Intra-tenant role-level permission distribution system and method based on large model agent

Through the modularly designed in-tenant role-level permission allocation system, the problem of insufficient flexibility and security in a multi-tenant environment is solved, and flexible permission allocation and strict permission verification are realized to ensure the security and availability of the system.

CN120337187APending Publication Date: 2025-07-18SHANDONG LANGCHAO YUNTOU INFORMATION TECH CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510415675.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-03
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

Traditional permission management systems are difficult to allocate agent permissions to different roles in a multi-tenant environment, and cannot effectively isolate tenant data, resulting in security and availability issues.

Method used

A modularly designed in-tenant role-level permission allocation system includes agent list creation and maintenance, registration, role definition, permission management interface, permission database, permission verification and logging module, supporting flexible permission allocation and strict permission verification.

Benefits of technology

It realizes flexible, safe and efficient permission management, supports real-time adjustment and recording, and ensures the scalability and security of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120337187A_ABST
    Figure CN120337187A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of artificial intelligence and system security, in particular to an intra-tenant role-level permission allocation system and method based on a large model agent, and the system comprises an agent list creation and maintenance module, an agent registration module, a role definition module, a role allocation module, a permission management interface, a permission database and a permission adjustment module. An authority verification module, an execution and log recording module; the system has the beneficial effects that the system adopts a modular design, and modules of agent registration and management, role management, role-level permission allocation, permission verification and execution and the like are organically combined to form a flexible, safe and efficient permission management architecture. The architecture design not only can meet the current service requirements, but also has good expansibility.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical fields of artificial intelligence and system security, and specifically provides a tenant-internal role-level permission allocation system and method based on large model agents. Background Art

[0002] With the rapid development of artificial intelligence technology, large models have achieved remarkable results in various fields, and the application of agents in multi-tenant environments is becoming increasingly widespread. In a multi-tenant environment, there are usually different roles within a tenant (such as administrators, primary tenants, ordinary users, etc.), and each role requires different permissions to complete its work. However, traditional methods have many limitations in permission management and are difficult to flexibly allocate and manage agent permissions for different roles within a tenant. Specific problems include: 1) Traditional systems often adopt fixed permission templates and are difficult to adapt to complex and changing business requirements. 2) The permission allocation process is usually cumbersome, lacking flexibility and real-time performance. For example, in a multi-tenant environment, the tenant administrator needs to allocate different permissions to each user, but traditional methods cannot quickly respond to business changes. 3) In a multi-tenant architecture, ensuring data isolation and security between tenants is crucial. Traditional methods may not be able to effectively isolate tenant data, resulting in a risk of data leakage. These problems not only affect the security and availability of the system but also increase management costs and risks.

[0003] To meet the tenant management agent permission requirements in complex business scenarios of large models, a new permission management method is needed that can efficiently and flexibly allocate agent permissions for different roles while ensuring the security and availability of the system. Summary of the Invention

[0004] The purpose of the present invention is to provide a tenant-internal role-level permission allocation system and method based on large model agents to solve the problems raised in the above background art.

[0005] To achieve the above purpose, the present invention provides the following technical solution: A tenant-internal role-level permission allocation system based on large model agents, comprising:

[0006] An agent list creation and maintenance module for storing the names, function descriptions, and resource requirement information of all available agents and assigning a unique identifier to each agent;

[0007] An agent registration module for registering the information of a new agent into the agent list through a standardized registration interface when the new agent goes online and subjecting it to system review;

[0008] A role definition module for defining different roles within each tenant, where each role has different permission levels and function requirements;

[0009] Role Assignment Module, which allows the tenant administrator to assign roles to internal users within the tenant through the system interface and determine the scope of user permissions;

[0010] Permission Management Interface, which provides functions such as role selection, agent selection, and permission level setting for the tenant administrator to grant agent permissions to different roles;

[0011] Permission Database, which is used to store the permission relationships between roles and agents and supports fast query and update operations;

[0012] Permission Adjustment Module, which allows the tenant administrator to dynamically adjust the agent permissions of roles and update the permission database in real time;

[0013] Permission Verification Module, which verifies whether the caller has the corresponding permissions when the agent is called and completes the verification by querying the permission database;

[0014] Execution and Logging Module, which allows or rejects the agent call according to the permission verification result and records the relevant log information.

