Resource management method, system and equipment based on user authentication and medium

By generating unified authentication account information and allocating resource management tokens, the problems of inconsistent resource management between enterprise application platforms and cumbersome user authentication are solved, and work efficiency and user experience are improved.

CN120277646APending Publication Date: 2025-07-08AULTON NEW ENERGY AUTOMOBILE TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410377634.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-12-29
Filing Date
2024-03-29
Publication Date
2025-07-08

AI Technical Summary

Technical Problem

It is difficult to achieve unified resource management among existing enterprise application platforms, and user authentication methods are cumbersome, which affects work efficiency and user experience.

Method used

By generating unified authentication account information, assigning resource management tokens, determining the application platform permission set, and displaying the corresponding application platform on the user terminal, unified authentication and resource management are achieved.

Benefits of technology

Reduces login errors among users between different application platforms, improves work efficiency and user experience, simplifies the authentication process, and ensures the unity of data integrity and permission management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120277646A_ABST
    Figure CN120277646A_ABST
Patent Text Reader

Abstract

The invention provides a resource management method, system and device based on user authentication and a medium, and belongs to the technical field of internet platform resource management. The method comprises the following steps: in response to a newly-added operation of a management terminal, registering input user information to a user center, and generating corresponding unified authentication account information; the newly-added operation represents the operation of the newly-added user; after a login request corresponding to the unified authentication account information is received, allocating a resource management token to a login account corresponding to the login request to determine an application platform permission set corresponding to the login account; the application platform permission set comprises one or more application platforms in the application platform set, and the login account has operation permissions of the application platforms; and loading corresponding application platform display information according to the application platform permission set, and displaying the information on a corresponding user terminal, so as to enter any corresponding application platform based on the operation of the user on the user terminal, and carry out corresponding resource management operation.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application claims priority based on the invention patent application titled "A Resource Management Method, System, and Device Based on User Authentication" with an application number of 202311871525.8, which was filed with the China National Intellectual Property Administration on December 29, 2023. This application incorporates the entire text of the above-mentioned Chinese patent application by reference. Technical Field

[0002] This application relates to the technical field of resource management in Internet platforms, and particularly to a resource management method, system, device, and medium based on user authentication. Background Art

[0003] With the continuous development of Internet technology, enterprises have developed application platforms for different departments, different businesses, or different users to assist in handling enterprise operations. Especially for enterprises with a certain scale, a large number of personnel, and a complex department structure, the number of enterprise application platforms will be even more.

[0004] During the use of enterprise application platforms, the frequency of user authentication is also very high. The purpose is to provide platform usage permissions after user authentication, which can ensure the security of enterprise data resources. Therefore, it is becoming increasingly important to complete user authentication effectively and stably, which can improve the information resource security of enterprises and the work efficiency of enterprise users, and effectively manage enterprise resources.

[0005] Previous user authentication methods usually adopted the single sign-on method for user authentication of enterprise application platforms. With the development of enterprises, enterprise application platforms will gradually grow to a relatively large scale and achieve function segmentation. At the same time, the users faced by enterprise application platforms are constantly expanding, and users may correspond to one or more enterprise application platforms. The above method cannot bring a good platform usage experience to enterprises and users. Because when there are multiple platforms, some users may need to remember different accounts and passwords and perform platform switching authentication to manage enterprise resources on different platforms, which may lead to login errors or login failures, and situations where the currently handled business does not match the currently logged-in account among the current platforms with inconsistent data resources, resulting in business handling errors. This not only affects work efficiency but also easily makes users have a resistant mood and a bad enterprise system usage experience. Summary of the Invention

[0006] Embodiments of this application provide a resource management method, system, device, and medium based on user authentication, which are used to solve the problems that it is difficult to achieve unified resource management among current enterprise application platforms, the user authentication method is cumbersome, affecting work efficiency and the user's system usage experience.

[0007] On the one hand, embodiments of this application provide a resource management method based on user authentication, and the method includes:

[0008] In response to the new operation of the management terminal, register the input user information into the user center and generate corresponding unified authentication account information; the new operation represents an operation to add a new user.

[0009] After receiving a login request corresponding to the unified authentication account information, allocate a resource management token to the login account corresponding to the login request to determine the set of application platform permissions corresponding to the login account; the set of application platform permissions includes one or more application platforms in the application platform set, and the login account has the operation permissions for the application platforms.

[0010] According to the set of application platform permissions, load the corresponding application platform display information and display it on the corresponding user terminal, so as to enter any one of the corresponding application platforms based on the user's operation on the user terminal and perform corresponding resource management operations.

[0011] Through the above solution, generating unified authentication account information enables the corresponding user to log in to the application platforms with operation permissions, avoiding the problem of login errors or failures to a certain extent. By only displaying the application platforms with operation permissions for the login account, it is possible to avoid the problem of incorrect business handling when the currently handled business does not match the login account, improving work efficiency and user experience.

[0012] In one implementation manner of the present application, registering the input user information into the user center and generating corresponding unified authentication account information specifically includes:

[0013] Obtain the user information input by the new operation; the user information at least includes the operation permissions of the user for each application platform.

[0014] Generate a permission list corresponding to the user information, record it in the user center, and obtain the login account corresponding to the user in the user center.

[0015] According to the login account and the single sign-on module, generate a synchronization account corresponding to the user in the single sign-on module; the synchronization account is used to call the single sign-on module to log in to the historical login account and obtain the operation permissions and resource management records of the historical login account.

[0016] Perform an association process on the login account and the corresponding synchronization account to generate the unified authentication account information corresponding to the user after the association process.

[0017] Through the above solution, the accounts on the historical platform can be synchronized to the unified authentication platform, and user data can be unified on the premise of ensuring data integrity; and different operation permissions can be provided to different logged-in accounts, which can avoid problems such as incorrect business handling due to the mismatch between the currently processed business and the currently logged-in account when the login account is incorrect.

