Unified authority management method and system, electronic equipment and medium
By designing a unified enterprise rights management system, the problems of multiple systems being scattered and complex configurations in traditional rights management are solved, centralized and refined rights management is achieved, management efficiency and security are improved, and dynamic adjustment and unified configuration are supported.
Patent Information
- Application Number
- CN202510718613.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-30
- Publication Date
- 2025-09-12
AI Technical Summary
Traditional permission management methods have problems such as decentralized permission management across multiple systems, complex configuration, high maintenance costs, inconsistent permissions, and difficulty maintaining them. Especially in enterprise information management, administrators need to repeatedly configure permissions in each system, increasing workload and the risk of errors.
Adopting a unified permission management approach, by clarifying the relationship between applications, roles, users and resources, we design a unified enterprise permission management system, including application management, resource management, role management, user management, authorization management and a unified login module, to achieve centralized and refined permission management for multiple application systems.
It simplifies permission configuration and maintenance, improves management efficiency, solves the problems of permission abuse and insufficiency, provides flexible permission management and dynamic adjustment mechanism, and ensures the instant update of permission configuration and efficient maintenance of the system.
Smart Images

Figure CN120632908A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure belongs to the field of information management technology, and in particular relates to a unified authority management method, system, electronic equipment and medium. Background Art
[0002] In enterprise information management, rights management is a core component of system design. As enterprise businesses continue to expand, the number of backend systems gradually increases, and user roles and identities become increasingly complex, the importance of rights management becomes increasingly prominent.
[0003] Traditional permission management methods such as Figure 1 As shown. In response to the user's request to create an account in Application A, the administrator creates account A1 in Application A. After the creation is successful, the administrator notifies the user of account A1. In response to the user's request to create an account in Application B, the administrator creates account A1 in Application B. After the creation is successful, the administrator notifies the user of account A2. The administrator creates role R1 in Application A and role R2 in Application B. In response to the user's request to apply for permissions in Application A, the administrator authorizes role R1 to access resources in Application A. After the authorization is successful, the user is notified that account A1 is authorized successfully. In response to the user's request to apply for permissions in Application B, the administrator authorizes role R2 to access resources in Application B. After the authorization is successful, the user is notified that account B1 is authorized successfully. The user logs in to Application A and accesses the resources of Application A. Application A reports that the login and access are successful. The user logs in to Application B and accesses the resources of Application B. Application B reports that the login and access are successful.
[0004] As can be seen from the above process, traditional permission management typically uses a decentralized and independent approach to manage permissions across enterprise application systems. Each system has its own permission management mechanism, lacking unified coordination with other systems. Permission configuration is often based on applications, resulting in a coarse granularity and relying primarily on manual management and maintenance.
[0005] Traditional permission management models suffer from the following major issues: First, decentralized permission management across multiple systems. Enterprises often use multiple systems (such as financial management systems, CRM, and ERP) provided by different vendors. These systems operate independently and have inconsistent permission management mechanisms. This forces administrators to repeatedly configure permissions in each system, increasing workload and the risk of errors. Second, permissions across different systems are difficult to maintain consistency, potentially leading to redundant or insufficient permissions. Changes in user roles or departments require individual permission configuration adjustments, resulting in high maintenance costs.
[0006] Therefore, it is currently necessary to propose a permission management method to achieve refined permission allocation, unified management, and efficient operation, while improving management efficiency and reducing security risks to meet the permission management needs in complex enterprise scenarios. Summary of the Invention
[0007] To solve the above problems, the present disclosure provides a unified permission management method, system, electronic device and medium, which uses clear relationships between applications, roles, users and resources to achieve centralized and refined permission management of multiple application systems of an enterprise.
