Access authority management method and device of service system, electronic equipment and storage medium

Through the multi-level permission authentication method, combined with multi-dimensional and dynamic permission authentication, the network security risks of a single authentication method in business system access control are solved, and authentication accuracy and system security are improved.

CN120455156AActive Publication Date: 2025-08-08CHINA INT DATA SYST CO LTD
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
CN202510833302.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-20
Publication Date
2025-08-08
Estimated Expiration
2045-06-20

AI Technical Summary

Technical Problem

In the access control scenario of the business system in the prior art, the permission authentication method is single, and there is a network security risk.

Method used

A multi-level permission authentication method is adopted, including first-level multi-dimensional authentication and second-level dynamic permission authentication. By obtaining authentication information of user dimensions, resource dimensions, environment dimensions and business status dimensions, and combining time authorization, spatial authorization, behavior authorization and business status information, the target permission information of the access request is determined.

Benefits of technology

It improves the authentication accuracy of access requests and the network security of the business system, and enhances the effectiveness of multi-level permission management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120455156A_ABST
    Figure CN120455156A_ABST
Patent Text Reader

Abstract

The invention provides an access authority management method and device of a service system, electronic equipment and a storage medium. The method comprises the following steps: receiving an access request of a client to a service system, and obtaining multi-dimensional authentication information corresponding to the access request; performing first-level authority authentication on the access request based on the multi-dimensional authentication information to obtain first authority information corresponding to the access request; obtaining at least one item of time authorization information, space authorization information, behavior authorization information and service state information corresponding to the client, and performing second-level authority authentication on the access request to obtain second authority information corresponding to the access request; and determining target permission information corresponding to the access request based on the first permission information and the second permission information, and responding to the access request based on the target permission information. Through authority authentication of two levels, the access security of the service system is improved, and the network security of the service system is further improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of network security technology, and in particular to a method, device, electronic device, and storage medium for managing access rights of a business system. Background Art

[0002] With the continuous development of computer technology and network technology, online business has also flourished, and the resulting security issues have become increasingly severe.

[0003] In the process of implementing the present disclosure, it was found that there are at least the following technical problems in the prior art: in the access control scenario of the business system, the permission authentication method for access requests is single, which poses a network security risk. Summary of the Invention

[0004] The present disclosure provides a method, device, electronic device, and storage medium for managing access rights of a business system, so as to improve the network security of the business system.

[0005] According to one aspect of the present disclosure, a method for managing access rights of a business system is provided, comprising:

[0006] Receive a client's access request to the business system, and obtain multi-dimensional authentication information corresponding to the access request, wherein the multi-dimensional authentication information includes authentication information corresponding to at least one dimension of a user dimension, a resource dimension, an environment dimension, and a business status dimension;

[0007] Performing a first-level permission authentication on the access request based on the multi-dimensional authentication information to obtain first permission information corresponding to the access request;

[0008] Obtain at least one of the time authorization information, space authorization information, behavior authorization information, and service status information corresponding to the client to perform second-level authority authentication on the access request, and obtain second authority information corresponding to the access request;

[0009] The target permission information corresponding to the access request is determined based on the first permission information and the second permission information, and the access request is responded to based on the target permission information.

[0010] Optionally, the first permission information includes allow and deny; the second permission information includes allow and deny; when either the first permission information or the second permission information is deny, the target permission information is deny; when both the first permission information and the second permission information are allow, the target permission information is allow;

[0011] The step of obtaining at least one of the time authorization information, space authorization information, and behavior authorization information corresponding to the client to perform second-level permission authentication on the access request to obtain second permission information corresponding to the access request includes:

[0012] Perform at least one of the following information matches, and when any matching result is a mismatch, the second permission information is denied, and when all matching results are matches, the second permission information is allowed:

[0013] Match the access time of the access request with the time authorization information corresponding to the client to obtain a time matching result; match the location information corresponding to the access request with the space authorization information corresponding to the client to obtain a space matching result; match the access operation corresponding to the access request with the behavior authorization information corresponding to the client to obtain a behavior matching result; match the current business status of the business system with the accessible status information of the business system to obtain a business status matching result.

[0014] Optionally, the first permission information is a basic permission value, and the second permission information is an adjusted permission value; the target permission information is a target permission value; and the target permission value is determined based on the basic permission value and the adjusted permission value;

[0015] Wherein, responding to the access request based on the target permission information includes: determining the data access scope and operation access scope corresponding to the client according to the target permission value; and responding to the access request according to the data access scope and operation access scope.

[0016] Optionally, the data access scope and the operation access scope are respectively positively correlated with the target authority value; the confidentiality level of business data in the data access scope is positively correlated with the target authority value; and the sensitivity of operation behavior within the operation access scope is positively correlated with the target authority value.

[0017] Optionally, the method for determining the basic authority value includes: mapping the multi-dimensional authentication information into an authentication value based on a mapping relationship between multi-dimensional authentication information and a value; and fusing the authentication values corresponding to the multi-dimensional authentication information based on a fusion authentication calculation model of the multi-dimensional authentication information to obtain the basic authority value.

[0018] Optionally, the adjustment authority value is determined based on at least one of the following: processing the access time of the access request and the time authorization information corresponding to the client based on the time adjustment function to obtain a first adjustment authority value; processing the location information corresponding to the access request and the space authorization information corresponding to the client based on the space adjustment function to obtain a second adjustment authority value; processing the historical operation behavior of the client and the behavior authorization information corresponding to the client based on the behavior adjustment function to obtain a third adjustment authority value; processing the business status of the business system based on the business status adjustment function to obtain a fourth adjustment authority value.