[0018] In an implementation manner of the present application, before registering the input user information into the user center, the method further includes:

[0019] Determine the specified operation permission and / or specified role corresponding to the new operation; there is a corresponding relationship between the specified role and one or more of the specified operation permissions;

[0020] Based on the specified role determined after completing the new operation, determine the role association degree with the historical registered role; the role association degree is obtained based on the operation permission corresponding business attribute vectors of each role; each business attribute corresponding to the business attribute vector is obtained based on the usage frequency and usage functions of the role for each application platform;

[0021] Determine the historical registered roles corresponding to the maximum and minimum values respectively among the role association degrees, so as to generate an associated role triple according to the obtained two historical registered roles and the specified role;

[0022] According to the intersection set of business attributes corresponding to the associated role triple, determine the corresponding filtered business attributes;

[0023] According to the filtered business attributes, update the specified business attribute set corresponding to the specified role, so as to determine the application platform permission set corresponding to the user information according to the updated specified business attribute set.

[0024] Through the above solution, according to the actual usage frequency and usage functions of the application platform, and according to different roles, the operation permissions of roles for different application platforms can be adaptively updated. On the one hand, the application platforms corresponding to users can be obtained more intelligently. On the other hand, by flexibly updating the permissions, the manpower investment in researching user requirements can be saved, and the development time invested by developers can be saved.

[0025] In an implementation manner of the present application, before performing the corresponding resource management operation, the method further includes:

[0026] Obtain the application platform to be entered selected by the user on the user terminal;

[0027] According to the user information corresponding to the logged-in account and the selected application platform to be entered, determine the menu items corresponding to the specified operation permissions of the user;

[0028] Generate a system menu tree corresponding to the selected application platform to be accessed and including each of the menu items, and display it on the user terminal.

[0029] Through the above solution, a more hierarchical menu tree is provided for users to use, reducing the operation difficulty of the application platform for users. At the same time, the menu items in the menu tree are related to the user operation permissions, which can reduce the complexity of the user display interface, retain the effective functions, provide them to the users, and improve the user experience.

[0030] In one implementation manner of the present application, before allocating a resource management token to the login account corresponding to the login request, the method further includes:

[0031] Real-time monitor the change of the account role corresponding to each unified authentication account information in the user center;

[0032] In the case where the account role corresponding to the unified authentication account information changes, update the application platform permission set of the corresponding user.

[0033] By monitoring the change of the user role and updating the application platform permission set, there is no need for manual adjustment in the background, improving the intelligence level of the system.

[0034] In one implementation manner of the present application, after determining the specified operation permission and / or specified role corresponding to the new operation, the method further includes:

[0035] Obtain the historical usage frequencies of several roles identical to the specified role for each of the application platforms;

[0036] In the case where the historical usage frequency is less than a preset threshold, use the operation permission of the corresponding application platform as the exclusion permission;

[0037] Exclude the corresponding exclusion permission from the specified operation permission of the specified role to update the specified operation permission corresponding to the specified role.

[0038] Utilize the historical usage frequency in the actual usage scenario to update the specified operation permission, so that the specified operation permission no longer depends on manual specification and can be automatically updated, making it easier and more convenient for users to add new operations and reducing the workload in manual adjustment.

[0039] In one implementation manner of the present application, the method further includes:

[0040] After receiving a resource management instruction from the user terminal on the corresponding application platform, match the operation permission corresponding to the resource management token with the management resource information corresponding to the resource management instruction to verify the resource management token corresponding to the resource management instruction;

[0041] When the resource management token passes the verification, execute the resource management instruction.

[0042] Through the above solution, after logging in, verify the resource management token of the proposed resource management instruction to ensure that the management is legal and avoid problems such as management overrun and business processing errors.

[0043] In an implementation manner of the present application, the method further includes:

[0044] When the resource management token fails to pass the verification, generate an invalid login prompt message and send it to the user terminal;

[0045] After receiving the re-login request of the user terminal within a predetermined time, determine the corresponding re-login account to redirect to the redirect application platform corresponding to the re-login account of the re-login request;

[0046] On the redirect application platform, match the operation permissions corresponding to the resource management token of the re-login account with the corresponding management resource information to verify the resource management token corresponding to the resource management instruction so as to execute the resource management instruction.

[0047] Through the above solution, when the user logs in to the wrong account, the user can be reminded and log in to the correct account for resource management, effectively avoiding problems in business processing.

[0048] On the other hand, the embodiment of the present application further provides a resource management system based on user authentication, and the system includes:

[0049] A registration generation module, configured to respond to a new operation of a management terminal, register the input user information in a user center, and generate corresponding unified authentication account information; the new operation represents an operation of adding a user;

[0050] An allocation module, configured to, after receiving a login request corresponding to the unified authentication account information, allocate a resource management token to the login account corresponding to the login request to determine an application platform permission set corresponding to the login account; the application platform permission set includes one or more application platforms in an application platform set, and the login account has operation permissions for the application platform;

[0051] A loading and display module, configured to load corresponding application platform display information according to the application platform permission set and display it on a corresponding user terminal, so as to enter any one of the corresponding application platforms based on the user's operation on the user terminal for corresponding resource management operations.

[0052] In another aspect, an embodiment of the present application further provides a resource management device based on user authentication, and the device includes:

[0053] At least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and when the instructions are executed by the at least one processor, the at least one processor is enabled to:

[0054] In response to a new operation of the management terminal, register the input user information into the user center to generate corresponding unified authentication account information; the new operation represents an operation of adding a new user;

[0055] After receiving a login request corresponding to the unified authentication account information, allocate a resource management token to the login account corresponding to the login request to determine the application platform permission set corresponding to the login account; the application platform permission set includes one or more application platforms in the application platform set, and the login account has operation permissions for the application platform;

[0056] According to the application platform permission set, load corresponding application platform display information and display it on the corresponding user terminal, so as to enter any one of the corresponding application platforms based on the user's operation on the user terminal and perform corresponding resource management operations.

