Method and device for managing multiple system accounts and permissions in enterprise and medium

By building a central identity management platform and automation tools, the automated management of multi-system accounts and permissions within the enterprise is solved, and the problems of cumbersome manual operations and difficult system integration are solved, and management efficiency and security are improved.

CN120277647APending Publication Date: 2025-07-08AULTON NEW ENERGY AUTOMOBILE TECHNOLOGY CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202411541600.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-12-29
Filing Date
2024-10-31
Publication Date
2025-07-08

AI Technical Summary

Technical Problem

Traditional internal multi-system accounts and permission management methods of enterprises rely on manual operations, resulting in cumbersome operations, inefficient and security risks. It is difficult to integrate the central identity management platform with self-developed systems and is costly.

Method used

Build a central identity management platform, and through automation tools and pre-installed integrated interfaces, it realizes the automation and standardization of account life cycle management, defines the relationship mapping table between account roles and permissions, configures compatible communication protocols, and simplifies data interaction and permission management between various systems.

Benefits of technology

Improve management efficiency, reduce manual intervention and errors, ensure management consistency and security, reduce operational complexity and integration costs, and achieve rapid integration and secure data transmission between various systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120277647A_ABST
    Figure CN120277647A_ABST
Patent Text Reader

Abstract

The invention discloses a method and equipment for managing multiple system accounts and permissions in an enterprise and a medium, and relates to the technical field of enterprise user management. The method comprises the following steps: switching an interface of a central identity management platform corresponding to an administrator account to a system interface corresponding to a first system environment based on a first system environment switching request sent by the administrator account; receiving a user account allocation request sent by the administrator account; wherein the user account allocation request comprises account allocation information of at least one user and system permission information of an allocated account; and creating a target user account for the user based on the account allocation information, and determining a first operation authority of the target user account in the first system environment based on the system authority information. According to the invention, on the premise of ensuring the security of account and authority management, the rapid integration of the central identity management platform and each self-developed system is realized, the management efficiency is improved, and the operation complexity is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application claims priority from the Chinese patent application filed with the Chinese Patent Office on December 29, 2023, with the application number 202311867788.1 and the invention title "A Method, Device, and Medium for Managing Multiple System Accounts and Permissions within an Enterprise". The entire text of the above Chinese patent application is incorporated herein by reference. Technical Field

[0002] This application relates to the technical field of enterprise user management, and particularly to a method, device, and medium for managing multiple system accounts and permissions within an enterprise. Background Art

[0003] With the continuous deepening of enterprise informatization construction, there are often multiple self-developed management platforms or systems within an enterprise to support the daily operation, management, and decision-making work of the enterprise. These platforms or systems each have their own independent account systems and permission management mechanisms. After a new user joins the enterprise, they need to create accounts and configure corresponding permissions in each platform or system separately in order to use these platforms or systems normally.

[0004] However, the traditional methods of account creation and permission configuration mainly rely on manual operations, such as completing steps like manually filling in user information, selecting user roles, and assigning system permissions. This method is not only cumbersome and inefficient but also prone to errors, bringing unnecessary management costs and potential security risks to the enterprise. Especially in the face of scenarios such as a large number of new users joining or user role changes, the drawbacks of the traditional method are even more obvious.

[0005] To solve this problem, some enterprises have started to try using a central identity management platform to uniformly manage multiple system accounts and permissions within the enterprise. The central identity management platform can provide a centralized user management interface, support one-click creation, update, and deletion of user accounts, and can interact with each self-developed system through interfaces to achieve automatic synchronization of accounts and permissions. However, in the actual application process, due to possible differences in the API interfaces, communication protocols, data formats, etc. of each self-developed system, the integration of the central identity management platform with each self-developed system is difficult, and a large amount of time and cost are required for custom development. Therefore, how to improve management efficiency, reduce operation complexity, and achieve rapid integration of the central identity management platform with each self-developed system while ensuring the security of account and permission management has become a technical problem to be solved urgently. Summary of the Invention

[0006] The embodiments of the present application provide a method, device, and medium for managing multi-system accounts and permissions within an enterprise, aiming to solve the problem of how to improve management efficiency, reduce operation complexity, and achieve rapid integration of the central identity management platform with each self-developed system while ensuring the security of account and permission management.

[0007] In a first aspect, the embodiments of the present application provide a method for managing multi-system accounts and permissions within an enterprise. The method includes: based on a first system environment switching request sent by an administrator account, switching the interface of the administrator account corresponding to the central identity management platform to the system interface corresponding to the first system environment; receiving a user account allocation request sent by the administrator account; where the user account allocation request includes account allocation information for at least one user and system permission information for the allocated accounts; creating target user accounts for the users based on the account allocation information, and determining the first operation permissions of the target user accounts in the first system environment based on the system permission information.

