Central authority service device, authority management method, device, equipment and medium
Through the central platform layer and authentication component layer of the central authority service device, centralization and systematization of permission management are achieved, the problems of low efficiency and low security of permission management are solved, operation and maintenance efficiency and system security are improved, and dynamic changes of multi-service platforms are adapted to.
Patent Information
- Application Number
- CN202510828077.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-19
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2045-06-19
AI Technical Summary
In the prior art, permission management efficiency is low, system security and operation and maintenance efficiency are low, and the permission strategies of each business platform are difficult to unified and manage.
The central authority service device is adopted, including the central platform layer and the authentication component layer, and provides user management, project management, permission management, log management and policy engine modules, combining standardized software development toolkit, real-time authentication interface and cache management module to achieve centralized and systematic management of permissions.
It improves the efficiency of permission management and system security, reduces operation and maintenance costs, supports unified management and dynamic permission control of multi-service platforms, and enhances the flexibility and maintainability of the system.
Smart Images

Figure CN120358084A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of computer security technologies, and in particular, to a central permission service device, a permission management method, device, equipment, and medium. Background Art
[0002] With the continuous development of information technology and the in-depth promotion of enterprise digital transformation, enterprises generally deploy multiple business platforms in their daily operations to support different business needs. To ensure data security and access control for each platform, a permission management system has become an indispensable core component. Traditional permission management mostly adopts a decentralized architecture, where each business platform maintains an independent permission system, resulting in increasingly prominent problems such as difficult-to-unify permission policies, difficult-to-track permission changes, and inconsistent authentication interfaces. Therefore, how to achieve centralized management and dynamic control of permissions for multiple business platforms has become an important research direction in the current enterprise IT system construction.
[0003] In the prior art, common permission management models include role-based access control (RBAC) and discretionary access control (DAC), etc. For example, a resource management platform of a large enterprise adopts the RBAC model, dividing users into roles such as ordinary users, merchants, and administrators, and assigning corresponding operation permissions to different roles; while its cloud platform uses the DAC model, where the resource owner decides who can access their resources. These permission information is usually stored in the databases or configuration files of each platform itself, lacking a unified standard and centralized management mechanism. In addition, there are significant differences in the authentication interfaces between platforms, and developers need to make separate adaptations for different platforms, increasing the development and maintenance costs.
[0004] Currently, the permission management efficiency is low, the system security is low, and the operation and maintenance efficiency is low. Summary of the Invention
[0005] The present disclosure provides a central permission service device, a permission management method, device, equipment, and medium to at least solve the problems of low permission management efficiency, low system security, and low operation and maintenance efficiency.
[0006] According to a first aspect of the present disclosure, there is provided a central permission service device, including: a central platform layer and an authentication component layer; The central platform layer includes: a user management module, a user group management module, a project management module, a permission management module, a log management module, and a policy engine module; the user management module is used to manage the user information of the central permission management platform; the user group management module is used to manage the user group information of the central permission management platform; the project management module is used to centrally manage the metadata information and permission files of the project, and has a version control function; the permission management module is used to perform editing operations on the permission files and identify the permission codes that users can access through a unified authentication component; the log management module is used to record the operation logs related to permissions; the policy engine module is used to parse and execute the generation of permission policies; The authentication component layer includes: a standardized software development kit module, a real-time authentication interface module, and a cache management module; the standardized software development kit module is used to provide multiple programming language interfaces for the service platform to call the authentication function; the real-time authentication interface module is used to process the authentication requests of users; and the cache management module is used to manage the life cycle of the local cache.
[0007] According to a second aspect of the present disclosure, there is provided a permission management method, including: After the service platform is deployed, an encrypted activation code carrying metadata information and current attribute information is sent to the central permission service device; The central permission service device parses the encrypted activation code, matches the corresponding permission file, generates a permission policy, and returns the permission initialization data to the service platform; The service platform writes the permission initialization data into the local permission database for the authentication software development kit to call.
[0008] According to a third aspect of the present disclosure, there is provided a permission management device, including: A sending module, configured to send an encrypted activation code carrying metadata information and current attribute information to the central permission service device after the service platform is deployed; A generating module, configured to enable the central permission service device to parse the encrypted activation code, match the corresponding permission file, generate a permission policy, and return the permission initialization data to the service platform; A writing module, configured to enable the service platform to write the permission initialization data into the local permission database for the authentication software development kit to call.
[0009] According to a fourth aspect of the present disclosure, there is provided an electronic device, including: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the method described in the foregoing second aspect.
[0010] According to a fifth aspect of the present disclosure, there is provided a non-transitory computer-readable storage medium storing computer instructions, wherein the computer instructions are used to cause the computer to execute the method described in the foregoing second aspect.
[0011] According to a sixth aspect of the present disclosure, there is provided a computer program product including a computer program / instructions, and the computer program / instructions are executed by a processor to perform the steps in the method described in the foregoing second aspect.
[0012] In some embodiments of the present disclosure, the central authority service device includes: a central platform layer and an authentication component layer; the central platform layer includes: a user management module, a user group management module, a project management module, a permission management module, a log management module, and a policy engine module; the user management module is used to manage the user information of the central authority management platform; the user group management module is used to manage the user group information of the central authority management platform; the project management module is used to centrally manage the metadata information and permission files of the project, and has a version control function; the permission management module is used to perform editing operations on the permission files, and authenticate the permission codes that the user can access through a unified authentication component; the log management module is used to record the operation logs related to permissions; the policy engine module is used to parse and execute the generation of permission policies; the authentication component layer includes: a standardized software development kit module, a real-time authentication interface module, and a cache management module; the standardized software development kit module is used to provide multiple programming language interfaces for the service platform to call the authentication function; the real-time authentication interface module is used to process the authentication requests of users; and the cache management module is used to manage the life cycle of the local cache; the present disclosure changes the decentralized management mode, realizes the centralization and systematization of permission management and authentication, thereby improving the permission management efficiency, improving the system security, and improving the operation and maintenance efficiency.