[0057] In yet another aspect, an embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it realizes:

[0058] In response to a new operation of the management terminal, register the input user information into the user center to generate corresponding unified authentication account information; the new operation represents an operation of adding a new user;

[0059] After receiving a login request corresponding to the unified authentication account information, allocate a resource management token to the login account corresponding to the login request to determine the application platform permission set corresponding to the login account; the application platform permission set includes one or more application platforms in the application platform set, and the login account has operation permissions for the application platform;

[0060] According to the application platform permission set, load corresponding application platform display information and display it on the corresponding user terminal, so as to enter any one of the corresponding application platforms based on the user's operation on the user terminal and perform corresponding resource management operations.

[0061] A resource management method, system, device, and medium based on user authentication provided by an embodiment of the present application have the following technical effects:

[0062] First, this application registers user information in the user center and generates unified authentication account information. Users can use the unified authentication account information to log in to the system that includes multiple application platforms uniformly. Then, when logging in, a resource management token can be allocated and the application platform permissions for the corresponding application platform can be determined. Then, the application platforms with operation permissions are displayed on the user terminal so that users can perform resource management operations according to the displayed application platforms. This application can reduce the operations when users log in to different application platforms, enable users to achieve unified resource management among application platforms, and reduce the complexity of the user authentication method, which can improve the work efficiency of user resource management. The user terminal can display the application platform display interface corresponding to its operation permissions, and users can perform resource management more flexibly and with fewer mistakes, ensuring the user's system usage experience. BRIEF DESCRIPTION OF THE DRAWINGS

[0063] The drawings described herein are used to provide a further understanding of this application, form a part of this application, and the schematic embodiments of this application and their descriptions are used to explain this application, and do not constitute an improper limitation to this application. In the drawings:

[0064] Figure 1 It is a schematic flowchart of a resource management method based on user authentication in an embodiment of this application;

[0065] Figure 2 It is another schematic flowchart of a resource management method based on user authentication in an embodiment of this application;

[0066] Figure 3 It is a schematic diagram of the business attribute intersection set in a resource management method based on user authentication in an embodiment of this application;

[0067] Figure 4 It is a schematic structural diagram of a resource management system based on user authentication in an embodiment of this application;

[0068] Figure 5 It is a structural diagram of a resource management device based on user authentication in an embodiment of this application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0069] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below in conjunction with the specific embodiments of this application and the corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of this application.

[0070] The embodiments of the present application provide a resource management method, system, device and medium based on user authentication, which are used to solve the technical problems that it is difficult to achieve unified resource management between current enterprise application platforms, the user authentication method is cumbersome, affecting work efficiency and the user's system usage experience.

[0071] The following will describe each embodiment of the present application in detail with reference to the accompanying drawings.

[0072] The embodiments of the present application provide a resource management method based on user authentication, as Figure 1 shown, the method may include steps S101 - S103:

[0073] S101, in response to the addition operation of the management terminal, the server registers the input user information into the user center and generates corresponding unified authentication account information. The addition operation represents the operation of adding a user. The unified authentication account information represents the unified authentication information of the login accounts of the user on at least two application platforms. For example, the unified authentication account information may be the association information or account synchronization information of the login accounts of the user on at least two application platforms.

[0074] In another flow schematic diagram of a resource management method based on user authentication provided by the present application, as Figure 2 shown, the method may include steps S201 - S202:

[0075] S201, in response to the addition operation of the management terminal, the server registers the input user information into the user center and generates corresponding unified authentication account information.

[0076] S202, after the server receives a login request corresponding to the unified authentication account information, it allocates a resource management token to the login account corresponding to the login request to determine the application platform permission set corresponding to the login account. The resource management token is generated based on the user center after registering the user information. The application platform permission set includes one or more application platforms in the application platform set, and the login account has the operation permission for the application platform.

[0077] S203, the server loads the corresponding application platform display information according to the application platform permission set and displays it on the corresponding user terminal, so as to enter any corresponding application platform based on the user's operation on the user terminal and perform corresponding resource management operations.

[0078] It should be noted that the server, as the execution entity of the resource management method based on user authentication, is only an exemplary existence, and the execution entity is not limited to the server. The present application does not make specific limitations on this.

[0079] The management terminal can be an operation user center for user identity registration, establishing an account for resource management and using the resource management system corresponding to this application. The management terminal can be a device such as a computer or a mobile phone, and this application does not make specific limitations on this. The above-mentioned new operation refers to the operation of adding a new user. More specifically, it can be understood as inputting user information including the user's name, role (i.e., identity), operation permissions, etc. in the user center to add a new user. The specific user information can be adjusted during actual use, and this application does not make specific limitations on this.

[0080] During actual use, the generated unified authentication account information can specifically be included in the login credentials, such as the account name and password, for logging in to the resource management system. The user center can include a user center platform for logging in to the user center and providing a corresponding front-end operation interface to support the operation of adding new users; it also includes a user center gateway for forwarding requests from the user center or other application platforms and verifying the token (resource management token) of the corresponding requests; it also includes a user center application for setting the user's permissions for the application platform; it also includes a user center account service for recording the above-mentioned unified authentication account information.

[0081] At the same time, this application is a user authentication technical solution provided on the basis of the original single sign-on (SSO) system. Specifically, after the server records the unified authentication account information in the user center account service, it can construct interaction parameters. These interaction parameters correspond to the account information of the current unified authentication account information on the original single sign-on system. By using the interaction parameters to call the SSO and adding a new user on the original single sign-on system, it can be realized that the old information under the original single sign-on system can be accessed through the unified authentication account information, and new system information can also be accessed. The interaction parameters correspond to the association relationship between the login account and the corresponding synchronized account and are included in the unified authentication account information.

[0082] The resource management system of this application can interact with the original single sign-on system to ensure that data will not be lost, unify the data of the user on the old and new platforms, and there is no need to consume labor costs for data migration, with lower costs.