[0008] In an implementation manner of the present application, the method further includes: based on a second system environment switching request sent by the administrator account, switching the interface of the administrator account corresponding to the central identity management platform to the system interface corresponding to the second system environment; determining the second operation permissions of the target user accounts in the second system environment based on the received system permission allocation request sent by the administrator account.

[0009] In an implementation manner of the present application, the method further includes: constructing a central identity management platform and obtaining environment parameter data corresponding to at least one system to be integrated; where the systems to be integrated include at least the first system environment and the second system environment; creating the systems to be integrated in the central identity management platform based on the environment parameter data, and configuring integration interfaces for interacting with the systems to be integrated; defining the execution logic of account life cycle management based on a preset automation tool; where account life cycle management includes: creation, update, deletion; defining a relationship mapping table between account roles and permissions, and associating the relationship mapping table with the execution logic of account life cycle management; in the case where account life cycle management needs to be performed on the systems to be integrated, implementing account life cycle management based on the automation tool.

[0010] A method for managing multi-system accounts and permissions within an enterprise provided by an embodiment of the present application can uniformly manage the accounts and permissions of each system by constructing a central identity management platform, avoiding the chaos and inconvenience of decentralized management. Based on a preset automated tool, it can automatically execute account lifecycle management, including operations such as creation, update, deletion, etc., improving management efficiency. By defining a relationship mapping table between account roles and permissions and associating the relationship mapping table with the execution logic of account lifecycle management, standardized operations of account lifecycle management can be achieved, ensuring the consistency and accuracy of management. Through the automated tool and the central identity management platform, better control over account permission allocation can be achieved, avoiding security issues caused by over-allocation of permissions or misoperations. Through the automated tool and the central identity management platform, the account lifecycle management process can be simplified, reducing manual intervention and errors, and improving management efficiency. By configuring an integration interface for interacting with the system to be integrated, integrated management of accounts and permissions between systems can be achieved, improving the enterprise's system integration ability. Through the operation logs of account lifecycle management recorded by the automated tool, auditing and problem tracking can be carried out to ensure the compliance and security of management.

[0011] In an implementation manner of the present application, configuring an integration interface for the system to be integrated specifically includes: obtaining the API interface control files of each system to be integrated; wherein, the interface control files contain interface protocols for controlling interface communication; performing a compatibility process on the interface protocols in each API interface control file to determine the corresponding compatible protocol; and based on the compatible protocol, defining a preset interface to be integrated to obtain the integration interface.

[0012] By performing a compatibility process on the interface protocols in the API interface control files of each system to be integrated, the embodiment of the present application can ensure the consistency and compatibility of the communication protocols between the integration interface and each system to be integrated, avoiding problems such as data transmission errors caused by protocol mismatches. By defining a preset interface to be integrated, an expansion interface can be provided for systems that need to be integrated in the future, facilitating the future business expansion of the enterprise. Through the integration interface, fast and efficient data transmission and interaction between systems can be achieved, improving the overall operation efficiency of the enterprise. By uniformly managing the interface protocols and compatible protocols of each system to be integrated, the cost of the enterprise for data interaction and integration between different systems can be reduced, and the operation cost of the enterprise can be lowered. Through the security design of the integration interface, the security and confidentiality of data transmission between systems can be ensured, avoiding data leakage and security risks. By defining a preset interface to be integrated, standardized operations of account and permission management between systems can be achieved, ensuring the consistency and accuracy of management.

[0013] In an implementation of the present application, based on a preset automation tool, the execution logic for account lifecycle management is defined, specifically including: determining the communication protocol between the automation tool and the central identity management platform; based on the communication protocol, defining the data exchange format and instruction format between the automation tool and the central identity management platform; based on the type of account lifecycle management, writing corresponding execution scripts and integrating the execution scripts with the automation tool, so that the automation tool can perform corresponding account lifecycle management operations based on account lifecycle management instructions.

[0014] In the embodiment of the present application, through the automation tool, account lifecycle management operations can be executed quickly and accurately, avoiding the cumbersome and error-prone manual operations and improving the management efficiency. By defining the execution logic for account lifecycle management, standardized operations for account lifecycle management can be achieved, ensuring the consistency and accuracy of management. Through the definition of the automation tool and the execution logic, the account lifecycle management process can be simplified, reducing manual intervention and errors and improving the management efficiency. Through the automation tool, the dependence on human resources and resources can be reduced, and the operating costs of the enterprise can be reduced. Through the definition of the automation tool and the execution logic, the permission allocation of accounts can be better controlled, avoiding security problems caused by over-allocation of permissions or misoperations. Through the operation logs recorded by the automation tool, auditing and problem tracking can be carried out to ensure the compliance and security of management.

