Authority authentication method and device, electronic equipment and storage medium

By obtaining the credibility of users with similar permissions, dynamically adjusting the credibility threshold of the first user, and combining the exception type and compliance operation duration, the problem of insufficient adaptability of permission authentication in existing technologies is solved, and accurate permission matching and security improvement are achieved.

CN120602137APending Publication Date: 2025-09-05CHINA UNITED NETWORK COMM GRP CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510709803.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-29
Publication Date
2025-09-05

AI Technical Summary

Technical Problem

Existing identity authentication and access control technologies are unable to adapt to the dynamic changes in user behavior in the rapidly changing network environment, resulting in insufficient or excessive restrictions on permissions and posing security threats.

Method used

By obtaining the credibility of the second user who has similar permissions to the first user, dynamically adjusting the credibility threshold of the first user, and combining the exception type and compliance operation duration, permission authentication is performed to achieve accurate matching.

Benefits of technology

It improves the adaptability and accuracy of permission authentication, reduces the possibility of security threats, and adapts to changes in complex network environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602137A_ABST
    Figure CN120602137A_ABST
Patent Text Reader

Abstract

The invention provides a permission authentication method and device, electronic equipment and a storage medium, relates to the field of communication security, and can reduce the problem of insufficient adaptability to a network environment. The method comprises the steps that in response to an authentication request of a first user, the credibility of second users is obtained, the second users comprise the first user and other users with similar authority to the first user, and the credibility is used for indicating the credibility of the users; based on the creditworthiness of the second user, determining a creditworthiness threshold value of the first user; and based on the creditworthiness of the first user and a creditworthiness threshold value, performing authority authentication on the first user. Compared with a fixed preset creditworthiness threshold value, the creditworthiness threshold value can be obtained more accurately, the obtained creditworthiness threshold value of the first user has higher dynamic nature and applicability, authority authentication is carried out on the first user through the creditworthiness threshold value and the creditworthiness of the first user, and the user experience is improved. And thus, accurate matching of the permission of the first user is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication security, and in particular to a permission authentication method, device, electronic device and storage medium. Background Art

[0002] With the rapid development of Internet technology and Internet of Things technology, identity authentication technology and access control technology are used to assign permissions to users and enable users to operate specific resources.

[0003] Currently, the user's credibility is mainly evaluated through the user's behavior pattern, and the user's authority is determined based on the comparison result between the user's credibility and the preset credibility threshold.

[0004] However, this method is difficult to adapt to the rapid and complex changes in the network environment, and may lead to problems such as insufficient or excessive restrictions on user permissions, which can easily lead to security threats. Summary of the Invention

[0005] The present application provides a permission authentication method, device, electronic device and storage medium, which can improve adaptability to network environments and reduce security threats.

[0006] To achieve the above objectives, this application adopts the following technical solutions:

[0007] In a first aspect, the present application provides a method for authority authentication, which includes: in response to an authentication request from a first user, obtaining the credibility of a second user, where the second user includes the first user and other users with similar permissions to the first user, and the credibility is used to indicate the user's trustworthiness; based on the credibility of the second user, determining the credibility threshold of the first user; and authenticating the first user based on the credibility and credibility threshold of the first user.

[0008] In combination with the first aspect above, in a possible implementation method, the credibility threshold of the first user is determined based on the credibility of the second user, including: when the first user is a newly registered user and there is no abnormality in the authority authentication system, the first credibility threshold is determined as the credibility threshold of the first user based on the credibility of the second user; when the first user is a newly registered user and there is an abnormality in the authority authentication system, the second credibility threshold is determined as the credibility threshold of the first user based on the first credibility threshold and the abnormality type, and the abnormality type is used to indicate the type of abnormality in the authority authentication system; when the first user is not a newly registered user, the credibility threshold of the first user is determined based on the second credibility threshold and the compliance operation time of the first user, and the compliance operation time is used to indicate the time duration of the first user's operation that complies with the regulations.

[0009] In combination with the first aspect above, in a possible implementation, the process of determining the first credibility threshold includes: determining the first credibility threshold based on the average value of the second user's credibility and the standard deviation of the second user's credibility, the first credibility threshold being positively correlated with the average value and negatively correlated with the standard deviation.

[0010] In combination with the first aspect above, in a possible implementation method, the process of determining the second credibility threshold includes: determining the corresponding abnormality level based on the abnormality type, and the abnormality type and the abnormality level correspond one to one; determining the second credibility threshold based on the first credibility threshold and the abnormality level, the second credibility threshold is positively correlated with the first credibility threshold, and the second credibility threshold is positively correlated with the abnormality level.

[0011] In combination with the first aspect above, in a possible implementation method, the credibility threshold of the first user is determined based on the second credibility threshold and the compliance operation time of the first user, including: determining the compliance coefficient of the first user based on the compliance operation time of the first user, and the compliance coefficient is used to indicate the degree coefficient of the compliance behavior of the first user; determining the credibility threshold of the first user based on the second credibility threshold and the compliance coefficient, the credibility threshold is positively correlated with the second credibility threshold, and the credibility threshold is negatively correlated with the compliance coefficient.

[0012] In combination with the above-mentioned first aspect, in one possible implementation, the credibility of the second user is related to the behavior of the second user. After determining the credibility threshold of the first user based on the credibility of the second user, the method further includes: when the deviation between the behavior of the second user and the historical behavior of the second user is greater than the deviation threshold, re-determining the credibility threshold of the first user.

[0013] In combination with the first aspect above, in one possible implementation, the first user is authenticated based on the first user's credibility and credibility threshold, including: in response to the first user's credibility being less than or equal to the credibility threshold, determining that the first user undergoes secondary authentication; in response to the first user's credibility being greater than the credibility threshold, determining that the first user passes the authentication.

[0014] In combination with the first aspect above, in a possible implementation, in response to the first user's credibility being less than or equal to a credibility threshold, after determining that the first user has performed secondary authentication, the method further includes: obtaining the number of secondary authentications of the first user; and forcing the first user to log off when the number of secondary authentications of the first user is greater than or equal to a preset number.

[0015] In the second aspect, the present application provides an authority authentication device, which includes: an acquisition unit for acquiring the credibility of a second user in response to an authentication request of a first user, where the second user includes the first user and other users with similar permissions as the first user, and the credibility is used to indicate the user's trustworthiness; a determination unit for determining the credibility threshold of the first user based on the credibility of the second user; and an authentication unit for performing authority authentication on the first user based on the credibility and credibility threshold of the first user.

[0016] In combination with the above-mentioned second aspect, in a possible implementation method, the determination unit is specifically used to: when the first user is a newly registered user and there is no abnormality in the authority authentication system, determine the first credibility threshold as the credibility threshold of the first user based on the credibility of the second user; when the first user is a newly registered user and there is an abnormality in the authority authentication system, determine the second credibility threshold as the credibility threshold of the first user based on the first credibility threshold and the abnormality type, and the abnormality type is used to indicate the type of abnormality in the authority authentication system; when the first user is not a newly registered user, determine the credibility threshold of the first user based on the second credibility threshold and the compliance operation time of the first user, and the compliance operation time is used to indicate the time duration of the first user's operation that complies with the regulations.