[0019] Optionally, the response to the access request includes at least one of the following: executing the access request and feeding back a request result corresponding to the access request; rejecting the access request; and providing secondary permission verification for the client.

[0020] According to another aspect of the present disclosure, there is provided an access rights management device for a business system, comprising:

[0021] Request receiving module, receiving client's access request to the business system;

[0022] an information acquisition module, configured to acquire multi-dimensional authentication information corresponding to the access request, the multi-dimensional authentication information including authentication information corresponding to at least one of a user dimension, a resource dimension, an environment dimension, and a business status dimension;

[0023] a first permission information determination module, configured to perform a first level permission authentication on the access request based on the multi-dimensional authentication information, and obtain first permission information corresponding to the access request;

[0024] A second permission information determination module is configured to obtain at least one of the time authorization information, space authorization information, behavior authorization information, and service status information corresponding to the client, perform a second-level permission authentication on the access request, and obtain second permission information corresponding to the access request;

[0025] An access request response module is configured to determine target permission information corresponding to the access request based on the first permission information and the second permission information, and respond to the access request based on the target permission information.

[0026] According to another aspect of the present disclosure, an electronic device is provided, comprising:

[0027] at least one processor; and

[0028] a memory communicatively connected to the at least one processor; wherein,

[0029] The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the access permission management method of the business system described in any embodiment of the present disclosure.

[0030] According to another aspect of the present disclosure, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the access permission management method of the business system described in any embodiment of the present disclosure when executed.

[0031] The technical solution of the embodiment of the present disclosure performs two-level permission authentication processing by obtaining access requests, and determines the target permission information corresponding to the access request based on the permission information obtained from the two-level permission authentication, thereby improving multi-level permission management. Specifically, in the first-level permission authentication process, by obtaining multi-dimensional authentication information, the comprehensiveness and diversity of the authentication information are improved, and the accuracy of the permission authentication is improved. In the second-level permission authentication process, dynamic permission management is performed on the access request through at least one of time authorization information, space authorization information, behavior authorization information and business status information, thereby improving the authentication accuracy of dynamic permissions. Through two-level permission authentication, the access security of the business system is improved, and the network security of the business system is further improved.

[0032] It should be understood that the contents described in this section are not intended to identify the key or important features of the embodiments of the present disclosure, nor are they intended to limit the scope of the present disclosure. Other features of the present disclosure will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present disclosure. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0034] Figure 1 This is a flow chart of a method for managing access rights of a business system provided by an embodiment of the present disclosure;

[0035] Figure 2 This is a flow chart of a method for managing access rights of a business system provided by an embodiment of the present disclosure;

[0036] Figure 3 This is a schematic diagram of the structure of an access rights management device for a business system provided by an embodiment of the present disclosure;

[0037] Figure 4It is a structural diagram of an electronic device provided by an embodiment of the present disclosure. DETAILED DESCRIPTION

[0038] In order to enable those skilled in the art to better understand the solutions of the present disclosure, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below in conjunction with the drawings in the embodiments of the present disclosure. Obviously, the embodiments described are only part of the embodiments of the present disclosure, not all of the embodiments. Based on the embodiments of the present disclosure, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present disclosure.

[0039] It should be noted that the terms "first", "second", etc. in the specification and claims of the present disclosure and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present disclosure described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0040] The acquisition, storage and / or processing of data in the technical solutions involved in this application comply with the relevant provisions of national laws and regulations. It should be noted that in the embodiments of this application, certain software, components, models and other existing solutions in the industry may be mentioned, which should be considered as exemplary. Their purpose is only to illustrate the feasibility of implementing the technical solutions of this application, but does not mean that the applicant has or will necessarily use such solutions.

[0041] A business system can be understood as a system of business activities and services carried out through an Internet platform, which may include information exchange, service provision and commercial transactions through the network. Exemplarily, a business system may be an online business system, and the online business performed by the online business system may include but is not limited to online transaction business based on an e-commerce platform, online financial business, online multimedia content service business, online sharing business, online social business, online medical business and online government affairs business, etc. A business system can also be an enterprise business system for executing internal enterprise business. The client can interact with the business system by sending an access request to the business system. In order to improve the network security of the business system, the embodiment of the present disclosure provides a method for managing access rights of a business system, which performs permission management on access requests sent by the client. See Figure 1 , Figure 1This is a flowchart of a method for access rights management of a business system provided by an embodiment of the present disclosure. This embodiment is applicable to the case where multi-level access rights management is performed on access requests initiated by a client to a business system. This method can be executed by an access rights management device of the business system. The access rights management device of the business system can be implemented in the form of hardware and / or software. The access rights management device of the business system can be configured in a computer device or server. Figure 1 As shown, the method includes:

[0042] S110. Receive a client's access request to a business system, and obtain multi-dimensional authentication information corresponding to the access request, where the multi-dimensional authentication information includes authentication information corresponding to at least one of a user dimension, a resource dimension, an environment dimension, and a business status dimension.

[0043] S120: Perform first-level permission authentication on the access request based on the multi-dimensional authentication information to obtain first permission information corresponding to the access request.

[0044] S130: Obtain at least one of the time authorization information, space authorization information, behavior authorization information, and business status information corresponding to the client to perform second-level authority authentication on the access request, and obtain second authority information corresponding to the access request.