[0083] In an embodiment of this application, registering the input user information in the user center to generate the corresponding unified authentication account information is specifically as follows:

[0084] Obtain the user information of the newly added operation input. The user information includes at least the operation permissions of the user for each application platform. Generate a permission list corresponding to the user information, record it in the user center, and obtain the login account corresponding to the user in the user center. According to the login account and the single sign-on module, generate the synchronization account corresponding to the user in the single sign-on module. The synchronization account is used to call the single sign-on module to log in to the historical login account and obtain the operation permissions and resource management records of the historical login account. Perform an association process on the login account and the corresponding synchronization account to generate the unified authentication account information corresponding to the user after the association process.

[0085] The above operation permissions can be determined based on the role and the role association degree. The permission list records the corresponding relationship between the application platform and the operation permissions. Among the records of the permission list in the user center, a login account can be generated for the user. The login account represents the account assigned to the user by the user center and can be used to log in to the application platform with operation permissions. The synchronization account represents the historical login account of the original SSO system. The association process means associating the login account with the synchronization account so that there is an association relationship between the login account and the synchronization account, and generating the unified authentication account information according to this association relationship. For example, add the association relationship between the login account and the synchronization account information to the unified authentication account information.

[0086] In other words, analyze the operation permissions for each application platform included in the user information, and the operation permissions can be determined by the role in the user information and its role association degree with other roles. Load the operation permissions into the permission list to obtain the login account of the user in the user center. Subsequently, the server establishes the synchronization account corresponding to the single sign-on module according to the login account and the single sign-on module, which is used for the historical login account of the SSO platform. The server also establishes an association relationship between the login account and the synchronization account to generate the unified authentication account information including this association relationship.

[0087] In addition, after the generation of the unified authentication account information is completed, the synchronization account can also be removed from the historical login account corresponding to the single sign-on module.

[0088] One login account in this application can correspond to one or more synchronization accounts. For example, if a login account has the operation permissions for Application Platform 1 and Application Platform 2, and the single sign-on module has historical login account 1 and historical login account 2 for Application Platform 1 and Application Platform 2 respectively, then there is an association relationship between one login account and historical login account 1 and historical login account 2, that is, one login account corresponds to these two historical login accounts, so as to obtain the corresponding unified authentication account information.

[0089] Through the above solution, the accounts on the historical platform can be synchronized to the unified authentication platform of this application, and the user data can be unified on the premise of ensuring data integrity. Moreover, different operation permissions are provided to different logged-in accounts, which can avoid problems such as incorrect business handling when the logged-in account is incorrect and the currently handled business does not match the currently logged-in account.

[0090] In an embodiment of this application, the operation permissions in the user information are often specified manually, and multiple and repeated determinations may be required offline. Or, a certain or certain operation permissions are fixedly assigned, and adjustments are made later if necessary. On the one hand, the fixedly assigned operation permissions may not be the commonly used ones of the corresponding users, or the commonly used operation permissions are not assigned to the users, resulting in poor user experience; on the other hand, subsequent adjustments consume communication costs and manual adjustment workload. Therefore, this application provides the following solution before registering the input user information into the user center, including:

[0091] First, determine the specified operation permissions and / or specified roles corresponding to the new operation. There is a corresponding relationship between the specified roles and one or more specified operation permissions. Then, based on the specified roles determined after completing the new operation, determine the role association degree with the historical registered roles. The role association degree is obtained based on the operation permission corresponding business attribute vectors of each role. Each business attribute corresponding to the business attribute vector is obtained based on the usage frequency and usage functions of the role for each application platform. Subsequently, determine the historical registered roles corresponding to the maximum and minimum values in each role association degree respectively, so as to generate an associated role triple according to the two obtained historical registered roles and the specified roles. Then, determine the corresponding filtered business attributes according to the intersection of the business attributes corresponding to the associated role triple. Then, update the specified business attribute set corresponding to the specified role according to the filtered business attributes, so as to determine the application platform permission set corresponding to the user information according to the updated specified business attribute set.

[0092] In the actual use process, the above new operation can be operated by the administrator or the user, and the operation can provide the specified operation permissions and / or specified roles bound to the user information. Among them, there is a corresponding relationship between the provided specified operation permissions and specified roles. If the new operation provides specified operation permissions, the server will automatically judge the associated specified roles, and if it provides specified roles, it will also automatically judge the corresponding specified operation permissions. The specified operation permissions represent the operation permissions selected by the administrator or the user in the new operation. For example, the first specified operation permission has the usage permission for the application platform M, and the second specified operation permission has the usage permission for the application platform M2. The specified role represents the role with pre-existing specified operation permissions, and different specified roles may correspond to different specified operation permissions; for example, the specified role Y1 has the first specified operation permission; the specified role Y2 has the second specified operation permission.

[0093] After obtaining the specified role, the server can generate a first service attribute vector from the operation permissions of the specified role, and generate a second service attribute vector from the operation permissions corresponding to the historical registered roles. The service attribute vector is composed of service attributes that meet the predetermined conditions for the usage functions and corresponding usage frequencies of the corresponding application platforms. The predetermined conditions are used to determine whether the usage frequency corresponding to the usage function is greater than the predetermined value. For example, if a role has a first operation permission for function a of application platform A and the usage frequency is greater than a predetermined value, the first service attribute is obtained; the role has a second operation permission for function b of application platform B and the usage frequency is greater than the predetermined value, the second service attribute is obtained, and the first service attribute and the second service attribute are encoded to generate the service attribute vector of the role. The predetermined value is set according to actual usage and is used to screen service attributes. The present application does not make specific limitations on this. By calculating the role association degree between the first service attribute vector and each second service attribute vector, the role association degree represents the degree of association between the specified role and the historical registered roles. Specifically, the role association degree can be obtained by calculating the cosine similarity between vectors or the reciprocal of the Euclidean distance, etc. The present application does not make specific limitations on the specific calculation method for calculating the role association degree.