[0017] In combination with the above-mentioned second aspect, in a possible implementation method, the determination unit is specifically used to: determine a first credibility threshold based on an average value of the second user's credibility and a standard deviation of the second user's credibility, where the first credibility threshold is positively correlated with the average value and negatively correlated with the standard deviation.

[0018] In combination with the above-mentioned second aspect, in a possible implementation method, the determination unit is specifically used to: determine the corresponding abnormality level based on the abnormality type, and the abnormality type corresponds one-to-one to the abnormality level; based on the first credibility threshold and the abnormality level, determine the second credibility threshold, the second credibility threshold is positively correlated with the first credibility threshold, and the second credibility threshold is positively correlated with the abnormality level.

[0019] In combination with the above-mentioned second aspect, in a possible implementation method, the determination unit is specifically used to: determine the compliance coefficient of the first user based on the compliance operation time of the first user, and the compliance coefficient is used to indicate the degree coefficient of the compliance behavior of the first user; determine the credibility threshold of the first user based on the second credibility threshold and the compliance coefficient, and the credibility threshold is positively correlated with the second credibility threshold, and the credibility threshold is negatively correlated with the compliance coefficient.

[0020] In combination with the above-mentioned second aspect, in one possible implementation, the credibility of the second user is related to the behavior of the second user, and the device also includes: a second determination unit, which is used to re-determine the credibility threshold of the first user when the deviation between the behavior of the second user and the historical behavior of the second user is greater than the deviation threshold.

[0021] In combination with the above-mentioned second aspect, in a possible implementation method, the authentication unit is specifically used to: in response to the first user's credibility being less than or equal to the credibility threshold, determine that the first user undergoes secondary authentication; in response to the first user's credibility being greater than the credibility threshold, determine that the first user passes the authentication.

[0022] In combination with the above-mentioned second aspect, in a possible implementation method, the device also includes: a second acquisition unit, used to obtain the number of secondary authentications of the first user; and a comparison unit, used to force the first user to log off when the number of secondary authentications of the first user is greater than or equal to a preset number.

[0023] In a third aspect, the present application provides an electronic device comprising: a processor and a communication interface; the communication interface and the processor are coupled, and the processor is used to run a computer program or instructions to implement the authority authentication method described in the first aspect and any possible implementation method of the first aspect.

[0024] In a fourth aspect, the present application provides a computer-readable storage medium, which stores instructions. When the instructions are executed on an electronic device, the electronic device executes the permission authentication method described in the first aspect and any possible implementation of the first aspect.

[0025] In a fifth aspect, the present application provides a computer program product comprising instructions, which, when executed on an electronic device, enables the electronic device to execute the permission authentication method as described in the first aspect and any possible implementation of the first aspect.

[0026] In a sixth aspect, the present application provides a chip, which includes a processor and a communication interface, the communication interface and the processor are coupled, and the processor is used to run a computer program or instructions to implement the authority authentication method described in the first aspect and any possible implementation method of the first aspect.

[0027] Specifically, the chip provided in this application also includes a memory for storing computer programs or instructions.

[0028] It should be noted that the above-mentioned computer instructions may be stored in whole or in part on a computer-readable storage medium. The computer-readable storage medium may be packaged together with the processor of the device or separately from the processor of the device, and this application does not limit this.

[0029] In a seventh aspect, the present application provides an authority authentication system, including: a terminal and an electronic device, wherein the electronic device is used to execute the authority authentication method described in the first aspect and any possible implementation manner of the first aspect.

[0030] The descriptions of the second to seventh aspects of this application can refer to the detailed description of the first aspect; and the beneficial effects of the descriptions of the second to seventh aspects can refer to the analysis of the beneficial effects of the first aspect, which will not be repeated here.

[0031] In this application, the name of the aforementioned authorization authentication device does not limit the device or functional module itself. In actual implementation, these devices or functional modules may appear with other names. As long as the functions of each device or functional module are similar to those of this application, they fall within the scope of the claims of this application and their equivalents.

[0032] These and other aspects of the present application will become more readily apparent from the following description.

[0033] The above scheme brings at least the following beneficial effects: the permission authentication method provided in this application determines the credibility threshold of the first user based on the credibility of the second user who has similar permissions to the first user. Compared with the fixed preset credibility threshold, a more accurate credibility threshold can be obtained, and the dynamic adjustment of the credibility threshold of the first user can be realized. The obtained credibility threshold of the first user has stronger dynamics and applicability. The first user is authenticated by the credibility threshold and credibility of the first user, thereby achieving accurate matching of the permissions of the first user and reducing the possibility of security threats. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] Figure 1 A schematic diagram of the architecture of an authorization authentication system provided in an embodiment of the present application;

[0035] Figure 2 A schematic diagram of the hardware structure of an electronic device provided in an embodiment of the present application;

[0036] Figure 3 A flowchart of a method for authentication of permissions provided in an embodiment of the present application;

[0037] Figure 4 A flowchart of another permission authentication method provided in an embodiment of the present application;

[0038] Figure 5 A schematic diagram of an authorization authentication system provided in an embodiment of the present application;

[0039] Figure 6 A schematic diagram of the structure of an authorization authentication device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0040] The following will be combined with the accompanying drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments of this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0041] The term "and / or" in this article is merely a description of the association relationship between associated objects, indicating that three relationships may exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone.

[0042] The terms "first" and "second" and the like in the specification and drawings of this application are used to distinguish different objects, or to distinguish different processing of the same object, rather than to describe a specific order of objects.

[0043] Furthermore, the terms "including," "having," and any variations thereof, as used in the description of this application are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or apparatus comprising a series of steps or units is not limited to the listed steps or units, but may optionally include other steps or units not listed, or may optionally include other steps or units inherent to the process, method, product, or apparatus.

[0044] It should be noted that in the embodiments of this application, words such as "exemplary" or "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described as "exemplary" or "for example" in the embodiments of this application should not be interpreted as being more preferred or advantageous over other embodiments or designs. Rather, the use of words such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner.

[0045] In the description of the present application, unless otherwise specified, “plurality” means two or more.

[0046] In recent years, with the rapid development of Internet and Internet of Things technologies, identity authentication and access control technologies have been widely used in various fields. Identity authentication technology confirms user identities, and access control technology assigns permissions to different user identities, allowing users to operate specific resources.

[0047] Traditional authentication technologies typically rely on static credentials, such as passwords, biometrics, multi-factor authentication, or trust-based authentication. The core logic of these authentication technologies remains the "initial trust assumption," meaning that once a user passes a one-time authentication, they assume a long-term trust status.

[0048] This approach relies on initial trust assumptions and cannot dynamically assess the credibility of user behavior. If identity credentials are stolen or insiders abuse their privileges, the system struggles to respond promptly, cope with complex network environments and ever-changing security threats, and meet user needs.

[0049] In recent years, behavioral authentication technology has gained increasing attention. This approach analyzes user behavior patterns and characteristics to determine user trustworthiness. For example, it can identify abnormal user behavior based on login frequency, time intervals, and access paths. This approach reduces reliance on fixed keys, thereby improving system flexibility and security.