[0013] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present application, nor is it used to limit the scope of the present application. Other features of the present application will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] The accompanying drawings herein are incorporated into the specification and constitute a part of this specification, showing embodiments consistent with the present disclosure, and are used together with the specification to explain the principles of the present disclosure and do not constitute an improper limitation of the present disclosure.
[0015] Figure 1 A structural diagram of a central authority service device provided for an exemplary embodiment of the present disclosure; Figure 2 A flowchart of a permission management method provided by an exemplary embodiment of the present disclosure; Figure 3 A structural diagram of a permission management device provided by an exemplary embodiment of the present disclosure; Figure 4 A structural diagram of an electronic device provided by an exemplary embodiment of the present disclosure. Detailed implementation manners
[0016] The following describes exemplary embodiments of the present disclosure with reference to the accompanying drawings. Various details of the embodiments of the present disclosure are included to assist understanding, and they should be considered merely exemplary. Therefore, those of ordinary skill in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the present disclosure. Similarly, for clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description.
[0017] Next, a central permission service device, a permission management method, a device, and an electronic device for storing data according to embodiments of the present disclosure are described with reference to the accompanying drawings.
[0018] Figure 1 A structural diagram of a central permission service device provided by an exemplary embodiment of the present disclosure. As Figure 1 shown, the central permission service device includes: a central platform layer and an authentication component layer. The central platform layer includes: a user management module, a user group management module, a project management module, a permission management module, a log management module, and a policy engine module; the user management module is used to manage user information of the central permission management platform; the user group management module is used to manage user group information of the central permission management platform; the project management module is used to centrally manage project metadata information and permission files, and has a version control function; the permission management module is used to perform editing operations on permission files and identify permission codes that users can access through a unified authentication component; the log management module is used to record operation logs related to permissions; the policy engine module is used to parse and execute permission policy generation; The authentication component layer includes: a standardized software development kit module, a real-time authentication interface module, and a cache management module; the standardized software development kit module is used to provide multiple programming language interfaces for the business platform to call the authentication function; the real-time authentication interface module is used to process user authentication requests; and the cache management module is used to manage the life cycle of the local cache.
[0019] The user management module is responsible for managing user information in the central permission management platform, including functions such as user registration, login, and information modification. It supports batch import and export of users, facilitating large-scale user management for enterprises. By integrating with the existing enterprise user management system, it realizes unified management and synchronization of user information, avoiding duplicate entry and inconsistent issues of user information.
[0020] The user group management module is responsible for managing user group information in the central permission management platform, including functions such as creation, editing of user groups, management of group members, and project management of user groups. A user can belong to multiple user groups, and a user group can contain multiple projects. Users within a group can perform permission management operations on projects managed by the user group.
[0021] The project management module is a characteristic module of the central permission management platform, responsible for centralized management and version control of metadata information and permission files of each project, including functions such as project creation, editing, status adjustment, and deletion. Project management operations integrate git functions: creating a project saves project information and creates a local git repository; editing a project can edit project information and delete the original local git repository to create a new one; deleting a project can delete project information and the git local repository; project version management can view information and permission files of each version of the project, and supports creating snapshots of permission files, allowing the permission file of a certain version of the project to be quickly restored to the saved snapshot; status management can set the files of a certain version of the project to active or completed status. Permission files in the active status support viewing and editing, while permission files in the completed status only allow viewing. Permission files are saved in a format based on ABAC (Attribute-Based Access Control) to achieve more flexible and fine-grained permission control. The permission files contain rich attribute information, including user attributes, resource attributes, and environmental attributes, etc. User attributes can include information such as user roles, departments, positions, and working years; resource attributes can include resource types, affiliated projects, access frequencies, sensitivity levels, etc.; environmental attributes can include access times, access locations, network status, etc. Through the combination of these attribute information, complex and precise permission policies can be defined.
[0022] The permission management module is responsible for editing operations on the permission files of a certain version of a project. API (Application Programming Interface) - related operations include adding APIs, editing APIs, deleting APIs, and viewing APIs. Permission code - related operations include adding permission codes, editing permission codes, deleting permission codes, and viewing permission codes. Policy - related operations include adding policies, editing policies, deleting policies, and viewing policies. APIs are bound to permission codes, and according to the current attributes of the business platform, the permission codes that a user can access are dynamically calculated according to the set policies. Through a unified authentication component, it is determined whether the permission codes corresponding to the APIs requested by the user are allowed to be accessed.
[0023] The log management module records all operation logs related to permissions, including user login and logout records, permission change records, authentication request records, etc. The audit logs are stored in a structured manner, facilitating query and analysis. By analyzing the audit logs, potential security risks can be detected in a timely manner, such as abnormal permission changes, frequent authentication failures, etc., and corresponding measures can be taken for handling. At the same time, the audit logs also provide an important basis for compliance audits, meeting the enterprise's requirements for data security and compliance.
[0024] The policy engine module is the core module of the central permission management platform and is responsible for parsing and executing permission policy generation. After the business platform is installed and deployed, an encrypted activation code with the business platform's metadata information and current attribute information is sent to the central permission management platform to request permission initialization data. After the central permission management platform parses the activation code, it returns the permission data to the business platform. The business platform writes the original permission data into the permission database for the authentication SDK (Software Development Kit) to call. The permission files are stored in JSON format, which has good readability and scalability. Each permission policy exists in the file in the form of an independent object, containing fields such as the policy's ID, name, description, conditional expression, and corresponding permission operations. The conditional expression is a logic expression based on attributes, and it determines whether the permission conditions are met by judging user attributes, resource attributes, and environmental attributes. A permission policy may stipulate that only during working hours on weekdays (environmental attribute), "senior engineers" (user attribute) from the "R & D department" (user attribute) can perform modification operations (permission operation) on code files (resource attribute) in "Project A" (resource attribute). This ABAC-based permission file structure can quickly adjust and expand permission policies according to business changes and actual needs, improving the flexibility and adaptability of permission management. According to the metadata information and attribute information of the business platform, the permission files are automatically matched and parsed, and corresponding permission policies are dynamically generated according to the attribute information. Using efficient algorithms and data structures to ensure the speed and accuracy of policy parsing, enabling quick response to a large number of authentication requests. Support for dynamic update and expansion of policies, when business rules change, the permission policies can be adjusted in a timely manner without restarting the system.