[0094] After calculating the role association degrees of all roles, the server will compare the sizes of the role association degrees, select the maximum value and the minimum value. The maximum value is the one closest to the specified role, and the minimum value is the one least close to the specified role. Calculate the intersection and difference sets of the two service attribute sets of the historical registered roles corresponding to the maximum value and the minimum value, and the service attribute set of the specified role, to obtain the service attribute intersection and difference set corresponding to the associated role triple. As Figure 3 shown, it is a schematic diagram of a service attribute intersection and difference set. For example, the original specified service attribute set X of the specified role includes {x1, x2, x3, x4}, the service attribute set Y of the historical registered role corresponding to the maximum value is {x1, x2, y1, z2}, and the service attribute set Z of the historical registered role z1 corresponding to the minimum value is {x2, x4, z1, z2}. The common intersection of the three sets XYZ of the associated role triple is {x2}, the set intersection of XY is {x1}, the set intersection of XZ is {x4}, the set intersection of YZ is {z2}, the set difference between Y and X, Z is {y1}, the set difference between X and Y, Z is {x3}, and the set difference between Z and X, Y is {z1}. Among them, screening service attributes at least includes eliminating service attributes, adding service attributes, and retaining service attributes. For example, x4 above is an eliminated service attribute, y1 is an added service attribute, and x1, x2, x3 are retained service attributes. Update the specified service attribute set {x1, x2, x3, x4} according to the screened service attributes, so as to generate the application platform permission set corresponding to the user information.

[0095] Through the above solution, according to the actual usage frequency of the application platform and different roles, the operation permissions of the role for different application platforms can be adaptively updated. On the one hand, the corresponding application platform of the user can be obtained more intelligently, improving the user experience. On the other hand, by flexibly updating the permissions, the manpower investment in researching user needs can be saved, and the time invested by developers and the time for subsequent permission adjustment can be saved.

[0096] In an embodiment of the present application, after determining the specified operation permission and / or the specified role corresponding to the newly added operation, it further includes:

[0097] Obtain the historical usage frequencies of several roles the same as the specified role for each application platform. In the case where the historical usage frequency is less than the preset threshold, the operation permission of the corresponding application platform is used as the exclusion permission. From the specified operation permissions of the specified role, the corresponding exclusion permissions are excluded to update the specified operation permissions corresponding to the specified role. The preset threshold is a threshold set based on the actual usage scenario, and the present application does not make specific limitations on this.

[0098] In other words, after receiving the specified role from the management terminal, the server can perform re-analysis. First, obtain the historical usage frequencies of the roles the same as the specified role for each application platform. If there is an application platform with a historical usage frequency less than the preset threshold specified in advance by the developer, the operation permission for this application platform is excluded from the specified operation permissions.

[0099] The above solution uses the historical usage frequency in the actual usage scenario to update the specified operation permissions, enabling the specified operation permissions to be updated automatically instead of relying on manual specification, making it easier and more convenient for users to add new ones, and reducing the workload during manual adjustment.

[0100] S102. After the server receives a login request corresponding to the unified authentication account information, it allocates a resource management token to the login account corresponding to the login request to determine the application platform permission set corresponding to the login account. The login request can be understood as the login request corresponding to the login operation when the user uses the unified authentication account information to log in to the application platform and the server receives it. The resource management token is generated by the user center after registering the user information in the user center. The application platform permission set includes one or more application platforms in the application platform set, and the login account has the operation permission for the application platform.

[0101] In the user login process, the server verifies the login request, that is, verifies whether the unified authentication account information already exists in the server. If it exists, the login verification passes; otherwise, the login is not allowed. If the login verification passes, the server can obtain the resource management token generated by the user center and assign the resource management token, i.e., the token, to the login account corresponding to the login request. That is to say, the server associates the token with the login account. Among them, the token and its corresponding user information can be buffered through a Remote Dictionary Server (Redis). The server determines the user login cost and returns the token to end the login process.

[0102] In addition, before the above-mentioned server login process, a gateway token verification process will also be carried out. When the user logs in to the application platform through their user terminal, the message corresponding to the login request initiated from the user terminal will request the gateway interface. The server can verify through the gateway whether the Header contains a valid token. If not, the user will be asked to log in again; if the Header contains a valid token, the user information will be obtained through the token and appended to the request body of the login request, and then the original request, i.e., the login request, will be forwarded to the server.

[0103] In the embodiment of the present application, when the server logs in with the unified authentication account information, it can assign a resource management token to the login account, associate the login account with its operation permissions, and avoid situations such as permission overstepping.

[0104] S103. The server loads the corresponding application platform display information according to the application platform permission set and displays it on the corresponding user terminal, so as to enter any corresponding application platform based on the user's operation on the user terminal and perform corresponding resource management operations. The application platform display information includes controls of the application platforms with operation permissions. For example, the application platform display information includes the entry buttons of the application platforms with operation permissions. The resource management operation refers to the operation of the user in the application platform. For example, the user performs an order query operation in the operation platform.

[0105] In other words, the server can generate the application platform display information that the login account has operation permissions. For example, the entry buttons of each application platform in the application platform permission set are displayed on the user terminal. When the user clicks to enter through the user terminal, the clicked application platform is entered to perform resource management operations.

[0106] Through the above solution, this application enables the corresponding user to log in to the application platform with operating permissions by generating unified authentication account information, which can avoid the problems of login errors or failures to a certain extent. By only displaying the application platforms with operating permissions through the logged-in account, it is possible to avoid the problem of incorrect business handling caused by the mismatch between the currently handled business and the logged-in account, improving work efficiency and user experience.

[0107] In an embodiment of this application, before performing the corresponding resource management operation, it further includes:

[0108] Obtain the application platform to be entered selected by the user on the user terminal. According to the user information corresponding to the logged-in account and the selected application platform to be entered, determine the menu items corresponding to the user's specified operation permissions. Generate a system menu tree corresponding to the selected application platform to be entered and including each menu item, and display it on the user terminal.