[0050] However, existing behavioral authentication technologies still have shortcomings. This approach often relies on large amounts of historical data, making it difficult to accurately assess user trustworthiness in rapidly changing network environments. This approach relies solely on simple rules to capture anomalous user behavior, making it difficult to identify complex anomalous user behavior. This can lead to performance bottlenecks when dealing with high concurrent access and large user groups, especially in the face of multiple interference factors.

[0051] Existing access control technologies primarily include role-based access control (RBAC) and attribute-based access control (ABAC). RBAC assigns permissions based on predefined roles. After a user passes identity authentication, the user is assigned a role, which in turn grants the corresponding permissions. RBAC enables fine-grained control of resources by defining the relationships between users, roles, and permissions. ABAC uses dynamic attributes to make real-time permission decisions. By associating user permissions with attributes, ABAC supports more flexible access control policies. This approach improves system flexibility and scalability.

[0052] However, existing identity authentication and access control technologies still have limitations. They suffer from static policies, excessive trust, and coarse granularity. Specifically, this approach typically uses predefined static policies to assign permissions, making it difficult to adapt to real-time changes in user behavior in dynamic environments and lacking the ability to adjust user behavior and trust status in real time. For example, in environments such as the Internet of Things and zero-trust networks, it is difficult to update user permissions based on real-time changes in user behavior. Especially in dynamic environments like the Internet of Things, zero-trust networks, and cloud computing, the trust status of devices or users may fluctuate frequently, making this approach ineffective in responding to these changes. Furthermore, this approach fails to quantify historical user behavior, creating a disconnect between permission assignments and potential risks. For example, historical user behavior could include unusual logins, data access frequency, and compliance records. This approach lacks proactive defenses against malicious internal users or persistent attackers, and over-authorization can easily lead to data breaches.

[0053] The permission authentication method provided in this application determines the credibility threshold of the first user based on the credibility of a second user who has similar permissions to the first user. Compared with a fixed preset credibility threshold, a more accurate credibility threshold can be obtained, and dynamic adjustment of the credibility threshold of the first user can be achieved. The obtained credibility threshold of the first user has greater dynamism and applicability. The first user's credibility threshold and credibility are used to authenticate the permissions of the first user, thereby achieving a precise match of the first user's permissions and reducing the possibility of security threats. In addition, by setting a sliding time window, this solution can dynamically evaluate the user's credibility based on the user's historical behavior within the corresponding time window, which can more accurately reflect the current credibility of the user. After the user exhibits abnormal behavior, not only the abnormal behavior is recorded, but the user's credibility can also be reduced based on the user's abnormal behavior, which is more adaptable to complex network environments and changing security threats; by adjusting the credibility of the first user in real time, that is, adjusting the credibility of the second user in real time, the credibility threshold of the first user is adjusted. Combined with the abnormal type of the authority authentication system and the compliance operation time of the first user, the credibility threshold of the first user is calculated differentially according to the situation. Through the differentiated calculation of the credibility threshold of the first user, the user's authority can be relaxed or tightened. By comparing the credibility of the first user with the credibility threshold, it is determined whether to authenticate the first user. This can better adapt to changes in the environment and reduce the security risks brought about by fixed credibility and fixed credibility threshold.

[0054] The following will describe in detail the implementation of the embodiment of the present application in conjunction with the accompanying drawings.

[0055] Figure 1This is a schematic diagram of the architecture of a permission authentication system provided in an embodiment of the present application. Figure 1 As shown, the architecture includes: a terminal 101 and an electronic device 102.

[0056] Terminal 101 can be at least one of a smart phone, a smart watch, a desktop computer, a laptop, a virtual reality terminal, an augmented reality terminal, a wireless terminal, a laptop, an Internet of Things device, an edge device, etc., and the embodiments of the present application are not limited to this.

[0057] In some embodiments, the terminal 101 has a communication function. For example, the terminal 101 can send an authentication request to the electronic device 102.

[0058] It should be noted that the number of terminals 101 may be one or more, which is not limited in the embodiment of the present application.

[0059] The electronic device 102 may be a mobile phone, a tablet computer, a computer with wireless transceiver capabilities, a virtual reality (VR) terminal, an augmented reality (AR) terminal, a wireless terminal, a computer, an independent physical server, a server cluster consisting of multiple physical servers, or at least one of a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content distribution networks, and big data or artificial intelligence platforms. This embodiment of the present application does not limit this. Of course, the electronic device 102 can also include other functions to provide more comprehensive and diverse services.

[0060] In some embodiments, the electronic device 102 has a communication function, for example, communication between the electronic device 102 and the terminal 101.

[0061] In other embodiments, the electronic device 102 has a processing function. For example, the electronic device 102 can process the second user's reputation to obtain the first user's reputation threshold. For another example, the electronic device 102 can perform permission authentication on the first user based on the first user's reputation and the reputation threshold.

[0062] The electronic device 102 may be one or more, and this embodiment of the present application does not limit this. Figure 1 Only one is shown.

[0063] The terminal 101 and the electronic device 102 are connected via a communication link. The communication link may be a wired communication link or a wireless communication link, which is not limited in the embodiment of the present application.

[0064] When implemented by hardware, the electronic device may be provided as follows Figure 2 The hardware structure shown, specifically, Figure 2 This is a hardware structure diagram of an electronic device provided in an embodiment of the present application. Figure 2 As shown, the electronic device includes at least one processor 201, a communication line 202, and at least one communication interface 204, and may further include a memory 203. The processor 201, the memory 203 and the communication interface 204 may be connected via the communication line 202.

[0065] The processor 201 can be a central processing unit (CPU), an application specific integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present application, such as one or more digital signal processors (DSPs), or one or more field programmable gate arrays (FPGAs).

[0066] The communication line 202 is used to transmit information between the above components.

[0067] The communication interface 204 is used to communicate with other devices or communication networks and can use any transceiver-like device, such as Ethernet, radio access network (RAN), wireless local area network (WLAN), etc.

[0068] The memory 203 may be a read-only memory (ROM) or other type of static storage device that can store static information and instructions, a random access memory (RAM) or other type of dynamic storage device that can store information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compact disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium that can be used to include or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited to these.

[0069] In one possible design, the memory 203 can exist independently of the processor 201, that is, the memory 203 can be a memory external to the processor 201. In this case, the memory 203 can be connected to the processor 201 via the communication line 202 to store execution instructions or application code, and the execution is controlled by the processor 201 to implement the permission authentication method provided in the following embodiment of this application. In another possible design, the memory 203 can also be integrated with the processor 201, that is, the memory 203 can be the internal memory of the processor 201. For example, the memory 203 is a cache that can be used to temporarily store some data and instruction information.

[0070] As a possible implementation, the processor 201 may include one or more CPUs, such as Figure 2 As another possible implementation, the electronic device may include multiple processors, such as Figure 2 As another possible implementation, the electronic device may further include an output device 205 and an input device 206.