[0008] In a first aspect, a unified rights management method is provided, comprising:
[0009] The application management module receives an application registration request carrying application system information and generates an application system ID based on the application system information, wherein the application system information includes: application name, application description, application type and application access address;
[0010] The resource management module receives a resource registration request carrying resource information and generates a resource identifier based on the resource information;
[0011] The role management module receives role creation requests and creates roles; receives role association requests that carry roles and role permission scopes, and establishes an association between the roles and role permission scopes; wherein the role permission scope is a macro application-level permission described by the relationship between the application system ID and the configured application operation permissions, or an operation permission for specific resources within the application described by the relationship between the application system ID, resource identifier, and the configured resource operation permissions;
[0012] The user management module receives a user account creation request carrying user information and creates a user account using the user information;
[0013] The authorization management module receives the authorization request carrying the user account and the corresponding role, and uses the association established by the role management module to establish the association between the user account, the corresponding role and the role authority range;
[0014] The authorization management module receives resource access requests carrying user accounts and application system IDs, and uses the application's access address to push corresponding applications to the user account; according to the association relationship established between the user account, the corresponding role and the role's permission range, the module authorizes the user with corresponding operation permissions.
[0015] Furthermore, before the authorization management module receives the resource access request from the user carrying the user account and application system ID, the following steps are further included:
[0016] The unified login module receives the login request with the user account and password, and after verification, displays the application system ID registered in the application management module;
[0017] The unified login module receives the application system ID, and sends the user account and application system ID along with the resource access request to the authorization management module.
[0018] Furthermore, the method further includes: the role management module receiving an update request carrying the role and the updated role authority scope, and updating the association between the role and the role authority scope using the updated role authority scope.
[0019] Furthermore, resources include: page resources, function resources, API interface resources, data table resources and file resources. The specific operation permissions for each type of resource include: viewing, inserting, deleting, modifying, editing and calling part or all of them.
[0020] Furthermore, it also includes:
[0021] The application management module receives an application status change request and performs access management on the application according to the application status in the application status change request, wherein the application status includes: enabled, disabled, and temporarily frozen.
[0022] In a second aspect, a unified rights management system is provided, comprising: an application management module, a resource management module, a role management module, a user management module, and an authorization management module, wherein:
[0023] An application management module is configured to receive an application registration request carrying application system information and generate an application system ID based on the application system information, wherein the application system information includes: application name, application description, application type, and application access address;
[0024] The resource management module is used to receive a resource registration request carrying resource information and generate a resource identifier based on the resource information;
[0025] The role management module is configured to receive role creation requests and create roles; receive role association requests containing roles and role permission scopes, and establish an association between roles and role permission scopes; wherein the role permission scope is a macro application-level permission described by the relationship between the application system ID and the configured application operation permissions, or an operation permission for a specific resource within an application described by the relationship between the application system ID, resource identifier, and the configured resource operation permissions;
[0026] The user management module is used to receive a user account creation request carrying user information and create a user account using the user information;
[0027] The authorization management module is used to receive authorization requests carrying user accounts and corresponding roles, and use the association relationship established by the role management module to establish an association relationship between the user account, the corresponding role and the role authority range; and receive resource access requests carrying user accounts and application system IDs, and use the application's access address to push the corresponding application to the user account; according to the association relationship established between the user account, the corresponding role and the role authority range, authorize the user to have the corresponding operation permission.
[0028] Furthermore, it also includes: a unified login module;
[0029] The unified login module is used to receive login requests carrying user account and password. After verification, it displays the application system ID registered in the application management module; after receiving the application system ID, it carries the user account and application system ID in the resource access request and sends it to the authorization management module.
[0030] Furthermore, the role management module is further configured to receive an update request carrying a role and an updated role authority scope, and update the association between the role and the role authority scope using the updated role authority scope.
[0031] In a third aspect, an electronic device is provided, comprising a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other via the communication bus;
[0032] Memory for storing computer programs;
[0033] The processor is configured to implement the steps of the above method when executing the program stored in the memory.
[0034] According to a fourth aspect, a computer storage medium is provided, wherein a computer program is stored in the computer storage medium, and when the computer program is executed by a processor, the steps of the above method are implemented.
[0035] Compared with the prior art, the present disclosure has the following advantages:
[0036] This disclosure simplifies the configuration and maintenance of permissions in multiple application systems within an enterprise's backend system by unifying the management of applications, roles, users, and resources, meeting the enterprise's needs for efficient, secure, and flexible permission management. Furthermore, by refining permission control to the resource level, it addresses the problems of permission abuse and insufficient permissions, and improves the flexibility and accuracy of permission management. At the same time, this disclosure utilizes the role management module to update the scope of role permissions, providing a dynamic adjustment and automatic synchronization mechanism for permissions, ensuring immediate updates to permission configurations and effectively improving system maintenance efficiency.
