Information system user authentication management method based on RBAC model

By combining the RBAC model in the B/S and C/S hybrid software architecture, the problem of combining access permissions and front-end application framework in the microservice architecture is solved, and the secure and controllable access control of the information system is realized, ensuring the security of business functions and data flows.

CN120342701APending Publication Date: 2025-07-18NANJING RES INST OF ELECTRONICS TECH
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510511820.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-23
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

In the microservice software architecture, access permissions are not organically combined with the front-end application framework, making it difficult to guarantee the business functions and data flow security of the information system.

Method used

Using the information system user authentication management method based on the RBAC model, in the B/S and C/S hybrid software architecture, the back-end microservice user authentication module and terminal permission management are organically combined to establish a ‘user-role-permission-resource’ model to perform identity authentication and authorization management.

Benefits of technology

It realizes monitoring of the entire process of information system login, authentication and cancellation, ensuring the security and controllability of business functions and data flows, and providing flexible and easy-to-manage access control policies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342701A_ABST
    Figure CN120342701A_ABST
Patent Text Reader

Abstract

An information system user authentication management method based on an RBAC model is characterized in that in a B / S and C / S mixed software architecture of an information system, a technical scheme of organically combining a rear-end micro-service user authentication module with terminal authority management by using seat authority is adopted, and a user-role-authority-resource model is established; the technical effect of monitoring the whole process of login, authentication and logout of the information system is achieved, and the service function and the data flow are ensured to be safe and controllable.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of information management, and particularly relates to a user authentication technology for the RBAC model. Background Art

[0002] The most common problem of information systems regarding situation data is security, and the most crucial aspects of security are authentication and authorization. Authentication is used to solve the problem of whether a user's identity is legitimate, and authorization is the management of resource access permissions or resource lists after user authentication. With the extensive application of microservice software architectures, access permissions are not organically integrated with the front-end application framework. The security of the data flow of business functions is becoming increasingly severe, and there is an urgent need to solve the authentication and authorization problems of information systems.

[0003] The master's thesis of Beijing University of Posts and Telecommunications, "Research and Application of Access Control Technology in the Microservice Environment," deeply studied the identity authentication model and access control model of microservices, and proposed a unified identity management and single sign-on / logout model for microservices based on the microservice gateway and JWT tokens. However, it is also necessary to consider the integrated control method of permissions in the hybrid architecture mode, and organically combine the microservice architecture and the front-end application framework. Only by closely integrating the seat permissions of the front-end application framework with the user authentication of the microservice architecture can the security and controllability of the data flow of business functions be ensured. Summary of the Invention

[0004] To solve the authentication and authorization problems existing in information systems, the present invention proposes a user authentication management method for information systems based on the RBAC model. In the B / S and C / S hybrid software architectures of information systems, a technical solution that organically combines the seat permissions of the back-end microservice user authentication module and the terminal permission management is adopted, establishing a "user-role-permission-resource" model, and achieving the technical effect of full-process monitoring of information system login, authentication, and logout, ensuring the security and controllability of business functions and data flows.

[0005] Establish a permission design model based on RBAC, form a front-end and back-end user and permission management model, implement a flexible and easy-to-manage access control strategy, provide an extensible and manageable access control strategy, and protect system resources from unauthorized access threats.

[0006] Based on RBAC, establish a "user-role-permission-resource" data maintenance model, manage data for users, roles, and their affiliated permission resources, and simultaneously manage the association relationships between modules, including user information management, role information management, permission information maintenance, and association information management, clarifying the corresponding relationships between various elements.

[0007] According to the RBAC model, design the user authentication for the entire process of each business function, including the roles to which the user belongs, login verification, session maintenance, and their corresponding resources, business plugins, and microservice information.

[0008] Establish an identity authentication model, including client visitors, API gateways, authentication units, token issuance units, token conversion units, token parsing units, and identity management units. Taking the user as the core, use the identity management unit to store the front-end and back-end users and their affiliated information. After authentication by the authentication unit, obtain the list of usage permissions for front-end business software and the list of back-end microservice resource locations. The microservice side includes the generation and management of token issuance units, token conversion units, and token parsing units.

[0009] Design user authentication for the front-end and back-end hybrid architecture, discretize the functional resources involved in the situation display, form situation display business plugins and situation generation microservice lists. The overall architecture style supports the BS and CS hybrid architectures, divide the situation display functions, and set microservice components.