[0045] S140: Determine target permission information corresponding to the access request based on the first permission information and the second permission information, and respond to the access request based on the target permission information.

[0046] In this embodiment, the client sends an access request to the business system based on operational requirements. Different business systems may correspond to different types of access requests, which may include but are not limited to data operation requests, functional operation requests, and system control requests. For example, data operation requests may include but are not limited to data read requests, data write requests, data modification requests, data deletion requests, and data export requests. Functional operation requests may include but are not limited to UI function requests, API call requests, and batch task processing requests. System control requests may include but are not limited to infrastructure management requests, permission management requests, and log access requests. The specific types of access requests are not limited here.

[0047] By obtaining multi-dimensional authentication information corresponding to the access request, the access request is authenticated in a multi-dimensional manner, wherein the dimensions of the authentication information include at least one of the user dimension, resource dimension, environment dimension, and business status dimension. The authentication information in the user dimension can be understood as static attribute information and dynamic attribute information representing the access subject, wherein the static attribute information in the user dimension authentication information includes but is not limited to identity, department / rank, and security level; the dynamic attribute information in the user dimension authentication information includes but is not limited to login frequency within a historical time period, number of historical violations, number of current active sessions, behavior credibility score, etc. The authentication information in the resource dimension can be understood as the sensitivity and business characteristics of the accessed object, which can include but is not limited to resource type (for example, a database table, API endpoint, or file, etc.), data sensitivity level (for example, public, internal, and confidential, etc.), business-critical data (for example, a value between 0 and 1), business domain, and last modified timestamp, etc. The authentication information of the environmental dimension can be understood as the contextual environment information that characterizes the access. For example, it may include but is not limited to time characteristics, space characteristics, device characteristics and environmental anomaly characteristics, among which time characteristics may include, for example, holidays / working hours, or the time interval since the last access, etc., space characteristics may include physical space characteristics (such as geographic location information) and network space information (such as intranet, 4G or VPN, etc.), device characteristics may include device type and device security status, and environmental anomaly characteristics may include network attack warning information, etc. The authentication information of environmental anomaly characteristics can be understood as the current operating status information of the business system, for example, it may include but is not limited to the business cycle stage, system load status, process approval status and risk event markers, etc. It can be understood that the information content and quantity of authentication information of each dimension may be different in different business systems, and can be determined according to the permission management requirements of the business system.

[0048] In some embodiments of the present disclosure, permission verification rules are pre-set, and the permission verification rules may include verification sub-rules corresponding to the user dimension, resource dimension, environment dimension, and business status dimension, respectively. The authentication information of the corresponding dimension is verified by the verification sub-rules corresponding to each dimension. The first permission information includes permission and rejection. When the authentication information of each dimension is successfully verified, the first permission information is determined to be permission. When the authentication information of at least one dimension fails to be verified, the first permission information is determined to be rejection.

[0049] In some embodiments of the present disclosure, a hybrid permission control model is pre-constructed. The hybrid permission control model can be constructed by role-based access control (RBAC) and attribute-based access control (ABAC). The above-mentioned multi-dimensional authentication information can be authenticated through the hybrid permission control model to obtain the first permission information.

[0050] After performing first-level permission authentication on the access request through multi-dimensional authentication information to obtain first permission information, dynamic permission authentication, i.e., second-level permission authentication, is performed on the access request through at least one of the client's corresponding time authorization information, space authorization information, behavior authorization information, and business status information to obtain second permission information. The target permission information is jointly determined by the first permission information and the second permission information to implement multi-level permission management of access requests, thereby improving the accuracy of permission management and the security of the business system.

[0051] For different business systems, or different business types corresponding to access requests, the information required for the second-level authority authentication is determined in the time authorization information, space authorization information, behavior authorization information and business status information corresponding to the client, and the second-level authority authentication is performed based on the information required for the second-level authority authentication, wherein the information required for the second-level authority authentication can be at least one of the time authorization information, space authorization information, behavior authorization information and business status information corresponding to the client.

[0052] Optionally, at least one of the following information matches is performed, and when any matching result is a mismatch, the second permission information is rejected, and when all matching results are matches, the second permission information is allowed: matching the access time of the access request with the time authorization information corresponding to the client to obtain a time matching result; matching the location information corresponding to the access request with the space authorization information corresponding to the client to obtain a space matching result; matching the access operation corresponding to the access request with the behavior authorization information corresponding to the client to obtain a behavior matching result; matching the current business status of the business system with the accessible status information of the business system to obtain a business status matching result.

[0053] The time authorization information corresponding to the client can be understood as the time range in which the client has access rights. The time authorization information can be set or adjusted as needed. For example, the time authorization information of a temporary client can be (t1, t2), where t1 can be the starting time of the permission and t2 can be the ending time of the permission. For example, when the user is on vacation, the time authorization information of the user client can be (-, t3)(t4, -), indicating that t3 can be the ending time of the permission and t4 is the time when the permission is restarted. For example, the time authorization information (-, -) of the user client indicates that the client's permission in the time dimension is not restricted.

[0054] The access time of the access request is matched with the time authorization information corresponding to the client. If the access time of the access request is within the time authorization information corresponding to the client, the matching result is determined to be a match. If the access time of the access request is outside the time authorization information corresponding to the client, the matching result is determined to be a mismatch.