[0071] It should be pointed out that the various embodiments of the present application can refer to each other, for example, the same or similar steps, method embodiments, system embodiments and device embodiments can refer to each other without limitation.

[0072] Figure 3 This is a flowchart of a method for authentication of permissions provided in an embodiment of the present application. This method can be applied to Figure 2 In the electronic device shown. Figure 3 As shown, the method can be implemented through S301 to S303.

[0073] S301: The electronic device obtains the credibility of the second user in response to the authentication request of the first user.

[0074] The first user is a user who needs to be authenticated.

[0075] The second user includes the first user and other users with similar permissions as the first user. For example, the second user can be a user with the same role as the first user. The role can be "Financial Manager," "Ordinary Employee," or similar. For another example, the second user can be a user with the same permission level as the first user.

[0076] Credibility is used to indicate the user's trustworthiness. A high credibility indicates a high degree of trustworthiness; a low credibility indicates a low degree of trustworthiness. The credibility value range can be [0, 1], or [0, 100]. This embodiment of the present application is not limited to this.

[0077] In a possible implementation, the second user's credibility may be determined based on the second user's behavior data.

[0078] For example, the electronic device obtains the behavior data of the second user, pre-processes the behavior data of the second user, and then determines the credibility of the second user by weighted summation.

[0079] In a possible implementation, the second user's credibility is stored in a storage module of the electronic device. After the electronic device receives the authentication request of the first user, the electronic device obtains the second user's credibility by calling the second user's credibility in the storage module.

[0080] S302: The electronic device determines a credibility threshold of the first user based on the credibility of the second user.

[0081] The credibility threshold of the first user is used to determine whether the first user needs to perform secondary authentication.

[0082] In a possible implementation, the electronic device determines the credibility threshold of the first user based on an average value of the credibility of the second user and a standard deviation of the credibility of the second user.

[0083] In another possible implementation, the electronic device determines the credibility threshold of the first user based on an average value of the second user's credibility, a standard deviation of the second user's credibility, and an abnormality type.

[0084] The exception type is used to indicate the type of exception that occurred in the authorization authentication system.

[0085] In another possible implementation, the electronic device determines the credibility threshold of the first user based on an average value of the second user's credibility, a standard deviation of the second user's credibility, an abnormality type, and a compliance operation duration of the first user.

[0086] The compliance operation duration is used to indicate the duration of the first user's operation that complies with regulations.

[0087] S303: The electronic device performs authority authentication on the first user based on the first user's credibility and the credibility threshold.

[0088] In a possible implementation, the electronic device performs authority authentication on the first user by determining the relationship between the first user's credibility and a credibility threshold.

[0089] Exemplarily, when the credibility of the first user is less than or equal to the credibility threshold, it is determined to perform secondary authentication on the first user.

[0090] As another example, when the first user's credibility is greater than a credibility threshold, it is determined that the first user has passed the authentication.

[0091] The permission authentication method provided in this application determines the credibility threshold of the first user by using the credibility of a second user who has similar permissions to the first user. Compared with a fixed preset credibility threshold, this method can obtain a more accurate credibility threshold, realize dynamic adjustment of the credibility threshold of the first user, and the obtained credibility threshold of the first user has greater dynamism and applicability. The first user's credibility threshold and credibility are used to authenticate the permissions of the first user, thereby achieving accurate matching of the first user's permissions and reducing the possibility of security threats.

[0092] The following is the above Figure 3 The process of determining the credibility threshold of the first user in S302 is described below. The above S302 can also be implemented in the following three ways.

[0093] Method 1: When the first user is a newly registered user and there is no abnormality in the authority authentication system, the electronic device determines a first credibility threshold as the credibility threshold of the first user based on the credibility of the second user.

[0094] Here, the first user is a newly registered user, which can also be understood as the first user having no historical operation data.

[0095] In a possible implementation, the process of determining the first credibility threshold may be implemented by following step 11.

[0096] Step 11: The electronic device determines a first credibility threshold based on an average value of the credibility of the second user and a standard deviation of the credibility of the second user.

[0097] The first credibility threshold is positively correlated with the average value, and the first credibility threshold is negatively correlated with the standard deviation.

[0098] In a possible implementation, the first credibility threshold is determined based on an average value of the second user's credibility, a standard deviation of the second user's credibility, and the following formula (1).

[0099] T base =μ-k×σ Formula (1)

[0100] Where, T base represents the first credibility threshold; μ represents the average credibility of the second user; σ represents the standard deviation of the credibility of the second user; and k represents the safety factor. The safety factor can be used to indicate the risk level of the business running the authorization authentication system. The safety factor is a preset fixed value. For example, if the business running in the authorization authentication system is financial business, k = 2; if the business running in the authorization authentication system is office business, k = 1.5.

[0101] In this way, the method for determining the first credibility threshold can be clarified, and the first credibility threshold can be determined by the average value of the second user's credibility and the standard deviation of the second user's credibility. When the first user is a newly registered user and there is no abnormality in the authority authentication system, a judgment basis is provided for the first user to perform authority authentication.

[0102] Method 2: When the first user is a newly registered user and an exception occurs in the authority authentication system, the electronic device determines a second credibility threshold as the credibility threshold of the first user based on the first credibility threshold and the type of the exception.

[0103] The exception type indicates the type of exception that occurred in the authentication system. For example, the exception type could be a distributed denial of service (DDoS) attack, a phishing email attack, a malware attack, an advanced persistent threat (APT) attack, or a firewall interception.

[0104] Exemplarily, the authorization authentication system determines the abnormality type by real-time monitoring of the system log. The interface corresponding to the electronic device obtains the abnormality type and then determines the second credibility threshold based on the first credibility threshold and the abnormality type.

[0105] In a possible implementation, the process of determining the second credibility threshold may be implemented through steps 21 and 22 below.

[0106] Step 21: The electronic device determines a corresponding abnormality level based on the abnormality type, where the abnormality type corresponds to the abnormality level in a one-to-one manner.

[0107] In one possible implementation, the exception level corresponding to each exception type may be predefined. The exception level may be a normalized value. That is, the exception level ranges from [0 to 1]. When the exception level is 0, it indicates that no exception has occurred in the authorization authentication system.

[0108] For example, when the anomaly type is a DDoS attack, the anomaly level is 0.8.

[0109] Step 22: The electronic device determines a second credibility threshold based on the first credibility threshold and the abnormality level.

[0110] The second credibility threshold is positively correlated with the first credibility threshold, and the second credibility threshold is positively correlated with the abnormality level.

[0111] In a possible implementation, the second credibility threshold is determined based on the first credibility threshold, the abnormality level, and the following formula (2).

[0112] T current =T base ·(1+α·S theat ) Formula (2)

[0113] Where, T current represents the second credibility threshold; T base represents the first credibility threshold; S theat represents the abnormality level; α represents the adjustment factor. α is a preset value. For example, α is generally 0.2. If the permission authentication system is used in a high-security scenario, α can be adaptively increased. For example, α can be increased to 0.5.

[0114] For example, when the anomaly type is a DDoS attack and the first user is a new user, that is, α=0.2, S theat =0.8, the second credibility threshold is increased by 16% compared to the first credibility threshold. That is, for the first user, the increase in the credibility threshold is equivalent to tightening the permission access threshold.