[0015] In an implementation of the present application, a relationship mapping table for account roles and permissions is defined, specifically including: obtaining the organizational structure and role classification of the enterprise; based on the organizational structure and role classification of the enterprise, analyzing the application systems required by each role and the corresponding system permissions; based on the application systems required by each role and the corresponding system permissions, defining the relationship mapping table for account roles and permissions.

[0016] In the embodiment of the present application, by defining the relationship mapping table for account roles and permissions, the permissions corresponding to each role can be clearly defined, avoiding chaotic permission allocation and unnecessary permission redundancy. Through the mapping table, the permissions owned by a certain role can be quickly located, facilitating permission adjustment and management by managers. Through reasonable role-permission mapping, it can be ensured that each account only has the minimum permissions required by it, thereby reducing the risk of system attacks or misoperations. When the organizational structure and roles of the enterprise change, only the mapping table needs to be adjusted to adapt to the new requirements, without the need to adjust each account individually, improving the flexibility and adaptability of the system. Through the mapping table, the permission application and approval process can be simplified, reducing manual intervention and errors and improving the management efficiency. The mapping table provides a clear basis for auditing, facilitating auditors to conduct compliance checks on the permission allocation of the system.

[0017] In an implementation of the present application, the relationship mapping table is associated with the account lifecycle management execution logic, specifically including: determining the reference identifier to be used for the relationship mapping table, and introducing the identifier to be applied into the relationship mapping table identifier reference parameter of the execution script; storing the relationship mapping table at the relationship mapping table storage address specified in the execution script.

[0018] In the embodiments of the present application, by associating the relationship mapping table with the account lifecycle management execution logic, automated management of the account lifecycle can be achieved, reducing manual intervention and errors. Through automated management, account lifecycle management operations can be executed quickly and accurately, improving management efficiency. By associating the relationship mapping table with the account lifecycle management execution logic, standardized operations for account lifecycle management can be realized, ensuring the consistency and accuracy of management. Through automated management, the account lifecycle management process can be simplified, reducing manual intervention and errors and improving management efficiency. Through automated management, better control over the permission allocation of accounts can be achieved, avoiding security issues caused by over-allocation of permissions or misoperations.

[0019] In an implementation of the present application, based on an automated tool, account lifecycle management is realized, specifically including: configuring account lifecycle management instructions based on the front-end interaction interface corresponding to the central identity management platform, and sending the account lifecycle management instructions to the automated tool; the automated tool parses the account lifecycle management instructions to determine the user information included in the account lifecycle management instructions; based on the user information, determining the user role corresponding to the account to be managed; based on the user role, triggering the corresponding account lifecycle management execution logic to complete the account lifecycle management.

[0020] In the embodiments of the present application, through the automated tool, account lifecycle management operations can be executed quickly and accurately, improving management efficiency. Through the automated tool, standardized operations for account lifecycle management can be realized, ensuring the consistency and accuracy of management. Through the automated tool, the account lifecycle management process can be simplified, reducing manual intervention and errors and improving management efficiency. Through the automated tool, better control over the permission allocation of accounts can be achieved, avoiding security issues caused by over-allocation of permissions or misoperations. Through the operation logs recorded by the automated tool, auditing and problem tracking can be carried out to ensure the compliance and security of management. The automated tool can automatically handle common errors and exceptions, reducing manual intervention and errors.

[0021] In an implementation manner of the present application, an account lifecycle management instruction is configured based on the front-end interaction interface corresponding to the central identity management platform, specifically including: determining the account to be managed based on the front-end interaction interface, and selecting the user information corresponding to the account to be managed; wherein the user information includes: organizational structure and role classification; selecting the type corresponding to the account lifecycle management; constructing an account lifecycle management instruction based on the type corresponding to the account lifecycle management and the user information corresponding to the account to be managed.

[0022] In the embodiment of the present application, through the front-end interaction interface, the administrator can directly select the account to be managed and configure the account lifecycle management instruction, with intuitive and convenient operations. The front-end interaction interface can be customized and adjusted according to actual needs to meet the requirements of different management scenarios, with high flexibility. The front-end interaction interface is integrated with the central identity management platform, which can be conveniently updated and maintained to ensure the stability and security of the system. Through the front-end interaction interface, the operation process of account lifecycle management can be standardized to ensure the consistency and accuracy of management. Through the front-end interaction interface, the access rights to account lifecycle management can be controlled to avoid misoperations or malicious modifications.

[0023] In an implementation manner of the present application, after implementing account lifecycle management based on an automated tool, the method further includes: obtaining the execution result of the account lifecycle management; generating a corresponding execution report based on the execution result, and sending the execution result to the front-end interaction interface corresponding to the central identity management platform.