[0025] The standardized software development kit module provides a set of standardized software development kits, facilitating the integration of unified authentication functions by various business platforms. The SDK provides simple and easy-to-use interfaces, and the business platform only needs to call the corresponding interfaces to implement user authentication and authorization operations. It supports multiple programming languages and development frameworks, such as Java, Python, etc., adapting to the technology selection of different business platforms. At the same time, the SDK has good compatibility and scalability, and can be easily integrated with the existing functional modules of the business platform. The real-time authentication interface module is responsible for processing users' authentication requests, communicating with the cache or the business platform database to obtain the latest authentication results. It adopts an efficient communication protocol and interface design to ensure the quick response and processing of authentication requests. It supports multiple authentication methods, such as token-based authentication, certificate-based authentication, etc., to meet the security requirements of different business scenarios. At the same time, the real-time authentication interface has good fault tolerance and stability, and can provide reliable authentication services in case of network anomalies or central service failures. The cache management module realizes the collaborative work of the local cache and the central service to improve the authentication efficiency. The cache management module is responsible for managing the life cycle of the local cache, including operations such as cache creation, update, and deletion. It adopts advanced cache algorithms and data structures to ensure the cache hit rate and data consistency. When a user makes an authentication request, it first queries the local cache. If there is a valid authentication result in the cache, it directly returns; if the authentication result does not exist in the cache or has expired, it sends a request to the business platform database and caches the latest authentication result locally for future use. Through cache management, the pressure on the central service is reduced, and the overall performance and response speed of the system are improved.
[0026] In some other embodiments of the present disclosure, the version control function of the project management module includes: saving project information and creating an original local repository when creating a project; editing project information and creating a new local repository to replace the original local repository when editing a project; deleting project information and deleting the original local repository when deleting a project; the project version management can view the information and permission files of each version of the project, and supports creating a snapshot of the permission file and quickly restoring the permission file of any version of the project to the saved snapshot, and the status management can set the files of any version of the project to the active and completed status. Among them, when creating a project, the initial information of the project is automatically saved, and an original local repository is created on the local server to store the initial version files of the project; when editing a project, the project information is updated, and a new local repository is created to replace the original original local repository, retaining the historical version records; when deleting a project, the project information and the original local repository corresponding to the project information are synchronously deleted; among them, the project version management supports viewing the project information and permission configuration files of each version, allowing users to create snapshots for the permission files, and being able to quickly restore the permission files of any historical version to the saved snapshot state when needed; the status management function allows users to set the project files of the specified version to the active state for use, or set them to the completed state to terminate subsequent modifications and operations.
[0027] In a specific embodiment of the present disclosure, the project management module is designed to efficiently and securely manage software development projects. When a user creates a new project, the system first automatically saves the initial information of the project, including basic information such as the project name, description, creation time, etc., and creates an original local repository for the project on the local server. This repository will store the initial version files of the project, ensuring a complete version control record from the very beginning of the project.
[0028] During the project progress, if there is a need to edit project information (such as updating the project description or modifying certain configurations), the system will perform the following steps: First, update the basic information of the project; Second, create a new local repository to replace the original one while retaining the historical version records to ensure that any historical state of the project can be traced back at any time. This mechanism not only supports the flexible adjustment of project information but also guarantees the security and integrity of the data.
[0029] For projects that no longer need to be maintained, the user can choose to delete the project. At this time, the system will perform two operations synchronously: one is to delete all relevant information of the project, and the other is to remove the original local repository corresponding to the project. This process ensures the effective management and cleaning of system resources, avoiding unnecessary space occupation.
[0030] In addition, the project version management function allows users to view the project information and permission configuration files of each version. Users can create snapshots for the permission files according to their needs. In this way, when it is found that there is a problem with the permission settings or it is necessary to roll back to a specific state at any time in the future, the permission files of any historical version can be quickly restored to the saved snapshot state. This greatly enhances the flexibility and security of the system.
[0031] Finally, the status management function enables users to set the project files of a specified version to the "activated" state for use, or set them to the "completed" state to terminate any subsequent modifications and operations. In this way, team members can clearly know which versions are currently in use and which versions have completed their life cycles.
[0032] This embodiment significantly improves the efficiency and security of project management by integrating an efficient version control system, meticulous permission management, and clear status identification. It not only makes the management of project information and files easier but also greatly reduces the risk of data loss caused by misoperations by providing a mechanism for quickly accessing and restoring historical versions. At the same time, the status management function helps the team better organize the work process, clarify the roles of each version, and further promotes the speed and quality of team collaboration and project progress. In summary, this embodiment provides a comprehensive, flexible, and powerful project management solution.
[0033] The permission files in the project management module are saved in the format of attribute - based access control. The permission files include: user attributes, resource attributes, and environmental attributes. User attributes include at least one of the following: the role, department, position, and working years of the user; resource attributes include at least one of the following: the type of resource, the project to which it belongs, the access frequency, and the sensitivity level; environmental attributes include at least one of the following: access time, access location, and network status.
[0034] In some other embodiments of the present disclosure, the editing operations of the permission management module include application - interface - related operations, permission - code - related operations, and policy - related operations. The application - interface - related operations are used for the configuration and update of the application interfaces. Among them, the application - interface - related operations support the modification of the interface address, request method, and parameter format, and automatically perform interface connectivity verification; the permission - code - related operations are used for the definition and assignment of permission codes. Among them, the permission - code - related operations include adding, deleting, or modifying permission identifiers and their corresponding operation scopes; the policy - related operations are used for the setting and adjustment of access control policies. Among them, the policy - related operations include the editing of role - based access control policy rules, and support the configuration of permission control logic and version association.