[0037] Other features and advantages of the present disclosure will be described in the following description, and in part will become apparent from the description, or will be understood by practicing the present disclosure. The purposes and other advantages of the present disclosure can be realized and obtained by the structures indicated in the description, claims and drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0038] In order to more clearly illustrate the embodiments of the present disclosure or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present disclosure. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0039] Figure 1 Shown is a schematic diagram of a traditional rights management method;
[0040] Figure 2 A schematic diagram of a rights management system interacting with a backend according to an embodiment of the present disclosure is shown;
[0041] Figure 3 A schematic diagram of a rights management method according to an embodiment of the present disclosure is shown;
[0042] Figure 4 A block diagram of a rights management system according to an embodiment of the present disclosure is shown. DETAILED DESCRIPTION
[0043] To make the objectives, technical solutions, and advantages of the embodiments of the present disclosure more clear, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present disclosure, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present disclosure without making any creative efforts shall fall within the scope of protection of the present disclosure.
[0044] This paper proposes a unified permissions management solution. By clarifying the relationships between applications, roles, users, and resources, a unified enterprise permissions management system based on these relationships is designed. This approach aims to achieve centralized and refined permissions management across multiple enterprise backend systems. This system implements unified configuration and dynamic adjustment of permissions through application registration, resource management, and the association of applications with roles, roles with resources, and users with roles.
[0045] The present invention is a unified enterprise background authority management system based on applications, roles, users and resources, such as Figure 2As shown, it includes six modules: application management module, resource management module, role management module, user management module, authorization management module and unified login module.
[0046] The following describes the solution of the present disclosure from the perspective of the user and the perspective of the machine:
[0047] (1) Explain the unified rights management system disclosed in this disclosure from the user's perspective:
[0048] The application management module is the foundation of the unified permission management system and is used to register various back-end systems of the enterprise into the unified permission management system. Administrators can use this module to register multiple application systems inside or outside the enterprise and need to fill in detailed information, including application name, description, type (such as Web application, API service, etc.) and application address. The system will automatically generate a unique identifier for each registered application - the application system ID (Application ID), which serves as a credential to distinguish different applications and is used in scenarios such as permission allocation and unified login (SSO) to ensure management accuracy. In addition, the application management module also supports application status management, allowing administrators to enable or disable an application, or temporarily freeze its access rights, so as to limit access to the application in emergency situations such as when security vulnerabilities are discovered, thereby improving overall security.
[0049] The resource management module is responsible for the granular management of resources across enterprise application systems, including pages, functions, API interfaces, data tables, files, and other resources. During permissions management, resources are typically categorized by access levels, such as view, edit, delete, and manipulate permissions. Administrators can register resources for each application system and categorize them by type, such as page resources, interface resources, and file resources. Each resource type can be further divided into specific operational permissions. For example, page resources can be divided into "view page" and "edit page" permissions; interface resources can be divided into "call interface" and "modify interface" permissions. Resource management supports multi-level categorization, allowing a page resource to include multiple sub-resources (such as buttons and forms), each of which can be assigned separate permissions, ensuring granular operations. Each resource is assigned a clear description and unique identifier, helping administrators more intuitively identify resources when configuring roles and permissions. Furthermore, resources can be tagged based on type, priority, sensitivity, and other factors, assisting administrators in making more precise decisions when allocating permissions.
[0050] The role management module is a core component of the unified permissions management system. It aggregates different permissions through roles, simplifying user permission management. A role represents a user's identity within the system. Administrators can define roles to control the applications and resources that role can access. Administrators can create multiple roles, name and describe each role, associate roles with multiple applications, and assign corresponding resource permissions within each application. Role permissions can range from macro-level application permissions to specific resource operations, such as page viewing permissions and button operation permissions. When configuring role permissions, administrators can select specific applications and resources within them and assign different permissions to each resource. For example, a "Finance Manager" role might only have the permission to view reports, while a "Finance Director" role might have both the permission to view and edit reports. The module also supports dynamic permission allocation, allowing flexible adjustment of role permissions based on business needs. For example, when new features are launched or business processes change, administrators can adjust role resource permissions in a timely manner to ensure business continuity.