[0055] The client's spatial authorization information can be understood as the spatial scope to which the client has access rights, and the spatial authorization information can be set or adjusted as needed. Exemplarily, the client's spatial authorization information is the working scope of the client user, for example, it can be the working scope of the enterprise to which the client user belongs. The access request sent by the client carries the client's location information, that is, the location information corresponding to the access request. The location information corresponding to the access request is matched with the client's spatial authorization information. If the location information corresponding to the access request is within the working scope corresponding to the spatial authorization information, the matching result is determined to be a match. If the location information corresponding to the access request is outside the working scope corresponding to the spatial authorization information, the matching result is determined to be a mismatch.

[0056] The client's corresponding behavior authorization information can be understood as a set of operational behaviors for which the client has access rights. Different clients may correspond to different sets of operational behaviors, and the operational behaviors included in the set may include, but are not limited to, at least one of the following: query, modify, upload, download, and delete. The access operation corresponding to the access request is matched against the set of operational behaviors for which the client has access rights. If the access operation corresponding to the access request is within the set of operational behaviors for which the client has access rights, the match result is determined to be a match; if the access operation corresponding to the access request is not within the set of operational behaviors for which the client has access rights, the match result is determined to be a mismatch.

[0057] The business status information corresponding to the client can be understood as the business status of the business system opening access rights to the client. Exemplarily, the business status information may include "under development", "updating", "applying", etc., wherein in the "under development" and "updating" states, the business system does not open access rights to the client, and in the "applying" state, the business system opens access rights to the client. Determine the current business status of the business system when the access request is sent. If the current business status of the business system is the "applying" state, then the matching result is determined to be a match; if the current business status of the business system is the "under development" or "updating" state, then the matching result is determined to be a mismatch. It is understandable that the status information of different business systems may be different and can be set according to the needs of the business system.

[0058] In some embodiments of the present disclosure, the first right information and the second permission information include permission and rejection, respectively; when either the first permission information or the second permission information is rejection, the target permission information is rejection; when both the first permission information and the second permission information are permission, the target permission information is permission.

[0059] In some embodiments of the present disclosure, if the first permission information is allow, S130 is continued to be executed. If the second permission information is allow, the target permission information is determined to be allow. If the second permission information is deny, the target permission information is determined to be deny. If the first permission information is deny, step S130 is not required and the target permission information is determined to be deny.

[0060] When the target permission information is allowed, the response method to the access request is: execute the access request and feedback the request result corresponding to the access request; when the target permission information is denied, the response method to the access request is: deny the access request.

[0061] The technical solution of this embodiment performs two-level permission authentication processing by obtaining access requests, and determines the target permission information corresponding to the access request based on the permission information obtained from the two-level permission authentication, thereby improving multi-level permission management. Specifically, in the first-level permission authentication process, by obtaining multi-dimensional authentication information, the comprehensiveness and diversity of the authentication information are improved, and the accuracy of the permission authentication is improved. In the second-level permission authentication process, dynamic permission management is performed on the access request through at least one of time authorization information, space authorization information, behavior authorization information, and business status information, thereby improving the authentication accuracy of dynamic permissions. Through two-level permission authentication, the access security of the business system is improved, and the network security of the business system is further improved.

[0062] Figure 2This is a flowchart of a method for managing access rights of a business system provided by an embodiment of the present disclosure. Based on the above embodiment, another method for determining target permission information is provided. Figure 2 As shown, the method includes:

[0063] S210. Receive a client's access request to the business system, and obtain multi-dimensional authentication information corresponding to the access request, where the multi-dimensional authentication information includes authentication information corresponding to at least one of a user dimension, a resource dimension, an environment dimension, and a business status dimension.

[0064] S220: Perform first-level authority authentication on the access request based on the multi-dimensional authentication information to obtain a basic authority value corresponding to the access request.

[0065] S230. Obtain at least one of the time authorization information, space authorization information, behavior authorization information, and business status information corresponding to the client to perform a second-level authority authentication on the access request, and obtain an adjustment authority value corresponding to the access request.

[0066] S240. Determine a target authority value corresponding to the access request based on the basic authority value and the adjusted authority value, and respond to the access request based on the target authority value.

[0067] In the embodiment of the present disclosure, the first permission information, the second permission information and the target permission information are in numerical form, and the size of the numerical value represents the size of the permission. The larger the numerical value, the greater the access permission corresponding to the access request.

[0068] Optionally, the method for determining the basic authority value includes: mapping the multi-dimensional authentication information into an authentication value based on the mapping relationship between the multi-dimensional authentication information and the value; and fusing the authentication values corresponding to the multi-dimensional authentication information based on a fusion authentication calculation model of the multi-dimensional authentication information to obtain the basic authority value.

[0069] A mapping relationship between the information content and the numerical value of each authentication information item in the multi-dimensional authentication information is pre-set. That is, different information contents of the same authentication information item can correspond to different numerical values. For each information content in the multi-dimensional authentication information corresponding to the access request, the corresponding authentication numerical value is determined in the above mapping relationship, and the authentication numerical values corresponding to the multiple authentication information in the multi-dimensional authentication information are obtained. The authentication numerical values corresponding to the multiple authentication information in the multi-dimensional authentication information are input into the fusion authentication calculation model of the multi-dimensional authentication information for calculation to obtain the basic permission value. The fusion authentication calculation model of the multi-dimensional authentication information can, for example, be a weighted calculation model for the authentication numerical values corresponding to the multi-dimensional authentication information.