[0035] In some other embodiments of the present disclosure, the permission management module provides the ability to flexibly edit the system permission configuration. This module supports three main types of editing operations: application - programming - interface (API) - related operations, permission - code - related operations, and policy - related operations.
[0036] Among them, the application - interface - related operations are used for the configuration and update of the APIs involved in permission control in the system. Users can modify the address path, request method (such as GET, POST, PUT, DELETE, etc.), parameter format, and data - type definition of the specified API through a graphical interface or by calling the background interface. After each modification, the system will automatically execute an interface connectivity verification process to ensure that the updated interface can still be accessed normally and can correctly respond to authentication requests. This mechanism effectively prevents service unavailability problems caused by configuration errors.
[0037] The permission - code - related operations are used to achieve fine - grained management of permission identifiers. Administrators can add permission codes corresponding to new business operations, delete unused permission identifiers, or modify the operation scope and description information of existing permission codes. For example, for the "user management" module, multiple permission codes such as "user creation", "user deletion", "user viewing", etc. can be defined respectively, and their applicable objects and influence scopes can be precisely set. The system also supports the batch import and export of permission codes, which is convenient for the maintenance of large - scale permission systems.
[0038] Furthermore, the policy-related operations are used to set and adjust the access control policies of the system. Specifically, the system supports the Role-Based Access Control (RBAC) model, allowing administrators to assign permission codes to different roles and build complex permission control logics through a rule engine. For example, it can be set that the "department manager" role has read and write permissions for specific resources, while the "intern" role only has read-only permissions. At the same time, all policy configurations can be bound to project versions, enabling quick rollback and reuse of policy configurations when switching versions.
[0039] In addition, when the system executes the above various editing operations, it will automatically generate operation logs and record key information such as the operator, operation time, and changed content to support subsequent auditing and traceability.
[0040] In this embodiment, by dividing the permission management module into three major functional modules: API configuration, permission code management, and access policy editing, high flexibility and maintainability of permission control are achieved. The API automatic verification mechanism improves the security and stability of interface configuration; the structured management of permission codes enhances the ability to control permission granularity; and the associated design of policies and versions significantly improves the reuse efficiency and consistency of permission configuration under multi-version projects. Overall, this solution not only simplifies the complexity of permission management but also effectively improves system security, auditability, and operation and maintenance efficiency, providing a solid technical support for building a fine-grained and extensible permission management system.
[0041] In some other embodiments of the present disclosure, the policy engine module receives an encrypted activation code sent by the business platform with business platform metadata information and current attribute information, and after parsing the activation code, returns the permission data to the business platform.
[0042] In some other embodiments of the present disclosure, the policy engine module is configured as the core processing unit in the permission control system, for receiving the encrypted activation code from the business platform and performing permission parsing and return operations based on the activation code.
[0043] Specifically, when the business platform initiates a system activation, function enabling, or user authentication request, an encrypted activation code containing platform metadata information (such as platform identifier, device information, deployment environment, etc.) and current attribute information (such as user role, access time, geographical location, etc.) will be generated and sent to the policy engine module. Among them, the encrypted activation code is encapsulated using symmetric or asymmetric encryption algorithms to ensure the security of the transmission process.
[0044] After receiving the activation code, the policy engine module first calls the decryption module to decrypt it and extract the platform metadata and current attribute information. Subsequently, the policy engine evaluates and calculates the permission status of the target business platform based on the preset permission policy rules (for example, based on RBAC, ABAC and other models) and the extracted information, and generates the corresponding permission data set, including but not limited to the list of accessible resources, the types of operations allowed to be performed, the validity period of permissions, etc.
[0045] Finally, the policy engine module returns the generated permission data to the business platform in a structured format (such as JSON, XML, etc.) for subsequent permission verification, function opening, or access control decision-making. During the entire process, the system also records complete operation logs, including activation code sources, parsing results, returned data, etc., to support subsequent auditing and tracking.
[0046] Through the above implementation methods, the policy engine module realizes the intelligent analysis and issuance of dynamic permissions of the business platform, and improves the flexibility and security of permission management. The use of encrypted activation codes effectively ensures the tamper-proof and anti-leakage of permission data during transmission; and the combination of platform metadata and current attribute information for permission calculation makes permission control more refined and scenario-based, and can adapt to complex permission requirements in multi-tenant, cross-platform, and dynamic environments. In addition, the structured return of permission data and the complete logging mechanism also enhance the maintainability and auditability of the system, which helps to build an efficient, secure, and controllable permission management system.
[0047] In other embodiments of the present disclosure, when receiving an authentication request, the cache management module queries the local cache; when no valid authentication result is found, it requests authentication data from the service platform database and updates the local cache.
[0048] Specifically, when a user initiates a business operation request, the system triggers the authentication process, and the cache management module intervenes first. After receiving the authentication request, the module first queries the local cache based on the key fields such as user ID, role information, resource ID, etc. carried in the request to determine whether there is a valid authentication result record.
[0049] If a valid authentication result is found in the local cache (for example, the user has been verified to have access to a resource within the current time range), the cache management module directly returns the authentication result to the caller without initiating a query to the database, thereby significantly improving response efficiency and reducing network latency and database load.
[0050] If no valid authentication result is found in the local cache, the cache management module further sends an authentication data request to the business platform database to obtain the latest permission status information. After obtaining the authentication data returned by the database, the cache management module not only returns the authentication result to the caller, but also writes the result into the local cache so that subsequent identical or similar requests can directly hit the cache, achieving fast response.
[0051] To ensure the validity and security of the cached data, the cache management module also sets up a cache expiration mechanism and update policy, such as time-based TTL (Time To Live) control, event-driven active refresh mechanism, etc., to ensure that the authentication information in the cache is always consistent with the database or has a difference within an acceptable time window.