[0115] In this way, the method for determining the second credibility threshold can be clarified, and the second credibility threshold can be determined through the first credibility threshold and the abnormality level. When the first user is a newly registered user and an abnormality occurs in the authority authentication system, a judgment basis is provided for the first user to perform authority authentication, which can improve the credibility threshold of the first user, thereby improving the system security and reducing the security risks caused by abnormalities in the authority authentication system.

[0116] Method three: When the first user is not a newly registered user, the electronic device determines the credibility threshold of the first user based on the second credibility threshold and the compliance operation duration of the first user.

[0117] Here, the first user is not a newly registered user, which can also be understood as the first user having historical operation data.

[0118] The compliant operation duration indicates the duration of time the first user's operations comply with regulations. For example, the compliant operation duration could be 30 consecutive days of compliant operations. The compliant operation duration could also be the duration of time the first user has not performed any abnormal operations. For example, abnormal operations could include frequent access to sensitive data or access to modules outside of the user's permissions.

[0119] It should be noted that before determining the credibility threshold of the first user, the electronic device needs to obtain the compliance operation duration of the first user.

[0120] In a possible implementation, the process of determining the credibility threshold of the first user may be implemented through steps 31 and 32 .

[0121] Step 31: The electronic device determines the compliance coefficient of the first user based on the compliance operation duration of the first user.

[0122] The compliance coefficient is used to indicate the degree of compliance behavior of the first user.

[0123] In one possible implementation, the compliance coefficient is calculated based on the compliance operation duration. For example, the compliance coefficient corresponds to the compliance operation duration.

[0124] Step 32: The electronic device determines the credibility threshold of the first user based on the second credibility threshold and the compliance coefficient.

[0125] Among them, the credibility threshold is positively correlated with the second credibility threshold, and the credibility threshold is negatively correlated with the compliance coefficient.

[0126] In a possible implementation, the electronic device determines the credibility threshold of the first user based on the second credibility threshold, the compliance coefficient, and the following formula (3).

[0127] T individual =T current ·(1-β·C trust ) Formula (3)

[0128] Where, T individual represents the credibility threshold of the first user; T current represents the second credibility threshold; C trustrepresents the compliance coefficient; β represents the buffer coefficient. trust The value range of is [0, 1]. β is a preset value used to prevent the first user's credibility threshold from being set too loosely. For example, β is 0.1.

[0129] For example, the compliance coefficient C trust When the first user's credibility threshold is 0.5, the first user's credibility threshold is reduced by 5% compared with the second credibility threshold.

[0130] The method for determining the credibility threshold of the first user can be clarified, and for users who have been able to operate in compliance for a long time, their credibility threshold can be lowered, giving users who have been able to operate in compliance for a long time a credibility threshold buffer, thereby reducing the probability of misjudgment.

[0131] In this way, by fully considering whether the first user is a new user and whether there are any abnormalities in the authority authentication system, the credibility threshold of the first user is calculated separately in different situations, thereby achieving differentiated matching of different types of users with their corresponding credibility thresholds, being able to dynamically adjust the credibility threshold of the first user, taking into account both the efficiency and accuracy of the credibility threshold calculation, and improving the accuracy of the credibility threshold. The credibility threshold of the first user can be adjusted based on the credibility of the second user, the type of abnormality, and the duration of the first user's compliant operation, solving the problem of insufficient adaptability of fixed thresholds in a constantly changing environment, reducing the misjudgment and omission of authority authentication that may be caused by fixed thresholds, and ensuring the security protection capabilities of the authority authentication system in different business scenarios. It is also possible to determine the corresponding credibility threshold for each user, achieving differentiated settings of the credibility threshold, improving accuracy, and achieving dynamic management and control of security risks.

[0132] It should be noted that the second user's credibility is related to the second user's behavior. Figure 3 After determining the credibility threshold of the first user in S302 , the authority authentication method further includes the following step 41 .

[0133] Step 41: When the deviation between the second user's behavior and the second user's historical behavior is greater than the deviation threshold, the electronic device re-determines the first user's credibility threshold.

[0134] In a possible implementation, the deviation between the second user's behavior and the second user's historical behavior may be determined based on the KL (Kullback-Leibler) divergence, that is, the following formula (4).

[0135]

[0136] Where D KLrepresents the deviation between the second user's behavior and the second user's historical behavior; current represents the predicted probability of the second user's behavior; P base represents the true probability of the second user's historical behavior; i represents a historical behavior of the user.

[0137] The deviation threshold is used to determine whether the second user's behavior has changed significantly. The deviation threshold can be represented by θ. θ can be a preset value, which can be determined based on the business running in the authorization authentication system.

[0138] It should be noted that when D KL When θ > θ, the deviation between the second user's behavior and their historical behavior is too high. Since the second user's credibility is related to their behavior, a high deviation indicates a significant change in the second user's behavior, and therefore a corresponding change in their credibility. When the second user's credibility changes, the previously calculated credibility threshold for the first user is no longer applicable and needs to be recalculated.

[0139] In this way, when the deviation between the second user's behavior and the second user's historical behavior is greater than the deviation threshold, the credibility threshold of the first user can be recalculated, so that the re-determined credibility threshold of the first user is more adapted to the current user behavior and can adapt to the long-term evolution of the user's behavior. The obtained credibility threshold can more accurately determine whether the user needs secondary authentication.

[0140] The following is the above Figure 3 The process of performing authority authentication on the first user in S303 is described. The above S303 can also be implemented by following steps 51 to 52.

[0141] Step 51: In response to the first user's credibility being less than or equal to a credibility threshold, the electronic device determines that the first user undergoes secondary authentication.

[0142] Secondary authentication refers to re-confirming a user's identity through two different verification methods. For example, the verification method can be SMS verification or fingerprint verification.

[0143] Step 52: In response to the first user's credibility being greater than a credibility threshold, the electronic device determines that the first user has passed authentication.

[0144] In this way, when the credibility of the first user is less than or equal to the credibility threshold, secondary authentication by the first user can accurately identify and prevent possible malicious behavior of users with low credibility, thereby improving the security and stability of the authority authentication system.

[0145] After the above step 51 , the authority authentication method further includes the following steps 61 to 62 .

[0146] Step 61: The electronic device obtains the number of secondary authentications of the first user.

[0147] In a possible implementation, a storage unit of the electronic device stores the number of secondary authentications corresponding to each user. The number of secondary authentications of the first user is obtained by reading the number of secondary authentications of the first user from the storage unit of the electronic device.

[0148] Step 62: When the number of secondary authentications of the first user is greater than or equal to a preset number, the electronic device forces the first user to log off.

[0149] It is understandable that when the number of secondary authentications of the first user is greater than or equal to the preset number, it means that the first user has performed secondary authentications more frequently, that is, the first user's credibility is less than or equal to the credibility threshold more frequently, indicating that there may be non-compliant operations during the operation of the first user, that is, there is a high possibility that the first user is at risk of security. By forcing the first user to go offline, the security of the system is ensured.