[0109] In other words, the user can select the application platform to be entered through operations such as clicking or swiping. The user's specified operation permissions include permissions for each function module in each application platform. The function modules with permissions are in the menu items. The server can generate a system menu tree of the application platform to be entered selected by the user based on the specified operation permissions and display it on the user terminal for the user to perform resource management. Resource management includes accessing application platform resources to view resource information, etc.

[0110] Thus, a more hierarchical menu tree is provided for the user to use, reducing the operation difficulty of the application platform for the user. At the same time, the menu items in the menu tree are related to the user's operation permissions, which can reduce the complexity of the user display interface, retain the effective functions, and provide them to the user, improving the user experience.

[0111] In an embodiment of this application, the user role may change continuously with the progress of the business. Therefore, this application also provides the following embodiment. Before allocating the resource management token to the logged-in account corresponding to the login request, it includes:

[0112] Monitor the change of the account role corresponding to each unified authentication account information in the user center in real time. In the case where the account role corresponding to the unified authentication account information changes, update the application platform permission set of the corresponding user. The change of the account role means that the content in the unified authentication account information changes; for example, if the role and the operation permissions for any application platform in the unified authentication account information change, then the account role has changed.

[0113] That is to say, the server can monitor the change of the user role and update the application platform permission set according to the role change. When updating, it can be executed with reference to the user information generation method of this application, which will not be elaborated here.

[0114] By monitoring the change of the user role as described above, the permission set of the application platform is updated, eliminating the need for manual adjustment in the background and improving the intelligence level of the system.

[0115] In an embodiment of the present application, after receiving a resource management instruction from a user terminal on a corresponding application platform, the operation permissions corresponding to the resource management token are matched with the management resource information corresponding to the resource management instruction to verify the resource management token corresponding to the resource management instruction. When the resource management token is verified successfully, the resource management instruction is executed. The resource management instruction is generated after the user initiates an operation on the application platform. For example, when the user clicks a query button on the application platform, a resource management instruction for the query button is generated.

[0116] In other words, the server can verify the resource management instructions sent by the user terminal after the user terminal completes login to ensure resource management security. This makes the resource management legal and avoids problems such as management overrun and errors in business processing.

[0117] In an example, if the user terminal is an operating user and the resource management instruction is to view the order list, the server will intercept the resource management instruction and obtain the token for token verification before providing the feedback on the order list query. When the user information corresponding to the token includes the operation permission for viewing the order list, the corresponding order information is fed back to the user terminal.

[0118] In another embodiment of the present application, when the resource management token verification fails, an invalid login prompt message is generated and sent to the user terminal. After receiving a re-login request from the user terminal within a predetermined time, the corresponding re-login account is determined to redirect to the redirected application platform corresponding to the re-login account of the re-login request. On the redirected application platform, the operation permissions corresponding to the resource management token of the re-login account are matched with the corresponding management resource information to verify the resource management token corresponding to the resource management instruction for executing the resource management instruction. The redirected application platform means that the page is returned to the page corresponding to the resource management instruction. For example, if the resource management instruction corresponds to an order query page, the server will redirect to the order query page during redirection.

[0119] That is to say, if the resource management token verification fails, such as when the user information corresponding to the token does not include the operation permission for viewing the order list, the resource management token verification fails. The user terminal is prompted to re-login, and within a preset predetermined time, when the re-login request of the user terminal is received and a resource management token is assigned, it is redirected to the display interface of the application platform with the operation permission. And the order information corresponding to viewing the order list is retrieved again to be fed back to the user terminal interface for viewing or sharing. The specific duration of the predetermined time is not specifically limited in this application.

[0120] In an embodiment of the present application, a re-login request may be generated according to the judgment result of the MAC address of the user terminal. For example, if the server determines that the MAC address has been prompted for re-login and switches the unified authentication account information for login within a predetermined time, the login request sent by the MAC address is a re-login request.

[0121] In another embodiment of the present application, a re-login request may be determined according to the specified login request of the user terminal. The specified login request includes specifying user terminals with different identity identifiers for login, and the identity identifier may be a MAC address. For example, the user terminal with the first MAC address specifies the user terminal with the second MAC address for login. When the user terminal with the second MAC address logs in, it is determined as the re-login request of the user terminal with the first MAC address, and the resource management instruction is continued to be executed by the second MAC address.. For example, employee 1 does not have the operation permission to view the order list and is prompted to re-login. Employee 1 can enter information such as the terminal name or MAC address of another user terminal, specify another user terminal for login. In the case of another user terminal logging in, it is regarded as the re-login request of the user terminal, so as to redirect to the application platform on another user terminal and execute the resource management instruction. Entering the terminal name or MAC address of another user terminal can also be provided by the server for employee 1 to select according to information such as the department and cooperation relationship of employee 1.

[0122] Through the above solution, when the user logs in to the wrong account, the user can be reminded and log in to the correct account for resource management, effectively avoiding the problem of incorrect business handling and preventing irreparable errors caused by executing corresponding resource management on the wrong account. At the same time, the user can choose the way of re-login, use the account with the corresponding resource management instruction permission to complete resource management, the user authentication and usage method are more flexible, and the resource management is more convenient.

[0123] Through the above technical solution, it is possible to generate unified authentication account information with flexible operation permissions in the user center, obtain a set of application platform permissions with flexible orchestration by assigning resource management tokens to login requests, and then enable the user to obtain an application platform display interface that can be operated and has a permission management association with it, so that the user can perform flexible resource management. It realizes unified resource management between enterprise application platforms, simplifies the user authentication method, improves work efficiency and the user's system usage experience.

[0124] Figure 4 The following is a schematic structural diagram of a resource management system based on user authentication provided by an embodiment of the present application. The system includes:

[0125] The registration and generation module 301, in response to the new operation of the management terminal, registers the input user information to the user center and generates corresponding unified authentication account information. The new operation represents the operation of adding a new user.