[0052] In addition, the cache management module supports a multi-level cache structure, including the cooperation of local memory cache and distributed cache, to adapt to the business requirements under different scales and deployment environments.
[0053] In terms of access control, it is proposed that multiple business platforms uniformly adopt an attribute-based access control policy and a unified authentication component, and the central permission management platform uniformly manages the access control permission files of each business. Developers of each business platform create, edit, view, and delete permission files based on the management module API provided by the central permission service device. The permission files are encrypted and stored to ensure the security and confidentiality of the permission data. When parsing the permission files, the permissions are dynamically parsed according to the real-time environmental information and user attribute information, improving the flexibility and adaptability of permission management.
[0054] This disclosure designs a project permission management model that supports version control. This model allows version control of the permission file management strategy and records the historical information of each permission change. When it is necessary to roll back to a specific permission state, it is convenient to switch to the corresponding version. During the project development process, the permissions may be adjusted and optimized multiple times. Through version control, it is possible to clearly understand the reasons and impacts of each permission change, facilitating the auditing and evaluation of permission management. At the same time, version control also provides convenience for the testing and verification of permission management. When testing a new permission policy, it can be tested first on a specific version to ensure its stability and security before applying it to the formal environment.
[0055] In terms of the authentication architecture, a real-time authentication architecture with cache collaboration is constructed to achieve a balance between performance and security. The unified authentication component supports the collaborative working mode of local cache and database. When a user makes an authentication request, the local cache is queried first. If a valid authentication result exists in the cache, it is directly returned, improving the speed and efficiency of authentication. If the authentication result does not exist in the cache or has expired, a request is sent to the database to ensure the real-time and accuracy of authentication. This architecture effectively improves the system performance while ensuring system security, and reduces the pressure on the database caused by authentication requests. In high-concurrency business scenarios, a large number of authentication requests can be quickly processed through the local cache, reducing the load on the central service and improving the overall response speed of the system.
[0056] The present disclosure proposes a dynamic permission initialization mechanism to dynamically adjust the permissions of the business platform. The central permission service device can dynamically generate and initialize permissions according to the business platform attributes and policy information. When the business rules of the business platform change or the platform attributes change, the system can adjust the permissions in real time to ensure the consistency of permissions with business requirements and the actual situation of users. When the business platform requests the central permission platform with different attributes, the platform can dynamically generate a permission file according to the current attributes and policies of the business platform, reducing the storage of permission data irrelevant to the current attributes of the business platform, improving the authentication efficiency and achieving more accurate access control.
[0057] The present disclosure realizes the centralized management of permissions for multiple business platforms through the central permission service device, avoiding the chaos and inconsistency problems brought by decentralized management, and improving the management efficiency and accuracy. Based on the dynamic update function of the ABAC-based permission management and policy engine, the permission policy can be quickly adjusted and extended according to business changes and actual needs to adapt to the dynamic development of enterprise business. The unified authentication component provides users with a convenient and efficient unified authentication service, reducing the trouble of multiple user identity verifications, and at the same time improving the security and reliability of authentication. The log management module records all operation logs related to permissions, and the structured storage method is convenient for querying and analysis, which helps to discover potential security risks in time and meet the enterprise compliance requirements. The cache management module realizes the collaborative working of the local cache and the central service, improves the authentication efficiency, reduces the pressure on the central service, and enhances the overall performance and response speed of the system.
[0058] Figure 2 It is a schematic flowchart of a permission management method provided for an exemplary embodiment of the present disclosure.
[0059] As Figure 2 shown, the method includes the following steps: Step 201, after the deployment of the business platform is completed, send an encrypted activation code carrying metadata information and current attribute information to the central permission service device.
[0060] Step 202: The central authority service device parses the encrypted activation code, matches the corresponding authority file, generates an authority policy, and returns the authority initialization data to the service platform.
[0061] Step 203: The service platform writes the authority initialization data into the local authority database for the authentication software development kit to call.
[0062] In this embodiment, the execution subject of the above method may be a server or a terminal device.
[0063] Among them, the terminal device includes, but is not limited to, a mobile station (MS), a mobile terminal, a mobile telephone, a handset, and portable equipment, etc. The terminal device can communicate with one or more core networks via a radio access network (RAN). For example, the terminal device can be a mobile telephone (or a "cellular" phone), a computer with wireless communication functions, etc. The terminal device can also be a computer with wireless transceiver functions, a virtual reality (VR) terminal device, an AR terminal device, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, a wireless terminal in a smart home, etc. And the operating systems installed on the terminal device include, but are not limited to: IOS, Android, windows, linux, Mac OS and other operating systems. In different networks, the terminal can be called different names. For example: user equipment, mobile station, user unit, station, cellular phone, personal digital assistant, wireless modem, wireless communication device, handheld device, laptop, cordless phone, wireless local loop station, TV, etc. For the convenience of description, it is simply referred to as the terminal device in this embodiment.
[0064] In this embodiment, the implementation form of the server is not limited. For example, the server can be a conventional server, a cloud server, a cloud host, a virtual center and other server devices. Among them, the composition of the server mainly includes a processor, a hard disk, a memory, a system bus, etc., and a general computer architecture type.
[0065] In this embodiment, the implementation manners of the steps of the above method can be referred to the descriptions of the corresponding parts of the foregoing embodiments, and will not be elaborated herein.
[0066] In some embodiments of the present disclosure, when a user initiates an authentication request, the authentication software development kit queries the local cache; if a valid authentication result is hit in the local cache, the authentication software development kit returns the authentication result to the service platform; if a valid authentication result is not hit in the local cache, the authentication software development kit requests to initiate an authentication data request to the service platform database, and updates the local cache after obtaining the authentication data; the central permission service device records all permission-related operation logs and stores them in a structured manner. Among them, the permission policy is constructed based on attribute-based access control, and a conditional expression is formed based on a combination of user attributes, resource attributes, and environmental attributes; according to the conditional expression, it is judged whether the user has the qualification to perform the target permission operation.