[0051] The user management module centrally manages all user accounts in the system. In modern enterprise information environments, user identities may span multiple application systems, involving complex roles and permissions. Therefore, this module needs to flexibly address the diverse needs of user creation and maintenance. Administrators can use this module to create new users, modify user information, and delete users. User information typically includes username, employee ID, email address, mobile phone number, and department. The system supports unified management of the same account across multiple application systems, eliminating the need to create multiple accounts for the same user in different systems. Administrators only need to create one account for a user and then uniformly configure their permissions across different applications. The user management module also supports user status management, such as enabling, disabling, and locking. This ensures that accounts can be promptly disabled when employees leave or no longer require system access, ensuring system security. A user can hold multiple roles simultaneously, potentially across multiple application systems. For example, a user could have the "Administrator" role in System A and the "Auditor" role in System B. The system would then assign permissions to each role accordingly. Since each application system has user information and corresponding permission information, the administrator can obtain user information and permission information from each application system, and on this basis, use the user management module and role management module disclosed in this disclosure to configure permissions in more detail.
[0052] The authorization management module is a key link in achieving the association between users, roles, applications, and resources. Through this module, administrators can assign different users to different roles, thereby granting users corresponding system permissions. Administrators can use the module to associate users with roles. A user can have multiple roles at the same time, and the system will automatically grant corresponding permissions based on the roles associated with the user. In addition, the authorization management module also supports dynamic adjustment of roles. Administrators can flexibly adjust user roles based on business needs. For example, when a user's position or responsibilities change, their role and permissions can be adjusted in a timely manner. To improve management efficiency, the system also supports batch authorization operations. Administrators can assign the same role or permissions to multiple users at once, which is particularly important for large-scale permission adjustments.
[0053] The unified login module (single sign-on, SSO) is designed to enhance the user experience, reduce multiple login operations, and allow users to access multiple application systems within the enterprise through a one-time login authentication. Users only need to log in once to access all relevant application systems within their permissions, thus avoiding the tedious process of logging in repeatedly between different systems. SSO achieves this function by managing the user's authentication information in the background. In addition, the system supports integration with multiple application systems within the enterprise to achieve single sign-on across systems. For example, after logging into the enterprise unified portal, users can directly access systems such as CRM and ERP without having to enter their username and password again. In terms of security, the system provides strong authentication protection to ensure that data is not leaked. At the same time, in terms of session management, when the user logs out or the session times out, the system automatically terminates access rights to all application systems, thereby enhancing overall security.
[0054] (2) Explain the unified rights management method disclosed in this disclosure from the user's perspective:
[0055] The disclosed enterprise backend unified permission management method based on applications, roles, users and resources has the characteristics of refined permission allocation, unified management and efficient operation. From the user's perspective, Figure 3 The specific steps are as follows:
[0056] Step 1: The administrator first registers a new application system through the "Application Management Module". For example, the administrator registers a new financial management system (financial system). During the registration process, the administrator needs to fill in the basic information of the application, including the application name (such as "Financial Management System"), application description (such as "used for the management and report generation of company financial data"), application type (such as Web application, API service, etc.) and application access address (such as http: / / finance.company.com). The system will generate a unique identifier (Application ID) based on this information and register the application to the unified permission management system to facilitate subsequent permission configuration and management. At the same time, the administrator can set the status of the application in this module, such as enabled or disabled, so that it can be adjusted in time when security or business needs change.
[0057] Step 2: In the "Resource Management Module", the administrator registers all resources in the financial system. The resources here can be of different types, such as page resources, interface resources, database tables or files, etc. The administrator first registers all relevant resources for the financial system (such as "financial report page", "report editing function", "financial data table", etc.). Each resource will be subdivided into different operation permissions. For example, page resources can be divided into permissions such as "view report page" and "edit report page"; interface resources can be divided into permissions such as "call financial data interface" and "export financial report interface". By fine-grained management of each resource, the administrator can ensure that each role has precise permissions in each system, thereby avoiding excessive or insufficient allocation of permissions.