[0024] In the embodiment of the present application, by sending the execution result and execution report of the account lifecycle management to the front-end interaction interface, the administrator can understand the execution situation of the account lifecycle management in real time, realizing transparent management. The records of the execution result and execution report can facilitate auditing and problem tracking to ensure the compliance and security of management. The real-time feedback of the execution result and execution report can help the administrator promptly discover and solve problems occurring in the management process, improving management efficiency. Based on the data analysis of the execution result and execution report, it can help the administrator make better decisions and improve management effectiveness. Through the integration of the automated tool and the front-end interaction interface, the operation process of account lifecycle management can be simplified, reducing manual intervention and errors, and improving management efficiency.

[0025] In a second aspect, the embodiment of the present application further provides a device for managing multi-system accounts and permissions within an enterprise, characterized in that the device includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute a method for managing multi-system accounts and permissions within an enterprise as described above.

[0026] In a third aspect, an embodiment of the present application further provides a non-volatile computer storage medium for managing multi-system accounts and permissions within an enterprise, storing computer-executable instructions, characterized in that the computer-executable instructions are set as: a method for managing multi-system accounts and permissions within an enterprise as described above.

[0027] A method, device, and medium for managing multi-system accounts and permissions within an enterprise provided by an embodiment of the present application. By constructing a central identity management platform, an enterprise can uniformly manage the accounts and permissions of each system, avoiding the chaos and inconvenience of decentralized management and improving management efficiency. Based on the pre-set automated tools, account lifecycle management can be automatically executed, including operations such as creation, update, and deletion, reducing manual intervention and errors and improving management efficiency. By defining a relationship mapping table between account roles and permissions and associating the relationship mapping table with the execution logic of account lifecycle management, standardized operations of account lifecycle management can be achieved, ensuring the consistency and accuracy of management. Through the automated tools and the central identity management platform, better control over the permission allocation of accounts can be achieved, avoiding security issues caused by over-allocation of permissions or misoperations. Through the automated tools and the central identity management platform, the account lifecycle management process can be simplified, reducing manual intervention and errors and improving management efficiency. By configuring an integration interface for interacting with the system to be integrated, integrated management of accounts and permissions between systems can be achieved, improving the enterprise's system integration ability. Through the operation logs of account lifecycle management recorded by the automated tools, auditing and problem tracking can be carried out to ensure the compliance and security of management. Through the front-end interaction interface, managers can directly select the accounts to be managed and configure account lifecycle management instructions, with intuitive and convenient operations. The front-end interaction interface can be customized and adjusted according to actual needs to meet the requirements of different management scenarios, with high flexibility. The front-end interaction interface is integrated with the central identity management platform, facilitating updates and maintenance to ensure the stability and security of the system. Based on the data analysis of the execution results and execution reports, it can help managers make better decisions and improve management effectiveness. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation of the present application. In the drawings:

[0029] Figure 1 is a flowchart of a method for managing multi-system accounts and permissions within an enterprise provided by an embodiment of the present application;

[0030] Figure 2 is a flowchart of a method for building a central identity management platform provided by an embodiment of the present application;

[0031] Figure 3 Schematic diagram of the internal structure of a device for managing multi-system accounts and permissions within an enterprise provided by an embodiment of the present application. Detailed implementation manners

[0032] To make the objectives, technical solutions and advantages of the present application clearer, the technical solutions of the present application will be clearly and completely described below in conjunction with specific embodiments of the present application and the corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0033] An embodiment of the present application provides a method, device and medium for managing multi-system accounts and permissions within an enterprise, aiming to solve the problem of how to improve management efficiency, reduce operation complexity, and achieve rapid integration of the central identity management platform with each self-developed system while ensuring the security of account and permission management.

[0034] The technical solutions proposed in the embodiments of the present application will be described in detail below with reference to the drawings.

[0035] Figure 1 Flowchart of a method for managing multi-system accounts and permissions within an enterprise provided by an embodiment of the present application. As Figure 1 shown, a method for managing multi-system accounts and permissions within an enterprise provided by an embodiment of the present application specifically includes the following steps:

[0036] Step 101: Based on the first system environment switching request sent by the administrator account, switch the interface of the administrator account corresponding to the central identity management platform to the system interface corresponding to the first system environment;

[0037] Step 102: Receive the user account allocation request sent by the administrator account; wherein, the user account allocation request includes the account allocation information of at least one user and the system permission information of the allocated account.

[0038] Step 103: Create a target user account for the user based on the account allocation information, and determine the first operation permission of the target user account in the first system environment based on the system permission information.

[0039] In an embodiment of the present application, when the target user account also requires second operation permissions in the second system environment, after the configuration of the first operation permissions in the first system environment is completed, further, based on the second system environment switching request sent by the administrator account, the interface of the central identity management platform corresponding to the administrator account is switched to the system interface corresponding to the second system environment; based on the received system permission allocation request sent by the administrator account, the second operation permissions of the target user account in the second system environment are determined.