[0150] In this way, when the number of secondary authentications of the first user is greater than or equal to the preset number, the first user is forced to log off, which can accurately determine the security level of the first user and improve the security of the authority authentication system.

[0151] Figure 4 This is a flowchart of another method for authentication of permissions provided in an embodiment of the present application. Figure 4 As shown, taking the first user as a non-newly registered user as an example, the method can be implemented through S401-S418.

[0152] S401: The electronic device determines the credibility of the second user.

[0153] In a possible implementation, the reputation may be calculated based on the user's behavioral characteristics or the user's behavioral data.

[0154] Exemplarily, the user's credibility is obtained by performing a weighted sum based on the user's login location, the user's login device, the browser used by the user to log in, and the baseline detection result of the authority authentication system.

[0155] As another example, the credibility can be obtained by weighted summation based on activity indicators, compliance indicators, spatiotemporal indicators, security indicators, and scenario indicators.

[0156] Among them, the activity index is obtained by weighted summation based on the user's average daily operation frequency, session duration, and access density over a period of time.

[0157] The compliance index is calculated by taking a weighted sum of the proportion of user-infringing operations and the frequency of sensitive operations. For example, a user-infringing operation could be unauthorized access, while a sensitive operation could be data export.

[0158] The spatiotemporal index is obtained by weighted summation based on the proportion of users' frequently used login locations and the proportion of operations performed outside the company during working hours.

[0159] The security indicator may refer to the abnormality level of the authorization authentication system.

[0160] Scenario indicators are weighted and summed based on database type and compliance requirement level. For example, database type could be public database, core database, etc. Compliance requirement level could be the special restriction level for financial data under the General Data Protection Regulation (GDPR).

[0161] Determining credibility based on user behavioral characteristics or user behavioral data can break through the traditional identity authentication model and dynamically adjust the user's credibility.

[0162] Furthermore, in determining the second user's credibility, it is necessary to first obtain the user's behavioral data. The obtained user behavioral data can first be normalized to eliminate dimensional differences between different data types, thereby obtaining normalized data. For example, the normalization process can be Z-score normalization. The normalized data is then extracted using a sliding time window to obtain extracted data. The length of the sliding time window can be preset based on the business scenario. For example, if the business scenario is a financial scenario, the sliding time window can be 5 minutes; if the business scenario is an Internet of Things (IoT) scenario, the sliding time window can be 1 hour. Finally, the extracted data is filtered for outliers to prevent abnormal data from contaminating the credibility threshold calculation. For example, the behavioral data of extremely abnormal users can be deleted based on the boxplot method or the isolation forest algorithm, or the abnormal behavioral data of a specific user can be deleted. Furthermore, statistical analysis of the obtained second user's behavioral data can be used to identify the second user's typical behavioral patterns.

[0163] It is understandable that before determining the credibility of the second user, the second user must first pass identity authentication when registering or logging in to verify his or her identity information and permissions. When performing identity authentication, the user can perform preliminary authentication through the device fingerprint to ensure that the user is using a real device. For example, the device fingerprint can be obtained through the user's device identity document (ID), media access control (MAC) address, fingerprint and other information. In order to further verify the user's identity, other multi-factor authentication methods can also be combined to improve the accuracy and security of identity authentication. For example, multi-factor authentication methods can be biometrics and behavioral pattern analysis.

[0164] It should be noted that if the user is a newly registered user, after the user completes identity authentication through device fingerprint and multi-factor authentication, the user's reputation can be directly assigned. The user's reputation can be a default value; or the user's reputation can be determined based on the reputation of other users with similar permissions.

[0165] For example, a newly registered user's reputation score = A * Basic Reputation 1 + B * Basic Reputation 2. Basic Reputation 1 is calculated based on the sum of the reputation scores of other users with similar permissions to the user / the number of other users. Basic Reputation 2 is calculated based on information such as the user's login location, login device, and baseline scans. A and B are weights, and their specific values ​​are preset and can be set based on specific usage scenarios.

[0166] S402: The electronic device continuously monitors the operation of the first user.

[0167] By continuously monitoring the operations of the first user, the electronic device can analyze the first user's behavior patterns and behavioral characteristics in real time, and then dynamically adjust the first user's credibility and access rights, thereby realizing dynamic monitoring and permission management of the first user, and realizing more flexible, secure and efficient permission authentication, thereby more flexibly responding to security threats.

[0168] S403: The electronic device determines whether the first user has any abnormal access. If yes, execute S404; if no, execute S405.

[0169] It should be noted that after a user passes identity authentication, the electronic device continuously monitors and evaluates the user's behavioral data in real time, adjusting the user's reputation in real time based on this data. This dynamic adjustment of reputation can effectively identify and respond to abnormal user behavior while ensuring the security and stability of the authorization authentication system.

[0170] For example, user behavior data includes but is not limited to the type of resources accessed by the user, frequency, duration, access path, etc. By analyzing user behavior data, the user's reputation can be dynamically calculated.

[0171] Abnormal access can be unauthorized access, repeated access to sensitive resources, long periods of absence from login, high frequency of access to specific resources, unreasonable time intervals, etc.

[0172] S404: When the first user has abnormal access, the electronic device reduces the credibility of the first user and uses the reduced credibility as the credibility of the first user.

[0173] In the case of abnormal access by the first user, in addition to reducing the first user's credibility, the first user may even be required to undergo secondary authentication or be forced to log off.

[0174] When the first user has abnormal access, by quickly responding to the abnormal behavior and initiating multiple authentications, the problem of the permission authentication system crashing or the user being mistakenly blocked due to abnormal behavior can be avoided, thereby improving system stability.

[0175] S405: When there is no abnormal access by the first user, the electronic device increases the credibility of the first user and uses the increased credibility as the credibility of the first user.

[0176] The first user's non-abnormal access can also be understood as the first user accessing within the scope of their authorized permissions, that is, the first user's behavior is as expected, or the first user has successfully accessed the system multiple times in a row, or the first user has not made any abnormal access within a period of time. In this case, the user can be incentivized by increasing their credibility, extending their login validity period, improving their access rights, etc., to encourage them to maintain good behavior habits.

[0177] S406: The electronic device obtains the abnormality type and the compliance operation duration of the first user.

[0178] It should be noted that there is no strict order between obtaining the exception type and obtaining the compliance operation time of the first user in the above step S406. The exception type can be obtained first and then the compliance operation time of the first user, or the compliance operation time of the first user can be obtained first and then the exception type, or the exception type and the compliance operation time of the first user can be obtained at the same time. The embodiment of the present application does not make specific restrictions on this.

[0179] S407: The electronic device determines a first credibility threshold based on the credibility of the second user.

[0180] S408: The electronic device determines a second credibility threshold based on the first credibility threshold and the abnormality type.

[0181] S409: The electronic device determines a credibility threshold of the first user based on the second credibility threshold and the compliance operation duration of the first user.

[0182] S410: The electronic device determines whether the first user's credibility is less than or equal to the first user's credibility threshold. If so, execute S411; if not, execute S412.

[0183] S411: In response to the first user's credibility being less than or equal to a credibility threshold, the electronic device determines that the first user performs secondary authentication.