[0070] For example, the calculation method of the basic authority value can be expressed by the following formula:

[0071] P base =w1·U+w2·R+w3·E+w4·B

[0072] Among them, U represents the authentication data vector corresponding to the authentication information of the user dimension, U=(U1, U2…U n ); R represents the authentication data vector corresponding to the authentication information of the resource dimension, R=(R1, R2…U n ); E represents the authentication data vector corresponding to the authentication information of the environment dimension, E=(E1, E2…E n ); B represents the authentication data vector corresponding to the authentication information of the business status dimension, B=(B1, B2…B n ). w1, w2, w3 and w4 are the weights corresponding to the user dimension, resource dimension, environment dimension and business status dimension respectively.

[0073] Optionally, the adjustment authority value is determined based on at least one of the following:

[0074] Processing the access time of the access request and the time authorization information corresponding to the client based on a time adjustment function to obtain a first adjustment authority value;

[0075] Processing the location information corresponding to the access request and the space authorization information corresponding to the client based on a space adjustment function to obtain a second adjustment authority value;

[0076] Processing the historical operation behavior of the client and the behavior authorization information corresponding to the client based on the behavior adjustment function to obtain a third adjustment authority value;

[0077] The business status of the business system is processed based on the business status adjustment function to obtain a fourth adjustment authority value.

[0078] Optionally, the time adjustment function can be expressed by the following formula: Where λ1 is the time decay coefficient, t0 is the time length corresponding to the time authorization information, and t is the authorized time length corresponding to the access time of the access request. According to the time adjustment function, within the authorization time, the first adjustment authority value gradually decays with time.

[0079] Optionally, the time adjustment function may also be a piecewise function, which can be expressed by the following formula:

[0080] Among them, P1 is greater than P2, and P2 can be zero.

[0081] Optionally, the method for determining the second adjustment authority value includes: obtaining the distance between the location information corresponding to the access request and the spatial authorization information corresponding to the client, inputting the distance into the spatial adjustment function, and obtaining the second adjustment authority value. The spatial adjustment function can be a mapping function of the second adjustment authority value and the above-mentioned distance, and the second adjustment authority value is negatively correlated with the distance.

[0082] For example, the spatial adjustment function can be expressed by the following formula: adjust_2 =e -λ2·d , where λ2 is the spatial attenuation coefficient, and d represents the distance between the location information corresponding to the access request and the reference location information in the client's corresponding spatial authorization information. l represents the location information corresponding to the access request, and l0 represents the reference location information in the client's corresponding spatial authorization information. This reference location information can be the center location information of the spatial authorization information. This distance can be calculated using the Euclidean distance method, where l and l0 are coordinate values.

[0083] Exemplarily, the spatial adjustment function can also be expressed by the following formula:

[0084] Where L is the space authorization information corresponding to the client, P3 is greater than P4, and P4 can be zero.

[0085] Optionally, the method for determining the third adjustment authority value includes: obtaining the historical operation behavior of the client within a preset historical time period, determining the operation risk score of the historical operation behavior based on the behavior authorization information corresponding to the client, and obtaining the third adjustment authority value based on the operation risk score and behavior attenuation coefficient of the historical operation behavior, wherein the higher the operation risk score, the higher the security risk representing the historical operation behavior, and the smaller the third adjustment authority value.

[0086] If the historical operation behavior belongs to the authorized operation behavior in the behavior authorization information corresponding to the client, the operation risk score is zero. If the historical operation behavior does not belong to the authorized operation behavior in the behavior authorization information corresponding to the client, the operation risk score is greater than zero. The operation risk score of the historical operation behavior is determined based on the sensitivity of the historical operation behavior. The higher the sensitivity of the historical operation behavior, the higher the operation risk score of the historical operation behavior. The operation risk score of the historical operation behavior can be a value between 0-1.

[0087] Exemplarily, specifically, the operational risk score is input into the behavior adjustment function to obtain the third adjustment authority value, wherein the behavior adjustment function can be represented by the following formula:

[0088] Among them, S represents the operational risk score, and λ3 represents the behavioral attenuation coefficient.

[0089] Optionally, the method for determining the fourth adjustment authority value includes: obtaining the current business status of the business system when the access request is sent, processing the current business status of the business system and the business status set of the business system that opens access rights to the client through the business status adjustment function, and obtaining the fourth adjustment authority value.

[0090] Exemplarily, the spatial adjustment function can also be expressed by the following formula:

[0091] Where M is the business state set for which the business system opens access rights to the client, and m is the current business state of the business system when the access request is sent; P5 is greater than P6, and P6 can be zero.

[0092] In some embodiments of the present disclosure, any one of the first adjustment authority value, the second adjustment authority value, the third adjustment authority value, and the fourth adjustment authority value may be determined as the adjustment authority value. For example, in the case where the client is a temporary authority client, the first adjustment authority value may be used as the adjustment authority value, and the adjustment authority value is automatically decayed according to the contract period of the authority until the target authority value triggers the automatic recovery of the authority. During the contract period of the authority, the data comprehensiveness of the business system or the project progress is continuously improved, and the security of the business system data or project data is improved by automatically adjusting the adjustment authority value.

[0093] In some embodiments of the present disclosure, the adjustment authority value may be obtained based on a weighted calculation of at least two of the first adjustment authority value, the second adjustment authority value, the third adjustment authority value, and the fourth adjustment authority value. In some embodiments of the present disclosure, the adjustment authority value may be determined based on the product of at least two of the first adjustment authority value, the second adjustment authority value, the third adjustment authority value, and the fourth adjustment authority value.