[0040] In an embodiment of the present application, to manage multi-system accounts and permissions within an enterprise, before creating the target user account, it is also necessary to build a central identity management platform for managing multi-system accounts and permissions within the enterprise. Figure 2 It is a flowchart of a method for building a central identity management platform provided by an embodiment of the present application. As Figure 2 shown, a method for building a central identity management platform provided by an embodiment of the present application specifically includes the following steps:

[0041] Step 201, build a central identity management platform and obtain environment parameter data corresponding to at least one system to be integrated.

[0042] Among them, the central identity management platform is used for front-end interaction and back-end account and permission management; the systems to be integrated include at least a first system environment and a second system environment.

[0043] Step 202, based on the environment parameter data, create the systems to be integrated in the central identity management platform and configure the integration interfaces for interacting with the systems to be integrated.

[0044] Specifically, obtain the API interface control files of each system to be integrated; among them, the interface control file contains the interface protocol for controlling interface communication; perform compatibility processing on the interface protocols in each API interface control file to determine the corresponding compatible protocol; based on the compatible protocol, define the preset interfaces to be integrated to obtain the integration interfaces.

[0045] In one embodiment, in a large enterprise, there are multiple business systems that need to be integrated, including financial systems, human resources systems, supply chain systems, etc. To achieve the integration of these systems, a central identity management platform needs to be built to uniformly manage the accounts and permissions of each system. First, we need to obtain the API interface control files of each system to be integrated. These interface control files contain the interface protocols used by each system to control interface communication. For example, the interface protocol of the financial system may be different from that of the human resources system. Next, we need to perform compatibility processing on the interface protocols in each API interface control file. This means that we need to determine one or more compatible protocols so that each system can communicate with each other. For example, we can convert the interface protocols of all systems to the RESTful API format, so that each system can communicate through a unified interface protocol. Then, based on these compatible protocols, we can define the pre-set interfaces to be integrated. These interfaces will be used to connect each system and implement the management of accounts and permissions. For example, we can define an interface for creating new accounts, an interface for updating account information, and an interface for deleting accounts. Finally, through these pre-set interfaces to be integrated, we can achieve the integrated management of accounts and permissions between each system. For example, when we create a new account in the central identity management platform, the account information will be automatically synchronized to each relevant system, thus achieving unified management.

[0046] Through the above embodiments, we can see how to obtain the API interface control files of each system to be integrated, perform compatibility processing on the interface protocols, define the pre-set interfaces to be integrated, and achieve the integrated management of accounts and permissions. This method helps to improve the enterprise's system integration ability, simplify the management process, and enhance security.

[0047] Step 203: Define the execution logic of account lifecycle management based on the pre-set automation tool.

[0048] It should be noted that the account lifecycle management in the embodiments of this application includes: creation, update, and deletion.

[0049] Specifically, determine the communication protocol between the automation tool and the central identity management platform; based on the communication protocol, define the data exchange format and instruction format between the automation tool and the central identity management platform; based on the type of account lifecycle management, write the corresponding execution script and integrate the execution script with the automation tool so that the automation tool can perform the corresponding account lifecycle management operations based on the account lifecycle management instructions.

[0050] In one embodiment, the central identity management platform needs to be integrated with automation tools to achieve automated management of the account lifecycle. To achieve this goal, the following steps are required: First, determine the communication protocol between the automation tools and the central identity management platform. This can be a communication protocol based on RESTful API because RESTful API has good scalability and cross-platform capabilities. By using RESTful API, the automation tools can exchange data and transfer instructions with the central identity management platform. Next, based on the communication protocol, define the data exchange format and instruction format between the automation tools and the central identity management platform. The data exchange format can be JSON format because it is a common data exchange format that is easy to read, write, and parse. The instruction format can define different instruction types, such as creating an account, updating account information, and deleting an account, etc. Then, based on the type of account lifecycle management, write the corresponding execution scripts. These scripts can be programs written in programming languages such as Python, Java, etc., for performing specific account lifecycle management operations. For example, the script for creating a new account can check the necessary information provided by the user and add the new account information to the central identity management platform. Finally, integrate the execution scripts with the automation tools. This can be achieved by writing an adapter program that is responsible for converting the instruction format of the automation tools into the data format and instruction format required by the execution scripts. Once the integration is completed, the automation tools can perform the corresponding account lifecycle management operations based on the account lifecycle management instructions.

[0051] Through the above embodiments, we can see how to determine the communication protocol between the automation tools and the central identity management platform, define the data exchange format and instruction format, write the execution scripts, and integrate the execution scripts with the automation tools. This method helps to improve the automation level of account lifecycle management, reduce manual intervention and errors, and improve management efficiency.

[0052] Step 204: Define the relationship mapping table between account roles and permissions, and associate the relationship mapping table with the execution logic of account lifecycle management.

