any one of claims 1 to 4 are performed.

Citation Information

Patent Citations

  • Remote policing system and method based on public security network and public security digital certificate authentication

    CN112434998B

  • Judicial data sharing system, method and computer equipment based on cross-chain

    CN117879785B

  • Judicial data sharing system and method based on cross-chain and computer equipment

    CN117879785A

  • Intelligent network connection automobile fine-grained data evidence obtaining method based on conditional agent re-encryption

    CN118102289A