[0094] In some embodiments of the present disclosure, the target authority value is determined based on the basic authority value and the adjustment authority value; alternatively, the target authority value can be obtained based on the product of the basic authority value and the adjustment authority value. For example, the target authority value can be achieved by the following formula: final =P base ×P adjust , where P adjust To adjust the permission value.

[0095] Optionally, the target authority value may be obtained based on the tensor product of the basic authority value and the adjusted authority value. For example, the target authority value may be implemented by the following formula: Among them, P adjust To adjust the permission value.

[0096] Based on the above embodiment, responding to the access request based on the target permission information includes: determining the data access range and operation access range corresponding to the client according to the target permission value; and responding to the access request according to the data access range and operation access range.

[0097] The client's corresponding data access scope can be understood as the data range to which the client has access rights, and the client's corresponding operation access scope can be understood as the set of access operations to which the client has access rights. The data access scope and the operation access scope are positively correlated with the target permission value. The larger the target permission information, the larger the data access scope and the more operation types within the operation access scope.

[0098] Optionally, correspondences between the target permission information and the data access scope and the operation access scope are preset, and the data access scope and the operation access scope corresponding to the target permission information are determined based on the correspondences.

[0099] Business systems include a large amount of data, and different data has different confidentiality levels. For example, the confidentiality levels of data can include public, internal, and confidential. The confidentiality level of business data in the data access scope is positively correlated with the target authority value. In other words, the larger the target authority value, the larger the amount of data included in the data access scope corresponding to the target authority value, and the higher the confidentiality level of the data. For example, when the target authority value is 0.5, the data access scope corresponding to the target authority value is the data scope with a confidentiality level of public; when the target authority value is 0.8, the data access scope corresponding to the target authority value is the data scope with a confidentiality level of public and internal; when the target authority value is 1, the data access scope corresponding to the target authority value is the data scope with a confidentiality level of public, internal, and confidential.

[0100] The client has multiple access operations to the business system, and different access operations have different sensitivities. For example, the sensitivity of access operations such as delete, download, and view decreases in sequence. The sensitivity of the operation behavior within the operation access range is positively correlated with the target authority value. That is, the larger the target authority value, the more types of access operations are included in the operation access range corresponding to the target authority value, and the higher the sensitivity of the access operation. For example, when the target authority value is 0.5, the operation access range corresponding to the target authority value includes view; when the target authority value is 0.8, the operation access range corresponding to the target authority value includes view and download; when the target authority value is 1, the operation access range corresponding to the target authority value includes view, download, and delete.

[0101] Optionally, responding to the access request according to the data access scope and the operation access scope includes: determining whether the access object of the access request belongs to the data access scope corresponding to the client, and whether the access operation of the access request belongs to the operation access scope; if the access object of the access request belongs to the data access scope corresponding to the client, and the access operation of the access request belongs to the operation access scope, executing the access request and feeding back the request result corresponding to the access request; if the access object of the access request does not belong to the data access scope corresponding to the client, and the access operation of the access request does not belong to the operation access scope, rejecting the access request, or providing the client with secondary permission verification.

[0102] The technical solution of this embodiment uses first-level permission processing to obtain a base permission value, second-level limit processing to obtain an adjusted permission value, and finally, a target permission value derived from the base and adjusted permission values. The target permission value is used to represent the extent of the client's access rights to the business system. By responding to client access requests using the target permission value, this achieves digital management of business system access rights, improves the accuracy of permission management, and enhances the network security of the business system.

[0103] Figure 3 This is a schematic diagram of the structure of an access rights management device for a business system provided by an embodiment of the present disclosure. Figure 3 As shown, the device includes: a request receiving module 310, an information obtaining module 320, a first permission information determining module 330, a second permission information determining module 340 and an access request responding module 350. Among them:

[0104] Request receiving module 310, receiving a client's access request to the business system;

[0105] An information acquisition module 320 is configured to acquire multi-dimensional authentication information corresponding to the access request, wherein the multi-dimensional authentication information includes authentication information corresponding to at least one of a user dimension, a resource dimension, an environment dimension, and a business status dimension;

[0106] A first permission information determination module 330 is configured to perform a first-level permission authentication on the access request based on the multi-dimensional authentication information to obtain first permission information corresponding to the access request;

[0107] The second permission information determination module 340 is configured to obtain at least one of the time authorization information, space authorization information, behavior authorization information, and service status information corresponding to the client, perform a second-level permission authentication on the access request, and obtain the second permission information corresponding to the access request;

[0108] The access request response module 350 is configured to determine target permission information corresponding to the access request based on the first permission information and the second permission information, and respond to the access request based on the target permission information.

[0109] The technical solution of this embodiment performs two-level permission authentication processing by obtaining access requests, and determines the target permission information corresponding to the access request based on the permission information obtained from the two-level permission authentication, thereby improving multi-level permission management. Specifically, in the first-level permission authentication process, by obtaining multi-dimensional authentication information, the comprehensiveness and diversity of the authentication information are improved, and the accuracy of the permission authentication is improved. In the second-level permission authentication process, dynamic permission management is performed on the access request through at least one of time authorization information, space authorization information, behavior authorization information, and business status information, thereby improving the authentication accuracy of dynamic permissions. Through two-level permission authentication, the access security of the business system is improved, and the network security of the business system is further improved.