[0184] S412: In response to the first user's credibility being greater than a credibility threshold, the electronic device determines that the first user has passed authentication.

[0185] It should be noted that after executing the above step S412, continue to execute the above step S402.

[0186] After executing the above step S411, the electronic device determines whether the secondary authentication of the first user is successful in step S413. If so, the electronic device executes step S414; if not, the electronic device executes step S415.

[0187] S414: In response to the first user successfully completing the secondary authentication, the electronic device obtains the number of secondary authentications of the first user.

[0188] S415: In response to the first user failing to perform secondary authentication, the electronic device forces the first user to log off.

[0189] After executing step S414, the electronic device determines whether the number of secondary authentications of the first user is greater than or equal to a preset number in step S416. If so, the electronic device executes step S417; if not, the electronic device executes step S418.

[0190] S417: When the number of secondary authentications of the first user is greater than or equal to a preset number, the electronic device forces the first user to log off.

[0191] S418. When the number of secondary authentications of the first user is less than a preset number, the electronic device adds the first user to a risk management queue.

[0192] Among them, users in the risk management queue are key monitored users and are used to improve the security of the authority management system.

[0193] It should be noted that after executing the above step S418, continue to execute the above step S402.

[0194] Based on the above technical solution, the credibility threshold of the first user can be dynamically adjusted, taking into account the efficiency and accuracy of the credibility threshold calculation, thereby improving the accuracy of the credibility threshold. The credibility threshold of the first user can be adjusted according to the credibility of the second user, the type of anomaly, and the duration of the first user's compliance operation, which solves the problem of insufficient adaptability of fixed thresholds in a constantly changing environment, can reduce the misjudgment and omission of permission authentication caused by fixed thresholds, and ensure the security protection capabilities of the permission authentication system in different business scenarios. Not only does it improve the recognition accuracy of low-credibility users, but the dynamic adjustment of user credibility and credibility thresholds can achieve the optimal balance between security protection and business continuity of the permission authentication system, providing core access control capabilities for complex digital scenarios.

[0195] It should be noted that the above authorization authentication method is applicable to IoT devices and can be deployed in edge devices (for example, industrial gateways). Combining reputation threshold calculation with real-time reputation adjustment can reduce resource consumption and meet the requirements of low-latency scenarios.

[0196] The aforementioned authorization authentication method can be implemented based on existing software development tools and technical frameworks, eliminating the need for new technologies or servers. The computational power required to calculate the first user's credibility threshold can be provided by existing system servers and cloud computing resources. This implementation of the aforementioned authorization authentication method can reduce development cycles and costs, thereby enhancing the method's economic viability.

[0197] Figure 5 This is a schematic diagram of a permission authentication system provided in an embodiment of the present application. The permission authentication method provided in an embodiment of the present application can be applied to Figure 5 In the authorization authentication system shown, a user's reputation is calculated by performing a weighted summation based on the user's login location, login device, browser used for login, and baseline detection results of the authorization authentication system. The authorization authentication system includes a user terminal and a server terminal. The user terminal is used to record user operations, including the user's login location, login device, browser used for login, and baseline detection results of the authorization authentication system. The server terminal includes a control center and a security gateway. The control center can calculate the user's reputation by performing a weighted summation based on the user's login location, login device, browser used for login, and baseline detection results of the authorization authentication system. The control center can also calculate a reputation threshold based on the user's reputation. When the user initiates an authentication request to the security gateway, the security gateway compares the user's reputation with the reputation threshold. If the reputation is less than or equal to the reputation threshold, the user undergoes secondary authentication. If the reputation is greater than the reputation threshold, the user can access authorized resources within their user permissions and cannot access unauthorized resources within their user permissions.

[0198] As a specific example, take the case where the authority authentication system is applied to a financial system, the second users are financial approvers, and the number of second users is 10. The average value of the second user's credibility μ = 85, the standard deviation of the second user's credibility σ = 8, and k = 2. The first credibility threshold is determined based on the following formula (5).

[0199] T base =85-2*8=69 Formula (5)

[0200] The anomaly type is a phishing email attack, and the anomaly level is S. theat =0.7, α=0.2, then the second credibility threshold is determined based on the following formula (6).

[0201] T current =69*(1+0.2*0.7)=69*1.14≈79 Formula (6)

[0202] The first user is user A. User A’s compliance operation time is half a year. User A’s compliance coefficient is C. trust =0.6, β=0.1, then the credibility threshold of user A is determined based on the following formula (7).

[0203] T individual =79*(1-0.1*0.6)≈79*0.94≈74 Formula (7)

[0204] Among them, the reputation of user A is 75. By comparing the reputation of user A with the reputation threshold, that is, 75>74, user A passes the authentication.

[0205] However, if user A accesses sensitive approvals multiple times in a short period of time, this behavior will be reported to the electronic device, which can provide a basis for abnormal audits and can also be used for subsequent calculation of user A's credibility.

[0206] If the first user is user B, and user B is a newly registered user, user B's credibility threshold is the second credibility threshold, i.e., 79. User B's credibility is 73. By comparing user B's credibility with the credibility threshold, i.e., 73 < 79, user B needs to undergo secondary authentication. For example, secondary authentication can be facial recognition, approval by a superior, etc.

[0207] The embodiment of the present application can divide the authority authentication device into functional modules or functional units according to the above method example. For example, each functional module or functional unit can be divided corresponding to each function, or two or more functions can be integrated into one processing module. The above-mentioned integrated module can be implemented in the form of hardware or in the form of software functional modules or functional units. Among them, the division of modules or units in the embodiment of the present application is schematic and is only a logical functional division. There may be other division methods in actual implementation.

[0208] Figure 6 A structural schematic diagram of an authority authentication device 60 provided in an embodiment of the present application, wherein the authority authentication device 60 includes: an acquisition unit 601, for acquiring the credibility of a second user in response to an authentication request of a first user, where the second user includes the first user and other users with similar permissions to the first user, and the credibility is used to indicate the trustworthiness of the user; a determination unit 602, for determining a credibility threshold of the first user based on the credibility of the second user; and an authentication unit 603, for performing authority authentication on the first user based on the credibility and the credibility threshold of the first user.

[0209] In one possible implementation, the determination unit 602 is specifically used to: when the first user is a newly registered user and no abnormality occurs in the authority authentication system, determine the first credibility threshold as the credibility threshold of the first user based on the credibility of the second user; when the first user is a newly registered user and an abnormality occurs in the authority authentication system, determine the second credibility threshold as the credibility threshold of the first user based on the first credibility threshold and the abnormality type, and the abnormality type is used to indicate the type of abnormality that occurs in the authority authentication system; when the first user is not a newly registered user, determine the credibility threshold of the first user based on the second credibility threshold and the compliance operation time of the first user, and the compliance operation time is used to indicate the time duration of the first user's operation that complies with the regulations.

[0210] In a possible implementation, the determining unit 602 is specifically configured to determine a first credibility threshold based on an average value of the second user's credibility and a standard deviation of the second user's credibility, where the first credibility threshold is positively correlated with the average value and negatively correlated with the standard deviation.