[0010] Construct an identity authentication conversion model architecture, issue JWT tokens. When the user logs in, the gateway verifies whether the client request carries a token, the authentication unit verifies the client's identity credentials, the token issuance unit assembles the JWT token, and the gateway converts the JWT token into a CT token.

[0011] User identity authentication includes token conversion operations, token verification operations, and identity extraction operations, which occur during the process of the client carrying a token to request resources from the microservice. The client is an end user or other microservices. The user holds a CT token, and the microservice holds a JWT token. Description of the Drawings

[0012] Figure 1 It is a RBAC permission design diagram.

[0013] Figure 2 It is a diagram of the association relationship of user permissions.

[0014] Figure 3 It is a user authentication design diagram.

[0015] Figure 4 It is a front-end and back-end authentication design diagram. Detailed Implementation Modes

[0016] The following specifically describes the technical solutions of the present invention in conjunction with the accompanying drawings.

[0017] Step 1: Establish a RBAC-based permission design model to form a front-end and back-end user and permission management model.

[0018] The RBAC permission design is as Figure 1 shown, realizing a flexible and easy-to-manage access control policy, providing an extensible and manageable access control policy, and protecting system resources from unauthorized access threats.

[0019] Step 2: Establish a "user-role-permission-resource" data maintenance model based on RBAC, manage data for users, roles, and their associated permission resources, and simultaneously manage the association relationships between modules, such as Figure 2 as shown, clarify the corresponding relationships between various elements.

[0020] User information management: View information, add, modify, and delete users who can log in to the framework software, and save them in the database.

[0021] Role information management: Use roles as the core elements of permission management to associate users and their associated permission resources, and view information, add, modify, and delete role information.

[0022] Permission information maintenance: Manage the functional permissions corresponding to roles, synchronously load the plugin list, menu bar settings, and tool menu configurations in the corresponding seat information of the information system, and view information, add, modify, and delete.

[0023] Association information management: According to the associated resource management, realize the automatic maintenance of the association of the "user-role-permission-resource" model data, and record the structured data of users, roles, seats, plugins, and microservices in Tables 1-5.

[0024] Table 1 User structured data

[0025] Serial number Field Name 1 userid User ID 2 username User name 3 rolelist Role list ...

[0026] Table 2 Role structured data

[0027] Serial number Field Name 1 roleid User ID 2 rolename User name 3 seatlist Seat list ...

[0028] Table 3 Seat structured data

[0029] Serial number Field Name 1 seatid User ID 2 seatname User name 3 pluginslist Seat list 4 microserlist Microservice list ...

[0030] Table 4 Plugin structured data

[0031] Serial number Field Name 1 pluginsid Plugin ID 2 pluginsname Plugin name 3 menulist Menu list 4 toollist Toolbar list 5 screenlist Secondary screen list ...

[0032] Table 5 Microservice structured data

[0033] Serial number Field Name 1 microserid Plugin ID 2 microsername Plugin name 3 microserinfo Menu list ...

[0034] Step 3: Design user authentication for the entire process of each business function according to the RBAC model, such as Figure 3 as shown, including the roles to which the user belongs, login verification, session maintenance, and their corresponding resources, business plugins, and microservice information.

[0035] Step 4: Establish an identity authentication model, including client visitors, API gateways, authentication units, token issuance units, token conversion units, token parsing units, and identity management units. Taking the user as the core, use the identity management unit to store the front-end and back-end users and their affiliated information. After authentication by the authentication unit, obtain the list of usage permissions for front-end business software and the list of resource locations for back-end microservices. The microservice side includes the generation and management of token issuance units, token conversion units, and token parsing units.

[0036] Step 5: Design user authentication for the front-end and back-end hybrid architecture. As Figure 4 shown, discretize the functional resources involved in the situation display to form a situation display service plugin and a situation generation microservice list. The overall architecture style supports the BS and CS hybrid architecture. Use Table 2 to divide the situation display functions and Table 3 to set the microservice components.

[0037] Table 6 Situation Display Service Plugin

[0038]

[0039] Table 7 Microservice Components

[0040] Component Type In-memory database redis Gateway GW User authentication Auth Load balancing Ribbon Registry center Nacos

[0041] Carry out plugin-based and microservice-based transformation of the situation display function. On the front-end, form a situation display process plugin, and form a microservice list for situation data parsing, situation style calculation, and situation display and hiding calculation.

[0042] Step 6: Build an identity authentication conversion model architecture, issue JWT tokens. When the user logs in, the gateway verifies whether the client request carries a token. The authentication unit verifies the client's identity credentials. The token issuance unit assembles the JWT token, and the gateway converts the JWT token into a CT token.