[0126] The allocation module 302 is used to, after receiving a login request corresponding to the unified authentication account information, allocate a resource management token to the login account corresponding to the login request to determine the set of application platform permissions corresponding to the login account. The set of application platform permissions includes one or more application platforms in the application platform set, and the login account has the operation permissions for the application platform.

[0127] The loading and display module 303 is used to, according to the set of application platform permissions, load the corresponding application platform display information and display it on the corresponding user terminal, so as to enter any corresponding application platform based on the user's operation on the user terminal and perform corresponding resource management operations.

[0128] In a feasible implementation manner, the registration and generation module 301 is further used to:

[0129] Obtain the user information input by the new operation. The user information at least includes the operation permissions of the user for each application platform. Generate a permission list corresponding to the user information, record it in the user center, and obtain the login account corresponding to the user in the user center. According to the login account and the single sign-on module, generate a synchronization account corresponding to the user in the single sign-on module. The synchronization account is used to call the single sign-on module to log in to the historical login account and obtain the operation permissions and resource management records of the historical login account. Perform an association process on the login account and the corresponding synchronization account to generate unified authentication account information corresponding to the user after the association process.

[0130] In a feasible implementation manner, before registering the input user information to the user center, the system can also:

[0131] Determine the specified operation permissions and / or specified role corresponding to the new operation. The specified role has a corresponding relationship with one or more specified operation permissions. Based on the specified role determined after completing the new operation, determine the role association degree with the historical registered role. The role association degree is obtained based on the service attribute vectors corresponding to the operation permissions of each role. Each service attribute corresponding to the service attribute vector is obtained based on the usage frequency and usage functions of the role for each application platform. Determine the historical registered roles corresponding to the maximum and minimum values respectively in the role association degrees, so as to generate an associated role triple according to the two obtained historical registered roles and the specified role. According to the service attribute intersection set corresponding to the associated role triple, determine the corresponding filtered service attributes. Update the specified service attribute set corresponding to the specified role according to the filtered service attributes, so as to determine the user information according to the updated specified service attribute set. The specified service attribute set is used to generate the set of application platform permissions.

[0132] In a feasible implementation manner, before performing corresponding resource management operations, the loading and display module 303 can also:

[0133] Obtain the application platform to be entered selected by the user on the user terminal. According to the user information corresponding to the logged-in account and the selected application platform to be entered, determine the menu items corresponding to the specified operation permissions of the user. Generate a system menu tree corresponding to the selected application platform to be entered and including each menu item, and display it on the user terminal.

[0134] In a feasible implementation manner, before allocating a resource management token to the logged-in account corresponding to the login request, the system can also:

[0135] Real-time monitor the changes in the account roles corresponding to the unified authentication account information in the user center. In the case where the account role corresponding to the unified authentication account information changes, update the application platform permission set of the corresponding user.

[0136] In a feasible implementation manner, the system can also:

[0137] Obtain the historical usage frequencies of several roles identical to the specified role for each application platform. In the case where the historical usage frequency is less than the preset threshold, use the operation permissions of the corresponding application platform as the excluded permissions. Exclude the corresponding excluded permissions from the specified operation permissions of the specified role to update the specified operation permissions corresponding to the specified role.

[0138] In a feasible implementation manner, the system can also:

[0139] After receiving a resource management instruction from the user terminal on the corresponding application platform, match the operation permissions corresponding to the resource management token with the management resource information corresponding to the resource management instruction to verify the resource management token corresponding to the resource management instruction. In the case where the resource management token is verified successfully, execute the resource management instruction.

[0140] In a feasible implementation manner, the system can also:

[0141] In the case where the resource management token is verified unsuccessfully, generate an invalid login prompt message and send it to the user terminal. After receiving a re-login request from the user terminal within a predetermined time, determine the corresponding re-login account to redirect to the redirected application platform corresponding to the re-login account of the re-login request. On the redirected application platform, match the operation permissions corresponding to the resource management token of the re-login account with the corresponding management resource information to verify the resource management token corresponding to the resource management instruction, so as to execute the resource management instruction.

[0142] Figure 5The structural schematic diagram of a resource management device provided by an embodiment of the present application is as follows: Figure 5 As shown, the device includes:

[0143] At least one processor. And, a memory communicatively connected to the at least one processor. Wherein, the memory stores instructions executable by the at least one processor, and when the instructions are executed by the at least one processor, the at least one processor is capable of:

[0144] In response to an addition operation of the management terminal, register the input user information to the user center, and generate corresponding unified authentication account information. The addition operation represents an operation of adding a user. After receiving a login request corresponding to the unified authentication account information, allocate a resource management token to the login account corresponding to the login request to determine the application platform permission set corresponding to the login account. The application platform permission set includes one or more application platforms in the application platform set, and the login account has operation permissions for the application platforms. According to the application platform permission set, load the corresponding application platform display information and display it on the corresponding user terminal, so as to enter any of the corresponding application platforms based on the user's operation on the user terminal and perform corresponding resource management operations.

[0145] An embodiment of the present application also provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, it realizes:

[0146] In response to an addition operation of the management terminal, register the input user information to the user center, and generate corresponding unified authentication account information. The addition operation represents an operation of adding a user. After receiving a login request corresponding to the unified authentication account information, allocate a resource management token to the login account corresponding to the login request to determine the application platform permission set corresponding to the login account. The application platform permission set includes one or more application platforms in the application platform set, and the login account has operation permissions for the application platforms. According to the application platform permission set, load the corresponding application platform display information and display it on the corresponding user terminal, so as to enter any of the corresponding application platforms based on the user's operation on the user terminal and perform corresponding resource management operations.

[0147] Each embodiment in the present application is described in a progressive manner. The same or similar parts among the embodiments can be referred to each other, and the key points of each embodiment are the differences from other embodiments. In particular, for system and device embodiments, since they are basically similar to method embodiments, the description is relatively simple, and the relevant parts can refer to the partial description of the method embodiments.