[0211] In one possible implementation, the determination unit 602 is specifically used to: determine the corresponding abnormality level based on the abnormality type, and the abnormality type corresponds one-to-one to the abnormality level; determine the second credibility threshold based on the first credibility threshold and the abnormality level, and the second credibility threshold is positively correlated with the first credibility threshold, and the second credibility threshold is positively correlated with the abnormality level.

[0212] In one possible implementation, the determination unit 602 is specifically used to: determine the compliance coefficient of the first user based on the compliance operation duration of the first user, where the compliance coefficient is used to indicate the degree coefficient of the compliance behavior of the first user; determine the credibility threshold of the first user based on the second credibility threshold and the compliance coefficient, where the credibility threshold is positively correlated with the second credibility threshold, and the credibility threshold is negatively correlated with the compliance coefficient.

[0213] In one possible implementation, the second user's credibility is related to the second user's behavior, and the device further includes: a second determination unit, configured to re-determine the first user's credibility threshold when a deviation between the second user's behavior and the second user's historical behavior is greater than a deviation threshold.

[0214] In one possible implementation, the authentication unit 603 is specifically configured to: in response to the first user's credibility being less than or equal to a credibility threshold, determine that the first user undergoes secondary authentication; in response to the first user's credibility being greater than the credibility threshold, determine that the first user passes authentication.

[0215] In a possible implementation, the device further includes: a second acquisition unit, configured to acquire the number of secondary authentications of the first user; and a comparison unit, configured to force the first user to log off if the number of secondary authentications of the first user is greater than or equal to a preset number.

[0216] Through the description of the above embodiments, those skilled in the art will clearly understand that for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above. The specific working processes of the above-described systems, devices, and units can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0217] An embodiment of the present application provides a computer program product containing instructions. When the computer program product is run on an electronic device, the electronic device executes the permission authentication method in the above method embodiment.

[0218] An embodiment of the present application also provides a computer-readable storage medium, which stores instructions. When the instructions are executed on an electronic device, the electronic device executes the permission authentication method in the method flow shown in the above method embodiment.

[0219] Among them, the computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination thereof. More specific examples of computer-readable storage media (a non-exhaustive list) include: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a register, a hard disk, an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above, or any other form of computer-readable storage medium known in the art. An exemplary storage medium is coupled to a processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be an integral part of the processor. The processor and the storage medium can be located in an application-specific integrated circuit (ASIC). In the embodiments of the present application, a computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.

[0220] Since the permission authentication device, computer-readable storage medium, and computer program product in the embodiments of the present application can be applied to the above method, the technical effects that can be obtained can also refer to the above method embodiments, and the embodiments of the present application will not be repeated here.

[0221] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0222] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0223] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0224] The above are only specific embodiments of the present application, but the scope of protection of the present application is not limited thereto. Any changes or replacements within the technical scope disclosed in this application should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.

Claims

1. A method for authentication of authority, characterized in that: The method comprises: In response to an authentication request from a first user, obtaining a reputation of a second user, where the second user includes the first user and other users with similar permissions to the first user, the reputation being used to indicate a user's trustworthiness; determining a credibility threshold of the first user based on the credibility of the second user; Based on the credibility and credibility threshold of the first user, the first user is authenticated.

2. The method according to claim 1, characterized in that The determining the credibility threshold of the first user based on the credibility of the second user includes: When the first user is a newly registered user and no abnormality occurs in the authority authentication system, determining a first credibility threshold as the credibility threshold of the first user based on the credibility of the second user; When the first user is the newly registered user and an abnormality occurs in the authority authentication system, determining a second credibility threshold as the credibility threshold of the first user based on the first credibility threshold and an abnormality type, wherein the abnormality type indicates the type of abnormality that occurred in the authority authentication system; In the case that the first user is not a newly registered user, the credibility threshold of the first user is determined based on the second credibility threshold and the compliance operation time of the first user, where the compliance operation time is used to indicate the time duration of the first user's operation that complies with regulations.

3. The method according to claim 2, characterized in that The process of determining the first credibility threshold includes: The first credibility threshold is determined based on an average value of the second user's credibility and a standard deviation of the second user's credibility, wherein the first credibility threshold is positively correlated with the average value and negatively correlated with the standard deviation.

4. The method according to claim 2, characterized in that The process of determining the second credibility threshold includes: Determine a corresponding abnormality level based on the abnormality type, wherein the abnormality type corresponds to the abnormality level in a one-to-one manner; The second credibility threshold is determined based on the first credibility threshold and the abnormality level, wherein the second credibility threshold is positively correlated with the first credibility threshold and the second credibility threshold is positively correlated with the abnormality level.

5. The method according to claim 2, characterized in that The determining the credibility threshold of the first user based on the second credibility threshold and the compliance operation duration of the first user includes: Determining a compliance coefficient of the first user based on a compliance operation duration of the first user, where the compliance coefficient is used to indicate a degree of compliance behavior of the first user; Based on the second credibility threshold and the compliance coefficient, a credibility threshold of the first user is determined, where the credibility threshold is positively correlated with the second credibility threshold and negatively correlated with the compliance coefficient.

6. The method according to claim 1, characterized in that The second user's reputation is related to the second user's behavior. After determining the first user's reputation threshold based on the second user's reputation, the method further includes: In a case where the deviation between the behavior of the second user and the historical behavior of the second user is greater than a deviation threshold, the credibility threshold of the first user is determined again.

7. The method according to claim 1, characterized in that The performing authority authentication on the first user based on the credibility and credibility threshold of the first user includes: In response to the first user's credibility being less than or equal to the credibility threshold, determining that the first user undergoes secondary authentication; In response to the first user's reputation being greater than the reputation threshold, it is determined that the first user undergoes secondary authentication.

8. The method according to claim 7, characterized in that After determining that the first user undergoes secondary authentication in response to the first user's credibility being less than or equal to the credibility threshold, the method further includes: Obtaining the number of secondary authentications of the first user; When the number of secondary authentications of the first user is greater than or equal to a preset number, the first user is forced to log off.

9. A permission authentication device, characterized in that: The device comprises: an acquiring unit, configured to acquire, in response to an authentication request from a first user, a credibility of a second user, where the second user includes the first user and other users with similar permissions to the first user, the credibility being used to indicate a degree of trustworthiness of the user; a determining unit, configured to determine a credibility threshold of the first user based on the credibility of the second user; An authentication unit is configured to perform authority authentication on the first user based on the first user's credibility and a credibility threshold.

10. An electronic device, characterized in that: include: A processor and a communication interface; the communication interface is coupled to the processor, and the processor is used to run a computer program or instruction to implement the permission authentication method according to any one of claims 1 to 8.

11. A computer-readable storage medium, characterized in that The computer-readable storage medium stores instructions. When the electronic device executes the instructions, the electronic device executes the permission authentication method according to any one of claims 1 to 8.

12. A computer program product, characterized in that The computer program product includes computer instructions, and when the computer instructions are executed on an electronic device, the electronic device executes the permission authentication method according to any one of claims 1 to 8.