[0043] Build an identity authentication conversion model architecture. Based on the gateway and JWT tokens, the authentication module issues JWT tokens and transfers them between multiple microservices.

[0044] The login process is triggered by the user's active login or redirection due to microservice verification failure, authenticates the user's identity, and issues tokens.

[0045] The gateway intercepts the client request. If the request carries a client token, it determines that the client token is valid and attempts to convert it into a JWT token. The gateway does not perform JWT verification operations. If the conversion is successful, it means the user has logged in. If the request does not carry a client token or the conversion to JWT fails, it forwards the request to the authentication unit.

[0046] The authentication unit requires the client to provide a username and password as identity credentials. The authentication unit queries the relevant privilege management information. If the authentication is successful, it transfers to the token issuance unit; otherwise, it requests re-authentication.

[0047] According to the provisions of RFC7519 standard, the token issuance unit generates a header, a payload, and a signature in sequence. The header is based on the signature algorithm pre-set in the system. The payload contains the basic data stipulated by the standard and the user identity information provided by the privilege management. The first two parts are signed using the pre-set signature algorithm, and then assembled into a complete JWT token, which is returned to the gateway.

[0048] The gateway converts the JWT token into a CT token, stores the mapping relationship, and returns the CT token to the client.

[0049] User identity authentication includes token conversion operations, token verification operations, and identity extraction operations, which occur during the process of the client carrying a token to request a resource microservice. The client can be an end user or other microservices. The user holds a CT token, and the microservice holds a JWT token.

[0050] When the client accesses the situation microservice, the request is intercepted by the gateway GW. If it is a CT token, it attempts the token conversion operation. If the conversion fails, the user access ends and the user is redirected to the login page. If the conversion is successful, the gateway accesses with the JWT token. If it is a JWT token, it is sent to the accessed microservice.

[0051] After receiving the JWT token, the microservice performs a Base64 decryption operation to obtain the relevant algorithm and the content of the header, payload, and signature, calculates the message digest of the header and payload, and verifies the integrity and credibility of the token according to the signature algorithm and the public key of the token issuance unit, and checks whether the token has expired. If successful, it extracts the user identity from the payload of the JWT token; otherwise, it transfers to the login operation.

[0052] The client logs out of the identity of the entire application system, including the logout operation of the token issuance unit and the logout operation of the gateway.

[0053] Logout operation of the token issuance unit: The gateway converts the client's CT token into a JWT token and requests the token issuance unit to log out the JWT token.

[0054] Logout operation of the gateway: The gateway removes the mapping relationship between the client's CT token and the JWT token.

[0055] The above are the embodiments of the present invention and do not limit the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention are all included in the protection scope of the present invention.

Claims

1. An information system user authentication and management method based on the RBAC model, characterized in that Including: Establish an RBAC-based permission design model to form a front-end and back-end user and permission management model, implement a flexible and easy-to-manage access control policy, provide an extensible and manageable access control policy, and protect system resources from unauthorized access threats; Based on the RBAC model, establish a "user-role-permission-resource" data maintenance model, manage data for users, roles, and their affiliated permission resources, and synchronously manage the association relationships between modules to clarify the corresponding relationships between various elements; According to the RBAC model, design user authentication for the entire process of each business function, including the roles to which the user belongs, login verification, session maintenance, and their corresponding resources, business plugins, and microservice information; Establish an identity authentication model, including client visitors, API gateways, authentication units, token issuance units, token conversion units, token parsing units, and identity management units. With the user as the core, use the identity management unit to store front-end and back-end users and their affiliated information. After authentication by the authentication unit, obtain the list of front-end business software usage permissions and the list of back-end microservice resource locations. The microservice side includes the generation and management of token issuance units, token conversion units, and token parsing units; Design user authentication for the front-end and back-end hybrid architecture, discretize the functional resources involved in the situation display to form a situation display business plugin and a situation generation microservice list, and the overall architecture style supports the BS and CS hybrid architecture; Construct an identity authentication conversion model architecture, issue JWT tokens. When the user logs in, the gateway verifies whether the client request carries a token, the authentication unit verifies the client's identity credentials, the token issuance unit assembles the JWT token, the gateway converts the JWT token into a CT token, stores the mapping relationship, and returns the CT token to the client.