[0067] In some embodiments of the present disclosure, the authentication process is jointly completed by the authentication software development kit (SDK) and the central permission service device. Combining the local cache mechanism with the attribute-based access control (ABAC) model, efficient and fine-grained permission judgment and management are realized. When a user initiates a service operation request, the system first triggers the authentication process. At this time, the authentication SDK, as the front-end processing component, will first query the authentication result record in the local cache. This cache stores the recent permission judgment results of users, including information such as user identification, resource identification, operation type, and permission status, and has a reasonable time-to-live (TTL) to ensure the freshness of the data. If a valid authentication result is hit in the local cache, the authentication SDK directly returns the result to the service platform, quickly completing the permission verification, improving the response speed and reducing the dependence on the backend system. If a valid authentication result is not hit, the authentication SDK initiates an authentication data request to the service platform database. After receiving the request, the database forwards the relevant information to the central permission service device for permission judgment. The central permission service device, based on the ABAC model, comprehensively analyzes multi-dimensional information such as the attributes of the user (such as role, department, position), the attributes of the resource (such as resource type, affiliated project, sensitivity level), and the environmental attributes (such as access time, geographical location, device type), constructs a conditional expression to evaluate whether the current user has the permission to perform the target operation. For example, the conditional expression can be: "If the user belongs to the 'Finance Department', and the access time is from 9:00 to 18:00 on a working day, and the target resource is of the 'expense report' type, then the viewing operation is allowed." The central permission service device makes a logical judgment according to such rules, generates the final authentication result, and returns it to the authentication SDK.
[0068] After the authentication SDK obtains the result, on the one hand, it returns the result to the business platform for subsequent operations, and on the other hand, it updates the local cache so that the same or similar requests can be quickly responded to next time. At the same time, the central permission service device will also record the complete log of this permission-related operation, including information such as the operator, operation time, accessed resource, judgment basis, result output, etc., and store it persistently in a structured manner (such as JSON, XML, relational table structure) for subsequent auditing and tracking. In addition, the entire authentication process supports dynamic policy configuration and real-time effective mechanism. Administrators can flexibly adjust the permission rules through the graphical interface or API interface without restarting the service or affecting the operation of existing services.
[0069] In the above embodiment, when the permission policy changes, the central permission service device updates the permission file and synchronizes the updated permission file to each business platform through the standardized software development kit. When the permission policy changes, for example, adding or adjusting access control rules, modifying role permission relationships, etc., the central permission service device will generate an updated permission file according to the change content and replace the original configuration file. Subsequently, the device synchronizes the updated permission file to each business platform through the standardized software development kit (SDK). The SDK provides a unified interface and communication protocol to ensure that the permission change can take effect in all access systems in real time or near real time. At the same time, the synchronization process supports version control and rollback mechanisms to ensure the consistency and security of permission updates. This mechanism effectively improves the centralized management ability and distribution efficiency of permission policies, ensuring that the permission status under multiple business platforms is always synchronized and compliant.
[0070] Exemplarily, the business request is sent to the unified authentication component to parse the user information and request interface information, and calculate the set of permissions that the user can access according to the authentication policy based on the user information and environment information; if the set of accessible permissions contains the permission code that can access the API, the authentication is successful and the authentication success result is returned; if the set of accessible permissions does not contain the permission code that can access the API, the authentication fails and the authentication failure result is returned.
[0071] It should be noted that the embodiments of the present disclosure may include multiple steps. For the convenience of description, these steps are numbered, but these numbers are not intended to limit the execution time slots and execution orders between the steps; these steps can be implemented in any order, and the embodiments of the present disclosure do not make any limitations in this regard.
[0072] In summary, the embodiments of the present disclosure have the following beneficial effects: In some embodiments of the present disclosure, the central authority service device includes: a central platform layer and an authentication component layer; the central platform layer includes: a user management module, a user group management module, a project management module, a permission management module, a log management module, and a policy engine module; the user management module is used to manage the user information of the central authority management platform; the user group management module is used to manage the user group information of the central authority management platform; the project management module is used to centrally manage the metadata information and permission files of the project, and has a version control function; the permission management module is used to perform editing operations on the permission files, and identify the permission codes that the user can access through a unified authentication component; the log management module is used to record the operation logs related to permissions; the policy engine module is used to parse and execute the generation of permission policies; the authentication component layer includes: a standardized software development kit module, a real-time authentication interface module, and a cache management module; the standardized software development kit module is used to provide multiple programming language interfaces for the service platform to call the authentication function; the real-time authentication interface module is used to process the authentication requests of users; and the cache management module is used to manage the life cycle of the local cache; the present disclosure changes the decentralized management mode, realizes the centralization and systematization of permission management and authentication, thereby improving the permission management efficiency, improving the system security, and improving the operation and maintenance efficiency.
[0073] Exemplarily, Figure 3 FIG. 5 is a schematic structural diagram of a permission management device 30 provided for an exemplary embodiment of the present disclosure. As Figure 3 shown, the permission management device 30 includes: a sending module 31, a generating module 32, and a writing module 33.
[0074] Among them, the sending module 31 is used to send an encrypted activation code carrying metadata information and current attribute information to the central authority service device after the service platform is deployed; The generating module 32 is used for the central authority service device to parse the encrypted activation code, match the corresponding permission file, generate a permission policy, and return the permission initialization data to the service platform; The writing module 33 is used for the service platform to write the permission initialization data into the local permission database for the authentication software development kit to call.
[0075] Optionally, the writing module 33 can also be used to: when a user initiates an authentication request, the authentication software development kit queries the local cache; if a valid authentication result is hit in the local cache, the authentication software development kit returns the authentication result to the service platform; if a valid authentication result is not hit in the local cache, the authentication software development kit initiates an authentication data request to the service platform database, and updates the local cache after obtaining the authentication data; the central authority service device records all operation logs related to permissions and stores them in a structured manner.