[0015] Preferably, the agent registration module further includes:

[0016] Agent Instance Creation Unit, which is used to create agent instances and assign unique identifiers;

[0017] Agent Information Configuration Unit, which is used to add the agent instance to the agent list and configure its function description and resource requirements;

[0018] Security Policy Configuration Unit, which is used to configure security policies for agents to ensure their secure operation;

[0019] Information Synchronization Unit, which is used to synchronize agent information to the permission management control center for subsequent permission assignment and management.

[0020] Preferably, the permission management interface includes:

[0021] Role Selection Interface, which is used to display the role list and allow the tenant administrator to select a role;

[0022] Agent Selection Interface, which is used to display the agent list and allow the tenant administrator to select an agent;

[0023] Permission Level Setting Interface, which is used to allow the tenant administrator to set the permission level for the selected agent for the selected role, including read, write, and management levels.

[0024] Preferably, the execution process of the permission verification module includes:

[0025] Receive the agent call request initiated by the user, where the request contains the user identity information and the target agent identifier;

[0026] Query the role information of the user;

[0027] Verify whether the role is granted the calling permission of the target agent and whether the call conforms to the permission level of the role;

[0028] According to the verification result, allow or reject the agent call and record the relevant log information.

[0029] Preferably, it further includes an operation log recording module for:

[0030] Record the operation logs of the user's agent calls, including user ID, agent ID, call time, and call result information;

[0031] When the call fails, record the reason for failure, such as insufficient permissions or the agent being unavailable;

[0032] Provide log information for subsequent security audits and problem troubleshooting.

[0033] A method for a role-level permission allocation system within a tenant based on large model agents, including the following steps:

[0034] Create and maintain an agent list, store the names, function descriptions, and resource requirement information of all available agents, and assign a unique identifier to each agent;

[0035] Register the name and function description information of the new agent into the agent list through a standardized registration interface and pass the system review;

[0036] Define different roles within each tenant, and each role has different permission levels and function requirements;

[0037] Provide a permission management interface to allow the tenant administrator to grant different agent permissions to different roles within the tenant, including role selection, agent selection, and permission level setting;

[0038] Store the permission relationship between the role and the agent in the permission database to support fast query and update operations.

[0039] Preferably, it further includes the following steps:

[0040] The tenant administrator dynamically adjusts the agent permissions of the role through the permission management interface, including operations such as adding, deleting, and modifying permissions;

[0041] Real-time update the permission database to reflect the latest status of the role-agent permissions;

[0042] When the agent is called, the system first verifies whether the caller has the corresponding permissions, and the verification process is completed by querying the permission database.

[0043] Preferably, the permission verification step specifically includes:

[0044] Query the role information of the caller;

[0045] Query whether this role is granted the permission to call the target agent;

[0046] Verify whether the call conforms to the permission level of the role, including reading, writing, and management;

[0047] According to the verification result, allow or reject the agent call, and record relevant log information when rejecting for subsequent security audits.

[0048] Preferably, the registration and management steps of the agent further include:

[0049] Create an agent instance and assign a unique identifier to it;

[0050] Add the agent instance to the agent list, and configure its function description and resource requirements;

[0051] Configure a security policy for the agent to ensure its secure operation;

[0052] Synchronize the agent information to the permission management control center for subsequent permission assignment and management.

[0053] It also includes the following steps:

[0054] When the user passes the permission verification, allow the user to call the agent, and the agent receives the user's call request;

[0055] The agent performs corresponding operations according to the user's request content, such as data processing and task execution;

[0056] The agent returns the execution result to the user;

[0057] Regardless of whether the call is successful, the system records relevant operation logs, including user ID, agent ID, call time, call result information. If the call fails, the failure reason is also recorded for subsequent security audits and problem troubleshooting.

[0058] Compared with the prior art, the beneficial effects of the present invention are:

[0059] The tenant - level role - based permission allocation system and method based on large - model agents proposed by the present invention adopts a modular design, which organically combines modules such as agent registration and management, role management, role - level permission allocation, and permission verification and execution, forming a flexible, secure, and efficient permission management architecture. This architecture design can not only meet the current business requirements but also has good scalability.

[0060] Through the interface operation and dynamic adjustment mechanism, it supports the tenant administrator to adjust the agent permissions of roles in real - time on the permission management interface, including adding, deleting, and modifying operations of permissions, and updates the permission database in real - time to ensure the flexibility and dynamics of permission allocation.