[0053] In one embodiment of the present application, after defining the execution logic of account lifecycle management based on the preset automation tools, define the relationship mapping table between account roles and permissions.

[0054] Specifically, obtain the organizational structure and role classification of the enterprise; based on the organizational structure and role classification of the enterprise, analyze the application systems required by each role and the corresponding system permissions; based on the application systems required by each role and the corresponding system permissions, define the relationship mapping table between account roles and permissions.

[0055] In one embodiment, a large manufacturing enterprise has multiple departments and positions, and each department and position has its own application system and permission requirements. To achieve centralized management of the account life cycle, the following steps are required: First, obtain the organizational structure and role classification of the enterprise. This can be done by collaborating with the human resources department to obtain information such as the departments and positions in the enterprise, as well as the job responsibilities of each position. Next, based on the organizational structure and role classification of the enterprise, analyze the application systems required by each role and the corresponding system permissions. For example, employees in the production department need to use the production management system, while employees in the quality department need to use the quality management system. At the same time, each system has different permission levels, such as read, write, delete, etc. Then, based on the application systems required by each role and the corresponding system permissions, define a relationship mapping table for account roles and permissions. This mapping table can be a database table or a spreadsheet, which records the corresponding relationship between each role and the application systems and permissions it requires. For example, the supervisor of the production department may need to access all functions of the production management system, while production line workers may only be granted certain specific operation permissions.

[0056] Through the above embodiment, we can see how to obtain the organizational structure and role classification of the enterprise, analyze the application systems and permission requirements of each role, and how to define the relationship mapping table for account roles and permissions. This method helps to ensure the accuracy and consistency of account life cycle management, and avoid confusion in permission allocation and security risks.

[0057] Furthermore, associate the relationship mapping table with the execution logic of account life cycle management.

[0058] Specifically, determine the reference identifier to be used for the relationship mapping table, and introduce the identifier to be applied into the relationship mapping table identifier reference parameter of the execution script; store the relationship mapping table at the relationship mapping table storage address specified in the execution script.

[0059] In one embodiment, to achieve the automated execution of account lifecycle management, the following steps are required: First, determine the reference identifiers of the relationship mapping table. These identifiers are used to reference the data in the relationship mapping table in the execution script. For example, specific variable names or placeholders can be used to represent the reference identifiers to be used. Next, introduce the reference identifiers to be applied into the relationship mapping table identifier reference parameters of the execution script. This means that in the execution script, specific syntax or formats need to be used to reference these identifiers. For example, string formatting or parameter substitution can be used to reference these identifiers. Then, store the relationship mapping table at the relationship mapping table storage address specified in the execution script. This can be a location such as the local file system, a database, or cloud storage, depending on the requirements and configuration of the execution script. For example, the relationship mapping table can be stored as a CSV file, and the path of this file can be specified in the execution script. Finally, when the account lifecycle management operation is executed through an automated tool, the execution script will read the data in the relationship mapping table and perform corresponding account lifecycle management operations based on the permission relationships therein. For example, when creating a new account, the execution script will check the permission allocation of the account according to the data in the relationship mapping table and automatically add it to the corresponding application system.

[0060] Through the above embodiments, we can see how to determine the reference identifiers of the relationship mapping table, introduce the reference identifiers to be applied into the relationship mapping table identifier reference parameters of the execution script, and how to store the relationship mapping table at the relationship mapping table storage address specified in the execution script. This method helps to automate the execution of account lifecycle management operations, reduce manual intervention and errors, and improve management efficiency.

[0061] Step 205, in the case where account lifecycle management needs to be performed on the system to be integrated, implement account lifecycle management based on an automated tool.

[0062] In one embodiment of the present application, in the case where account lifecycle management needs to be performed on the system to be integrated, implement account lifecycle management based on an automated tool.

[0063] Specifically, configure the account lifecycle management instruction based on the front-end interaction interface corresponding to the central identity management platform, and send the account lifecycle management instruction to the automated tool; the automated tool parses the account lifecycle management instruction to determine the user information included in the account lifecycle management instruction; based on the user information, determine the user role corresponding to the account to be managed; based on the user role, trigger the corresponding account lifecycle management execution logic to complete the account lifecycle management.

[0064] In an embodiment of the present application, an account lifecycle management instruction is configured based on the front-end interaction interface corresponding to the central identity management platform, which specifically includes: based on the front-end interaction interface, determining the account to be managed and selecting the user information corresponding to the account to be managed; wherein the user information includes: organizational structure and role classification; selecting the type corresponding to the account lifecycle management; and constructing an account lifecycle management instruction based on the type corresponding to the account lifecycle management and the user information corresponding to the account to be managed.