[0076] Optionally, the writing module 33 can also be used for: constructing an attribute-based access control for permission policies, and forming a conditional expression based on a combination of user attributes, resource attributes, and environmental attributes; and determining whether a user is eligible to perform a target permission operation according to the conditional expression.
[0077] Optionally, the writing module 33 can also be used for: when the permission policy changes, the central permission service device updates the permission file and synchronizes the updated permission file to each business platform through a standardized software development kit.
[0078] Regarding the device in the above embodiments, the specific manners in which each module performs operations have been described in detail in the embodiments related to the method, and will not be elaborated herein.
[0079] According to an embodiment of the present disclosure, the present disclosure also provides an electronic device, a readable storage medium, and a computer program product.
[0080] Figure 4 A schematic block diagram of an exemplary electronic device 400 that can be used to implement the embodiments of the present disclosure is shown. The electronic device is intended to represent various forms of digital computers, such as, a laptop computer, a desktop computer, a workbench, a personal digital assistant, a server, a blade server, a mainframe computer, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, a personal digital processor, a cellular phone, a smart phone, a wearable device, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely exemplary and are not intended to limit the implementation of the present disclosure described and / or claimed herein.
[0081] As Figure 4 shown, the device 400 includes a computing unit 401, which can execute various appropriate actions and processes according to a computer program stored in a ROM (Read-Only Memory) 402 or a computer program loaded from a storage unit 408 into a RAM (Random Access Memory) 403. In the RAM 403, various programs and data required for the operation of the device 400 can also be stored. The computing unit 401, the ROM 402, and the RAM 403 are connected to each other through a bus 404. An I / O (Input / Output) interface 405 is also connected to the bus 404.
[0082] Multiple components in device 400 are connected to I / O interface 405, including: an input unit 406, such as a keyboard, a mouse, etc.; an output unit 407, such as various types of displays, speakers, etc.; a storage unit 408, such as a disk, an optical disc, etc.; and a communication unit 409, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 409 allows device 400 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0083] The computing unit 401 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 401 include but are not limited to a CPU (Central Processing Unit), a GPU (Graphic Processing Units), various dedicated AI (Artificial Intelligence) computing chips, various computing units running machine learning model algorithms, a DSP (Digital Signal Processor), and any suitable processor, controller, microcontroller, etc. The computing unit 401 executes the various methods and processes described above, such as the permission management method. For example, in some embodiments, the permission management method can be implemented as a computer software program that is tangibly contained in a machine-readable medium, such as the storage unit 408. In some embodiments, part or all of the computer program can be loaded and / or installed onto device 400 via the ROM 402 and / or the communication unit 409. When the computer program is loaded into the RAM 403 and executed by the computing unit 401, one or more steps of the method described above can be executed. Alternatively, in other embodiments, the computing unit 401 can be configured to execute the aforementioned permission management method in any other suitable manner (e.g., by means of firmware).
[0084] The various embodiments of the systems and techniques described above in this specification can be implemented in digital electronic circuitry, integrated circuit systems, FPGAs (Field Programmable Gate Arrays), ASICs (Application-Specific Integrated Circuits), ASSPs (Application Specific Standard Products), SOCs (System On Chip), CPLDs (Complex Programmable Logic Devices), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which may be a special-purpose or general-purpose programmable processor that can receive data and instructions from, and transmit data and instructions to, a storage system, at least one input device, and at least one output device.
[0085] The program code for implementing the methods of the present disclosure can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that the program codes, when executed by the processor or controller, cause the functions / operations specified in the flowchart and / or block diagram to be implemented. The program code can be executed entirely on the machine, partly on the machine, as a stand-alone software package partly on the machine and partly on a remote machine, or entirely on a remote machine or server.
[0086] In the context of this disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a RAM, a ROM, an EPROM (Electrically Programmable Read-Only Memory), or a flash memory, an optical fiber, a CD-ROM (Compact Disc Read-Only Memory), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0087] To provide for interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (Cathode-Ray Tube) or LCD (Liquid Crystal Display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the computer. Other kinds of devices can also be used to provide for interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, speech input, or tactile input).
[0088] The systems and techniques described herein can be implemented in a computing system that includes backend components (such as, for example, a data server), or a computing system that includes middleware components (such as, for example, an application server), or a computing system that includes frontend components (such as, for example, a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected by any form or medium of digital data communication (such as, for example, a communication network). Examples of a communication network include: a LAN (Local Area Network), a WAN (Wide Area Network), the Internet, and a blockchain network.
[0089] A computer system may include a client and a server. The client and the server are generally far from each other and usually interact through a communication network. The relationship between the client and the server is generated by computer programs running on the respective computers and having a client-server relationship with each other. The server may be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system, and solves the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services ("Virtual Private Server", or simply "VPS"). The server may also be a server of a distributed system or a server combined with a blockchain.
[0090] It should be noted that artificial intelligence is a discipline that studies how to make a computer simulate certain thinking processes and intelligent behaviors of humans (such as learning, reasoning, thinking, planning, etc.), and it has both hardware-level technologies and software-level technologies. Artificial intelligence hardware technologies generally include technologies such as sensors, dedicated artificial intelligence chips, cloud computing, distributed storage, and big data processing; artificial intelligence software technologies mainly include several major directions such as computer vision technology, speech recognition technology, natural language processing technology, and machine learning / deep learning, big data processing technology, and knowledge graph technology.
[0091] The various digital numbers such as the first, second, etc. involved in this disclosure are only for the convenience of description and do not limit the scope of the embodiments of this disclosure, nor do they represent the order of precedence.
[0092] At least one in this disclosure can also be described as one or more. The more can be two, three, four, or more, and this disclosure does not make any restrictions. In the embodiments of this disclosure, for a technical feature, the technical features in this technical feature are distinguished by "the first", "the second", "the third", "A", "B", "C", and "D", etc. There is no order of precedence or size order among the technical features described by "the first", "the second", "the third", "A", "B", "C", and "D".