[0061] The permission verification mechanism is more stringent. When an agent is called, the system will verify whether the caller (tenant and its role) has the corresponding permissions through the permission database. If the caller fails the verification, the system will reject the call request and record the relevant log information for subsequent security audits. BRIEF DESCRIPTION OF THE DRAWINGS

[0062] Figure 1 It is a flowchart of the tenant - level role - based permission allocation of the present invention;

[0063] Figure 2 It is an implementation architecture diagram of the tenant - level role - based permission allocation of the present invention;

[0064] Figure 3 It is a flowchart of user access to the agent of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0065] In order to clearly and completely describe the objectives, technical solutions of the present invention and make the advantages more clear, the following further details the embodiments of the present invention with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are some embodiments of the present invention, rather than all embodiments, and are only used to explain the embodiments of the present invention, not to limit the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.

[0066] Please refer to Figures 1 to 3 , the present invention provides a technical solution: a tenant - level role - based permission allocation system and method based on large - model agents. The system realizes flexible, secure, and efficient management of agent permissions for different roles within the tenant through modules such as agent registration, role management, role - level permission allocation, and permission verification and execution. The core idea of the present invention is as follows:

[0067] 1) Create and maintain a list of agents, storing information such as the names, function descriptions, resource requirements, etc. of all available agents. Each agent has a unique identifier in the system;

[0068] 2) When a new agent goes online, register its name, function description, and other information into the agent list through a standardized registration interface. The registration information needs to be reviewed by the system to ensure it complies with security and function specifications;

[0069] 3) Inside each tenant, define different roles (such as administrator, first-level tenant, ordinary user, etc.), and each role has different permission levels and function requirements;

[0070] 4) The tenant administrator can assign different roles to users within the tenant through the system interface, thereby determining the scope of permissions of the users within the tenant;

[0071] 5) The system provides a permission management interface. The tenant administrator can grant different agent permissions to different roles within the tenant through this interface. The interface provides functions such as role selection, agent selection, and permission level setting;

[0072] 6) The system stores the permission relationship between roles and agents in a permission database. The permission database supports fast query and update operations to ensure the real-time and accuracy of permission allocation;

[0073] 7) The tenant administrator can dynamically adjust the agent permissions of roles through the permission management interface. The system supports operations such as adding, deleting, and modifying permissions and updates the permission database in real-time;

[0074] 8) When an agent is called, the system first verifies whether the caller (tenant and its role) has the corresponding permissions. The verification process is completed by querying the permission database to ensure that the caller uses the agent within the legal permission scope;

[0075] 9) If the caller passes the permission verification, the system allows it to call the agent and perform related operations; if the caller fails the permission verification, the system rejects the call request and records relevant log information for subsequent security audits.

[0076] The basic implementation architecture of this technical solution is as Figure 2 shown, mainly including the following components: 1) Role-level permission management interface; 2) Permission management control center; 3) Permission database; 4) Agent registration and management module; 5) Agent permission management API.

[0077] 1) Role-level permission management interface

[0078] The role-level permission management interface is mainly used to provide permission management interfaces for the upper management platform or third-party systems, including interfaces for querying, creating, modifying, and deleting roles, allocating and revoking agent permissions, and querying and modifying user roles.

[0079] The role list interface displays information such as role ID, name, and permission level, and the agent permission interface displays information such as agent name, function description, and permission level.

[0080] 2) Permission Management Control Center

[0081] The permission management control center is mainly responsible for processing the core business logic of permission management. When an administrator assigns roles or agent permissions to users through the management platform interface or API interface, the role-level permission management interface will trigger the permission management control center to perform specific operations, such as creating, modifying, and deleting permissions. The permission management control center records the user's role and agent permission information in the permission database for persistence.

[0082] Among them, the business process of assigning agent permissions to users is as follows:

[0083] Step 1: The administrator selects a user and a role through the management platform interface to assign a role to the user.

[0084] Step 2: The administrator selects the agent for which permissions need to be assigned and sets the permission level (such as read, write, manage, etc.).

[0085] Step 3: Call the agent permission management API to verify whether the agent exists. If it does not exist, return that the agent information does not exist.

[0086] Step 4: Package the permission parameters and store the permission information in the permission database.

[0087] Step 5: The permission management control center records the user's role and agent permission information.

[0088] 3) Permission Database

[0089] The permission database is mainly responsible for storing the persistence of user role and agent permission data. When the system restarts or exits abnormally, it can restore the user's permission information from the permission database to ensure the availability of user permission management.

[0090] There are two tables related to permission information: the role table (role) and the permission table (role_agent_permission). The role table stores information such as role ID, name, and permission level; the permission table stores information such as role ID, agent ID, permission level, and creation time.