[0058] Step 3: In the "Role Management Module," the administrator creates a new role, such as the "Finance Manager" role. The administrator provides a detailed description for the role, such as "Responsible for reviewing financial statements and managing financial data." After the role is defined, the administrator associates the role with the financial management system and assigns appropriate resource permissions. For example, the "Finance Manager" role is granted the "View Financial Statements" and "Edit Reports" permissions. At the same time, the administrator can further refine permissions, such as granting the role access to specific report functions, the ability to edit financial data, or export financial data. The purpose of this step is to bind resource permissions to the role, ensuring that in subsequent user management, any user assigned to the role will automatically obtain the corresponding permissions.
[0059] Step 4: In the "User Management Module", the administrator creates a new user account, such as "Zhang San", and enters the user's basic information, including user name (such as "zhangsan"), email address, employee number (such as "1001"), department (such as "Finance Department"), etc.
[0060] Step 5: In the "Authorization Management Module," the administrator performs authorization. The administrator associates the "Zhang San" user with the permissions of the "Financial Manager" role, ensuring that "Zhang San" can access resources in the financial management system and perform corresponding operations (such as viewing and editing reports). During the authorization process, the administrator can also perform batch authorization. If multiple users require the same permissions or roles, they can be assigned the same role at once, improving efficiency.
[0061] Step 6: Zhang San uses the "Unified Login Module (SSO)" to perform single sign-on. Zhang San enters authentication information (such as user name and password) once to log in to the enterprise unified portal system, and the system will verify his identity information. Through the SSO mechanism, Zhang San does not need to log in to other application systems again, and can directly access the financial management system and other related systems without repeatedly entering the user name and password. After accessing the financial management system, the system will automatically grant Zhang San the permission to view and edit reports based on the permissions of the "Financial Director" role, ensuring that he can successfully complete his work tasks according to his role permissions. The system will also manage Zhang San's session to ensure that when he exits the system, all permissions and session information will be terminated in a timely manner to ensure system security.
[0062] (3) Explain the unified rights management method disclosed in this disclosure from the perspective of a machine:
[0063] The unified rights management method disclosed herein includes the following steps:
[0064] Step 101: The application management module receives an application registration request carrying application system information, and generates an application system ID based on the application system information.
[0065] The application system information includes: application name, application description, application type and application access address.
[0066] Step 102: The resource management module receives a resource registration request carrying resource information and generates a resource identifier based on the resource information.
[0067] In this step 102, the resources include: page resources, function resources, API interface resources, data table resources and file resources.
[0068] Step 103: The role management module receives the role creation request and creates the role; receives the role association request carrying the role and the role authority range, and establishes an association relationship between the role and the role authority range.
[0069] The role permission scope is the macro application-level permission described by the relationship between the application system ID and the configured application operation permissions, or the operation permissions of specific resources within the application described by the association between the application system ID, resource identifier and configured resource operation permissions.
[0070] Here, the role management module can be used to configure specific operation permissions for each type of resource. The specific operation permissions for each type of resource include: viewing, inserting, deleting, modifying, editing, and calling some or all of them.
[0071] Step 104: The user management module receives the user account creation request carrying the user information, and creates a user account using the user information.
[0072] Step 105: The authorization management module receives the authorization request carrying the user account and the corresponding role, and uses the association established by the role management module to establish an association between the user account, the corresponding role, and the role authority range.
[0073] Step 106: Receive a resource access request carrying the user account and application system ID, and use the application access address to push the corresponding application to the user account; according to the association relationship established between the user account, the corresponding role and the role authority range, authorize the user to have the corresponding operation authority.
[0074] Furthermore, in order to improve user experience, reduce multiple login operations, and allow users to access multiple application systems within the enterprise through a single login authentication, before the authorization management module receives the user's resource access request carrying the user account and application system ID, it also includes:
[0075] The unified login module receives the login request with the user account and password, and after verification, displays the application system ID registered in the application management module;
[0076] The unified login module receives the application system ID, and sends the user account and application system ID along with the resource access request to the authorization management module.