[0110] Based on the above embodiment, optionally, the first permission information includes allow and deny; the second permission information includes allow and deny; when either the first permission information or the second permission information is deny, the target permission information is deny; when both the first permission information and the second permission information are allow, the target permission information is allow;

[0111] The second permission information determination module 340 is used to: perform at least one of the following information matches, when any matching result is a mismatch, the second permission information is a rejection, and when all matching results are matches, the second permission information is a permission: matching the access time of the access request with the time authorization information corresponding to the client to obtain a time matching result; matching the location information corresponding to the access request with the space authorization information corresponding to the client to obtain a space matching result; matching the access operation corresponding to the access request with the behavior authorization information corresponding to the client to obtain a behavior matching result; matching the current business status of the business system with the accessible status information of the business system to obtain a business status matching result.

[0112] Based on the above embodiment, optionally, the first permission information is a basic permission value, the second permission information is an adjusted permission value; the target permission information is a target permission value; and the target permission value is determined based on the basic permission value and the adjusted permission value.

[0113] Optionally, the access request response module 350 is configured to: determine a data access scope and an operation access scope corresponding to the client according to the target permission value; and respond to the access request according to the data access scope and the operation access scope.

[0114] Optionally, the data access scope and the operation access scope are respectively positively correlated with the target authority value; the confidentiality level of business data in the data access scope is positively correlated with the target authority value; and the sensitivity of operation behavior within the operation access scope is positively correlated with the target authority value.

[0115] Optionally, the first authority information determination module 330 is used to: map the multi-dimensional authentication information into an authentication value based on a mapping relationship between the multi-dimensional authentication information and the value; and fuse the authentication values corresponding to the multi-dimensional authentication information based on a fusion authentication calculation model of the multi-dimensional authentication information to obtain the basic authority value.

[0116] Optionally, the second permission information determination module 340 is used to perform at least one of the following: processing the access time of the access request and the time authorization information corresponding to the client based on the time adjustment function to obtain a first adjustment permission value; processing the location information corresponding to the access request and the space authorization information corresponding to the client based on the space adjustment function to obtain a second adjustment permission value; processing the historical operation behavior of the client and the behavior authorization information corresponding to the client based on the behavior adjustment function to obtain a third adjustment permission value; processing the business status of the business system based on the business status adjustment function to obtain a fourth adjustment authority value.

[0117] Optionally, the access request response module 350 performs one of the following: executing the access request and feeding back a request result corresponding to the access request; rejecting the access request; and providing secondary permission verification for the client.

[0118] The access permission management device for a business system provided by an embodiment of the present disclosure can execute the access permission management method for a business system provided by any embodiment of the present disclosure, and has functional modules and beneficial effects corresponding to the execution method.

[0119] Figure 4 1 is a schematic diagram of the structure of an electronic device provided by an embodiment of the present disclosure. The electronic device 10 is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present disclosure described and / or required herein.

[0120] like Figure 4As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., which is communicatively connected to the at least one processor 11. The memory stores a computer program that can be executed by the at least one processor, and the processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. Various programs and data required for the operation of the electronic device 10 can also be stored in the random access memory (RAM) 13. The processor 11, the read-only memory (ROM) 12, and the random access memory (RAM) 13 are connected to each other via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.

[0121] Multiple components in the electronic device 10 are connected to the I / O interface 15, including an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a magnetic disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.

[0122] The processor 11 can be any general-purpose and / or specialized processing component with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various specialized artificial intelligence (AI) computing chips, various processors that run machine learning model algorithms, a digital signal processor (DSP), and any other suitable processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as the access rights management method for the business system.

[0123] In some embodiments, the access permission management method for a business system can be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as a storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed on the electronic device 10 via the read-only memory (ROM) 12 and / or the communication unit 19. When the computer program is loaded into the random access memory (RAM) 13 and executed by the processor 11, one or more steps of the access permission management method for the business system described above can be performed. Alternatively, in other embodiments, the processor 11 can be configured to execute the access permission management method for the business system by any other appropriate means (for example, by means of firmware).

[0124] Various embodiments of the systems and techniques described herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system-on-chip systems (SOCs), programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.

[0125] The computer programs used to implement the access rights management methods for the business systems disclosed herein can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, so that when executed by the processor, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The computer programs can be executed entirely on the machine, partially on the machine, as a standalone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0126] The present disclosure also provides a computer-readable storage medium storing computer instructions, wherein the computer instructions are used to cause a processor to execute a method for managing access rights of a business system, the method comprising:

[0127] Receive a client's access request to a business system, obtain multi-dimensional authentication information corresponding to the access request, and obtain multi-dimensional authentication information corresponding to the access request, wherein the multi-dimensional authentication information includes authentication information corresponding to at least one dimension of user dimension, resource dimension, environment dimension, and business status dimension; perform a first-level permission authentication on the access request based on the multi-dimensional authentication information, and obtain first permission information corresponding to the access request; obtain at least one item of time authorization information, space authorization information, behavior authorization information, and business status information corresponding to the client, and perform a second-level permission authentication on the access request to obtain second permission information corresponding to the access request; determine the target permission information corresponding to the access request based on the first permission information and the second permission information, and respond to the access request based on the target permission information.

[0128] In the context of the present disclosure, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by an instruction execution system, device or equipment or used in combination with an instruction execution system, device or equipment. A computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium can be a machine-readable signal medium. A more specific example of a machine-readable storage medium can include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0129] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0130] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.