[0091] 4) Agent Registration and Management Module

[0092] The agent registration and management module is mainly responsible for the registration, configuration, and maintenance management of agents. Its specific functions include the creation, deletion of agents, the update of function descriptions, and the configuration of resource requirements.

[0093] Among them, the steps for agent registration are as follows:

[0094] Step 1: Create an agent instance and assign it a unique identifier.

[0095] Step 2: Add the agent instance to the agent list and configure its function description and resource requirements.

[0096] Step 3: Configure a security policy for the agent to ensure its secure operation.

[0097] Step 4: Synchronize the agent information to the permission management control center for subsequent permission allocation and management.

[0098] 5) Agent Permission Management API

[0099] The agent permission management API is responsible for comprehensively managing the permission allocation and recovery of agents, as well as the corresponding operations of user permissions. Through this API, administrators can allocate or recover agent permissions for users and synchronize them to the permission database in real time.

[0100] When managing agent permissions, special attention needs to be paid to the setting of permission levels and security policies.

[0101] In-depth analysis of permission levels and security policies:

[0102] Permission level: This attribute determines the scope of user operation permissions for agents, such as reading, writing, management, etc. The permission level directly affects the scope of use and functions of agents by users and is a core link in permission management.

[0103] Security policy: This attribute determines the security access policy of agents, including the allowed IP range, ports, protocols, etc. The security policy is the key to ensuring the secure operation of agents and can effectively prevent unauthorized access and attacks.

[0104] Regarding the optional values and specific meanings of the above two attributes:

[0105] Read permission: Users can only view the status and output of agents and cannot modify or operate them.

[0106] Write permission: Users can configure and operate agents but cannot manage their core functions.

[0107] Management Permissions: Users can comprehensively manage agents, including configuration, operation, and monitoring.

[0108] In summary, by reasonably configuring permission levels and security policies, the system can flexibly and efficiently support the permission management of agents, meeting diverse business requirements.

[0109] After the tenant administrator assigns agent permissions to roles within the tenant, the process for users to access the agent platform is as follows, as Figure 3 shown:

[0110] 1) The user initiates an agent call request

[0111] The user initiates a call request for a certain agent through the system interface or API. The request contains the user's identity information (such as user ID) and the identifier of the target agent (such as agent ID).

[0112] 2) The system receives the request and triggers the permission verification module

[0113] After the system receives the user's call request, it triggers the permission verification module. The permission verification module verifies whether the user has the permission to call the agent by querying the permission database. The verification process includes the following steps:

[0114] a) Query the user's role.

[0115] b) Query whether the role has been granted the permission to call the target agent.

[0116] c) Verify whether the call conforms to the role's permission level (such as read, write, manage, etc.).

[0117] 3) Processing of permission verification results

[0118] Based on the return result of the permission verification module, the system performs corresponding processing:

[0119] a) If the verification passes: The system allows the user to call the agent and execute relevant operations.

[0120] b) If the verification fails: The system rejects the user's call request and records relevant log information for subsequent security audits. The reasons for rejecting the call may include: The user role has not been granted the corresponding permission, insufficient permission level, etc.

[0121] 4) The agent executes the operation

[0122] If the user passes the permission verification, the system allows the user to call the agent and perform the following operations:

[0123] a) The agent receives the user's call request.

[0124] b) The agent performs corresponding operations (such as data processing, task execution, etc.) according to the user's request content.

[0125] c) The agent returns the execution result to the user.

[0126] 5) Record operation logs

[0127] Whether the call is successful or not, the system will record relevant operation logs, and these log information will be used for subsequent security audits and problem troubleshooting.

[0128] a) The log content includes information such as user ID, agent ID, call time, call result, etc.

[0129] b) If the call fails, record the reason for failure (such as insufficient permissions, agent unavailable, etc.).

[0130] 6) End of agent access

[0131] The operation of the user calling the agent is completed, and the system returns the final result to the user.