[0077] Furthermore, in order to achieve dynamic adjustment of permissions, the unified permission management method further includes: the role management module receives an update request carrying a role and an updated role permission range, and updates the association between the role and the role permission range using the updated role permission range.
[0078] Furthermore, the unified permission management method further includes: the application management module receiving an application status change request, and performing access management on the application according to the application status in the application status change request, wherein the application status includes: enabled, disabled, and temporarily frozen.
[0079] In the solution of the embodiment of the present disclosure, each module is used to coordinate permission configuration, which is highly flexible. In the solution of the embodiment of the present disclosure, permission allocation is performed based on roles and resources rather than applications, and the granularity is finer than that of the transmitted configuration solution, which can meet the needs of refinement. To a large extent, it avoids users from obtaining permissions beyond their actual needs, reduces security risks, and affects normal business operations due to insufficient permissions. Furthermore, the solution of the present disclosure is to uniformly manage the permissions of each application, simplifying maintenance. And the resource permission allocation is refined, and administrators can allocate permissions at a higher level, and can also accurately configure the permissions of specific resources to specific functions or data, making permission management clear. This is because the mapping relationship between resources and role permission ranges in the solution of the present disclosure is clear. On the other hand, the precise permission allocation ensures that sensitive data or functions will not be accessed by unauthorized users, and to a large extent avoids data leakage and business risks, and ensures data security.
[0080] (4) Explain the unified rights management system of the present disclosure from the perspective of the machine:
[0081] Based on the above method, the embodiment of the present disclosure also provides a unified authority management system corresponding to the above method, such as Figure 4 As shown, it includes: application management module, resource management module, role management module, user management module and authorization management module, among which:
[0082] An application management module is configured to receive an application registration request carrying application system information and generate an application system ID based on the application system information, wherein the application system information includes: application name, application description, application type, and application access address;
[0083] The resource management module is used to receive a resource registration request carrying resource information and generate a resource identifier based on the resource information;
[0084] The role management module is configured to receive role creation requests and create roles; receive role association requests containing roles and role permission scopes, and establish an association between roles and role permission scopes; wherein the role permission scope is a macro application-level permission described by the relationship between the application system ID and the configured application operation permissions, or an operation permission for a specific resource within an application described by the relationship between the application system ID, resource identifier, and the configured resource operation permissions;
[0085] The user management module is used to receive a user account creation request carrying user information and create a user account using the user information;
[0086] The authorization management module is used to receive authorization requests carrying user accounts and corresponding roles, and use the association relationship established by the role management module to establish an association relationship between the user account, the corresponding role and the role authority range; and receive resource access requests carrying user accounts and application system IDs, and use the application's access address to push the corresponding application to the user account; according to the association relationship established between the user account, the corresponding role and the role authority range, authorize the user to have the corresponding operation permission.
[0087] Furthermore, it also includes: a unified login module;
[0088] The unified login module is used to receive login requests carrying user account and password. After verification, it displays the application system ID registered in the application management module; after receiving the application system ID, it carries the user account and application system ID in the resource access request and sends it to the authorization management module.
[0089] Furthermore, the role management module is further configured to receive an update request carrying a role and an updated role authority scope, and update the association between the role and the role authority scope using the updated role authority scope.
[0090] Based on the same inventive concept as the above disclosure, the present disclosure also provides an electronic device. The electronic device of the present disclosure embodiment includes at least one processor and at least one memory electrically connected to each other, the memory being electrically connected to the processor, wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method described above.
[0091] It should be noted that the electrical connection between the above-mentioned units does not necessarily mean the connection between lines. An indirect connection method can be applied to the embodiments of the present disclosure as long as the purpose of the present disclosure is achieved.
[0092] Based on the same inventive concept, the present disclosure further provides a computer storage medium, wherein the computer storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the above method are implemented.
[0093] Although the present disclosure has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present disclosure.