[0065] In an embodiment, to achieve more flexible and user-friendly account lifecycle management, the following steps are required: First, configure an account lifecycle management instruction based on the front-end interaction interface corresponding to the central identity management platform. The front-end interaction interface can be a web page or an application program, providing a visual interface for users to operate. Users can select the account to be managed through the interface and view its relevant user information, such as organizational structure and role classification. Next, users can select the type of account lifecycle management, such as creating a new account, updating account information, or deleting an account, etc. Then, based on the selected type of account lifecycle management and the user information of the account to be managed, the front-end interaction interface will automatically generate the corresponding account lifecycle management instruction. After the instruction is generated, it is sent to an automated tool for processing. After receiving the instruction, the automated tool will parse it to determine the user information contained in the instruction. For example, the automated tool can parse out information such as the user name, organizational structure, and role classification of the account to be managed. Based on the user information, the automated tool can determine the user role corresponding to the account to be managed. According to the user role, the automated tool will trigger the corresponding account lifecycle management execution logic. The execution logic is executed based on the previously defined relationship mapping table, and can include steps such as verifying user permissions, checking account status, and performing corresponding operations. Finally, through the execution logic of the automated tool, the operation of account lifecycle management is completed. For example, if the instruction is to create a new account, the automated tool will automatically assign corresponding permissions and roles to the new account according to the data in the relationship mapping table and add it to the corresponding application system.

[0066] Through the above embodiments, we can see how to configure an account lifecycle management instruction based on the front-end interaction interface corresponding to the central identity management platform, how to send the instruction to an automated tool for parsing and processing, and how to trigger the corresponding execution logic to complete the account lifecycle management. This method provides a more flexible and user-friendly way to manage the account lifecycle, enabling users to operate and manage more conveniently.

[0067] In one embodiment of the present application, after implementing account lifecycle management based on an automated tool, the method further includes: obtaining the execution result of the account lifecycle management; generating a corresponding execution report based on the execution result, and sending the execution result to the front-end interaction interface corresponding to the central identity management platform.

[0068] The above is the method embodiment proposed by the present application. Based on the same inventive concept, the embodiments of the present application also provide a device for managing multi-system accounts and permissions within an enterprise, and its structure is as Figure 3 shown.

[0069] Figure 3 This is a schematic diagram of the internal structure of a device for managing multi-system accounts and permissions within an enterprise provided by an embodiment of the present application. As Figure 3 shown, the device includes:

[0070] At least one processor 301;

[0071] And a memory 302 communicatively connected to at least one processor;

[0072] Wherein, the memory 302 stores instructions executable by at least one processor, and the instructions are executed by at least one processor 301 so that at least one processor 301 can:

[0073] Based on the first system environment switching request sent by the administrator account, switch the interface of the administrator account corresponding to the central identity management platform to the system interface corresponding to the first system environment;

[0074] Receive a user account allocation request sent by the administrator account; wherein, the user account allocation request includes account allocation information of at least one user and system permission information of the allocated account;

[0075] Create a target user account for the user based on the account allocation information, and determine the first operation permission of the target user account in the first system environment based on the system permission information.

[0076] Some embodiments of the present application provide a non-volatile computer storage medium corresponding to Figure 1 for managing multi-system accounts and permissions within an enterprise, storing computer-executable instructions, and the computer-executable instructions are set as:

[0077] Based on the first system environment switching request sent by the administrator account, switch the interface of the administrator account corresponding to the central identity management platform to the system interface corresponding to the first system environment;

[0078] Receive a user account allocation request sent by the administrator account; wherein, the user account allocation request includes account allocation information of at least one user and system permission information of the allocated account;

[0079] Create a target user account for the user based on the account allocation information, and determine the first operation permissions of the target user account in the first system environment based on the system permission information.

[0080] Each embodiment in this application is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the embodiments of Internet of Things devices and media, since they are basically similar to the method embodiments, the description is relatively simple, and for the relevant parts, reference can be made to the partial description of the method embodiments.

[0081] The systems and media provided by the embodiments of this application correspond one-to-one with the methods. Therefore, the systems and media also have beneficial technical effects similar to the corresponding methods. Since the beneficial technical effects of the methods have been described in detail above, the beneficial technical effects of the systems and media will not be elaborated here.

[0082] Those skilled in the art should understand that the embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, this application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0083] This application is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of this application. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0084] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device that implements the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0085] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one process Figure 1 one process or multiple processes and / or blocks Figure 1 or steps of the functions specified in multiple blocks.

[0086] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.

[0087] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM) and / or non-volatile memory such as read-only memory (ROM) or flash memory (flash RAM). Memory is an example of computer-readable media.

[0088] Computer-readable media includes permanent and non-permanent, removable and non-removable media and can store information by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices, or any other non-transmission media that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transitory media such as modulated data signals and carrier waves.

[0089] It should also be noted that the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, commodity or device comprising a series of elements not only includes those elements but also includes other elements not expressly listed, or also includes elements inherent to such process, method, commodity or device. Without further limitation, an element defined by the statement "comprising one..." does not exclude the presence of additional identical elements in the process, method, commodity or device comprising the element.