[0132] Although the embodiments of the present invention have been shown and described, for those of ordinary skill in the art, it can be understood that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. A tenant - level role - based permission allocation system based on large - model agents, characterized in that: It includes: An agent list creation and maintenance module, which is used to store the names, function descriptions, and resource requirement information of all available agents, and assign a unique identifier to each agent; An agent registration module, which is used to register the information of a new agent into the agent list through a standardized registration interface when the new agent goes online, and is subject to system review; A role definition module, which is used to define different roles within each tenant, and each role has different permission levels and function requirements; A role assignment module, which allows the tenant administrator to assign roles to the internal users of the tenant through the system interface to determine the user's permission scope; A permission management interface, which provides functions for role selection, agent selection, and permission level setting, and is used for the tenant administrator to grant agent permissions to different roles; A permission database, which is used to store the permission relationships between roles and agents, and supports fast query and update operations; A permission adjustment module, which allows the tenant administrator to dynamically adjust the agent permissions of a role and update the permission database in real time; A permission verification module, which verifies whether the caller has the corresponding permissions when an agent is called, and completes the verification by querying the permission database; An execution and logging module, which allows or rejects the agent call according to the permission verification result and records the relevant log information.

2. The tenant - level role - based permission allocation system based on large - model agents according to claim 1, wherein: The agent registration module further includes: An agent instance creation unit, which is used to create an agent instance and assign a unique identifier; An agent information configuration unit, which is used to add the agent instance to the agent list and configure its function description and resource requirements; A security policy configuration unit, which is used to configure security policies for agents to ensure their secure operation; An information synchronization unit, which is used to synchronize agent information to the permission management control center for subsequent permission allocation and management.

3. The tenant - level role - based permission allocation system based on large - model agents according to claim 2, characterized in that: The permission management interface includes: A role selection interface, which is used to display the role list and allow the tenant administrator to select a role; An agent selection interface, which is used to display the agent list and allow the tenant administrator to select an agent; A permission level setting interface, which is used to allow the tenant administrator to set the permission level for the selected agent for the selected role, including read, write, and management levels.

4. The tenant - level role - based permission allocation system based on large - model agents according to claim 3, characterized in that: The execution process of the permission verification module includes: Receiving an agent call request initiated by a user, which contains the user identity information and the target agent identifier; Querying the role information of the user; Verifying whether the role is granted the call permission for the target agent and whether the call conforms to the role's permission level; According to the verification result, allowing or rejecting the agent call and recording the relevant log information.

5. The tenant - level role - based permission allocation system based on large - model agents according to claim 4, characterized in that: It also includes an operation log recording module, which is used for: Recording the operation logs of the user's agent calls, including the user ID, agent ID, call time, and call result information; When the call fails, recording the failure reason, such as insufficient permissions or the agent being unavailable; Providing log information for subsequent security audits and problem troubleshooting.

6. A method for a tenant - level role - based permission allocation system based on large - model agents according to claim 5, characterized in that: It includes the following steps: Creating and maintaining an agent list, storing the names, function descriptions, and resource requirement information of all available agents, and assigning a unique identifier to each agent; Registering the name and function description information of the new agent into the agent list through a standardized registration interface and subjecting it to system review; Define different roles within each tenant, where each role has different permission levels and functional requirements; Provide a permission management interface that allows tenant administrators to grant different agent permissions to different roles within the tenant, including role selection, agent selection, and permission level setting; Store the permission relationship between roles and agents in a permission database to support quick query and update operations.

7. A method according to claim 6, wherein: It also includes the following steps: Tenant administrators dynamically adjust the agent permissions of roles through the permission management interface, including operations such as adding, deleting, and modifying permissions; Update the permission database in real time to reflect the latest status of role agent permissions; When an agent is called, the system first verifies whether the caller has the corresponding permission, and the verification process is completed by querying the permission database.

8. A method according to claim 7, characterized in that: The permission verification steps specifically include: Query the role information of the caller; Query whether this role has been granted the call permission for the target agent; Verify whether the call conforms to the permission level of the role, including read, write, and manage; According to the verification result, allow or deny the agent call, and record relevant log information when denying for subsequent security audits.

9. A method according to claim 8, wherein: The registration and management steps of the agent further include: Create an agent instance and assign a unique identifier to it; Add the agent instance to the agent list and configure its function description and resource requirements; Configure a security policy for the agent to ensure its secure operation; Synchronize the agent information to the permission management control center for subsequent permission allocation and management.

10. A method according to claim 9, characterized in that: It also includes the following steps: When the user passes the permission verification, allow the user to call the agent, and the agent receives the user's call request; The agent performs corresponding operations according to the user's request content, such as data processing and task execution; The agent returns the execution result to the user; Regardless of whether the call is successful, the system records relevant operation logs, including user ID, agent ID, call time, call result information, and if the call fails, the reason for the failure is also recorded for subsequent security audits and problem troubleshooting.

Citation Information

Cited By

  • Intelligent agent collaborative management system and method based on multi-tenant isolation and dynamic role permission

    CN120896736A