2. The information system user authentication management method based on the RBAC model according to claim 1, characterized in that, The data management for users, roles, and their affiliated permission resources includes: user information management, which views, adds, modifies, and deletes the information of users who can log in to the framework software and saves it in the database; Role information management, which takes the role as the core element of permission management, is used to associate users and their affiliated permission resources, and views, adds, modifies, and deletes role information; Permission information maintenance, which manages the functional permissions corresponding to roles, synchronously loads the plugin list, menu bar settings, and tool menu configurations in the corresponding seat information of the information system, and views, adds, modifies, and deletes the information; Association information management, which realizes the automatic maintenance of the association of the "user-role-permission-resource" model data according to the associated resource management; 3. The information system user authentication management method based on the RBAC model according to claim 2, characterized in that The association information management includes: recording the structured data of users, roles, seats, plugins, and microservices in Tables 1 to 5; Table 1 User structured data Table 2 Role structured data Table 3 Seat structured data Table 4 Plugin structured data Table 5 Microservice structured data 。 4. The information system user authentication management method based on the RBAC model according to claim 1, characterized in that, The user authentication for the designed front-end and back-end hybrid architecture includes: transforming the situation display function into a plug-in and microservices architecture, forming a situation display process plug-in at the front end, and forming a microservices list for situation data parsing, situation style calculation, and situation display and hiding calculation. The situation display service plug-in is recorded in Table 6, and the microservices components are recorded in Table 7; Table 6 Situation Display Service Plug-in Table 7 Microservices Components 。 5. The method for user authentication management of an information system based on the RBAC model according to claim 1, characterized in that, The component identity authentication conversion model architecture is based on a gateway and JWT tokens. The authentication module issues JWT tokens, which are passed between multiple microservices; The issuance of JWT tokens is triggered by the user's active login or redirection due to microservice authentication failure. The user's identity is authenticated, and the token is issued; The gateway verifies whether the client request carries a token. The gateway intercepts the client request. If the request carries a client token, it determines that the client token is valid and attempts to convert it into a JWT token. The gateway does not perform JWT verification operations. If the conversion is successful, it indicates that the user has logged in. If the request does not carry a client token or the JWT conversion fails, it forwards the request to the identity verification unit; The identity verification unit verifies the client's identity credentials, requires the client to provide a username and password as identity credentials, and the identity verification unit queries relevant permission management information. If the authentication is successful, it transfers the request to the token issuance unit; otherwise, it requires re-authentication; The token issuance unit assembles the JWT token. According to the provisions of RFC7519, it generates the header, payload, and signature in sequence. The header is based on the signature algorithm preset by the system. The payload contains the basic data specified by the standard and the user identity information provided by the permission management. It signs the first two parts using the preset signature algorithm and assembles them into a complete JWT token, which is then returned to the gateway.

6. The method for user authentication management of an information system based on the RBAC model according to claim 5, characterized in that, The identity authentication includes: token conversion operations, token verification operations, and identity extraction operations, which occur during the process of the client carrying a token to request a resource microservice. The client can be an end user or another microservice. The user holds a CT token, and the microservice holds a JWT token.

7. The method for user authentication management of an information system based on the RBAC model according to claim 6, characterized in that, The identity authentication also includes: when the client accesses the situation microservice, the request is intercepted by the gateway GW. If it is a CT token, it attempts a token conversion operation. If the conversion fails, the user access is terminated, and the user is redirected to the login page. If the conversion is successful, the gateway accesses with the JWT token. If it is a JWT token, it is sent to the accessed microservice; When the microservice receives the JWT token, it performs a Base64 decryption operation to obtain the relevant algorithm, header, payload, and signature content, calculates the message digest of the header and payload, and verifies the integrity and credibility of the token according to the signature algorithm and the public key of the token issuance unit. It checks whether the token has expired. If successful, it extracts the user identity from the payload of the JWT token; otherwise, it transfers to the login operation; The client logs out of the identity of the entire application system, including the logout operation of the token issuance unit and the logout operation of the gateway.

8. The method for user authentication management of an information system based on the RBAC model according to claim 7, characterized in that For the logout operation of the token issuance unit, the gateway converts the client CT token into a JWT token and requests the token issuance unit to log out the JWT token; For the logout operation of the gateway, the gateway removes the mapping relationship between the client CT token and the JWT token.

Citation Information

Patent Citations

  • Method for realizing micro service access control

    CN107528853A

  • Micro-service unified authority control method and system based on user attributes

    CN113098695A

  • Authority management system and method based on RBAC model

    CN114722408A