[0090] The above are only embodiments of the present application and are not intended to limit the present application. For those skilled in the art, various changes and modifications can be made to the present application. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included within the scope of the claims of the present application.

Claims

1. A method for managing multi-system accounts and permissions within an enterprise, characterized in that, The method includes: Based on the first system environment switching request sent by the administrator account, switching the interface of the central identity management platform corresponding to the administrator account to the system interface corresponding to the first system environment; Receiving the user account allocation request sent by the administrator account; wherein, the user account allocation request includes account allocation information of at least one user and system permission information for the allocated account; Creating a target user account for the user based on the account allocation information, and determining the first operation permission of the target user account in the first system environment based on the system permission information.

2. The method for managing multi-system accounts and permissions within an enterprise according to claim 1, wherein, The method further includes: Based on the second system environment switching request sent by the administrator account, switching the interface of the central identity management platform corresponding to the administrator account to the system interface corresponding to the second system environment; Determining the second operation permission of the target user account in the second system environment based on the received system permission allocation request sent by the administrator account.

3. A method for managing multi-system accounts and permissions within an enterprise according to claim 1, characterized in that, The method further includes: Constructing a central identity management platform and obtaining environment parameter data corresponding to at least one system to be integrated; wherein, the system to be integrated includes at least the first system environment and the second system environment; Based on the environment parameter data, creating the system to be integrated in the central identity management platform and configuring an integration interface for interacting with the system to be integrated; Defining the execution logic of account life cycle management based on a preset automation tool; wherein, account life cycle management includes: creation, update, deletion; Defining a relationship mapping table between account roles and permissions, and associating the relationship mapping table with the execution logic of account life cycle management; When it is necessary to perform account life cycle management on the system to be integrated, implementing account life cycle management based on the automation tool.

4. A method for managing multi-system accounts and permissions within an enterprise according to claim 3, characterized in that, Configuring the integration interface for the system to be integrated specifically includes: Obtaining the API interface control file of each system to be integrated; wherein, the interface control file contains an interface protocol for controlling interface communication; Performing compatibility processing on the interface protocols in each API interface control file to determine the corresponding compatible protocol; Based on the compatible protocol, defining a preset interface to be integrated to obtain an integration interface.

5. A method for managing multi-system accounts and permissions within an enterprise according to claim 3, characterized in that Defining the execution logic of account life cycle management based on a preset automation tool specifically includes: Determining the communication protocol between the automation tool and the central identity management platform; Based on the communication protocol, defining the data exchange format and instruction format between the automation tool and the central identity management platform; Based on the type of account life cycle management, writing a corresponding execution script and integrating the execution script with the automation tool so that the automation tool can perform corresponding account life cycle management operations based on account life cycle management instructions.

6. A method for managing multi-system accounts and permissions within an enterprise according to claim 3, characterized in that, Defining the relationship mapping table between account roles and permissions specifically includes: Obtaining the organizational structure and role classification of the enterprise; Based on the organizational structure and role classification of the enterprise, analyzing the application systems required by each role and the corresponding system permissions; Based on the application systems required by each role and the corresponding system permissions, defining the relationship mapping table between account roles and permissions.

7. A method for managing multi-system accounts and permissions within an enterprise according to claim 3, characterized in that Associate the relationship mapping table with the account lifecycle management execution logic, specifically including: Determine the reference identifier to be cited in the relationship mapping table, and introduce the reference identifier to the relationship mapping table identifier reference parameter in the execution script; Store the relationship mapping table at the specified relationship mapping table storage address in the execution script.

8. A method for managing multi-system accounts and permissions within an enterprise according to claim 3, characterized in that, Based on the automation tool, implement account lifecycle management, specifically including: Configure the account lifecycle management instruction based on the front-end interaction interface corresponding to the central identity management platform, and send the account lifecycle management instruction to the automation tool; The automation tool parses the account lifecycle management instruction to determine the user information included in the account lifecycle management instruction; Based on the user information, determine the user role corresponding to the account to be managed; Based on the user role, trigger the corresponding account lifecycle management execution logic to complete the account lifecycle management.

9. A device for managing multi-system accounts and permissions within an enterprise, characterized in that, The device includes: At least one processor; And a memory communicatively connected to the at least one processor; Wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute a method for managing multi-system accounts and permissions within an enterprise as described in any one of claims 1-8.

10. A non-volatile computer storage medium for managing multi-system accounts and permissions within an enterprise, storing computer-executable instructions, characterized in that, When the computer-executable instructions are executed by a computer, they can implement a method for managing multi-system accounts and permissions within an enterprise as described in any one of claims 1-8.

Citation Information

Cited By

  • Account management method and device, equipment, medium and product

    CN121603270A