[0131] A computing system may include clients and servers. The clients and servers are typically remote from each other and typically interact via a communication network. This client-server relationship arises through computer programs running on the respective computers, creating a client-server relationship. The server may be a cloud server, also known as a cloud computing server or cloud host. This server is a hosting product within the cloud computing service ecosystem that addresses the management difficulties and limited scalability of traditional physical hosting and VPS services.

[0132] It should be understood that the various forms of processes shown above can be used to reorder, add, or delete steps. For example, the steps described in this disclosure can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions of this disclosure can be achieved, and this document is not limited here.

[0133] The above specific embodiments do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure shall be included within the scope of protection of this disclosure.

Claims

1. A method for managing access rights of a business system, characterized in that: include: Receive a client's access request to the business system, and obtain multi-dimensional authentication information corresponding to the access request, wherein the multi-dimensional authentication information includes authentication information corresponding to at least one dimension of a user dimension, a resource dimension, an environment dimension, and a business status dimension; Performing a first-level permission authentication on the access request based on the multi-dimensional authentication information to obtain first permission information corresponding to the access request; Obtain at least one of the time authorization information, space authorization information, behavior authorization information, and service status information corresponding to the client to perform second-level authority authentication on the access request, and obtain second authority information corresponding to the access request; The target permission information corresponding to the access request is determined based on the first permission information and the second permission information, and the access request is responded to based on the target permission information.

2. The method according to claim 1, characterized in that The first permission information includes permission and rejection; the second permission information includes permission and rejection; when either the first permission information or the second permission information is rejection, the target permission information is rejection; When both the first permission information and the second permission information are allowed, the target permission information is allowed; The step of obtaining at least one of the time authorization information, space authorization information, and behavior authorization information corresponding to the client to perform second-level permission authentication on the access request to obtain second permission information corresponding to the access request includes: Perform at least one of the following information matches, and when any matching result is a mismatch, the second permission information is denied, and when all matching results are matches, the second permission information is allowed: Matching the access time of the access request with the time authorization information corresponding to the client to obtain a time matching result; Matching the location information corresponding to the access request with the space authorization information corresponding to the client to obtain a space matching result; Matching the access operation corresponding to the access request with the behavior authorization information corresponding to the client to obtain a behavior matching result; The current business status of the business system is matched with the accessible state information of the business system to obtain a business status matching result.

3. The method according to claim 1, characterized in that The first permission information is a basic permission value, the second permission information is an adjustment permission value; the target permission information is a target permission value; The target authority value is determined based on the basic authority value and the adjustment authority value; The step of responding to the access request based on the target permission information includes: Determine the data access scope and operation access scope corresponding to the client according to the target permission value; The access request is responded to according to the data access scope and the operation access scope.

4. The method according to claim 3, characterized in that The data access scope and the operation access scope are respectively positively correlated with the target authority value; the confidentiality level of business data in the data access scope is positively correlated with the target authority value; the sensitivity of operation behavior within the operation access scope is positively correlated with the target authority value.

5. The method according to claim 3, characterized in that Methods for determining the basic authority value include: Based on the mapping relationship between the multi-dimensional authentication information and the numerical value, mapping the multi-dimensional authentication information into the authentication numerical value; Based on a fusion authentication calculation model of multi-dimensional authentication information, the authentication values corresponding to the multi-dimensional authentication information are fused to obtain the basic authority value.

6. The method according to claim 3, characterized in that The adjustment authority value is determined based on at least one of the following: Processing the access time of the access request and the time authorization information corresponding to the client based on a time adjustment function to obtain a first adjustment authority value; Processing the location information corresponding to the access request and the space authorization information corresponding to the client based on a space adjustment function to obtain a second adjustment authority value; Processing the historical operation behavior of the client and the behavior authorization information corresponding to the client based on the behavior adjustment function to obtain a third adjustment authority value; The business status of the business system is processed based on the business status adjustment function to obtain a fourth adjustment authority value.

7. The method according to claim 1 or 3, characterized in that The response to the access request includes at least one of the following: Execute the access request and feedback the request result corresponding to the access request; deny the access request; A secondary authority verification is provided for the client.

8. An access rights management device for a business system, characterized in that: include: Request receiving module, receiving client's access request to the business system; an information acquisition module, configured to acquire multi-dimensional authentication information corresponding to the access request, the multi-dimensional authentication information including authentication information corresponding to at least one of a user dimension, a resource dimension, an environment dimension, and a business status dimension; a first permission information determination module, configured to perform a first level permission authentication on the access request based on the multi-dimensional authentication information, and obtain first permission information corresponding to the access request; A second permission information determination module is configured to obtain at least one of the time authorization information, space authorization information, behavior authorization information, and service status information corresponding to the client, perform a second-level permission authentication on the access request, and obtain second permission information corresponding to the access request; An access request response module is configured to determine target permission information corresponding to the access request based on the first permission information and the second permission information, and respond to the access request based on the target permission information.

9. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the access permission management method for a business system according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the access permission management method for a business system according to any one of claims 1 to 7 when executed.

Citation Information

Patent Citations

  • Access control method, device and equipment and readable storage medium

    CN112653714A

  • Multi-factor authentication method based on zero trust

    CN113824732A

  • Zero-trust network access control method and system based on time window dynamic switching

    CN116545731A

  • Data authority management method and device, equipment and storage medium

    CN116756768A

  • Fine-grained dynamic authority control method based on operation behavior feedback

    CN117828578A