[0093] It should be understood that various forms of processes shown above can be used, and steps can be reordered, added, or deleted. For example, the steps recorded in this disclosure can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions disclosed in this disclosure can be achieved, and no limitations are made herein.
[0094] The above specific embodiments do not constitute a limitation on the protection scope of the present disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions and improvements made within the spirit and principle of the present disclosure shall be included within the protection scope of the present disclosure.
Claims
1. A central authority service device, characterized in that, Including: A central platform layer and an authentication component layer; The central platform layer includes: a user management module, a user group management module, a project management module, a permission management module, a log management module, and a policy engine module; the user management module is used to manage the user information of the central permission management platform; the user group management module is used to manage the user group information of the central permission management platform; the project management module is used to centrally manage the metadata information and permission files of the project, and has a version control function; the permission management module is used to perform editing operations on the permission files and identify the permission codes that users can access through a unified authentication component; the log management module is used to record the operation logs related to permissions; the policy engine module is used to parse and execute the generation of permission policies; The authentication component layer includes: a standardized software development kit module, a real-time authentication interface module, and a cache management module; the standardized software development kit module is used to provide multiple programming language interfaces for the business platform to call the authentication function; the real-time authentication interface module is used to process the authentication requests of users; and the cache management module is used to manage the life cycle of the local cache.
2. The device according to claim 1, characterized in that, The version control function of the project management module is used for: When creating a project, automatically save the initial information of the project and create an original local repository on the local server to store the initial version file of the project; When editing a project, update the project information and create a new local repository to replace the original local repository, retaining the historical version records; When deleting a project, synchronously delete the project information and the original local repository corresponding to the project information; Among them, project version management supports viewing the project information and permission configuration files of each version, allowing users to create snapshots for the permission files, and being able to quickly restore the permission files of any historical version to the saved snapshot state when needed; the status management function allows users to set the project files of a specified version to the active state for use, or set them to the completed state to terminate subsequent modifications and operations.
3. The device according to claim 1, wherein, The project management module is also used for: The permission files in the project management module are saved in the format of attribute-based access control, and the permission files include: user attributes, resource attributes, and environmental attributes.
4. The device according to claim 3, characterized in that, The user attributes include at least one of the following: the role, department, position, and working years of the user; the resource attributes include at least one of the following: the type of the resource, the project to which it belongs, the access frequency, and the sensitivity level; the environmental attributes include at least one of the following: the access time, the access location, and the network status.
5. The device according to claim 1, characterized in that, The permission management module is also used for: The editing operations include: application programming interface-related operations, permission code-related operations, and policy-related operations; The application programming interface-related operations are used for the configuration and update of the application programming interface. Among them, the application programming interface-related operations support the modification of the interface address, request method, and parameter format, and automatically perform interface connectivity verification; The operations related to the permission code are used for the definition and allocation of the permission code. Among them, the operations related to the permission code include adding, deleting, or modifying the permission identifier and its corresponding operation scope; The operations related to the policy are used for the setting and adjustment of the access control policy. Among them, the operations related to the policy include the editing of the role-based access control policy rules, and support the configuration and version association of the permission control logic.
6. The device according to claim 1, characterized in that The policy engine module is further used for: Receiving the encrypted activation code sent by the service platform with the service platform metadata information and the current attribute information, and returning the permission data to the service platform after parsing the activation code.
7. The device according to claim 1, characterized in that, The cache management module is further used for: Querying the local cache when receiving the authentication request; If a valid authentication result is not hit in the local cache, then requesting authentication data from the service platform database and updating the local cache.
8. A permission management method, characterized in that, including: After the service platform is deployed, sending the encrypted activation code carrying the metadata information and the current attribute information to the central permission service device; The central permission service device parses the encrypted activation code, matches the corresponding permission file, generates a permission policy, and returns the permission initialization data to the service platform; The service platform writes the permission initialization data into the local permission database for the authentication software development kit to call.
9. The method according to claim 8, wherein The method further includes: When the user initiates an authentication request, the authentication software development kit queries the local cache; If a valid authentication result is hit in the local cache, then the authentication software development kit returns the authentication result to the service platform; If a valid authentication result is not hit in the local cache, then the authentication software development kit initiates an authentication data request to the service platform database, and updates the local cache after obtaining the authentication data; The central permission service device records all permission-related operation logs and stores the permission-related operation logs in a structured manner.
10. The method according to claim 8, characterized in that The method further includes: The permission policy is constructed based on attribute-based access control, and a conditional expression is formed based on the combination of user attributes, resource attributes, and environmental attributes; According to the conditional expression, it is judged whether the user has the qualification to execute the target permission operation.
11. The method according to claim 8, wherein The method further includes: When the permission policy changes, the central permission service device updates the permission file and synchronizes the updated permission file to each service platform through the standardized software development kit.
12. A permission management device, characterized in that, including: A sending module, used for sending the encrypted activation code carrying the metadata information and the current attribute information to the central permission service device after the service platform is deployed; A generating module, used for the central permission service device to parse the encrypted activation code, match the corresponding permission file, generate a permission policy, and return the permission initialization data to the service platform; A writing module, used for the service platform to write the permission initialization data into the local permission database for the authentication software development kit to call.
13. An electronic device, characterized in that including: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the method according to any one of claims 8-11.
14. A non-transitory computer-readable storage medium storing computer instructions, characterized in that the computer instructions are used to cause the computer to execute the method according to any one of claims 8-11.
15. A computer program product, comprising computer programs / instructions, characterized in that, When the computer program / instructions are executed by a processor, the steps in the method according to any one of claims 8-11 are implemented.
Citation Information
Patent Citations
Authority management method, device and system, server and medium
CN111767524A
Permission management method and device and storage medium
CN112100585A
Authority control method and device, equipment and storage medium
CN113239377A
Application permission management method and device, computer equipment and storage medium
CN114282195A
Access system, method, device and equipment of computing power network operating system and medium
CN116319096A