Claims
1. A unified rights management method, characterized in that: include: The application management module receives an application registration request carrying application system information and generates an application system ID based on the application system information, wherein the application system information includes: application name, application description, application type and application access address; The resource management module receives a resource registration request carrying resource information and generates a resource identifier based on the resource information; The role management module receives role creation requests and creates roles; receives role association requests that carry roles and role permission scopes, and establishes an association between the roles and role permission scopes; wherein the role permission scope is a macro application-level permission described by the relationship between the application system ID and the configured application operation permissions, or an operation permission for specific resources within the application described by the relationship between the application system ID, resource identifier, and the configured resource operation permissions; The user management module receives a user account creation request carrying user information and creates a user account using the user information; The authorization management module receives the authorization request carrying the user account and the corresponding role, and uses the association established by the role management module to establish the association between the user account, the corresponding role and the role authority range; The authorization management module receives resource access requests carrying user accounts and application system IDs, and uses the application's access address to push corresponding applications to the user account; according to the association relationship established between the user account, the corresponding role and the role's permission range, the module authorizes the user with corresponding operation permissions.
2. The method according to claim 1, characterized in that Before the authorization management module receives the user's resource access request carrying the user account and application system ID, it also includes: The unified login module receives the login request with the user account and password, and after verification, displays the application system ID registered in the application management module; The unified login module receives the application system ID, and sends the user account and application system ID along with the resource access request to the authorization management module.
3. The method according to claim 1, characterized in that Also includes: The role management module receives an update request carrying a role and an updated role authority scope, and updates an association between the role and the role authority scope using the updated role authority scope.
4. The method according to any one of claims 1 to 3, characterized in that: Resources include: Page resources, function resources, API interface resources, data table resources, and file resources. Specific operation permissions for each type of resource include: viewing, inserting, deleting, modifying, editing, and calling some or all of them.
5. The method according to claim 1, characterized in that Also includes: The application management module receives an application status change request and performs access management on the application according to the application status in the application status change request, wherein the application status includes: enabled, disabled, and temporarily frozen.
6. A unified rights management system, characterized in that: include: Application management module, resource management module, role management module, user management module and authorization management module, including: An application management module is configured to receive an application registration request carrying application system information and generate an application system ID based on the application system information, wherein the application system information includes: application name, application description, application type, and application access address; The resource management module is used to receive a resource registration request carrying resource information and generate a resource identifier based on the resource information; The role management module is configured to receive role creation requests and create roles; receive role association requests containing roles and role permission scopes, and establish an association between roles and role permission scopes; wherein the role permission scope is a macro application-level permission described by the relationship between the application system ID and the configured application operation permissions, or an operation permission for a specific resource within an application described by the relationship between the application system ID, resource identifier, and the configured resource operation permissions; The user management module is used to receive a user account creation request carrying user information and create a user account using the user information; The authorization management module is used to receive authorization requests carrying user accounts and corresponding roles, and use the association relationship established by the role management module to establish an association relationship between the user account, the corresponding role and the role authority range; and receive resource access requests carrying user accounts and application system IDs, and use the application's access address to push the corresponding application to the user account; according to the association relationship established between the user account, the corresponding role and the role authority range, authorize the user to have the corresponding operation permission.
7. The system according to claim 6, characterized in that Also includes: Unified login module; The unified login module is used to receive login requests carrying user account and password. After verification, it displays the application system ID registered in the application management module; after receiving the application system ID, it carries the user account and application system ID in the resource access request and sends it to the authorization management module.
8. The system according to claim 6, characterized in that The role management module is further configured to receive an update request carrying a role and an updated role authority scope, and update the association between the role and the role authority scope using the updated role authority scope.
9. An electronic device, characterized in that: It includes a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other via the communication bus; Memory for storing computer programs; A processor, configured to implement the steps of the method according to any one of claims 1 to 5 when executing a program stored in a memory.
10. A computer storage medium, characterized in that The computer storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 5 are implemented.
Citation Information
Cited By
User authority management determination method and device, electronic equipment and storage medium
CN121071911A
Account management method and device, equipment, medium and product
CN121603270A
Multi-user system authority management method and system applied to micro-service architecture, medium and computer program product
CN121808810A