[0148] The system, device, and method provided by the embodiments of the present application are in one-to-one correspondence. Therefore, the system and device also have beneficial technical effects similar to those of their corresponding methods. Since the beneficial technical effects of the method have been described in detail above, the beneficial technical effects of the system and device will not be elaborated here.

[0149] It should also be noted that the term "including", "comprising", or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, commodity, or device including a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, commodity, or device. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of additional identical elements in the process, method, commodity, or device including the said element.

[0150] The above are only the embodiments of the present application and are not used to limit the present application. For those skilled in the art, the present application may have various modifications and changes. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.

Claims

1. A resource management method based on user authentication, characterized in that The method includes: In response to a new operation of the management terminal, registering the input user information into the user center and generating corresponding unified authentication account information; the new operation represents an operation of adding a new user. After receiving a login request corresponding to the unified authentication account information, allocating a resource management token to the login account corresponding to the login request to determine an application platform permission set corresponding to the login account; the application platform permission set includes one or more application platforms in the application platform set, and the login account has operation permissions for the application platforms. According to the application platform permission set, loading corresponding application platform display information and displaying it on the corresponding user terminal, so as to enter any one of the corresponding application platforms based on the user's operation on the user terminal and perform corresponding resource management operations.

2. The resource management method based on user authentication according to claim 1, wherein Registering the input user information into the user center and generating corresponding unified authentication account information specifically includes: Obtaining the user information input by the new operation; the user information at least includes the operation permissions of the user for each application platform. Generating a permission list corresponding to the user information, recording it in the user center, and obtaining the login account corresponding to the user in the user center. According to the login account and the single sign-on module, generating a synchronization account corresponding to the user in the single sign-on module; the synchronization account is used to call the single sign-on module to log in to the historical login account and obtain the operation permissions and resource management records of the historical login account. Performing an association process on the login account and the corresponding synchronization account to generate the unified authentication account information corresponding to the user after the association process.

3. The resource management method based on user authentication according to claim 2, characterized in that Before registering the input user information into the user center, the method further includes: Determining a specified operation permission and / or a specified role corresponding to the new operation; the specified role has a corresponding relationship with one or more specified operation permissions. Based on the specified role determined after completing the new operation, determining the role association degree with the historical registered role; the role association degree is obtained based on the service attribute vectors corresponding to the operation permissions of each role; each service attribute corresponding to the service attribute vector is obtained based on the usage frequency and usage functions of the role for each application platform. Determining the historical registered roles corresponding to the maximum and minimum values respectively among the role association degrees, so as to generate an associated role triple according to the two obtained historical registered roles and the specified role. Determining corresponding filtered service attributes according to the service attribute intersection set corresponding to the associated role triple. Updating the specified service attribute set corresponding to the specified role according to the filtered service attributes, so as to determine the user information according to the updated specified service attribute set; the specified service attribute set is used to generate the application platform permission set.

4. The resource management method based on user authentication according to claim 3, wherein, Before performing corresponding resource management operations, the method further includes: Obtaining the application platform to be entered selected by the user on the user terminal. Determining the menu items corresponding to the specified operation permissions of the user according to the user information corresponding to the login account and the selected application platform to be entered. Generate a system menu tree corresponding to the selected application platform to be accessed and including each of the menu items, and display it on the user terminal.

5. The resource management method based on user authentication according to claim 3, characterized in that Before allocating a resource management token to the login account corresponding to the login request, the method further includes: Real-time monitor the account role changes corresponding to each of the unified authentication account information in the user center; In the case where the account role corresponding to the unified authentication account information changes, update the application platform permission set of the corresponding user.

6. The resource management method based on user authentication according to claim 3, characterized in that After determining the specified operation permission and / or specified role corresponding to the new operation, the method further includes: Obtain the historical usage frequencies of several roles identical to the specified role for each of the application platforms; In the case where the historical usage frequency is less than a preset threshold, use the operation permission of the corresponding application platform as the exclusion permission; Exclude the corresponding exclusion permission from the specified operation permission of the specified role, so as to update the specified operation permission corresponding to the specified role.

7. A resource management method based on user authentication according to claim 1, characterized in that The method further includes: After receiving a resource management instruction from the user terminal on the corresponding application platform, match the operation permission corresponding to the resource management token with the management resource information corresponding to the resource management instruction, so as to verify the resource management token corresponding to the resource management instruction; In the case where the resource management token is verified to be passed, execute the resource management instruction.

8. A resource management method based on user authentication according to claim 7, characterized in that The method further includes: In the case where the resource management token is verified to be not passed, generate an invalid login prompt message and send it to the user terminal; After receiving a re-login request from the user terminal within a predetermined time, determine the corresponding re-login account, so as to redirect to the re-login application platform corresponding to the re-login account corresponding to the re-login request; On the re-login application platform, match the operation permission corresponding to the resource management token of the re-login account with the corresponding management resource information, so as to verify the resource management token corresponding to the resource management instruction, so as to execute the resource management instruction.

9. A resource management system based on user authentication, characterized in that, The system includes: A registration generation module, configured to respond to a new operation of a management terminal, register the input user information into the user center, and generate corresponding unified authentication account information; the new operation represents an operation of adding a user; An allocation module, configured to, after receiving a login request corresponding to the unified authentication account information, allocate a resource management token to the login account corresponding to the login request, so as to determine the application platform permission set corresponding to the login account; the application platform permission set includes one or more application platforms in the application platform set, and the login account has the operation permission of the application platform; A loading display module, configured to load corresponding application platform display information according to the application platform permission set, and display it on the corresponding user terminal, so as to enter any one of the corresponding application platforms based on the operation of the user on the user terminal, and perform corresponding resource management operations.

10. A resource management device based on user authentication, characterized in that The device includes: At least one processor; and, A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute a resource management method based on user authentication as described in any one of claims 1-8 above.

11. A computer-readable storage medium having a computer program stored thereon, characterized in that, When executed by a processor, the computer program implements a resource management method based on user authentication as described in any one of claims 1-8.